Privacy Policy
Effective 10 October 2026. Data Fiduciary / Controller: Support IT Ventures, Mumbai, Maharashtra, India.
This policy explains what personal data Kavach processes, why, for how long, and your rights. It is written to meet the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (India), and, for users in the EU/UK, the GDPR / UK GDPR.
1. Data we collect
| Category | What | Source |
|---|---|---|
| Account data | email address, hashed API key, plan and payment-provider references (customer / subscription ids), Terms version accepted and when, organisation membership and role | you |
| Scan data | the target URL/domain you submit, the technical observations (response headers, certificate metadata, DNS records, script origins and hashes, redirect behaviour), grades, category scores, signed evidence manifests, deployment ids you report | you; the public responses of the target |
| Monitoring data | schedules, alert channels (webhook URL, Slack URL or email address), alert delivery logs, guarded payment-page URLs and script baselines | you |
| Operational data | IP address of requests, timestamps, rate-limit and security events (e.g. refused targets), server logs | your use of the Service |
| Billing data | handled by Razorpay / Stripe; we receive confirmations and references only. We never store card, UPI or bank details. | payment provider |
We do not store response bodies of scanned pages beyond what is needed to classify a
finding during the scan, and we never store the contents of exposed secret files (such as
.env): we record only that a file matched a classifier, its size and a hash.
2. Purposes and lawful basis
- Providing the Service you requested (scans, reports, monitoring, alerts, passports) — performance of a contract / your consent given when you submit a target.
- Security and abuse prevention (rate limits, SSRF defence, telemetry, blocking misuse) — legitimate interest / legal obligation to keep the Service and third parties safe.
- Billing, invoicing and tax compliance — contract and legal obligation.
- Service communications (alerts you configured, security notices, Terms changes) — contract. We do not send marketing email without separate consent.
- Research and improvement using aggregated, de-identified statistics that never identify a specific website or person — legitimate interest.
3. Cookies and local storage
Kavach sets no tracking or advertising cookies and uses no third-party analytics. Your browser’s local storage may hold your API key for convenience (“Use key” / “Forget key” in the dashboard); it stays on your device. Embedded badges are plain images and do not track viewers.
4. Sharing and sub-processors
We share personal data only with providers needed to run the Service, each bound by their own terms and security commitments: Hostinger (hosting and email, servers in India/EU), Razorpay (payments, India), Stripe (international payments, if enabled), Google Public DNS (DNS-over-HTTPS lookups of the domains you scan), and public Certificate Transparency logs (crt.sh, Cert Spotter) when you use the CT explorer. Alerts you configure are sent to the webhook, Slack or email destination you chose. We do not sell personal data. We may disclose data if required by law or to protect rights, safety or the Service.
5. International transfers
Data is primarily stored in India. Where a sub-processor processes data outside India (or outside the EU/UK for European users) we rely on the provider’s contractual safeguards and, for European users, standard contractual clauses or an adequacy decision as applicable.
6. Retention
| Data | Retention |
|---|---|
| Public scans (not linked to an account) | 30 days |
| Scan history of verified domains | Free 30 days · Pro 180 · Team/Agency 400 · Business 730 days (per plan) |
| Account, domains, schedules, alert logs | life of the account |
| Security/abuse events and server logs | 90 days |
| Billing records | as required by Indian tax law (currently 8 years) |
| After account deletion | purged within 30 days, including from backups within their 14-day rotation |
7. Security
API keys are stored hashed; evidence manifests are signed; all traffic is encrypted in transit (TLS 1.2+, HSTS); servers are firewalled and patched automatically; access is key-based only; the scanner is isolated from internal networks and is itself continuously audited by Kavach’s own checks. No system is perfectly secure; we will notify you and the Data Protection Board of India (and, where applicable, EU/UK authorities) of a personal data breach as the law requires.
8. Your rights
You may: access and obtain a copy of your data (GET /api/export or on request),
correct it, delete your account and data (DELETE /api/account or on request), withdraw
consent (which stops the related processing going forward), nominate a person to exercise your
rights under the DPDP Act, and lodge a grievance with us or a complaint with the Data Protection
Board of India. EU/UK users additionally have rights to restriction, objection, portability and to
complain to their supervisory authority. We respond within 30 days.
Grievance Officer (DPDP): Support IT Ventures, Mumbai, Maharashtra, India — privacy@kavachscan.com.
9. Children
The Service is for businesses and adults (18+). We do not knowingly process children’s data.
10. Changes
We will post changes here with a new effective date and notify account holders of material changes by email or in the dashboard.
Contact: privacy@kavachscan.com · Support IT Ventures, Mumbai, Maharashtra, India