Privacy policy
Introduction
We are committed to upholding high standards of data privacy and security. Our practices are designed to comply with applicable laws, including the Information Technology Act, 2000 (and its Rules) and the Digital Personal Data Protection Act, 2023 ("DPDP Act"), and platform requirements such as the Google Play Store and Apple App Store.
This Privacy Policy describes how Mitigata, operated by Alphawave Technologies Private Limited ("Mitigata", "we", "our", "us") collects, uses, shares, and protects your personal data ("Personal Data") when you use our digital safety companion app and related services ("Services").
1. Data We Collect
Data you provide
- Personal Data — any data about an individual who is identifiable by or in relation to such data, including name, email address, password, mobile phone number, registration or account information, PAN, date of birth and other identifiers, and financial data such as bank account or credit/debit card numbers (considered sensitive personal data).
- Non-Personal Data — anonymised or aggregated data that cannot identify an individual, including session data, log files, cookies, device/browser metadata, web beacons, and analytics information.
- Verification documents / identity proofs, if required for certain features.
- Communication content (e.g. feedback, support tickets, emails).
- Preferences, settings, and opt-ins / opt-outs.
- Identifiers you submit for Dark Web Monitoring or Identity Theft Watch (e.g. an email address or phone number you want checked).
- Account and consent information you provide for AutoPay Scan.
- Any other data you choose to submit via the Mitigata app or Services.
Device and usage data
- Device model, operating system, and app version.
- IP address.
- Crash logs and diagnostic logs.
- Network and connectivity information (e.g. whether you are on Wi-Fi or mobile data), used to run safety checks reliably.
- Device status indicators (e.g. risky settings, screen lock status) used only to detect security weaknesses — not to read personal content.
- General feature usage and app performance data.
Security scan data
- URLs and domains you choose to check, or that are opened through Safe Browsing Shield, used to detect phishing and other malicious web content.
- QR code content and destination links you scan through Safe QR Pay.
- Message text or links you voluntarily paste or share into Safe Messaging for scanning — not read automatically from your SMS or call logs.
- File and app metadata scanned for malware (Real-Time App Monitor, Premium).
- Wi-Fi network name (SSID) and connection risk signals, used only to warn you about unsafe networks.
- Results of the above checks, risk labels, and your weekly Threat Report data.
Third-party sources
- Data from public sources or breach / data exposure repositories (used for the Identity Theft feature).
- Partner(s) providing threat intelligence or breach databases.
- Account Aggregator partner(s), used only for AutoPay Scan and only with your explicit consent.
- Third-party service providers (analytics, cloud storage, security technology providers).
Aggregated / anonymous data
We may derive aggregated metrics or anonymised insights — for example, overall trends in scam types or threats blocked across all users — for product improvement, safety research, and internal analysis. Once anonymised, such data is not considered Personal Data.
Collection of data is based on your informed and explicit consent, obtained at the time of installation, sign-up, or first use of a specific feature, as required by applicable law. We ensure that only data necessary for providing and improving our Services is collected. You have the right to withdraw your consent for such data collection at any time through the app settings, without affecting your access to essential features. All data collected is processed securely, adhering to industry best practices and data protection principles to safeguard your privacy.
2. App Permissions We Ask For
- Camera: Used only when you open the QR scanner, to check if a QR code leads to a safe or unsafe destination.
- Notifications: Used to deliver security alerts, breach warnings, and your weekly Threat Report to your device. You can change this at any time in your device settings.
- Wi-Fi / network access: Used to check whether your connected network looks unsafe.
- Location: "While Using the App" — used only to check Wi-Fi Safety, never for advertising or tracking.
- SMS: Used to check incoming messages for phishing or scam links and warn or block the unsafe site.
3. How We Use Your Data
- Providing core Services: Checking whether your submitted identifiers (such as email addresses, phone numbers, or other account identifiers) have been exposed in data breaches or on dark web sources.
- User account management: Registration, login, profile maintenance, and identity verification through OTP.
- Identity theft monitoring: Using your phone number to detect if data associated with your accounts has been exposed, leaked, or is being used to impersonate you.
- Security and protection services: Detecting, preventing, and investigating malicious links, unsafe QR codes, malware, and fraud.
- Device and file threat scanning: Scanning installed apps and files on your device to detect and remove malware, spyware, and other malicious threats, and taking action (such as flagging or removing detected threats) to protect your device.
- Threat intelligence updates: Automatically updating threat definitions and detection rules on your device to keep protection current, without requiring action from you.
- Notifications and alerts: Sending you breach warnings, security alerts, and safety recommendations.
- SMS spam / scam and forwarding detection: Analysing SMS content and metadata on your device to detect phishing (smishing), fraudulent messages, and suspicious SMS forwarding behaviours, and to warn you before you act on them.
- Link and QR safety: Using URLs, domains, and QR codes you choose to check, to detect phishing and other malicious content and show you clear warnings before you proceed.
- AutoPay and subscription risk detection: Using Account Aggregator consent and mandate data to identify active autopay mandates and forgotten subscriptions.
- Weekly safety reporting: Using your in-app activity (links checked, QR scans, threats blocked) to generate your personal Threat Report.
- App, device, and network risk assessment: Using installed app information, sensitive permission use, device configuration (for example, root or developer mode), SIM and call-forwarding status, and network connectivity data to identify risky setups, apps, or behaviours associated with scams and fraud.
- Analytics and improvement: Usage analysis, improving features, and performance optimisation.
- Customer support: Handling your queries, complaints, or support tickets.
- Communications and marketing: With your consent, sending newsletters, promotional content, or updates.
- Legal and compliance: Responding to lawful requests, enforcement of terms, and regulatory obligations.
- Backup and archival: For data retention, business continuity, and audit requirements.
- Subscriptions or purchases: To process purchases through the Application, including payment handling and post-purchase support.
- Third-party sharing: To share Personal Data with authorised third-party processors (under lawful contract) for personalisation, analytics, hosting, and related processing tasks.
4. Legal Basis and Consent
- Data processing is based on your consent.
- You may withdraw consent at any time via in-app settings.
- Withdrawing consent for a specific feature may mean that feature can no longer function, since it depends on the underlying data.
- Consent is requested contextually — close to the point where a specific feature or permission is actually needed, not all at once during sign-up.
5. Data Sharing and Disclosure
Mitigata does not sell or rent Personal Information. Personal Information may be disclosed under the following circumstances:
- To trusted third parties (e.g. affiliates, cloud vendors, IT service providers) who assist in running our applications. These entities are contractually bound to maintain confidentiality and follow legal safeguards as per prevailing law.
As necessary, to:
- Comply with Indian or foreign law.
- Respond to court orders or lawful requests by public authorities.
- Enforce our Terms of Service.
- Protect our users, systems, or affiliates.
- Prevent fraud or harm, or pursue remedies in case of a breach.
The following types of data may be shared under valid consent or contract:
- Name, email, phone number, PAN, and date of birth.
- Device ID, usage logs, location, browser type, and operating system.
These are used to personalise the app and conduct lawful analytics.
Mitigata may use third-party analytics tools (like Google Analytics) to collect anonymised data (traffic stats, interests, bounce rates), governed by their own cookie/tracking policies.
6. Data Security
Mitigata uses reasonable security practices, procedures, and measures — at a minimum, those mandated under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("IT Rules 2011") and applicable law — to safeguard your Personal Data. These reasonable security measures and safeguards include but are not limited to:
- Encryption of Personal Data in transit and at rest.
- Logging and monitoring to detect and remediate unauthorised access.
- Business continuity and disaster recovery procedures.
These safeguards align with IT Rules 2011, which mandates implementation of reasonable security practices such as ISO/IEC 27001 standards. Mitigata also implements security safeguards to prevent personal data breaches.
You acknowledge the inherent risks of data transmission over the internet and agree that Mitigata will not be liable for breaches unless caused by gross or wilful negligence.
Your data is primarily stored electronically, though some may be stored physically.
Mitigata may enter into an agreement with third parties (in India) to store your Personal Information with such third parties. Mitigata will ensure that such third parties adopt reasonable security standards to safeguard your Personal Information.
Notwithstanding anything contained in this Policy or elsewhere, Mitigata shall not be held responsible for any loss, damage, or misuse of your Personal Information if such loss, damage, or misuse is attributable to a Force Majeure Event. A "Force Majeure Event" means any event beyond the reasonable control of Mitigata, including without limitation sabotage, fire, flood, explosion, acts of God, civil commotion, strikes or industrial action of any kind, riots, insurrection, war, acts of government, computer hacking, unauthorised access to computer data and storage devices, computer crashes, breach of security and encryption, and similar events.
7. Children's Data
Our Applications and Services are not intended for users under the age of 18. We do not knowingly collect Personal Information or data from children under 18, or market to or solicit information from anyone under the age of 18. If we become aware that a person submitting Personal Information is under 18, we will delete such Personal Information as soon as possible. If you believe we might have information from or about a child under 18, please contact us at care@mitigata.com.
8. Data Retention
We retain your Personal Data only for as long as necessary to fulfil the purposes for which it was collected, to provide our Services, to comply with our legal obligations, and to resolve disputes. Retention periods vary by data type: for example, sensitive logs may be deleted after a short period (e.g. 30–90 days), while your account information is retained for as long as your account is active.
9. Account Deletion
Deleting the Mitigata app from your device is different from deleting your Mitigata account. Uninstalling the app does not automatically delete your account or the data we hold about you.
If you have created an account in the Mitigata app, you can request deletion of that account and associated Personal Data in two ways:
- In-app: via the Mitigata app settings (for example, Settings → Account → Delete Account), where available.
- Outside the app: by visiting our account deletion request page (linked from our Google Play listing and website) or by contacting us using the details in the "Contact & Grievance Redressal" section.
When you request account deletion, the following rules apply:
9.1 Free Plan Users
Your account and associated Personal Data are scheduled for deletion. Device bindings associated with your account are removed. If you sign up again later, you will be treated as a new user with a new user identifier.
9.2 Premium / Paid Plan Users
If you are on an active paid plan, your access continues until the expiry of your current billing period, after which we delete or anonymise your Personal Data in line with this section. Subscription billing, refunds (if any), and other commercial terms are governed by our separate Terms of Service and applicable platform policies.
9.3 Family Plans
If you are part of a family plan:
- Primary account holder: If the primary (paying) account holder requests deletion, the family plan ends at the expiry of the current billing period. After that date, we delete or anonymise Personal Data associated with the primary account and linked family accounts in line with this section, and linked family members may revert to a free plan or create their own separate accounts.
- Family member: If a non-paying family member requests deletion of their own account, we delete or anonymise that member's Personal Data and remove them from the family plan. The family plan for remaining members continues under the primary account holder.
In all cases, the individual who requests deletion will permanently lose access to their account activity and preferences once deletion takes effect. If you log in again before the scheduled deletion date, we may show a banner or notice that your account is scheduled for deletion and offer you a way to cancel the pending deletion request.
9.4 Data We May Retain After Account Deletion
When we delete an account based on your request, we delete or irreversibly anonymise Personal Data associated with that account, except for limited data that we may retain where we have a legitimate reason to do so, such as:
- Records needed to prevent, detect, and investigate fraud, abuse, or security incidents.
- Records needed to comply with legal or regulatory obligations, including accounting and tax.
- Aggregated or anonymised metrics and insights that do not identify you.
For any retained data, we restrict access to only those people and purposes necessary for these limited reasons, and keep the data only for the minimum period required. You can contact us at any time using the details in the "Contact & Grievance Redressal" section if you have questions about how account deletion works for your specific plan.
Expected deletion timeline: your account and associated Personal Data are scheduled for deletion within 30 days of your request. If you log in again before this period ends, you can cancel the pending deletion request.
10. Your Rights
- Right to Access: You can request a copy of the Personal Data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate or incomplete data.
- Right to Erasure (Right to be Forgotten): You can request that we delete your Personal Data, subject to certain legal exceptions.
- Right to Restrict Processing: You can request that we limit the way we use your data.
- Right to Data Portability: You can request your Personal Data in a structured, commonly used format, where technically feasible.
- Right to Withdraw Consent: You can withdraw consent for any specific data use at any time.
- Right to Grievance Redressal: You can raise a complaint with our Grievance Officer (see Section 14).
To exercise any of these rights, please contact us using the details in Section 14. We may need to verify your identity before acting on a request.
11. Notifications and Marketing
We may send you weekly Threat Reports, security alerts, and breach notifications by push notification; you can turn these off at any time in your device or in-app settings. We may also occasionally send you promotional or educational messages, only with your consent where required, and you can opt out at any time using the unsubscribe link in emails or your in-app preferences. Opting out of marketing does not affect essential account or security communications.
12. Automated Safety Checks
Some of our warnings — such as flagging an unsafe link, risky QR code, or unsafe Wi-Fi network — are generated automatically using security technology and threat intelligence. These outputs are safety recommendations only. They help you make more informed decisions, but they do not make legal, credit, employment, insurance, or financial eligibility decisions about you, and they may not always be 100% accurate.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, features, or legal requirements. If we make material changes, we will notify you through the app, our website, or email, and update the "Last Updated" date at the top of this Policy.
14. Contact & Grievance Redressal
If you have questions, concerns, or complaints about this Privacy Policy or how we handle your data, please contact our Grievance Officer: care@mitigata.com
Grievance Officer
Abhishek Srivastava
2nd Floor, Gayathri Mansion, ORR, Bellandur, 560103
We aim to respond within 30 days of receiving your request, or as required under applicable law.