Skip to content
SECQON

SecQon GDPR and UK Data Protection Addendum

Effective date: 28 September 2026 · Version: 2026-09-v2

This Addendum supplements the SecQon Privacy Policy and Data Processing Agreement (the "DPA") of Infiqon Private Limited ("Infiqon", "we", "us"). Those documents are written for India's Digital Personal Data Protection Act, 2023, which is the law we are established under. This Addendum adds what the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "EU GDPR") and the UK GDPR and Data Protection Act 2018 require when either of them applies. We call them together "the GDPR".

When it applies. When the processing is subject to the GDPR. Usually that is because you are established in the European Economic Area or the United Kingdom, or because we offer the Service to people who are there (GDPR Article 3(2)). Where it does not apply, this Addendum has no effect and the Privacy Policy and DPA stand alone.

It changes nothing about what the Service does. It maps what the Privacy Policy and DPA already describe onto the GDPR's terms, and adds the transfer safeguards the GDPR requires. The facts come from those two documents: where the data is hosted, what reaches a language model, who the sub-processors are and how deletion works. If this Addendum ever appears to describe different processing, that is a mistake and we want to hear about it.

Part A covers personal data we control. Part B covers personal data we process for you.


Part A — Where we are the controller

This is the data described in Privacy Policy §1.1: your account, the people you invite, our billing, security and audit records, the free exposure check, and what a visitor does on our marketing site.

A1. Who we are

Controller: Infiqon Private Limited, Plot No. 20, Block H-1/A, Sector 63, Noida, Gautam Buddha Nagar 201301, Uttar Pradesh, India · legal@secqon.com.

Representatives in the EU and the UK (GDPR Article 27): not yet appointed. Until they are, write to legal@secqon.com about anything this Addendum covers. That address is answered by the same people a representative would pass your request to. When we appoint representatives we will name them here, with their contact details, and you may then contact them instead of us.

A2. Our lawful bases

Privacy Policy §3 states our purposes in DPDP Act terms. Under the GDPR the bases are these:

PurposeWhat it coversLawful basis (Article 6(1))
Providing the Serviceyour account, your team, verifying assets, running scans, Reports, transactional email(b) contract
Billinginvoices, payment records, the tax details on them(b) contract, and (f) legitimate interests in keeping the records Indian tax law requires of us
Keeping testing lawful and boundedthe ownership gate, scope guard, rate limits and the append-only audit log(f) legitimate interests: proving who authorised live testing of which system, and protecting the owners of systems that were not authorised
Securing the platforminvestigating abuse of public endpoints, the keyed IP digest on the free exposure check, and Google reCAPTCHA on the sign-up, log-in, password-reset and free-check forms (Privacy Policy §2.9)(f) legitimate interests: keeping the Service and the systems it touches safe, and keeping automated sign-ups and credential-stuffing off it
Measuring our own funnelthe first-touch attribution record in Privacy Policy §2.1 and the storage table in §2.8(f) legitimate interests: knowing which of our own links brought a visitor. See the note below
Analytics and ad measurementGoogle Tag Manager, Google Analytics, Google Ads, the LinkedIn Insight Tag (Privacy Policy §2.6)(a) consent, given in the banner. Nothing loads without it
Marketing email after a free exposure checkthe address you gave us for the full result(a) consent, withdrawable from any message

Obligations under Indian law — the CERT-In directions and the Information Technology Act, 2000 — are not "legal obligations" for GDPR Article 6(1)(c), which covers only EU and UK law. Where we keep records because Indian law requires it, we rely on legitimate interests under Article 6(1)(f). We do not claim Article 6(1)(c).

On the attribution record. It sits in your browser's storage before you answer the consent banner, and it records nothing but campaign parameters and a referring host. Privacy Policy §2.8 lists it with everything else we store in your browser. It is never sent to a third party.

Where we rely on legitimate interests, you may ask us for the balancing test we applied.

A3. Your rights

Under GDPR Articles 15 to 22 you may ask us to give you a copy of your data, to correct it or erase it, or to restrict how we use it. You may also receive the data you gave us in a portable form, object to processing we base on legitimate interests, and withdraw consent at any time without affecting processing that took place before.

Write to legal@secqon.com. We respond within one month, which Article 12(3) lets us extend by two further months for a complex request. If we extend, we will tell you why within the first month. Privacy Policy §9 explains what we cannot erase and why. The main example is the append-only audit log.

You may complain to the data protection supervisory authority in the EU member state where you live or work or where you believe the infringement happened. In the UK that is the Information Commissioner's Office. We would rather hear from you first.

A4. Automated decisions

We make no decision about you that produces legal or similarly significant effects based solely on automated processing (Article 22). The language model described in Privacy Policy §5 assesses Findings about systems, not people.

A5. Where your data goes

We are established in India and host in asia-south1 (Mumbai). When you give us personal data directly, by signing up or submitting a form, you are sending it to a company in India. The sub-processors that handle it are listed at secqon.com/legal/subprocessors, with where each one processes.


Part B — Where we are the processor

This is the Customer Data defined in DPA §1.1: the Assets you add, the Scans you run, and the Findings, evidence and Reports they produce. You are the controller, or, in the agency case in DPA §1.4, a processor for your client, and we are your sub-processor.

B1. The Article 28 terms

GDPR Article 28(3) lists what a processing contract must contain. The DPA already contains each item. This table maps them:

Article 28(3)RequirementWhere the DPA meets it
preamblesubject matter, duration, nature, purpose, data and data subjects§2
(a)process only on documented instructions, including on transfers§3.1–3.2, and B4 below
(a), last sentencetell you if an instruction infringes the law§3.3
(b)confidentiality of authorised persons§4
(c)Article 32 security measures§5 and §6
(d)conditions for engaging sub-processors§7, and B3 below
(e)help you answer data subject requests§9.1
(f)help with Articles 32 to 36: security, breach notification, impact assessments, prior consultation§5, §9.2 and §10, and B2 below
(g)delete or return data at the end of the Service§8
(h)information and audits§11

References in the DPA to the "DPDP Act", "Data Fiduciary", "Data Processor" and "Data Principal" are read, for this Part, as references to the GDPR, "controller", "processor" and "data subject". DPA §1 already provides for this.

B2. Breach notification

DPA §10.1 commits us to notify you without undue delay after we become aware of a personal data breach affecting Customer Data. For processing under the GDPR, we will also notify you no later than 48 hours after we become aware. That leaves you time to meet your own 72-hour deadline under Article 33. If we do not have everything by then, we give you what we have and send the rest as we learn it.

B3. Sub-processors

You give general written authorisation (Article 28(2)) for the sub-processors listed at secqon.com/legal/subprocessors. For processing under the GDPR, we will give you at least 30 days' notice before adding or replacing a sub-processor that handles Customer Data. The notice goes by email to your organisation's owners and on that page. Your right to object is DPA §7.3.

Each sub-processor is bound by written terms giving protection no less than this Addendum and the DPA (Article 28(4)). We stay fully liable to you for their performance.

B4. Transfers to India, and onward

Customer Data is hosted and processed in India, and the EU and UK have made no adequacy decision for India. So a transfer to us from the EEA or the UK is a restricted transfer, and it is made under the safeguards below.

B4.1 EU Standard Contractual Clauses. The standard contractual clauses adopted by European Commission Implementing Decision (EU) 2021/914 (the "SCCs") are incorporated into this Addendum by reference and form part of it. We apply:

  1. Module Two (controller to processor) where you are the controller;
  2. Module Three (processor to processor) where you are a processor for your client (DPA §1.4).

With these choices:

  1. Clause 7 (docking clause) applies;
  2. Clause 9(a), Option 2 (general written authorisation) applies, with the notice period in B3;
  3. the optional wording in Clause 11(a) does not apply;
  4. Clause 13: the competent supervisory authority is the one for your establishment. If you have none in the EEA, it is the one for the member state where your Article 27 representative is established;
  5. Clauses 17 and 18: the SCCs are governed by the law of, and disputes resolved by the courts of, Ireland.

B4.2 The Annexes.

  1. Annex I.A (parties): you are the data exporter. Infiqon is the data importer, contact legal@secqon.com. Accepting the Terms of Service counts as signing the SCCs for both of us.
  2. Annex I.B (description of the transfer): DPA §2, plus: transfers are continuous for as long as you use the Service, and retention is DPA §8.
  3. Annex I.C (competent supervisory authority): as in B4.1(d).
  4. Annex II (technical and organisational measures): DPA §5 and §6.
  5. Annex III (sub-processors): the list at secqon.com/legal/subprocessors.

B4.3 The United Kingdom. For transfers under the UK GDPR, the International Data Transfer Addendum to the EU Commission Standard Contractual Clauses issued by the Information Commissioner (version B1.0, in force 21 March 2022) is incorporated by reference. Its Tables 1 to 3 are completed with the information in B4.1 and B4.2. For Table 4, either party may end it as its Section 19 allows.

B4.4 Switzerland. Where the Swiss Federal Act on Data Protection applies, the SCCs apply with these changes: references to the GDPR mean that Act, the competent authority is the Federal Data Protection and Information Commissioner, and "member state" includes Switzerland, so that data subjects there can enforce their rights where they are.

B4.5 Onward transfers. Customer Data leaves India only through the processors named in DPA §12.2. Each one is on the sub-processor list with where it processes. We apply safeguards to any onward transfer that meet SCC Clause 8.8.

B5. Requests from public authorities

  1. We will tell you promptly if a public authority asks for Customer Data, unless the law forbids us. If it does, we will ask for that restriction to be lifted (SCC Clause 15.1).
  2. We will review each request for lawfulness and challenge one we believe unlawful, and we will disclose only the minimum a request requires (SCC Clause 15.2).
  3. We will give you the information about Indian law and practice that you reasonably need for your own transfer impact assessment under SCC Clause 14.

B6. Order of precedence

On a conflict:

  1. the SCCs and the UK Addendum prevail over everything else, as SCC Clause 5 requires;
  2. then this Addendum;
  3. then the DPA, and then the Terms.

The Rules of Engagement still govern the conduct and scope of testing (DPA §13.3). What we may send to your systems is a safety question before it is a data protection one.


Contact

Data protection, this Addendum, and signed copies: legal@secqon.com. If your procurement process needs the SCCs as a separately signed document, write to us and we will provide one on these terms.

EU and UK representatives: not yet appointed. See A1.

Infiqon Private Limited, India.