Skip to main content
RingSafe
Academy

Learn

Browse ModulesPractitioner-grade lessons across 18 tracks AI Security Hub5-level practitioner track Certifications GuideOSCP, CISSP, CEH, AWS, more All Modules & TracksFull index across every track

Plan your path

Learning RoadmapBeginner → expert, tier by tier Skill MapInteractive skill graph — explore by node Practitioner RoadmapCISSP-style 8-domain map
Browse all modules & tracks
My Academy →
Services

Offensive Security

VAPT — Penetration TestingManual, senior-led pentest & VA VAPT — overview & scopeWhat it is, methodology, FAQ VAPT Buyer's GuideScope, pricing, RFP template

Cloud Security

Cloud Security AuditsAWS, Azure, GCP, Kubernetes Cloud Security — overviewDomains, India compliance, FAQ Cloud Hardening GuideMulti-cloud hardening playbook

Advisory & Response

DPDP / Privacy AdvisoryGap assessment, RoPA, DPIA, DPA Compliance AdvisoryISO, SOC 2, RBI, SEBI, IRDAI… vCISO AdvisoryFractional security leadership Incident ResponseContainment, forensics, notify
Case Studies — recent anonymised engagements
Book a scoping call →
Vendor Risk
RingSafe TrustManaged vendor risk (TPRM) — done for you, not another tool to staff How it worksDiscovery → onboarding → ongoing monitoring Why managed, not a toolManaged TPRM vs DIY or a platform to staff PricingShaped to your vendor count
Compliance

Universal · India

DPDP HubLearn the law — guide, tools, modules DPDP Act 2023 GuidePrivacy law, ₹250cr penalty CERT-In Direction6h reporting, 180d logs

Sectoral · India

RBI Cyber FrameworkBanks, NBFCs, payments SEBI CSCRFBrokers, RIAs, AMCs, MIIs IRDAI GuidelinesInsurance sector ABDM & Health DataHospitals, healthtech, EHR PCI-DSS v4.0Card data handling TRAI / DoT CyberTelecom, ISP, VNO

International

ISO 27001:2022ISMS certification SOC 2 (Type I & II)For US enterprise sales HIPAAFor US healthcare PHI GDPRFor EU customers
Indian Compliance Hub — view all frameworks
Readiness self-assessments →
News
Blog

Articles by Topic

AI SecurityMCP, prompt injection, agent red team Threat IntelligenceCVEs, campaigns, TTPs, IOCs VAPT & PentestMethodology, scoping, reports

 

Cloud SecurityAWS, Azure, GCP, Kubernetes DPDP & ComplianceIndian regulatory mapping Red TeamingAD, lateral movement, evasion
Latest: Apache HTTP/2 CVE-2026-23918: Double-Free RCE
All articles → Templates & downloads →
Tools

Compliance Tools

DPDP Self-AssessmentPrivacy posture in 5 minutes DPDP Penalty CalculatorEstimate exposure under §33 vAPT Scope CalculatorEffort & INR pricing estimate

Readiness Checklists

vAPT Readiness20 questions · live score Cloud Audit Readiness20 questions · live score DPDP ReadinessFor every Indian business CERT-In ReadinessFor every Indian business

Developer Tools

JWT DecoderInspect & verify tokens Hash GeneratorSHA-256, SHA-1, MD5, more Password StrengthEntropy + crack-time estimate HTTP Header AnalyzerCSP, HSTS, security score
All free security tools
About
About RingSafeFounder story & approach Contact[email protected]
Legal Privacy Policy Terms of Service Cookie Policy
Sign Up Free Book a scoping call Sign In
Sign In Sign Up Book a call
Privacy · Updated 26 April 2026

Privacy Policy

How we collect, use, and protect your personal information when you use RingSafe — written so you can actually understand it.

6 min read Plain English India-based
The Short Version

We collect the minimum

Only what we need to run your account, deliver the academy, and keep the site secure.

You're in control

Access, correct, or delete your data on request. Withdraw consent any time.

Stored securely in India

Encrypted in transit and at rest. Logs retained 180 days as required by CERT-In.

We never sell your data

No advertisers, no data brokers, no behavioural-targeting third parties.

Contents
  1. Who we are
  2. What we collect
  3. How we use it
  4. Who we share with
  5. Legal basis
  6. Your rights
  7. How we protect data
  8. How long we keep it
  9. Cookies
  10. Cross-border transfers
  11. Children's data
  12. Changes to this policy
  13. Contact us

01Who we are

RingSafe ("RingSafe", "we", "us") is a cybersecurity consulting practice and online learning academy operated from India. Manish Garg is the founder, principal consultant, and the contact person for any privacy-related question or request.

You can reach the privacy contact at [email protected] with the subject line "Privacy Request" — we aim to respond within 14 working days.

Note: RingSafe is a small founder-led practice. We are working towards full DPDP Rules operationalisation as the government notifies them in 2026. This policy describes our current practices.

02What information we collect

2.1 When you visit ringsafe.in

  • Analytics data — aggregated, anonymised browsing activity (pages viewed, device type, approximate location) via Google Analytics 4. We do not record your IP address in full.
  • Cookies — essential cookies for site functionality (LiteSpeed cache, sessions), analytics cookies (Google Analytics), and preference cookies (theme, sidebar state).
  • Server access logs — basic access logs, kept by our hosting provider for security and performance, retained for up to 180 days as required by CERT-In Direction (28 April 2022).

2.2 When you sign up for the academy

Account creation is via Google OAuth (Google Sign-In). Google provides us with:

  • Your full name (first + last)
  • Your Google-verified email address
  • Your Google profile picture URL (we cache a copy locally)
  • Your Google user ID (used for future sign-in)

We do not receive your password, contacts, calendar, drive content, location history, or any other Google data. We do not access, request, or store any additional Google-linked information beyond the four fields above.

2.3 When you use the academy

To provide personalised learning, progress tracking, and credential issuance, we store:

  • Modules you have completed and quiz attempts (questions answered, score)
  • Points, badges, and learning streaks (via GamiPress)
  • Subscription tier (Free / Basic / Pro) and equity-tier (where applicable)
  • Forum posts and comments you have authored (via bbPress)
  • Certificates issued in your name and download history

2.4 When you purchase a subscription

Payments are processed entirely by Razorpay, a PCI-DSS-compliant payment gateway licensed by the RBI. RingSafe does not collect, store, or process your card number, CVV, UPI PIN, netbanking credentials, or bank account details. Razorpay shares with us only:

  • A transaction reference ID
  • Payment status (succeeded / failed) and amount
  • Timestamp of payment
  • Your name and email (to match to your academy account)

Razorpay's own privacy terms apply to payment processing and are available at razorpay.com/privacy.

2.5 When you contact us or submit forms

Forms on the contact page, DPDP-checklist download, and booking forms collect only the fields you explicitly fill in — typically name, email, phone (optional), and your message. Submissions are processed by WPForms, stored in our database, and emailed to [email protected].

2.6 When you post in the community forum

Forum posts are public by default. Your display name and avatar are visible alongside posts. Do not post sensitive information (credentials, client names, real attack details) — community guidelines apply.

03How we use your information

We use collected information strictly for the following purposes:

  • Service delivery — providing consulting services, delivering academy content, personalising your learning, processing payments.
  • Account management — authenticating sign-ins, recording progress and credentials, communicating transactional emails (course reset, password change, receipts).
  • Support & communication — responding to your enquiries, providing support, sending requested resources (e.g. PDF downloads).
  • Security & legal — preventing fraud and abuse, complying with lawful requests under the IT Act and DPDP, responding to security incidents.
  • Improvement — understanding aggregated usage patterns to improve site and academy content (we do not profile individuals).

We do not use your data for:

  • Marketing emails without explicit opt-in consent
  • Selling or rental to third parties
  • Targeted advertising (we do not run ads)
  • Profiling for credit, employment, or insurance decisions
  • AI/ML model training on your personal data

04Who we share information with

We share data only with the service providers required to operate RingSafe, each governed by their own contracts and data-protection terms:

ProviderPurposeData shared
Namecheap (hosting)Website & database hostingAll site data; servers in India
CloudflareCDN, WAF, DDoS protectionIP, request metadata; not stored long-term
Google (OAuth)Sign-in via Google accountAuthentication; we receive only name + email + picture
Google AnalyticsAggregate site analyticsAnonymised page-view events; IP anonymisation enabled
RazorpayPayment processingName, email, transaction details (handled entirely by Razorpay)
Email providerTransactional emailsRecipient email + content

We may also disclose information when legally required — court order, lawful demand by Indian authorities under the IT Act, or to enforce our Terms of Service. We will challenge overbroad or improper requests where we believe doing so is appropriate.

05Legal basis for processing

Under the DPDP Act 2023 framework, we process personal data on the following bases:

  • Consent — for newsletter subscriptions, marketing communications, optional analytics cookies.
  • Performance of a contract — for delivering paid services, processing payments, issuing certificates.
  • Legitimate uses (DPDP §7) — for security incident response, fraud prevention, fulfilling legal obligations.
  • Compliance with law — for CERT-In log retention, IT Act obligations, lawful authority requests.

06Your rights as a Data Principal

You have the right to:

  • Access your personal data we hold
  • Correct or complete inaccurate data
  • Erase your data when no longer needed (subject to legal retention obligations)
  • Withdraw consent at any time, as easily as you gave it
  • Nominate another person to exercise your rights in case of death or incapacity
  • Grievance redressal by contacting our DPO at [email protected]
  • Escalate to the Data Protection Board of India if your grievance is not resolved within 14 days

To exercise any right, email [email protected] with subject "DPDP Rights Request" and your registered email address. We will respond within 14 working days. We may verify your identity before fulfilling sensitive requests (e.g. account deletion).

07How we protect your data

  • Encryption in transit — TLS 1.2+ on all site connections, HSTS enabled.
  • Encryption at rest — database credentials and sensitive fields encrypted; backups encrypted.
  • Access control — admin accounts protected with strong passwords and MFA; access reviewed quarterly.
  • Security headers — Content-Security-Policy, X-Frame-Options, Permissions-Policy, Referrer-Policy enforced.
  • WAF & DDoS — Cloudflare WAF with managed rules; Wordfence intrusion-prevention behind it.
  • Logging & monitoring — security events logged and reviewed; alerts configured for anomalous activity.
  • Patching — WordPress core, theme, and plugins updated promptly after security releases.
  • Incident response — documented runbook with CERT-In notification template (6-hour reporting window).

No system is 100% secure. We will notify you and the relevant authority within the timelines required by law if a breach affecting your data occurs.

08How long we keep your data

Data typeRetention
Account & profileUntil you delete your account; 30 days after for backups, then purged.
Course progress & certificatesLifetime of account; certificates remain valid even after deletion (anonymised).
Payment records7 years (Income Tax Act, GST Act statutory retention).
Server access logs180 days (CERT-In Direction April 2022).
Email correspondence3 years from last contact, unless required by ongoing legal matter.
Forum postsPublic, retained while forum is active. You can delete your own posts.
Marketing consentUntil you withdraw; record of withdrawal kept 3 years.

09Cookies

RingSafe uses essential, functional, and analytics cookies. We do not use advertising or behavioural-tracking cookies. Read the full Cookie Policy for category breakdowns and how to manage them.

10Cross-border transfers

RingSafe servers and databases are located in India. Some service providers we use (Cloudflare, Google Analytics, Google OAuth) may process data outside India in the course of their service. We rely on:

  • Standard contractual terms with each provider
  • Each provider's published data-protection commitments (GDPR, SOC 2, ISO 27001)
  • The DPDP §16 framework for permitted cross-border transfers

Payment data handled by Razorpay is processed and stored in India per RBI's payment-data localisation directive (April 2018).

11Children's data

RingSafe is intended for users aged 18 and above. We do not knowingly collect personal data from anyone under 18. We do not run targeted advertising or behavioural monitoring. If we discover that we have collected data from a minor, we will delete it promptly. Parents or guardians who believe their child has provided us data may contact [email protected].

12Changes to this policy

We update this policy whenever our practices, providers, or applicable law materially change. The latest version is always available at ringsafe.in/privacy-policy. The "Last updated" date at the top reflects the most recent change. Substantive changes will be flagged in the page header for at least 30 days. We will email registered users where the change materially affects them.

13Contact us

For any privacy question, request, or grievance:

  • Email — [email protected]
  • Subject line — "Privacy Request" (for fastest routing)
  • Postal — RingSafe, India (full address provided on request)
  • Response time — 14 working days

If you are not satisfied with our response, you may escalate to the Data Protection Board of India under the DPDP Act once the Board is operationalised.

Privacy Question?

We respond within 14 working days

Email us with subject "Privacy Request" — we read every message and respond personally, not via automated bot.

Email [email protected]
RingSafe Cybersecurity for INDIA

An offensive-security partner & academy for Indian startups, SMEs and enterprises that ship fast and need a defender who thinks like the other side.

[email protected] India · serving globally

Services

  • vAPT
  • Cloud Security
  • DPDP Compliance
  • Incident Response
  • Case Studies
  • All Services

Learning

  • Academy Hub
  • All Modules
  • AI Practitioner Path
  • Skill Map
  • Certification Guide

Resources

  • Free Tools
  • Templates
  • VAPT Scope Calculator
  • DPDP Assessment
  • DPDP Penalty Calc

Company

  • About
  • Contact
  • Blog
  • News
  • Community
  • Verify a certificate

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Acceptable Use
© 2026 RingSafe (Ring Safe Cybersecurity). All rights reserved. Cybersecurity consulting · VAPT · DPDP advisory · India
● RingSafe

Hands-on
cybersecurity for India.

  • 🎓 396 free academy modules · 18 tracks
  • 🏆 Verifiable LinkedIn-shareable certificates
  • 🛠 50+ hacking-tool guides + interactive CTFs
  • ⚖ India-context: DPDP, RBI, SEBI, CERT-In
100% free · no card required

Welcome back.

Pick up where you left off — track progress across 396 modules, claim shareable certificates, and get the weekly threat-intel digest.

Continue with Google
or use email
Forgot?

By continuing, you agree to RingSafe's Terms and Privacy Policy.

New here? Create a free account → Already a member? Sign in →