Skip to main content

SecurePledge

SecurePledge Privacy Policy 

Effective Date: [CONFIRM: effective date] Last Updated: [CONFIRM: last updated date] 

Introduction

This Privacy Policy explains how [CONFIRM: exact registered legal entity name – believed to be StrategyWiz Consulting Private Limited] (“SecurePledge,” “we,” “us,” or “our“) collects, uses, discloses, and protects information in connection with the SecurePledge AI Interaction Security Platform (the “Service“), our website at [CONFIRM: website URL] (the “Site“), and related products, including the AI Gateway, the Sensitive Data Redactor, the Shadow AI Protector, and the Governance & Audit Layer (collectively, the “Platform“). 

SecurePledge is a business-to-business (“B2B”) platform. It is designed to sit between an organization’s employees and third-party AI tools (such as ChatGPT, Claude, and Gemini) to detect, prevent, redirect, log, and help prove appropriate handling of sensitive data during AI interactions. 

Please read this Policy carefully. By using the Site or the Service, you agree to the practices described here, in conjunction with our Terms and Conditions and, where applicable, the negotiated agreement between SecurePledge and your organization.

Scope of This Policy – Who This Applies To

Because SecurePledge is a B2B security platform, different people interact with us in different capacities, and this Policy applies differently to each: 

  • Website visitors who browse the Site, request a demo, or contact us. 
  • Customer administrators and authorized users – individuals at an organization (“Customer“) who register for, configure, or manage a SecurePledge account. 
  • End users – employees or contractors of a Customer whose AI prompts and interactions are processed by the Service because their employer has deployed SecurePledge. 

Important – please read: When a Customer deploys SecurePledge (the AI Gateway, Redactor, Protector, or Governance Dashboard) inside its organization, SecurePledge acts as a data processor / service provider on behalf of that Customer. The Customer is the data controller / data fiduciary with respect to the personal data of its own employees. If you are an end user and have questions about how your employer has configured SecurePledge, what is logged, or how your data is used, please contact your employer’s IT, Security, or Compliance team first. The specific terms governing SecurePledge’s processing of Customer Data on behalf of a Customer are set out in the applicable Order Form and Data Processing Agreement (“DPA“) between SecurePledge and that Customer, which take precedence over this Policy for that Customer’s data. [CONFIRM: does a standard DPA template currently exist? If not, this should be a near-term priority alongside SOC 2 work.]

Information We Collect

1 Website Visitor Information 

  • Contact and demo-request form data: name, business email, company name, job title, phone number, and message content. 
  • Automatically collected technical data: IP address, browser and device type, pages viewed, referring/exit pages, and approximate location, generally via cookies and similar technologies (see Section 12). 

2 Customer Account & Administrator Information 

  • Registration details: name, business email, organization name, role/title, and password (stored hashed, never in plain text). 
  • Billing and invoicing details. [CONFIRM: payment processor to be named here once selected, e.g., Stripe/Razorpay.] 
  • Organization configuration data: policy rules, approved AI providers, user and role assignments, and API key references (see Section 3.4 – SecurePledge does not require or store your organization’s underlying AI provider credentials in plaintext; [CONFIRM: exact encryption/storage method for customer-supplied API keys with engineering before publishing]). 

3 Information Processed Through the Service (“Interaction Data”) 

This is the category of data at the heart of what SecurePledge does, and we want to be precise about it. Depending on which components your organization enables, the following may be processed: 

  • Prompts and content submitted by end users to AI tools (via the Protector, the AI Gateway, or our chat interface, internally referred to as “Masker”), which pass through our Detection Engine before reaching an AI model. 
  • Detected sensitive-data indicators – e.g., that a prompt contained what appears to be PII, PHI, financial data, or credentials – used to enforce your organization’s policies (allow / block / redact / warn). 
  • Redacted or masked versions of prompts, and, depending on your organization’s configuration, the original (unmasked) content. 
  • Reversible-redaction mapping data. Our Redactor supports reversible masking, which allows an authorized user to see the original value behind a redacted placeholder within the same request/session. This requires storing a scoped mapping between the placeholder and the original value for a limited time. [CONFIRM with engineering/security: exact encryption method, access controls, and maximum retention window for this mapping data before publishing – this is one of the more sensitive data flows in the product and deserves precise, accurate language rather than a placeholder claim.] 
  • AI model responses returned from your organization’s chosen AI provider. 
  • Metadata: user and organization identifiers, timestamps, the AI platform or domain accessed, the policy action taken, and the general category of data detected. 

Exactly what content is retained in full, redacted, or metadata-only form – and for how long – depends on the data-handling policies your organization’s administrator configures (see Section 9, Data Retention). 

4 Your Organization’s Own AI Provider Credentials (“Bring Your Own Key”) 

SecurePledge is built on a “bring-your-own-key” model: your organization supplies its own credentials for the AI providers it wants to use (e.g., OpenAI, Anthropic, Google). SecurePledge uses these credentials to route requests on your organization’s behalf, after applying detection and policy enforcement, but your organization – not SecurePledge – holds the direct commercial and data-processing relationship with that AI provider. That provider’s own privacy policy and terms govern its handling of the request once it receives it. We are not responsible for, and this Policy does not cover, the data practices of third-party AI providers.

How We Use Information

We use the information described above to: 

  • Provide, operate, and maintain the Platform, including the detect → prevent → redirect → log → prove workflow. 
  • Enforce the policies your organization’s administrators configure. 
  • Generate audit logs, compliance reports, incident records, and dashboard analytics for your organization. 
  • Manage accounts, billing, and subscriptions. 
  • Provide customer support. 
  • Maintain security, detect and prevent fraud or abuse, and troubleshoot technical issues. 
  • Communicate with you about the Service, including updates and security notices. 
  • Comply with legal obligations and enforce our agreements. 
  • With your organization’s consent under the applicable Order Form, improve the accuracy of our detection and redaction models. [CONFIRM: this is a material decision that needs to be made explicitly and reflected accurately here – specifically, whether Customer prompt content is ever used, in any form (including de-identified or aggregated), to train, fine-tune, or evaluate SecurePledge’s own detection models. If the current practice is “no,” say so explicitly; if it is or may become “yes,” this needs clear, opt-in customer consent language and should not be buried.] 
  • Market our services to prospective customers (with opt-out available at any time). 

We do not sell personal data, and we do not use Interaction Data processed on behalf of a Customer for our own marketing purposes.

Legal Bases for Processing

Where applicable law requires a legal basis for processing (for example, under the EU/UK GDPR, if we serve customers with users located there), we rely on: 

  • Performance of a contract – to provide the Service to our Customers and their authorized users. 
  • Legitimate interests – for security, fraud prevention, and service improvement, balanced against your rights. 
  • Consent – for optional marketing communications and non-essential cookies. 
  • Legal obligation – where we must retain or disclose information to comply with law. 

Given our primary market is India, we also structure our practices with reference to the Digital Personal Data Protection Act, 2023 (“DPDPA”) and the Information Technology Act, 2000 and its rules, including the Sensitive Personal Data or Information (SPDI) Rules, 2011. [CONFIRM with counsel: DPDPA’s implementing rules were still being finalized as of early 2026 in some respects – this section should be checked against the current rulebook before publishing.]

Third-Party AI Providers and Other Sub-Processors

As of the date of this Policy, categories of third parties that may process data in connection with the Service include: 

  • AI model providers your organization chooses to enable (e.g., OpenAI, Anthropic, Google), under the BYOK model described in Section 3.4. 
  • Cloud infrastructure and hosting: Amazon Web Services (AWS). [CONFIRM: hosting region(s) – important for enterprise/regulated customers who will ask about data residency.] 
  • Content delivery / network security: Cloudflare. 
  • [CONFIRM: payment processor, if any.] 
  • [CONFIRM: email/communications provider, if any, e.g., for transactional emails.] 
  • [CONFIRM: website analytics provider, if any, e.g., Google Analytics – this must match what is actually implemented on the Site and disclosed in the cookie banner.] 

We will maintain a current list of sub-processors for enterprise Customers and will provide notice of material changes as required under the applicable DPA. [CONFIRM: whether this subprocessor-notification mechanism currently exists; if not, recommend implementing one before signing enterprise DPAs.]

How We Share Information

We share information: 

  • With the sub-processors listed above, under confidentiality and data-protection obligations. 
  • Within your organization, according to the roles and permissions your administrators configure (e.g., a Security admin may see audit logs that a general employee cannot). 
  • In connection with a merger, acquisition, financing, or sale of assets, with notice to affected Customers where required. 
  • When required by law, regulation, legal process, or governmental request, or to protect the rights, safety, and security of SecurePledge, our Customers, or others. Where legally permitted, we will attempt to notify the affected Customer before disclosure. 

We do not sell personal data to third parties.

Data Security

We take a security-first approach, consistent with SecurePledge’s purpose as a security product. Current and planned measures include: 

  • Encryption in transit (TLS) for data submitted to the Platform. [CONFIRM with engineering: encryption at rest for MongoDB-stored logs, prompts, and redaction mapping data.] 
  • Role-based access controls limiting who can view raw versus redacted content. 
  • Restricted, scoped access to reversible-redaction mapping data. 
  • [CONFIRM: any additional controls – e.g., secrets management approach, key rotation, logging of administrative access.] 

Honest disclosure on certification status: SecurePledge is designed to align with frameworks such as SOC 2, HIPAA, ISO 27001, and GDPR documentation requirements. As of the date of this Policy, SecurePledge has not yet completed SOC 2 or other independent third-party security certifications. We will update this Policy and our website as certifications are achieved. If your organization requires a signed Business Associate Agreement (BAA) for HIPAA purposes, or a specific compliance attestation, please contact us to discuss current status before relying on the Service for regulated workloads. 

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. In the event of a data breach affecting your information, we will notify affected Customers and, where required, regulators and individuals, in accordance with applicable law and contractual commitments.

Data Retention

  • Website inquiry data is retained for [CONFIRM: retention period], after which it is deleted or anonymized. 
  • Customer account and billing data is retained for the duration of the subscription plus [CONFIRM: post-termination retention period], as required for legal, tax, or accounting purposes. 
  • Interaction Data (prompts, redaction records, audit logs): retention is configurable by your organization’s administrator (store / anonymize / delete). Absent a specific configuration, the default retention period is [CONFIRM: this default has not yet been fixed as a product decision – we recommend setting and documenting one, e.g., 12 months, before publishing this Policy]. 
  • Reversible-redaction mapping data is retained only for as long as necessary to serve the immediate request or session, unless your organization configures a longer window. [CONFIRM exact default with engineering.]

Your Rights
Subject to applicable law (including the DPDPA, and GDPR/CCPA where applicable), you may have rights to: 

  • Access the personal data we (or, for Interaction Data, your employer as data fiduciary/controller) hold about you. 
  • Correct inaccurate or incomplete data. 
  • Withdraw consent, where processing is based on consent. 
  • Request erasure, subject to legal, contractual, or legitimate business retention needs. 
  • Lodge a grievance or complaint (see Section 11). 
  • Nominate another individual to exercise your rights in the event of death or incapacity (a DPDPA-specific right). 

End users: because your employer typically controls how SecurePledge is configured and what is logged about your AI usage, please direct data-subject requests about your Interaction Data to your employer first. Website visitors and Customer administrators may contact us directly at [CONFIRM: privacy contact email].

Grievance Officer / Data Protection Contact (India)

In accordance with the Information Technology Act, 2000, its rules, and the Digital Personal Data Protection Act, 2023 (once its grievance-redressal provisions are in force), we will publish the details of our Grievance Officer here: 

Name: [CONFIRM] Designation: [CONFIRM] Email: [CONFIRM] Address: [CONFIRM] 

[This appointment is a legal requirement for entities handling sensitive personal data in India and should be completed before this Policy is published live.]

Cookies and Tracking Technologies

Our Site may use: 

  • Essential cookies – required for basic site functionality. 
  • Analytics cookies – to understand site usage. [CONFIRM: specific tool(s) in use, e.g., Google Analytics, Plausible, etc.] 
  • Marketing cookies – for advertising and retargeting, if used. [CONFIRM: whether any are currently implemented.] 

[CONFIRM: whether a cookie-consent banner / preference center is implemented on the Site; if serving EU/UK visitors, one is generally required and should be linked here.] 

International Data Transfers

If data is processed or stored outside the country where you or your organization are located (for example, due to the location of our hosting infrastructure or your chosen AI provider), we take steps intended to ensure it receives an adequate level of protection. [CONFIRM: actual hosting region(s) and, if serving EU/UK customers, whether Standard Contractual Clauses or another transfer mechanism is in place – this needs legal input.] 

Children’s Privacy

SecurePledge is a business product intended for use by organizations and their employees. It is not directed at, and we do not knowingly collect personal data from, individuals under the age of 18. 

Changes to This Policy

We may update this Policy from time to time. We will post the revised version with an updated “Last Updated” date and, for material changes, provide additional notice as appropriate (e.g., email to Customer administrators). 

Contact Us

If you have questions about this Privacy Policy, please contact: 

[CONFIRM: Company legal name] [CONFIRM: registered address] Email: [CONFIRM: privacy contact email] Phone: [CONFIRM: phone number, optional]