Legal

Terms, Privacy & Data Practices

How AppSecWarrior handles your data and the rules for using our website and services — aligned with applicable Indian law, including the Digital Personal Data Protection Act, 2023.

Effective date: 28 August 2026  ·  Last updated: 28 August 2026

Policy timeline

Key milestones for our legal framework and this document.

  1. 2000

    Information Technology Act

    India’s primary cyber and electronic-commerce law; informs our security and lawful-use obligations.

  2. 2023

    Digital Personal Data Protection Act

    DPDP Act enacted — establishes rights of Data Principals and duties of Data Fiduciaries in India.

  3. 2026

    Unified site policy (this document)

    Combined Terms of Use and Privacy & Data Practices for appsecwarrior.org, contact forms, and newsletter.

1. Introduction

Welcome to AppSecWarrior (“we”, “us”, “our”), operating at appsecwarrior.org. These Terms of Use and Privacy & Data Practices (“Policy”) govern access to our website, contact and subscription forms, free career services, and paid application-security consulting.

By using our website or submitting a form, you agree to this Policy. If you do not agree, please do not use our services. We are an organisation focused on application security education, assessment, and community support, based in Pune, Maharashtra, India.

This Policy is provided for transparency and operational compliance. It is not legal advice. For specific legal questions, consult qualified counsel.

2. Services offered

Free career services

  • Interview preparation
  • Resume guidance
  • Mock interviews
  • Job referrals

Provided at no charge to security professionals, subject to availability and our discretion.

Paid security services

  • Vulnerability assessment & penetration testing (VAPT)
  • Secure code review & SCA
  • API & mobile application testing
  • Threat modeling & secure UX design
  • Secure web development consulting

Scope, fees, and deliverables are agreed separately before engagement.

3. Acceptable use

You agree to:

  • Provide accurate information in contact and subscription forms.
  • Use the website only for lawful purposes under Indian law.
  • Not attempt unauthorised access, scraping that impairs service, malware distribution, or disruption of our systems.
  • Not misuse free career services (e.g. spam, false identity, or harassment).

We may suspend or refuse service if these rules are violated.

4. Personal data we collect

As a Data Fiduciary under the DPDP Act, 2023, we collect only data necessary for stated purposes (data minimisation):

SourceDataPurpose
Contact forms (paid / free) Name, email, subject, service type, message, captcha verification Respond to enquiries and deliver requested services
Newsletter subscribe Email address Send updates you opted into; stored in our subscriber list
Website & analytics IP address, browser/device type, pages visited, referral URL, cookie identifiers Security, performance, and aggregated usage analysis
Cookie consent (Cookiebot) Consent preferences Record and honour your cookie choices

We do not knowingly collect personal data from children under 18. Our services are not directed at minors.

5. Lawful basis & use of data

We process personal data based on:

  • Consent — when you submit a form, subscribe to updates, or accept non-essential cookies.
  • Legitimate uses — as permitted under the DPDP Act, including responding to your requests, securing our website, and complying with law.
  • Contract — where processing is necessary to deliver paid services you engage us for.

We do not sell your personal data. We do not use contact form data for unrelated marketing without consent.

6. Your rights as a Data Principal

Under the DPDP Act, 2023, you may have the right to:

  • Access — obtain a summary of personal data we hold about you and how it is processed.
  • Correction & erasure — request correction of inaccurate data or erasure when no longer needed or consent is withdrawn.
  • Withdraw consent — unsubscribe from emails or withdraw cookie consent at any time.
  • Grievance redressal — raise concerns with our Grievance Officer (see Section 13).
  • Nominate — nominate another person to exercise your rights in the event of death or incapacity, as permitted by law.

To exercise rights, email info@appsecwarrior.org with subject line “Data Principal Request”. We may verify identity before responding. We aim to respond within timelines prescribed under applicable rules.

7. Cookies, analytics & third parties

We use:

  • Cookiebot — to manage and record cookie consent.
  • Google Analytics — to understand aggregated website traffic (may involve cross-border processing by Google).
  • Essential cookies — for security (e.g. CSRF session tokens on forms) and basic site operation.

Non-essential cookies load only after consent where required. You can change preferences via the cookie banner or browser settings. Third-party processors are engaged for legitimate operational purposes; we require appropriate safeguards where applicable.

8. Retention, security & breach notification

We retain personal data only as long as needed for the purposes above, or as required by law. Typical periods:

  • Contact enquiries — up to 24 months after last communication, unless a longer period is needed for an active engagement.
  • Newsletter subscribers — until you unsubscribe or request deletion.
  • Server/rate-limit logs — short-term retention for abuse prevention.

We apply reasonable technical and organisational measures (encryption in transit via HTTPS, access controls, input validation, rate limiting, and secure headers). No method is 100% secure.

If a personal data breach likely affects you, we will notify you and the Data Protection Board of India as required under applicable law and rules.

9. Paid services & payments

  • Fees and scope are agreed in writing before work begins.
  • Payment terms, invoices, and taxes (including GST where applicable) are as per the engagement agreement.
  • Refunds, if any, follow the specific service agreement; assessment deliverables may not be refundable once work has commenced.
  • Security testing is conducted with your authorisation and within agreed scope only.

10. Intellectual property

Website content, branding, reports, methodologies, and materials are owned by AppSecWarrior or licensors. You may not copy, redistribute, or commercialise our content without written permission. Limited personal use for evaluation is permitted.

11. Disclaimers & limitation of liability

Website content and free resources are provided “as is” for general information. They do not guarantee employment, certification outcomes, or that all vulnerabilities in your systems will be found.

To the fullest extent permitted by Indian law, AppSecWarrior is not liable for indirect, incidental, or consequential damages arising from use of the website or services. Our total liability for any claim is limited to fees paid to us for the specific paid service giving rise to the claim in the twelve (12) months before the claim, except where law does not allow such limitation.

You agree to indemnify us against claims arising from your unlawful use of the site or breach of this Policy.

12. Changes to this Policy

We may update this Policy to reflect legal, technical, or business changes. Material updates will be posted on this page with a revised “Last updated” date. Continued use after changes constitutes acceptance of the updated Policy.

13. Grievance redressal

In accordance with the DPDP Act and Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, grievances may be submitted to:

Grievance Officer — AppSecWarrior

Email: info@appsecwarrior.org

Location: Pune, Maharashtra, India

We endeavour to acknowledge grievances within 24 hours and resolve them within 15 days, or as otherwise required by applicable law.

14. Governing law & jurisdiction

This Policy is governed by the laws of India. Courts at Pune, Maharashtra shall have exclusive jurisdiction, subject to applicable consumer protection remedies where you qualify as a consumer under the Consumer Protection Act, 2019.

15. Contact us

Questions about these terms or your personal data: