This Privacy Policy explains how Bugmetrics Technologies Private Limited (CIN: U58201KA2024PTC186247) ("Bugmetrics", "we", "us", or "our") collects, uses, shares, stores, and protects personal data when you visit https://bugmetrics.io (the "Website") or use our platform and related services (together, the "Services").
We process personal data in accordance with applicable laws, including India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and, where applicable, the EU/UK General Data Protection Regulation ("GDPR").
1. Our Role
- Data Fiduciary / Controller, for Website visitors, prospects, account users, and business contacts, where we determine the purpose and means of processing.
- Data Processor, for customer data processed within the Bugmetrics platform under a Master Services Agreement ("MSA") or other applicable customer agreement.
Customers remain responsible for determining the lawful basis for processing personal data they submit to the Services. This Policy primarily addresses our role as Data Fiduciary.
2. Categories of Personal Data
Depending on how you interact with us, we may collect:
- Identity, name, designation, company.
- Contact, business email and phone number.
- Account, details to provision and administer platform access.
- Authentication, username, password hash, MFA settings.
- Device & browser, device type, browser, OS.
- IP address and security logs.
- Audit logs and platform activity.
- Support communications.
- Scheduling, details when booking a demo or meeting.
- Marketing preferences.
- Billing, where applicable to your engagement.
3. How We Collect Personal Data
We collect personal data:
- directly from you (for example, when you request a demo or contact us);
- automatically through cookies and analytics (see our Cookies Policy);
- from customer administrators who provision users; and
- from integrated third-party systems authorised by our customers.
Analytics cookies load only after you accept them in the cookie banner. You can change or withdraw that choice anytime via Cookie settings in the Website footer. For details of the cookies and analytics technologies we use (including Google Analytics) and how to manage your preferences, see our Cookies Policy.
4. Purposes and Legal Basis
We process personal data for the following purposes.
Where we rely on consent (for example, for non-essential cookies or certain marketing), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
5. Security Logs
To protect our platform and users, we collect and process authentication logs, login history, failed login attempts, administrative activity, audit trails, and security events. These records help us detect, investigate, and respond to security incidents.
6. AI and Automated Processing
Bugmetrics may use automated technologies, including artificial intelligence, to analyse cybersecurity events, prioritise risks, recommend remediation actions, generate summaries, and improve platform functionality.
These capabilities assist users and are not intended to produce solely automated decisions that have legal or similarly significant effects on individuals. Where automated processing is used, human oversight remains part of how decisions are made.
7. How We Share Personal Data
We never sell personal data. We share personal data only as follows, and our service providers are bound by contractual obligations to protect it and use it solely as instructed:
- Cloud hosting providers.
- Email delivery providers.
- CRM providers.
- Scheduling providers.
- Customer support providers.
- Analytics providers.
- Professional advisers (legal, accounting, and similar).
- Government or regulatory authorities, where legally required.
- Successors in a merger, acquisition, financing, or sale of assets, in which case we will require the recipient to honour this Policy and notify you before your data becomes subject to a different policy.
Sub-processors. A current list of the key sub-processors we engage is available on request at legal@bugmetrics.io.
8. Data Hosting and International Transfers
Customer data is primarily hosted on Amazon Web Services (AWS) in the Asia Pacific (Mumbai) region (ap-south-1), within India. Certain service providers (for example, analytics or email tools) may process limited personal data outside India.
Where international transfers occur, Bugmetrics applies appropriate contractual and technical safeguards consistent with applicable law. Transfers of personal data outside India are made in accordance with the DPDP Act and any restrictions notified by the Central Government.
9. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. Indicative retention periods:
When personal data is no longer required, we erase or anonymise it. Where you withdraw consent or your account is closed, we erase your personal data unless retention is required by law.
10. Your Rights as a Data Principal
Subject to applicable law, you may exercise the following rights:
- Access, a summary of the personal data we process about you and our processing activities.
- Correction and updating, correction of inaccurate or incomplete data.
- Erasure, deletion of data no longer necessary for the purpose collected, subject to legal retention requirements.
- Withdrawal of consent, where processing is based on consent.
- Grievance redressal, to have grievances addressed through our Grievance Officer.
- Nomination, to nominate another individual to exercise your rights in the event of death or incapacity, under the DPDP Act.
Where GDPR applies, you may also have rights to data portability, restriction of processing, objection to processing, and to lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at legal@bugmetrics.io. We will respond within the timelines required by applicable law and may need to verify your identity before acting on a request.
11. Security of Your Personal Data
As a cybersecurity company, protecting data is central to what we do. We maintain administrative, technical, and physical safeguards, including:
- encryption of data in transit and at rest;
- role-based access control and least-privilege access;
- security monitoring and audit logging;
- vulnerability management;
- secure software development practices;
- backup and recovery controls;
- infrastructure hosted in AWS Mumbai (ap-south-1);
- an ISMS aligned with ISO/IEC 27001:2022 (certification in progress).
No method of transmission or storage is completely secure; while we use appropriate measures to reduce risk to an appropriate level, we cannot guarantee absolute security. To report a security concern or suspected vulnerability, contact security@bugmetrics.io.
12. Security Incidents
Where required by law or contract, Bugmetrics will notify affected customers without undue delay following confirmation of a security incident involving customer personal data, and will cooperate as needed to meet applicable breach-notification obligations.
13. Government and Legal Requests
Bugmetrics may disclose personal data where necessary to comply with a legal obligation or a valid request from a public authority. Where legally permitted, we will endeavour to notify the relevant customer before disclosing their data in response to such a request.
14. Children's Data
The Services are intended for business use by professionals and are not directed to individuals under the age of 18. We do not knowingly collect personal data of children (individuals under 18). If we become aware that we have inadvertently collected a child's personal data without verifiable parental or guardian consent, we will take steps to delete it. If you believe a child has provided us with personal data, contact legal@bugmetrics.io.
15. Third-Party Links
Our Website may contain links to third-party websites and services we do not operate or control. This Privacy Policy does not apply to them, and we are not responsible for their content or privacy practices. We encourage you to review their privacy policies.
16. Grievance Officer and Contact
In accordance with the DPDP Act, you may contact our Grievance Officer with any questions, concerns, or grievances regarding your personal data or this Privacy Policy:
We will acknowledge and respond to grievances within the timelines prescribed under applicable law.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will revise the version number and "Last Updated" date above, and material changes will be communicated through the Website or other appropriate channels. Your continued use of the Services after changes become effective constitutes acknowledgement of the updated Policy.