← CITRA Insight

Privacy Policy

Last updated: July 2026

At CITRA Insight, we deal with information about software environments that belong to our customers. We take that responsibility seriously.

This Privacy Policy explains what information we collect, why we collect it, how we protect it, how long we keep it, and the choices available to you.

1. Who We Are

CITRA Insight is a product of Code & Clause Systems, a sole proprietorship based in Bhopal, Madhya Pradesh, India.

GSTIN: 23DDQPS9840L1ZN

For the purposes of applicable data protection law, Code & Clause Systems is responsible for determining how personal data is handled in connection with the CITRA Insight service.

2. Information We Collect

CITRA Insight is designed to understand the software environment of the machines included in an assessment.

When the CITRA collection utility is run on an authorised Windows device, it may collect information such as:

  • Installed software, including software names, versions and publishers
  • Hardware information such as processor, memory, storage and operating system
  • Software usage information where required for the assessment
  • Installed fonts and audio plugins
  • Software activation and licensing indicators

The collection utility is not designed to collect the contents of personal files, email messages, browsing history, keystrokes or screenshots.

The organisation running the assessment is responsible for ensuring that the CITRA utility is used only on devices it owns or is authorised to assess.

3. Why We Collect This Information

The information collected by CITRA is used to:

  • Build an inventory of software across the assessed environment
  • Compare installed software with licence and purchase information provided by the customer
  • Identify technical indicators that may require further licence review
  • Calculate indicative financial exposure where appropriate
  • Identify potentially unused or unnecessary software
  • Prepare the CITRA Insight assessment report
  • Provide support relating to the assessment

We do not use assessment findings to market software products to you.

4. Your Rights

Where applicable under the Digital Personal Data Protection Act, 2023 and other relevant law, individuals may have rights relating to their personal data, including rights to access, correction, erasure and grievance redressal.

Requests relating to personal data can be sent to: hello@citrainsight.in

Please include enough information for us to understand the request and identify the relevant customer or engagement.

Where a request concerns an employee or other individual whose device was assessed on behalf of an organisation, we may need to coordinate with that organisation before taking action.

5. Data Security

We take reasonable technical and organisational measures to protect information handled through CITRA Insight.

Data transmitted to our systems is encrypted in transit using TLS. Stored data is encrypted at rest where supported by the relevant infrastructure.

Customer environments are logically separated so that one customer cannot access another customer's assessment data.

Access to customer information is restricted to people who need it to provide the service or support the engagement.

6. Where Your Data Is Stored

CITRA Insight is designed to store customer assessment data on infrastructure located in India.

We aim to keep the handling of customer assessment information within the scope described in this Privacy Policy and our contractual arrangements with customers.

7. When We Share Information

Your assessment data belongs to your business.

We do not sell customer assessment data.

We do not provide software publishers with your assessment findings for their compliance or commercial activities.

We do not disclose customer assessment information to third parties except where:

  • You have authorised us to do so;
  • It is necessary for a service provider supporting CITRA Insight and that provider is subject to appropriate confidentiality and data protection obligations; or
  • Disclosure is required by applicable law or a lawful order.

8. How Long We Keep Your Data

CITRA Insight is designed as a one-time assessment service.

The encrypted scan bundles collected from your machines, together with findings derived from those bundles, are retained for 30 days after your report is delivered.

This period allows us to answer reasonable questions about your report and verify findings against the underlying assessment data.

After the 30-day period, the scan data is permanently deleted in accordance with our retention process.

You may request earlier deletion of scan data, subject to any legal or contractual requirement that prevents us from doing so.

Certain business records, such as invoices, payment records and engagement references, may need to be retained for the period required under applicable tax, accounting or other laws.

9. Grievance Officer

For privacy or data protection concerns, you may contact:

Chitra Arora
Email: hello@citrainsight.in

We aim to respond to grievances within the applicable statutory timeframe and, where applicable, within 30 days.

10. Contact

For privacy-related questions or requests: hello@citrainsight.in