Cytrusst Privacy Policy
Cytrusst Intelligence Private Limited
1. Purpose
This Privacy & Personal Data Processing Policy defines how Cytrusst Intelligence Private Limited (“Cytrusst”) collects, uses, stores, protects, shares, retains, and disposes of personal data.
This Policy supports compliance with applicable privacy and data protection requirements, including the Digital Personal Data Protection Act, 2023 (DPDPA), ISO/IEC 27001, ISO/IEC 27701, contractual requirements, and applicable industry practices.
2. Objectives
Cytrusst aims to:
- Process personal data lawfully, fairly, and transparently.
- Collect and process only the personal data necessary for identified purposes.
- Protect the confidentiality, integrity, and availability of personal data.
- Maintain appropriate technical and organizational safeguards.
- Respect applicable rights of data principals/data subjects.
- Obtain, manage, record, and withdraw consent where consent is the applicable lawful basis.
- Maintain appropriate records of personal data processing.
- Meet applicable legal, regulatory, contractual, and customer requirements.
- Support customers with applicable privacy and compliance obligations.
3. Scope
This Policy applies to:
- Employees, contractors, consultants, Interns, and third-party partners.
- All Cytrusst business units, applications, services, systems, and platforms.
- Personal data processed in electronic or physical form.
- Clients, employees, vendors, partners, and other individuals whose personal data is processed by Cytrusst.
This Policy applies throughout the personal data lifecycle, including collection, use, storage, processing, sharing, retention, archival, and disposal.
4. Definitions
- Personal Data
- Information relating to an identifiable individual.
- Processing
- Any operation performed on personal data, including collection, recording, use, disclosure, storage, retention, and deletion.
- Data Principal / Data Subject
- The individual to whom personal data relates.
- Data Fiduciary / Controller
- The organization that determines the purpose and means of processing personal data.
- Data Processor
- A third party that processes personal data on behalf of Cytrusst or its customers.
- Sensitive or High-Risk Personal Data
- Personal data requiring additional protection based on applicable law, contractual requirements, risk assessment, or the potential impact of unauthorized access, disclosure, alteration, or loss.
5. Categories of Personal Data
Depending on the processing activity, Cytrusst may process:
5.1 Customer Data
- Name and contact information
- Organization information
- User account information
- Customer documents and evidence
- Personal data configured or provided by customers
5.2 Employee and HR Data
- Identification information
- Contact information
- Employment records
- Background verification information
- Payroll and financial information
5.3 Website and Application Data
- Cookies
- IP address
- Device information
- Usage and analytics information
- Contact form information
5.4 Vendor and Third-Party Data
- Business contact information
- Contractual information
- NDAs and compliance documents
- Security and compliance reports
5.5 Product Data
Cytrusst products, including User Consent Management (UCM) and Data Security Posture Management (DSPM), may process customer-defined personal data based on the customer's configuration and requirements.
Depending on the implementation, this may include:
- Identity information
- Government identifiers
- Contact information
- Financial information
- Healthcare information
- Employment information
- Education information
- Online identifiers
- Location information
- Family-related information
- Communication records
The actual data processed depends on the customer's implementation, applicable regulations, configured data sources, and defined processing purposes.
6. Lawful Basis for Processing
Cytrusst may process personal data based on:
- Consent
- Contractual necessity or service delivery
- Legal and regulatory requirements
- Legitimate interests where applicable
- Security and fraud prevention
- Other lawful bases permitted by applicable law
Where consent is the applicable lawful basis, Cytrusst obtains and records consent before processing personal data.
7. Purposes of Processing
Personal data may be processed for:
- Delivering cybersecurity, compliance, privacy, and audit services.
- Customer onboarding, communication, and support.
- Employee lifecycle management.
- Administration, operations, billing, and recordkeeping.
- Platform security, monitoring, and threat detection.
- Service improvement, analytics, and product development.
- Legal, contractual, regulatory, and audit requirements.
- Vendor and third-party assessments.
- Incident response and fraud prevention.
- Marketing where applicable and with required consent.
- Managing consent preferences and consent records through UCM.
- Discovering, classifying, monitoring, and protecting personal data through DSPM.
- Supporting customers with privacy, security, and regulatory compliance requirements.
8. Personal Data Processing
Cytrusst processes personal data in accordance with applicable laws, contractual obligations, and defined business purposes.
Cytrusst shall ensure that:
- Personal data is collected for specified and legitimate purposes.
- Processing is performed based on an appropriate lawful basis.
- Access is limited to authorized personnel and approved processors.
- Appropriate technical and organizational controls are implemented.
- Processing activities are documented and periodically reviewed.
- Personal data is retained only for the applicable retention period.
- Personal data is securely deleted, anonymized, or disposed of when no longer required.
- Personal data is not used for unrelated purposes.
8.1 UCM
The UCM platform processes customer-defined personal data for consent management, consent records, privacy preferences, and applicable privacy rights.
8.2 DSPM
The DSPM platform processes customer-authorized data sources to discover, identify, classify, monitor, and protect personal data.
DSPM scan results and associated information are securely stored using appropriate security controls, including encryption, role-based access control, logging, and monitoring.
Personal data identified through scanning shall be processed only for authorized purposes such as discovery, classification, risk assessment, governance, and security monitoring.
8.3 Data Inventory
Cytrusst maintains a Data Inventory to provide visibility into personal data processed across business processes, departments, applications, systems, vendors, and activities.
The Data Inventory may include:
- Personal data elements
- Personal data category
- Data subject
- Purpose of processing
- Source of data
- Data classification
- Storage location
- Data owner
- Authorized access
- Third-party sharing
- Retention period
- Security controls
- Cross-border transfers
- Backup arrangements
- Data minimization requirements
- Data accuracy and verification status
The Data Inventory shall be reviewed when significant changes occur to the processing activity, data, system, vendor, purpose, storage, retention, or other relevant conditions.
9. Data Minimization and Accuracy
Cytrusst follows the principle of data minimization and processes only personal data that is adequate, relevant, and necessary for the intended purpose.
Cytrusst shall:
- Avoid collecting unnecessary or excessive personal data.
- Periodically review personal data for continued relevance.
- Maintain accurate and up-to-date personal data.
- Support correction of inaccurate or incomplete information.
- Securely delete or anonymize obsolete or unnecessary personal data.
- Document the justification for retaining personal data where required.
Where identity or age verification is required, Cytrusst may use trusted services such as DigiLocker for eligibility verification. Unnecessary personal information obtained during verification shall not be retained.
10. Data Retention and Disposal
Personal data shall be retained based on:
- The purpose for which it was collected.
- Applicable legal and regulatory requirements.
- Applicable NDA, contract, or other contractual requirements.
- Legitimate organizational requirements.
Where a specific retention period is defined in an applicable NDA, contract, or other agreement, Cytrusst shall follow the specified retention period.
Where no specific retention period is defined, data may be retained for up to 7 years in accordance with the Cytrusst Secure Data Deletion Policy, subject to applicable legal, regulatory, contractual, and business requirements.
Retention requirements shall be documented in the Data Inventory where applicable.
At the end of the applicable retention period, personal data shall be securely deleted, anonymized, or otherwise disposed of unless continued retention is required or permitted by law, contract, or legitimate organizational requirements.
Secure disposal may include:
- Secure digital deletion
- Data wiping
- Secure archive deletion
- Physical shredding
- Other approved secure disposal methods
11. Data Sharing and Third-Party Processing
Personal data may be shared with:
- Authorized Cytrusst employees and internal teams.
- Approved cloud and technology service providers.
- Auditors and professional service providers.
- Authorized third-party processors.
- Regulatory or legal authorities where required.
Cytrusst shall ensure that applicable third-party processing is subject to appropriate privacy and security requirements, contractual safeguards, and due diligence based on the nature and risk of processing.
Personal data shall be shared only where necessary for the identified purpose and where an applicable lawful, contractual, legal, or permitted basis exists.
Applicable recipients, processors, vendors, and sharing arrangements shall be documented in the Data Inventory where required.
12. Cross-Border Data Transfers
Where personal data is transferred outside India or processed in another jurisdiction, Cytrusst shall implement appropriate safeguards in accordance with applicable legal, regulatory, and contractual requirements.
Appropriate measures may include:
- Contractual safeguards
- Secure transfer mechanisms
- Encryption
- Access controls
- Applicable privacy and security requirements
13. Customer Privacy and Compliance Support
Where Cytrusst processes personal data on behalf of customers, Cytrusst provides reasonable support for applicable privacy and compliance requirements.
Support may include:
- Privacy and security due diligence.
- Relevant compliance documentation and evidence where permitted.
- Assistance with applicable Data Subject Rights requests.
- Customer audits and assessments.
- Regulatory reviews where contractually required.
- Information regarding applicable subprocessors.
- Support for privacy and security compliance requirements.
- Notification of applicable personal data breaches in accordance with contractual and legal requirements.
Customers may contact Cytrusst through the designated support channel or assigned customer representative for privacy-related requests or concerns.
14. Security Controls
Cytrusst implements appropriate administrative, technical, and physical safeguards to protect personal data.
Security measures may include:
- Access control and identity management
- Encryption in transit and at rest
- Network and application security
- Endpoint protection and monitoring
- Security monitoring and logging
- Vulnerability and patch management
- Backup and disaster recovery
- Employee security awareness
- Data masking and pseudonymization where applicable
- Role-based access control
- Audit logging and monitoring
Customer-authorized data processed through DSPM is transferred through secure communication channels and stored using appropriate encryption and access controls.
Access to personal data and scan results is restricted to authorized personnel based on business requirements.
15. Rights of Data Principals / Data Subjects
Subject to applicable law, individuals may have rights including:
- Right to access information about processing.
- Right to correct inaccurate or outdated information.
- Right to withdraw consent where consent is the lawful basis.
- Right to request erasure where legally applicable.
- Right to data portability where applicable.
- Other rights provided under applicable privacy laws.
Requests may be submitted through the designated Cytrusst support or compliance channels.
16. Consent Management
Where consent is the applicable lawful basis, Cytrusst shall obtain, record, manage, and maintain consent appropriately.
Cytrusst shall ensure that:
- Consent is clear, specific, informed, and obtained through affirmative action.
- Individuals are informed about the purpose of processing.
- Relevant personal data categories and applicable retention information are communicated.
- Consent records are maintained where required.
- Individuals can withdraw consent through available channels.
- Withdrawal requests are processed promptly.
- When consent is withdrawn, the related processing will stop unless there is another valid legal reason to continue.
Customer-facing applications may use an explicit Yes/No consent mechanism where consent is required.
18. Privacy Incidents and Breach Notification
Cytrusst maintains an Incident Response Plan and appropriate security monitoring mechanisms to identify and respond to privacy and security incidents.
Where a personal data breach occurs, Cytrusst shall assess and respond to the incident and notify affected customers, authorities, or other stakeholders where required by applicable law or contractual obligations.
19. Roles and Responsibilities
Management
Management shall:
- Ensure implementation of this Policy.
- Provide appropriate resources for privacy management.
- Support compliance with applicable requirements.
Data Protection Lead / Compliance Officer
The Data Protection Lead / Compliance Officer shall:
- Oversee implementation of privacy requirements.
- Monitor personal data processing activities.
- Manage or coordinate privacy-related requests.
- Oversee consent management.
- Support customer privacy assessments and audits.
- Review privacy risks and recommend corrective actions.
Employees
Employees shall:
- Follow this Policy and applicable privacy procedures.
- Process only the personal data necessary for assigned responsibilities.
- Obtain or verify consent where required.
- Protect personal data from unauthorized access or disclosure.
- Report inaccuracies, privacy incidents, and unauthorized processing.
- Handle customer and employee information in accordance with organizational requirements.
Third Parties
Third parties shall comply with applicable contractual privacy and security requirements when processing personal data on behalf of Cytrusst.
Data Owners
Data Owners shall:
- Maintain accurate Data Inventory information.
- Ensure personal data is necessary for the identified purpose.
- Review access, sharing, retention, and security requirements.
- Support periodic review of processing activities.
- Identify and report unnecessary, inaccurate, outdated, or unauthorized processing.
- Coordinate with the Data Protection Lead / Compliance Officer when significant changes occur.
20. Policy Review and Updates
This Policy shall be reviewed at least annually or when there is a significant change in:
- Applicable laws or regulations.
- Business operations.
- Technology or applications.
- Personal data processing activities.
- Data categories or processing purposes.
- Data storage or access arrangements.
- Vendors or third-party processors.
- Retention requirements.
- Cross-border transfer arrangements.
- Security or backup controls.
The Data Inventory shall also be reviewed and updated when significant changes occur to personal data processing activities.
21. Compliance
All personnel and applicable third parties shall comply with this Policy and related privacy, information security, data retention, consent management, and data protection procedures.
Violations of this Policy may result in corrective or disciplinary action in accordance with applicable organizational procedures and contractual requirements.
22. Contact
Privacy-related questions, requests, or concerns may be submitted through the designated Cytrusst support or compliance communication channel.
Cytrusst Intelligence Private LimitedBengaluru, Karnataka, India- Website
- https://www.cytrusst.com/
- [email protected]
- Privacy Contact
- [email protected]
23. Acceptance
By accessing Cytrusst services, systems, or applications, or by providing personal data where applicable, individuals acknowledge that their personal data may be processed in accordance with this Policy and applicable privacy requirements.
Where consent is required as the lawful basis, processing shall be performed only after obtaining the required consent.
This Policy shall be read together with applicable contracts, NDAs, privacy notices, information security policies, data retention requirements, and other applicable Cytrusst policies and procedures.