Privacy Policy
How Cybrovate collects, uses, discloses, retains, and protects personal data across the Website, CybPortal, and business interactions.
Current Version: 2
Effective Date: July 13, 2026
1. Introduction
Cybrovate Technologies Pvt. Ltd. ("Cybrovate", "we", "us" or "our") is a private limited company incorporated under the Companies Act, 2013, with its registered office at L5 South Park, Nallangandla, Lingampally, Hyderabad, 500019, India. Cybrovate provides an AI-driven cybersecurity and IT management platform comprising its CYB Protect, CYB Asset and CYB Manage suites.
This Privacy Policy (the "Policy") explains how Cybrovate, acting as a Data Fiduciary (data controller), collects, uses, discloses, retains and protects personal data when you visit www.cybrovate.com (the "Website"), correspond with us, hold an account on the Cybrovate customer portal ("CybPortal"), engage with us commercially, or otherwise interact with our business. It also describes the rights available to you and how to exercise them.
Important scope boundary. This Policy does not govern the security telemetry, system-generated logs and technical metadata that Cybrovate ingests from a customer's IT environment in the course of delivering the Services. In respect of that data, Cybrovate acts as a Data Processor on the documented instructions of the customer (who is the controller), and processing is governed exclusively by the Master Service Agreement (CYB-LEGAL-MSA) and the Data Processing Agreement (CYB-LEGAL-DPA). Section 4 sets out this distinction in full.
2. Definitions
In this Policy, the following terms have the meanings set out below. Terms used but not defined here carry the meaning given to them under Applicable Data Protection Laws.
| Term | Meaning |
|---|---|
| Applicable Data Protection Laws | The Digital Personal Data Protection Act, 2023 (India) ("DPDPA") and rules made thereunder; the Information Technology Act, 2000 and the SPDI Rules, 2011; and, where applicable to you, the Personal Information Protection and Electronic Documents Act (Canada) ("PIPEDA"), the Personal Data Protection Act 2012 (Singapore) ("PDPA"), and the EU/UK General Data Protection Regulation ("GDPR"). |
| Personal Data | Any data about an individual who is identifiable by or in relation to such data. |
| Sensitive Personal Data | Categories of Personal Data afforded special protection under Applicable Data Protection Laws, for example financial information, health data, biometric data, or official identifiers. |
| Data Principal / Data Subject | The identifiable individual to whom Personal Data relates, referred to in this Policy as "you". |
| Data Fiduciary / Controller | The person who determines the purpose and means of processing Personal Data. In respect of the data covered by this Policy, this is Cybrovate. |
| Data Processor | A person who processes Personal Data on behalf of a Data Fiduciary / controller. |
| Security Telemetry | System-generated logs, events, network activity data, identity and access events, and technical metadata originating from a customer IT environment. This is governed by the DPA, not this Policy. |
| Services | Cybrovate AI-driven cybersecurity and IT management platform and related services across the CYB Protect, CYB Asset and CYB Manage suites. |
| Process / Processing | Any operation performed on Personal Data, including collection, recording, storage, use, disclosure, retention or erasure. |
3. Who We Are and How to Contact Us
For the purposes of this Policy, the Data Fiduciary is:
| Contact point | Details |
|---|---|
| Entity | Cybrovate Technologies Pvt. Ltd. |
| Registered Office | L5 South Park, Nallangandla, Lingampally, Hyderabad, 500019, India |
| General Enquiries | info@cybrovate.com |
| Support | support@cybrovate.com |
| Privacy / Data Protection | privacy@cybrovate.com |
| Grievance Officer | Dev Pandey, grievance@cybrovate.com |
Under Section 13 of the DPDPA, Cybrovate is required to publish the contact details of a Grievance Officer (and, where Cybrovate is notified as a Significant Data Fiduciary, a Data Protection Officer). All privacy enquiries, requests and complaints may be addressed to the contact points above.
4. Scope of this Policy
4.1 What this Policy covers
This Policy applies to Personal Data that Cybrovate collects and processes as a Data Fiduciary, including in relation to:
visitors to and users of the Website (www.cybrovate.com);
individuals who submit enquiries through our contact-us forms or correspond with us by email;
authorised users and administrators who hold accounts on CybPortal, in respect of their account, identity and usage data, not the customer telemetry processed through it;
business contacts, prospects and representatives of our customers, partners and suppliers;
individuals who apply for employment or engagement with Cybrovate; and
recipients of our marketing or service communications.
4.2 What this Policy does not cover (the controller / processor boundary)
Cybrovate's platform is engineered to process Security Telemetry - logs, system events, network activity and technical metadata drawn from a customer's IT environment for the purpose of threat detection, analysis and response. Personal Data, where present in such telemetry, is incidental and not the primary subject of processing. In respect of that telemetry:
the customer is the Data Fiduciary / controller and determines the purposes and means of processing;
Cybrovate acts solely as a Data Processor on the customer's documented instructions;
Cybrovate does not intentionally collect or process business content, application-layer data, file contents, e-mail bodies or user-generated content; and
such processing is governed by the Master Service Agreement (CYB-LEGAL-MSA) and the Data Processing Agreement (CYB-LEGAL-DPA), and not by this Policy.
If you are an employee, contractor or end-user of a Cybrovate customer and your query concerns telemetry processed about you within your employer's systems, your first point of contact is that organisation (the controller).
5. Categories of Personal Data We Collect
We practise data minimisation and collect only what is necessary for the purposes set out in Section 7. Depending on how you interact with us, we may collect the following categories:
| Category | Examples |
|---|---|
| Identity & contact data | Name, business e-mail address, telephone number, employer / organisation, job title. |
| Account data (CybPortal) | Username, hashed credentials, role and permissions, account preferences, authentication and access logs relating to the account. |
| Enquiry & correspondence data | Information you submit via contact-us forms, support tickets, and the content of your communications with us. |
| Commercial & relationship data | Records of demonstrations, proposals, contracts, billing contacts and communication preferences. |
| Technical & usage data | IP address, device and browser identifiers, log data, pages viewed and interaction data collected through cookies and similar technologies. |
| Recruitment data | Details contained in a CV / resume, application and any data you provide during a recruitment process. |
| Marketing data | Subscription status and engagement with our communications. |
Sensitive Personal Data. Cybrovate does not seek to collect Sensitive Personal Data through the Website, CybPortal or our business interactions. Please do not submit such data to us unless we have specifically requested it for a lawful purpose.
Children. The Website and Services are intended for businesses and persons aged 18 and above. We do not knowingly collect Personal Data of children. See Section 14.
6. How We Collect Personal Data
We collect Personal Data through the following channels:
Directly from you - when you complete a form, create or use a CybPortal account, contact us, enter into or negotiate a contract, attend an event, or apply for a role.
Automatically - when you use the Website, through cookies, server logs and similar technologies (Section 8).
From third parties and public sources - such as our customers (where they provide business-contact details of authorised users), referral partners, and publicly available professional information, in each case where lawful.
7. Purposes of Processing and Legal Bases
We process Personal Data only where we have a lawful basis to do so. Under the DPDPA, processing is principally founded on your consent or on certain "legitimate uses" recognised by the Act; where the GDPR applies, the corresponding bases are identified below.
| Purpose | Categories used | Legal basis |
|---|---|---|
| Operating and securing the Website and CybPortal | Account, technical & usage data | Legitimate use / legitimate interests; performance of a contract (GDPR Art. 6(1)(b)/(f)). |
| Responding to enquiries and providing support | Identity, contact, correspondence data | Consent; performance of a contract / steps prior to contract (GDPR Art. 6(1)(a)/(b)). |
| Providing and administering the Services | Account, commercial data | Performance of a contract (GDPR Art. 6(1)(b)). |
| Managing the customer / supplier relationship and billing | Identity, contact, commercial data | Performance of a contract; legal obligation (GDPR Art. 6(1)(b)/(c)). |
| Sending service and, where permitted, marketing communications | Identity, contact, marketing data | Consent; legitimate interests (GDPR Art. 6(1)(a)/(f)). |
| Recruitment and assessment of applicants | Recruitment data | Consent; steps prior to entering a contract (GDPR Art. 6(1)(a)/(b)). |
| Ensuring security, preventing fraud and protecting our systems | Technical, account, usage data | Legitimate use / legitimate interests (GDPR Art. 6(1)(f)). |
| Complying with law and enforcing our rights | As relevant | Legal obligation; establishment/exercise of legal claims (GDPR Art. 6(1)(c)/(f)). |
Where we rely on your consent, you may withdraw it at any time (Section 13). Withdrawal does not affect the lawfulness of processing carried out before withdrawal, and the consequence of withdrawal may be that we are unable to provide a particular feature or communication.
8. Cookies and Similar Technologies
The Website uses cookies and similar technologies to function, to remember your preferences, and to understand how the Website is used. Where required, non-essential cookies are deployed only with your consent, which you may manage or withdraw through our cookie banner or browser settings. Full particulars - including categories, purposes and retention - are set out in the Cybrovate Cookie Policy (CYB-LEGAL-COOKIES-Policies), which forms part of this Policy by reference.
9. Disclosure of Personal Data
We do not sell your Personal Data. We disclose it only as described below, and subject to appropriate safeguards:
Service providers and sub-processors - cloud infrastructure and hosting providers (including Microsoft Azure, and where applicable AWS and Google Cloud Platform), communications and productivity tools (including Office 365), analytics and support providers, each engaged under written terms requiring confidentiality and security.
Professional advisers - lawyers, auditors, accountants and insurers, where reasonably necessary.
Corporate transactions - an acquirer or successor entity in connection with a merger, acquisition, reorganisation or sale of assets, subject to this Policy.
Legal and regulatory recipients - courts, regulators, law-enforcement and government authorities, where required or permitted by law or to establish, exercise or defend legal claims.
Note: sub-processors engaged for the processing of customer Security Telemetry are governed by, and listed under, the DPA - not this Policy.
10. International Data Transfers
Cybrovate operates principally in India, with a business presence in Canada and Singapore. Personal Data is primarily processed in India. Where Personal Data is transferred to, or accessed from, another jurisdiction - for example through globally distributed cloud infrastructure or our sub-processors - we ensure that such transfers are carried out in accordance with Applicable Data Protection Laws.
We comply with the DPDPA and any restrictions on transfers to specified jurisdictions notified by the Government of India. Where Personal Data subject to the GDPR is transferred outside the European Economic Area or the United Kingdom, we rely on an adequacy decision or appropriate safeguards such as Standard Contractual Clauses, together with supplementary technical and organisational measures (including encryption and access controls). Where PIPEDA or the Singapore PDPA applies, we apply comparable protection consistent with those laws.
11. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy legal, accounting, tax or reporting requirements, and to establish, exercise or defend legal claims. Retention periods are determined by reference to:
the nature of the data and the purpose of processing;
the duration of our relationship with you or the relevant customer;
any contractual retention commitments; and
applicable statutory limitation and record-keeping periods.
When Personal Data is no longer required, we will securely delete, erase or anonymise it. Retention of customer Security Telemetry (which by default is retained for the period stated in the DPA, presently three (3) months unless otherwise configured) is governed by the DPA, not this Policy.
12. How We Protect Personal Data
Cybrovate maintains an information security management system and implements appropriate technical and organisational measures to protect Personal Data against unauthorised or unlawful processing and against accidental loss, destruction or damage. These measures include:
encryption of data in transit and at rest;
role-based access controls, authentication and the principle of least privilege;
continuous monitoring and logging of system activity;
vulnerability management and regular security assessments;
incident detection and response procedures; and
use of reputable cloud infrastructure providers operating under written security obligations.
Cybrovate holds ISO 9001 and ISO 27001 certifications, and SOC 2 Type II certification is in progress. No security measure can be guaranteed to be wholly impenetrable; we do not warrant absolute security, but we undertake to implement and maintain reasonable and appropriate safeguards and to keep them under review.
13. Your Rights
Subject to, and in accordance with, Applicable Data Protection Laws, you may have the following rights in respect of your Personal Data:
| Right | What it means |
|---|---|
| Access / information | To obtain a summary of the Personal Data we process about you and the processing activities undertaken. |
| Correction | To have inaccurate or incomplete Personal Data corrected, completed or updated. |
| Erasure | To request deletion of Personal Data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations. |
| Withdraw consent | To withdraw any consent you have given, at any time, as easily as it was given. |
| Grievance redressal | To have a readily available means of registering a grievance with our Grievance Officer. |
| Nominate | To nominate another individual to exercise your rights in the event of death or incapacity (DPDPA). |
| Additional GDPR rights (where applicable) | Data portability, restriction of processing, objection to processing, and the right not to be subject to solely automated decisions producing legal or similarly significant effects. |
To exercise any of these rights, contact us at privacy@cybrovate.com or via our Grievance Officer. We may need to verify your identity before acting on a request. We will respond within the timeframe required by Applicable Data Protection Laws and, in any event, will use reasonable efforts to respond within thirty (30) days. There is normally no fee, although we may charge a reasonable fee or decline a request that is manifestly unfounded, excessive or repetitive, to the extent permitted by law.
14. Children's Personal Data
The Website and Services are directed to businesses and to individuals aged 18 years or older. We do not knowingly collect Personal Data of children, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Where the DPDPA requires verifiable consent of a parent or lawful guardian for the processing of a child's Personal Data, we will obtain it before processing. If you believe we have inadvertently collected a child's Personal Data, please contact us so that we may delete it.
15. Automated Processing and Artificial Intelligence
Cybrovate's platform applies AI-driven analysis (including its Cybrovate Security Intelligence Fabric, AI-Remediator and SmartSOC Prioritizer components) solely for cybersecurity purposes - threat detection, correlation, anomaly detection and risk analysis on customer Security Telemetry. That automated processing operates on data for which Cybrovate is a Processor and is governed by the DPA. Customer data is not used to train generalised AI models for external commercial purposes, and any model improvements do not result in identification of a customer or its individuals.
In respect of the Personal Data covered by this Policy (Website, CybPortal accounts, business contacts), we do not make decisions producing legal or similarly significant effects about you based solely on automated processing, nor do we carry out profiling for marketing.
16. Third-Party Websites and Services
The Website may contain links to third-party websites, plug-ins or services that we do not operate or control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. We encourage you to review the privacy notices of any third party before providing your Personal Data to it.
17. Changes to this Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements or other factors. The current version, and its effective date, will always be available on the Website. Where a change is material, we will provide a more prominent notice as required by law. Your continued use of the Website or Services after the effective date of a revised Policy constitutes acknowledgement of the changes, to the extent permitted by law.
18. Grievance Redressal and Complaints
If you have any concern or complaint about how we handle your Personal Data, please contact our Grievance Officer at grievance@cybrovate.com. We will acknowledge and address grievances within the timeframe prescribed under the DPDPA. If you remain dissatisfied, you have the right to lodge a complaint with the Data Protection Board of India or, where applicable to you, the Office of the Privacy Commissioner of Canada, the Personal Data Protection Commission (Singapore), or the relevant supervisory authority under the GDPR.
19. Governing Law
This Policy and any matter arising from it are governed by and construed in accordance with the laws of India. Where mandatory provisions of Applicable Data Protection Laws of another jurisdiction apply to you, those provisions apply only to the extent required by law and do not otherwise displace the governing law of India. Nothing in this Policy limits any statutory right you may have under Applicable Data Protection Laws.
20. How to Contact Us
If you have any questions about this Policy or our data practices, please contact us:
| Contact point | Details |
|---|---|
| Cybrovate Technologies Pvt. Ltd. | L5 South Park, Nallangandla, Lingampally, Hyderabad, 500019, India |
| General | info@cybrovate.com |
| Privacy | privacy@cybrovate.com |
| Grievance Officer | Dev Pandey - grievance@cybrovate.com |
Quick Jump To
- 1.Introduction
- 2.Definitions
- 3.Who We Are and How to Contact Us
- 4.Scope of this Policy
- 5.Categories of Personal Data We Collect
- 6.How We Collect Personal Data
- 7.Purposes of Processing and Legal Bases
- 8.Cookies and Similar Technologies
- 9.Disclosure of Personal Data
- 10.International Data Transfers
- 11.Data Retention
- 12.How We Protect Personal Data
- 13.Your Rights
- 14.Children's Personal Data
- 15.Automated Processing and Artificial Intelligence
- 16.Third-Party Websites and Services
- 17.Changes to this Policy
- 18.Grievance Redressal and Complaints
- 19.Governing Law
- 20.How to Contact Us