A quick note before you read on
This Privacy Policy tells you in plain language what personal data Subex collects when you visit www.subex.com, why we collect it, who we share it with, how long we keep it, and what rights you have.
It is underpinned by our internal Global Privacy & Cookies Policy, which is the master compliance document covering GDPR, India’s DPDPA, California’s CPRA, Singapore’s PDPA, the UAE’s PDPL, and Canada’s PIPEDA / Law 25. Where there is a conflict between this public Data Privacy policy and the Global Policy, the Global Policy prevails.
If you have a question not answered here, please email our Data Protection Officer: dpo@subex.com
1. Who We Are
When we say Subex, we, us, or our in this policy, we mean Subex Limited and its group companies, which include:
1.1. Subex Limited (India) — the main data controller
1.2. Subex (UK) Limited (United Kingdom)
1.3. Subex Inc. and Subex Americas Inc. (United States)
1.4. Subex (Asia Pacific) Pte Limited (Singapore)
1.5. Subex Middle East (FZE) (Dubai, UAE)
1.6. Subex Assurance LLP, Subex Digital LLP, and Subex Bangladesh Pvt Limited.
Each entity acts as a data controller for personal data collected from individuals in its territory, or jointly with Subex Limited where services are delivered across entities. Our website is operated by Subex Limited. For questions about this policy or your personal data, contact our Data Protection Officer at dpo@subex.com.
2.Personal Data We Collect and Why
We only collect data we need. Here is a plain-language breakdown of what we collect and the reason.
2.1. When You Fill in a Form on Our Website
When you, Contact Us, request a Demo, Subscribe to Updates, or similar form, we collect:
What we collect
Full name, business email address, phone number, company name, job title, and country.
Why
To respond to your enquiry, send you information you requested, and if you have opted in, to keep you updated about Subex products and events.
Legal basis
Contract (taking steps at your request) and/or your consent (for marketing communications).
How long we keep it
3 years from your last interaction with us, or until you ask us to delete it. We will never use your data for purposes that are incompatible with the reason we collected it, without first telling you and where required, getting your consent.
2.2. When You Apply for a Job
If you submit a job application through our website or careers portal, we collect:
What we collect
Name, contact details, CV/resume, qualifications, work history, and any other information you choose to include.
Why
To assess your application and, if successful, to progress your candidacy.
Legal basis
Pre-contractual steps (taking steps to enter a contract with you).
How long we keep it
2 years if your application is unsuccessful (or longer with your consent for future roles). If hired, your data moves into our employment records.
2.3. When You Simply Visit Our Website
What we collect
Anonymous IP address, browser type, device type, pages visited, time on page, and referring website.
Why
To understand how our website is used so we can improve it, and to maintain the security of our systems.
Legal basis
Legitimate interests (website analytics and security) and your consent (for analytics cookies, see our Cookies Policy at [Insert Link]).
How long we keep it
13 months for analytics data. Security logs are deleted after 90 days unless an incident requires longer retention.
2.4. Business Cards and Event Contacts
3. How We Use Your Personal Data
We use your personal data only for the purposes described at the time we collect it. In summary:
- Responding to your enquiries and providing you with information about our products and services.
- Sending marketing communications (only where you have opted in, or where we have a legitimate interest and you have not opted out).
- Processing job applications and managing our recruitment process.
- Improving our website through analytics and performance monitoring.
- Keeping our systems and your data secure
- Meeting our legal and regulatory obligations in the countries where we operate.
- We will never use your data for purposes that are incompatible with the reason we collected it, without first telling you and where required, getting your consent.
4. The Legal Basis for Using Your Data
Data protection law requires us to have a valid legal reason for every way we use personal data. Here is what we rely on:
Legal Basis When We Use It
Your Consent Where you tick a box to receive marketing emails or accept analytics cookies. You can withdraw consent at any time.
Contract
Where we need to process data to respond to your enquiry or to take steps towards entering a contract with you (e.g., processing a job application).
Legitimate
Interests Where we have a genuine business reason that does not override your rights, for example, keeping our website secure, or sending relevant business updates to existing contacts.
Legal Obligation
Where the law requires us to collect or retain certain data, for example, tax records or anti-money-laundering checks.
5. Who We Share Your Data With
We do not sell your personal data. We share it only in the following limited circumstances:
- Subex group companies: We may share your data within the Subex group for internal administrative purposes (for example, if your enquiry is handled by a team in a different country).
- Trusted service providers: We use third-party companies to help us run our business, for example, our website hosting provider, CRM platform, email marketing tool, and analytics provider. They can only use your data as we instruct them, and they must keep it secure. We have signed data processing agreements with each of them.
- Professional advisors: Lawyers, auditors, and accountants, where necessary and subject to confidentiality obligations.
- Legal authorities: Where we are required to disclose data by law, court order, or a regulator.
- Business transfers: If Subex is involved in a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you if this happens.
With your consent: If you have specifically agreed to us sharing your data with a named third party.
6. International Data Transfers
Subex operates globally. Your personal data may be transferred to and stored in countries outside your home country, including India, the United Kingdom, the United States, Singapore, and the UAE.
When we transfer data outside the European Economic Area (EEA) or the UK, we make sure it is protected through one of the following safeguards:
- The destination country has been approved of providing adequate data protection (for example, the UK has an adequacy decision from the EU).
- We use Standard Contractual Clauses (SCCs) legal contracts approved by the European Commission that require the recipient to protect your data to the same standard as the GDPR.
- We are carrying out a Transfer Impact Assessment to check the legal environment in the receiving country and confirm the SCCs are effective.
- Personal data of Indian Data Principals may be transferred outside India only to countries notified by the Central Government as permissible under DPDPA clause16.
For details of the specific safeguards in place for any transfer, please contact dpo@subex.com.
7. How Long We Keep Your Data
We only keep personal data for as long as we need it. Our standard retention periods are:
Enquiry / contact form data
3 years from your last interaction with us, or until you request deletion.
Marketing contact data
3 years from last interaction, or until you unsubscribe, whichever comes first.
Job application data (unsuccessful)
2 years (or longer with your consent).
Website analytics data
13 months.
Security logs
90 days (unless an incident requires longer retention).
Contract and financial records
7 years (required by accounting and tax law).
Employee data
Duration of employment + up to 10 years (depending on data type and local law).
8. Your Rights
You have strong rights over your personal data under data protection law. These apply regardless of which country you are in, the specific law that applies may vary, but the core rights are consistent.
Your Right What It Means
Right to Know / Be Informed We tell you exactly what personal data we collect, why we collect it, how long we keep it, and who we share it with — this Privacy Policy does that.
Right of Access
You can ask us for a copy of the personal data we hold about you at any time.
Right to Correct
If any of your personal data is wrong or out of date, you can ask us to fix it.
Right to Delete
You can ask us to delete your personal data. We will do so unless we have a legal reason to keep it.
Right to Restrict Processing
You can ask us to pause how we use your data in certain circumstances.
Right to Data Portability
You can ask us to send your data to you or another organisation in a format you can reuse.
Right to Object
You can object to us using your data for marketing, or where we rely on ‘legitimate interests’.
Right to Withdraw Consent
If you gave us consent to process your data, you can take it back at any time — it won’t affect anything we already did lawfully.
Right to Lodge a Complaint
You can report a concern to your local data protection authority (e.g. the ICO in the UK).
Right to Nominate
You have the right to nominate, who shall exercise the rights of the Data on your behalf in the event of death or incapacity of the Data Principal.
How to exercise your rights:
Email us at dpo@subex.com with the subject line ‘Privacy Rights Request’.
Tell us what right you wish to exercise and provide enough information for us to identify you.
We will respond within 30 days (or 45 days for California residents). We will not charge you.
If we cannot do what you ask (for example, if the law requires us to keep certain records), we will explain why.
9. Your Duties
You also have the right to lodge a complaint with the relevant Supervisory Authority. If you would like to exercise this right and require assistance in obtaining contact information for the correct Supervisory Authority, please refer clause 16.2:
- You acknowledge to comply with the provisions of this privacy policy and all applicable laws in force while exercising your rights under this Policy.
- You must not impersonate any person while providing any data for the specified purpose.
- You must ensure to not supress any material information while providing your personal information for any purposes including but not limited to documentation, proof of identity, identification purposes or proof of address for any statutory benefits or compliance as required by the State or any of its instrumentalities.
- You must not initiate or register a false or frivolous grievance or complaint with the Data officer.
- You must ensure that the information provided is authentic, accurate and true to your knowledge while exercising your rights to correction and erasure requests.
10. Cookies
Our website uses cookies. A cookie is a small text file stored on your device when you visit a website. We use cookies to make our website work, to understand how it is used, and with your consent, to personalize your experience and show relevant advertising.
We do not place any non-essential cookies on your device until you have given your consent. You can manage your cookie preferences at any time through the Cookie Settings link in the footer of our website.
For a full explanation of the cookies we use, the legal basis for each, and how to manage them, please refer to our separate Cookies Policy, available at [insert Link].
11. Marketing Communications
We will only send you marketing emails, newsletters, or event invitations if:
- You have explicitly opted in by ticking a consent checkbox on one of our forms, or
- You are an existing business contact, and we send information about similar products or services to those you have already engaged with (and you have not opted out).
Every marketing communication we send includes an unsubscribed link. You can also opt out at any time by emailing dpo@subex.com or updating your preferences at www.subex.com/preferences. We will process your opt-out request within 10 business days.
12. Security
We take the security of your personal data seriously and have put in place appropriate technical and organizational measures to protect it. These include:
- Encrypting data in transit (using HTTPS/TLS) and at rest.
- Restricting access to personal data to authorised staff only, using multi-factor authentication and role-based access controls.
- Conducting regular security assessments and penetration testing of our systems.
- Training our staff on data protection and cybersecurity awareness.
If we ever experience a data breach that is likely to affect your rights or privacy, we will notify you and the relevant regulator as quickly as possible, and always within the timeframes required by law.
13. Children
Our website is not intended for children under the age of 18. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data about a child, please contact us at dpo@subex.com and we will delete it promptly.
14. Third-Party Websites
Our website may contain links to third-party websites. If you click on a link and visit another website, that site has its own privacy policy and we are not responsible for how they handle your data. We encourage you to read the privacy policy of any website you visit.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the ‘Last updated’ date at the top and, where the change is significant, we will notify you by posting a banner on our website or by email.
We encourage you to review this page periodically to stay informed about how we protect your data.
16. Contact Us
16.1. Contact Our DPO
Email- dpo@subex.com
Subject line- ‘Privacy Enquiry’ or ‘Privacy Rights Request’
Post- Data Protection Officer, Subex Limited, Pritech Park, SEZ Block-09, 4th Floor B Wing, Bengaluru 560103, India
Response time- We aim to respond within 5 business days for general enquiries, and within 30 days for formal rights requests.
16.2. Supervisory Authorities
If you are not satisfied with our response, you have the right to complain to your local data protection authority. Key authorities include:
- UK: Information Commissioner’s Office (ICO) ico.org.uk
- EU: Your national supervisory authority – a list is available at edpb.europa.eu
- India: Data Protection Board of India – meity.gov.in
- California: California Privacy Protection Agency – cppa.ca.gov
- Singapore: Personal Data Protection Commission – pdpc.gov.sg
- UAE / Dubai: UAE Data Office – uaedataoffice.ae | DIFC: difc.ae
- Canada: Office of the Privacy Commissioner – priv.gc.ca | Quebec CAI -cai.quebec.ca
Subex Limited – Website Privacy Policy
Version 2.0 | Effective April 2026 | Governed by Global Privacy Policy
This public policy is aligned to and governed by Subex’s Global Privacy & Cookies Policy as updated from time to time. In the event of conflict, the Global Policy prevails.
Start with a sprint.Scale to a Managed Operation.
Whether you need a 2-week Risk Advisory or a fully managed 24/7 operation, our team will scope the right engagement model and stay accountable through delivery.