1. Key Terms Used in This Policy
| Term | Meaning |
|---|---|
| Personal Data | Any data about an individual who is identifiable by or in relation to such data. |
| Data Principal | The individual to whom the personal data relates — i.e., you. |
| Data Fiduciary | The entity that determines the purpose and means of processing personal data — here, Peregrine Guarding Private Limited and/or Tenon Facility Management India Private Limited, as clarified in Section 3. |
| Data Processor | Any entity that processes personal data on behalf of a Data Fiduciary. |
| Processing | Any operation performed on personal data, including collection, storage, use, sharing, and deletion. |
| Consent | Your free, specific, informed, unconditional, and unambiguous agreement, communicated through a clear affirmative action. |
2. Who We Are (Data Fiduciaries)
"Tenon" is a shared brand name, not a registered legal entity. Services marketed under the Tenon name are provided by two independently incorporated Indian companies. Each is separately responsible, as a Data Fiduciary under the DPDPA, for the personal data it collects.
Peregrine Guarding Private Limited
- Registered Office
- 2nd Floor, House No. 859, Khasra No. 220, Opposite Pillar No. 5, Near Railway Crossing, Bijwasan, New Delhi – 110077
- Corporate Office
- Plot No. 13, Tenon Lane, Electronic City, Phase IV, Udyog Vihar, Gurugram – 122015, Haryana
- Website
- www.peregrine-security.com
- info@peregrine-security.com
- Phone
- 0124-6479800
Tenon Facility Management India Private Limited
- Registered Office
- Plot No. 13, Tenon Lane, Electronic City, Phase IV, Udyog Vihar, Gurugram, Haryana – 122015
- Corporate Office
- Plot No. 458, Udyog Vihar, Phase V, Gurugram, Haryana, India – 122001
- Website
- www.tenonfm-india.com
- info@tenon-fm.com
- Phone
- 0124-6479800
Soteria Command Center Private Limited
- Registered Office
- 2nd Floor, House No. 859, Khasra No. 220, Opp. Pillar No. 5, Near Railway Crossing, Bijwasan, New Delhi – 110077
- Corporate Office
- Plot No. 301, SCO Complex, Sector-29, Gurugram – 122001, Haryana, India
- Website
- www.soteria.in
- info@soteria.in
- Phone
- 0124 6479800
3. Which Entity Is Responsible for Your Data
Because Peregrine Guarding, Tenon FM, and Soteria are separate legal entities marketed under one brand, the Data Fiduciary responsible for your data depends on which company's service prompted your enquiry:
- If you responded to a Peregrine Guarding advertisement or Lead Gen Form (including the LinkedIn campaign this policy is linked from) — Peregrine Guarding Private Limited is the Data Fiduciary responsible for your personal data.
- If you responded to a Tenon FM advertisement or enquiry relating to facility management services — Tenon Facility Management India Private Limited is the Data Fiduciary responsible for your personal data.
- If you responded to a Soteria advertisement or enquiry relating to AI-driven surveillance or command centre services — Soteria Command Center Private Limited is the Data Fiduciary responsible for your personal data.
Where more than one company's team is involved in following up on a single enquiry, they act as joint Data Fiduciaries for that specific interaction and remain bound by this Policy.
4. Scope of This Policy
- Our websites — including peregrine-security.com and the Tenon FM India site — and any forms hosted on them;
- LinkedIn Sponsored Content and Lead Gen Forms, and other digital advertising campaigns run by either company;
- Email, phone, WhatsApp, or in-person interactions with our sales, marketing, or customer service teams;
- Business partners, vendors, and channel referrals who share personal data with us.
This Policy does not cover personal data of our employees, which is governed by internal HR policies, or data processed strictly on client premises under separate client agreements (e.g., visitor logs maintained for a client site).
5. Personal Data We Collect
| Category | Examples | Source |
|---|---|---|
| Identity data | Full name | Provided directly by you |
| Contact data | Email address, phone number | Provided directly by you |
| Professional data | Company name, job title, company size / industry | Provided directly by you (auto-filled from LinkedIn profile, where applicable) |
| Technical data | IP address, browser type, device identifiers, pages visited, referring URL | Automatically collected via cookies / analytics |
| Marketing preference data | Consent status, opt-in/opt-out record, communication history | Generated when you interact with our forms |
| Correspondence data | Content of emails, calls, or messages you send us | Provided directly by you |
We do not knowingly collect any sensitive category of personal data (financial account details, health data, biometric data, government ID numbers) through our website or LinkedIn Lead Gen Forms.
6. Data Collected via LinkedIn Ads & Lead Gen Forms
When you submit a LinkedIn Lead Gen Form in response to our advertisement, LinkedIn shares the following data points with us, pre-filled from your LinkedIn profile and confirmed by you before submission:
- Name
- Email address
- Phone number
- Company name
- Job title
- Company size / industry
7. Why We Process Your Data
| Data category | Purpose |
|---|---|
| Name, email, phone | To respond to your enquiry, share requested information or quotes, and contact you about our security guarding or facility management services |
| Company, job title, company size | To qualify your enquiry, tailor our response to your organisation's scale and requirements, and route it to the correct sales representative |
| Technical / website data | To operate and secure our website, measure advertising campaign performance, and improve user experience |
| Marketing preference data | To honour your consent choices and suppress communications where you have opted out |
| Correspondence data | To manage and respond to your communications with us, and maintain a record of the relationship |
We do not use your data for any purpose beyond what is disclosed above without seeking fresh, specific consent.
8. Consent & Legal Basis
We process your personal data on the basis of your free, specific, informed, unconditional, and unambiguous consent, given when you submit a LinkedIn Lead Gen Form or a form on our website. Consent is not bundled with any other terms and is presented separately, itemised by purpose, in line with the DPDP Rules, 2025.
You may withdraw your consent at any time by writing to the relevant entity's email address in Section 2, with withdrawal being as easy as giving consent. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and does not affect any independent legal obligation we may have to retain certain records (for example, under tax, contract, or PSARA licensing requirements) regardless of consent.
9. Cookies & Tracking Technologies
Our website and advertising campaigns may use the following categories of cookies and pixels:
| Category | Purpose | Examples |
|---|---|---|
| Strictly necessary | Required for the website to function | Session cookies, security tokens |
| Analytics | Understand how visitors use our site | Google Analytics or similar |
| Advertising / measurement | Measure campaign performance and attribute conversions | LinkedIn Insight Tag, Meta Pixel |
You can control or disable cookies through your browser settings, and opt out of LinkedIn's advertising cookies via your LinkedIn advertising preferences. Disabling cookies may affect certain website features.
10. Sharing & Disclosure of Personal Data
| Recipient category | Purpose |
|---|---|
| Internal teams (Sales, Marketing, Operations) at Peregrine Guarding and/or Tenon FM | To respond to and fulfil your enquiry |
| CRM and marketing automation providers (Data Processors) | To store and manage your enquiry and communications |
| LinkedIn / Microsoft | As the advertising platform through which your data was collected |
| IT, hosting, and cloud service providers | To host our website and store data securely |
| Professional advisors (legal, audit) | Where necessary to obtain advice or meet compliance obligations |
| Regulators, courts, or law enforcement | Where required or permitted by law |
| A successor entity in a merger, acquisition, or restructuring | To ensure business continuity, subject to equivalent privacy protections |
We do not sell your personal data to third parties, and we do not share it for third-party marketing without your separate consent.
11. Data Processors & Safeguards
Any third party that processes personal data on our behalf (a Data Processor) does so under a written agreement that requires it to: process data only on our documented instructions; maintain security safeguards at least equivalent to our own; assist us in honouring Data Principal rights requests; and delete or return personal data once the engagement ends.
12. Cross-Border Data Transfer
Some of our service providers (for example, cloud hosting or CRM platforms) may process or store personal data on servers located outside India. Where this occurs, we take reasonable steps to ensure such transfers comply with the DPDPA and any applicable Government of India notification restricting transfer to specific countries, and that the receiving party maintains a standard of protection consistent with this Policy.
13. Data Retention & Deletion
We will ensure that personal data is retained only for as long as necessary to fulfil the purpose for which it was collected, in line with the following schedule:
| Data category | Retention period |
|---|---|
| Lead / enquiry data (name, contact, company details) | 24 months from your last interaction with us, or until you withdraw consent, whichever is earlier |
| Data of leads who do not convert to customers | 12 months from collection, after which it is anonymised or deleted |
| Contractual / customer records | 8 years from the end of the contractual relationship, in line with statutory record-keeping requirements under the Companies Act, 2013 and applicable tax law |
| Website analytics data | 14 months, consistent with standard analytics tool retention settings |
Once the purpose of processing is fulfilled and no legal obligation requires further retention, your personal data is securely deleted or anonymised, in line with the standards prescribed under the DPDP Rules, 2025.
14. Data Security
We implement reasonable technical and organisational safeguards — including access controls, encryption in transit, role-based internal access, and vendor due diligence — to protect your personal data against unauthorised access, alteration, disclosure, or destruction. No system is completely secure, and we continuously review our safeguards.
15. Automated Decision-Making
We do not use your personal data for any automated decision-making that produces legal or similarly significant effects on you. Lead qualification (matching your enquiry to a sales representative) is performed with human review.
16. Your Rights as a Data Principal
- Right to Access — obtain a summary of the personal data we hold about you and the processing activities carried out.
- Right to Correction — have inaccurate or incomplete personal data corrected or updated.
- Right to Erasure — request deletion of your personal data once it is no longer necessary for the purpose it was collected, subject to legal exceptions.
- Right to Grievance Redressal — raise a complaint about our handling of your data and receive a response within a reasonable time.
- Right to Nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity.
- Right to Withdraw Consent — at any time, as described in Section 8.
17. How to Exercise Your Rights
To exercise any of the rights above, write to the relevant entity using the contact details in Section 2, or to our shared Grievance Officer in Section 22. We will respond to you within 90 days of receiving your request, in line with the timeline prescribed under the DPDP Rules, 2025 for grievance redressal. We may ask you to verify your identity before actioning a request, to protect your data from unauthorised access.
18. Children's / Minors' Data
Our website, LinkedIn advertisements, and Lead Gen Forms are directed at business professionals and are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children, and we do not carry out behavioural tracking or targeted advertising directed at minors. If we become aware that we have inadvertently collected personal data from a child without verifiable parental consent, we will delete it promptly.
19. Third-Party Links
Our website and communications may contain links to third-party websites (including LinkedIn, client sites, or partner sites). We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies separately.
20. Data Breach Notification
In the event of a personal data breach, we will, in accordance with the DPDPA and DPDP Rules, 2025, notify the Data Protection Board of India and affected Data Principals as required, describing the nature of the breach, its likely consequences, and the measures taken or proposed to mitigate risk.
21. Legal & Regulatory Framework
This Policy is drafted with reference to:
- The Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025;
- The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, to the extent still applicable;
- The Private Security Agencies (Regulation) Act, 2005 ("PSARA") and applicable state rules, to the extent they impose record-keeping obligations relevant to Peregrine Guarding's security services;
- LinkedIn's Lead Gen Forms terms and advertising policies.
22. Grievance Officer
In accordance with the DPDPA, the details of our Grievance Officer, appointed jointly for both entities, are:
| Name | Aryan |
|---|---|
| Designation | Assistant Manager, Corporate Communications |
| aryan@tenonworld.com | |
| Phone | 0124-6479800 |
| Address | Plot No. 13, Tenon Lane, Electronic City, Phase IV, Udyog Vihar, Gurugram – 122015, Haryana |
23. Right to Approach the Data Protection Board of India
If you are not satisfied with our response to your grievance, you have the right to file a complaint with the Data Protection Board of India, the regulatory authority established under the DPDPA.
24. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices or applicable law. The "Last updated" date at the top of this page indicates when this Policy was last revised. Material changes will be notified through appropriate means before they take effect.
25. Governing Law & Jurisdiction
This Policy is governed by the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Gurugram, Haryana.
26. Contact Us
If you have questions about this Privacy Policy or how we handle your personal data, contact the entity relevant to your enquiry (Section 2), or write to:
Email: info@tenonworld.com
Phone: 0124-6479800