1. Who we are
Araghatta ("we", "us") provides AI Security Posture Management software and security-testing services. For platform data processed on behalf of a customer, the customer is the data controller and we act as processor under the Data Processing Addendum. For our website and enquiries, we are the controller.
2. Data we collect
- Enquiry data: name, work email, organisation, and the details you submit through our contact form or when booking a call.
- Platform telemetry (as processor): AI-usage metadata from your endpoints — process/binary names, API-key presence and provider (never values), MCP configurations, installed AI tools, and egress destinations, attributed to machine and user. We do not collect file contents, secret values, keystrokes, or prompt/response bodies.
- Account & usage: authentication data (hashed credentials, MFA secrets), audit logs of actions taken in the console.
- Website: minimal server logs; we do not use advertising trackers. Essential cookies only.
- Workforce (monitored endpoints): for platform customers, the sensor collects AI-usage metadata only — never file contents, prompts, keystrokes or screenshots. See how we handle the privacy of monitored employees, including our DPIA-friendly data map and works-council support.
3. Why we process it & legal basis
To respond to enquiries and provide the service (contract / legitimate interests), to secure and improve the product (legitimate interests), and to meet legal obligations. Platform telemetry is processed only on documented instructions from the customer-controller.
4. Retention
Enquiry data: up to 24 months from last contact. Platform data: per the customer's configured retention, deleted on request or at contract end. Audit logs are retained for the period required for security and compliance.
5. Sharing & subprocessors
We do not sell personal data. We share it only with the subprocessors listed in our Trust Center and DPA, and where legally required. In-VPC deployments have no external data subprocessors.
6. International transfers
Managed tenants can be pinned to a US or EU region. Where transfers occur, we rely on appropriate safeguards (e.g. Standard Contractual Clauses).
7. Your rights
Subject to applicable law (GDPR/UK GDPR/CCPA), you may request access, correction, deletion, restriction, portability, or object to processing, and (CCPA) opt out of "sale" — which we do not do. Contact info@araghatta.com. For platform data, we forward requests to the relevant customer-controller.
8. Security
We apply the controls described in our Trust Center — encryption in transit and at rest, RBAC, MFA, least-privilege access and audit logging.
9. Changes & contact
We will post material changes here with an updated date. Questions: info@araghatta.com.