Skip to content Skip to footer

Privacy Policy

Who We Are

Pragya Cyber Pvt. Ltd. is a cybersecurity services and products company incorporated in India. We also operate through Pragya Inc., our United States affiliate. Together, we provide security assessments, compliance services, managed security, training, staffing, and two SaaS platforms — VERIFI and SecuraGPT.

For the purposes of data protection law, Pragya Cyber Pvt. Ltd. is the data controller for personal data collected through our website and in the delivery of our services. Where we process personal data on behalf of a client organisation, we act as a data processor under that client’s instructions.

Data Protection Officer: While we are not currently required to appoint a statutory DPO, we have designated a privacy contact who oversees our data protection compliance. Contact: privacy@pragyacyber.com
02

Scope of This Policy

This Privacy Policy applies to:

  • Visitors to our website at www.pragyacyber.com
  • Prospective clients who contact us or request proposals
  • Clients and their employees who engage our services or use our platforms (VERIFI, SecuraGPT)
  • Candidates who apply for roles at Pragya Cyber
  • Attendees of our training programmes, webinars, and events
  • Partners, resellers, and referral contacts

This Policy does not apply to personal data processed by our clients using the VERIFI or SecuraGPT platforms for their own purposes — such processing is governed by the client’s own privacy policy and our Data Processing Agreement.

🇮🇳
India
Digital Personal Data Protection Act, 2023 (DPDPA) · IT Act, 2000
🇺🇸
United States
State privacy laws (CCPA/CPRA for California residents) · sector-specific regulations
🇬🇧
United Kingdom
UK GDPR · Data Protection Act 2018
🌍
Middle East
UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection · applicable national laws
03

Information We Collect

3.1 Information You Provide to Us

Category What We Collect How Collected
Contact Information Name, job title, company name, work email address, phone number Contact forms, email enquiries, meeting bookings, event registrations
Account Information Username, email, password (hashed), organisation details, role VERIFI / SecuraGPT platform registration
Engagement Information Scope documents, system details, IP ranges, credentials provided for testing, NDA details Onboarding for security assessment engagements
Payment Information Billing contact details, bank or card details (processed via payment gateway — not stored by us), GST/tax identification number Invoicing and payment processing
Communications Email correspondence, support tickets, meeting notes Email, platform support channels
Job Applications CV/résumé, work history, educational background, skills, references Job application forms, recruitment platforms

3.2 Information We Collect Automatically

Category What We Collect
Usage Data Pages visited, features accessed, time and duration of visits, click-through paths, error logs
Device & Technical Data IP address, browser type and version, operating system, device type, screen resolution, referral source
Platform Activity Logs Login events, scan requests, report downloads, configuration changes, API calls (for VERIFI and SecuraGPT users)
Cookies & Trackers Session cookies, analytics cookies, preference cookies — see Section 10

3.3 Information from Third Parties

  • Business contact details from LinkedIn or professional directories when researching prospects
  • Referral information from channel partners or existing clients
  • Publicly available information (e.g., company registration data, published contact details) for sales and marketing purposes

3.4 Special Categories of Data

We do not intentionally collect sensitive personal data (such as health data, biometric data, or data about religious or political beliefs). If any such data is inadvertently shared with us, we will delete it promptly. In the context of security assessments, client systems may contain personal data — our access to this is strictly within the agreed engagement scope and is treated as client confidential information.

04

How We Use Your Information

Purpose Information Used Basis
Delivering contracted services and engagements Contact info, engagement details, system credentials (where provided) Contract performance
Operating and improving VERIFI and SecuraGPT platforms Account data, usage logs, platform activity Contract performance; legitimate interests
Invoicing and payment processing Contact info, billing details, tax information Contract performance; legal obligation
Responding to enquiries and providing support Contact info, communication history Legitimate interests; pre-contractual steps
Marketing and communications Contact info, engagement history, preferences Consent; legitimate interests (B2B)
Security monitoring and fraud prevention Usage logs, IP addresses, access records Legitimate interests; legal obligation
Legal compliance and audit All relevant personal data Legal obligation
Recruitment and talent management CV, work history, interview notes Consent; legitimate interests
Analytics and service improvement Aggregated, anonymised usage data Legitimate interests
We do not sell your personal data. We do not share personal data with third parties for their own marketing purposes. We do not use personal data for automated decision-making that produces legal or similarly significant effects on individuals.
06

Sharing Your Information

We do not sell, rent, or trade personal data. We share personal data only in the following limited circumstances:

6.1 Service Providers (Data Processors)

We engage trusted third-party vendors to support our operations. These vendors act as data processors under our instructions and are contractually bound to protect personal data:

  • Cloud infrastructure: Amazon Web Services (AWS) — platform hosting, storage, compute
  • Email & communications: Zoho Workspace — email delivery and business communications
  • CRM & sales: Zoho CRM — contact management, marketing automation
  • Analytics: Google Analytics (anonymised) — website analytics
  • Security tools: Threat intelligence and scan data providers used in delivering ERA and CloudGuard assessments

6.2 Affiliated Entities

We may share personal data between Pragya Cyber Pvt. Ltd. (India) and Pragya Inc. (USA) for the purpose of delivering cross-border services. Both entities are bound by the same data protection standards described in this Policy.

6.3 Legal Requirements

We may disclose personal data if required to do so by applicable law, court order, or lawful request from a government or regulatory authority. Where permitted, we will notify the relevant individual before disclosure.

6.4 Business Transfers

In the event of a merger, acquisition, or sale of all or part of our business, personal data may be transferred as part of that transaction. We will notify affected individuals and ensure the receiving party is bound by equivalent privacy protections.

6.5 With Your Consent

We may share your information for other purposes where you have given us explicit consent to do so, such as publishing a case study or testimonial with your approval.

07

International Data Transfers

As a company operating across India, the US, and the UK, personal data may be transferred between these jurisdictions in the course of delivering services. We take the following steps to ensure such transfers are lawful and protected:

  • India ↔ US: Transfers between Pragya Cyber Pvt. Ltd. and Pragya Inc. are governed by an intra-group data transfer agreement ensuring equivalent protection.
  • India → UK/EU: Where personal data of UK or EU data subjects is processed in India, we rely on appropriate safeguards including Standard Contractual Clauses (SCCs) or the UK International Data Transfer Agreement (IDTA) as applicable.
  • Cloud infrastructure: AWS processes data in regions agreed with clients. For UK/EU data subjects, we configure AWS to use EU or UK regions wherever possible.
Your rights regarding international transfers: You have the right to request information about the safeguards we have in place for international transfers of your personal data. Contact privacy@pragyacyber.com for details.
08

Data Retention

We retain personal data only for as long as necessary for the purposes described in this Policy, or as required by applicable law. Our key retention periods are:

Data Category Retention Period Reason
Client contact & engagement data Duration of engagement + 7 years Legal obligation (tax, audit); dispute resolution
Security assessment reports & findings Duration of engagement + 12 months Client reference; retest baseline; then securely deleted or returned
VERIFI / SecuraGPT platform data Active subscription + 12 months after termination Trend analysis; then securely deleted on request
Platform access & audit logs 12 months Security monitoring; incident investigation
Marketing & communications data Until consent withdrawn or 3 years of inactivity Consent-based; legitimate interests
Job applicant data (unsuccessful) 6 months after decision Future opportunities (with consent); legal compliance
Financial & billing records 8 years Tax and statutory obligations under Indian Companies Act
Website analytics (aggregated) 26 months Service improvement; standard analytics retention

On expiry of the applicable retention period, personal data is securely deleted or anonymised so that it can no longer be linked to an individual.

09

Security Measures

As a cybersecurity company, we apply the same rigour to protecting personal data that we apply to our clients’ systems. Our technical and organisational security measures include:

  • Encryption: AES-256 encryption at rest for all stored data; TLS 1.3 encryption in transit for all data transfers
  • Access control: Role-based access control (RBAC); multi-factor authentication (MFA) mandatory for all staff and platform users; principle of least privilege enforced
  • Tenant isolation: Separate database per client tenancy on VERIFI and SecuraGPT platforms; row-level security enforced at the database layer
  • Network security: VPC isolation; dedicated security assessment VPC separate from application infrastructure; internal-only MCP server endpoints
  • Secrets management: Credentials stored in HashiCorp Vault or AWS Secrets Manager — never in application databases
  • Monitoring & logging: Comprehensive audit logging of all privileged actions; security event monitoring with alerting; distributed tracing across platform services
  • Annual penetration testing: VERIFI and SecuraGPT platforms are penetration tested annually or after major releases
  • Staff training: All staff complete security awareness training; personnel handling personal data are bound by confidentiality obligations

9.1 Data Breach Response

In the event of a personal data breach, we will assess the risk and, where required by applicable law, notify the relevant supervisory authority within 72 hours of becoming aware of the breach (UK GDPR / GDPR requirement) or within the timeframe required by applicable Indian and other national law. Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay.

To report a suspected security incident or data breach, contact: security@pragyacyber.com

10

Cookies & Tracking Technologies

Our website uses cookies and similar technologies to operate correctly, understand how visitors use the site, and improve your experience. We categorise our cookies as follows:

Category Purpose Consent Required?
Strictly Necessary Essential for the website to function — session management, security, load balancing. Cannot be disabled. No
Functional Remember your preferences (language, region, cookie consent settings). No
Analytics Understand how visitors interact with our site (page views, traffic sources, user journeys). Data is anonymised and aggregated (Google Analytics). Yes
Marketing Track effectiveness of marketing campaigns; LinkedIn Insight Tag for B2B audience insights. Yes

You can manage your cookie preferences through our cookie banner on first visit, or by adjusting your browser settings at any time. Disabling analytics cookies does not affect your ability to use our website or services.

Platform cookies: The VERIFI and SecuraGPT platforms use session cookies necessary for authentication and security. These are strictly necessary cookies and do not require separate consent.
11

Your Privacy Rights

Depending on your location, you have the following rights over your personal data. We will respond to any rights request within 30 days (or within the timeframe required by applicable law).

Right What It Means Jurisdictions
Right of Access Obtain a copy of the personal data we hold about you and information about how we use it. India · UK · US (CA) · UAE
Right to Correction Request that we correct inaccurate or incomplete personal data. India · UK · US (CA) · UAE
Right to Erasure Request deletion of your personal data where there is no compelling reason for us to continue processing it. India · UK · UAE
Right to Restrict Processing Ask us to pause processing of your data in certain circumstances, e.g., while a dispute is resolved. UK
Right to Data Portability Receive your personal data in a structured, machine-readable format to transfer to another provider. UK
Right to Object Object to processing based on legitimate interests, including direct marketing. UK
Right to Withdraw Consent Where processing is based on consent, withdraw that consent at any time without affecting prior processing. All jurisdictions
Right to Grievance Redressal Lodge a grievance with our privacy contact and receive a response within the timeframe prescribed by applicable law. India (DPDPA)
Right to Opt-Out of Sale Opt out of the sale or sharing of personal data (note: we do not sell personal data). US — California (CCPA/CPRA)

How to Exercise Your Rights

To exercise any of these rights, submit a written request to privacy@pragyacyber.com with sufficient detail to identify yourself and the specific right you wish to exercise. We may need to verify your identity before processing the request. We will not charge a fee for reasonable requests.

Note: Some rights are subject to exceptions — for example, we may be unable to delete data that we are required by law to retain, or data that is necessary to fulfil a contractual obligation. We will explain any applicable exceptions when responding to your request.
12

Children’s Privacy

Our services and platforms are intended for use by business organisations and adults aged 18 and over. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that personal data of a child has been collected without appropriate parental consent, we will delete it promptly.

If you believe a child has provided us with personal data, please contact us at privacy@pragyacyber.com.

13

Third-Party Links & Integrations

Our website and platform may contain links to third-party websites, tools, or services (such as LinkedIn, partner portals, or integrated security tools). We are not responsible for the privacy practices of those third parties. We encourage you to read the privacy policy of any third-party site or service you access.

VERIFI and SecuraGPT may offer integrations with third-party tools such as Slack, Jira, and cloud providers. When you enable an integration, you authorise Pragya Cyber to exchange data with that third-party service within the scope of the integration. The third party’s privacy policy applies to their handling of any data received.

14

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our data practices, our services, or applicable law. We will post the updated Policy on our website and update the “Last updated” date at the top of this page.

For material changes — particularly those that reduce your rights or expand how we use your personal data — we will provide at least 30 days’ advance notice by email to registered users before the changes take effect. Your continued use of our services following notice of changes constitutes acceptance of the updated Policy.

Previous versions of this Privacy Policy are available on request by contacting privacy@pragyacyber.com.
15

Contact Us & Complaints

If you have any questions about this Privacy Policy, wish to exercise your rights, or have a concern about our data practices, please contact us:

Privacy Contact — Pragya Cyber Pvt. Ltd.
Privacy enquiries privacy@pragyacyber.com
Security incidents security@pragyacyber.com
General contact hello@pragyacyber.com
Website www.pragyacyber.com

Supervisory Authority Complaints

If you are not satisfied with our response to a privacy concern, you have the right to lodge a complaint with the relevant supervisory authority:

  • India: Data Protection Board of India (once constituted under the DPDPA, 2023)
  • United Kingdom: Information Commissioner’s Office (ICO) — ico.org.uk
  • European Union: Your local EU Data Protection Authority
  • United States (California): California Privacy Protection Agency (CPPA)

We would always appreciate the opportunity to address your concern directly before you approach a supervisory authority.