Privacy Policy
Bryte Guard Force Pvt Ltd · Last updated 30 September 2026
1. Who we are
Bryte Guard Force Pvt Ltd (“Bryte”, “we”, “us”) is a PSARA-licensed security and facility management company operating in Maharashtra, India. We operate the website brytegf.com.
Registered office: Ambience Park, Sector 19A, Vashi, Navi Mumbai, Maharashtra 400703.
Email: care@brytegf.com · Phone: +91 86523 45610
For the purposes of the Digital Personal Data Protection Act, 2023, we are the data fiduciary for the personal data described in this policy. That means we decide why and how your data is used, and we are accountable for it.
Who this policy covers
This policy applies to everyone whose personal data we handle in our own right: visitors to this website, people who enquire about our services, our clients and their staff, our suppliers and sub-contractors, job applicants, and our own employees and guards. Two groups are dealt with by separate documents because their data is different in kind — our staff, by the notice described in section 12, and visitors to our clients’ premises, as section 13 explains.
2. What we collect
When you contact us about security or facility services
Our enquiry forms, our quote form and our cost calculator ask for:
- Your name
- Your phone number
- Your email address
- Your company, society or site name, and its city
- What you need — the type of site, the number of guards or staff, and any details you choose to write in the message field
If you contact us through an advertisement on Instagram or Facebook, the form opens inside that app and your name, phone number and email may be filled in automatically from your account. You can edit them before you submit, and the form is only sent to us when you choose to submit it.
When you call or message us
If you call the number on this site, or start a WhatsApp conversation with us, we keep a record of the conversation and the details you give us, so that we can follow up on your enquiry.
When you subscribe to updates
Our newsletter form collects your email address only.
When you simply visit the website
Like almost every website, ours records technical information automatically: your IP address, browser and device type, the pages you viewed, how you arrived at the site, and the date and time. This is described in section 5.
We do not ask for, and you should never send us, sensitive information such as bank or card details, Aadhaar or PAN numbers, or passwords, through any form or message on this website.
3. Why we collect it
| What we do with it | Why |
|---|---|
| Call or email you back about your enquiry, and arrange a free site assessment | This is the reason you contacted us, and it is what the form says will happen |
| Prepare a written proposal and quotation for your site | To give you the pricing you asked for |
| Keep a record of the enquiry and our correspondence | To serve you properly if you contact us again, and to meet our own record-keeping and tax obligations |
| Send you service updates if you have subscribed | With your consent, which you may withdraw at any time |
| Understand which pages and advertisements bring genuine enquiries | To improve the website and to spend our advertising budget sensibly. See sections 5 and 6 |
We do not sell your personal data, and we do not rent or trade enquiry lists. We do not use your enquiry details to advertise anything other than our own services.
4. Your consent
When you submit an enquiry form, you are consenting to us using the details in that form to respond to you, as described in section 3. We ask for your data for a specific purpose, and we use it for that purpose.
We do not pre-tick consent boxes, and we do not treat the mere act of browsing this website as consent to anything beyond what is necessary to show you the page.
You can withdraw your consent at any time — one line to care@brytegf.com with “Withdraw consent” in the subject will do it, and withdrawing must be as easy as giving it was. Withdrawing consent does not undo anything already done lawfully while it was in force, and we may still need to keep some records for the periods described in section 8.
5. Cookies and tracking
This website uses cookies and similar technologies. Some are needed for the site to work at all; others help us measure how the site and our advertising are performing.
| Kind | What it does |
|---|---|
| Necessary | Keeps the site working — remembers form state, keeps pages loading quickly, and protects our forms against automated abuse. The site cannot function without these. |
| Measurement | Counts visits and pages viewed, and records when an enquiry form is successfully sent, or when someone taps our phone number or WhatsApp link. This tells us which pages produce enquiries. We manage these through Google Tag Manager. |
| Advertising | Lets Google and Meta report which of their advertisements led to an enquiry, and lets us show our advertisements to people who have visited this website. See section 6. |
The cookies this website actually sets
Rather than describe cookies in the abstract, here is what a visit to brytegf.com places on your device today. Durations are those set by the provider and can change.
| Name | Set by | What it does | Kind | Typical life |
|---|---|---|---|---|
_ga | Google Analytics | Distinguishes one visitor from another so that visits can be counted | Measurement | 2 years |
_ga_<ID> | Google Analytics | Keeps the state of your session for the specific analytics property | Measurement | 2 years |
_gcl_au | Google Ads | Records that a visit followed an advertisement, so that an enquiry can be attributed to it | Advertising | 90 days |
_fbp | Meta | Identifies your browser to Meta so that our advertising can be measured and shown to you again | Advertising | 3 months |
litespeed_qc_hide_banner | This website | Remembers that a notice from our caching system has been dismissed | Necessary | Short-lived |
wp-settings-* | This website | Remembers screen preferences. Set only for people who log in to administer the site, not for ordinary visitors | Necessary | 1 year |
You can block or delete cookies in your browser settings at any time. If you block measurement and advertising cookies, the site will still work normally; we will simply have less information about how it is performing.
6. Advertising
We advertise our services on Google Search and on Instagram and Facebook. To know whether that advertising works, we use two measurement tools on this website:
- Google Ads conversion tracking. When you successfully send an enquiry form, or tap our phone number or WhatsApp link, this records that an enquiry happened. It tells us that an advertisement worked; it does not send Google the contents of your enquiry.
- The Meta pixel. This does the same for our Instagram and Facebook advertising. It also allows us to show our advertisements to people who have visited this website, and to ask Meta to find people similar to our visitors.
What remarketing means in practice
“Remarketing” is the reason you may see a Bryte advertisement after visiting this website. So that you know what it involves:
- When a page on this site loads, these tools set a small identifier in your browser and send Google and Meta the address of the page, your IP address, and your browser and device type.
- If you are signed in to Google, Facebook or Instagram on the same device, those companies can connect the visit to your account. This is what allows them to show you our advertisement later, and it means the visit is not anonymous to them.
- We can then ask Google or Meta to show our advertisements to people who visited this website. We never see the list of who those people are, and we cannot pick you out of it — we set the rule, the platform shows the advertisement.
- We also ask them to report how many enquiries an advertisement produced. That report is a count; it does not carry what you wrote in the form.
What Google and Meta require us to tell you
Using these tools obliges us to disclose the following, and we would rather do it here than in small print:
- We use Google Analytics and have enabled its advertising features, which is what allows remarketing audiences and demographic reporting. You can read how Google uses data when you use its partners’ sites or apps.
- These features work by combining our own first-party cookie — the Google Analytics cookie set by this site — with Google’s third-party advertising cookies. Neither alone would let an advertisement follow you; together they do.
- We never send Google or Meta anything that identifies you personally — no name, email address or phone number, hashed or otherwise — through these tags. What you type into an enquiry form stays with us.
- Meta and other companies may collect information through pixels and similar technologies on the pages of this site, and use it for measurement, advertising targeting and delivery.
How to stop it
- Change your settings at Google Ads settings and Meta ad preferences.
- Block or delete cookies in your browser, or use its private browsing mode. This is the most direct control, and it works today.
- Install the Google Analytics opt-out add-on.
- Use the industry opt-out pages at optout.aboutads.info, optout.networkadvertising.org or youronlinechoices.eu.
Google and Meta process this information under their own privacy policies, and as independent controllers of the data they hold about you: Google Privacy Policy · Meta Privacy Policy.
If you submit an enquiry through a form inside Instagram or Facebook, Meta passes the details of that form to us, and we then use them as described in section 3. Meta also keeps a copy under its own policy.
7. Who your data goes to
Two very different things get called “sharing”, and it matters which is which.
We do not sell, rent or trade your data
We do not sell your personal data. We do not sell, rent or trade enquiry lists. We do not pass your enquiry to other security agencies, franchise partners, lead brokers or marketing companies. Nobody receives your enquiry to use for their own business.
Service providers who work on our instructions
We use outside services to run the business, and your data passes through them. They may only use it to provide that service to us, they may not use it for their own purposes, and each is bound by a contract that requires this. Under the Digital Personal Data Protection Act they are data processors, and we remain accountable for what they do with your data. They are:
- Our customer relationship management (CRM) system, where enquiries are recorded and tracked so that we can follow them up, prepare proposals and keep a history of our dealings with you
- Our proposal and document tools, used to prepare and send quotations to you
- Our website host, which serves this website and stores form submissions in transit
- Our email provider, through which enquiry notifications and our replies to you are sent and stored
- Our telephony provider, where calls or SMS to and from our business numbers are handled
Advertising and measurement companies
This is a genuine disclosure to third parties, and we would rather state it plainly than bury it. Our website sends information about your visit to Google and Meta (Facebook and Instagram) so that we can measure our advertising and show our advertisements to people who have visited this site. Unlike the providers above, these companies also use the data for their own purposes, under their own privacy policies. Section 6 explains exactly what is sent and how to stop it.
Where the law requires it
- Authorities — where we are required to disclose information by law, by a court, or by a lawful request from a government authority, including under the Private Security Agencies (Regulation) Act
- A buyer or successor — if the business or part of it is ever sold or reorganised, your data may transfer with it, under the same protections as this policy
7a. Processing outside India
Some of the services described above operate from outside India, so your personal data may be stored or processed outside India. Where that is the case we use services that are permitted under applicable Indian law, and we require them by contract to protect your data to the standard set out in this policy.
8. How long we keep it
| What | How long |
|---|---|
| An enquiry that does not become a contract | 24 months from your last contact with us, then deleted |
| Client records, contracts, invoices | For the length of the contract, and afterwards for as long as tax, company and PSARA record-keeping law requires |
| Newsletter subscription | Until you unsubscribe |
| Job applications | See section 13 |
| Website measurement data | For the retention period set by the tool concerned, which is typically no more than 26 months |
Two things the law does to this table. It sets a minimum — records of processing and their logs must be kept for at least a year — so we cannot delete everything the moment you ask. And it lets us keep what another law requires, which for a licensed security agency means the record-keeping that private security, labour and tax law impose. Where we decline an erasure request, we will tell you which of those applies.
9. How we protect it
We take reasonable security safeguards to protect personal data against loss, unauthorised access and misuse. These include encrypted connections to this website, access limited to staff who need it, and accounts protected by passwords and, where available, two-step verification.
Where the law requires us to keep a record of processing and its logs for a minimum period — currently one year — we do, even where you have asked us to erase something. We will tell you when that applies.
If a breach happens
Indian law sets no minimum severity for reporting a personal data breach. We will tell you without delay, in plain language: what happened and when, what it means for you, what we have done, what you can do to protect yourself, and who to speak to. We will tell the Data Protection Board of India without delay and give it a full report within 72 hours, and we will report to CERT-In within 6 hours where the incident falls under its directions.
No method of transmission or storage is completely secure, and we would rather tell you what we will do about a failure than promise it cannot happen.
Telling us about a problem
If you believe data of yours has been exposed, or you spot a weakness in this website, write to care@brytegf.com with “Security” in the subject line. We will look into it and tell you what we find. Please do not test or exploit anything you find.
10. Your rights
Under the Digital Personal Data Protection Act, 2023, you have the right to:
- Access a summary of the personal data we hold about you and how we are using it
- Be told who else has had it — the service providers and other companies we shared it with, and what was shared. One exception the law allows: we may be unable to tell you about a disclosure to an authority that requested it in writing for the prevention, detection or investigation of an offence or a cyber incident
- Correction of data that is inaccurate or incomplete, and updating of data that has changed
- Erasure of your data, where we no longer need it for the purpose you gave it for and no law requires us to keep it
- Withdraw consent at any time, and it must be as easy as giving it was. If you consented by ticking a box, one line to care@brytegf.com with “Withdraw consent” in the subject is enough — we will not ask you for a letter or a visit
- Grievance redressal — to complain to us first, through the officer named in section 11
- Nominate another person to exercise these rights on your behalf in the event of your death or incapacity
To exercise any of these rights, write to our grievance officer. We will acknowledge within 2 working days and answer within one month — the period the Information Technology Rules 2011 require of us today, and shorter than the ninety days the Digital Personal Data Protection Rules allow. We may need to verify your identity first, so that we do not disclose your data to someone else.
10a. What the law asks of you
The Act gives you rights and also places a few duties on you. In plain terms: give us information that is true, do not impersonate anyone else when you use our forms, and do not raise a complaint you know to be false. If you ask us to correct something, give us enough detail to act on.
10b. If we cannot agree
If you are not satisfied with our response, please tell our grievance officer and we will try again — the law asks you to exhaust our own grievance route first. Failing that, you may complain to the Data Protection Board of India, and the parties may also agree to mediation under the Digital Personal Data Protection Act, 2023 and the Mediation Act, 2023.
11. Grievance officer
For any question or complaint about your personal data:
Jaspreet Singh Bhagtana
Grievance Officer
Bryte Guard Force Pvt Ltd
Email: care@brytegf.com
Phone: +91 86523 45610
Address: Ambience Park, Sector 19A, Vashi, Navi Mumbai, Maharashtra 400703
Hours: Monday to Saturday, 10:00 AM to 6:00 PM
12. Our guards and employees
Most of the personal data we hold is not about website visitors at all — it is about the people who work for us. To employ and deploy licensed security staff we hold identity and address documents, photographs, character and antecedent verification records, medical fitness, training records, attendance, bank and statutory numbers, and next-of-kin details. At sites that use biometric attendance or biometric access control we also hold biometric data for the staff posted there.
Because that data concerns our own staff rather than visitors to this website, it is governed by a separate privacy notice issued to every employee when they join, which sets out each category, why we need it, how long we keep it and what choices they have. A copy is available to any employee or applicant from the grievance officer named in section 11.
Aadhaar
Where we accept Aadhaar as proof of identity and address, we accept it as a document only. We do not use Aadhaar to authenticate anyone against the UIDAI database, we do not use it as a customer or employee identifier in our systems, and we do not disclose it to clients or to anyone else except where a law requires it. Other identity documents are accepted instead.
13. Data we handle at our clients’ sites
When our staff work at a client’s premises, they handle personal data that belongs to that client’s operation, not to ours. Typically this means:
- Visitor registers. Our guards record visitors at gates and receptions, in the client’s register, according to the client’s protocol. The register stays at the site and belongs to the client.
- Access control and attendance systems operated by the client, including biometric systems where the client uses them.
- Closed-circuit television, where our staff are posted to observe the client’s cameras.
- Incident and occurrence records made at the site, which may name people involved in an incident.
For all of this, the client is the data fiduciary and we act as a data processor on the client’s instructions. The client decides what is collected and why, and is responsible for the notices and consents given to the people concerned. We use this data only to perform the security service the client has engaged us for; we do not copy it into our own systems, use it for our own purposes, or use it for marketing. Our agreements with clients set this out in writing.
If you are a visitor to a site we guard and you have a question about a register or a camera there, the quickest route is the owner or manager of that site. You are also welcome to contact our grievance officer, who will put you in touch with the right person.
14. No automated decision-making
We do not make decisions about you by automated means alone, and we do not profile you to predict your behaviour. A person reads every enquiry and a person decides every quotation.
15. Links to other websites
This website links to other sites, including our own social media pages and the policies of the companies named in section 6. We are not responsible for the privacy practices of sites we do not operate, and we suggest you read their policies before giving them your data.
16. Language
This policy is published in English. Under the Digital Personal Data Protection Act you may ask for the notice in Hindi, Marathi or any other language listed in the Eighth Schedule to the Constitution. Write to our grievance officer and we will provide it.
17. Children
Our services are sold to companies, housing societies and other organisations, and this website is not directed at children. We do not knowingly collect personal data of anyone under 18. If you believe a child has given us personal data, write to our grievance officer and we will delete it.
18. Job applicants
If you apply for a job through our careers page, we collect the name, contact details, role, city and experience you provide, and use them only to consider your application and contact you about it. We do not use job applications for marketing.
If we take your application forward we will ask for more: identity and address documents, previous employment details, and the character and antecedent verification that licensed security work requires by law. We will tell you what is needed at that point, and the separate staff privacy notice described in section 12 explains how each category is handled.
Because security work is a licensed activity, engagement is subject to identity and background verification as required by law. We will tell you what is needed before any verification is carried out.
We keep applications for 12 months so that we can consider you for later openings, unless you ask us to delete them sooner.
19. Changes to this policy
We may update this policy as our services or the law change. The date at the top shows when it was last updated. If a change materially affects how we use your data, we will take reasonable steps to bring it to your attention.
20. Contact us
Bryte Guard Force Pvt Ltd
Ambience Park, Sector 19A, Vashi, Navi Mumbai, Maharashtra 400703
Email: care@brytegf.com · Phone: +91 86523 45610
Monday to Saturday, 10:00 AM to 6:00 PM
