Legal

Privacy Policy

Effective: 14 June 2026 · Last updated: 14 June 2026 · Version: 1.0

This Privacy Policy (“Policy”) is issued by BitScore Cybertech LLP, a Limited Liability Partnership incorporated in India and registered under the Startup India initiative (“BitScore”, “we”, “us”, “our”). BitScore is the authorised India partner for the Bitsight Cyber Risk Intelligence Platform operated by Bitsight Technologies, Inc. (“Bitsight”). References to “you” or “your” mean the natural person or legal entity using https://www.bitscore.in/ and https://www.bitscore.ai.in/(the “Website”) or engaging us for services.

1. Scope of this Policy

This Policy explains what personal data we collect, how we use it, who we share it with, the lawful bases on which we process it, and the rights you have. It applies to:

This Policy does notgovern data processed by Bitsight on its own platform when you interact directly with Bitsight (for example, via bitsight.com or the Bitsight portal under a separate Bitsight licence). For those interactions, Bitsight's own privacy notice and Security Ratings Access Terms apply. We will tell you when a transfer to Bitsight is involved.

When you request a report via our Website, you are redirected to Bitsight's intake form. Bitsight collects the data you submit there as an independent controller. We may also receive your contact details from Bitsight or from direct correspondence with us.

2. What personal data we collect

We have deliberately designed our service to minimise personal data collection. The Bitsight platform measures external, attacker-visible signals about an organisation — it does not require an agent on your systems, credentials, or access to your internal environment, and it does not rely on a self-reported questionnaire.

(a) Information you provide directly

(b) Information collected automatically on the Website

On your first visit, we offer a cookie choice. Non-essential marketing and analytics tags load only after you select “Accept all.” You can change your choice at any time via Cookie settings in the Website footer or your browser controls.

(c) Information collected through service delivery

(d) Information we do not collect

We do not deploy agents on your endpoints, do not request system or network credentials, and do not require access to internal logs or telemetry. We do not knowingly process Sensitive Personal Data or Information (“SPDI”) as defined under the SPDI Rules — financial information, biometrics, health data, sexual orientation, and similar categories — for the operation of the Website or the rating service. Please do not include SPDI in unsolicited correspondence.

3. How and why we use personal data

Under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), we rely on consent as the primary basis for processing personal data, and on the legitimate uses specified in Section 7 of the DPDP Act where applicable (notably, processing where you have voluntarily provided your data for a specified purpose). Where the SPDI Rules apply, we rely on consent and the necessity of processing for the purpose for which the information was provided.

PurposeTypical dataLawful basis
Respond to enquiries and report requestsName, work email, phone, role, company, domain, message contentConsent / voluntary provision (DPDP §7)
Deliver Bitsight ratings, SPM, or TPRMDomain(s), stakeholder contacts, service configuration, billing detailsContract performance / consent
Operate and secure the WebsiteIP address, browser/device data, server logsLegitimate uses / legal obligation
Understand aggregate Website usagePage views and interaction telemetry via Vercel Analytics & Speed InsightsLegitimate uses (first-party, privacy-oriented analytics)
Marketing measurement (with consent)Usage signals via GTM/GA4, Zoho PageSense, LinkedIn Insight TagConsent
Legal, tax, and regulatory complianceRecords required by Indian lawLegal obligation

We will not use your personal data for any purpose materially different from those listed above without giving you notice and, where required, obtaining fresh consent.

4. Sharing of personal data

We share personal data only as described below, with parties contractually bound to handle it consistently with this Policy:

We do not sell personal data, and we do not share it with advertisers for purposes unrelated to the services described above.

5. International transfers

The Bitsight platform is operated from outside India, including the United States and the European Economic Area. By engaging us, you understand that we will transfer the personal data necessary to provision the service to Bitsight in such jurisdictions, which may have data protection regimes different from India's. Transfers are made in accordance with the DPDP Act and under contractual safeguards with Bitsight. Marketing and analytics providers listed in Section 4 may also process data outside India when you have given cookie consent.

6. Data retention

Once retention is no longer justified, personal data is securely deleted or irreversibly anonymised.

7. How we protect personal data

As a cyber-risk intelligence business, we maintain information security practices mapped to ISO/IEC 27001 — the international standard for information security management. BitScore is not ISO 27001 certified; we align our policies and controls to that framework as a structured baseline, without claiming third-party certification.

Our programme includes reasonable practices consistent with Section 43A of the IT Act and applicable rules, including access controls, encryption of personal data in transit (TLS 1.2 or higher), segregation of environments where practicable, logging and monitoring, vendor review for key sub-processors, and a documented approach to incident response.

No security programme is infallible. If a personal data breach is likely to cause harm to you, we will notify the Data Protection Board of India and affected users in the form and within the timelines required by the DPDP Act and subordinate rules.

8. Your rights as a Data Principal

Subject to the DPDP Act and applicable conditions, you have the right to:

To exercise any right, write to nimitt@bitscore.ai.in. We will respond within the timelines prescribed by law (and, in any event, within 30 days for most requests). We may verify your identity before acting on a request.

9. Children

Our services are designed for enterprises and are not directed to children. We do not knowingly collect personal data of children under 18 without verifiable parental consent or in any manner detrimental to a child's well-being. If you believe we have inadvertently collected data about a child, please contact us and we will delete it.

10. Cookies and tracking technologies

The Website uses the following categories:

The LinkedIn Insight Tag may set cookies and transmit data to LinkedIn Ireland Unlimited Company only after you accept cookies. You can opt out via LinkedIn account settings or by selecting Essential only in our cookie banner. A detailed cookie inventory is available on request from the Grievance Officer.

11. Grievance Officer / Data Protection Officer

In accordance with the IT Act, the Intermediary Rules, and the DPDP Act:

We will acknowledge any complaint within 48 hours and seek to resolve it within 15 days, in line with the Intermediary Rules.

12. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will revise the “Last updated” date above and, where appropriate, notify you by email or via a prominent notice on the Website before the change takes effect.

13. Contact

For any question about this Policy or our data practices, write to nimitt@bitscore.ai.in with the subject line “Privacy Policy — Query”.

Registered office: BitScore Cybertech LLP, Satyam Corporate Square, Block-B, Behind Rajpath Club, Ahmedabad 380059, Gujarat, India.

Bitsight is a registered trademark of Bitsight Technologies, Inc. BitScore is an authorised partner for Bitsight and is not affiliated with any other rating service that uses a similar name.

← Back to BitScore · Responsible Disclosure