Legal

Privacy Policy

Last updated: 30 September 2026

1. Who we are

UrKavach (“we”, “us”) is a website security, uptime, performance and SEO monitoring service operated by UrKavach, [Your postal address (LEGAL_ADDRESS)]. For questions about this policy or your data, write to support@urkavach.com.

2. Our two roles

As a controller we decide why and how we use the personal data of people who use our dashboard, contact us or visit our public pages (for example your name, email address and login details).

As a processor we handle data on behalf of our customers when we monitor, scan, crawl or back up the customer's websites. That data can include personal data of the customer's own visitors, customers and staff. In that case the customer is the controller and we act on its instructions, as described in our GDPR & data protection page.

3. What we collect and why

DataExamplesWhy (and legal basis)
Account dataName, email address, role, password (stored only as a salted scrypt hash, never in clear text), last loginTo create and secure your account and provide the service. Contract.
Session and security dataSession cookie; the IP address and browser type of each signed-in device (shown to you under Account, so you can spot and sign out unknown devices); login attempts. Your IP address is also used in memory to slow down repeated failed logins and appears in server or proxy logs. If you turn on two-factor login we store the secret for your authenticator app and hashed recovery codes.To keep you signed in, prevent abuse and protect the service. Legitimate interests.
Customer content you enterClient names and contact emails, notes, logos, website addresses, alert email addresses and webhook URLsTo run the features you configure. Contract.
Monitoring resultsUptime checks, security findings, SEO crawl results (page URLs, titles, headings, links), speed measurements, alert historyTo provide monitoring, alerts and reports. Contract.
Data from the optional WordPress pluginWordPress, PHP, plugin and theme versions; administrator usernames and email addresses; file lists and checksums; and, only if you use backups, a copy of the site's database and filesTo detect tampering, apply updates and make backups you ask for. Contract. We act as a processor for this data.
Billing dataBilling name, email and address, GSTIN if you provide it, plan, and payment records (amount, date, status, payment reference). Card, UPI and bank details go directly to the payment provider and never reach our servers.To take payment, issue invoices and meet tax and accounting law. Contract / legal obligation.
Sign-up verificationWhile you sign up, your email address, name, company name and a hash of your chosen password are held for up to 10 minutes until you confirm the emailed code. Nothing is kept if you do not finish.To confirm that you own the email address before an account exists. Contract / legitimate interests.
MessagesEmails you send us; alert and digest emails we send youTo answer you and deliver the service. Contract / legitimate interests.
Public websiteStandard server logs (IP address, browser, pages requested)Security and reliability. Legitimate interests.

We do not use advertising, analytics or tracking tools on our public pages, and we do not build profiles of visitors.

4. Who we share data with

We do not sell personal data. We use the following categories of service providers (“sub-processors”), depending on which features you enable:

  • Infrastructure: [Hosting provider (HOSTING_PROVIDER)] hosts the service and its database (region: [Hosting region (HOSTING_REGION)]).
  • Payments: our payment provider processes subscription payments and receives your name, email and billing details.
  • Email delivery: the SMTP provider configured for sending alerts and digests.
  • Google: PageSpeed Insights receives the website address to test speed; Web Risk or Safe Browsing (if enabled) receive the website address to check for malware and phishing warnings; Search Console data is read only when you connect it.
  • Vulnerability data: if enabled, a vulnerability database provider (WPScan) receives plugin, theme and WordPress version identifiers, not personal data.
  • Domain registries: the public RDAP service receives the domain name to check its expiry date.
  • Chat and email destinations you choose: Slack, Discord, Google Chat or email recipients receive alert text you configure.

We may also disclose data if the law requires it, to protect our rights, or in a business transfer, always with the same level of protection.

5. International transfers

The service is hosted in [Hosting region (HOSTING_REGION)]. Some providers listed above may process data in other countries. Where personal data is transferred out of the EEA, the UK or another region with transfer rules, we rely on an adequacy decision or on appropriate safeguards such as standard contractual clauses.

6. How long we keep data

DataDefault retention
Uptime checks and alert history90 days
Sign-in sessions14 days, or until you log out
Speed test historyUp to the 60 most recent tests per site
SEO crawl page data and plugin snapshotsThe 3 most recent crawls and snapshots per site
Site backupsThe newest 7 per site, until you delete them
Issues, reports and site settingsUntil you delete the site or the account
Payment and invoice recordsAs long as tax and accounting law requires, even after you close your account
Account dataWhile your account is active; removed on request or when the account is closed, unless the law requires us to keep it

Deleting a site removes its scan results, issues, backups records and settings. Backups stored on our servers are deleted with it.

7. Security

We protect data with encrypted connections (HTTPS), salted password hashing, protection against cross-site request forgery, HttpOnly session cookies, role-based access (client users are read-only), signed and time-limited requests between the dashboard and the WordPress plugin, and checksum-verified backups. No system is completely secure. If a personal data breach affects you we will notify you and the relevant authority as the law requires.

8. Your rights

Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent where we rely on it. This includes rights under the EU and UK GDPR, India's Digital Personal Data Protection Act 2023, and the California Consumer Privacy Act. We do not sell or “share” personal information for advertising.

Signed-in users can download their account data and delete their account from the Account page. For anything else write to support@urkavach.com; we aim to respond within one month. You may also complain to your data protection authority (in India, the Data Protection Board; in the EU, your national supervisory authority; in the UK, the ICO).

If we hold your data as a processor for one of our customers, please contact that customer first; we will help them respond.

9. Children

UrKavach is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18.

10. Cookies

We only set essential cookies (sign-in, and short-lived ones during sign-up and two-factor login). Details are in our Cookie Policy.

11. Changes to this policy

We will update this page when our practices change and change the “last updated” date above. For material changes we will also notify account holders by email or in the dashboard.

12. Contact

UrKavach
[Your postal address (LEGAL_ADDRESS)]
support@urkavach.com