Privacy Policy
Last updated: [date to be confirmed]
This policy explains how Sciagen Private Limited ("Sciagen", "we", "us") collects and uses personal data when you use the Sciagen Web Capture website and service.
1. Who we are
[Controller / data fiduciary details, registered address and, where required, data protection officer or grievance officer contact.]
2. Data we collect
- Account data — name, email address, company, password (stored only as a secure hash), organisation membership and role.
- Try-it requests — the URL you submit, the device view, your email address and your consent choices.
- Demo and contact requests — name, company, role, email, country and your message.
- Capture data — website content captured on your instruction, generated PDFs and reports, and credentials you provide for staging or members-only areas (encrypted on receipt and deleted when the job ends).
- Usage and security data — IP address, browser information, audit-log entries and, only with your consent, privacy-friendly analytics.
- Cookies — see our Cookie Policy.
3. Purposes and legal bases
[Providing the Service; verifying email addresses; preventing abuse (including bot protection); security and audit; responding to demo and contact requests; product news only where you have opted in; legal obligations. Legal bases / grounds for processing to be supplied.]
4. AI processing
AI features (auto-recipe, version diff and compliance pre-check) are powered by Anthropic Claude. Captured page content is sent to Anthropic for processing only for organisations that have enabled AI features. Anonymous try-it captures are not sent for AI processing. [Sub-processor terms and transfer safeguards to be supplied.]
5. Sharing and sub-processors
[Hosting and storage providers, email delivery, bot protection, AI provider (for organisations that enable AI), and delivery to the Sciagen Content Management System when your organisation configures it.]
6. Retention
- Customer capture outputs: deleted automatically after the organisation's retention period — 30 days by default.
- Anonymous try-it captures: deleted automatically after 7 days.
- Site credentials: deleted when the capture job ends.
- [Account, audit-log and enquiry retention periods to be supplied.]
7. International transfers
[To be supplied.]
8. Your rights
Depending on where you are, you may have rights under the EU/UK General Data Protection Regulation (GDPR) and India's Digital Personal Data Protection Act, 2023 (DPDP Act), including the right to:
- access the personal data we hold about you;
- correct or update inaccurate data;
- erase your data;
- restrict or object to processing, and withdraw consent at any time;
- data portability;
- nominate another person to exercise your rights (DPDP Act);
- raise a grievance with us and complain to a supervisory authority or the Data Protection Board of India.
9. Data export and deletion
[How to request an export of your data or deletion of your account, response times, and in-product export and deletion options for organisation administrators.]
10. Security
[Summary of technical and organisational measures: encryption, isolated capture workers, SSRF protection, access controls, audit trail.]
11. Children
The Service is intended for business users and is not directed at children.
12. Changes to this policy
[To be supplied.]
13. Contact
To exercise your rights or ask a question about privacy, use our contact form. [Postal address and grievance officer details to be supplied.]