Privacy Policy
Your data. Your rights. Our commitment to transparency.
Data Collection
Information We Collect
- •Account information (name, email, username, password hash)
- •Payment information (processed by Stripe, not stored on our servers)
- •Profile data you voluntarily provide (avatar, bio, links)
- •Usage data (features used, time spent, interaction patterns)
- •Technical data (IP address, browser type, device information, OS)
Sensitive & Special Category Information
- •We do not intentionally collect government-issued IDs, financial account numbers, or health data.
- •We do not collect or store biometric data such as fingerprints or facial recognition templates.
- •If you choose to include sensitive information in your profile, it will be visible to others according to your privacy settings.
- •We may inadvertently collect sensitive data included in user-generated content (messages, files, links).
- •Data classified as sensitive under GDPR Article 9 or similar regulations is handled with enhanced protections.
- •Any sensitive data discovered in logs or backups is purged within 48 hours of detection.
Biometric Data
- •We do not collect biometric identifiers for the purpose of uniquely identifying a natural person.
- •We do not use facial recognition, fingerprint scanning, or voice recognition on our platform.
- •Any biometric data shared through our messaging features is processed transiently and never stored.
Usage & Retention
How We Use Your Information
- •Providing and maintaining the GANGA Offensive Ops platform and its features.
- •Personalizing your experience and delivering content relevant to your interests.
- •Communicating with you about updates, security alerts, and support.
- •Analyzing usage patterns to improve our services and develop new features.
- •Detecting and preventing fraud, abuse, and security incidents.
- •Complying with legal obligations and enforcing our terms.
- •Processing payments and managing your subscription.
- •Conducting internal research and analytics using aggregated, de-identified data.
Data Retention
- •Account data: Retained while your account is active and for 30 days after deletion.
- •Payment records: Retained for 7 years as required by tax and financial regulations.
- •Usage logs: Retained for 90 days in identifiable form, then aggregated or deleted.
- •Content you post: Retained until you delete it, subject to backup propagation delays (up to 30 days).
- •Support tickets: Retained for 2 years after resolution.
- •Marketing preferences: Retained until you unsubscribe or delete your account.
Your Rights
GDPR Rights (EU/EEA Users)
- •Right of access: Request a copy of the personal data we hold about you.
- •Right to rectification: Request correction of inaccurate or incomplete data.
- •Right to erasure: Request deletion of your personal data ("right to be forgotten").
- •Right to restrict processing: Request limitation of how we process your data.
- •Right to data portability: Receive your data in a structured, machine-readable format.
- •Right to object: Object to processing based on legitimate interests or direct marketing.
- •Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
- •Right to lodge a complaint: File a complaint with your local supervisory authority.
US State Privacy Rights
- •California (CCPA/CPRA): Right to know, delete, correct, opt-out of sale/sharing, and non-discrimination.
- •Virginia (VCDPA): Right to access, delete, correct, opt-out of targeted advertising and sale.
- •Colorado (CPA): Right to access, delete, correct, opt-out of profiling and targeted advertising.
- •Connecticut (CTDPA): Right to access, delete, correct, opt-out of sale and targeted advertising.
- •Additional states: We extend core rights (access, delete, correct) to all US users regardless of state.
- •Verification: We may require identity verification before processing rights requests.
Other Regional Rights
- •Brazil (LGPD): Rights similar to GDPR including access, correction, deletion, and data portability.
- •Canada (PIPEDA): Right to access, correct, and challenge compliance with data protection principles.
- •We comply with applicable data protection laws in all jurisdictions where we operate.
Security & Legal
Data Security
- •AES-256 encryption for data at rest, TLS 1.3 for data in transit.
- •Regular security audits and penetration testing by independent firms.
- •Bug bounty program to encourage responsible vulnerability disclosure.
- •SOC 2 Type II compliance (in progress — expected Q2 2026).
- •Incident response plan with 72-hour breach notification procedures.
Legal Bases for Processing
- •Consent: Where you have given explicit consent for specific processing purposes.
- •Contract: Processing necessary for the performance of our Terms of Service.
- •Legitimate interests: Processing necessary for our legitimate interests (security, fraud prevention, analytics) balanced against your rights.
- •Legal obligation: Processing required to comply with applicable laws and regulations.
- •Vital interests: Processing necessary to protect someone's life (rare, emergency situations only).
- •Public interest: Processing necessary for tasks carried out in the public interest (not applicable to our services).
Special Categories
Children's Privacy
- •GANGA Offensive Ops is not intended for users under 13 years of age (or the applicable age in your jurisdiction).
- •We do not knowingly collect personal information from children under 13.
- •If we discover we have collected data from a child under 13, we will delete it promptly.
- •Users between 13-16 (or applicable age) require parental consent in certain jurisdictions.
AI Products & Processing
- •AI features process data in real-time and do not store inputs beyond the session.
- •No user data is used to train AI models without explicit consent.
- •AI-generated content is clearly labeled and attributed.
- •We comply with emerging AI regulations including transparency requirements.
- •AI processing does not make automated decisions with legal or similarly significant effects without human oversight.
Social Login & Third-Party Connections
- •Social login providers (Google, GitHub, etc.) share basic profile information per your authorization.
- •We receive only the data you authorize during the OAuth consent flow.
- •Third-party connections are governed by both our privacy policy and the third party's terms.
- •You can revoke third-party access at any time through your account settings.
- •We do not store third-party OAuth tokens on our servers after initial authentication.
Offensive Tools & Tools
OSINT Disclosure
- •GANGA Offensive Ops provides OSINT capabilities for legitimate security research and authorized assessments.
- •Users are responsible for ensuring they have proper authorization before conducting OSINT activities.
- •OSINT data collected through our platform is subject to the same retention and security policies.
- •We log OSINT queries for security monitoring and compliance purposes.
- •Unauthorized OSINT activities may result in account suspension or termination.
Dual-Use & Ethical Use
- •GANGA Offensive Ops tools are designed for defensive security purposes.
- •Users agree not to use our tools for unauthorized access, harassment, or illegal activities.
- •We reserve the right to restrict access to tools that are misused.
- •Report suspected misuse to security@gangaoffensiveops.com.np.
- •We cooperate with law enforcement in cases of confirmed abuse.
Authorization & Access Controls
- •All tool access requires authenticated membership.
- •Premium tools require active subscription and may have usage limits.
- •Access logs are maintained for security auditing.
- •Unauthorized access attempts are flagged and may result in account review.
Contact & Control
Review, Update & Delete Your Data
- •Review your data: Visit your account settings to view and download your personal information.
- •Update your data: Edit your profile and preferences directly in your account settings.
- •Delete your data: Request account deletion through settings or by contacting privacy@gangaoffensiveops.com.np.
- •Export your data: Request a machine-readable export of your data (JSON format).
- •Automated processing review: Request information about automated decision-making affecting you.
- •We process data access and deletion requests within 30 days.
Contact Us About Privacy
- •Privacy inquiries: privacy@gangaoffensiveops.com.np
- •Data protection officer: dpo@gangaoffensiveops.com.np
- •Security reports: security@gangaoffensiveops.com.np
- •Mailing address: GANGA Offensive Ops Pvt. Ltd., SundarHaraicha-5 Morang, Koshi Province, Nepal
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- •Posting the updated policy on this page with a new "Last Updated" date.
- •Sending an email to the address associated with your account.
- •Displaying a prominent notice within the platform.
Your Consent
By using GANGA Offensive Ops, you consent to this Privacy Policy. If you do not agree with our practices, please do not use our platform. You can withdraw consent at any time by contacting us or adjusting your account settings. Continued use of the platform after changes to this policy constitutes acceptance of those changes. We are committed to working with you to resolve any concerns about our data practices.
Last Updated: May 30, 2026
GANGA Offensive Ops Pvt. Ltd. | Security Operations | legal@gangaoffensiveops.com.np