Trust Center

Privacy Policy

๐Ÿ“… Effective: 1 June 2025 ๐Ÿ”„ Last updated: 21 June 2026 ๐Ÿ“‹ Version 1.1
๐Ÿ‡ฎ๐Ÿ‡ณ India - DPDP Act 2023 ๐Ÿ‡ช๐Ÿ‡บ EU/EEA - GDPR ๐Ÿ‡บ๐Ÿ‡ธ US - CCPA / State Laws ๐ŸŒ Global

Contents

  1. Who We Are
  2. What Data We Collect
  3. Why We Collect It (Legal Bases)
  4. How We Use Your Data
  5. Who We Share Data With
  6. International Transfers
  7. How Long We Keep Data
  8. Your Rights
  9. Children's Privacy
  10. Cookies
  11. Security
  12. Changes to This Policy
  13. Contact Us
Plain language promise: We've written this policy so that any person can understand exactly what we do with your data, and why. If anything is unclear, email us at contact@fragiliti.com.

1. Who We Are

Fragiliti Narratives Private Limited ("Fragiliti", "we", "us", or "our") is a private limited company incorporated under the Companies Act, 2013, with its registered office at:

163, Ferns Habitat, Doddanekkundi, Bangalore 560037, India.

We make Fragiliti, a decision-support platform that is currently deployed on-premises for enterprise customers - it runs inside your own environment, and the data you analyse with it stays there. Our public website is available at fragiliti.com.

This policy covers the limited personal data we collect directly - through our website, enterprise enquiries, sales and support. It does not cover the data you load into a Fragiliti deployment, which never leaves your environment and to which we have no access (see section 2.3).

For the purposes of applicable data protection laws, in respect of the personal data we collect directly:

Data Protection Contact: Tarun Agarwal - contact@fragiliti.com

2. What Data We Collect

2.1 Data You Give Us Directly

2.2 Data We Collect Automatically

We do not run product analytics that send your usage of a Fragiliti deployment back to us - the software runs in your environment.

2.3 Data Inside Your Fragiliti Deployment

Because Fragiliti is deployed on-premises, any files you load and everything the platform computes stay entirely within your own environment. We do not receive, host, access or store this data. It is yours, and you are its controller.

Important: If that data contains personal information about third parties (e.g. your employees or customers), you are responsible for ensuring you have the legal right to process it within your deployment. Our Data Processing Agreement is available to enterprise customers on request.

2.4 Data From Third Parties

3. Why We Collect It - Legal Bases

We only process your data when we have a lawful reason to do so. Here is an explanation of the legal bases we rely on:

Purpose Legal Basis (GDPR) Legal Basis (DPDP India)
Responding to your enquiry or providing a demo Contract / Legitimate interests Contract / Legitimate use
Enterprise sales and onboarding Contract / Legitimate interests Contract / Legitimate use
Providing support Contract / Legitimate interests Contract / Legitimate use
Sending product and security updates Legitimate interests Legitimate use
Sending marketing emails Consent Consent
Legal compliance and fraud prevention Legal obligation Legal obligation
Security and abuse prevention Legitimate interests / Legal obligation Legitimate use / Legal obligation

4. How We Use Your Data

We never sell your personal data to any third party.

5. Who We Share Data With

We share data only where necessary, and only with parties who are contractually bound to protect it.

Party Purpose Location
Web3Forms Processing submissions from our website contact form United States
Google Firebase Hosting Hosting and serving our public website Global (Google Cloud)
Cloudflare Web Analytics Cookieless, privacy-first measurement of website usage (aggregate page views) Global (EU / US)
Email and productivity providers Corresponding with you about enquiries, sales and support Global
Legal and regulatory authorities When required by law or court order As required
Business acquirers In the event of a merger, acquisition, or asset sale (you will be notified) As applicable

We do not share your data with advertisers, data brokers, or any party for their own marketing purposes.

For on-premises deployments, your data is processed entirely within your own environment and is not shared with sub-processors. A current sub-processor list covering any hosted services is available to enterprise customers on request.

6. International Transfers

Fragiliti is based in India. The personal data we collect directly (enquiries, sales and support) may be processed in India and in other countries where our website service providers operate - for example, the United States for our contact-form provider. Data inside your on-premises deployment is not transferred to us and stays wherever you host it.

For EU/EEA users (GDPR)

When we transfer the data we hold outside the EU/EEA, we rely on appropriate safeguards, such as:

For Indian users (DPDP Act 2023)

We transfer personal data outside India only to countries or entities permitted under applicable rules notified by the Government of India.

For US users

We comply with applicable US state privacy laws including CCPA (California), VCDPA (Virginia), and equivalent laws. We do not "sell" personal data as defined under these laws.

7. How Long We Keep Your Data

Type of DataRetention Period
Enquiry & contact-form dataUp to 24 months after your last contact, or until you ask us to delete it
Sales recordsDuration of the relationship, plus as required for tax and legal obligations
Support communications3 years
Website server logs90 days
Data inside your deploymentNot applicable - held in your environment, never by Fragiliti
Legal hold dataAs required by law or ongoing dispute

After retention periods expire, we securely delete or anonymise your data.

8. Your Rights

Depending on where you are located, you have various rights over your personal data. We honour all of them.

Everyone (Global)

EU/EEA residents (GDPR)

Indian residents (DPDP Act 2023)

California residents (CCPA/CPRA)

To exercise any right: Email contact@fragiliti.com with the subject line "Privacy Rights Request". We will verify your identity and respond within 30 days (EU: 1 month, extendable by 2 months for complexity). No fees are charged for reasonable requests.

9. Children's Privacy

The Fragiliti Platform is designed for business users and is not intended for children under the age of 18 (or the applicable age of digital consent in your jurisdiction, 13 in the US, 16 in much of the EU).

We do not knowingly collect data from minors. If you believe a child has provided us with personal data, please contact us immediately at contact@fragiliti.com and we will delete it promptly.

10. Cookies

Our website uses a strictly necessary preference store (such as your light/dark theme choice) via local storage. For privacy-friendly usage measurement we use Cloudflare Web Analytics, which is cookieless โ€” it counts aggregate page views and visit data without setting cookies and without tracking you across other websites. We do not use advertising cookies.

11. Security

The data you analyse in Fragiliti stays within your own on-premises environment, secured by your infrastructure; we do not receive or store it. For the limited personal data we do hold (enquiries, sales and support), key measures include:

For our full security practices, see the Security Compliance Overview.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will:

The latest version always governs. If you have questions about a change, contact us at contact@fragiliti.com.

13. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data:

NameTarun Agarwal
RoleData Protection Contact / Grievance Officer
Emailcontact@fragiliti.com
AddressFragiliti Narratives Private Limited, 163, Ferns Habitat, Doddanekkundi, Bangalore 560037, India
Response timeWithin 48 hours (acknowledgement), 30 days (resolution)

For EU residents: if you are not satisfied with our response, you have the right to complain to your local data protection authority.