Privacy Policy
Effective Date: July 29, 2026 Last Updated: July 29, 2026
Who We Are
This Privacy Policy explains how CorpSecurity International collects, uses, stores, and protects your personal information when you access our website at https://corpsecurity.org or use any of our Services.
The Services are operated by two affiliated entities:
- LYL Corp International LLC, a limited liability company organized under the laws of the State of Delaware, USA (“LYL Corp”) — global brand and IP owner, responsible for membership data.
- CSS CorpSecuritySolutions Pvt Ltd, a private limited company incorporated under the Companies Act, 2013, in Hyderabad, Telangana, India (“CSS India”) — operational and support entity, responsible for processing training, examination, and customer support data.
Together referred to as “CorpSecurity International,” “we,” “us,” or “our.”
This Policy is incorporated by reference into our Terms of Use.
1. Information We Collect
1.1 Information You Provide Directly
- Account & Registration: Name, email address, country, professional details, and username when you create an account or become a member.
- Purchases & Payments: Name, billing address, and payment method details when you purchase a product, pay an Annual Maintenance Fee (AMF), or register for an event or examination. Payment card data is processed by our payment processor (Stripe) and is not stored by us.
- Certification & Examination: Professional credentials, work experience, and identification information submitted as part of certification applications or exam registrations.
- Communications: Any information you share when you contact our support team, submit feedback, or participate in surveys or forums.
1.2 Information We Collect Automatically
- Usage Data: Pages visited, time spent, links clicked, and actions taken on our website.
- Device & Technical Data: IP address, browser type, operating system, device identifiers, and referring URLs.
- Cookies & Tracking Technologies: We use cookies, pixel tags, and similar technologies to recognize your browser, remember preferences, and measure website performance. See Section 6 for details.
1.3 Information from Third Parties
- Payment Processors: Transaction confirmation and status from Stripe.
- Analytics Providers: Aggregated and anonymized usage data from services such as Google Analytics.
- Professional Networks: Where you connect a third-party account (e.g., LinkedIn) for profile verification, we may receive basic profile information you authorize.
2. How We Use Your Information
We use your personal information only for the following purposes:
- To deliver Services — processing your membership, AMF, exam registration, certification issuance, and training access.
- To manage your account — creating and maintaining your CorpSecurity International profile and certification records.
- To process payments — billing, invoicing, and managing auto-renewal of subscriptions through Stripe.
- To communicate with you — sending transactional emails (order confirmations, renewal reminders, exam results, certification notices) and, where you have opted in, newsletters or product updates.
- To provide support — responding to your queries, resolving disputes, and troubleshooting issues.
- To maintain certification integrity — verifying credentials, investigating false certification claims, and enforcing our Code of Professional Ethics.
- To improve our Services — analysing usage patterns, conducting research, and enhancing website functionality.
- To comply with legal obligations — meeting requirements under applicable law, including tax, accounting, and regulatory obligations.
We do not sell your personal information to third parties. We do not use your data for purposes incompatible with those listed above.
3. Legal Basis for Processing
For Users in the European Economic Area (EEA) and UK (GDPR)
We process your data on the following legal bases:
- Contract performance — to deliver the Services you have purchased or registered for.
- Legal obligation — to comply with applicable laws and regulations.
- Legitimate interests — to improve our Services, prevent fraud, and maintain certification integrity, where these interests are not overridden by your rights.
- Consent — for marketing communications and non-essential cookies, where required.
For Users in India (Digital Personal Data Protection Act, 2023)
CSS CorpSecuritySolutions Pvt Ltd acts as the Data Fiduciary for personal data processed in India. We process your data based on your consent and for the purposes of fulfilling our contractual obligations to you. You have the rights of a Data Principal as set out in Section 7 below.
For Users in California (CCPA/CPRA)
Please refer to Section 8 for your California-specific rights.
4. How We Share Your Information
We do not sell, rent, or trade your personal information. We share your data only in the following limited circumstances:
- Service Providers: We engage trusted third-party vendors (including Stripe for payments, email delivery platforms, and cloud hosting providers) who process data on our behalf under strict confidentiality obligations and only for the purposes we direct.
- Between our Entities: LYL Corp and CSS India share data internally as necessary to deliver the Services, manage memberships, and provide global support.
- Event Co-Sponsors: Where an event is co-hosted with a partner, we may share registrant information with that partner as disclosed at the time of registration.
- Legal Compliance: We may disclose information where required by law, court order, or to protect the rights, property, or safety of CorpSecurity International, our members, or the public.
- Business Transfer: In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to equivalent privacy protections.
5. Data Retention
We retain your personal information for as long as necessary to fulfil the purposes for which it was collected, including:
- Account data: For the duration of your membership plus 7 years thereafter for legal and accounting purposes.
- Certification records: Indefinitely, as certification history is a permanent credential record.
- Payment data: As required by applicable tax and financial regulations (typically 7 years).
- Support communications: 3 years from the date of last interaction.
- Marketing data: Until you withdraw consent or opt out.
When data is no longer required, we securely delete or anonymise it.
6. Cookies & Tracking Technologies
We use the following types of cookies on our website:
- Essential Cookies: Required for the website to function (login sessions, security, checkout). These cannot be disabled.
- Analytics Cookies: Help us understand how visitors use our site (e.g., Google Analytics). These are anonymised and aggregated.
- Preference Cookies: Remember your settings and preferences across sessions.
- Marketing Cookies: Used to measure the effectiveness of our advertising campaigns. These are only placed with your consent.
You can manage your cookie preferences through your browser settings or our cookie consent banner. Disabling non-essential cookies will not affect your ability to use core Services.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data, subject to our legal retention obligations.
- Portability: Request your data in a structured, machine-readable format.
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests or for direct marketing.
- Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior processing.
India (DPDP Act 2023): As a Data Principal, you have the right to access, correct, and erase your personal data, and to nominate a representative for data rights in the event of your death or incapacity.
To exercise any of these rights, contact us at support@corpsecurity.org. We will respond within the timeframe required by applicable law (generally 30 days). We may need to verify your identity before processing your request.
8. California Privacy Rights (CCPA/CPRA)
California residents have the right to:
- Know what personal information we collect, use, disclose, or sell.
- Request deletion of personal information we have collected.
- Opt out of the sale or sharing of personal information (we do not sell personal data).
- Non-discrimination for exercising your privacy rights.
- Correct inaccurate personal information.
- Limit the use of sensitive personal information.
To exercise your rights, contact us at support@corpsecurity.org, +1 302 244 7474 (US), or +91 90300 55542 (India). You may also contact the California Attorney General’s office or the California Privacy Protection Agency.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, loss, alteration, or disclosure. These include encrypted data transmission (SSL/TLS), access controls, and regular security assessments.
However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that affects your rights, we will notify you as required by applicable law.
10. Children’s Privacy
Our Services are not directed at individuals under the age of 18. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately at support@corpsecurity.org and we will delete it promptly.
11. International Data Transfers
Your personal information may be transferred to and processed in countries other than your country of residence, including India and the United States. Where such transfers occur, we ensure appropriate safeguards are in place in accordance with applicable data protection laws, including standard contractual clauses where required under GDPR.
12. Third-Party Links
Our website may contain links to third-party websites. This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party site you visit.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website at least 14 days before they take effect. Your continued use of our Services after the effective date constitutes acceptance of the updated Policy.
14. Contact Us
For any privacy-related questions, requests, or concerns:
CorpSecurity International Operated by LYL Corp International LLC (US) and CSS CorpSecuritySolutions Pvt Ltd (India)
India Office (CSS CorpSecuritySolutions Pvt Ltd — Data Fiduciary for India): 5-72/4, Chandanagar, Hyderabad, Telangana – 500050, India
Phone (India): +91 90300 55542 Phone (US): +1 302 244 7474 Email: support@corpsecurity.org Website: https://corpsecurity.org
This Privacy Policy is effective as of July 29, 2026 and supersedes all prior versions.