How Zurlux Technologies collects, uses, and protects personal data under the Digital Personal Data Protection Act 2023.
This policy applies to the PatchMortem website and the PatchMortem platform.
Zurlux Technologies Private Limited (CIN: U62013PN2026PTC257274), registered at Flat No. 304, C-Wing, Aavishkar, Moshi, Pune, Maharashtra 412105, India, operates PatchMortem. In this policy, “we”, “us” and “Zurlux” refer to that company.
This policy explains how we collect, use, and protect personal data under the Digital Personal Data Protection Act 2023 (DPDP Act).
We collect three categories of data.
Name, work email address, organisation, job role, and the content of enquiries you send us through the website or by email.
Data collected by the PatchMortem agent from managed endpoints: hostnames, operating system and build, patch state, servicing and event logs, error codes, failed components, cluster role and topology, and snapshot availability.
Authentication events, actions taken in the dashboard, approvals granted, and the identity of the operator who took each action. These are written to the audit chain by design.
PatchMortem does not require, request, or process the personal data of your own customers. It processes infrastructure telemetry and the identity of your operators.
We do not sell personal data. We do not use customer telemetry to train models for other customers.
Where you contact us or create an account, we process on the basis of your consent and to perform the contract between us. Where we process operational telemetry, we do so as Data Processor on behalf of the customer, who is the Data Fiduciary, under the terms of a signed Data Processing Addendum. Some processing is necessary to comply with legal obligations or to protect the security of the platform.
All customer data is stored and processed in AWS Asia Pacific (Mumbai), ap-south-1. Nothing is replicated outside India. We will not change this default without written notice to affected customers.
Data in transit is encrypted with TLS 1.3. Data at rest is encrypted with AES-256, with per-tenant key isolation and keys managed through AWS KMS with automatic rotation.
| Audit chain records | Retention configured by the customer; records are append-only and cannot be edited or deleted by any user, including Zurlux staff |
| Operational telemetry | Retained for the term of the subscription unless a shorter period is agreed in the DPA |
| Account data | Retained for the term of the relationship and for as long afterwards as required by law |
| Enquiry data | Retained for up to 24 months from last contact unless you ask us to erase it sooner |
To exercise any of these, write to hello@zurlux.com. Where you are an end user of a customer's PatchMortem deployment, we will direct your request to that customer, who is the Data Fiduciary.
We use a limited set of sub-processors. The full list applicable to a given engagement is disclosed in the executed Data Processing Addendum, and material changes are notified in advance.
| Amazon Web Services | Infrastructure hosting — ap-south-1 (Mumbai), India |
Access to production systems is restricted and logged. We enforce mTLS between internal services, PostgreSQL row-level security for tenant isolation, and secrets management through AWS Secrets Manager. Container images are scanned on push and dependencies monitored for known vulnerabilities.
Full detail is on the security page, including the certifications we have not yet obtained.
PatchMortem is an enterprise infrastructure product. It is not directed at children and we do not knowingly collect the personal data of any individual under 18. If you believe we have, contact us and we will erase it.
We may update this policy. Where a change is material, we will notify customers in writing before it takes effect. The date of last revision is shown at the top of this page.
For any question about this policy or to exercise your rights, contact:
| Grievance Officer | hello@zurlux.com |
| Security reports | security@zurlux.com |
| Postal | Zurlux Technologies Private Limited, Flat No. 304, C-Wing, Aavishkar, Moshi, Pune, Maharashtra 412105, India |
We acknowledge grievances within 72 hours and aim to resolve them within 30 days, as required under the DPDP Act 2023.
This page is a plain-language statement of our position. Where a signed agreement or Data Processing Addendum is in place, that document governs.