Privacy Policy
Last updated: August 17, 2026
1. Introduction
BlueSentinel ("we", "our", "us"), a product of Rupenet Technologies Pvt. Ltd., is committed to protecting the privacy and security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our products, or engage with our services.
By accessing or using BlueSentinel, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our services.
2. Information We Collect
2.1 Information You Provide
- Account Information: Name, email address, company name, phone number, and job title when you create an account or request a demo.
- Billing Information: Payment details processed through our third-party payment processors. We do not store credit card numbers on our servers.
- Communication Data: Information you provide when contacting support, submitting feedback, or participating in surveys.
2.2 Information Collected by the DLP Agent
The BlueSentinel DLP Agent, installed on tenant endpoints, collects the following data stored exclusively on the tenant's BlueSentinel's secure infrastructure (or self-hosted for Enterprise customers):
- Device Information: Hostname, operating system, hardware model, serial number, MAC address, IP address.
- Security Events: Guard violation alerts (USB insertion attempts, blocked uploads, clipboard activity, screenshot attempts, process executions).
- Guard Status: Which security guards are active, policy version, compliance status.
- Encryption Keys: Disk encryption recovery keys (BitLocker/FileVault), AES-256 encrypted before storage.
Important: Data Sovereignty
For SaaS customers, all endpoint data is stored on BlueSentinel's secure servers hosted in India with strict tenant isolation — no cross-tenant access is possible. For Enterprise self-hosted customers, all data remains on the tenant's own infrastructure. In both models, recovery keys are AES-256 encrypted and access to tenant data is role-controlled and fully audited.
2.3 Automatically Collected Information (Website)
- Browser type, operating system, and device information
- IP address and approximate geographic location
- Pages visited, time spent, and referral sources
- Cookies and similar tracking technologies (see Cookie Policy)
3. How We Use Your Information
- To provide, maintain, and improve our products and services
- To process transactions and send billing-related communications
- To respond to your inquiries and provide customer support
- To send product updates, security advisories, and administrative notices
- To detect, prevent, and address technical issues and security threats
- To comply with legal obligations and enforce our terms
- To conduct analytics and improve user experience (website only)
4. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information. We may share information only in the following circumstances:
- Service Providers: Trusted third parties who assist in operating our website, payment processing, and email delivery, bound by confidentiality obligations.
- Legal Requirements: When required by law, court order, or governmental regulation, or to protect our rights, safety, or property.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, with prior notice to affected users.
- With Your Consent: When you explicitly authorize us to share your information.
5. Data Security
We implement industry-standard security measures including:
- AES-256 encryption for sensitive data at rest
- TLS/HTTPS for all data in transit
- SHA-256 hashing for API keys and bcrypt for passwords
- Role-based access control (RBAC) with 4-level permissions
- Complete audit trail for all administrative actions
- Multi-tenant data isolation at the database level
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide services. Upon account termination, we will delete or anonymize your data within 90 days, except where retention is required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).
Tenant endpoint data (alerts, device information, recovery keys) is stored on the tenant's own servers and is entirely under the tenant's control and retention policies.
7. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: Request a copy of your personal data
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your personal data
- Portability: Request your data in a portable format
- Objection: Object to processing of your data for certain purposes
- Withdrawal of Consent: Withdraw consent at any time where processing is based on consent
To exercise these rights, contact us at privacy@bluesentinel.io. We will respond within 30 days.
8. GDPR Compliance (European Users)
For users in the European Economic Area (EEA), we process personal data under the following legal bases: contractual necessity, legitimate interests, consent, and legal obligation. As a SaaS platform hosted in India, tenant data remains within Indian data centers. Self-hosted Enterprise customers control their own data jurisdiction.
9. DPDP Act Compliance (Indian Users)
In accordance with India's Digital Personal Data Protection Act, 2023, we process personal data only for lawful purposes with informed consent. Data principals may exercise their rights by contacting our Data Protection Officer. BlueSentinel's SaaS servers are hosted in India, ensuring data residency. Self-hosted Enterprise deployments allow customers to choose their own data center location.
10. Children's Privacy
BlueSentinel is an enterprise product not directed at individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or a prominent notice on our website. Continued use after changes constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related inquiries or to exercise your data rights:
Data Protection Officer
Rupenet Technologies Pvt. Ltd.
Email: privacy@bluesentinel.io
Website: bluesentinel.io/contact