Privacy Policy

1. About Elytra Security

Elytra Security Pvt Ltd (“Elytra”, “we”, “our”, “us”) is an information-security company headquartered at 7th Floor, Kirloskar Tech Park, Hebbal Kempapura, Bengaluru, Karnataka 560024. For the purposes of the Digital Personal Data Protection Act, 2023 (DPDPA) we are the Data Fiduciary for personal data collected through:

  • elytrasecurity.com and its sub-domains
  • Customer portals, demo environments, webinars, events and marketing campaigns
  • Consulting, managed-service and support engagements

Contact: dpo@elytrasecurity.com

2. Key Definitions (DPDPA §2)

Term

Meaning (abridged)

Personal Data (PD)

Data about an individual who is identifiable directly or in combination with other data.

Processing

Any operation (collection, storage, use, transmission, erasure) on PD.

Data Principal

The individual to whom the PD relates (“you”, “your”).

Consent

A clear affirmative action signifying agreement to process PD for a specified purpose.

Legitimate Use

Processing necessary for the performance of a lawful contract or compliance obligation where consent is not practicable.

3. Personal Data We Process

Category

Typical Elements

Source

Identity & Contact

Name, title, org, e-mail, phone, postal address

Web forms, contracts

Professional

Government-issued ID for KYC, designation, skills/certs

Customer onboarding

Usage & Device

IP, browser type, pages visited, event timestamps

Site analytics, product telemetry

Marketing Preferences

Opt-in/opt-out flags, topics of interest

Consent forms

Support Artefacts

Log files, configuration snippets, screenshots

Customer tickets

We do not knowingly collect children’s data; services are strictly business-to-business.

4. Why & How We Use Your Data (DPDPA §4, §7)

Purpose

Lawful Basis

Key Retention Rule

Deliver contracted products & services (e.g., portal access, SOC monitoring)

Contract performance (Legitimate Use)

7 years after contract end (tax & audit requirement)

Account onboarding & KYC

Legal Obligation (RBI / SEBI guidelines)

8 years

Respond to enquiries / demos

Consent

12 months after last interaction

Security monitoring & incident response

Legitimate Use – vital for threat prevention

Until incident closed + 1 year

Marketing emails, newsletters, webinars

Consent (withdrawable anytime)

Until consent withdrawn or 24 months of inactivity

Improving products (analytics & telemetry)

Legitimate Use (minimal, aggregated)

18 months

Logs may be anonymised and retained indefinitely for statistical security research.

5. Disclosures & Sub-Processors

We never sell personal data. Data may be shared with:

  1. Cloud & SaaS hosting providers (ISO 27001/SOC 2 certified, India-or adequate-jurisdiction data centres)
  2. Payment gateways & accounting firms (for invoicing & statutory filings)
  3. Regulators / law-enforcement when legally compelled under written order

A complete up-to-date list of sub-processors is maintained at elytrasecurity.com/sub-processors.

6. Cross-Border Transfers (DPDPA §16)

Personal data is stored primarily in India. Limited transfers to jurisdictions as notified by GoI; contractual safeguards applied, occur for backup and global email delivery. In such cases, standard contractual clauses and equivalent protection measures are applied.

7. Security Measures (DPDPA §8)

  • ISO 27001:2022 aligned ISMS
  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Zero-Trust network segmentation & least-privilege IAM
  • 24 × 7 security-operations monitoring (Elytra Shield+)
  • Regular penetration testing & vulnerability management
  • Supplier security due-diligence programme

8. Your Rights as Data Principal (DPDPA §11)

You have the right to:

  1. Access copies of your personal data
  2. Correct inaccurate or incomplete data
  3. Erase data no longer required or processed unlawfully
  4. Data Portability (where technically feasible, voluntary facility)
  5. Grievance Redressal within defined timelines
  6. Withdraw Consent at any time without detriment
  7. Right to Nominate at any time without detriment

9. How to Exercise Your Rights

Submit a request to privacy@elytrasecurity.com with the subject line “DPDPA Right – [Access / Correction / Erasure / Portability / Withdrawal]”.

We will acknowledge within 48 hours and fulfil or formally respond within 7 working days (complex cases: ≤ 15 days). Identification proof may be requested to validate your identity.

10. Consent Withdrawal (Illustrative Form)

You may withdraw marketing or service-specific consent via:

  • Online Preference Centre: elytrasecurity.com/withdraw
  • Email: privacy@elytrasecurity.com
  • Postal: Data Protection Officer, Elytra Security Pvt Ltd, 7th Floor, Kirloskar Tech Park, Hebbal Kempapura, Bengaluru, Karnataka 560024

Minimum fields required: name, business email, consents to revoke, optional comment.
Upon validation your data is flagged “Restricted – Consent Withdrawn” in 24 hours and purged from marketing systems in ≤ 5 days (back-ups overwritten by retention cycle).

11. Grievance Redressal Officer

Name: Venkat Mangudi, CEO
Email: gro@elytrasecurity.com

Unresolved grievances may be escalated to the Data Protection Board of India as per DPDPA rules.

12. Cookies & Tracking

We use:

  • Strictly Necessary Cookies – session, CSRF, load-balancer IDs
  • Analytics Cookies – self-hosted Matomo (aggregated, IP-truncated)
  • Marketing Tags – LinkedIn Insight (opt-in)

See our Cookie Notice for granular controls. Consent choices are honoured for at least 12 months unless you clear browser cookies earlier.

13. Changes to This Notice

Material changes will be posted on this page with date-stamp and, where appropriate, notified via email. Continued use of our services after such changes constitutes acknowledgment.

Effective Date: August 8, 2025
Last update: August 8, 2025

14. Contact

Questions about this notice or our privacy practices?