Who we are and what this covers
This website, keensec.ai, is run by Digital Wolf (“Digital Wolf”, “we”, “us”). KeenSec is a Digital Wolf product brand, not a separate company. Digital Wolf decides how the personal data described here is used.
This policy covers the website: its pages, its forms and the Spot the Signal exercise.
It does not cover the KeenSec product. The product runs at portal.keensec.ai and is available only to organisations we have onboarded under a signed customer agreement, Data Processing Agreement (DPA) and NDA. Personal data in the product, such as employee details, simulation results, reported emails and training records, is handled under those agreements. Under applicable frameworks including the GDPR and CCPA/CPRA, the customer organisation (the employer) is explicitly designated as the Data Controller. Digital Wolf operates strictly as a Data Processor acting upon the documented instructions of the Data Controller. If you use KeenSec through your employer, contact your employer first; we will help them respond.
What we collect
| Source | What we receive | Why |
|---|---|---|
| Forms you submit (demo, quote, contact, partner) | Your name, work email, organisation, job title or role, organisation size, country, the topic or areas you are interested in and your message. The partner form also asks about your company type, customer base and services; the quote form about the capabilities, channels and hosting you need. We also record your product updates choice, the notice you saw and when you submitted. | To respond to your request, arrange your demo, prepare your quote or review your partner application, and to contact you about KeenSec in connection with it. |
| Visit context, only if you allowed measurement | The page you first landed on, the referring website, campaign tags, the pages you read, the button that led you to the form, your number of visits and time on site, and your device type, screen size, language and time zone. This is kept in your browser and sent only with a form you submit. | To understand which pages and campaigns bring enquiries. |
| Every visit | Your IP address, browser details, the page requested and the time. These are processed by our hosting provider, and by our lead service when you submit a form. | To deliver the website, keep it secure and prevent abuse such as spam and floods of requests. |
| Email you send us | Whatever you choose to include. | To reply to you. |
We don’t ask for payment details, government identifiers or sensitive personal data. Please don’t include them in a message.
Spot the Signal runs entirely in your browser. Your answers and score are not sent to us, and they are forgotten when you leave the page.
How we use it, and on what basis
- Responding to your request. Each form tells you, next to the submit button, who will use your details and for what. Submitting the form is your agreement to that use.
- Product updates. Only if you tick the separate, optional box. It is never ticked for you. Every update email has an unsubscribe link.
- Measurement. Only if you choose Accept in the cookie banner or turn on Measurement in Cookie settings. See the Cookie Notice.
- Security. Technical data is used to run and protect the website and our lead service.
Where India’s Digital Personal Data Protection Act 2023 applies, we rely on your consent for these uses, or on the uses the Act allows without it. Where the GDPR or a similar law applies, we rely on our legitimate interest in answering business enquiries and keeping our services secure, and on your consent for product updates and measurement.
We don’t sell your personal data, share it with advertising networks or use it to make decisions about you that have legal or similarly significant effects.
Who receives it
Our sales team and the people who handle your request see your details. We also use these service providers, who process data for us under contract:
| Provider | What they do for us | Data involved |
|---|---|---|
| Cloudflare | Hosts and delivers this website and protects it from attacks. | Technical data from every visit. |
| Amazon Web Services (AWS) | Runs our lead service (api.keensec.ai), which receives and stores the forms you submit. It is hosted in the AWS region that data-residency requirements call for: for India, the AWS Mumbai region. | Your form details, visit context if you allowed it, and technical data. |
| Email delivery providers | Send our replies to your enquiry and, if you opted in, product updates. | Your name, email address and the content of the email. |
| Better Stack | Error logging and uptime monitoring for our services. | Technical error and performance data from our services. |
We share your details with others only when:
- you ask to buy through one of our MSSP partners, and agree to us passing your enquiry to them;
- the law, a court or a regulator requires it, or it is needed to protect people or our services from harm;
- we reorganise, merge or sell part of the business, in which case the recipient must protect your data as this policy describes.
If you send a form by email instead, for example because the form could not reach our servers, your email provider and ours also handle it.
Where your data is processed
This website can be visited from anywhere, and Cloudflare serves it from data centres around the world. Some of our service providers may process your data outside your country, including outside India. We use providers that commit by contract to protecting it.
Where your data is hosted in the KeenSec product is set by your organisation’s customer agreement and DPA, not by this policy.
How long we keep it
We keep form details for up to 12 months from the day you submit the form, or delete them sooner once we have dealt with your request, whichever comes first. If you opted in to product updates, we keep your name and email for that purpose until you unsubscribe, again for no more than 12 months. If the law requires us to keep a particular record for longer, we keep only that record, only for as long as required. You can ask us to delete your details at any time.
Technical logs are kept for a limited period for security and troubleshooting. Visit context stored in your browser is described in the Cookie Notice.
How we protect it
We use access controls and encrypt data in transit between your browser and our services. No method of transmission or storage is completely secure. If a breach affects your personal data, we will notify you and the relevant authorities where the law requires it.
Our wider security and AI practices are described in the Trust Center.
Your rights and choices
Where India’s Digital Personal Data Protection Act 2023 applies (its main duties apply from May 2027), and under the GDPR or other data protection laws where they apply, you can:
- ask for a summary of the personal data we hold about you and how we use it;
- ask us to correct, complete or erase it;
- withdraw consent at any time, as easily as you gave it: use Cookie settings, the unsubscribe link in any update email, or write to us. Withdrawal does not affect processing before it;
- nominate another person to exercise these rights for you, where the DPDP Act allows it;
- raise a grievance with us and, where the DPDP Act applies, complain to the Data Protection Board of India after using our grievance process. Where another law applies, you may also complain to your local data protection authority.
Write to privacy@keensec.ai. We may ask you to confirm your identity, and we reply within the time the applicable law allows.
Grievances: privacy@keensec.ai.
Children
This website is meant for organisations and is not directed at children. We don’t knowingly collect personal data from anyone under 18 through it. If you believe a child has sent us their details, write to privacy@keensec.ai and we will delete them.
Changes and contact
We update this policy when our website or the law changes. The effective date at the top shows the current version.
Digital Wolf, 22/263 Jodhpur Gardens, Kolkata, West Bengal 700045, India. Privacy questions: privacy@keensec.ai.