Your data, your rights

Privacy Policy

Effective: 22 April 2026 · Last updated: 22 April 2026

We process personal data as a business necessity to run ThreatReady. This policy explains what we collect, why, and the rights you have over it — written in plain language, under India's Digital Personal Data Protection Act 2023 (DPDPA) and the EU General Data Protection Regulation (GDPR).

GDPR compliant India DPDPA 2023 Encrypted in transit & at rest Plain English

1Who we are

ThreatReady is operated by Aerovant Technologies Private Limited, a company incorporated in India (the "Company," "we," "us"). For the purposes of this Privacy Policy, Aerovant Technologies is the data fiduciary under DPDPA 2023 and the data controller under GDPR for data collected directly from engineers (B2C) and website visitors.

When you use ThreatReady as a business customer and upload or assess your candidates' data, your organization is the data fiduciary/controller for that candidate data, and Aerovant Technologies acts as the data processor. The terms of that processing are set out separately in our Data Processing Agreement.

Aerovant Technologies Private Limited
Registered in India

2What data we collect

2.1 Account data

2.2 Assessment data

2.3 Usage data

2.4 Communications

What we do not collect We do not collect biometric data, government IDs, health information, financial records beyond payment processing, or any sensitive personal data as defined under DPDPA 2023. We do not fingerprint your device across sessions for advertising.

3Why we collect it (legal basis)

PurposeLegal basis (GDPR)Lawful ground (DPDPA)
Provide the ThreatReady serviceContract (Art. 6(1)(b))Contractual necessity
Process payments and billingContract & legal obligationLegal obligation
Evaluate your assessment answers via AIContractContractual necessity
Security, fraud prevention, abuse detectionLegitimate interest (Art. 6(1)(f))Legitimate use
Improve the platform and scoring accuracyLegitimate interestLegitimate use
Send marketing emails (Attack of the Week)Consent (Art. 6(1)(a))Consent
Comply with legal requestsLegal obligationLegal obligation

4Who we share it with

We share the minimum data necessary with the following categories of third parties:

4.1 Sub-processors

A current list of sub-processors is available in our DPA. We give business customers 30 days' notice before engaging any new sub-processor that handles their data.

4.2 When required by law

We may disclose data in response to a valid legal request (subpoena, court order, warrant) after reviewing the request and, where legally permitted, notifying the affected user.

4.3 Business transfers

If Aerovant Technologies is involved in a merger, acquisition, or sale of assets, your data may transfer to the acquirer. You will be notified and given the opportunity to delete your account before any transfer.

What we never do We do not sell your data. We do not share it with advertisers. We do not share assessment answers or scores with anyone other than the account holder (for B2C) or the employing organization (for B2B candidate assessments).

5How long we keep it

6Your rights

Under GDPR and DPDPA 2023, you have the following rights over your personal data:

To exercise any right, email [email protected]. We will respond within 30 days (or 7 days for DPDPA grievance redressal, escalating to 30 days for complex requests). There is no charge for reasonable requests.

7Cookies

We use a minimal set of cookies:

We do not use third-party advertising cookies. We do not track you across other websites.

8International transfers

Primary storage of your data is in India (AWS Mumbai, ap-south-1). When we transmit data to Anthropic for AI evaluation, that data is transferred to the United States.

For users in the European Economic Area and United Kingdom, these transfers are protected by Standard Contractual Clauses (SCCs) as adopted by the European Commission. For users in India, we rely on the DPDPA framework for cross-border processing.

You can read more about how Anthropic handles API data in Anthropic's Privacy Policy.

9Children's data

ThreatReady is a professional platform intended for users 18 years and older. We do not knowingly collect personal data from children under 18. Under DPDPA 2023, additional consent requirements apply to users under 18 in India; we require age verification at signup and do not accept accounts from minors. If you believe a minor has created an account, contact us and we will delete it.

10Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to registered users at least 14 days before taking effect. The "Last updated" date at the top reflects the current version. Previous versions are available on request.

11Contact & Grievance Officer

For privacy questions, data requests, or complaints:

Data Protection contact

Email: [email protected]
Postal: Aerovant Technologies Pvt. Ltd., [Registered Office Address], Chennai, Tamil Nadu, India

Grievance Officer (per DPDPA 2023 §32)

Name: [To be appointed]
Email: [email protected]
Response SLA: Initial response within 7 days. Resolution within 30 days.

If your grievance is not resolved to your satisfaction, you may approach the Data Protection Board of India for redressal under DPDPA 2023.