Skip to content
Talk to a Security Expert
TMG SECURITY · LEGAL

Privacy Policy

Your privacy matters. This policy explains how TMG Security collects, uses, protects, and manages information when you interact with our website, services, resources, training programs, and digital platforms.

EFFECTIVE DATE  TO BE CONFIRMED LAST UPDATED  TO BE CONFIRMED
ACCESS CONTROLENCRYPTIONRETENTIONMINIMISATIONYOUR RIGHTSTRANSPARENCY
00

Introduction

TMG Security (“TMG Security”, “TMG”, “we”, “us”, or “our”) respects the privacy of individuals who visit our website, communicate with us, use our services, access our resources, submit enquiries, participate in our training and educational programs, or otherwise interact with us.

This Privacy Policy explains how TMG Security collects, uses, stores, protects, discloses, and otherwise processes personal information and other information obtained through our website, digital platforms, communication channels, and related services.

By accessing or using our website, submitting information through our forms, subscribing to our communications, requesting information about our services, or otherwise interacting with TMG Security, you acknowledge that you have read and understood this Privacy Policy.

If you do not agree with the practices described in this Privacy Policy, please discontinue use of the relevant website or service.

01

About TMG Security

TMG Security is a cybersecurity company providing cybersecurity services, security consulting, professional training, cybersecurity education, research, security resources, and related technology and security solutions.

For purposes of this Privacy Policy, TMG Security may operate through or in connection with its business operations in India and the United States.

Our contact details

UNITED STATES OFFICE
117 South Lexington Street STE 100
Harrisonville, MO 64701
United States
INDIA OFFICE
3rd Floor, Centre 2, SCO 250 & 251
Gmada Aerocity
Mohali, Punjab 140306
India

For privacy-related requests, users may contact us using the details above and identify the request as a “Privacy Request.”

02

Scope of This Privacy Policy

This Privacy Policy applies to information collected through or in connection with:

  • TMG Security's primary website
  • service and solution pages
  • cybersecurity service enquiries
  • contact and consultation forms
  • corporate training enquiries
  • TMG-Aegis enquiries
  • TMG Labs access requests
  • research and security resources
  • technical articles and security advisories
  • newsletter or resource subscriptions
  • communications with TMG Security
  • recruitment or partnership enquiries where applicable
  • online educational and training-related interactions where this website collects information
  • other digital services or websites that expressly link to this Privacy Policy

This Privacy Policy does not automatically apply to third-party websites, platforms, educational portals, payment providers, or services operated independently by other organizations.

03

Information We Collect

Depending on how you interact with TMG Security, we may collect different categories of information.

We seek to collect only information that is reasonably necessary for the relevant purpose.

3.1 Information you provide directly

You may voluntarily provide:

  • full name
  • business email address
  • personal email address where voluntarily provided
  • company or organization name
  • job title or professional role
  • telephone number
  • country or region
  • service of interest
  • training requirement
  • laboratory or research interest
  • message or enquiry details
  • information included in uploaded documents, where uploads are enabled
  • communication preferences
  • other information you voluntarily provide
04

Information Collected Automatically

When you visit our website, certain technical information may be collected automatically.

This may include:

  • IP address or network information
  • browser type
  • browser version
  • operating system
  • device type
  • screen resolution
  • language preferences
  • approximate geographic information
  • referring website
  • pages visited
  • time spent on pages
  • navigation paths
  • interaction with website elements
  • date and time of access
  • website performance information
  • error information
  • security-related logs
  • similar technical information

Some information may be collected through standard web server logs, cookies, analytics technologies, security controls, or similar technologies.

05

Google Analytics

TMG Security uses Google Analytics / Google Analytics 4 (GA4) to understand how visitors interact with our website and to improve website content, usability, performance, and marketing effectiveness.

Google Analytics may collect information such as:

  • pages viewed
  • events and interactions
  • approximate geographic information
  • device information
  • browser information
  • traffic source
  • referral information
  • website usage patterns
  • engagement information
  • other measurement information configured within our Analytics property

TMG Security may configure Google Analytics privacy and data-retention settings based on operational, legal, and compliance requirements.

We do not intentionally use Google Analytics to collect:

  • passwords
  • authentication credentials
  • payment card information
  • private encryption keys
  • information that should not be included in analytics events or URLs

We seek to avoid transmitting personal information to Google Analytics through custom event parameters, page URLs, or other analytics fields.

06

How We Use Google Analytics

We may use Analytics information to:

  • understand website traffic
  • identify popular content
  • understand visitor navigation
  • improve website design
  • improve page performance
  • identify usability issues
  • measure engagement
  • understand marketing campaign performance
  • evaluate services or resources generating interest
  • improve security resources
  • develop future content
  • understand general audience trends
07

Cookies and Similar Technologies

TMG Security may use:

  • cookies
  • local storage
  • pixels
  • tags
  • scripts
  • similar technologies

These may be used for:

Essential functionality

  • website functionality
  • navigation
  • forms
  • security
  • abuse prevention

Analytics

  • traffic measurement
  • engagement measurement
  • website improvement

Preferences

  • user preferences
  • interface settings
  • accessibility preferences
  • functionality-related choices
08

Managing Cookies

Depending on your browser, device, and geographic location, you may be able to:

  • block cookies
  • delete cookies
  • restrict certain technologies
  • configure browser privacy settings
  • use privacy-enhancing browser features

Blocking certain cookies or technologies may affect website functionality.

Where legally required, TMG Security may implement mechanisms allowing users to manage or provide consent for certain non-essential cookies and analytics technologies.

09

Information from Contact Forms

When you submit a contact form, we may collect:

  • name
  • email address
  • company
  • phone number
  • selected service
  • enquiry details
  • page or source from which the enquiry originated
  • laboratory or product context where applicable
  • relevant technical metadata

We use this information to:

  • respond to your enquiry
  • communicate with you
  • understand your requirements
  • provide requested information
  • prepare proposals
  • arrange consultations
  • provide cybersecurity services
  • provide corporate training information
  • process product or solution enquiries
  • maintain appropriate business records
10

Corporate Training Enquiries

If you request corporate cybersecurity training information, we may collect:

  • name
  • business email
  • company
  • job title
  • telephone number
  • approximate organization size
  • training requirements
  • preferred training topics
  • number of participants
  • preferred training format
  • other voluntarily provided information

We use this information to understand your training requirements and communicate appropriate training options.

11

TMG-Aegis Enquiries

If you submit an enquiry regarding TMG-Aegis or another TMG Security solution, we may collect:

  • name
  • company
  • professional email
  • job title
  • organization type
  • security requirements
  • product interest
  • technical requirements
  • additional voluntarily provided information

We use this information to:

  • respond to product enquiries
  • arrange demonstrations
  • understand technical requirements
  • provide product information
  • communicate product availability
  • support legitimate business development activities
12

TMG Labs Access Requests

Certain TMG Labs may require users to submit a request before accessing a laboratory or research environment.

Where applicable, requests may relate to:

  • TMG AI Security Lab
  • TMG Vulnerable Web Application Lab
  • TMG Vulnerable API Lab
  • TMG Application Security Lab
  • other TMG research or training environments

We use this information to process access requests and communicate with requesters.

13

Resource and Newsletter Subscriptions

If you subscribe to TMG Security resources, newsletters, technical updates, research reports, security advisories, or similar communications, we may collect:

  • email address
  • name where provided
  • subscription preferences
  • source of subscription
  • communication interaction information

You may unsubscribe from marketing or newsletter communications at any time.

14

Business Communications

When you communicate with TMG Security through email, telephone, website forms, or other channels, we may retain relevant communications for legitimate business purposes.

This may include:

  • correspondence
  • enquiries
  • proposals
  • service discussions
  • training discussions
  • support requests
  • partnership communications
  • other business communications
15

How We Use Personal Information

We may use personal information for:

Providing services

  • responding to enquiries
  • providing cybersecurity services
  • performing security assessments
  • providing consulting
  • providing training
  • supporting customers
  • managing projects

Business operations

  • managing relationships
  • maintaining business records
  • managing enquiries
  • processing proposals
  • coordinating projects
  • improving operations
  • business communication

Website improvement

  • improving content
  • improving usability
  • understanding traffic
  • troubleshooting
  • improving performance
  • developing resources

Security

  • protecting our website
  • preventing abuse
  • detecting malicious activity
  • investigating suspicious activity
  • protecting systems
  • enforcing security controls
  • maintaining website integrity

Communications

  • responding to enquiries
  • sending requested information
  • providing service updates
  • sending relevant resources
  • communicating about training
  • providing marketing communications where permitted
16

Legal Bases for Processing

Where applicable, TMG Security may process personal information based on:

  • consent
  • performance of a contract
  • steps requested before entering into a contract
  • legitimate business interests
  • compliance with legal obligations
  • protection of systems and individuals
  • responding to requests
  • other lawful grounds under applicable law
17

India — Data Protection

TMG Security operates in India and may process personal data relating to individuals in India.

Our privacy practices are intended to take applicable Indian data-protection requirements into account, including the Digital Personal Data Protection Act, 2023, to the extent applicable to the relevant processing activities and provisions in force.

Where applicable, TMG Security will process personal data in accordance with applicable legal requirements.

18

International Users

TMG Security may provide services to customers and visitors located in multiple countries.

Personal information may therefore be processed in jurisdictions other than the country where you reside.

Depending on services used, information may be processed in India, the United States, or other jurisdictions where TMG Security or service providers operate.

Where applicable, we seek to use appropriate contractual, organizational, and technical safeguards for international data transfers.

19

European Economic Area, United Kingdom and Switzerland

If you are located in the EEA, UK, or Switzerland, additional privacy rights may apply depending on the circumstances.

These may include:

  • access
  • correction
  • deletion
  • restriction
  • objection
  • data portability
  • withdrawal of consent
  • complaint to a supervisory authority

Where GDPR or similar laws apply, TMG Security will seek to provide the rights and protections required by those laws.

20

Data Sharing

TMG Security does not sell personal information as a general business practice.

We may share information with selected third parties where reasonably necessary for legitimate business purposes.

These may include:

Service providers

  • hosting providers
  • email infrastructure providers
  • analytics providers
  • security providers
  • cloud infrastructure providers
  • communication platforms
  • database providers
  • professional service providers

Business partners

Where necessary to provide requested services or fulfill legitimate business purposes.

Legal and regulatory authorities

Where disclosure is:

  • required by law
  • necessary to comply with legal process
  • necessary to protect rights or safety
  • otherwise legally permitted

Business transactions

Personal information may be transferred as part of:

  • merger
  • acquisition
  • restructuring
  • financing
  • sale of assets
  • similar corporate transaction
21

Data Security

TMG Security takes reasonable technical and organizational measures designed to protect personal information against:

  • unauthorized access
  • unauthorized disclosure
  • alteration
  • misuse
  • accidental loss
  • destruction
  • unauthorized processing

Security measures may include:

  • access controls
  • encryption where appropriate
  • secure communications
  • server security
  • authentication controls
  • logging
  • monitoring
  • vulnerability management
  • security testing
  • administrative controls
22

Security Incidents and Data Breaches

If TMG Security becomes aware of a personal data incident affecting information under our control, we will assess the incident and take appropriate steps based on:

  • nature of the incident
  • affected information
  • applicable legal requirements
  • potential impact
  • security considerations
  • notification obligations

Where legally required, we may notify affected individuals, regulators, authorities, or other relevant parties.

23

Data Retention

We retain personal information only for as long as reasonably necessary for purposes including:

  • responding to enquiries
  • providing services
  • maintaining business relationships
  • complying with legal requirements
  • resolving disputes
  • enforcing agreements
  • maintaining security records
  • legitimate business purposes

When information is no longer required, we may:

  • delete it
  • anonymize it
  • aggregate it
  • securely archive it where legally appropriate
24

Your Privacy Rights

Depending on your location and applicable law, you may have rights including:

  • right to know what personal information is processed
  • right to access personal information
  • right to correct inaccurate information
  • right to request deletion
  • right to withdraw consent where applicable
  • right to object to certain processing
  • right to restrict processing
  • right to data portability where applicable
  • right to opt out of marketing communications
  • right to request information about data sharing
  • right to lodge a complaint with an appropriate authority
25

How to Exercise Your Rights

Contact TMG Security using the details below and mark your message “Privacy Request — TMG Security”.

EMAIL [email protected] PHONE +91 6283538660 SUBJECT Privacy Request — TMG Security

We may request additional information to verify identity and prevent unauthorized disclosure.

26

Marketing Communications

Where permitted by applicable law, TMG Security may send information about:

  • cybersecurity services
  • training programs
  • security research
  • technical resources
  • webinars
  • workshops
  • educational programs
  • product updates
  • relevant TMG Security activities

You may unsubscribe from marketing emails at any time.

Unsubscribing from marketing communications does not necessarily prevent essential transactional or service-related communications.

27

Children's Privacy

Our primary services and professional cybersecurity offerings are intended for businesses, professionals, organizations, and individuals capable of entering into applicable agreements.

We do not knowingly seek to collect personal information from children through our professional cybersecurity website.

If you believe a child has provided personal information to us without appropriate authorization, contact us so we can investigate.

28

Third-Party Websites

Our website may contain links to:

  • educational platforms
  • course platforms
  • university websites
  • social media
  • technology providers
  • research resources
  • partner organizations
  • other external websites

When you leave our website, this Privacy Policy may no longer apply.

We are not responsible for the privacy practices, content, security, or policies of third-party websites.

29

Social Media

TMG Security may maintain profiles or pages on third-party social media platforms.

Interactions with those platforms may be governed by their respective privacy policies.

Information publicly posted on social media platforms may be visible to others depending on privacy settings.

30

Business Information

If you interact with TMG Security on behalf of a company or organization, you represent that you have appropriate authority to provide business information.

Contact information associated with an individual may still constitute personal information.

31

Aggregated and Anonymized Information

TMG Security may create aggregated, statistical, or anonymized information from data collected through the website and services.

This may be used to:

  • understand trends
  • improve services
  • measure website performance
  • analyze resource popularity
  • improve training
  • conduct internal research
  • develop business strategies
32

Security Research Information

TMG Security operates cybersecurity research and educational initiatives.

If you voluntarily provide vulnerability information, security research, technical reports, proof-of-concept material, or similar information, please avoid unnecessary personal information.

Technical information may be processed for:

  • vulnerability analysis
  • security research
  • educational content
  • responsible disclosure
  • security testing
  • development of security resources
33

Do Not Submit Confidential Credentials

Do not submit through ordinary website forms:

  • passwords
  • API keys
  • access tokens
  • private keys
  • seed phrases
  • payment credentials
  • production database credentials
  • cloud credentials
  • authentication cookies
  • other secrets
34

Data Accuracy

We seek to maintain accurate personal information.

If you believe information we maintain about you is inaccurate or incomplete, contact us.

35

Automated Decision-Making

Unless expressly stated otherwise for a particular service, TMG Security does not intend to make decisions producing significant legal or similarly significant effects about individuals solely through automated processing based on information collected through this website.

36

Do-Not-Track Signals

Some browsers offer “Do Not Track” or similar signals.

Because there is no universally consistent technical standard governing how websites should respond to every such signal, our website may not respond to every browser-level signal in the same manner.

Where applicable law requires a particular response, we will comply with relevant requirements.

37

Privacy of Client Information

Information provided to TMG Security in connection with cybersecurity engagements may be subject to additional contractual obligations, confidentiality agreements, statements of work, data-processing agreements, or other agreements.

Where a client agreement contains privacy or data-processing provisions that specifically govern certain information, those contractual terms may apply in addition to this Privacy Policy.

38

Confidential Security Information

Cybersecurity engagements may involve highly confidential information belonging to customers.

Such information may be governed by:

  • confidentiality agreements
  • NDAs
  • statements of work
  • security policies
  • contractual data-processing terms
  • applicable laws
39

Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect:

  • changes in our services
  • changes in our website
  • new technologies
  • changes in data-processing practices
  • changes in legal requirements
  • improvements to our privacy practices

When we make material changes, we may update the “Last Updated” date.

Where required by applicable law, we may provide additional notice.

40

Governing Law and Jurisdiction

This Privacy Policy is intended to operate across jurisdictions in which TMG Security conducts business.

Applicable law may vary depending on:

  • user's location
  • nature of relationship
  • service involved
  • location of processing
  • contractual arrangements
  • mandatory legal requirements

Nothing in this Privacy Policy is intended to exclude or limit rights that cannot lawfully be excluded or limited under applicable law.

41

Contact Us

UNITED STATES OFFICE
117 South Lexington Street STE 100
Harrisonville, MO 64701
United States
INDIA OFFICE
3rd Floor, Centre 2, SCO 250 & 251
Gmada Aerocity
Mohali, Punjab 140306
India

Privacy Requests: mark your message Privacy Request — TMG Security.

Questions about this policy?

Contact the TMG Security team and mark your message “Privacy Request — TMG Security”.