Security Policy

Last Updated: September 7, 2026

This Security Policy outlines the technical, organizational, and administrative measures implemented by AICORZEN-BRAYNEXA TECHNOLOGIES (OPC) PRIVATE LIMITED (hereinafter referred to as "Company", "We", "Us", or "Our") to protect the confidentiality, integrity, and availability of personal data, sensitive information, and all digital assets under our control.

This Policy is designed to comply with:

This Policy applies to all employees, trainers, interns, contractors, vendors, and third-party service providers who access, process, or handle any data or systems owned or operated by the Company.


1. Scope and Applicability

This Security Policy applies to:

2. Reasonable Security Safeguards

The Company implements "reasonable security safeguards" as required under Section 43A of the IT Act, 2000 and the DPDP Rules, 2025[reference:7][reference:8]. These safeguards include, at a minimum, the following measures[reference:9][reference:10]:

2.1 Encryption

2.2 Access Control

2.3 Data Obfuscation and Masking

2.4 Logging and Monitoring

2.5 Periodic Audits and Vulnerability Assessments

2.6 Physical Security

3. Data Retention and Erasure

The Company adheres to the following data retention and erasure practices in compliance with Section 8(7) of the DPDP Act, 2023[reference:25]:

4. Incident Response and Breach Notification

The Company has established a comprehensive Incident Response Plan to detect, respond to, and recover from security incidents and personal data breaches[reference:29].

4.1 Incident Detection and Triage

4.2 Reporting to CERT-In

4.3 Breach Notification to Data Principals

4.4 Post-Incident Analysis

5. Third-Party Security

The Company engages third-party service providers (e.g., payment gateways, hosting providers, analytics services) to support its operations. All such engagements are subject to:

6. Employee Training and Awareness

The Company recognizes that human factors are critical to security. Accordingly:

7. Data Protection Officer and Grievance Redressal

In compliance with the DPDP Act, 2023 and the IT Act, 2000, the Company has designated a Grievance Officer / Data Protection Officer to oversee data protection and security matters. The officer can be contacted at:

Grievance Officer: [Name of the Grievance Officer / Data Protection Officer]
Email: [Your Official Grievance Email Address]
Phone: [Your Official Contact Number]

Any concerns, complaints, or inquiries regarding data security or this Security Policy should be directed to the Grievance Officer. The Company endeavors to acknowledge all complaints within 24 hours and resolve them within 30 days.

8. Compliance and Enforcement

Compliance with this Security Policy is mandatory for all employees, contractors, and third-party service providers. Non-compliance may result in disciplinary action, termination of employment or engagement, and legal proceedings as applicable under Indian law.

The Company reserves the right to update, modify, or amend this Security Policy at any time to reflect changes in legal requirements, industry best practices, or operational needs. Any changes will be posted on this page with an updated "Last Updated" date.

9. Contact Us

If you have any questions, concerns, or requests regarding this Security Policy or our data security practices, please contact us at:

AICORZEN-BRAYNEXA-TECHNOLOGIES (OPC) PRIVATE LIMITED
Email: info@aicorzenbraynexa.com

Important Note: This Security Policy is a living document and is subject to periodic review and updating. All users, employees, and stakeholders are encouraged to review this Policy regularly to stay informed about our security practices and their obligations.


© 2026 AICORZEN-BRAYNEXA TECHNOLOGIES (OPC) PRIVATE LIMITED. All Rights Reserved.