Skip to content
New · Ask Viglyn, your AI compliance copilot. Ask your program anything.See it
Legal

Privacy Policy

Effective: 13 May 2026Last updated: 13 May 2026

Viglyn Technology Private Limited ("Viglyn", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, share, and safeguard personal data when you visit our Website or use our governance, risk, and compliance ("GRC") automation platform and related services (the "Service").

This Policy is designed to comply with the Digital Personal Data Protection Act, 2023 ("DPDP Act") of India, and where applicable, the EU/UK General Data Protection Regulation ("GDPR") and other data protection laws. If you do not agree with this Policy, please do not use the Service.

1. Who We Are

For the purposes of the DPDP Act:

  • When we collect personal data from visitors to our Website, prospects, candidates, and individuals who contact us, we act as the Data Fiduciary and determine the purposes and means of processing.
  • When we process personal data on behalf of our customers as part of providing the Service, we act as a Data Processor under instructions from our customer (the Data Fiduciary). The customer's privacy policy and our Data Processing Addendum govern that processing.

Under the GDPR, the corresponding concepts are "controller" and "processor". Viglyn Technology Private Limited is incorporated under the Companies Act, 2013, with its registered office in India.

2. Scope of This Policy

This Policy describes how Viglyn processes personal data as a Data Fiduciary, including data we collect from visitors to our Website; prospective customers and leads; representatives of our customers (such as administrators and Authorized Users); job applicants; and vendors, partners, and other business contacts.

This Policy does not apply to personal data we process on behalf of our customers as a Data Processor (that is governed by our agreement with the customer and our Data Processing Addendum) or to third-party websites or services linked from our Website.

3. Personal Data We Collect

3.1 Information you provide directly

  • Account information: name, business email, phone number, job title, employer, password.
  • Billing information: billing contact, billing address, GSTIN (if applicable). Payment card details are collected and processed by our payment processor and are not stored by us.
  • Communications: the content of your emails, support tickets, demo requests, sales inquiries, and chat messages.
  • Recruitment data: your CV, employment history, and any other information you submit when applying for a role at Viglyn.

3.2 Information collected automatically

  • Device and log data: IP address, browser type and version, operating system, device identifiers, language preferences, referring URLs, pages viewed, and timestamps.
  • Usage data: features used, actions taken, time spent, errors encountered.
  • Cookies and similar technologies: see Section 9.

3.3 Information from third parties

  • Authentication providers: if you sign in via single sign-on, we receive basic profile information from those providers.
  • Marketing and enrichment data: publicly available business information from third-party sources, used for sales prospecting and account research.
  • Integration data: when you connect a Third-Party Service to your account, we receive data from those services in accordance with the permissions you grant. This data is Customer Data and is processed under our Data Processing Addendum, not this Policy.

We do not knowingly collect personal data of children (individuals under 18) in our role as Data Fiduciary. See Section 11.

4. How We Use Personal Data

We use personal data for the following purposes:

PurposeExamplesLegal basis
Providing the ServiceCreating and managing your account, authenticating users, delivering features, providing supportPerformance of a contract / certain legitimate uses under DPDP
Billing and paymentsProcessing subscription fees, issuing invoices, tax reportingPerformance of a contract / legal obligation
Sales and marketingResponding to inquiries, sending product updates, scheduling demos, account-based marketing, newslettersConsent (where required) / legitimate interests
Service improvementAnalytics, debugging, capacity planning, developing new featuresLegitimate interests / certain legitimate uses
Security and fraud preventionMonitoring for abuse, investigating incidents, enforcing termsLegitimate interests / legal obligation
Legal complianceResponding to lawful requests, tax records, audit obligationsLegal obligation
RecruitmentEvaluating applications, conducting interviews, making hiring decisionsConsent / steps prior to entering a contract

We will obtain your consent where required by applicable law, and you have the right to withdraw consent at any time as described in Section 7.

5. How We Share Personal Data

We do not sell personal data. We share personal data only as described below:

5.1 Sub-processors and service providers

We engage trusted vendors to help us operate the Service, including providers of cloud hosting, payment processing, business productivity tools, customer support and CRM platforms, and analytics and monitoring services. Each sub-processor is bound by written terms requiring confidentiality and appropriate safeguards. A current list of sub-processors is available on request.

5.2 Customers

If you are an Authorized User of a customer organization, we may share account-related information (such as your name, email, and activity) with that organization's account administrators.

5.3 Legal and safety

We may disclose personal data when we believe in good faith that disclosure is necessary to comply with applicable law or a lawful request; to protect the rights, property, or safety of Viglyn, our customers, or others; to investigate suspected fraud or violations; or to respond to a legal process.

5.4 Business transfers

If Viglyn is involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to standard confidentiality undertakings. We will notify affected individuals as required by law.

5.5 With your consent

We may share personal data with third parties where you have given consent for us to do so.

6. International Data Transfers

Viglyn primarily stores personal data on servers located in India. Some of our sub-processors may process data in other jurisdictions. Where we transfer personal data internationally, we rely on appropriate safeguards, such as:

  • Transfers to countries not restricted by the Indian Government under Section 16 of the DPDP Act.
  • The European Commission's Standard Contractual Clauses for transfers from the EEA.
  • The UK International Data Transfer Addendum for transfers from the UK.
  • Other lawful mechanisms permitted under applicable law.

You may contact us through the channels published on the Website for more information about the safeguards we use.

7. Your Rights

7.1 Under the DPDP Act

As a Data Principal you have the right to:

  • Access information about the personal data we process about you, including a summary of the data, processing activities, and the identities of Data Fiduciaries and Data Processors with whom the data has been shared.
  • Correction and erasure of inaccurate or misleading data and of personal data that is no longer necessary for the purpose for which it was collected.
  • Grievance redressal through the mechanism described in Section 14.
  • Nominate another individual to exercise your rights in the event of your death or incapacity.
  • Withdraw consent at any time, where processing is based on consent. Withdrawal will not affect the lawfulness of processing before the withdrawal.

7.2 Under the GDPR (where applicable)

You additionally have rights of access, rectification, erasure, restriction of processing, data portability, objection, and the right not to be subject to solely automated decision-making that produces legal or similarly significant effects. You also have the right to lodge a complaint with your local supervisory authority.

7.3 How to exercise your rights

You can exercise these rights by contacting us through the channels published on our Website, providing sufficient information for us to verify your identity. We will respond within the time required by applicable law. We will not discriminate against you for exercising any of these rights.

8. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. Indicative retention periods:

  • Account data: for the duration of your account, plus a reasonable period thereafter for legal and operational purposes.
  • Billing and tax records: up to eight (8) years to comply with Indian tax and corporate law requirements.
  • Marketing data: until you unsubscribe or otherwise object, after which we retain a suppression record to honour your preference.
  • Support communications: up to three (3) years after the last interaction.
  • Recruitment data: up to two (2) years after the conclusion of the recruitment process, unless you ask us to delete it sooner.
  • Server and security logs: generally up to twelve (12) months, subject to longer retention if required for an active investigation.

When personal data is no longer needed, we will delete or anonymize it in line with our retention schedule.

9. Cookies and Similar Technologies

We use cookies and similar tracking technologies on the Website to:

  • Keep you signed in (essential cookies).
  • Remember your preferences.
  • Understand how the Website is used and improve it (analytics cookies).
  • Support our marketing efforts (advertising cookies, where applicable).

You can manage cookies through your browser settings and, where required, through our cookie banner. Disabling certain cookies may affect the functionality of the Website.

10. Security

We maintain administrative, technical, and physical safeguards designed to protect personal data, including encryption of data in transit and at rest, role-based access controls and least-privilege principles, multi-factor authentication for internal systems, regular vulnerability assessments and penetration testing, continuous monitoring and logging, vendor risk management, and security training for our personnel.

No method of transmission over the internet or electronic storage is fully secure. We cannot guarantee absolute security, but we work continuously to protect your data. In the event of a personal data breach, we will notify affected individuals and the Data Protection Board of India as required by the DPDP Act and other applicable laws.

11. Children's Data

The Service is intended for use by organizations and their personnel. We do not knowingly collect personal data of individuals under the age of 18 in our capacity as Data Fiduciary. Where we process children's data on behalf of a customer, the customer is responsible for obtaining verifiable parental consent in accordance with the DPDP Act.

If you believe we have collected personal data from a child without appropriate consent, please contact us through the channels published on our Website and we will take steps to delete it.

12. Automated Decision-Making

We do not use personal data we process as a Data Fiduciary to make decisions that produce legal or similarly significant effects on you solely by automated means. Some Service features perform automated analysis on Customer Data (such as compliance checks), but these are configured and acted upon by our customers, not by Viglyn.

13. Changes to This Policy

We may update this Policy from time to time. If we make material changes, we will notify you by updating the "Last Updated" date above and, where appropriate, through the Service or other reasonable means. We encourage you to review this Policy periodically.

14. Grievance Redressal and Contact

If you have any questions, concerns, or complaints about this Policy or our processing of personal data, please contact us through the grievance redressal channels published on our Website. We have appointed a Grievance Officer in accordance with the DPDP Act, whose details are published and kept current on the Website.

We will acknowledge your communication and aim to resolve it within the timelines prescribed under the DPDP Act. If you are not satisfied with our response, you have the right to escalate your complaint to the Data Protection Board of India under the DPDP Act, or to your local supervisory authority under the GDPR (where applicable).

Contact
Viglyn Technology Private Limited
Unit 101 Oxford Towers, 139/88 HAL Old Airport Rd, H.A.L II Stage, Bangalore, Karnataka, India 560008