Privacy Policy
How we collect, use, share, and protect personal data across our website, our services, and the VERIFI, SecuraGPT, and SecuraGPT Browser Guard platforms.
Who We Are
Pragya Cyber Pvt. Ltd. is a cybersecurity services and products company incorporated in India. We also operate through Pragya Inc., our United States affiliate. Together, we provide security assessments, compliance services, managed security, training, staffing, and the VERIFI and SecuraGPT SaaS platforms.
Pragya Cyber Pvt. Ltd. is the data controller for personal data collected through our website and in delivering our services. Where we process personal data for a client organisation through VERIFI, SecuraGPT, or SecuraGPT Browser Guard, we act as a data processor under that client’s instructions and applicable Data Processing Agreement.
Data Protection Officer: While we are not currently required to appoint a statutory DPO, we have designated a privacy contact who oversees our data protection compliance. Contact: privacy@pragyacyber.com.
Scope
This Privacy Policy applies to:
- Visitors to our website at www.pragyacyber.com
- Prospective clients who contact us or request proposals
- Clients and their employees or any authorised users who engage our services or use our platforms (VERIFI, SecuraGPT, SecuraGPT Browser Guard Chrome extension)
- Candidates who apply for roles at Pragya Cyber
- Attendees of our training programmes, webinars, and events
- Partners, resellers, and referral contacts
This Policy does not apply to personal data processed by our clients using the VERIFI or SecuraGPT platforms for their own purposes — such processing is governed by the client’s own privacy policy and our Data Processing Agreement. Client organisations remain responsible for their own privacy notices and lawful basis when their employees or other users submit data to VERIFI, SecuraGPT, or Browser Guard.
| Jurisdiction | Applicable framework |
|---|---|
| 🇮🇳 India | Digital Personal Data Protection Act, 2023 (DPDPA) · IT Act, 2000 |
| 🇺🇸 United States | State privacy laws (CCPA/CPRA for California residents) · sector-specific regulations |
| 🇬🇧 United Kingdom | UK GDPR · Data Protection Act 2018 |
| 🌍 Middle East | UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection · applicable national laws |
Information We Collect
3.1 Information You Provide
| Category | What We Collect | How Collected |
|---|---|---|
| Contact Information | Name, job title, company name, work email address, phone number | Contact forms, email enquiries, meeting bookings, event registrations |
| Account Information | Username, email, password (hashed), organisation details, role | VERIFI / SecuraGPT platform registration |
| Engagement Information | Scope documents, system details, IP ranges, credentials provided for testing, NDA details | Onboarding for security assessment engagements |
| Payment Information | Billing contact details, bank or card details (processed via payment gateway — not stored by us), GST/tax identification number | Invoicing and payment processing |
| Communications | Email correspondence, support tickets, meeting notes | Email, platform support channels |
| Job Applications | CV/résumé, work history, educational background, skills, references | Job application forms, recruitment platforms |
3.2 Information Collected Automatically
| Category | What We Collect |
|---|---|
| Usage Data | Pages visited, features accessed, time and duration of visits, click-through paths, error logs |
| Device & Technical Data | IP address, browser type and version, operating system, device type, screen resolution, referral source |
| Platform Activity Logs | Login events, scan requests, report downloads, configuration changes, API calls (for VERIFI and SecuraGPT users) |
| Cookies & Trackers | Session cookies, analytics cookies, preference cookies — see Section 10 |
3.3 Information from Third Parties
- Business contact details from LinkedIn or professional directories when researching prospects
- Referral information from channel partners or existing clients
- Publicly available information (e.g., company registration data, published contact details) for sales and marketing purposes
3.4 SecuraGPT Browser Guard
Browser Guard is a Chrome extension that helps authorised SecuraGPT users prevent sensitive information in prompts and supported document attachments from reaching supported AI chat services. Its single purpose is to apply the user’s organisation-configured protection policy before the user submits content to a supported AI service.
Data processed locally in the browser. Browser Guard processes prompts and supported attachment content locally to detect sensitive information. This can include personal identifiers, financial information, authentication information and secrets, personal communications, IP-address values, and other website content that a user places in a prompt or supported attachment. It may therefore process health information or other sensitive content if a user includes it. The extension does not transmit raw prompt text, document text, attachment names, file contents, paths, hashes, MIME types, or matched sensitive values to Pragya Cyber.
Supported attachments. The extension can scan supported text files and extract text locally from PDF, Word, Excel, and PowerPoint files. It processes the selected file only to provide the protection feature. If policy permits, the user’s browser submits the file directly to the AI service the user selected; Browser Guard does not independently transfer the raw file to Pragya Cyber.
Account, configuration, and local storage. Browser Guard handles the signed-in user’s name, email, user and organisation identity, a short-lived SecuraGPT authentication session, an organisation’s protection configuration, a random installation identifier, and the latest local protection notice. The session is stored in browser session storage. The configuration, installation identifier, and latest protection notice are stored in browser-local extension storage. The local notice contains only the AI-service name, action, category names, match count, source, scan status/reason, and timestamp—not raw protected content or matched values.
Metadata telemetry. If the client organisation enables Browser Guard telemetry, Browser Guard sends authenticated, metadata-only activity to SecuraGPT. This may include the supported AI-service name; protection action; sensitive-data category names; match count; risk level; attachment count; scan status or scan-failure reason; and installation identifier. SecuraGPT associates that metadata with the authenticated user and organisation to provide authorised Browser Guard reporting, security monitoring, reliability, and support. It does not receive raw prompts, document contents, attachment names, or matched values from Browser Guard.
Browsing activity. Browser Guard operates only on specifically supported AI-service domains and records only the service and protection-event time when telemetry is enabled. It does not create or retain a general browsing-history list, page titles, or visited URLs. Its tabs access is used only to create, find, focus, and reuse a SecuraGPT sign-in tab.
AI services. A user may choose to submit content to a supported AI service only after Browser Guard has applied the organisation’s policy. That AI service receives the content directly from the user’s browser and handles it under its own privacy policy. Browser Guard is not affiliated with, endorsed by, or sponsored by those AI services.
3.5 Sensitive Data
We do not intentionally collect raw sensitive personal data (such as health data, biometric data, or data about religious or political beliefs) from any of our platforms (VERIFI, SecuraGPT, SecuraGPT Browser Guard). Browser Guard may locally process sensitive content because that is necessary to identify it before it is sent to an AI service; such raw content remains in the browser and is not sent to Pragya Cyber.
If any such data is inadvertently shared with us, we will delete it promptly. In the context of security assessments, client systems may contain personal data — our access to this is strictly within the agreed engagement scope and is treated as client confidential information.
How We Use Information
| Purpose | Information Used | Basis |
|---|---|---|
| Delivering contracted services and engagements | Contact info, engagement details, system credentials (where provided) | Contract performance |
| Operating and improving VERIFI and SecuraGPT platforms | Account data, usage logs, platform activity | Contract performance; legitimate interests |
| Invoicing and payment processing | Contact info, billing details, tax information | Contract performance; legal obligation |
| Responding to enquiries and providing support | Contact info, communication history | Legitimate interests; pre-contractual steps |
| Marketing and communications | Contact info, engagement history, preferences | Consent; legitimate interests (B2B) |
| Security monitoring and fraud prevention | Usage logs, IP addresses, access records | Legitimate interests; legal obligation |
| Legal compliance and audit | All relevant personal data | Legal obligation |
| Recruitment and talent management | CV, work history, interview notes | Consent; legitimate interests |
| Analytics and service improvement | Aggregated, anonymised usage data | Legitimate interests |
For Browser Guard, we use local prompt and attachment processing solely to provide the protection feature. We use telemetry only when enabled by the client organisation to provide Browser Guard activity reporting, measure feature reliability and security, investigate incidents or support requests, and improve the directly related protection feature.
We do not sell your personal data. We do not share personal data with third parties for their own marketing purposes. We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
Legal Basis
We process personal data only where we have a lawful basis to do so. Our primary legal bases are:
- Contract performance: Where processing is necessary to deliver services you have engaged us for, or to take steps at your request before entering a contract.
- Legitimate interests: Where we have a genuine business interest that is not overridden by your rights — for example, fraud prevention, network and information security, direct marketing to existing business contacts, and improving our services.
- Legal obligation: Where processing is required to comply with applicable law, such as tax reporting, audit obligations, or responding to lawful requests from authorities.
- Consent: Where you have given clear, specific consent — for example, subscribing to our newsletter, accepting non-essential cookies, or providing information as a job applicant. You may withdraw consent at any time.
For processing of personal data of individuals in the EU/UK, our legal bases under the UK GDPR / EU GDPR are as set out above. For Indian data principals, our processing is in accordance with the Digital Personal Data Protection Act, 2023.
Sharing and Transfers
We do not sell, rent, or trade personal data. We share personal data only in the following limited circumstances:
6.1 Service Providers (Data Processors)
We engage trusted third-party vendors to support our operations. These vendors act as data processors under our instructions and are contractually bound to protect personal data:
| Provider category | Provider | Purpose |
|---|---|---|
| Cloud infrastructure | Amazon Web Services (AWS) | Platform hosting, storage, compute |
| Email & communications | Zoho Workspace | Email delivery and business communications |
| CRM & sales | Zoho CRM | Contact management, marketing automation |
| Analytics | Google Analytics (anonymised) | Website analytics |
| Security tools | Threat intelligence and scan data providers | Delivering ERA and CloudGuard assessments |
6.2 Affiliated Entities
We may share personal data between Pragya Cyber Pvt. Ltd. (India) and Pragya Inc. (USA) for the purpose of delivering cross-border services. Both entities are bound by the same data protection standards described in this Policy.
6.3 Legal Requirements
We may disclose personal data if required to do so by applicable law, court order, or lawful request from a government or regulatory authority. Where permitted, we will notify the relevant individual before disclosure.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction. We will notify affected individuals and ensure the receiving party is bound by equivalent privacy protections.
6.5 With Your Consent
We may share your information for other purposes where you have given us explicit consent to do so, such as publishing a case study or testimonial with your approval.
6.6 Chrome Web Store Limited Use
SecuraGPT Browser Guard’s use of user data complies with the Chrome Web Store User Data Policy, including the Limited Use requirements. We limit Browser Guard data use to its disclosed protection purpose and related security, reliability, and support operations.
International Transfers
As a company operating across India, the US, and the UK, personal data may be transferred between these jurisdictions in the course of delivering services. We take the following steps to ensure such transfers are lawful and protected:
- India ↔ US: Transfers between Pragya Cyber Pvt. Ltd. and Pragya Inc. are governed by an intra-group data transfer agreement ensuring equivalent protection.
- India → UK/EU: Where personal data of UK or EU data subjects is processed in India, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as applicable.
- Cloud infrastructure: AWS processes data in regions agreed with clients. For UK/EU data subjects, we configure AWS to use EU or UK regions wherever possible.
- Your rights regarding international transfers: You have the right to request information about the safeguards we have in place for international transfers of your personal data. Contact privacy@pragyacyber.com for details.
Retention
We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law. Our key retention periods are:
| Data Category | Retention Period | Reason |
|---|---|---|
| Client contact & engagement data | Duration of engagement + 7 years | Legal obligation (tax, audit); dispute resolution |
| Security assessment reports & findings | Duration of engagement + 12 months | Client reference; retest baseline; then securely deleted or returned |
| VERIFI / SecuraGPT platform data | Active subscription + 12 months after termination | Trend analysis; then securely deleted on request |
| Platform access & audit logs | 12 months | Security monitoring; incident investigation |
| Marketing & communications data | Until consent withdrawn or 3 years of inactivity | Consent-based; legitimate interests |
| Job applicant data (unsuccessful) | 6 months after decision | Future opportunities (with consent); legal compliance |
| Financial & billing records | 8 years | Tax and statutory obligations under Indian Companies Act |
| Website analytics (aggregated) | 26 months | Service improvement; standard analytics retention |
Browser Guard does not retain raw prompt or attachment content at Pragya Cyber because it does not receive it.
On expiry of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be linked to an individual.
Security
As a cybersecurity company, we apply the same rigour to protecting personal data that we apply to our clients’ systems. Our technical and organisational security measures include:
- Encryption: AES-256 encryption at rest for all stored data; TLS 1.3 encryption in transit for all data transfers
- Access control: Role-based access control (RBAC); multi-factor authentication (MFA) mandatory for all staff and platform users; principle of least privilege enforced
- Tenant isolation: Separate database per client tenancy on VERIFI and SecuraGPT platforms; row-level security enforced at the database layer
- Network security: VPC isolation; dedicated security assessment VPC separate from application infrastructure; internal-only MCP server endpoints
- Secrets management: Credentials stored in HashiCorp Vault or AWS Secrets Manager — never in application databases
- Monitoring & logging: Comprehensive audit logging of all privileged actions; security event monitoring with alerting; distributed tracing across platform services
- Annual penetration testing: VERIFI and SecuraGPT platforms are penetration tested annually or after major releases
- Staff training: All staff complete security awareness training; personnel handling personal data are bound by confidentiality obligations
For Browser Guard, local scanning occurs in the extension on supported AI-service pages. The extension sends only authenticated metadata to SecuraGPT over HTTPS when telemetry is enabled. It limits access to supported AI-service domains and the configured SecuraGPT service origins. Browser Guard does not load remotely hosted executable code in its production package.
9.1 Data Breach Response
In the event of a personal data breach, we will assess the risk and, where required by applicable law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach (UK GDPR / EU GDPR requirement) or within the timeframe required by applicable Indian and other national law. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay.
To report a suspected security incident or data breach, contact: security@pragyacyber.com
Cookies and Similar Technologies
Our website uses cookies and similar technologies to operate correctly, understand how visitors use the site, and improve your experience. We categorise our cookies as follows:
| Category | Purpose | Consent Required? |
|---|---|---|
| Strictly Necessary | Essential for the website to function — session management, security, load balancing. Cannot be disabled. | No |
| Functional | Remember your preferences (language, region, cookie consent settings). | No |
| Analytics | Understand how visitors interact with our site (page views, traffic sources, user journeys). Data is anonymised and aggregated (Google Analytics). | Yes |
| Marketing | Track effectiveness of marketing campaigns; LinkedIn Insight Tag for B2B audience insights. | Yes |
You can manage your cookie preferences through our cookie banner on first visit, or by adjusting your browser settings at any time. Disabling analytics cookies does not affect your ability to use our website or services.
Platform cookies: The VERIFI and SecuraGPT platforms use session cookies necessary for authentication and security. These are strictly necessary cookies and do not require separate consent. Browser Guard uses Chrome extension storage, not website analytics or marketing cookies.
Your Privacy Rights
Depending on your location, you have the following rights over your personal data. We will respond to any rights request within 30 days (or within the timeframe required by applicable law).
| Right | What It Means | Jurisdictions |
|---|---|---|
| Right of Access | Obtain a copy of the personal data we hold about you and information about how we use it. | India · UK · US (CA) · UAE |
| Right to Correction | Request that we correct inaccurate or incomplete personal data. | India · UK · US (CA) · UAE |
| Right to Erasure | Request deletion of your personal data where there is no compelling reason for us to continue processing it. | India · UK · UAE |
| Right to Restrict Processing | Ask us to pause processing of your data in certain circumstances, e.g., while a dispute is resolved. | UK |
| Right to Data Portability | Receive your personal data in a structured, machine-readable format to transfer to another provider. | UK |
| Right to Object | Object to processing based on legitimate interests, including direct marketing. | UK |
| Right to Withdraw Consent | Where processing is based on consent, withdraw that consent at any time without affecting prior processing. | All jurisdictions |
| Right to Grievance Redressal | Lodge a grievance with our privacy contact and receive a response within the timeframe prescribed by applicable law. | India (DPDPA) |
| Right to Opt-Out of Sale | Opt out of the sale or sharing of personal data (note: we do not sell personal data). | US (CA) — CCPA/CPRA |
11.1 How to Exercise Your Rights
To exercise any of these rights, submit a written request to privacy@pragyacyber.com with sufficient detail to identify yourself and the specific right you wish to exercise. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests.
Some rights are subject to exceptions — for example, we may be unable to delete data that we are required by law to retain, or data that is necessary to fulfil a contractual obligation. We will explain any applicable exceptions when responding to your request.
Children’s Privacy
Our services and platforms are intended for use by business organisations and adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that personal data of a child has been collected without appropriate parental consent, we will delete it promptly.
If you believe a child has provided us with personal data, please contact us at privacy@pragyacyber.com.
Third-Party Services
Our website and platform may contain links to third-party websites, tools, or services (such as LinkedIn, partner portals, or integrated security tools). We are not responsible for the privacy practices of those third parties. We encourage you to read the privacy policy of any third-party site or service you access.
VERIFI and SecuraGPT may offer integrations with third-party tools such as Slack, Jira, and cloud providers. When you enable an integration, you authorise Pragya Cyber to exchange data with that third-party service within the scope of the integration. The third party’s privacy policy applies to their handling of any data received.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our data practices, our services, or applicable law. We will post the updated Policy on our website.
For material changes — particularly those that reduce your rights or expand how we use your personal data — we will provide at least 30 days’ advance notice by email to registered users before the changes take effect. Your continued use of our services following notice of changes constitutes acceptance of the updated Policy.
Previous versions of this Privacy Policy are available on request by contacting privacy@pragyacyber.com.
Contact and Complaints
If you have any questions about this Privacy Policy, wish to exercise your rights, or have a concern about our data practices, please contact us:
| Contact | Details |
|---|---|
| Privacy Contact — Pragya Cyber Pvt. Ltd. | privacy@pragyacyber.com |
| Security incidents | security@pragyacyber.com |
| General contact | hello@pragyacyber.com |
| Website | www.pragyacyber.com |
15.1 Supervisory Authority Complaints
If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant supervisory authority:
- India: Data Protection Board of India (once constituted under the DPDPA, 2023)
- United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
- European Union: Your local EU Data Protection Authority
- United States (California): California Privacy Protection Agency (CPPA)
We would always appreciate the opportunity to address your concern directly before you approach a supervisory authority.
