← CITRA Insight

Privacy Policy

Last updated: August 2026

At CITRA Insight, we deal with information about software environments that belong to our customers. We take that responsibility seriously.

This Privacy Policy explains what information we collect, why we collect it, how we protect it, how long we keep it, and the choices available to you.

Digital Personal Data Protection Act, 2023

India's Digital Personal Data Protection Act, 2023 requires an organisation that handles personal data to say plainly what it collects, why, where it is kept, who else can see it, how long it is held, and how a person can raise a concern.

This policy answers each of those questions directly:

An assessment is normally arranged by an organisation for machines it owns. Where the personal data of an employee is involved, we handle it on that organisation's instructions and only for the assessment they have asked us to carry out.

1. Who We Are

CITRA Insight is a product of Code & Clause Systems, a sole proprietorship based in Bhopal, Madhya Pradesh, India.

GSTIN: 23DDQPS9840L1ZN

For assessments carried out for a customer organisation, we act on that organisation's instructions and only for the assessment they have asked us to carry out.

2. Information We Collect

CITRA Insight is designed to understand the software environment of the machines included in an assessment. Doing that accurately requires recording some information that identifies a person. We would rather state that plainly than leave it implied.

When the CITRA collection utility is run on an authorised Windows device, it may collect:

About the software on the machine

  • Installed software, including names, versions and publishers
  • Software activation and licensing indicators
  • Running processes, installed services and scheduled tasks
  • Installed fonts and audio plugins
  • Entries in the system hosts file that affect licence verification

About the machine

  • Processor, memory, storage and operating system
  • Machine name, IP address, MAC address and manufacturer serial number
  • The Windows product ID, and the last five characters of the product key — never the full key

About the accounts that use the machine

  • The user accounts present on the machine: the account name, the full name recorded against it, the account identifier, the domain, and whether the account holds administrator rights
  • Which applications each account has opened, how many times, and when it last did so. Windows keeps these records itself; we read them, rather than watching anyone as they work
  • Running processes and the account each one belongs to

This third group is personal data, and we collect it because licensing is counted per person at least as often as it is per machine. One machine used by three people may require three licences, and a licence nobody has opened in a year is one you are paying for and not using. Neither question can be answered without knowing which account did what.

The collection utility does not collect the contents of your files, your email messages, your browsing history, your keystrokes or screenshots of your screen. Where the location of a program is recorded, that location may contain the folder name of the account it belongs to.

The organisation running the assessment is responsible for ensuring that the CITRA utility is used only on devices it owns or is authorised to assess.

3. Why We Collect This Information

The information collected by CITRA is used to:

  • Build an inventory of software across the assessed environment
  • Compare installed software with licence and purchase information provided by the customer
  • Identify technical indicators that may require further licence review
  • Calculate indicative financial exposure where appropriate
  • Identify potentially unused or unnecessary software
  • Prepare the CITRA Insight assessment report
  • Provide support relating to the assessment

We do not use assessment findings to market software products to you.

4. Your Rights

Under the Digital Personal Data Protection Act, 2023 and other relevant law, a person whose personal data we hold may ask us:

  • What personal data of theirs we hold, and what we have done with it
  • To correct anything inaccurate, or complete anything missing
  • To erase it, where we are not required to keep it for a legal or contractual reason
  • To accept a nomination, so that another person can exercise these rights on their behalf if they become unable to
  • To address a grievance. If our answer does not satisfy them, they may take the matter to the Data Protection Board of India

Requests relating to personal data can be sent to: hello@citrainsight.in

Please include enough information for us to understand the request and identify the relevant customer or engagement.

Where a request concerns an employee or other individual whose device was assessed on behalf of an organisation, we may need to coordinate with that organisation before taking action.

5. Data Security

We take reasonable technical and organisational measures to protect information handled through CITRA Insight.

Data transmitted to our systems is encrypted in transit using TLS. Stored data is encrypted at rest where supported by the relevant infrastructure.

Customer environments are logically separated so that one customer cannot access another customer's assessment data.

Access to customer information is restricted to people who need it to provide the service or support the engagement.

6. Where Your Data Is Stored

Customer assessment data — the encrypted scan bundles collected from your machines, and the findings derived from them — is stored on a server located in Bangalore, India, which DigitalOcean operates for us.

Some communication necessarily happens elsewhere. Transactional email, such as verification codes, notifications and links to your report, is delivered through Resend, which handles the recipient address and the content of the message outside India. Text messages are delivered through MSG91 and payments processed through Razorpay, both of which operate in India.

The assessment data itself is not copied out of that server. What leaves it is limited to the contents of the messages described above.

7. When We Share Information

Your assessment data belongs to your business.

We do not sell customer assessment data.

We do not provide software publishers with your assessment findings for their compliance or commercial activities.

We do not disclose customer assessment information to third parties except where:

  • You have authorised us to do so;
  • It is necessary for a service provider supporting CITRA Insight and that provider is subject to appropriate confidentiality and data protection obligations; or
  • Disclosure is required by applicable law or a lawful order.

The service providers we rely on

Running the service takes a small number of providers. Each receives only what it needs in order to do its part:

  • DigitalOcean — operates the Bangalore server on which assessment data is stored
  • Resend — delivers transactional email, and so receives recipient addresses and message content
  • MSG91 — delivers verification codes by text message, and so receives the mobile number
  • Razorpay — processes payments, and so receives billing and payment details. We do not store card numbers
  • Zoho — hosts our business email, so correspondence you send us is held there

Apart from DigitalOcean, which operates the server itself, none of these providers receives your assessment findings. None of them is permitted to use what it does receive for its own purposes.

8. How Long We Keep Your Data

CITRA Insight is designed as a one-time assessment service.

The encrypted scan bundles collected from your machines, together with findings derived from those bundles, are retained for 30 days after your report is delivered.

This period allows us to answer reasonable questions about your report and verify findings against the underlying assessment data.

After the 30-day period, the scan data is permanently deleted in accordance with our retention process.

You may request earlier deletion of scan data, subject to any legal or contractual requirement that prevents us from doing so.

Certain business records, such as invoices, payment records and engagement references, may need to be retained for the period required under applicable tax, accounting or other laws.

9. Grievance Officer

For privacy or data protection concerns, you may contact:

Chitra Arora
Email: hello@citrainsight.in

We aim to respond to grievances within the applicable statutory timeframe and, where applicable, within 30 days.

10. Contact

For privacy-related questions or requests: hello@citrainsight.in