Skip to content
SHADO Securities
Legal

Privacy Policy

What we collect, why we hold it, who may see it and how long it stays with us.


Close detail of dark expanded-metal security mesh

Last updated: 21 August 2026

1. Who we are

SHADO Securities (“SHADO”, “we”, “us” or “our”) is an intelligence-led physical security firm operating across India. We provide security consulting and risk advisory, investigations and intelligence, and trained security manpower and protection services.

This policy applies to www.shadosecurities.com and to the personal data we handle in the course of enquiries, client engagements and field operations. It should be read alongside the specific data protection and confidentiality terms of any signed service agreement, which govern in the event of a conflict.

Where we decide why and how personal data is processed — for example, data from our own website enquiry form or our employee and guard records — we act as a Data Fiduciary under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”). Where we process data on a client’s instruction — for example, monitoring a client’s CCTV estate, maintaining their visitor register or conducting background checks on their candidates — we act as a Data Processor for that client, who remains the Data Fiduciary.

2. Data we collect

2.1 Website and enquiry data

  • Name, organisation, role, email address, telephone number and the content of any message you send through our enquiry form or by email.
  • Details you volunteer about your security requirement, site or incident when requesting a proposal or an audit.
  • Technical data such as IP address, browser and device type, referring page and pages viewed, collected through server logs and any analytics tooling described in section 10.

2.2 Client and commercial data

  • Contact details of client representatives, site coordinators and emergency contacts.
  • Billing details, purchase orders, correspondence and contract documentation.

2.3 Operational and field data

This is the category unique to our industry, and we treat it as the most sensitive material we hold:

  • CCTV and video surveillance footage from cameras at sites we secure, monitor or audit, including any associated timestamps and camera metadata.
  • Access control and visitor logs — entry and exit records, gate registers, vehicle numbers, visitor identity details, badge or card swipe data and biometric attendance records where a client operates such a system.
  • Background verification records — identity documents, address history, employment and education verification, reference checks, criminal record and court record checks, and credential validation carried out with the candidate’s knowledge and on a client’s instruction.
  • Investigation case material — statements, interview notes, photographs, documentary evidence, asset and due-diligence findings, surveillance observations, incident reports and analytical products prepared for a client matter.
  • Guard force and deployment records — records of our own personnel, including verification files, training and licensing records, duty rosters, attendance and shift logs, and incident or occurrence book entries.
  • Patrol logs, control room records, alarm and incident data, and communications relating to an event at a protected site.

We do not seek personal data that is not needed for the engagement. Where an investigation or verification file inevitably captures information about third parties, we limit collection to what is relevant to the matter and proportionate to its purpose.

3. Lawful basis and purpose

Under the DPDP Act we process personal data either with the consent of the Data Principal, or for a legitimate use permitted by the Act. Our purposes are:

  • Responding to enquiries — to answer your message, prepare a proposal and follow up on a request you initiated.
  • Delivering contracted services — to plan, staff, run and audit the security, investigation or advisory work a client has engaged us for.
  • Safety of persons and property — to prevent, detect and respond to theft, fraud, trespass, violence and other threats at sites under our protection.
  • Employment and licensing — to verify, train, deploy, supervise and pay our security personnel, and to meet obligations under the Private Security Agencies (Regulation) Act, 2005 and applicable state rules.
  • Legal and regulatory compliance — to meet statutory obligations, respond to lawful orders and establish, exercise or defend legal claims.

Where consent is the basis, you may withdraw it at any time as described in section 8. Withdrawal does not affect processing already carried out, and may mean we can no longer provide a particular service.

4. Surveillance, investigations and confidentiality

Investigation and background-verification material is handled on a strict need-to-know basis. It is compartmentalised by case, accessible only to the assigned case officer and the reviewing supervisor, and is never used for any purpose other than the matter it was collected for.

  • Every investigation is undertaken only on written instruction from a client and within the lawful scope agreed in the engagement letter.
  • We do not conduct interception of communications, unauthorised access to accounts or devices, impersonation of public officials, or any technique prohibited by Indian law. We will decline instructions that would require it.
  • Findings are reported to the instructing client only. Investigators do not retain personal copies of case files, and working material is returned to the case record on closure.
  • CCTV monitoring is limited to areas the client has lawfully designated for surveillance. Cameras are not to be positioned in areas where a person has a reasonable expectation of privacy, and we will raise it with the client where we observe otherwise.
  • Footage review and export is logged. Copies are released only to the client’s authorised contact or in response to a lawful demand.
  • All personnel sign confidentiality undertakings that survive the end of their engagement with us.

5. How we share data

We do not sell personal data. We share it only as follows:

  • With the instructing client — reports, footage, logs and findings relating to their site, personnel or matter, released to their nominated authorised recipients.
  • With law enforcement and courts — where we receive a valid summons, warrant, court order or written request under applicable law, or where disclosure is necessary to report a cognisable offence or to prevent imminent harm to a person. We disclose the minimum necessary and, unless legally barred, inform the affected client.
  • With sub-processors and specialist vendors — verification agencies, forensic specialists, cloud hosting and video storage providers, IT support and professional advisers. They act on our documented instructions under written confidentiality and data protection terms.
  • With insurers and legal advisers — where needed to handle a claim, incident or dispute.

Data is primarily stored and processed in India. Where a sub-processor operates infrastructure outside India, we transfer data only as permitted under section 16 of the DPDP Act and subject to contractual safeguards.

6. Retention

We keep data only as long as it serves the purpose it was collected for, or as long as law requires. Indicative periods:

  • Website enquiries that do not become engagements — up to 12 months, then deleted.
  • CCTV footage — typically 30 to 90 days, according to the client’s configured retention setting, after which it is overwritten. Clips preserved for an incident or legal hold are retained until the matter concludes.
  • Visitor, access and patrol logs — generally 12 months, or as the client directs.
  • Background verification records — generally up to 3 years from the date of the report, unless the client requires earlier deletion or a longer regulatory period applies.
  • Investigation case files — generally up to 7 years from case closure, reflecting limitation periods for civil and criminal proceedings in which the evidence may be needed.
  • Employment, licensing and statutory records — for the periods prescribed by labour, tax and private security regulation.
  • Contract and financial records — up to 8 years, in line with tax and audit requirements.

Where we act as a processor, retention follows the client’s documented instruction. On termination we return or securely destroy client data, other than copies we are legally required to keep.

7. Security measures

  • Role-based access control, unique named accounts and multi-factor authentication for systems holding case, verification or footage data.
  • Encryption of data in transit and at rest on managed systems, with encrypted storage for portable media and field devices.
  • Physical controls at our offices and control rooms, including restricted access to evidence storage and locked handling of hard-copy case files.
  • Access, export and review logging for footage and case material, with periodic audit of those logs.
  • Vetting, background verification and confidentiality undertakings for all staff, with data handling covered in induction and refresher training.
  • Documented incident response. If a personal data breach occurs, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act, and inform affected clients without undue delay.

No system is absolutely secure. We commit to proportionate, industry-appropriate safeguards and to prompt, honest disclosure if something goes wrong.

8. Your rights

Subject to the DPDP Act and its exemptions, you may ask us to:

  • Access — confirm whether we hold your personal data and obtain a summary of it and of the recipients it has been shared with.
  • Correct or complete — rectify inaccurate or incomplete data, or update data that has changed.
  • Erase — delete data that is no longer needed for the purpose it was collected for.
  • Withdraw consent — where processing rests on consent, withdraw it as easily as it was given.
  • Nominate — nominate another individual to exercise these rights in the event of your death or incapacity.
  • Complain — raise a grievance with us and, if unresolved, with the Data Protection Board of India.

Send requests to info@shadosecurities.com. We will verify your identity and respond within a reasonable period. Please note two limits specific to our work: where we hold data as a processor for a client, we will route your request to that client, who is the Data Fiduciary; and access or erasure may be lawfully refused or deferred where it would prejudice an active investigation, the prevention or detection of an offence, the safety of a person, or evidence needed for legal proceedings. We will tell you when we rely on such a ground.

9. Children’s data

Our website and services are directed at organisations and are not intended for children. We do not knowingly collect personal data of a child (a person under 18 in India) through this site, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children.

Where a child’s data is unavoidably captured in an operational context — for example, a child appearing in CCTV footage at a residential or retail site, or a minor named in an incident report — it is processed only for the safety purpose for which the system exists, handled with heightened care and restricted access, and retained no longer than necessary. Where the DPDP Act requires verifiable parental consent for the processing of a child’s data, we will not proceed without it. If you believe we hold a child’s data in error, contact us and we will delete it.

10. Cookies and analytics

This website uses only what it needs to function, together with privacy-respecting measurement of aggregate traffic. We do not use advertising cookies, cross-site trackers or data brokers, and we do not build advertising profiles of visitors.

  • Essential — cookies or local storage needed for security, load balancing and basic site functionality.
  • Analytics — aggregate statistics on pages viewed and referral sources, used to improve the site. Where a provider is used that sets non-essential cookies, we will ask for consent first.

You can block or delete cookies through your browser settings. Blocking essential cookies may affect how the site works.

11. Changes to this policy

We may update this policy as our services, systems or legal obligations change. The revised version takes effect when published here, and the “last updated” date above will change. Where a change materially affects how we handle your data, we will take reasonable steps to notify you directly.

12. Contact and grievances

For any question about this policy, to exercise your rights, or to raise a grievance about how we have handled your data, contact our grievance point of contact:

If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the DPDP Act.