ANISH ENTERPRISES — Complete Legal Policy Framework

This document compiles the full legal policy framework governing ANISH ENTERPRISES' services, products, research, and operations. It is intended for clients, partners, researchers, and site visitors. For questions or to exercise rights, contact the addresses below.

CONTENTS
1. Privacy Policy
2. Terms of Service
3. Terms & Conditions
4. Cybersecurity Policy
5. Responsible Vulnerability Disclosure Policy
6. Penetration Testing Policy
7. Ethical Hacking Policy
8. Acceptable Use Policy (AUP)
9. Data Protection Policy
10. Information Security Policy
11. Artificial Intelligence Policy
12. Responsible AI Policy
13. Automation Policy
14. Software Development Policy
15. Security Research Policy
16. Bug Reporting Policy
17. Incident Response Policy
18. Risk Management Policy
19. Client Responsibilities Policy
20. Confidentiality Policy
21. Non-Disclosure Principles
22. Intellectual Property Policy
23. Copyright Policy
24. Trademark Policy
25. Open Source Software Policy
26. Communication Policy
27. Cookie Policy
28. Analytics Policy
29. External Links Policy
30. Payment Policy
31. Refund Policy
32. Cancellation Policy
33. Service Availability Policy
34. Accessibility Statement
35. Children's Privacy Policy
36. Export Control Statement
37. Sanctions Compliance Statement
38. Limitation of Liability
39. Disclaimer
40. Indemnification
41. Force Majeure
42. Termination & Suspension Policy
43. Governing Law & Jurisdiction
44. Policy Updates
45. Contact Information

---

1. PRIVACY POLICY

Purpose
ANISH ENTERPRISES ("Company", "we", "us", "our") is committed to protecting the privacy of natural persons whose personal data we process. This Privacy Policy explains the categories of personal data we collect, legal bases for processing, purposes of processing, how we store and secure personal data, data subject rights, cross-border transfers, retention, and contact channels for privacy inquiries.

Scope
This policy applies to all personal data processed by ANISH ENTERPRISES in India and abroad: website visitors, clients, contractors, suppliers, research participants, and end users of our services and products.

Definitions
- Personal Data: Any information relating to an identified or identifiable natural person.
- Sensitive Personal Data: Categories of information that require extra protection such as health, biometrics, or other specially regulated classes.
- Controller: The entity that determines the purposes and means of processing.
- Processor: A third party that processes data on behalf of the Controller.

Applicability
Applies to all business units, employees, contractors, and processors that handle personal data on behalf of the Company.

User Responsibilities
Data subjects should provide accurate information and may exercise rights (access, rectification, erasure, objection, restriction) as provided under the Digital Personal Data Protection Act, 2023 and related rules.

Company Responsibilities
We will:
- Maintain records of processing activities;
- Implement privacy-by-design in product development;
- Provide mechanisms to respond to data subject requests in required timeframes;
- Secure personal data through appropriate technical and organizational measures.

Security Considerations
We use TLS for in-transit protection, encryption for sensitive data at rest, access controls, logging, monitoring, and incident response integration. We conduct DPIAs for high-risk processing activities.

Compliance Requirements
This policy is aligned with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000. Cross-border transfers are assessed and implemented per legal requirements.

Legal Basis
Processing is based on contractual necessity, consent where required, legitimate interests (balancing test), or legal obligations.

Exceptions
Aggregated anonymized data used for analytics is outside personal data scope. Compelled disclosures by lawful authority are exceptions.

Enforcement
Violations of this policy by employees may result in disciplinary action. Processors in breach may face contract termination and indemnity obligations.

Reporting Procedures
Submit privacy requests to privacy@AnishEnterprises.site. Report suspected breaches to security@AnishEnterprises.site immediately.

Best Practices
Minimize data collection, implement retention schedules, perform periodic reviews, and ensure contractual protections with third-party processors.

FAQ
Q: How can I request deletion of my personal data?
A: Send a verified request to privacy@AnishEnterprises.site with proof of identity. We will respond per applicable statutory timelines.

Cross References
Data Protection Policy; Information Security Policy; Incident Response Policy; Cookie Policy; Analytics Policy.

---

2. TERMS OF SERVICE

Purpose
These Terms of Service set forth the relationship between ANISH ENTERPRISES and persons or entities accessing our website and services. They describe permitted uses, limitations, account responsibilities, and dispute resolution mechanisms.

Scope
Applies to access and use of public websites, trial services, and standard offerings unless a separate MSA or SOW is executed.

(Full terms are provided in contractual documentation; contact legal@AnishEnterprises.site for enterprise MSAs.)

---

3. TERMS & CONDITIONS

Purpose
Standard commercial terms governing delivery, acceptance, and remedies for services and products.

Scope
Applies to agreements not covered by bespoke contracts.

(Additional contractual details and warranty disclaimers are provided in SOWs and MSAs.)

---

4. CYBERSECURITY POLICY

Purpose
To establish the governance, controls, and standards necessary to protect ANISH ENTERPRISES' information assets and client environments.

Scope
Covers internal IT, cloud services, product development environments, client-managed assets under contract, and research infrastructure.

Key Elements
- Governance aligned to NIST CSF: Identify, Protect, Detect, Respond, Recover.
- Vulnerability management with scheduled patching and scanning.
- Secure SDLC practices, OWASP Top 10 mitigations, and dependency scanning.
- Incident escalation to internal IR and, if applicable, CERT-In.

Authorized Security Testing
Written authorization (RoE and SOW) required before active security testing. RoE enumerates scope, methods, safewords, and times.

Evidence Collection
Collect artifacts with forensic rigor and maintain chain-of-custody where legal preservation is required.

Reporting
security@AnishEnterprises.site.

---

5. RESPONSIBLE VULNERABILITY DISCLOSURE POLICY

Purpose
To enable safe reporting, triage, and remediation of security vulnerabilities by researchers and users.

Process
Acknowledge within 72 hours; triage and assign remediation timelines based on CVSS; coordinate disclosure; provide safe harbor for good-faith reporters.

Submit reports to security@AnishEnterprises.site. Use PGP for sensitive attachments (pgp key available on request).

---

6. PENETRATION TESTING POLICY

Purpose
To standardize planning, authorization, execution, reporting, and remediation of penetration tests.

Key Requirements
Signed authorization, clear RoE, non-destructive PoC, evidence handling, and client emergency contacts.

---

7. ETHICAL HACKING POLICY

Purpose
To govern authorized offensive security activities to ensure ethical conduct, minimize collateral impact, and protect human subjects.

Principles
Authorization, transparency, safety, privacy protection, and oversight by security and legal teams.

---

8. ACCEPTABLE USE POLICY (AUP)

Purpose
Define permitted and prohibited activities on Company systems.

Prohibited Conduct
Unauthorized access, malware distribution, denial-of-service, unauthorized scanning, and any activity violating applicable law.

Enforcement
Suspension, termination, and legal action where appropriate.

---

9. DATA PROTECTION POLICY

Purpose
Operational requirements for protecting personal and sensitive data, including DPIAs, classification, retention, encryption, and processor management.

---

10. INFORMATION SECURITY POLICY

Purpose
Framework for maintaining CIA of information assets: ISMS, risk assessments, control implementations, monitoring, and BC/DR planning.

---

11. ARTIFICIAL INTELLIGENCE POLICY

Purpose
Govern AI model lifecycle: data governance, provenance, model cards, testing for bias, adversarial robustness, and human oversight for high-risk outcomes.

---

12. RESPONSIBLE AI POLICY

Purpose
Ethical requirements for AI development: transparency, fairness, accountability, and auditability.

---

13. AUTOMATION POLICY

Purpose
Govern safe design, testing, approval, and deployment of automation and orchestration tools; require runbooks, rollback, and staged releases.

---

14. SOFTWARE DEVELOPMENT POLICY

Purpose
Require secure SDLC practices: threat modeling, code review, CI/CD security gating, SAST/DAST, dependency management, and reproducible builds.

---

15. SECURITY RESEARCH POLICY

Purpose
Ethical and legal constraints for security research, isolation for experiments, and responsible publication procedures.

---

16. BUG REPORTING POLICY

Purpose
Provide a structured reporting process for defects and security issues; triage and remediation tracking.

Submit to bugs@AnishEnterprises.site or security@AnishEnterprises.site.

---

17. INCIDENT RESPONSE POLICY

Purpose
A repeatable incident management lifecycle: detect, contain, eradicate, recover, and lessons learned. Regulatory notifications per law.

---

18. RISK MANAGEMENT POLICY

Purpose
Identify, assess, treat, and monitor risks across the enterprise. Maintain a risk register and assign owners to controls.

---

19. CLIENT RESPONSIBILITIES POLICY

Purpose
Clarify client obligations: authorization for testing, backups, providing access, and cooperation during engagements.

---

20. CONFIDENTIALITY POLICY

Purpose
Protect confidential information via NDAs, access controls, and limited disclosure except when compelled by law.

---

21. NON-DISCLOSURE PRINCIPLES

Purpose
Core NDA mechanics: definitions, permitted uses, exclusions, duration, and remedies for breach.

---

22. INTELLECTUAL PROPERTY POLICY

Purpose
Protect Company IP, manage ownership, and ensure contractual assignment of work product by employees and contractors.

---

23. COPYRIGHT POLICY

Purpose
Process copyright claims and takedown requests consistent with the Copyright Act, 1957.

Contact: copyright@AnishEnterprises.site

---

24. TRADEMARK POLICY

Purpose
Use and protect Company Trademarks consistent with the Trade Marks Act, 1999.

Contact: brand@AnishEnterprises.site

---

25. OPEN SOURCE SOFTWARE POLICY

Purpose
Govern OSS usage, license compliance, SBOMs, and release procedures for contributed code.

---

26. COMMUNICATION POLICY

Purpose
Centralize press and incident communications; designate official spokespeople and require legal review for sensitive disclosures.

Contact: communications@AnishEnterprises.site

---

27. COOKIE POLICY

Purpose
Describe cookie categories used on the website, retention, and opt-out mechanisms.

---

28. ANALYTICS POLICY

Purpose
Describe telemetry collection and retention practices; minimize PII in analytics and provide opt-outs where required.

---

29. EXTERNAL LINKS POLICY

Purpose
Disclaim responsibility for third-party content and outline vetting and removal procedures for harmful links.

---

30. PAYMENT POLICY

Purpose
Billing and payment terms, secure payment processors, and non-storage of raw payment card data unless PCI-DSS compliance is in place.

Contact: billing@AnishEnterprises.site

---

31. REFUND POLICY

Purpose
Define eligibility and processing for refunds as per contract terms.

---

32. CANCELLATION POLICY

Purpose
Describe notice periods and fees for early termination of services.

---

33. SERVICE AVAILABILITY POLICY

Purpose
State availability targets and maintenance windows; SLAs defined per SOW.

Contact: status@AnishEnterprises.site

---

34. ACCESSIBILITY STATEMENT

Purpose
Affirm commitment to accessibility and provide reporting channels for barriers.

Contact: accessibility@AnishEnterprises.site

---

35. CHILDREN'S PRIVACY POLICY

Purpose
Parental consent requirements and protections when processing personal data of minors.

---

36. EXPORT CONTROL STATEMENT

Purpose
Export control screening for software, cryptography, and technical assistance; require classification and licensing where applicable.

Contact: export@AnishEnterprises.site

---

37. SANCTIONS COMPLIANCE STATEMENT

Purpose
Commit to sanctions screening and refusal of services to sanctioned entities.

Contact: compliance@AnishEnterprises.site

---

38. LIMITATION OF LIABILITY

Purpose
Describe caps and exclusions on liability as permitted by applicable law and contracts; exceptions for gross negligence and willful misconduct.

---

39. DISCLAIMER

Purpose
Disclaimers of warranties for informational content and public materials unless an express warranty is provided in a contract.

---

40. INDEMNIFICATION

Purpose
Allocate indemnity obligations between the Company and counterparties for third-party claims and breaches.

Contact: legal@AnishEnterprises.site

---

41. FORCE MAJEURE

Purpose
Relief from performance obligations for events beyond reasonable control; notice obligations and remedies.

---

42. TERMINATION & SUSPENSION POLICY

Purpose
Grounds and procedures for suspension and termination, including data retention and secure handover obligations.

---

43. GOVERNING LAW & JURISDICTION

Purpose
Specify applicable law (India) and forums for disputes. Parties may agree otherwise by contract, subject to enforceability.

---

44. POLICY UPDATES

Purpose
Document review cycle, publication process, and notification of material changes.

---

45. CONTACT INFORMATION

Legal: legal@AnishEnterprises.site
Privacy: privacy@AnishEnterprises.site
Security: security@AnishEnterprises.site
Billing: billing@AnishEnterprises.site
AI Governance: ai-governance@AnishEnterprises.site

Address: ANISH ENTERPRISES, Headquarters: Buxar, Bihar, India

References:
- Information Technology Act, 2000: https://www.indiacode.nic.in/
- Digital Personal Data Protection Act, 2023: https://www.meity.gov.in/
- Copyright Act, 1957: https://copyright.gov.in/
- Trade Marks Act, 1999: https://ipindia.gov.in/
- CERT-In: https://www.cert-in.org.in/
- OWASP: https://owasp.org/
- NIST Cybersecurity Framework: https://www.nist.gov/cyberframework

---

(last updated: 2026-07-14)
