Privacy policy

This page describes exactly what this website collects and what we do with it. It is short because the site collects very little — there are no cookies, no analytics and no third-party requests of any kind.

Who we are

Abhinav Cybersecurity is an offensive security consultancy founded by Abhinav Kumar, operating from Patna, Bihar, India. For the purposes of the EU/UK GDPR we are the data controller for information collected through this website. For the purposes of India's Digital Personal Data Protection Act 2023 we are the data fiduciary.

Contact for any privacy matter: kalkii@abhinavcybersecurity.online.

Collection

What this website collects

That is the complete list. There is nothing else.

Server request logs

Our web server records your IP address, the time of the request, the page requested, the HTTP status, your browser's user-agent string and the referring page. This is standard web server logging and is used to operate the site, investigate faults and detect attacks.

  • Retained 14 days

Contact form submissions

If you submit the contact form we receive the name, email address, company, service interest and message you type. This is emailed to us over an encrypted connection. It is not stored in a database on this server.

  • Emailed, not stored

Security blocklist

If an IP address repeatedly fails authentication or probes for vulnerabilities, it is temporarily added to a firewall blocklist. This holds the IP address and a timestamp.

  • Automated bans

What this website does not do

We do not use cookies. The site sets none, and there is no cookie banner because there is nothing to consent to.

We do not use analytics — no Google Analytics, no Plausible, no Matomo, no pixels, no session recording and no heatmaps.

We load no third-party resources at all. No CDN, no external fonts, no embedded videos, no chat widgets. Every file the page requests comes from this domain, which means no other company learns that you visited. You can verify this yourself in your browser's network tab.

We do not sell, rent or share your personal data with anyone for marketing purposes. Ever.

Legal basis and retention

  • Server logs — legitimate interest in operating and securing the site; retained 14 days, then automatically deleted
  • Contact form — steps taken at your request prior to entering a contract; kept in our email account until you ask us to delete it
  • Security blocklist — legitimate interest in protecting the service; entries expire automatically within 24 hours
  • Email is hosted by Hostinger, our email provider, who process it on our behalf
  • Our server is hosted by OVH in Europe; the site is served from that infrastructure
  • We use no other processors, and no data is sold or shared for advertising

Your rights

Under the GDPR and the DPDP Act you may request access to the personal data we hold about you, ask us to correct it, ask us to delete it, object to processing, or request a copy in a portable format. You may also withdraw consent at any time where consent is the basis for processing.

To exercise any of these, email kalkii@abhinavcybersecurity.online. We will respond within 30 days. We do not charge for this, and we will not ask you to justify the request.

One practical note: because server logs are deleted automatically after 14 days and are keyed only to an IP address, we usually cannot identify which log entries belong to you. If you want log data deleted, tell us promptly and give us the approximate time and IP address.

If you are in the EU or UK and believe we have handled your data improperly, you may complain to your national data protection authority. In India, you may raise a complaint with the Data Protection Board.

Client engagement data

This policy covers the website. Data handled during a security engagement — credentials, test accounts, findings, and any personal data encountered while testing your systems — is governed by the non-disclosure agreement and statement of work signed for that engagement, not by this page.

In every engagement: an NDA is signed before scope is discussed, engagement data is held only for the duration of the work plus any agreed retention period, and all findings, credentials and collected artefacts are destroyed on request at the end. We never exfiltrate real customer data as proof — evidence is a screenshot and a record.

Changes

If this policy changes materially we will update the date below. It was last updated on 12 August 2026.

Next step

Questions about your data?

Email us and we will answer. Requests to access or delete your data are actioned within 30 days.