Legal

Privacy Policy

How Zurlux Technologies collects, uses, and protects your personal data under the DPDP Act 2023.

Last updated: 1 July 2026 · Effective date: 1 July 2026

This Privacy Policy explains how Zurlux Technologies Private Limited ("Zurlux", "we", "our", or "us") collects, uses, stores, and protects personal data in connection with our PatchMortem platform and this website. This policy is prepared in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India.

1. Who we are

Zurlux Technologies Private Limited is incorporated in India (CIN: U62013PN2026PTC257274) with its registered office at Flat No. 304, C-Wing, Aavishkar, Moshi, Pune, Maharashtra 412105. We are the Data Fiduciary for personal data collected through our products and services.

2. Data we collect

2.1 Information you provide directly

2.2 Information collected automatically

2.3 Data collected through PatchMortem

Infrastructure telemetry collected by PatchMortem is processed as customer data under our Data Processing Addendum. It is not used for any purpose other than delivering the PatchMortem service to the customer that owns it.

3. How we use your data

4. Legal basis for processing

We process personal data on the following grounds under the DPDP Act 2023:

5. Data storage and residency

All personal and customer data is stored and processed in AWS Asia Pacific (Mumbai), ap-south-1, within India. We do not transfer personal data outside India without appropriate safeguards in place and, where required, without your consent or a valid legal basis.

6. Data retention

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law. Customer infrastructure data is retained for the period specified in the applicable service agreement. After termination of a customer account, data is deleted within 90 days unless a longer retention period is required by law.

7. Your rights under the DPDP Act 2023

As a Data Principal, you have the following rights:

To exercise any of these rights, write to us at privacy@zurlux.com. We will respond within 30 days.

8. Third-party processors

We use the following categories of third-party processors, each bound by data processing agreements:

9. Security

We implement technical and organisational measures to protect personal data, including TLS 1.3 encryption in transit, AES-256 encryption at rest, per-tenant key isolation, role-based access control, and append-only audit logging. For full details, see our Security page.

10. Children

Our products and services are directed at enterprise IT professionals and are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors.

11. Changes to this policy

We will notify customers of material changes to this policy by email at least 30 days before they take effect. The current version is always available at this URL.

12. Contact and grievance officer

Grievance Officer
Rakesh Sakat
Zurlux Technologies Private Limited
Flat No. 304, C-Wing, Aavishkar, Moshi, Pune, Maharashtra 412105
privacy@zurlux.com
Response within 30 days of receipt