Elytra Security ("Elytra", "we", "us") respects your privacy. This policy explains what personal data we process through this website, why, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDPA) and the EU/UK General Data Protection Regulation (GDPR).
This site sets no cookies and performs no tracking. No analytics, no advertising or social pixels, no fingerprinting, and no third‑party requests — fonts are self‑hosted. The only personal data we hold is what you choose to send us through the evaluation/contact form.
Elytra Security is the Data Fiduciary (DPDPA) and Data Controller (GDPR) for personal data collected via this website. Elytra Shield is our on‑premise endpoint inventory and patch‑compliance product. Contact: privacy@elytra.security.
We practise data minimisation. We collect only:
We do not collect data through cookies, analytics, or third‑party scripts. Our hosting provider may keep short‑lived server logs (including IP address and timestamp) strictly for security and to deliver the page; these are not used to profile you and are retained only briefly.
We use the form details for one purpose: to respond to your enquiry and arrange an evaluation. The legal basis is your consent — given by ticking the consent box at the point of submission (DPDPA s.6; GDPR Art. 6(1)(a)). We will not use your details for marketing, and we will not build a profile of you.
Your operational data stays with you. Elytra Shield is on‑premise. Endpoint inventory, patch results and evidence are processed entirely inside your own network and are never transmitted to Elytra. This policy covers only the marketing website.
We do not sell or rent personal data, and we do not share it for advertising. We may use a small number of vetted data processors (e.g. our email provider) acting on our instructions under contract. We disclose data only where legally required.
We keep evaluation enquiries only as long as needed to handle your request and any follow‑up — by default no longer than 12 months — after which they are deleted, unless you enter into an agreement with us or ask us to keep them. You can ask us to erase your data sooner at any time.
We are based in India and process data here. Where a processor is located outside your jurisdiction, transfers are made only with appropriate safeguards (e.g. GDPR standard contractual clauses) and consistent with DPDPA requirements.
To exercise any right, email privacy@elytra.security. We respond within the timelines required by applicable law.
Our Grievance Officer / Data Protection Officer is reachable at grievance@elytra.security. If you are not satisfied, you may complain to the Data Protection Board of India (under the DPDPA) or, in the EU/UK, to your local supervisory authority.
Form submissions are sent over TLS. We apply access controls and retention limits, and we keep the attack surface small by avoiding cookies, trackers and third‑party scripts entirely.
This is a business product website not directed at children. We do not knowingly collect data from anyone under the age of 18, consistent with the DPDPA.
If we change this policy we will update the date above and, for material changes, note it on this page. Continued use after an update reflects the current version.
Questions about this policy? Email privacy@elytra.security.