● Privacy

Privacy Policy

Last updated September 2026

This Privacy Policy explains how Tribastion Technologies (“Tribastion”, the “Data Fiduciary”) collects, uses, discloses, retains and protects personal data in connection with the Tribastion TI platform (the “Service”), and the rights available to you as a Data Principal.

1. Data we process

CategoryExamplesPurpose
Account dataname, work email, organisation, role, hashed password, API-key hashauthentication, access control, billing, support
Usage & audit datasearches, actions, IP, timestamps, device/browsersecurity, audit trail, abuse prevention, service improvement
Threat-intelligence dataleaked credentials, breach records, infostealer-log artefacts that may contain third-party personal dataauthorised security, fraud-prevention and incident-response use by customers
Consent & preferencescookie/consent choices, communication preferenceshonouring your choices; DPDPA record-keeping

2. Purposes & lawful basis

We process account, usage and consent data on the basis of your consent and for legitimate uses permitted under the DPDPA (providing the Service you requested, security, and complying with law). Threat-intelligence data is processed by customers acting as Data Fiduciaries for their own authorised security purposes; Tribastion acts as a Data Processor for that data on their instructions.

3. Consent & notice

Where we rely on consent, we ask for it through clear, granular choices (see our on-site Consent Manager). Consent is as easy to withdraw as to give. Withdrawing consent does not affect processing already carried out, and may limit features that depend on it.

4. Your rights as a Data Principal

Subject to verification of your identity, you may:

Exercise any right through our data-rights request form. We respond within the statutory timeline. Subscription clients can also request account and data deletion directly from their dashboard.

5. Retention

We retain personal data only as long as necessary for the purposes above or as required by law, after which it is deleted or irreversibly anonymised. Audit logs are retained for a defined security period. Collected threat-intelligence is retained per customer configuration and the applicable data-processing terms.

6. Sharing & processors

We do not sell personal data. We share it only with: (a) sub-processors that host or support the Service under contractual confidentiality and security obligations; (b) upstream intelligence providers strictly to fulfil a search you initiate; and (c) authorities where legally required. A current list of sub-processors is available on request.

7. Security safeguards

We apply reasonable security safeguards aligned with our SOC 2 Type II controls: encryption of sensitive data at rest and in transit, strict least-privilege access control, masked-by-default output, a strict Content-Security-Policy, comprehensive audit logging, and secure-SDLC practices. See our Trust & Security page.

8. Cross-border transfers

Where personal data is processed outside your jurisdiction, we do so only to countries and under safeguards permitted by applicable law and any restrictions notified by the Government of India.

9. Children’s data

The Service is intended for business/professional use and not for children. We do not knowingly process the personal data of children without verifiable parental consent as required by law.

10. Personal-data breach

In the event of a personal-data breach, we will notify the Data Protection Board and affected Data Principals as required by the DPDPA, and take remedial action.

11. Grievance Officer / contact

To exercise rights or raise a grievance, use the request form, or contact our Grievance Officer:

Grievance Officer, Tribastion Technologies
Email: ASM@tribastion.com
We acknowledge grievances promptly and respond within the statutory period.