At CITRA Insight, we deal with information about software environments that belong to our customers. We take that responsibility seriously.
This Privacy Policy explains what information we collect, why we collect it, how we protect it, how long we keep it, and the choices available to you.
India's Digital Personal Data Protection Act, 2023 requires an organisation that handles personal data to say plainly what it collects, why, where it is kept, who else can see it, how long it is held, and how a person can raise a concern.
This policy answers each of those questions directly:
An assessment is normally arranged by an organisation for machines it owns. Where the personal data of an employee is involved, we handle it on that organisation's instructions and only for the assessment they have asked us to carry out.
CITRA Insight is a product of Code & Clause Systems, a sole proprietorship based in Bhopal, Madhya Pradesh, India.
GSTIN: 23DDQPS9840L1ZN
For assessments carried out for a customer organisation, we act on that organisation's instructions and only for the assessment they have asked us to carry out.
CITRA Insight is designed to understand the software environment of the machines included in an assessment. Doing that accurately requires recording some information that identifies a person. We would rather state that plainly than leave it implied.
When the CITRA collection utility is run on an authorised Windows device, it may collect:
This third group is personal data, and we collect it because licensing is counted per person at least as often as it is per machine. One machine used by three people may require three licences, and a licence nobody has opened in a year is one you are paying for and not using. Neither question can be answered without knowing which account did what.
The collection utility does not collect the contents of your files, your email messages, your browsing history, your keystrokes or screenshots of your screen. Where the location of a program is recorded, that location may contain the folder name of the account it belongs to.
The organisation running the assessment is responsible for ensuring that the CITRA utility is used only on devices it owns or is authorised to assess.
The information collected by CITRA is used to:
We do not use assessment findings to market software products to you.
Under the Digital Personal Data Protection Act, 2023 and other relevant law, a person whose personal data we hold may ask us:
Requests relating to personal data can be sent to: hello@citrainsight.in
Please include enough information for us to understand the request and identify the relevant customer or engagement.
Where a request concerns an employee or other individual whose device was assessed on behalf of an organisation, we may need to coordinate with that organisation before taking action.
We take reasonable technical and organisational measures to protect information handled through CITRA Insight.
Data transmitted to our systems is encrypted in transit using TLS. Stored data is encrypted at rest where supported by the relevant infrastructure.
Customer environments are logically separated so that one customer cannot access another customer's assessment data.
Access to customer information is restricted to people who need it to provide the service or support the engagement.
Customer assessment data — the encrypted scan bundles collected from your machines, and the findings derived from them — is stored on a server located in Bangalore, India, which DigitalOcean operates for us.
Some communication necessarily happens elsewhere. Transactional email, such as verification codes, notifications and links to your report, is delivered through Resend, which handles the recipient address and the content of the message outside India. Text messages are delivered through MSG91 and payments processed through Razorpay, both of which operate in India.
The assessment data itself is not copied out of that server. What leaves it is limited to the contents of the messages described above.
Your assessment data belongs to your business.
We do not sell customer assessment data.
We do not provide software publishers with your assessment findings for their compliance or commercial activities.
We do not disclose customer assessment information to third parties except where:
Running the service takes a small number of providers. Each receives only what it needs in order to do its part:
Apart from DigitalOcean, which operates the server itself, none of these providers receives your assessment findings. None of them is permitted to use what it does receive for its own purposes.
CITRA Insight is designed as a one-time assessment service.
The encrypted scan bundles collected from your machines, together with findings derived from those bundles, are retained for 30 days after your report is delivered.
This period allows us to answer reasonable questions about your report and verify findings against the underlying assessment data.
After the 30-day period, the scan data is permanently deleted in accordance with our retention process.
You may request earlier deletion of scan data, subject to any legal or contractual requirement that prevents us from doing so.
Certain business records, such as invoices, payment records and engagement references, may need to be retained for the period required under applicable tax, accounting or other laws.
For privacy or data protection concerns, you may contact:
Chitra Arora
Email: hello@citrainsight.in
We aim to respond to grievances within the applicable statutory timeframe and, where applicable, within 30 days.
For privacy-related questions or requests: hello@citrainsight.in