Confidentiality & Data-Handling Notice
Effective Date: 7 October 2026
Version: 1.0
Confidentiality by Default
Information received or generated in connection with an SPYTIK inquiry or engagement is treated as confidential unless disclosure is authorised or legally required.
Need-to-Know Access
Access to client, subject and case information is limited to persons or service providers who require the information for an authorised operational purpose.
Case Separation
Case information should be maintained separately and associated with the relevant inquiry or engagement to reduce accidental disclosure or cross-case contamination.
Evidence and Source Discipline
SPYTIK distinguishes, where relevant, between client-supplied information, independently obtained information, documentary evidence, reported information, analytical assessment and unresolved information.
Lawful Collection
SPYTIK does not use hacking, password theft, credential misuse, unauthorized access to accounts or devices, unlawful interception, or impersonation for unauthorized access. Collection activity must remain within the defined lawful scope.
Client Responsibilities
Clients should provide information they are lawfully entitled to provide and must not instruct SPYTIK to obtain information through unlawful means.
External Investigators and Vendors
Where external investigators or vendors are required, only information reasonably necessary for the assigned task should be shared, with appropriate confidentiality and security expectations.
Reports and Deliverables
Reports and other deliverables are provided to the authorised client or recipient. Recipients are responsible for protecting copies they receive.
Exceptions
Confidentiality may be limited where disclosure is required by law, court or lawful government process, necessary to protect legal rights or prevent serious harm, or otherwise required by a legal or professional obligation.
Data Minimisation and Retention
SPYTIK aims to collect and retain only information reasonably necessary for the defined purpose, engagement, legal requirement or evidentiary need.
Security and Incidents
Reasonable administrative, technical and organisational safeguards should be used to protect confidential information. Suspected loss, unauthorised access or disclosure should be escalated promptly.
Advertising Firewall
Confidential inquiry and case data is operational information, not advertising audience data. SPYTIK will not intentionally use confidential case narratives, findings, subject identities, client contact details or similar case information to construct advertising audiences.
Contact
Privacy and confidentiality queries: inquire@spytik.in.
Legal status: This operational notice should be independently reviewed by qualified Indian legal counsel and converted into binding contractual and internal SOP language where required.