Legal
Privacy Policy
This policy explains what personal data Trinetri collects through our website and the Trinetri Autonomous Platform, why we collect it, how we protect it, and the choices and rights you have wherever you are.
Contents18 sections
1.Who we are
“Trinetri”, “we”, “us” and “our” refer to Zirozen Software Corporation LLP , a limited liability partnership registered in India with its registered office at L801, Safal Parisar-1, South Bopal, Ahmedabad 380058, Gujarat, India, and its branch office at 710, Sun Central Place, South Bopal, Ahmedabad 380058. Zirozen Software Corporation LLP has no subsidiaries.
We provide the Trinetri Autonomous Platform, including EndpointOps (autonomous endpoint management), CloudOps (multi-cloud monitoring, posture and cost management), MobileOps (Android and Apple device management) and GAS AI, our agentic assistant.
2.Scope of this policy
This policy applies to personal data we process through:
- our websites, including trinetriops.com, docs.trinetriops.com and care.trinetriops.com;
- the Trinetri cloud console and on-premises or hybrid deployments where we have access to data (for example, during support);
- the Trinetri agents for Windows, macOS and Linux (including Red Hat Enterprise Linux, SUSE Linux Enterprise, Ubuntu, CentOS, Fedora, Rocky Linux and Oracle Linux);
- the Trinetri MobileOps apps and profiles for Android and Apple devices;
- sales, marketing, events, partner programmes, trials, demos and customer support.
Where a customer deploys Trinetri fully on-premises, the customer hosts and controls the data and we do not receive it unless the customer shares it with us, for example in a support ticket or through optional telemetry.
3.Our role: controller or processor
Privacy laws distinguish between the organisation that decides why and how personal data is processed (a “controller”, or “data fiduciary” under India’s DPDP Act) and an organisation that processes it on that organisation’s behalf a “processor”.
| Situation | Our role | Who to contact first |
|---|---|---|
| Data collected from devices, users and cloud accounts managed by a customer through the platform (“Customer Data”) | Processor / data processor | Your employer or the organisation that manages your device |
| Website visitors, trial sign-ups, customer account administrators, billing contacts, partners, support requesters, event attendees and job applicants | Controller / data fiduciary | Zirozen (see Contact) |
| Service data we generate to run, secure and bill the platform (e.g. usage metrics, licence counts, security logs) | Controller | Zirozen |
Our processing of Customer Data is governed by our agreement with the customer and our Data Processing Addendum. If you send us a request about Customer Data, we will forward it to the relevant customer and help them respond.
4.Information we collect
Information you give us
- Account and contact details: name, business email, phone number, company, job title, country, and login credentials (passwords are stored only as salted hashes).
- Commercial details: billing contact, billing address, tax identifiers and purchase history.
- Communications: demo and contact requests, support tickets, chat messages, call recordings (only with notice), feedback and survey responses.
- Job applications: CV and information you choose to share when applying for a role.
Information collected automatically on our website
- IP address, browser type, device type, operating system, referring page, pages viewed and approximate location derived from IP address.
- Cookie and similar identifiers, subject to your choices (see Cookies).
Customer Data processed through the platform
What is collected depends on the modules and policies the customer enables. Typical categories are:
| Module | Categories of data |
|---|---|
| EndpointOps agent | Device name, hostname, serial number, hardware inventory, OS and kernel version, installed software and packages, patch and vulnerability status, running services and processes, performance and experience metrics, logged-in username, IP and MAC addresses, file and registry integrity events for paths the customer configures, USB and peripheral events, compliance benchmark results, and logs of actions taken by administrators or automation. |
| CloudOps | Configuration metadata, resource inventory, security findings, identity and access metadata (such as user and role names) and billing data from cloud accounts the customer connects (e.g. AWS, Microsoft Azure, Google Cloud), accessed through the provider’s APIs using credentials or roles the customer grants. |
| MobileOps (Android and Apple) | Device model, serial number, UDID or enrolment identifier, IMEI/MEID (corporate-owned devices only), OS version, carrier, managed-app inventory, compliance status, and push tokens. Device location is collected only when the customer enables it and, where required, only after the user is notified. |
| GAS AI | Prompts and questions entered by administrators, the platform data needed to answer them, and the resulting recommendations and actions. |
| Integrations | Data exchanged with tools the customer connects (for example ServiceNow, Jira, Zendesk, Microsoft Teams, Microsoft 365, Telegram or WhatsApp), limited to what that integration requires. |
What we do not collect
The Trinetri agents and apps are not designed to capture keystrokes, screen contents, the content of emails, chats, documents or files, browsing history, photos, contacts, call logs or SMS. On personally owned (BYOD) devices enrolled through Android work profile or Apple User Enrollment, the customer and Trinetri can see only the managed work container, not personal apps or data.
5.How we use information
We use personal data only for the purposes below. Where the GDPR, UK GDPR, LGPD or similar laws apply, we rely on the legal basis shown. Under India’s DPDP Act, we process personal data on the basis of your consent or for the legitimate uses the Act permits.
| Purpose | Legal basis |
|---|---|
| Providing, operating and supporting the platform, including processing Customer Data on the customer’s instructions | Performance of a contract; for Customer Data, the customer’s instructions |
| Creating and managing accounts, trials and licences, billing and collecting payments | Performance of a contract |
| Securing the platform, detecting fraud and abuse, and troubleshooting | Legitimate interests; legal obligation |
| Improving the platform using aggregated or de-identified usage data | Legitimate interests |
| Responding to enquiries and demo requests | Legitimate interests; steps prior to a contract |
| Sending marketing emails and newsletters | Consent, or legitimate interests where the law allows B2B marketing; you can unsubscribe at any time |
| Analytics and advertising cookies on our website | Consent |
| Complying with law, tax, accounting and lawful requests from authorities | Legal obligation |
| Establishing, exercising or defending legal claims | Legitimate interests |
We do not sell personal data, do not use Customer Data or device data for advertising or profiling, and do not combine Customer Data with data from other customers except in aggregated, de-identified form that cannot reasonably identify any person or customer.
6.GAS AI and artificial intelligence
GAS AI analyses platform data to recommend and, where the customer allows, carry out actions such as deploying patches or remediating misconfigurations.
- No training on your data: we do not use Customer Data, prompts or outputs to train or fine-tune AI models.
- Model providers: GAS AI uses self-hosted models.
- Human control: customers decide which actions GAS AI may take automatically and which require approval. Actions are logged and can be audited.
- Optional AI integrations: if a customer connects their own AI account (for example ChatGPT or Claude), data sent to that provider is governed by the customer’s agreement with it.
7.Platform-specific disclosures
Trinetri integrates with operating systems and services from Apple, Google, Microsoft, Red Hat and SUSE. We follow the privacy and data-use requirements each of them sets for software and device-management vendors.
Apple (macOS, iOS, iPadOS)
- We use Apple’s Mobile Device Management framework, Apple Push Notification service (APNs) and, where the customer enables it, Apple Business Manager or Apple School Manager for automated enrolment.
- Data obtained through Apple’s MDM protocol and APIs is used only to provide device management to the customer and is never sold, used for advertising, or shared with data brokers, consistent with the Apple Developer Program License Agreement and App Store Review Guidelines.
- For personally owned devices we support User Enrollment, which keeps personal data separate and prevents us from seeing the device’s serial number, UDID or personal apps.
- Our App Store listing includes privacy details (the “privacy nutrition label”) consistent with this policy.
Google (Android and Google Cloud)
- MobileOps uses Android Enterprise, including the Android Management API, fully managed devices and work profiles.
- Our Android app complies with the Google Play Developer Program Policies and User Data policy. The Play Store Data safety section reflects the data described here.
- Where the app requests sensitive permissions (such as location, device administration, accessibility services or the list of installed apps), it shows a prominent in-app disclosure explaining what is collected and why, and asks for consent before collection where Google’s policies require it. These permissions are used only for device management features the customer enables.
- If we access Google user data through Google APIs (for example Google Workspace or Google Cloud), our use and transfer of that data adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use such data for advertising or to train generalised AI models.
Microsoft (Windows, Azure, Microsoft 365 and Entra ID)
- The EndpointOps agent on Windows collects the inventory and security data described above using standard Windows interfaces.
- When a customer connects Microsoft Azure, Microsoft Entra ID, Microsoft 365, Microsoft Graph or Microsoft Teams, we request only the permissions (scopes) needed for the features enabled and use the data solely to provide those features, in line with the Microsoft APIs Terms of Use and Microsoft identity platform requirements. Customers can revoke access at any time from their Microsoft tenant.
Red Hat and SUSE Linux
- On Red Hat Enterprise Linux and SUSE Linux Enterprise (and their related distributions), the agent reads package, repository, kernel and configuration metadata through the system’s package managers (such as DNF/YUM, RPM and Zypper) to assess patch status and compliance.
- The agent does not collect or transmit Red Hat or SUSE subscription credentials, and does not send any customer data to Red Hat or SUSE. Patches are installed from repositories the customer has configured under their own subscriptions.
- Vulnerability and advisory information (for example Red Hat Security Advisories and SUSE security updates, OVAL and CSAF feeds) is public data and contains no personal data.
Apple, macOS, iOS and iPadOS are trademarks of Apple Inc. Android and Google Cloud are trademarks of Google LLC. Microsoft, Windows, Azure, Microsoft 365, Entra and Teams are trademarks of the Microsoft group of companies. Red Hat and Red Hat Enterprise Linux are trademarks of Red Hat, Inc. SUSE is a trademark of SUSE LLC. Their mention does not imply endorsement unless stated.
9.International data transfers
We are based in India, and we host the Trinetri cloud in regions,India (Mumbai), EU (Frankfurt), US (Virginia), Singapore.
When personal data moves across borders, we protect it with appropriate safeguards, including:
- the European Commission’s Standard Contractual Clauses for transfers from the EEA and Switzerland;
- the UK International Data Transfer Addendum for transfers from the UK;
- contractual and technical safeguards required by other laws, such as the LGPD (Brazil), PDPA (Singapore), APPI (Japan), POPIA (South Africa), and the PDPL of Saudi Arabia and of the UAE;
- compliance with any restrictions on transfers the Government of India notifies under the DPDP Act.
You can ask for a copy of the relevant safeguards by contacting us.
10.Data retention
| Data | How long we keep it |
|---|---|
| Customer Data | For the subscription term as configured by the customer, then deleted within 60 days of termination, unless the customer asks for earlier deletion or the law requires longer retention. Backups roll off within 60 days. |
| Account and billing records | For the life of the account, and afterwards as required by tax and company law (currently up to 8 years in India). |
| Marketing contacts | Until you unsubscribe or 24 months after your last interaction. |
| Support tickets | 1 years after the ticket closes. |
| Website analytics | Up to 14 months. |
| Security and audit logs | Up to 1 year, or longer where required by law (including India’s CERT-In directions, which require certain logs to be kept for 180 days). |
| Job applications | 12 months after the process ends, unless you agree to longer. |
When personal data is no longer needed, we delete it or irreversibly de-identify it.
11.How we protect data
We maintain an information security programme certified to ISO/IEC 27001:2022. Our safeguards include:
- encryption in transit using TLS 1.2 or higher, and encryption at rest using AES-256;
- mutually authenticated, encrypted communication between agents and the platform;
- logical separation of each customer’s data in our multi-tenant platform;
- role-based access control, single sign-on, SCIM and multi-factor authentication for customer administrators;
- least-privilege, logged and reviewed access for our staff, who are bound by confidentiality obligations and receive regular privacy and security training;
- vulnerability management, penetration testing, secure development practices and signed agent releases;
- business continuity and disaster recovery plans that are tested regularly.
No system is perfectly secure. If you believe you have found a vulnerability, please report it to info@trinetriops.com.
12.Your rights by region
Depending on where you live, you may have the right to access, correct, update, delete, restrict or object to the processing of your personal data, to receive it in a portable format, and to withdraw consent at any time without affecting earlier processing. We will not discriminate against you for exercising these rights.
To make a request, email info@trinetriops.com. We may need to verify your identity before responding. If your request concerns Customer Data, we will pass it to the organisation that manages your device or account.
Select your region for details that apply to you.
IndiaDigital Personal Data Protection Act, 2023
As a Data Principal you can ask for a summary of your personal data and the processing activities, the identities of other data fiduciaries and processors it has been shared with, and correction, completion, updating or erasure of your data. You can withdraw consent as easily as you gave it, nominate another person to exercise your rights in the event of your death or incapacity, and raise a grievance with our Grievance Officer (see Contact). We will respond within the time set by the Digital Personal Data Protection Rules, 2025. If you are not satisfied, you can complain to the Data Protection Board of India. You may also manage consent through a registered Consent Manager where available.
United StatesCCPA/CPRA and other state privacy laws
Residents of California and of states with comprehensive privacy laws (including Colorado, Connecticut, Virginia, Utah, Texas, Oregon and others) may have the right to know what personal information we collect, use and disclose; to access, correct and delete it; to opt out of sale, sharing for targeted advertising and profiling; and to limit use of sensitive personal information. We do not sell or share personal information and do not use sensitive personal information to infer characteristics about you. We honour Global Privacy Control signals as an opt-out. You may use an authorised agent, and where your state provides it, you may appeal our decision by replying to our response. We respond within 45 days, extendable as the law permits.
In the preceding 12 months we collected the categories described in Information we collect: identifiers, commercial information, internet or network activity, approximate geolocation, professional information, and inferences limited to product usage. We disclosed them for business purposes only to the recipients in How we share information.
If your country is not listed, you can still contact us and we will respond in line with this policy and your local law.
14.Children’s data
Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal data from anyone under 18 (or the relevant age in your country) for our own purposes, and we do not track, behaviourally monitor or target advertising at children. If a customer, such as a school, uses Trinetri to manage devices used by children, the customer is responsible for obtaining any verifiable parental consent required by law, including under India’s DPDP Act, the US COPPA and the GDPR. If you believe a child has given us personal data, please contact us and we will delete it.
15.Automated decision-making
Trinetri automates IT and security operations on devices and cloud resources. We do not make decisions about individuals based solely on automated processing that produce legal or similarly significant effects on them. Customers configure how automation is used within their organisation.
16.Personal data breaches
If a breach affects personal data, we will notify affected customers without undue delay and support them in meeting their obligations. Where we are the controller, we will notify regulators and affected individuals as required by law, including the Data Protection Board of India and CERT-In (within 6 hours of noticing certain incidents), and EU and UK supervisory authorities (within 72 hours where required).
17.Changes to this policy
We may update this policy as our services or the law change. We will post the updated version here with a new 10-June-2026 and, for material changes, notify customers by email or in the console before the changes take effect. Previous versions are available on request.
18.Contact and grievances
For privacy questions, requests or complaints, contact us using the details below. We aim to acknowledge requests within 3 business days.
Privacy team
Postal address for registered office
Zirozen Software Corporation LLP
L801, Safal Parisar-1, South Bopal
Ahmedabad 380058, Gujarat, India
For product support, email info@trinetriops.com or raise a ticket at care.trinetriops.com.