Skip to content Skip to footer

Pragya Cyber · Legal

Privacy Policy

How we collect, use, share, and protect personal data across our website, our services, and the VERIFI, SecuraGPT, and SecuraGPT Browser Guard platforms.

01

Who We Are

Pragya Cyber Pvt. Ltd. is a cybersecurity services and products company incorporated in India. We also operate through Pragya Inc., our United States affiliate. Together, we provide security assessments, compliance services, managed security, training, staffing, and the VERIFI and SecuraGPT SaaS platforms.

Pragya Cyber Pvt. Ltd. is the data controller for personal data collected through our website and in delivering our services. Where we process personal data for a client organisation through VERIFI, SecuraGPT, or SecuraGPT Browser Guard, we act as a data processor under that client’s instructions and applicable Data Processing Agreement.

Data Protection Officer: While we are not currently required to appoint a statutory DPO, we have designated a privacy contact who oversees our data protection compliance. Contact: privacy@pragyacyber.com.

02

Scope

This Privacy Policy applies to:

  • Visitors to our website at www.pragyacyber.com
  • Prospective clients who contact us or request proposals
  • Clients and their employees or any authorised users who engage our services or use our platforms (VERIFI, SecuraGPT, SecuraGPT Browser Guard Chrome extension)
  • Candidates who apply for roles at Pragya Cyber
  • Attendees of our training programmes, webinars, and events
  • Partners, resellers, and referral contacts

This Policy does not apply to personal data processed by our clients using the VERIFI or SecuraGPT platforms for their own purposes — such processing is governed by the client’s own privacy policy and our Data Processing Agreement. Client organisations remain responsible for their own privacy notices and lawful basis when their employees or other users submit data to VERIFI, SecuraGPT, or Browser Guard.

Jurisdiction Applicable framework
🇮🇳 India Digital Personal Data Protection Act, 2023 (DPDPA) · IT Act, 2000
🇺🇸 United States State privacy laws (CCPA/CPRA for California residents) · sector-specific regulations
🇬🇧 United Kingdom UK GDPR · Data Protection Act 2018
🌍 Middle East UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection · applicable national laws

03

Information We Collect

3.1 Information You Provide

Category What We Collect How Collected
Contact Information Name, job title, company name, work email address, phone number Contact forms, email enquiries, meeting bookings, event registrations
Account Information Username, email, password (hashed), organisation details, role VERIFI / SecuraGPT platform registration
Engagement Information Scope documents, system details, IP ranges, credentials provided for testing, NDA details Onboarding for security assessment engagements
Payment Information Billing contact details, bank or card details (processed via payment gateway — not stored by us), GST/tax identification number Invoicing and payment processing
Communications Email correspondence, support tickets, meeting notes Email, platform support channels
Job Applications CV/résumé, work history, educational background, skills, references Job application forms, recruitment platforms

3.2 Information Collected Automatically

Category What We Collect
Usage Data Pages visited, features accessed, time and duration of visits, click-through paths, error logs
Device & Technical Data IP address, browser type and version, operating system, device type, screen resolution, referral source
Platform Activity Logs Login events, scan requests, report downloads, configuration changes, API calls (for VERIFI and SecuraGPT users)
Cookies & Trackers Session cookies, analytics cookies, preference cookies — see Section 10

3.3 Information from Third Parties

  • Business contact details from LinkedIn or professional directories when researching prospects
  • Referral information from channel partners or existing clients
  • Publicly available information (e.g., company registration data, published contact details) for sales and marketing purposes

3.4 SecuraGPT Browser Guard

Browser Guard is a Chrome extension that helps authorised SecuraGPT users prevent sensitive information in prompts and supported document attachments from reaching supported AI chat services. Its single purpose is to apply the user’s organisation-configured protection policy before the user submits content to a supported AI service.

Data processed locally in the browser. Browser Guard processes prompts and supported attachment content locally to detect sensitive information. This can include personal identifiers, financial information, authentication information and secrets, personal communications, IP-address values, and other website content that a user places in a prompt or supported attachment. It may therefore process health information or other sensitive content if a user includes it. The extension does not transmit raw prompt text, document text, attachment names, file contents, paths, hashes, MIME types, or matched sensitive values to Pragya Cyber.

Supported attachments. The extension can scan supported text files and extract text locally from PDF, Word, Excel, and PowerPoint files. It processes the selected file only to provide the protection feature. If policy permits, the user’s browser submits the file directly to the AI service the user selected; Browser Guard does not independently transfer the raw file to Pragya Cyber.

Account, configuration, and local storage. Browser Guard handles the signed-in user’s name, email, user and organisation identity, a short-lived SecuraGPT authentication session, an organisation’s protection configuration, a random installation identifier, and the latest local protection notice. The session is stored in browser session storage. The configuration, installation identifier, and latest protection notice are stored in browser-local extension storage. The local notice contains only the AI-service name, action, category names, match count, source, scan status/reason, and timestamp—not raw protected content or matched values.

Metadata telemetry. If the client organisation enables Browser Guard telemetry, Browser Guard sends authenticated, metadata-only activity to SecuraGPT. This may include the supported AI-service name; protection action; sensitive-data category names; match count; risk level; attachment count; scan status or scan-failure reason; and installation identifier. SecuraGPT associates that metadata with the authenticated user and organisation to provide authorised Browser Guard reporting, security monitoring, reliability, and support. It does not receive raw prompts, document contents, attachment names, or matched values from Browser Guard.

Browsing activity. Browser Guard operates only on specifically supported AI-service domains and records only the service and protection-event time when telemetry is enabled. It does not create or retain a general browsing-history list, page titles, or visited URLs. Its tabs access is used only to create, find, focus, and reuse a SecuraGPT sign-in tab.

AI services. A user may choose to submit content to a supported AI service only after Browser Guard has applied the organisation’s policy. That AI service receives the content directly from the user’s browser and handles it under its own privacy policy. Browser Guard is not affiliated with, endorsed by, or sponsored by those AI services.

3.5 Sensitive Data

We do not intentionally collect raw sensitive personal data (such as health data, biometric data, or data about religious or political beliefs) from any of our platforms (VERIFI, SecuraGPT, SecuraGPT Browser Guard). Browser Guard may locally process sensitive content because that is necessary to identify it before it is sent to an AI service; such raw content remains in the browser and is not sent to Pragya Cyber.

If any such data is inadvertently shared with us, we will delete it promptly. In the context of security assessments, client systems may contain personal data — our access to this is strictly within the agreed engagement scope and is treated as client confidential information.

04

How We Use Information

Purpose Information Used Basis
Delivering contracted services and engagements Contact info, engagement details, system credentials (where provided) Contract performance
Operating and improving VERIFI and SecuraGPT platforms Account data, usage logs, platform activity Contract performance; legitimate interests
Invoicing and payment processing Contact info, billing details, tax information Contract performance; legal obligation
Responding to enquiries and providing support Contact info, communication history Legitimate interests; pre-contractual steps
Marketing and communications Contact info, engagement history, preferences Consent; legitimate interests (B2B)
Security monitoring and fraud prevention Usage logs, IP addresses, access records Legitimate interests; legal obligation
Legal compliance and audit All relevant personal data Legal obligation
Recruitment and talent management CV, work history, interview notes Consent; legitimate interests
Analytics and service improvement Aggregated, anonymised usage data Legitimate interests

For Browser Guard, we use local prompt and attachment processing solely to provide the protection feature. We use telemetry only when enabled by the client organisation to provide Browser Guard activity reporting, measure feature reliability and security, investigate incidents or support requests, and improve the directly related protection feature.

We do not sell your personal data. We do not share personal data with third parties for their own marketing purposes. We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.

05

Legal Basis

We process personal data only where we have a lawful basis to do so. Our primary legal bases are:

  • Contract performance: Where processing is necessary to deliver services you have engaged us for, or to take steps at your request before entering a contract.
  • Legitimate interests: Where we have a genuine business interest that is not overridden by your rights — for example, fraud prevention, network and information security, direct marketing to existing business contacts, and improving our services.
  • Legal obligation: Where processing is required to comply with applicable law, such as tax reporting, audit obligations, or responding to lawful requests from authorities.
  • Consent: Where you have given clear, specific consent — for example, subscribing to our newsletter, accepting non-essential cookies, or providing information as a job applicant. You may withdraw consent at any time.

For processing of personal data of individuals in the EU/UK, our legal bases under the UK GDPR / EU GDPR are as set out above. For Indian data principals, our processing is in accordance with the Digital Personal Data Protection Act, 2023.

06

Sharing and Transfers

We do not sell, rent, or trade personal data. We share personal data only in the following limited circumstances:

6.1 Service Providers (Data Processors)

We engage trusted third-party vendors to support our operations. These vendors act as data processors under our instructions and are contractually bound to protect personal data:

Provider category Provider Purpose
Cloud infrastructure Amazon Web Services (AWS) Platform hosting, storage, compute
Email & communications Zoho Workspace Email delivery and business communications
CRM & sales Zoho CRM Contact management, marketing automation
Analytics Google Analytics (anonymised) Website analytics
Security tools Threat intelligence and scan data providers Delivering ERA and CloudGuard assessments

6.2 Affiliated Entities

We may share personal data between Pragya Cyber Pvt. Ltd. (India) and Pragya Inc. (USA) for the purpose of delivering cross-border services. Both entities are bound by the same data protection standards described in this Policy.

6.3 Legal Requirements

We may disclose personal data if required to do so by applicable law, court order, or lawful request from a government or regulatory authority. Where permitted, we will notify the relevant individual before disclosure.

6.4 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction. We will notify affected individuals and ensure the receiving party is bound by equivalent privacy protections.

6.5 With Your Consent

We may share your information for other purposes where you have given us explicit consent to do so, such as publishing a case study or testimonial with your approval.

6.6 Chrome Web Store Limited Use

SecuraGPT Browser Guard’s use of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We limit Browser Guard data use to its disclosed protection purpose and related security, reliability, and support operations.

07

International Transfers

As a company operating across India, the US, and the UK, personal data may be transferred between these jurisdictions in the course of delivering services. We take the following steps to ensure such transfers are lawful and protected:

  • India ↔ US: Transfers between Pragya Cyber Pvt. Ltd. and Pragya Inc. are governed by an intra-group data transfer agreement ensuring equivalent protection.
  • India → UK/EU: Where personal data of UK or EU data subjects is processed in India, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as applicable.
  • Cloud infrastructure: AWS processes data in regions agreed with clients. For UK/EU data subjects, we configure AWS to use EU or UK regions wherever possible.
  • Your rights regarding international transfers: You have the right to request information about the safeguards we have in place for international transfers of your personal data. Contact privacy@pragyacyber.com for details.

08

Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law. Our key retention periods are:

Data Category Retention Period Reason
Client contact & engagement data Duration of engagement + 7 years Legal obligation (tax, audit); dispute resolution
Security assessment reports & findings Duration of engagement + 12 months Client reference; retest baseline; then securely deleted or returned
VERIFI / SecuraGPT platform data Active subscription + 12 months after termination Trend analysis; then securely deleted on request
Platform access & audit logs 12 months Security monitoring; incident investigation
Marketing & communications data Until consent withdrawn or 3 years of inactivity Consent-based; legitimate interests
Job applicant data (unsuccessful) 6 months after decision Future opportunities (with consent); legal compliance
Financial & billing records 8 years Tax and statutory obligations under Indian Companies Act
Website analytics (aggregated) 26 months Service improvement; standard analytics retention

Browser Guard does not retain raw prompt or attachment content at Pragya Cyber because it does not receive it.

On expiry of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be linked to an individual.

09

Security

As a cybersecurity company, we apply the same rigour to protecting personal data that we apply to our clients’ systems. Our technical and organisational security measures include:

  • Encryption: AES-256 encryption at rest for all stored data; TLS 1.3 encryption in transit for all data transfers
  • Access control: Role-based access control (RBAC); multi-factor authentication (MFA) mandatory for all staff and platform users; principle of least privilege enforced
  • Tenant isolation: Separate database per client tenancy on VERIFI and SecuraGPT platforms; row-level security enforced at the database layer
  • Network security: VPC isolation; dedicated security assessment VPC separate from application infrastructure; internal-only MCP server endpoints
  • Secrets management: Credentials stored in HashiCorp Vault or AWS Secrets Manager — never in application databases
  • Monitoring & logging: Comprehensive audit logging of all privileged actions; security event monitoring with alerting; distributed tracing across platform services
  • Annual penetration testing: VERIFI and SecuraGPT platforms are penetration tested annually or after major releases
  • Staff training: All staff complete security awareness training; personnel handling personal data are bound by confidentiality obligations

For Browser Guard, local scanning occurs in the extension on supported AI-service pages. The extension sends only authenticated metadata to SecuraGPT over HTTPS when telemetry is enabled. It limits access to supported AI-service domains and the configured SecuraGPT service origins. Browser Guard does not load remotely hosted executable code in its production package.

9.1 Data Breach Response

In the event of a personal data breach, we will assess the risk and, where required by applicable law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach (UK GDPR / EU GDPR requirement) or within the timeframe required by applicable Indian and other national law. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay.

To report a suspected security incident or data breach, contact: security@pragyacyber.com

10

Cookies and Similar Technologies

Our website uses cookies and similar technologies to operate correctly, understand how visitors use the site, and improve your experience. We categorise our cookies as follows:

Category Purpose Consent Required?
Strictly Necessary Essential for the website to function — session management, security, load balancing. Cannot be disabled. No
Functional Remember your preferences (language, region, cookie consent settings). No
Analytics Understand how visitors interact with our site (page views, traffic sources, user journeys). Data is anonymised and aggregated (Google Analytics). Yes
Marketing Track effectiveness of marketing campaigns; LinkedIn Insight Tag for B2B audience insights. Yes

You can manage your cookie preferences through our cookie banner on first visit, or by adjusting your browser settings at any time. Disabling analytics cookies does not affect your ability to use our website or services.

Platform cookies: The VERIFI and SecuraGPT platforms use session cookies necessary for authentication and security. These are strictly necessary cookies and do not require separate consent. Browser Guard uses Chrome extension storage, not website analytics or marketing cookies.

11

Your Privacy Rights

Depending on your location, you have the following rights over your personal data. We will respond to any rights request within 30 days (or within the timeframe required by applicable law).

Right What It Means Jurisdictions
Right of Access Obtain a copy of the personal data we hold about you and information about how we use it. India · UK · US (CA) · UAE
Right to Correction Request that we correct inaccurate or incomplete personal data. India · UK · US (CA) · UAE
Right to Erasure Request deletion of your personal data where there is no compelling reason for us to continue processing it. India · UK · UAE
Right to Restrict Processing Ask us to pause processing of your data in certain circumstances, e.g., while a dispute is resolved. UK
Right to Data Portability Receive your personal data in a structured, machine-readable format to transfer to another provider. UK
Right to Object Object to processing based on legitimate interests, including direct marketing. UK
Right to Withdraw Consent Where processing is based on consent, withdraw that consent at any time without affecting prior processing. All jurisdictions
Right to Grievance Redressal Lodge a grievance with our privacy contact and receive a response within the timeframe prescribed by applicable law. India (DPDPA)
Right to Opt-Out of Sale Opt out of the sale or sharing of personal data (note: we do not sell personal data). US (CA) — CCPA/CPRA

11.1 How to Exercise Your Rights

To exercise any of these rights, submit a written request to privacy@pragyacyber.com with sufficient detail to identify yourself and the specific right you wish to exercise. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests.

Some rights are subject to exceptions — for example, we may be unable to delete data that we are required by law to retain, or data that is necessary to fulfil a contractual obligation. We will explain any applicable exceptions when responding to your request.

12

Children’s Privacy

Our services and platforms are intended for use by business organisations and adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that personal data of a child has been collected without appropriate parental consent, we will delete it promptly.

If you believe a child has provided us with personal data, please contact us at privacy@pragyacyber.com.

13

Third-Party Services

Our website and platform may contain links to third-party websites, tools, or services (such as LinkedIn, partner portals, or integrated security tools). We are not responsible for the privacy practices of those third parties. We encourage you to read the privacy policy of any third-party site or service you access.

VERIFI and SecuraGPT may offer integrations with third-party tools such as Slack, Jira, and cloud providers. When you enable an integration, you authorise Pragya Cyber to exchange data with that third-party service within the scope of the integration. The third party’s privacy policy applies to their handling of any data received.

14

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, our services, or applicable law. We will post the updated Policy on our website.

For material changes — particularly those that reduce your rights or expand how we use your personal data — we will provide at least 30 days’ advance notice by email to registered users before the changes take effect. Your continued use of our services following notice of changes constitutes acceptance of the updated Policy.

Previous versions of this Privacy Policy are available on request by contacting privacy@pragyacyber.com.

15

Contact and Complaints

If you have any questions about this Privacy Policy, wish to exercise your rights, or have a concern about our data practices, please contact us:

Contact Details
Privacy Contact — Pragya Cyber Pvt. Ltd. privacy@pragyacyber.com
Security incidents security@pragyacyber.com
General contact hello@pragyacyber.com
Website www.pragyacyber.com

15.1 Supervisory Authority Complaints

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant supervisory authority:

  • India: Data Protection Board of India (once constituted under the DPDPA, 2023)
  • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
  • European Union: Your local EU Data Protection Authority
  • United States (California): California Privacy Protection Agency (CPPA)

We would always appreciate the opportunity to address your concern directly before you approach a supervisory authority.