Build your future with us.

Enable continuous compliance with a unified, intelligent platform

Let's Discuss

Platform Privacy Policy

CYRAAC Services Private Limited

Effective Date: 1st April 2026 | Version 2.0 (Revised)

Platform Privacy Policy

This Privacy Policy has been prepared taking into consideration the principles of the Digital Personal Data Protection Act, 2023 (India) (“DPDPA”), and, to the extent CyRAACS processes Personal Data of individuals located outside India in connection with its Services, the applicable requirements of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), the UK GDPR, and other applicable data protection laws.

1.  INTRODUCTION

CYRAAC Services Private Limited (“CyRAACS”, “we”, “our”, or “us”) is committed to protecting the privacy, confidentiality, and security of the information entrusted to us by our customers, business partners, website visitors, and authorized users of our services.

As a cybersecurity consulting and technology company, we understand the importance of responsible information handling and recognize that trust forms the foundation of every relationship we build with our customers. Protecting information is central not only to the services we provide but also to the manner in which we conduct our business.

This Privacy Policy explains how we collect, use, store, process, disclose, retain, and protect information when you:

  • visit our website;
  • access or use the CyRAACS Platform;
  • communicate with us;
  • request information about our services;
  • register for webinars, demonstrations or events;
  • interact with our customer support team; or
  • use any products or services offered by CyRAACS.

Our cybersecurity platform enables organizations to strengthen their cybersecurity posture through automated evidence collection, security assessments, compliance monitoring, governance, risk management, vulnerability management, configuration reviews, asset visibility, and related cybersecurity services.

To deliver these services, our Platform may integrate with third-party cloud platforms, identity providers, enterprise applications, and security technologies. Such integrations are established only with the Customer’s authorization and only to the extent necessary to provide the requested services.

This Privacy Policy describes: the information we collect; how we collect information; how we use information; the legal basis on which we process information; when information may be shared; how we protect information; how long information is retained; cross-border transfers; the privacy choices available to you; your rights under applicable privacy laws; and how to reach us in the event of a query, request, or grievance.

By accessing our website or using our Services, you acknowledge that you have read and understood this Privacy Policy.

Where CyRAACS processes information on behalf of a Customer, the Customer acts as the Data Fiduciary (or data controller, as applicable) and determines the purposes for which such information is processed, while CyRAACS acts as a Data Processor and processes such information solely for providing the agreed Services, in accordance with the Customer’s instructions and any applicable Data Processing Agreement.

2.  SCOPE

This Privacy Policy applies to information collected through:

  • the CyRAACS website;
  • the CyRAACS cloud platform;
  • customer portals;
  • software applications;
  • APIs and authorized integrations;
  • customer support interactions;
  • sales and marketing communications;
  • webinars, training programmes, and events;
  • surveys and feedback;
  • any other products or services operated by CyRAACS unless governed by a separate privacy notice.

This Privacy Policy applies to: organizations using our Services; prospective customers; customers; administrators; authorized users; business partners; website visitors; and individuals who communicate with CyRAACS.

This Privacy Policy does not apply to third-party websites, third-party applications, external cloud platforms, or products or services not owned or controlled by CyRAACS. Such third-party services are governed by their own privacy policies and terms of use. We encourage you to review those policies before providing any information to such third parties.

3.  DEFINITIONS

For the purposes of this Privacy Policy:

“Account” means the account created by or on behalf of a Customer to access the CyRAACS Platform.

“Authorized User” means an employee, consultant, contractor, or representative authorized by the Customer to access and use the Platform.

“Consent Manager” means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review, or withdraw consent through an accessible, transparent, and interoperable platform, where CyRAACS makes such a mechanism available or is required to recognize one.

“Customer” means any organization or legal entity that subscribes to or uses the Services provided by CyRAACS.

“Customer Data” means information, documents, images, configurations, reports, logs, metadata, compliance evidence, audit information, technical information, and other content submitted, uploaded, synchronized, or otherwise made available through the Platform by or on behalf of a Customer.

“Data Fiduciary” means the person who, alone or in conjunction with others, determines the purpose and means of processing of Personal Data, as defined under the DPDPA.

“Data Principal” means the individual to whom Personal Data relates, as defined under the DPDPA.

“Data Processor” means a person who processes Personal Data on behalf of a Data Fiduciary.

“Personal Data” / “Personal Information” means any data or information about or relating to an identified or identifiable individual, as defined under applicable privacy laws, including the DPDPA and, where applicable, the GDPR.

“Personal Data Breach” means any unauthorized processing of Personal Data, or accidental or unlawful loss, disclosure, alteration, destruction, or access, that compromises the confidentiality, integrity, or availability of Personal Data.

“Platform” means the CyRAACS cloud-based cybersecurity platform, applications, dashboards, APIs, portals, and related software used to deliver our Services.

“Processing” means any operation performed on information, including collection, recording, organization, storage, retrieval, use, disclosure, transmission, analysis, deletion, or destruction.

“Services” means the cybersecurity consulting, managed security, governance, risk management, compliance, assessment, automation, advisory, software, and related services provided by CyRAACS.

“Third-Party Integration” means an authorized connection between the Platform and an external cloud service, application, identity provider, infrastructure platform, or other technology solution.

4.  INFORMATION WE COLLECT

The information we collect depends on the manner in which you interact with CyRAACS and the Services you use.

4.1  Information You Provide

You may voluntarily provide information when you: contact us; request a demonstration; enquire about our Services; complete online forms; subscribe to newsletters; register for webinars or events; apply for employment opportunities; or communicate with our customer support team. This information may include your name, business email address, telephone number, organization name, designation, country or region, business address, and any other information you choose to provide.

4.2  Account Information

When a Customer creates an account on our Platform, we may collect organization details, administrator information, subscription information, account identifiers, billing-related information, authentication credentials, and user preferences.

4.3  Customer Data

Customers may upload or synchronize information required for delivering our cybersecurity services, including policies, audit evidence, documents, screenshots, images, security configurations, compliance records, asset inventories, risk assessments, vulnerability information, reports, and logs. Customer Data remains the property of the Customer.

4.4  Technical Information

When you access our website or Platform, certain information may be collected automatically, including IP address, browser type, operating system, device information, language preferences, referring website, access times, pages visited, session information, and diagnostic information. This information helps us secure, maintain, and improve our website and Services.

4.5  Usage Information

We may collect information regarding the manner in which our Platform is used, including login activity, features accessed, navigation within the Platform, administrative actions, audit logs, system events, performance metrics, and usage statistics.

4.6  Information Received Through Third-Party Integrations

Where authorized by a Customer, the Platform may receive information from integrated third-party cloud platforms, identity providers, enterprise software, security tools, and compliance technologies. We access only the information necessary to deliver the Services requested by the Customer and only within the permissions granted by the Customer.

5.  HOW WE COLLECT INFORMATION

We collect information directly from you, from your organization, through your use of our website and Platform, through customer support interactions, during demonstrations and onboarding, through webinars and events, through surveys and feedback, through cookies and similar technologies, through authorized Third-Party Integrations, and through automated system logs generated during the operation of our Platform. We do not intentionally collect information that is unrelated to the provision of our Services.

6.  HOW WE USE INFORMATION

CyRAACS uses information for legitimate business purposes associated with operating our website and delivering our Services, strictly limited to the purposes for which it was collected or a purpose reasonably compatible with it. We may use information to:

  • provide and manage our Services;
  • create and administer customer accounts;
  • authenticate users;
  • enable Third-Party Integrations;
  • perform cybersecurity assessments;
  • facilitate compliance monitoring;
  • generate reports and dashboards;
  • provide customer support;
  • respond to enquiries;
  • improve our website and Platform;
  • monitor performance and security;
  • detect unauthorized activities;
  • investigate suspected security incidents;
  • comply with legal and regulatory obligations;
  • communicate service-related updates;
  • conduct training, webinars, and events;
  • improve our products and services; and
  • protect the rights, property, and security of CyRAACS, our Customers, and other users.

We do not sell Personal Information or Customer Data, nor do we use Customer Data for behavioural advertising or unrelated commercial purposes.

Where information has been anonymized or aggregated so that it can no longer reasonably identify an individual or a Customer, we may use such information for research, statistical analysis, product improvement, service enhancement, and cybersecurity trend analysis.

7.  LEGAL BASIS FOR PROCESSING

7.1  Processing under the Digital Personal Data Protection Act, 2023

Where CyRAACS processes Personal Data of Data Principals to whom the DPDPA applies, such processing is carried out only on the following grounds recognized under the DPDPA:

(a) Consent: Where processing is based on the free, specific, informed, unconditional, and unambiguous consent of the Data Principal, given in response to a clear notice. You may withdraw consent at any time, with the same ease with which it was given, subject to applicable legal or contractual requirements; withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.

(b) Certain Legitimate Uses (Section 7, DPDPA): Where the Data Principal has voluntarily provided their Personal Data for a specified purpose and has not indicated that they do not consent to its use (e.g., providing contact details to request a demonstration); where processing is necessary for CyRAACS to perform functions under any law, comply with a judgment or order, respond to a medical emergency, or ensure safety during a disaster; and, in relation to our own personnel, for employment-related purposes, including recruitment, safeguarding the employer against loss, and provision of services or benefits to employees.

CyRAACS does not rely on an open-ended “legitimate interest” ground for Personal Data governed by the DPDPA, as the Act does not recognize such a ground; processing is instead confined to consent or the specific categories of legitimate use set out in Section 7 of the Act.

7.2  Processing under the GDPR / Other International Frameworks

Where CyRAACS processes Personal Data of Data Principals located in the European Economic Area, the United Kingdom, or other jurisdictions whose data protection laws recognize a broader set of lawful bases, we process such Personal Data only where one or more of the following applies: the processing is necessary for the performance of a contract with the Data Principal or their organization; the processing is necessary for compliance with a legal obligation; the processing is based on the Data Principal’s freely given consent; or the processing is necessary for CyRAACS’s legitimate interests (such as maintaining platform security or improving our Services), provided such interests are not overridden by the Data Principal’s rights and freedoms.

8.  SHARING AND DISCLOSURE OF INFORMATION

CyRAACS respects the confidentiality of the information entrusted to us. We do not sell, rent, or trade Personal Information or Customer Data. We may disclose information only in the following circumstances:

8.1  Service Providers / Data Processors

We may engage trusted third-party service providers to assist us in operating our website and delivering our Services, including cloud hosting providers, infrastructure providers, customer support providers, communication service providers, payment processors, analytics providers, and other vendors necessary for the operation of our business. Such service providers are granted access only to the information reasonably necessary to perform their services on our behalf, are bound by written confidentiality and data processing terms, and are required to maintain appropriate confidentiality, privacy, and security standards.

8.2  Legal and Regulatory Requirements

We may disclose information where required by applicable law, regulation, court order, governmental authority, or other lawful process. Where legally permissible, we may notify the affected Customer before making such disclosure.

8.3  Protection of Rights

We may disclose information where reasonably necessary to protect the security and integrity of our website or Platform; investigate suspected fraud, misuse, or unlawful activities; enforce our agreements; respond to cybersecurity incidents; protect the rights, property, or safety of CyRAACS, our Customers, or third parties; or comply with legal or regulatory obligations.

8.4  Corporate Transactions

If CyRAACS is involved in a merger, acquisition, corporate restructuring, financing transaction, or sale of all or substantially all of its business or assets, information may be transferred as part of that transaction, subject to appropriate confidentiality and legal safeguards.

8.5  With Your Consent

We may disclose information where you have expressly authorised us to do so or where such disclosure is made at your request.

9.  THIRD-PARTY INTEGRATIONS

The CyRAACS Platform is designed to integrate with third-party cloud services, enterprise applications, identity providers, security tools, compliance platforms, and other technology solutions to enable automation and improve the delivery of our cybersecurity services. These integrations are established only with the authorization of the Customer.

Where a Customer authorizes an integration, CyRAACS will access only the information necessary to provide the requested Services; use the permissions granted solely for the purposes authorized by the Customer; implement reasonable safeguards to protect integration credentials and associated information; and process information in accordance with this Privacy Policy and applicable contractual commitments.

Customers remain responsible for managing and controlling the permissions granted to Third-Party Integrations. Third-party platforms integrated with the CyRAACS Platform are governed by their own privacy policies and terms of use. CyRAACS is not responsible for the privacy or security practices of such third-party services.

10.  DATA SECURITY

Protecting Customer Data and Personal Information is fundamental to the Services provided by CyRAACS. We implement administrative, technical, and organizational measures designed to protect information against unauthorized access, disclosure, alteration, loss, misuse, or destruction, informed by recognized industry frameworks and standards, including ISO/IEC 27001 and SOC 2 principles, to the extent applicable to our operations.

Our security measures may include:

  • encryption of data in transit using industry-standard protocols;
  • encryption of data at rest where appropriate;
  • role-based access controls and the principle of least privilege;
  • secure authentication mechanisms, including multi-factor authentication where applicable;
  • continuous monitoring of our Platform;
  • vulnerability assessments and security testing;
  • secure software development and change management practices;
  • audit logging and access monitoring;
  • regular backups and disaster recovery procedures; and
  • periodic review and enhancement of our security controls.

Access to Customer Data is restricted to authorized personnel who require such access to perform their assigned responsibilities and who are subject to appropriate confidentiality obligations.

While we take reasonable steps to protect the information entrusted to us, no method of electronic transmission or storage is completely secure. Accordingly, we cannot guarantee absolute security, and Customers should also implement appropriate safeguards within their own environments.

11.  DATA RETENTION

CyRAACS retains Personal Information and Customer Data only for as long as necessary to fulfil the purposes described in this Privacy Policy, comply with applicable legal obligations, resolve disputes, enforce our agreements, and support legitimate business operations.

The period for which information is retained depends on factors including the nature of the information; the purpose for which it was collected; applicable legal and regulatory requirements; contractual obligations; and legitimate business needs.

When information is no longer required, we take reasonable steps to securely delete, anonymize, or otherwise dispose of such information in accordance with our internal retention practices and applicable law, including any retention-period erasure obligations under the DPDPA where applicable.

12.  INTERNATIONAL DATA TRANSFERS

CyRAACS may process or permit the processing of information in jurisdictions other than the country in which you or your organization is located, where such processing is necessary to provide the Services.

Transfers of Personal Data Outside India: Under the DPDPA, CyRAACS may transfer Personal Data outside India to any country or territory, except where such transfer is restricted by the Central Government of India by notification. CyRAACS monitors such notifications and will not transfer Personal Data to a restricted jurisdiction in contravention of applicable law, and any cross-border transfer will remain subject to the terms of any applicable contract between CyRAACS and the Data Principal or the relevant Customer.

Transfers of EU/UK Personal Data: Where CyRAACS transfers Personal Data originating from the European Economic Area or the United Kingdom to a jurisdiction not deemed to provide an adequate level of protection, we implement appropriate safeguards, such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, or rely on another lawful transfer mechanism recognized under the GDPR or UK GDPR, as applicable.

13.  YOUR PRIVACY RIGHTS

Depending on your jurisdiction and the applicable privacy laws, you may have certain rights in relation to your Personal Information, including the right to:

  • request access to the Personal Information we hold about you;
  • request correction or updating of inaccurate or incomplete Personal Information;
  • request erasure of your Personal Information, subject to applicable legal or contractual requirements;
  • request restriction of the processing of your Personal Information in certain circumstances;
  • object to the processing of your Personal Information where permitted by law;
  • withdraw your consent at any time, with the same ease with which it was given, where processing is based on consent;
  • nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity;
  • request a copy of your Personal Information in a portable format, where applicable; and
  • lodge a complaint with the Data Protection Board of India, or the appropriate regulatory or supervisory authority in your jurisdiction, if you believe your privacy rights have been infringed.

Where CyRAACS processes Personal Information solely on behalf of a Customer as a Data Processor, requests relating to such information should ordinarily be directed to the relevant Customer, who acts as the Data Fiduciary and determines the purposes and means of processing such information; CyRAACS will provide reasonable assistance to the Customer in responding to such requests.

We will acknowledge and respond to privacy-related requests within a reasonable period, and in any event within the timelines prescribed under applicable law.

14.  COOKIES AND WEBSITE TECHNOLOGIES

The CyRAACS website may use cookies, web beacons, session identifiers, and similar technologies to improve the functionality, security, and performance of our website. These technologies help us to remember user preferences and settings; maintain secure user sessions; understand how visitors use our website; improve website functionality and user experience; analyse website traffic and performance; and enhance the security of our website.

Some cookies are essential for the operation of our website, while others are used to improve performance or provide analytical insights. You may configure your browser settings to refuse or manage cookies; however, disabling certain cookies may affect the functionality or performance of our website. Where required by applicable law, we will obtain your consent before placing non-essential cookies on your device, and will provide a mechanism for you to manage your cookie preferences.

15.  CHILDREN’S PRIVACY

The Services provided by CyRAACS are intended for businesses and organizations and are not directed towards children. CyRAACS does not knowingly collect Personal Data directly from children (individuals below the age of 18 years, as defined under the DPDPA) through our website or Services.

In the limited circumstances where CyRAACS may process the Personal Data of a child (for example, incidentally through Customer Data uploaded to the Platform), we will, to the extent required under the DPDPA: process such data only with the verifiable consent of the parent or lawful guardian; not undertake tracking or behavioural monitoring of children; and not carry out targeted advertising directed at children.

If we become aware that Personal Data relating to a child has been collected without appropriate verifiable parental or guardian consent, we will take reasonable steps to delete such information in accordance with applicable law. Parents or legal guardians who believe that a child has provided Personal Data to CyRAACS may contact us using the details set out in Clause 18 (Grievance Officer and Contact Details) below.

16.  THIRD-PARTY WEBSITES

Our website may contain links to third-party websites, applications, or online services for your convenience or information. CyRAACS does not own or control such third-party websites and is not responsible for their privacy practices, security, content, or policies. Your use of any third-party website is subject to the privacy policy and terms of use published by the relevant third party, and we encourage you to review those policies before providing any information.

17.  PERSONAL DATA BREACH NOTIFICATION

In the event of a Personal Data Breach, CyRAACS will take prompt and reasonable steps to contain, investigate, and remediate the breach.

Where CyRAACS acts as a Data Fiduciary in respect of the affected Personal Data, we will notify the Data Protection Board of India and the affected Data Principal(s) in the manner and within the timelines prescribed under the DPDPA, providing a description of the breach, its likely consequences, and the measures taken or proposed to be taken to mitigate its effects.

Where CyRAACS acts as a Data Processor in respect of the affected Personal Data (that is, where the breach involves Customer Data processed on a Customer’s behalf), CyRAACS will notify the affected Customer without undue delay upon becoming aware of the breach, and will provide reasonable cooperation and information to enable the Customer to fulfil its own notification obligations as Data Fiduciary.

18.  GRIEVANCE OFFICER AND CONTACT DETAILS

In accordance with the DPDPA, CyRAACS has designated a Grievance Officer to address questions, requests, and grievances relating to this Privacy Policy and the processing of Personal Data.

Grievance Officer: Mr. Murari Shanker

Designation: Co- Founder & COO

Email: [email protected]

Address: 5th Floor, Commerce Mantri 12, 1 & 2, Bannerghatta Road BTM Layout 2nd Stage Bengaluru, Karnataka 560076

Data Principals may direct privacy-related queries, requests, or grievances to the Grievance Officer using the contact details above. We will endeavour to acknowledge and resolve such grievances within the timelines prescribed under applicable law. If you are not satisfied with our response, you may escalate your grievance to the Data Protection Board of India or the appropriate supervisory authority in your jurisdiction.

19.  CHANGES TO THIS PRIVACY POLICY

CyRAACS may update this Privacy Policy from time to time to reflect changes in our practices, Services, or applicable law. Where changes are material, we will provide reasonable notice, such as by posting a notice on our website or, where appropriate, notifying Customers directly, prior to the change taking effect. The “Effective Date” at the top of this Policy indicates when it was last revised. We encourage you to review this Policy periodically.

20.  GOVERNING LAW

This Privacy Policy shall be governed by and construed in accordance with the laws of India. Any disputes arising out of or in connection with this Privacy Policy shall be subject to the jurisdiction of the courts at Bengaluru, Karnataka, India, without prejudice to any rights a Data Principal may have to approach the Data Protection Board of India or another competent regulatory authority.