Legal
Data Policy
How RikArena classifies, handles and protects data — both on this website and across the application, ERP and Digitus Egis engagements we deliver for clients.
This Data Policy sets out the principles RikArena Consultancy Pvt. Ltd. applies to data we handle as a company — distinct from our Privacy Policy, which covers personal information collected through this website. It is written for clients, partners and procurement teams who want to understand our data handling posture before or during an engagement.
1. Scope
This policy applies to data RikArena handles across three contexts: this website's own visitor and enquiry data; application, ERP and business-system engagements we build or support; and cyber security engagements built around our Digitus Egis platform, which processes host, log and endpoint telemetry on behalf of clients.
2. Data we handle
- Company data — enquiry and contact information collected through rikarena.org, described in our Privacy Policy.
- Engagement data — application data, business records and source code we access to build, run or support a client's systems.
- Security telemetry — host events, logs, configuration and behavioral signal collected by Digitus Egis for the purpose of intrusion detection, monitoring and compliance reporting within a client's environment.
3. Ownership and our role
Client data remains the property of the client at all times. In an engagement, RikArena acts as a service provider — and, where Digitus Egis is deployed, as a processor of the client's own security data on the client's behalf. We do not claim ownership of engagement or telemetry data, and we do not use it for any purpose outside the scope of the engagement it was collected for.
4. Handling principles
- Confidentiality. Engagements run under confidentiality and, where requested, non-disclosure terms.
- Least-privilege access. Access to client systems and data is scoped to the individuals delivering the engagement.
- Encryption. Data is encrypted in transit, and at rest where the platform and engagement support it.
- Environment segregation. Client environments and data are kept logically separated from one another and from our own internal systems.
- Audit trail. Actions taken within Digitus Egis and monitored environments are logged to support incident review and compliance evidence.
These principles are informed by the frameworks our cyber security practice already works against — ISO 27001, NIST CSF 2.0, CERT-In directions, India's DPDP Act, GDPR, PCI-DSS, HIPAA and SOC 2 — applied to the extent relevant to a given engagement.
5. Retention and disposal
Data is retained only for as long as the engagement agreement or applicable regulatory obligation requires — for example, log retention windows referenced in CERT-In directions. At the end of an engagement, data is securely returned to the client, deleted, or archived only where a longer retention obligation applies.
6. Sub-processors and third parties
Where we rely on hosting or infrastructure providers to deliver an engagement, they operate under confidentiality obligations consistent with this policy. We do not sell client or telemetry data, and any cross-border transfer of data is made only with appropriate contractual and technical safeguards in place.
7. Incident and breach response
We apply the same detection and response discipline behind Digitus Egis to data we ourselves hold. Where a security incident affects client data, we notify the affected client without undue delay and in line with the engagement agreement and applicable regulatory timelines, including CERT-In and DPDP Act breach notification expectations.
8. Client responsibilities
Clients remain responsible for their own regulatory obligations over the data they own, including obligations to their end users and regulators. RikArena's role — through Digitus Egis and our consultancy services — is to support that responsibility with monitoring, evidence and reporting; it does not replace a client's own compliance function.
9. Review
This Data Policy is reviewed periodically and updated as our practice, tooling or applicable law evolves. The "Effective" date at the top of this page reflects the current version.
10. Contact us
For data handling questions, or to request information as part of a security or procurement review, contact us:
- Email: archana@rikarena.org
- Phone: +91 8102113936
- Post: RikArena Consultancy Pvt. Ltd., 1503B, 1504, Iconic Corenthum, Sector 62, Noida (UP) 201301, India
Related policies