Secureline Technologies Private Limited ("Secureline", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Secureline GRC Platform.
1. Information We Collect
Account Information: When you register, we collect your name, email address, organization name, role, and authentication credentials.
Usage Data: We automatically collect information about how you interact with the Platform, including pages visited, features used, timestamps, browser type, IP address, and device information.
Customer Data: Data you upload, create, or manage within the Platform, including risk assessments, control documentation, audit evidence, compliance records, vendor information, and policy documents.
Cloud Security Data: When you connect cloud accounts (AWS, Azure, GCP) for CSPM features, we collect cloud configuration metadata, resource inventories, and security posture data necessary to perform security assessments.
Integration Data: When you connect third-party services (Jira, Slack, SSO providers), we collect only the data necessary to maintain the integration.
2. How We Use Your Information
We use collected information to:
- Provide, maintain, and improve the Platform and its features
- Authenticate users and enforce access controls
- Process and manage your GRC workflows, compliance programs, and security assessments
- Generate compliance reports, risk analytics, and security posture dashboards
- Send service notifications, security alerts, and product updates
- Detect, prevent, and respond to security threats and fraud
- Comply with legal obligations and regulatory requirements
- Generate anonymized, aggregated analytics to improve the Platform
3. Data Storage & Security
We implement industry-leading security measures to protect your data:
- Encryption: AES-256 encryption at rest, TLS 1.3 for all data in transit
- Tenant Isolation: Row-level security with dedicated encryption keys per tenant
- Access Controls: Role-based access control (RBAC) with audit logging
- Infrastructure: SOC 2 Type II certified cloud infrastructure
- Monitoring: 24/7 security monitoring, intrusion detection, and anomaly alerting
- Backup: Automated encrypted backups with point-in-time recovery (RPO < 1hr)
- Penetration Testing: Regular third-party security assessments
4. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may share data only in the following circumstances:
- Service Providers: With trusted infrastructure and service providers who assist in operating the Platform, subject to strict data processing agreements
- Legal Requirements: When required by law, court order, or regulatory authority
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with advance notice to affected users
- With Your Consent: When you explicitly authorize sharing with specific third parties
5. Data Retention
We retain your data for the duration of your subscription plus a 30-day grace period. After account termination, you may request a full data export within 30 days. After the grace period, all Customer Data is permanently and securely deleted from our systems and backups.
Usage logs and audit trails may be retained for up to 365 days (configurable per workspace) for compliance and security purposes.
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention requirements)
- Portability: Request your data in a structured, machine-readable format
- Restriction: Request restriction of processing in certain circumstances
- Objection: Object to processing based on legitimate interests
- Withdrawal: Withdraw consent where processing is based on consent
To exercise any of these rights, contact us at privacy@secureline.in.
7. International Data Transfers
Your data may be processed in regions outside your country of residence. When we transfer data internationally, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by relevant data protection authorities.
8. Cookies & Tracking
We use essential cookies to:
- Maintain your authenticated session
- Remember your preferences (theme, sidebar state, language)
- Ensure platform security and prevent fraud
We do not use third-party advertising cookies or tracking pixels. Analytics cookies, if enabled, collect only aggregated, anonymized usage data.
9. Compliance Frameworks
Our privacy practices are aligned with:
- GDPR (General Data Protection Regulation) — EU/EEA residents
- DPDP Act 2023 (Digital Personal Data Protection Act) — India
- CCPA (California Consumer Privacy Act) — California residents
- HIPAA — When processing protected health information under a BAA
- SOC 2 Type II — Independently audited security controls
- ISO 27001 — Information security management system
10. Children's Privacy
The Platform is intended for business use and is not directed at individuals under the age of 18. We do not knowingly collect personal information from children.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Platform at least 30 days before they take effect. The "Last updated" date at the top of this page indicates when this policy was last revised.
12. Data Protection Officer
For privacy-related inquiries, complaints, or to exercise your data rights:
- Email: privacy@secureline.in
- DPO: dpo@secureline.in
- Address: Secureline Technologies Pvt. Ltd., Bengaluru, Karnataka, India