Data protection · DPDPA 2023, IT Act 2000 & GDPR compliance
Effective Date: March 31, 2026 · Last Updated: July 27, 2026 · ArthaOps. Inc.
Welcome to the exhaustive Privacy Policy of ArthaOps. Inc. (hereinafter referred to interchangeably as "ArthaOps," "we," "us," or "our"). We recognize that in the modern enterprise software-as-a-service (SaaS) landscape, particularly concerning cloud cost optimization and infrastructure governance, data privacy is not merely a statutory obligation but a foundational pillar of trust, architectural integrity, and operational security.
This Privacy Policy sets forth our unwavering commitment to safeguarding the personal, technical, and metadata derived from our business-to-business (B2B) clientele. Our platform is designed with privacy-by-design and privacy-by-default architectures, strictly aligning with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000 (IT Act), the CERT-In Cyber Security Directions 2022, and maintaining rigorous sovereign alignment with the General Data Protection Regulation (GDPR) for our global stakeholders. We operate exclusively on a multi-tenant cloud cost management thesis, identifying waste and inefficiency across AWS environments, deploying our proprietary suite of 378 cloud cost waste detectors.
By executing an agreement, creating an account, authenticating via our Enterprise Single Sign-On (SSO) infrastructure, or otherwise utilizing the ArthaOps Control, Operator, or Command plans, you ("Customer," "User," "Enterprise," or "Data Principal") explicitly acknowledge, comprehend, and consent to the intricate data processing paradigms articulated in this multi-tiered policy document. We implore you to read this document with the utmost scrutiny, as it constitutes a binding legal framework governing the lifecycle, ingestion, processing, cryptology, and eventual purge of your data within our localized sovereign cloud environments in AP-SOUTH-1 (Mumbai).
To preclude ambiguity and establish a precise lexicon for this Privacy Policy and associated agreements, the following defined terms shall have the meanings ascribed to them hereunder, whether utilized in singular or plural form, and shall dictate the interpretative boundaries of our data processing undertakings:
This Privacy Policy universally governs all interactions, data exchanges, and API payloads executed between ArthaOps and its authorized users across the entire spectrum of our offerings. This scope includes the public-facing marketing website, the authenticated web application (Control Plane), our programmatic interfaces (APIs), our documentation repositories, and the backend ingestion daemons that interface with your localized AWS infrastructure. The architectural blueprint of ArthaOps is explicitly engineered to decouple the control plane (hosted by us) from the data plane (residing within your AWS accounts), thereby minimizing our blast radius and dramatically reducing the volume of sensitive data traversing our network boundaries.
It is imperative to note that this Policy does not govern the privacy practices of third-party platforms, open-source dependencies deployed within your environments independently, or the underlying core infrastructure provided by Amazon Web Services, except to the extent that ArthaOps interacts with such services via explicitly granted IAM roles. We emphatically disclaim any liability for data exposures, misconfigurations, or privacy breaches originating from the inherent insecurity of the customer's proprietary applications, underlying network architecture, or failure to adhere to the principle of least privilege when provisioning the ArthaOps IAM Role. Our scope is strictly bounded by the permissions defined in our provided CloudFormation and Terraform templates.
If you do not agree with the extensive, uncompromising data handling practices delineated herein, your sole and exclusive remedy is to immediately cease all usage of the ArthaOps platform, revoke all IAM roles granted to our AWS Account IDs, and initiate an account deletion request via our primary support vector at support@arthaops.com. Continued utilization of the service unequivocally constitutes binding acceptance of these architectural constraints and privacy protocols.
ArthaOps enforces an aggressive, unyielding stance on data minimization. We operate under the foundational premise that we cannot leak, lose, or expose data that we simply do not possess. Our ingestion daemons are mathematically constrained to invoke read-only AWS APIs (specifically List*, Describe*, and GetMetricData operations) to fetch the absolute minimum metadata required to fuel our 378 cloud cost waste detectors. We do not inspect payloads, we do not read object contents, and we do not query your relational or non-relational database rows. The ingestion scope is meticulously delineated across the following AWS services:
s3:GetObject permissions. We cannot read, download, or index the files, images, documents, or data payloads stored within your S3 buckets.GetMetricData to ingest time-series performance metrics for the aforementioned services. This data is purely numeric (timestamps and floating-point values) and contains no personally identifiable information (PII) or business logic.To further cement our commitment to data minimization and to provide absolute clarity to our enterprise clientele, ArthaOps explicitly, categorically, and unconditionally prohibits the ingestion, processing, storage, or transmission of the following categories of data. Our technical architecture actively prevents the collection of this information, and our IAM bounds are mathematically incapable of accessing it:
In strict adherence to the fundamental principles of modern privacy legislation, including the Digital Personal Data Protection Act, 2023 (DPDPA) and the General Data Protection Regulation (GDPR), ArthaOps processes your minimal Personal Data and extensive infrastructure Metadata on precisely defined legal bases. We do not engage in arbitrary or legally ambiguous data processing activities. Our processing operations are grounded in the following justifications:
A. Contractual Necessity (Performance of a Contract): The overwhelming majority of our data processing—including user registration via Logto Cloud OIDC, billing operations via Razorpay, and the core ingestion of AWS metadata—is strictly necessary for the performance of the SaaS agreement (Terms of Service) executed between ArthaOps and the Customer. Without processing this telemetry, the provision of our 378 cloud cost waste detectors would be technically impossible. This basis covers the core functionality of the Discovery, Control, Operator, and Command plans.
B. Explicit Consent: Where mandated by law, or for activities that fall outside the strict purview of contractual necessity (such as the activation of the autonomous Autopilot remediation features, or opting into marketing communications), we rely on explicit, informed, and unambiguous consent. Under the DPDPA 2023, this consent is obtained via clear affirmative action, managed transparently, and can be withdrawn at any time without prejudice, subject to the technical limitations of reversing automated actions already executed.
C. Legitimate Interests: We may process certain metadata, anonymized telemetry, and platform usage analytics to fulfill our legitimate business interests, provided such interests are not overridden by the fundamental rights and freedoms of the Data Principal. This includes activities such as platform security enhancements, fraud detection, performance optimization of our infrastructure in AP-SOUTH-1, and the continuous refinement of our waste detection algorithms. We utilize post-processed, sanitized data via PostHog to fulfill these interests, ensuring individual privacy is maintained.
D. Legal Obligation: ArthaOps will process and, if necessary, disclose Personal Data and audit logs when strictly required to comply with a binding legal obligation imposed by the laws of India. This includes, but is not limited to, compliance with the Companies Act 2013 for financial auditing, the CGST Act 2017 for tax invoicing (generating B2B GSTIN credit notes), and responding to lawful, validly issued subpoenas or warrants from Indian judicial authorities or statutory bodies such as CERT-In.
ArthaOps operates under a rigid sovereign data mandate, purposefully engineered to exceed the localization requirements and privacy standards of the Indian regulatory landscape. We have centralized our entire primary production infrastructure, including all compute clusters, relational databases, distributed cache layers (Redis), event brokers, and persistent block storage, exclusively within the AWS AP-SOUTH-1 (Mumbai) region. This architectural decision guarantees absolute data residency within the Republic of India.
Our compliance posture is deeply integrated with the mandates of the Digital Personal Data Protection Act, 2023 (DPDPA). We operationalize compliance with key sections as follows:
The cornerstone of ArthaOps' security and privacy framework is our uncompromising Zero Static Credential Architecture. Traditional SaaS platforms often request long-lived AWS Access Keys, creating a catastrophic vulnerability if the SaaS provider's database is compromised. ArthaOps categorically rejects this paradigm. We utilize the AWS Security Token Service (STS) to implement a dynamic, ephemeral credential vending machine.
When a Customer integrates their AWS environment with ArthaOps, they deploy an IAM Role via CloudFormation or Terraform. This role establishes a trust relationship exclusively with the ArthaOps AWS Account ID. Crucially, we mandate the use of a cryptographically secure, unique External ID generated during the onboarding process. This External ID acts as a cryptographic nonce, unequivocally mitigating the "Confused Deputy" vulnerability, ensuring that no other ArthaOps customer can maliciously assume your IAM role.
When our background worker pools require telemetry, they invoke the sts:AssumeRole API endpoint, supplying the target Role ARN and the specific External ID. AWS validates this request and issues ephemeral, short-lived session tokens (typically valid for 15 to 60 minutes). These temporary credentials are held only in the volatile memory of our worker nodes and are never written to persistent disk storage, databases, or cache layers. Once the ingestion task is complete, the session tokens evaporate. Even in the theoretical event of a database exfiltration, an attacker would yield absolutely zero actionable AWS credentials.
ArthaOps offers an advanced, optional capability termed "Autopilot," designed to execute autonomous remediation actions against identified cloud cost waste. Given the inherent risks of programmatic infrastructure modification, the Autopilot feature operates under an exceptionally strict data access governance model, requiring explicit, multi-layered authorization.
Autopilot is strictly opt-in. The default IAM Role provisioned during onboarding contains only ReadOnlyAccess bounds. To enable Autopilot, the Customer must proactively deploy a supplementary IAM policy that grants narrowly scoped mutation permissions (e.g., ec2:StopInstances, rds:StopDBInstance, ebs:DeleteVolume). ArthaOps will never autonomously attempt to escalate privileges or brute-force mutation operations.
Furthermore, the Autopilot engine operates via a rigorous Dry-Run Dependency Graph. Before any destructive or state-altering API call is executed, our engine simulates the action to evaluate potential cascading failures or downstream dependencies. All Autopilot actions—both dry-runs and actual executions—are permanently etched into our SHA-256 Hash-Chained Audit Ledger. For high-risk operations, Autopilot enforces a 1-click snapshot rollback mechanism, ensuring that point-in-time recovery data is available prior to resource termination, thereby safeguarding business continuity and data integrity.
ArthaOps processes the ingested metadata, telemetry, and personal data (such as authentication identifiers) for a meticulously defined set of purposes. We adhere to the principle of purpose limitation, ensuring that data is never repurposed for secondary, undisclosed activities such as data brokering or algorithmic surveillance. The explicit purposes for processing include:
ArthaOps operates as a modern cloud-native entity and, by necessity, leverages a curated selection of elite third-party service providers (Sub-processors) to deliver our SaaS capabilities. We do not sell, rent, or indiscriminately share your data. All sub-processors are subjected to intense security evaluations and are bound by stringent Data Processing Agreements (DPAs) that mandate security postures equivalent to or exceeding our own. Our primary sub-processors include:
Mandatory Disclosures: Notwithstanding the above, ArthaOps reserves the unassailable right to disclose your data if legally compelled to do so by a valid court order, subpoena, or statutory directive from Indian law enforcement or regulatory authorities (e.g., CERT-In), or when we determine in good faith that disclosure is strictly necessary to protect the physical safety, property, or vital interests of ArthaOps, our users, or the public.
As a technology company operating within the Indian jurisdiction, ArthaOps is fully cognizant of and strictly complies with the Information Technology Act, 2000, and the sweeping Cyber Security Directions issued by the Indian Computer Emergency Response Team (CERT-In) in April 2022.
In absolute compliance with CERT-In mandates, we maintain synchronized Network Time Protocol (NTP) servers connected to authorized Stratum 1 time sources (NIC/NPL) for all infrastructure logging. We are legally bound to report any severe cyber security incidents (as classified in Annexure I of the Directions) to CERT-In within the mandatory 6-hour window. This aggressive reporting timeline is embedded directly into our incident response runbooks.
Furthermore, we strictly adhere to the data retention mandates stipulated by the IT Act and CERT-In. We securely retain specified system logs, firewall configurations, and access trails within our sovereign Indian infrastructure for a rolling period of 180 days, making them available to authorized government agencies solely upon the presentation of a valid, lawful requisition order.
ArthaOps enforces precise, automated data retention and destruction lifecycles. We do not hoard data indefinitely. Our retention schedules are explicitly categorized and strictly enforced by automated background cron jobs:
Cryptographic security is not an afterthought; it is woven into the very fabric of the ArthaOps architecture. We employ military-grade encryption protocols to ensure the confidentiality and integrity of all data moving through or resting within our sovereign infrastructure.
Encryption in Transit: Absolute transport layer security is enforced across all network boundaries. All communication between the Customer's browser, our API gateways, internal microservices, and external sub-processors is rigorously encrypted using TLS 1.3 (Transport Layer Security) with perfect forward secrecy (PFS). We utilize strictly configured cipher suites (e.g., TLS_AES_256_GCM_SHA384) and explicitly disable legacy protocols such as TLS 1.0, TLS 1.1, and all versions of SSL. Non-HTTPS traffic is aggressively rejected or immediately redirected to secure endpoints via HTTP Strict Transport Security (HSTS) directives.
Encryption at Rest: Every single byte of data resting within our AP-SOUTH-1 infrastructure—encompassing our relational databases (Amazon RDS PostgreSQL), persistent block storage (Amazon EBS), object storage (Amazon S3 backups), and distributed cache (Amazon ElastiCache Redis)—is encrypted at rest using the Advanced Encryption Standard with a 256-bit key (AES-256). We utilize the AWS Key Management Service (KMS) for robust, centralized cryptographic key generation, rotation, and access control, ensuring that underlying storage volumes remain entirely impenetrable even in the event of physical drive theft from an AWS data center.
Transparency and operational accountability are paramount for enterprise trust. To provide unassailable proof of our platform's actions—particularly concerning IAM role assumptions and Autopilot mutations—ArthaOps has engineered a proprietary, cryptographically secure Audit Ledger.
This ledger operates on a linear, SHA-256 hash-chain architecture. Every significant state change, API invocation against a Customer's AWS account, and background synchronization event is recorded as a discrete, immutable block. Each block computes a cryptographic hash that inherently incorporates the hash of the immediately preceding block. This mechanism guarantees that the ledger is mathematically tamper-evident — any attempt to silently alter, delete, or rewrite historical logs would instantaneously invalidate the subsequent hash chain, triggering immediate internal security alarms and visibly corrupting the ledger's integrity. Note: this is a centrally managed, linear hash-chain ledger, distinct from decentralized blockchain architectures.
This Audit Ledger is fully accessible to the Customer via the Command plan interface, allowing security operations teams to continuously monitor exactly what ArthaOps is doing, when it did it, and under what authorization context.
Under the robust framework of the DPDPA 2023, the GDPR, and other progressive privacy legislations, you, as a Data Principal, possess a suite of fundamental, inalienable rights concerning your personal data. ArthaOps is fully committed to facilitating the seamless exercise of these rights:
To exercise any of the rights enumerated above, Data Principals must submit a formal Data Subject Access Request (DSAR). ArthaOps has instituted a streamlined, highly responsive DSAR workflow to ensure compliance with statutory timelines.
All DSARs must be initiated via written communication directed to our dedicated privacy inbox at privacy@arthaops.com. Upon receipt, our compliance team will initiate a mandatory identity verification protocol to prevent fraudulent data extraction or unauthorized alterations. We will never fulfill a DSAR without absolute confirmation of the requester's identity.
Once identity is verified, ArthaOps guarantees the fulfillment of the DSAR within the strict 30-day statutory window prescribed by global privacy standards. In the exceptionally rare event that a request is mathematically complex or requires extensive data collation spanning multiple tenant silos, we reserve the right to extend this period by a maximum of 30 additional days, provided we proactively notify the Data Principal of the extension and the specific technical reasons necessitating the delay. All standard DSAR processing is conducted entirely free of charge.
As emphasized in our localization commitments, ArthaOps operates under a strict Sovereign Data Lock paradigm. The overwhelming majority of your metadata, telemetry, and platform configurations remain physically and logically locked within the borders of India (AWS AP-SOUTH-1).
We vehemently reject the practice of indiscriminately replicating customer telemetry to international data centers for cost savings or operational convenience. Any incidental data transfers that cross international borders—such as transient API payloads sent to our global sub-processors (e.g., Logto Cloud for SSO, Sentry for error logging)—are subjected to extreme scrutiny. These specific data flows are governed by ironclad Standard Contractual Clauses (SCCs) and Data Processing Agreements (DPAs) that legally bind the recipient to uphold privacy standards that are completely isomorphic to the DPDPA 2023 and GDPR. Furthermore, all transmitted data is heavily sanitized, stripping out raw infrastructure identifiers, account numbers, and IP addresses prior to transmission across national borders.
In the highly unlikely event of a catastrophic security failure, unauthorized data exfiltration, or cryptographic compromise (a "Data Breach"), ArthaOps maintains an aggressive, rehearsed Security Incident Response Plan. We do not engage in obfuscation or delay tactics.
Upon the verified detection of a breach, our incident response team initiates immediate containment protocols, including the emergency revocation of all active AWS STS tokens, the isolation of compromised infrastructure segments, and the potential suspension of the SaaS control plane to prevent further lateral movement.
Notification Timelines: We adhere to a rigid, transparent notification policy. If a breach poses a risk to your personal data or AWS infrastructure, we will notify the primary technical contact associated with your enterprise account without undue delay, and in absolutely no case later than 72 hours after becoming aware of the breach. Furthermore, in strict compliance with CERT-In directions, any severe incident will be formally reported to the Indian Computer Emergency Response Team within 6 hours of discovery. Our notifications will detail the nature of the breach, the specific data categories impacted, our immediate mitigation efforts, and actionable guidance on how to secure your AWS environment (e.g., rotating IAM external IDs).
The ArthaOps platform, including all associated software, documentation, and services, is engineered, marketed, and contractually restricted exclusively for Business-to-Business (B2B) utilization. We serve modern enterprises, cloud-native startups, and corporate entities. Our SaaS product is categorically not intended for consumer use, personal data management, or household applications.
Consequently, we strictly enforce a Children's Data Exclusion policy. ArthaOps does not knowingly solicit, collect, process, or store any personal data from individuals under the age of 18 (or the age of majority in their respective jurisdictions). Our Terms of Service explicitly prohibit the creation of accounts by minors. If we become aware, through internal audits or external notification, that we have inadvertently collected data belonging to a minor, we will execute an immediate, unrecoverable cryptographic purge of that data from all active systems and backup archives, overriding all standard retention schedules.
The technology landscape, cloud computing paradigms, and global privacy legislations are in a state of continuous evolution. Consequently, ArthaOps reserves the absolute right to unilaterally modify, amend, or rewrite this Privacy Policy at our discretion to reflect architectural upgrades, regulatory shifts, or the introduction of new SaaS capabilities (such as additional detectors or Autopilot functions).
However, we recognize our profound obligation to maintain transparency. We will not silently alter fundamental privacy protections. In the event of material changes to this Policy—specifically alterations that expand our data ingestion scope, modify data sharing practices, or dilute Data Principal rights—we will provide explicit, proactive notification to all active Customers. This notification will be disseminated via an unmissable banner within the authenticated ArthaOps web console and a direct email communication sent to the registered primary billing and technical contacts at least 15 days prior to the enforcement of the revised policy. The "Effective Date" at the apex of this document will always reflect the most recent cryptographic commit of this policy text. Continued use of the platform following the effective date constitutes binding acceptance of the amended terms.
In absolute compliance with the mandates of the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, ArthaOps has designated a statutory Grievance Officer to oversee our privacy operations, manage DSARs, and resolve disputes. If you have any inquiries, concerns, complaints, or if you wish to exercise your fundamental data rights, you are instructed to contact our Grievance Officer utilizing the following vectors:
We commit to acknowledging all formal grievances within 24 hours of receipt and resolving them within 15 days, or such shorter period as mandated by prevailing law. If your grievance remains unresolved or is addressed unsatisfactorily, you maintain the statutory right to escalate your complaint to the Data Protection Board of India or the relevant judicial authorities within the jurisdiction of Mumbai/Jalgaon, Maharashtra.