Privacy Policy
Who We Are
Pragya Cyber Pvt. Ltd. is a cybersecurity services and products company incorporated in India. We also operate through Pragya Inc., our United States affiliate. Together, we provide security assessments, compliance services, managed security, training, staffing, and two SaaS platforms — VERIFI and SecuraGPT.
For the purposes of data protection law, Pragya Cyber Pvt. Ltd. is the data controller for personal data collected through our website and in the delivery of our services. Where we process personal data on behalf of a client organisation, we act as a data processor under that client’s instructions.
Scope of This Policy
This Privacy Policy applies to:
- Visitors to our website at www.pragyacyber.com
- Prospective clients who contact us or request proposals
- Clients and their employees who engage our services or use our platforms (VERIFI, SecuraGPT)
- Candidates who apply for roles at Pragya Cyber
- Attendees of our training programmes, webinars, and events
- Partners, resellers, and referral contacts
This Policy does not apply to personal data processed by our clients using the VERIFI or SecuraGPT platforms for their own purposes — such processing is governed by the client’s own privacy policy and our Data Processing Agreement.
Information We Collect
3.1 Information You Provide to Us
| Category | What We Collect | How Collected |
|---|---|---|
| Contact Information | Name, job title, company name, work email address, phone number | Contact forms, email enquiries, meeting bookings, event registrations |
| Account Information | Username, email, password (hashed), organisation details, role | VERIFI / SecuraGPT platform registration |
| Engagement Information | Scope documents, system details, IP ranges, credentials provided for testing, NDA details | Onboarding for security assessment engagements |
| Payment Information | Billing contact details, bank or card details (processed via payment gateway — not stored by us), GST/tax identification number | Invoicing and payment processing |
| Communications | Email correspondence, support tickets, meeting notes | Email, platform support channels |
| Job Applications | CV/résumé, work history, educational background, skills, references | Job application forms, recruitment platforms |
3.2 Information We Collect Automatically
| Category | What We Collect |
|---|---|
| Usage Data | Pages visited, features accessed, time and duration of visits, click-through paths, error logs |
| Device & Technical Data | IP address, browser type and version, operating system, device type, screen resolution, referral source |
| Platform Activity Logs | Login events, scan requests, report downloads, configuration changes, API calls (for VERIFI and SecuraGPT users) |
| Cookies & Trackers | Session cookies, analytics cookies, preference cookies — see Section 10 |
3.3 Information from Third Parties
- Business contact details from LinkedIn or professional directories when researching prospects
- Referral information from channel partners or existing clients
- Publicly available information (e.g., company registration data, published contact details) for sales and marketing purposes
3.4 Special Categories of Data
We do not intentionally collect sensitive personal data (such as health data, biometric data, or data about religious or political beliefs). If any such data is inadvertently shared with us, we will delete it promptly. In the context of security assessments, client systems may contain personal data — our access to this is strictly within the agreed engagement scope and is treated as client confidential information.
How We Use Your Information
| Purpose | Information Used | Basis |
|---|---|---|
| Delivering contracted services and engagements | Contact info, engagement details, system credentials (where provided) | Contract performance |
| Operating and improving VERIFI and SecuraGPT platforms | Account data, usage logs, platform activity | Contract performance; legitimate interests |
| Invoicing and payment processing | Contact info, billing details, tax information | Contract performance; legal obligation |
| Responding to enquiries and providing support | Contact info, communication history | Legitimate interests; pre-contractual steps |
| Marketing and communications | Contact info, engagement history, preferences | Consent; legitimate interests (B2B) |
| Security monitoring and fraud prevention | Usage logs, IP addresses, access records | Legitimate interests; legal obligation |
| Legal compliance and audit | All relevant personal data | Legal obligation |
| Recruitment and talent management | CV, work history, interview notes | Consent; legitimate interests |
| Analytics and service improvement | Aggregated, anonymised usage data | Legitimate interests |
Legal Basis for Processing
We process personal data only where we have a lawful basis to do so. Our primary legal bases are:
- Contract performance: Where processing is necessary to deliver services you have engaged us for, or to take steps at your request before entering a contract.
- Legitimate interests: Where we have a genuine business interest that is not overridden by your rights — for example, fraud prevention, network and information security, direct marketing to existing business contacts, and improving our services.
- Legal obligation: Where processing is required to comply with applicable law, such as tax reporting, audit obligations, or responding to lawful requests from authorities.
- Consent: Where you have given clear, specific consent — for example, subscribing to our newsletter, accepting non-essential cookies, or providing information as a job applicant. You may withdraw consent at any time.
For processing of personal data of individuals in the EU/UK, our legal bases under the UK GDPR / EU GDPR are as set out above. For Indian data principals, our processing is in accordance with the Digital Personal Data Protection Act, 2023.
Sharing Your Information
We do not sell, rent, or trade personal data. We share personal data only in the following limited circumstances:
6.1 Service Providers (Data Processors)
We engage trusted third-party vendors to support our operations. These vendors act as data processors under our instructions and are contractually bound to protect personal data:
- Cloud infrastructure: Amazon Web Services (AWS) — platform hosting, storage, compute
- Email & communications: Zoho Workspace — email delivery and business communications
- CRM & sales: Zoho CRM — contact management, marketing automation
- Analytics: Google Analytics (anonymised) — website analytics
- Security tools: Threat intelligence and scan data providers used in delivering ERA and CloudGuard assessments
6.2 Affiliated Entities
We may share personal data between Pragya Cyber Pvt. Ltd. (India) and Pragya Inc. (USA) for the purpose of delivering cross-border services. Both entities are bound by the same data protection standards described in this Policy.
6.3 Legal Requirements
We may disclose personal data if required to do so by applicable law, court order, or lawful request from a government or regulatory authority. Where permitted, we will notify the relevant individual before disclosure.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction. We will notify affected individuals and ensure the receiving party is bound by equivalent privacy protections.
6.5 With Your Consent
We may share your information for other purposes where you have given us explicit consent to do so, such as publishing a case study or testimonial with your approval.
International Data Transfers
As a company operating across India, the US, and the UK, personal data may be transferred between these jurisdictions in the course of delivering services. We take the following steps to ensure such transfers are lawful and protected:
- India ↔ US: Transfers between Pragya Cyber Pvt. Ltd. and Pragya Inc. are governed by an intra-group data transfer agreement ensuring equivalent protection.
- India → UK/EU: Where personal data of UK or EU data subjects is processed in India, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as applicable.
- Cloud infrastructure: AWS processes data in regions agreed with clients. For UK/EU data subjects, we configure AWS to use EU or UK regions wherever possible.
Data Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law. Our key retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Client contact & engagement data | Duration of engagement + 7 years | Legal obligation (tax, audit); dispute resolution |
| Security assessment reports & findings | Duration of engagement + 12 months | Client reference; retest baseline; then securely deleted or returned |
| VERIFI / SecuraGPT platform data | Active subscription + 12 months after termination | Trend analysis; then securely deleted on request |
| Platform access & audit logs | 12 months | Security monitoring; incident investigation |
| Marketing & communications data | Until consent withdrawn or 3 years of inactivity | Consent-based; legitimate interests |
| Job applicant data (unsuccessful) | 6 months after decision | Future opportunities (with consent); legal compliance |
| Financial & billing records | 8 years | Tax and statutory obligations under Indian Companies Act |
| Website analytics (aggregated) | 26 months | Service improvement; standard analytics retention |
On expiry of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be linked to an individual.
Security Measures
As a cybersecurity company, we apply the same rigour to protecting personal data that we apply to our clients’ systems. Our technical and organisational security measures include:
- Encryption: AES-256 encryption at rest for all stored data; TLS 1.3 encryption in transit for all data transfers
- Access control: Role-based access control (RBAC); multi-factor authentication (MFA) mandatory for all staff and platform users; principle of least privilege enforced
- Tenant isolation: Separate database per client tenancy on VERIFI and SecuraGPT platforms; row-level security enforced at the database layer
- Network security: VPC isolation; dedicated security assessment VPC separate from application infrastructure; internal-only MCP server endpoints
- Secrets management: Credentials stored in HashiCorp Vault or AWS Secrets Manager — never in application databases
- Monitoring & logging: Comprehensive audit logging of all privileged actions; security event monitoring with alerting; distributed tracing across platform services
- Annual penetration testing: VERIFI and SecuraGPT platforms are penetration tested annually or after major releases
- Staff training: All staff complete security awareness training; personnel handling personal data are bound by confidentiality obligations
9.1 Data Breach Response
In the event of a personal data breach, we will assess the risk and, where required by applicable law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach (UK GDPR / GDPR requirement) or within the timeframe required by applicable Indian and other national law. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay.
To report a suspected security incident or data breach, contact: security@pragyacyber.com
Cookies & Tracking Technologies
Our website uses cookies and similar technologies to operate correctly, understand how visitors use the site, and improve your experience. We categorise our cookies as follows:
| Category | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Essential for the website to function — session management, security, load balancing. Cannot be disabled. | No |
| Functional | Remember your preferences (language, region, cookie consent settings). | No |
| Analytics | Understand how visitors interact with our site (page views, traffic sources, user journeys). Data is anonymised and aggregated (Google Analytics). | Yes |
| Marketing | Track effectiveness of marketing campaigns; LinkedIn Insight Tag for B2B audience insights. | Yes |
You can manage your cookie preferences through our cookie banner on first visit, or by adjusting your browser settings at any time. Disabling analytics cookies does not affect your ability to use our website or services.
Your Privacy Rights
Depending on your location, you have the following rights over your personal data. We will respond to any rights request within 30 days (or within the timeframe required by applicable law).
| Right | What It Means | Jurisdictions |
|---|---|---|
| Right of Access | Obtain a copy of the personal data we hold about you and information about how we use it. | India · UK · US (CA) · UAE |
| Right to Correction | Request that we correct inaccurate or incomplete personal data. | India · UK · US (CA) · UAE |
| Right to Erasure | Request deletion of your personal data where there is no compelling reason for us to continue processing it. | India · UK · UAE |
| Right to Restrict Processing | Ask us to pause processing of your data in certain circumstances, e.g., while a dispute is resolved. | UK |
| Right to Data Portability | Receive your personal data in a structured, machine-readable format to transfer to another provider. | UK |
| Right to Object | Object to processing based on legitimate interests, including direct marketing. | UK |
| Right to Withdraw Consent | Where processing is based on consent, withdraw that consent at any time without affecting prior processing. | All jurisdictions |
| Right to Grievance Redressal | Lodge a grievance with our privacy contact and receive a response within the timeframe prescribed by applicable law. | India (DPDPA) |
| Right to Opt-Out of Sale | Opt out of the sale or sharing of personal data (note: we do not sell personal data). | US — California (CCPA/CPRA) |
How to Exercise Your Rights
To exercise any of these rights, submit a written request to privacy@pragyacyber.com with sufficient detail to identify yourself and the specific right you wish to exercise. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests.
Children’s Privacy
Our services and platforms are intended for use by business organisations and adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that personal data of a child has been collected without appropriate parental consent, we will delete it promptly.
If you believe a child has provided us with personal data, please contact us at privacy@pragyacyber.com.
Third-Party Links & Integrations
Our website and platform may contain links to third-party websites, tools, or services (such as LinkedIn, partner portals, or integrated security tools). We are not responsible for the privacy practices of those third parties. We encourage you to read the privacy policy of any third-party site or service you access.
VERIFI and SecuraGPT may offer integrations with third-party tools such as Slack, Jira, and cloud providers. When you enable an integration, you authorise Pragya Cyber to exchange data with that third-party service within the scope of the integration. The third party’s privacy policy applies to their handling of any data received.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, our services, or applicable law. We will post the updated Policy on our website and update the “Last updated” date at the top of this page.
For material changes — particularly those that reduce your rights or expand how we use your personal data — we will provide at least 30 days’ advance notice by email to registered users before the changes take effect. Your continued use of our services following notice of changes constitutes acceptance of the updated Policy.
Contact Us & Complaints
If you have any questions about this Privacy Policy, wish to exercise your rights, or have a concern about our data practices, please contact us:
| Privacy enquiries | privacy@pragyacyber.com |
| Security incidents | security@pragyacyber.com |
| General contact | hello@pragyacyber.com |
| Website | www.pragyacyber.com |
Supervisory Authority Complaints
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant supervisory authority:
- India: Data Protection Board of India (once constituted under the DPDPA, 2023)
- United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
- European Union: Your local EU Data Protection Authority
- United States (California): California Privacy Protection Agency (CPPA)
We would always appreciate the opportunity to address your concern directly before you approach a supervisory authority.
