At CITRA Insight, we deal with information about software environments that belong to our customers. We take that responsibility seriously.
This Privacy Policy explains what information we collect, why we collect it, how we protect it, how long we keep it, and the choices available to you.
CITRA Insight is a product of Code & Clause Systems, a sole proprietorship based in Bhopal, Madhya Pradesh, India.
GSTIN: 23DDQPS9840L1ZN
For the purposes of applicable data protection law, Code & Clause Systems is responsible for determining how personal data is handled in connection with the CITRA Insight service.
CITRA Insight is designed to understand the software environment of the machines included in an assessment.
When the CITRA collection utility is run on an authorised Windows device, it may collect information such as:
The collection utility is not designed to collect the contents of personal files, email messages, browsing history, keystrokes or screenshots.
The organisation running the assessment is responsible for ensuring that the CITRA utility is used only on devices it owns or is authorised to assess.
The information collected by CITRA is used to:
We do not use assessment findings to market software products to you.
Where applicable under the Digital Personal Data Protection Act, 2023 and other relevant law, individuals may have rights relating to their personal data, including rights to access, correction, erasure and grievance redressal.
Requests relating to personal data can be sent to: hello@citrainsight.in
Please include enough information for us to understand the request and identify the relevant customer or engagement.
Where a request concerns an employee or other individual whose device was assessed on behalf of an organisation, we may need to coordinate with that organisation before taking action.
We take reasonable technical and organisational measures to protect information handled through CITRA Insight.
Data transmitted to our systems is encrypted in transit using TLS. Stored data is encrypted at rest where supported by the relevant infrastructure.
Customer environments are logically separated so that one customer cannot access another customer's assessment data.
Access to customer information is restricted to people who need it to provide the service or support the engagement.
CITRA Insight is designed to store customer assessment data on infrastructure located in India.
We aim to keep the handling of customer assessment information within the scope described in this Privacy Policy and our contractual arrangements with customers.
Your assessment data belongs to your business.
We do not sell customer assessment data.
We do not provide software publishers with your assessment findings for their compliance or commercial activities.
We do not disclose customer assessment information to third parties except where:
CITRA Insight is designed as a one-time assessment service.
The encrypted scan bundles collected from your machines, together with findings derived from those bundles, are retained for 30 days after your report is delivered.
This period allows us to answer reasonable questions about your report and verify findings against the underlying assessment data.
After the 30-day period, the scan data is permanently deleted in accordance with our retention process.
You may request earlier deletion of scan data, subject to any legal or contractual requirement that prevents us from doing so.
Certain business records, such as invoices, payment records and engagement references, may need to be retained for the period required under applicable tax, accounting or other laws.
For privacy or data protection concerns, you may contact:
Chitra Arora
Email: hello@citrainsight.in
We aim to respond to grievances within the applicable statutory timeframe and, where applicable, within 30 days.
For privacy-related questions or requests: hello@citrainsight.in