Skip to content
Legal

Privacy Policy

This policy explains what personal data we process, why, on what legal basis, how long we keep it, and the rights you have. It applies to araghatta.com and the Araghatta platform.

Last updated: August 14, 2026

1. Who we are

Araghatta ("we", "us") provides AI Security Posture Management software and security-testing services. For platform data processed on behalf of a customer, the customer is the data controller and we act as processor under the Data Processing Addendum. For our website and enquiries, we are the controller.

2. Data we collect

  • Enquiry data: name, work email, organisation, and the details you submit through our contact form or when booking a call.
  • Platform telemetry (as processor): AI-usage metadata from your endpoints — process/binary names, API-key presence and provider (never values), MCP configurations, installed AI tools, and egress destinations, attributed to machine and user. We do not collect file contents, secret values, keystrokes, or prompt/response bodies.
  • Account & usage: authentication data (hashed credentials, MFA secrets), audit logs of actions taken in the console.
  • Website: minimal server logs; we do not use advertising trackers. Essential cookies only.
  • Workforce (monitored endpoints): for platform customers, the sensor collects AI-usage metadata only — never file contents, prompts, keystrokes or screenshots. See how we handle the privacy of monitored employees, including our DPIA-friendly data map and works-council support.

3. Why we process it & legal basis

To respond to enquiries and provide the service (contract / legitimate interests), to secure and improve the product (legitimate interests), and to meet legal obligations. Platform telemetry is processed only on documented instructions from the customer-controller.

4. Retention

Enquiry data: up to 24 months from last contact. Platform data: per the customer's configured retention, deleted on request or at contract end. Audit logs are retained for the period required for security and compliance.

5. Sharing & subprocessors

We do not sell personal data. We share it only with the subprocessors listed in our Trust Center and DPA, and where legally required. In-VPC deployments have no external data subprocessors.

6. International transfers

Managed tenants can be pinned to a US or EU region. Where transfers occur, we rely on appropriate safeguards (e.g. Standard Contractual Clauses).

7. Your rights

Subject to applicable law (GDPR/UK GDPR/CCPA), you may request access, correction, deletion, restriction, portability, or object to processing, and (CCPA) opt out of "sale" — which we do not do. Contact info@araghatta.com. For platform data, we forward requests to the relevant customer-controller.

8. Security

We apply the controls described in our Trust Center — encryption in transit and at rest, RBAC, MFA, least-privilege access and audit logging.

9. Changes & contact

We will post material changes here with an updated date. Questions: info@araghatta.com.