Legal & Compliance

Privacy Policy

Effective date: 26 August 2026  ·  Last updated: 26 August 2026
Applies to Peregrine Guarding Private Limited, Tenon Facility Management India Private Limited, and Soteria Command Center Private Limited — the companies operating under the Tenon brand.

This Privacy Policy explains, in plain language, how Peregrine Guarding Private Limited, Tenon Facility Management India Private Limited, and Soteria Command Center Private Limited — independently incorporated companies that market their services together under the Tenon brand — collect, use, share, retain, and protect your personal data. It is written to comply with India's Digital Personal Data Protection Act, 2023 ("DPDPA") and the Digital Personal Data Protection Rules, 2025, together with the Information Technology Act, 2000 and rules made thereunder. It applies whether you reach us through our websites, a LinkedIn advertisement or Lead Gen Form, or any other channel.

1. Key Terms Used in This Policy

Term Meaning
Personal Data Any data about an individual who is identifiable by or in relation to such data.
Data Principal The individual to whom the personal data relates — i.e., you.
Data Fiduciary The entity that determines the purpose and means of processing personal data — here, Peregrine Guarding Private Limited and/or Tenon Facility Management India Private Limited, as clarified in Section 3.
Data Processor Any entity that processes personal data on behalf of a Data Fiduciary.
Processing Any operation performed on personal data, including collection, storage, use, sharing, and deletion.
Consent Your free, specific, informed, unconditional, and unambiguous agreement, communicated through a clear affirmative action.

2. Who We Are (Data Fiduciaries)

"Tenon" is a shared brand name, not a registered legal entity. Services marketed under the Tenon name are provided by two independently incorporated Indian companies. Each is separately responsible, as a Data Fiduciary under the DPDPA, for the personal data it collects.

Peregrine Guarding Private Limited

CIN: U74920DL2003PTC122546
Registered Office
2nd Floor, House No. 859, Khasra No. 220, Opposite Pillar No. 5, Near Railway Crossing, Bijwasan, New Delhi – 110077
Corporate Office
Plot No. 13, Tenon Lane, Electronic City, Phase IV, Udyog Vihar, Gurugram – 122015, Haryana
Website
www.peregrine-security.com
Email
info@peregrine-security.com
Phone
0124-6479800

Tenon Facility Management India Private Limited

CIN: U45400HR2007PTC037415
Registered Office
Plot No. 13, Tenon Lane, Electronic City, Phase IV, Udyog Vihar, Gurugram, Haryana – 122015
Corporate Office
Plot No. 458, Udyog Vihar, Phase V, Gurugram, Haryana, India – 122001
Website
www.tenonfm-india.com
Email
info@tenon-fm.com
Phone
0124-6479800

Soteria Command Center Private Limited

CIN: U72900DL2014PTC263271
Registered Office
2nd Floor, House No. 859, Khasra No. 220, Opp. Pillar No. 5, Near Railway Crossing, Bijwasan, New Delhi – 110077
Corporate Office
Plot No. 301, SCO Complex, Sector-29, Gurugram – 122001, Haryana, India
Website
www.soteria.in
Email
info@soteria.in
Phone
0124 6479800

3. Which Entity Is Responsible for Your Data

Because Peregrine Guarding, Tenon FM, and Soteria are separate legal entities marketed under one brand, the Data Fiduciary responsible for your data depends on which company's service prompted your enquiry:

Where more than one company's team is involved in following up on a single enquiry, they act as joint Data Fiduciaries for that specific interaction and remain bound by this Policy.

4. Scope of This Policy

This Policy does not cover personal data of our employees, which is governed by internal HR policies, or data processed strictly on client premises under separate client agreements (e.g., visitor logs maintained for a client site).

5. Personal Data We Collect

Category Examples Source
Identity data Full name Provided directly by you
Contact data Email address, phone number Provided directly by you
Professional data Company name, job title, company size / industry Provided directly by you (auto-filled from LinkedIn profile, where applicable)
Technical data IP address, browser type, device identifiers, pages visited, referring URL Automatically collected via cookies / analytics
Marketing preference data Consent status, opt-in/opt-out record, communication history Generated when you interact with our forms
Correspondence data Content of emails, calls, or messages you send us Provided directly by you

We do not knowingly collect any sensitive category of personal data (financial account details, health data, biometric data, government ID numbers) through our website or LinkedIn Lead Gen Forms.

6. Data Collected via LinkedIn Ads & Lead Gen Forms

When you submit a LinkedIn Lead Gen Form in response to our advertisement, LinkedIn shares the following data points with us, pre-filled from your LinkedIn profile and confirmed by you before submission:

Your submission is governed both by LinkedIn's own Privacy Policy (for how LinkedIn handles your data as a platform) and by this Policy (for how we, as the advertiser receiving your data, process it once it reaches us). LinkedIn acts as an independent Data Fiduciary for its own platform activities; we act as the Data Fiduciary for what we do with your data after receipt, per Section 3.

7. Why We Process Your Data

Data category Purpose
Name, email, phone To respond to your enquiry, share requested information or quotes, and contact you about our security guarding or facility management services
Company, job title, company size To qualify your enquiry, tailor our response to your organisation's scale and requirements, and route it to the correct sales representative
Technical / website data To operate and secure our website, measure advertising campaign performance, and improve user experience
Marketing preference data To honour your consent choices and suppress communications where you have opted out
Correspondence data To manage and respond to your communications with us, and maintain a record of the relationship

We do not use your data for any purpose beyond what is disclosed above without seeking fresh, specific consent.

We process your personal data on the basis of your free, specific, informed, unconditional, and unambiguous consent, given when you submit a LinkedIn Lead Gen Form or a form on our website. Consent is not bundled with any other terms and is presented separately, itemised by purpose, in line with the DPDP Rules, 2025.

You may withdraw your consent at any time by writing to the relevant entity's email address in Section 2, with withdrawal being as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect any independent legal obligation we may have to retain certain records (for example, under tax, contract, or PSARA licensing requirements) regardless of consent.

9. Cookies & Tracking Technologies

Our website and advertising campaigns may use the following categories of cookies and pixels:

Category Purpose Examples
Strictly necessary Required for the website to function Session cookies, security tokens
Analytics Understand how visitors use our site Google Analytics or similar
Advertising / measurement Measure campaign performance and attribute conversions LinkedIn Insight Tag, Meta Pixel

You can control or disable cookies through your browser settings, and opt out of LinkedIn's advertising cookies via your LinkedIn advertising preferences. Disabling cookies may affect certain website features.

10. Sharing & Disclosure of Personal Data

Recipient category Purpose
Internal teams (Sales, Marketing, Operations) at Peregrine Guarding and/or Tenon FM To respond to and fulfil your enquiry
CRM and marketing automation providers (Data Processors) To store and manage your enquiry and communications
LinkedIn / Microsoft As the advertising platform through which your data was collected
IT, hosting, and cloud service providers To host our website and store data securely
Professional advisors (legal, audit) Where necessary to obtain advice or meet compliance obligations
Regulators, courts, or law enforcement Where required or permitted by law
A successor entity in a merger, acquisition, or restructuring To ensure business continuity, subject to equivalent privacy protections

We do not sell your personal data to third parties, and we do not share it for third-party marketing without your separate consent.

11. Data Processors & Safeguards

Any third party that processes personal data on our behalf (a Data Processor) does so under a written agreement that requires it to: process data only on our documented instructions; maintain security safeguards at least equivalent to our own; assist us in honouring Data Principal rights requests; and delete or return personal data once the engagement ends.

12. Cross-Border Data Transfer

Some of our service providers (for example, cloud hosting or CRM platforms) may process or store personal data on servers located outside India. Where this occurs, we take reasonable steps to ensure such transfers comply with the DPDPA and any applicable Government of India notification restricting transfer to specific countries, and that the receiving party maintains a standard of protection consistent with this Policy.

13. Data Retention & Deletion

We will ensure that personal data is retained only for as long as necessary to fulfil the purpose for which it was collected, in line with the following schedule:

Data category Retention period
Lead / enquiry data (name, contact, company details) 24 months from your last interaction with us, or until you withdraw consent, whichever is earlier
Data of leads who do not convert to customers 12 months from collection, after which it is anonymised or deleted
Contractual / customer records 8 years from the end of the contractual relationship, in line with statutory record-keeping requirements under the Companies Act, 2013 and applicable tax law
Website analytics data 14 months, consistent with standard analytics tool retention settings

Once the purpose of processing is fulfilled and no legal obligation requires further retention, your personal data is securely deleted or anonymised, in line with the standards prescribed under the DPDP Rules, 2025.

14. Data Security

We implement reasonable technical and organisational safeguards — including access controls, encryption in transit, role-based internal access, and vendor due diligence — to protect your personal data against unauthorised access, alteration, disclosure, or destruction. No system is completely secure, and we continuously review our safeguards.

15. Automated Decision-Making

We do not use your personal data for any automated decision-making that produces legal or similarly significant effects on you. Lead qualification (matching your enquiry to a sales representative) is performed with human review.

16. Your Rights as a Data Principal

17. How to Exercise Your Rights

To exercise any of the rights above, write to the relevant entity using the contact details in Section 2, or to our shared Grievance Officer in Section 22. We will respond to you within 90 days of receiving your request, in line with the timeline prescribed under the DPDP Rules, 2025 for grievance redressal. We may ask you to verify your identity before actioning a request, to protect your data from unauthorised access.

18. Children's / Minors' Data

Our website, LinkedIn advertisements, and Lead Gen Forms are directed at business professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children, and we do not carry out behavioural tracking or targeted advertising directed at minors. If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will delete it promptly.

19. Third-Party Links

Our website and communications may contain links to third-party websites (including LinkedIn, client sites, or partner sites). We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies separately.

20. Data Breach Notification

In the event of a personal data breach, we will, in accordance with the DPDPA and DPDP Rules, 2025, notify the Data Protection Board of India and affected Data Principals as required, describing the nature of the breach, its likely consequences, and the measures taken or proposed to mitigate risk.

21. Legal & Regulatory Framework

This Policy is drafted with reference to:

22. Grievance Officer

In accordance with the DPDPA, the details of our Grievance Officer, appointed jointly for both entities, are:

Name Aryan
Designation Assistant Manager, Corporate Communications
Email aryan@tenonworld.com
Phone 0124-6479800
Address Plot No. 13, Tenon Lane, Electronic City, Phase IV, Udyog Vihar, Gurugram – 122015, Haryana

23. Right to Approach the Data Protection Board of India

If you are not satisfied with our response to your grievance, you have the right to file a complaint with the Data Protection Board of India, the regulatory authority established under the DPDPA.

24. Changes to This Policy

We may update this Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page indicates when this Policy was last revised. Material changes will be notified through appropriate means before they take effect.

25. Governing Law & Jurisdiction

This Policy is governed by the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Gurugram, Haryana.

26. Contact Us

If you have questions about this Privacy Policy or how we handle your personal data, contact the entity relevant to your enquiry (Section 2), or write to:

Email: info@tenonworld.com
Phone: 0124-6479800