1. Overview
This Privacy Policy explains how Hyperledger IT Pvt Ltd ("Prapl", "we", "us"), the company behind the Prapl software brand, handles personal data when you visit our website, create an account, or use our software. We are the data controller for the personal data described here. For personal data we process on behalf of business customers, see our Data Processing Agreement.
2. Local-first by design
Many Prapl tools (such as our file transfer, migration and backup software) are designed so that your files, server credentials, database contents and backups stay on your own machines and storage, under your own encryption keys. We build our software so that we cannot see that content — even if asked. Where a tool works this way, that data is never transmitted to us.
3. What we collect
We collect only what we need to run our business and provide the Services:
- Account data — name, email address and password (hashed) when you register.
- Billing data — for paid products, billing name, address and payment identifiers. Card details are handled by our payment processors; we do not store full card numbers.
- Licence & usage data — product, version, licence status, and basic diagnostic/telemetry data (such as crash reports) where you have not opted out.
- Support data — the contents of messages you send to [email protected].
- Website data — IP address, browser type, pages visited and similar analytics data collected via cookies (see our Cookie Policy).
We do not collect your transferred files, backup contents, server passwords or database records for local-first tools.
4. How we use your data
- To provide, maintain and secure the Services and your account.
- To process payments, manage subscriptions and licences, and prevent fraud.
- To provide support and respond to your requests.
- To send service, security and (where permitted) marketing communications — you can opt out of marketing at any time.
- To improve our products through aggregated, diagnostic and analytics data.
- To comply with legal obligations and enforce our terms.
5. Legal bases for processing (EEA/UK)
Where GDPR or UK GDPR applies, we process personal data on the basis of: performance of a contract (to provide the Services), legitimate interests (to secure and improve the Services and for direct marketing to existing customers), consent (for non-essential cookies and certain marketing), and legal obligation (for tax and accounting records).
6. Cookies and tracking
We use strictly necessary cookies to run the site and, with your consent, analytics cookies to understand usage. Full details, including how to manage your preferences, are in our Cookie Policy.
7. Who we share data with
We do not sell your personal data. We share it only with:
- Service providers / processors — payment processors, hosting, email delivery, analytics and support tools, bound by contract to protect your data.
- Professional advisers and authorities — where required by law, court order, or to protect our rights.
- Successors — in connection with a merger, acquisition or sale of assets, subject to this Policy.
8. International data transfers
We operate globally and are based in India. Your data may be processed in countries other than your own. Where we transfer personal data out of the EEA or UK, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
9. How long we keep data
We keep personal data only as long as needed for the purposes above: account data for as long as your account is active, billing records for the period required by tax law, and support data for a reasonable period after resolution. We then delete or anonymise it.
10. Security
We use technical and organisational measures — including encryption in transit, access controls and least-privilege practices — to protect personal data. No system is perfectly secure, but our local-first architecture means the most sensitive data usually never reaches us. Learn more on our Security page.
11. Your rights (GDPR / UK GDPR)
If you are in the EEA or UK, you have the right to: access your data; rectify inaccurate data; erase your data ("right to be forgotten"); restrict or object to processing; data portability; and withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority. To exercise any right, email [email protected]. We will respond within the timeframes required by law.
12. US / California (CCPA/CPRA) rights
If you are a California resident, you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to opt out of any "sale" or "sharing" of personal information. We do not sell your personal information. To exercise these rights, contact [email protected]. We will not discriminate against you for exercising your rights.
13. Children's privacy
The Services are not directed to children under 16, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact us and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. Material changes will be reflected in the "Last updated" date and, where appropriate, notified to you.
15. Contact us
For any privacy question or to exercise your rights, contact Hyperledger IT Pvt Ltd at [email protected] or via our contact page.