Privacy Policy
How BitAssert Software Private Limited collects, uses, stores, shares and protects personal data in connection with the BitAssert Platform, under the DPDP Act, 2023 and the IT Act, 2000.
- Client
- BitAssert Software Private Limited
- Date
- June 2026
- Governing Law
- Laws of India
- Jurisdiction
- Courts of Hyderabad, Telangana, India
Contents
- 1Introduction
- 2Scope and Applicability
- 3Definitions
- 4Identity of the Data Fiduciary
- 5Personal Data We Collect
- 6Purposes of Processing and Lawful Basis
- 7Cookies and Tracking Technologies
- 8Disclosure and Sharing of Personal Data
- 9Information Security
- 10International Transfers of Personal Data
- 11Data Retention
- 12Rights of Data Principals
- 13Artificial Intelligence and Automated Processing
- 14Children’s Privacy
- 15Changes to This Policy
- 16Contact Information
- 13Automated Decision-Making and Profiling
- 14Grievance Redressal Process
1.Introduction
BitAssert Software Private Limited (“BitAssert”, “we”, “us”, or “our”) is an Indian private limited company incorporated under the Companies Act, 2013, bearing Corporate Identification Number U62013TS2025PTC203531, having its registered office at SY:11, WeWork Krishe Emerald, Laxmi Cyber City, Cyberabad, Shaikpet, Hyderabad 500081, Telangana, India.
BitAssert operates the BitAssert Platform, an AI-powered unified software test automation platform delivered as a cloud-based software-as-a-service, providing web testing, API testing, performance testing, and related AI-assisted quality engineering services (the “Platform”). The Platform is accessible at app.bitassert.com and is operated on BitAssert’s own private cloud infrastructure located in India.
This Privacy Policy (“Policy”) explains how BitAssert collects, uses, processes, stores, shares, transfers, and protects personal data in connection with the Platform. This Policy is published in compliance with the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023 (“DPDP Act”), as applicable.
2.Scope and Applicability
2.1Coverage
This Policy applies to all individuals who register for an Account on the Platform; visitors to BitAssert’s website and web properties; individuals whose personal data is submitted as part of Customer Data; and individuals who communicate with BitAssert for support, sales, legal, or compliance purposes.
2.2Processor Activities
Where BitAssert processes personal data on behalf of a Customer as a data processor, the terms of the applicable Data Processing Agreement govern that processing. This Policy addresses BitAssert’s own data processing activities as a controller or Data Fiduciary.
3.Definitions
| Defined Term | Meaning |
|---|---|
| Account | The account created by or on behalf of a Customer or individual user to access and use the Platform. |
| AI Features | Platform functionality that uses one or more third-party AI providers for AI inference, including the API Validation Expression Generation feature and AI-assisted test authoring. The current AI provider(s) are identified in Section 10.3 and the Data Processing Agreement. All AI-generated outputs are assigned ‘in_review’ status and require human review before execution. |
| Customer | A legal entity or individual that has subscribed to the Platform under a subscription agreement or Order Form. |
| Customer Data | All data, test scripts, test execution results, screenshots, video recordings, API payloads, network traces, and other content uploaded to or generated within the Platform by or on behalf of a Customer. |
| Data Fiduciary | Has the meaning given to it under section 2(i) of the DPDP Act — a person who alone or in conjunction with other persons determines the purpose and means of processing of personal data. |
| Data Principal | Has the meaning given to it under section 2(j) of the DPDP Act — the individual to whom the personal data relates. |
| DPDP Act | The Digital Personal Data Protection Act, 2023 (No. 22 of 2023), as in force from time to time. |
| Enterprise Plan | The subscription tier providing default retention of 180 days for Test Artefacts and a maximum of 500 concurrent virtual users and 240-minute duration for performance testing. |
| Local Agent | The downloadable software component a Customer may install within its own environment to enable AI-assisted test authoring. Communicates with BitAssert’s cloud API for test authoring and with the BitAssert browser application for local test execution. Operates via port 8887 by default (user-configurable). Minimum requirements: 2 CPU cores, 2 GB RAM. No root or administrator privileges required in steady-state operation. |
| Personal Data | Any information that relates to an identified or identifiable natural person, as defined under the DPDP Act and applicable equivalent legislation. |
| Platform | The BitAssert AI-augmented unified test automation platform, including all web interfaces, APIs, Local Agent software, device infrastructure, and related tooling. |
| Sensitive Personal Data | Data as defined under the IT (SPDI) Rules, 2011. |
| Standard Plan | The subscription tier providing default retention of 30 days for Test Artefacts and a maximum of 100 concurrent virtual users and 60-minute duration for performance testing. |
| Test Artefact | Test scripts, test execution results, screenshots, video recordings, HAR files, API payloads, logs, and AI-generated outputs stored within the Platform. |
4.Identity of the Data Fiduciary
4.1BitAssert as Data Fiduciary
For the purposes of the DPDP Act and applicable Indian data protection law, BitAssert Software Private Limited acts as the Data Fiduciary in respect of personal data it collects and processes for its own purposes, including account management, platform operation, support, billing, security, and communications.
- Company Name
- BitAssert Software Private Limited
- CIN
- U62013TS2025PTC203531
- Registered Address
- SY:11, WeWork Krishe Emerald, Laxmi Cyber City, Cyberabad, Shaikpet, Hyderabad 500081, Telangana, India
- Authorised Signatory
- Sudheer Kumar D, Co-Founder and Chief Executive Officer
- Platform URL
- app.bitassert.com
- Legal Contact
- legal@bitassert.com
- Grievance Officer
- Sudheer Kumar D
- Grievance Email
- grievance@bitassert.com
- Grievance Phone
- [Mobile Number — To Be Confirmed]
- Response Time
- Within 30 days of receipt of a valid grievance
5.Personal Data We Collect
5.1Account Registration and Authentication
When a user registers for a Platform Account, BitAssert collects the following:
- full name and email address;
- job title and employer name;
- hashed account password, where the user registers via email and password;
- OAuth authentication tokens issued by Google or GitHub, where the user authenticates using the ‘Sign in with Google’ or ‘Sign in with GitHub’ options. BitAssert does not store the user’s Google or GitHub password — authentication is delegated to those providers under the OAuth 2.0/OIDC protocol;
- account administrator designation and role configuration within the Platform; and
- organisation name and project identifiers.
5.2Billing and Commercial Data
BitAssert has no payment gateway currently integrated into the Platform. When a payment mechanism is introduced, billing information will be collected and this Policy will be updated to reflect the applicable data flows and subprocessors.
5.3Platform Usage Data
In the course of operating the Platform, BitAssert automatically collects log data including IP addresses, browser type and version, operating system, session identifiers, pages accessed, and error reports; organisation and project usage metadata; and platform performance and telemetry data.
No third-party analytics platforms, error tracking tools, session replay tools, or advertising scripts are currently deployed. Usage data is collected only through native Platform logging.
5.4Customer Data Containing Personal Data
Customers may upload or generate Customer Data that incidentally contains personal data, including test scripts referencing personal data, screenshots of applications under test, video recordings of test sessions, and AI prompts submitted through the AI authoring interface.
BitAssert processes such Customer Data solely to provide the Platform. Customers are solely responsible for their legal basis to submit personal data and must use anonymised or synthetic data in test environments where possible.
5.5AI Feature Data
Where a Customer enables AI Features, the following data may be submitted for inference processing:
- natural-language prompts describing test scenarios submitted through the AI test authoring interface;
- application source code or source code fragments provided through the Local Agent;
- API endpoint definitions, parameter data, and JSON response schemas for expression generation; and
- test case step descriptions for AI-assisted authoring.
Data is submitted in raw or verbatim form to BitAssert’s third-party AI provider(s). All AI-generated test case outputs are assigned ‘in_review’ status in the Platform workflow and are not executed until the Customer reviews and approves them.
Inference location is confirmed: AI requests are sent to BitAssert’s third-party AI provider(s), each of which processes inference in the United States and stores associated data in the United States. Each AI request is therefore a cross-border transfer from India to the United States.
BitAssert’s AI providers do not use data submitted via their APIs to train or fine-tune their models by default, under each provider’s current commercial terms. BitAssert does not use Customer Data to train any AI model.
5.6Local Agent Data
The Local Agent runs in the Customer’s environment and reads the Customer’s application source code within the project folder the Customer selects, to support AI-assisted test authoring. As confirmed by BitAssert engineering, the Local Agent transmits no data to BitAssert’s cloud; it communicates with the BitAssert web application over a local loopback connection. The Local Agent does not read OS environment variables or credential stores and does not require root or administrator privileges in steady-state operation.
5.7Data Not Currently Collected
BitAssert confirms the following are not currently collected or deployed:
- cookies — no cookies are deployed on the BitAssert website or Platform application;
- third-party analytics or tracking scripts (Google Analytics, LinkedIn Insight Tag, Meta pixels, session replay tools);
- personal data of children below 18 years of age — the Platform is not directed at minors; and
- government-issued identification numbers, except where required for tax compliance.
6.Purposes of Processing and Lawful Basis
| Purpose | Personal Data | DPDP Act Basis | GDPR Basis (if applicable) |
|---|---|---|---|
| Account registration and management | Name, email, authentication token, job title | Consent; Contractual necessity | Performance of contract |
| Google / GitHub OAuth authentication | OAuth token, email, name from provider | Consent; Contractual necessity | Performance of contract |
| Platform operation and test execution | Usage data, session data, test metadata | Contractual necessity; Legitimate use | Performance of contract |
| AI Feature processing (third-party AI providers) | Prompts, source code, API schemas | Consent; Contractual necessity | Performance of contract; Legitimate interests |
| Customer support | Name, email, correspondence | Contractual necessity; Legitimate use | Performance of contract; Legitimate interests |
| Security monitoring and fraud prevention | Log data, IP addresses, access patterns | Legitimate use; Legal obligation | Legitimate interests; Legal obligation |
| Legal and regulatory compliance | As required by applicable law | Legal obligation | Legal obligation |
| Billing (when payment gateway implemented) | Name, billing address, GST number | Contractual necessity; Legal obligation | Performance of contract; Legal obligation |
8.Disclosure and Sharing of Personal Data
8.1Confirmed Subprocessors
As of the date of this Policy, BitAssert has confirmed the following third-party subprocessors. These are the only third-party services that process personal data on BitAssert’s behalf. No public cloud infrastructure provider, CDN, analytics platform, error tracking tool, CRM, or payment processor is currently engaged.
| Provider | Service | Location | Data Processed |
|---|---|---|---|
| Anthropic PBC | AI inference: API validation expression generation; AI test case authoring. Inference and storage in the United States. | United States | Prompts, source code fragments, API schemas submitted through AI Features |
| OpenAI, L.L.C. | AI inference: API validation expression generation; AI test case authoring. Inference and storage in the United States. | United States | Prompts, source code fragments, API schemas submitted through AI Features |
| Resend | Transactional email: account notifications, password resets, support communications. | Country of operation not yet confirmed. | Email address, name, email content |
8.2Law Enforcement and Regulatory Disclosure
BitAssert may disclose personal data to governmental authorities, courts, or law enforcement where required by applicable law, including CERT-In directions under the IT Act. BitAssert will limit such disclosures to what is strictly required and will notify affected individuals where legally permissible.
8.3Corporate Transactions
In the event of a merger, acquisition, restructuring, or asset sale, personal data may be transferred as part of that transaction. BitAssert will take reasonable steps to ensure that the acquiring entity provides privacy protections at least equivalent to those in this Policy.
8.4No Sale of Personal Data
BitAssert does not sell personal data to third parties for commercial or marketing purposes.
9.Information Security
9.1Infrastructure
The Platform is operated on BitAssert’s private cloud infrastructure in India. No public cloud providers are used for primary Customer Data hosting. Authentication uses industry-standard OAuth 2.0/OIDC protocols. Specific infrastructure and security architecture details are set out in the Security and Subprocessor Schedule.
9.2Security Measures
BitAssert maintains administrative, technical, and organisational measures that it considers commercially reasonable for the nature and scale of the Platform. Confirmed measures include role-based access within the Platform, encrypted transmission between the Local Agent and BitAssert’s cloud API, and network-based isolation of test execution infrastructure.
9.3Breach Notification
In the event of a personal data breach, BitAssert will comply with its notification obligations under the DPDP Act, including notification to the Data Protection Board of India and affected Data Principals as required by applicable law and Rules.
10.International Transfers of Personal Data
10.1Primary Hosting in India
All Customer Data is stored on BitAssert’s private cloud infrastructure in India. BitAssert does not currently offer data residency selection or multi-region hosting.
10.2Transfer via Backups
BitAssert takes daily backups which are stored outside India. This constitutes a cross-border transfer of personal data. The transfer is subject to appropriate safeguards and the backups are retained for 30 days and purged within 30 days following primary deletion.
10.3Transfer via Third-Party AI Providers for AI Feature Processing
Where AI Features are enabled, data including natural-language prompts, application source code, and API schemas is transmitted to BitAssert’s AI providers — currently Anthropic PBC and OpenAI, L.L.C. — for inference processing. This constitutes a transfer of data from India to the United States, processed under each provider’s Data Processing Addendum (incorporating the EU Standard Contractual Clauses).
The legal basis for this cross-border transfer under the DPDP Act is: (a) consent of the Data Principal through acceptance of this Policy and the applicable Terms of Service; and (b) contractual necessity in connection with providing AI-assisted testing services requested by the Customer.
A Data Processing Addendum is in place with each AI provider, automatically incorporated under that provider’s standard commercial terms. Each addendum establishes the provider as a processor under GDPR Article 28, prohibits use of API data for model training by default, and incorporates the EU Standard Contractual Clauses for international transfers. The cross-border transfer to the United States is, as at June 2026, lawful under the DPDP Act (no restricted-country notification under Section 16 is currently in force) and is supported by the SPDI Rules 2011 and each provider’s DPA.
10.4Transfer via Resend for Email Delivery
Transactional email is delivered by Resend, Inc., which processes and stores email data in the United States. This is a cross-border transfer governed by Resend’s Data Processing Addendum, which incorporates the EU Standard Contractual Clauses and aligns with the EU-U.S. Data Privacy Framework.
10.5Customers and Data Principals Outside India
BitAssert is established in India and currently serves customers in India, with active expansion into the United States, the European Union, the United Kingdom, Singapore, Australia, and Canada. Where BitAssert processes personal data of individuals located in these jurisdictions, additional data protection laws may apply, and BitAssert handles such data consistently with their core requirements:
- European Union / EEA (GDPR): BitAssert acts as a processor on behalf of its Customers for Customer Data. International transfers from the EEA to India or the United States are made under the European Commission’s Standard Contractual Clauses. EEA Data Subjects retain the rights of access, rectification, erasure, restriction, portability, and objection, and may lodge complaints with their local supervisory authority.
- United Kingdom (UK GDPR and Data Protection Act 2018): equivalent rights apply. Transfers from the UK are made under the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. UK Data Subjects may complain to the Information Commissioner’s Office (ICO).
- United States (CCPA/CPRA, where applicable): for California residents, BitAssert acts as a service provider and does not sell or share personal information. California residents may exercise rights of access, deletion, correction, and non-discrimination through the contacts in this Policy. BitAssert warrants that it will not sell, retain, use, or disclose personal information processed on a Customer’s behalf for any purpose other than providing the Services under the Customer’s agreement with BitAssert, and will not combine such personal information with personal information BitAssert receives from other sources, except as permitted by the CCPA/CPRA.
- Singapore (PDPA), Australia (Privacy Act), and Canada (PIPEDA): where these laws apply, BitAssert processes personal data consistently with their consent, purpose-limitation, access, and correction requirements.
In each case, the lawful basis for processing and any cross-border transfer is as set out in the Data Processing Agreement entered into with the relevant Customer. Where a conflict arises between this Policy and a Customer’s Data Processing Agreement, the Data Processing Agreement governs in respect of that Customer’s personal data.
11.Data Retention
11.1Retention by Subscription Plan
Test Artefacts are retained for the following periods by subscription plan:
| Subscription Plan | Default Retention — Test Artefacts |
|---|---|
| Standard Plan | 30 days from creation or last activity |
| Enterprise Plan | 180 days from creation or last activity |
| Custom Plan | As agreed in the applicable Order Form |
Test Artefacts subject to this tiered retention include: test scripts, test execution results and logs, screenshots, video recordings, HAR files, network traces, AI-generated outputs, and API request/response payloads.
11.2Account and Registration Data
Account and registration data is retained for as long as the Account is active and for a reasonable period thereafter for legal compliance, dispute resolution, and billing purposes.
11.3Activity Logs
User activity logs are currently subject to data loss on new platform deployments. A backup policy is under development. Until implemented, BitAssert cannot make retention commitments for user activity logs.
11.4Retention Schedule
| Data Category | Retention Period |
|---|---|
| Test Artefacts — Standard Plan | 30 days |
| Test Artefacts — Enterprise Plan | 180 days |
| Test Artefacts — Custom Plan | As agreed in Order Form |
| Account and registration data | Duration of active Account + reasonable compliance period |
| User activity logs | Backup policy under development |
| API credentials stored by Platform | Reasonable period after deletion by Customer |
| Billing and invoicing records | As required by applicable Indian tax and GST law |
| Backup copies | Backup policy under development |
| Support and communications records | 3 years from resolution |
11.5Customer Deletion
Customers may delete individual Test Artefacts at any time through the Platform’s built-in manual deletion function. Upon termination, BitAssert will make Customer Data available for export for 30 days and will delete primary data within 30 days thereafter, subject to backup purge timelines and legal hold obligations. Upon written request, BitAssert will issue a written Deletion Certificate confirming that Customer Data has been deleted from primary systems in accordance with the applicable Data Retention Schedule.
12.Rights of Data Principals
12.1Rights Under the DPDP Act
| Right | Description |
|---|---|
| Right to Access | Obtain confirmation of whether BitAssert processes your personal data and a summary of the categories and purposes of processing. |
| Right to Correction | Have inaccurate, incomplete, or out-of-date personal data corrected. |
| Right to Erasure | Have personal data erased where processing is no longer necessary, subject to applicable legal obligations. |
| Right to Grievance Redressal | Have grievances addressed by BitAssert’s Grievance Officer within 30 days of filing a valid grievance. |
| Right to Nominate | Nominate an individual to exercise your rights in the event of your death or incapacity. |
12.2Exercise of Rights
To exercise any right or to raise a grievance, contact:
- Grievance Officer
- Sudheer Kumar D
- Telephone
- [Mobile Number — To Be Confirmed]
- Postal Address
- BitAssert Software Private Limited, SY:11, WeWork Krishe Emerald, Laxmi Cyber City, Cyberabad, Shaikpet, Hyderabad 500081, Telangana, India
- Response Time
- Within 30 days of receipt
13.Artificial Intelligence and Automated Processing
13.1AI Features and Human Review
BitAssert integrates AI-assisted test authoring into the Platform. AI Features produce Generated Outputs — test scripts, validation expressions, and test step suggestions — that are presented to users for review. All AI-generated test cases are assigned an ‘in_review’ status in the Platform workflow and require human review and approval before execution. No AI-generated output is auto-executed.
13.2AI Model and Provider
| Feature | Provider | Model | Data Transmitted |
|---|---|---|---|
| API Validation Expression Generation | Anthropic PBC / OpenAI, L.L.C. | Model varies by provider and feature configuration | Prompt, API schema, parameter descriptions |
| AI Test Case Authoring | Anthropic PBC / OpenAI, L.L.C. | Model varies by provider and feature configuration | Natural language prompt, application source code |
13.3No Automated Decision-Making
BitAssert does not use automated decision-making processes that produce legal effects or similarly significant effects on individuals. All AI Features produce suggestions for Customer review. No binding decisions are taken autonomously.
13.4AI Output Limitations
AI-generated outputs may be incomplete, inaccurate, or require technical validation before use. BitAssert does not warrant the accuracy, completeness, or fitness for purpose of any AI-generated output.
14.Children’s Privacy
The Platform is directed at enterprise and commercial users. BitAssert does not knowingly collect personal data of individuals below 18 years of age. If BitAssert becomes aware of such collection, it will take steps to delete the data without undue delay.
15.Changes to This Policy
BitAssert may update this Policy to reflect changes in law, regulatory guidance, the Platform, or data processing practices. Where changes are material, BitAssert will provide at least 30 days’ notice through the Platform or by email to registered users, except where a shorter notice period is required by law.
16.Contact Information
- Grievance Officer (DPDP Act)
- Sudheer Kumar D — grievance@bitassert.com
- Legal and contractual notices
- legal@bitassert.com
- Technical support
- support@bitassert.com
- Security disclosures
- security@bitassert.com
- Abuse reports
- abuse@bitassert.com
- Registered address
- SY:11, WeWork Krishe Emerald, Laxmi Cyber City, Cyberabad, Shaikpet, Hyderabad 500081, Telangana, India
13.Automated Decision-Making and Profiling
13.1No Legally Significant Automated Decisions
BitAssert does not make automated decisions about individuals that produce legal effects or similarly significant effects on those individuals. All decisions affecting Platform users are made by human personnel. The AI Features integrated into the Platform are assistive tools that generate suggestions for Customer review — they do not make autonomous binding decisions about any individual.
13.2AI Features are Assistive Only
AI-generated test cases, validation expressions, and suggestions are assigned ‘in_review’ status within the Platform and require explicit Customer approval before execution. BitAssert does not apply AI Features to evaluate, score, rank, or make decisions about Platform users, Authorised Users, or Data Principals. AI Features are applied to software testing workflows and artefacts, not to personal data of individuals in a manner that produces automated decisions about those individuals.
13.3No Profiling for Significant Purposes
BitAssert does not profile Platform users for the purpose of evaluating personal aspects relating to their professional performance, economic situation, preferences, interests, reliability, behaviour, or location. Usage analytics and platform telemetry are used solely to improve Platform features and operational performance, and are not used to construct individual profiles for decision-making.
13.4Customer Automated Decision-Making
Where a Customer uses Customer Data in connection with its own automated decision-making or profiling activities, the Customer is solely responsible for ensuring compliance with applicable law, including any obligations under the DPDP Act or GDPR to inform affected individuals, provide human oversight, implement appropriate safeguards, or offer rights to contest automated decisions.
14.Grievance Redressal Process
14.1How to Submit a Grievance
Under the Digital Personal Data Protection Act, 2023, Data Principals have the right to have any grievance addressed by BitAssert’s Grievance Officer. To submit a grievance regarding BitAssert’s processing of personal data:
| Contact Method | Detail |
|---|---|
| Email (primary) | grievance@bitassert.com — monitored by Sudheer Kumar D, Grievance Officer |
| Postal Address | Attn: Grievance Officer, BitAssert Software Private Limited, SY:11, WeWork Krishe Emerald, Laxmi Cyber City, Cyberabad, Shaikpet, Hyderabad 500081, Telangana, India |
| Subject Line Guidance | Include ‘Privacy Grievance — [Your Name] — [Nature of Grievance]’ to ensure prompt routing to the Grievance Officer |
14.2Grievance Response Timeline
| Stage | Timeline | Action |
|---|---|---|
| Acknowledgement | Within 72 hours of receipt | BitAssert acknowledges receipt, assigns a grievance reference number, and confirms the resolution timeline. |
| Investigation | Within 10 business days of receipt | The Grievance Officer investigates the grievance, reviews relevant processing activities, and gathers information from internal teams. |
| Resolution | Within 30 days of receipt | BitAssert provides a written response addressing the substance of the grievance, the finding, and any action taken or proposed. This timeline is prescribed by the DPDP Act. |
| Further Escalation | If dissatisfied with the response | The Data Principal may refer the matter to the Data Protection Board of India (once constituted) or pursue other applicable legal remedies. |
14.3Data Protection Board of India
The Data Protection Board of India, established under the Digital Personal Data Protection Act, 2023, is the designated authority for adjudication of complaints under the Act. Once the Board is operationally constituted and complaint procedures are notified, Data Principals may lodge complaints directly with the Board if they are not satisfied with BitAssert’s response to a grievance. Information about the Board’s complaint procedures will be published on the Ministry of Electronics and Information Technology’s official website.
This document is effective June 2026. Questions about it go to legal@bitassert.com.
Read the Terms of Service