PatchMortem / Privacy policy

Privacy Policy

How Zurlux Technologies collects, uses, and protects personal data under the Digital Personal Data Protection Act 2023.

This policy applies to the PatchMortem website and the PatchMortem platform.

1. Who we are

Zurlux Technologies Private Limited (CIN: U62013PN2026PTC257274), registered at Flat No. 304, C-Wing, Aavishkar, Moshi, Pune, Maharashtra 412105, India, operates PatchMortem. In this policy, “we”, “us” and “Zurlux” refer to that company.

This policy explains how we collect, use, and protect personal data under the Digital Personal Data Protection Act 2023 (DPDP Act).

2. Data we collect

We collect three categories of data.

Account and contact data

Name, work email address, organisation, job role, and the content of enquiries you send us through the website or by email.

Operational telemetry

Data collected by the PatchMortem agent from managed endpoints: hostnames, operating system and build, patch state, servicing and event logs, error codes, failed components, cluster role and topology, and snapshot availability.

Product usage data

Authentication events, actions taken in the dashboard, approvals granted, and the identity of the operator who took each action. These are written to the audit chain by design.

PatchMortem does not require, request, or process the personal data of your own customers. It processes infrastructure telemetry and the identity of your operators.

3. How we use your data

  • To provide the service — classifying patch failures, selecting and executing remediation, and writing the audit chain
  • To authenticate users and enforce role-based access control
  • To produce compliance exports at your request
  • To respond to enquiries and provide support
  • To investigate security incidents and maintain the integrity of the platform
  • To meet our own legal and regulatory obligations

We do not sell personal data. We do not use customer telemetry to train models for other customers.

4. Legal basis for processing

Where you contact us or create an account, we process on the basis of your consent and to perform the contract between us. Where we process operational telemetry, we do so as Data Processor on behalf of the customer, who is the Data Fiduciary, under the terms of a signed Data Processing Addendum. Some processing is necessary to comply with legal obligations or to protect the security of the platform.

5. Data storage and residency

All customer data is stored and processed in AWS Asia Pacific (Mumbai), ap-south-1. Nothing is replicated outside India. We will not change this default without written notice to affected customers.

Data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256, with per-tenant key isolation and keys managed through AWS KMS with automatic rotation.

6. Data retention

Audit chain recordsRetention configured by the customer; records are append-only and cannot be edited or deleted by any user, including Zurlux staff
Operational telemetryRetained for the term of the subscription unless a shorter period is agreed in the DPA
Account dataRetained for the term of the relationship and for as long afterwards as required by law
Enquiry dataRetained for up to 24 months from last contact unless you ask us to erase it sooner

7. Your rights under the DPDP Act 2023

  • Access — to obtain a summary of the personal data we process about you
  • Correction — to have inaccurate or incomplete data corrected or completed
  • Erasure — to have personal data erased where it is no longer required and no legal obligation requires us to keep it
  • Grievance redressal — to raise a complaint with our Grievance Officer
  • Nomination — to nominate another individual to exercise these rights in the event of death or incapacity

To exercise any of these, write to hello@zurlux.com. Where you are an end user of a customer's PatchMortem deployment, we will direct your request to that customer, who is the Data Fiduciary.

8. Third-party processors

We use a limited set of sub-processors. The full list applicable to a given engagement is disclosed in the executed Data Processing Addendum, and material changes are notified in advance.

Amazon Web ServicesInfrastructure hosting — ap-south-1 (Mumbai), India

9. Security

Access to production systems is restricted and logged. We enforce mTLS between internal services, PostgreSQL row-level security for tenant isolation, and secrets management through AWS Secrets Manager. Container images are scanned on push and dependencies monitored for known vulnerabilities.

Full detail is on the security page, including the certifications we have not yet obtained.

10. Children

PatchMortem is an enterprise infrastructure product. It is not directed at children and we do not knowingly collect the personal data of any individual under 18. If you believe we have, contact us and we will erase it.

11. Changes to this policy

We may update this policy. Where a change is material, we will notify customers in writing before it takes effect. The date of last revision is shown at the top of this page.

12. Contact and Grievance Officer

For any question about this policy or to exercise your rights, contact:

Grievance Officerhello@zurlux.com
Security reportssecurity@zurlux.com
PostalZurlux Technologies Private Limited, Flat No. 304, C-Wing, Aavishkar, Moshi, Pune, Maharashtra 412105, India

We acknowledge grievances within 72 hours and aim to resolve them within 30 days, as required under the DPDP Act 2023.

This page is a plain-language statement of our position. Where a signed agreement or Data Processing Addendum is in place, that document governs.