Live Webinar | 26 June 2025 9AM PT
From Black Box to Boardroom: Operationalizing Trust in AI Governance

Privacy Policy

This privacy policy (“Policy”) applies to Riversys Technologies Pvt Ltd along with its affiliates Scrut Automation Inc herein called as Scrut Automation and was last updated February 2025. We may change or update this policy at any time, and the same will be updated here.

If you are a Scrut Automation user or customer, we shall notify the changes or updates either by sending an email or a notification on the Scrut Automation App (as defined below). Please ensure to read such notices carefully.

We sincerely believe that you should always know what data we collect from you, the purposes for which such data is used, and that you should have the ability to make informed decisions about what you want to share with us.

Therefore, we want to be transparent about:
(i) how and why we collect, store and use your personal data in the various capacities in which you interact with us; and
(ii) the rights that you have to determine the contours of this interaction.

While we would strongly advise you to read the Policy in full, the following summary will give you a snapshot of the salient points covered herein:

This Policy details the critical aspects governing your personal data relationship with Riversys Technologies Private limited, having its registered office at 302, Plot No 15, 3rd Floor, Kumar Tower, Wazirpur Industrial Area, Delhi North-West, 110052, and its subsidiary, Scrut Automation, Inc., a company incorporated under the laws of United States of America, and having its registered office at 691 S Milpitas Blvd, Suite 217, Milpitas, CA 95035 USA (collectively, Scrut Automation);

Your personal data relationship with Scrut Automation varies based on the capacity in which you interact with us/avail of our products and solutions (“Services”). You could be: (i) a visitor to https://www.scrut.io/  (“Website”) or any pages thereof (“Visitor”); (ii) a person/entity availing of one of our Services (“Customer”); or (iii) an employee/agent/representative/appointee of a customer who uses the said Service (“User”);

Based on whether you are a Visitor, Customer or User, the type of data we collect and the purpose for which we use it will differ and this Policy details such variations;

This Policy is a part of and should be read in conjunction with our https://www.scrut.io/terms-of-use ; and

This Policy will clarify the rights available to you vis-à-vis the personal data you share with us.

If you have any queries or concerns with this Policy, please contact our Grievance Officer (refer Section 12). If you do not agree with the Policy, we would advise you to not visit/use the Website or the Scrut Automation application(s)/platform(s) (collectively “App”).

TYPE OF USER VISITOR CUSTOMER USER
WHAT DATA WE MAY COLLECT 1. Your location;

2. How you behave on the Website, (what pages you land on, how much time you spend, etc.);

3. What device you use to access the Website and its details (model, operating system, etc.);

4. Cookies and Web Beacon data

5. Name; and e-mail.
1. The name and e-mail of your representative who signs up for a Service on your behalf; and

2. Credit Card/ Debit Card/Other Payment Mode information to check your financial qualifications, detect fraud and facilitate payments for our Services.
1. Your name, e-mail;

2. How you behave in the relevant product environment and use the features;

3. What device you use to access the Website/App and its details (model, operating system, etc.);

4. Cookies and Web Beacon data;
HOW AND WHY, WE USE IT We use this information to analyse and identify your behaviour and enhance the interactions you have with the Website.

If you submit your details and give us your consent, we may send you newsletters and e-mails to market other products and services we may provide.
We collect this data in order to help you register for and facilitate provision of our Services.

We also use this data to enable you to make payments for our Services. We use a third-party service provider to manage payment processing. This service provider is not permitted to store, retain, or use information you provide except for the sole purpose of payment processing on our behalf.

If you give us your consent, we may send you newsletters and e-mails to market other products and services we may provide.
We collect this data in order to facilitate provision of our Services.

We will occasionally send you e-mails regarding changes or updates to the Service that you are using. In the event you report an issue with a Service, we may also screen/video record your device only when you use the App for a limited time period to help us better understand how to address the issue.

If you give us your consent, we may send you newsletters and e-mails to market other products and services we may provide.

Information transferred via the Google API: Scrut’s use and transfer of information received from Google API’s to any other app will adhere to Google API Services User Data Policy, including Limited Use requirements.

FOR THE AVOIDANCE OF ANY DOUBT, WE SHOULD CLARIFY THAT IN THE EVENT WE ANONYMIZE AND AGGREGATE INFORMATION COLLECTED FROM YOU, WE WILL BE ENTITLED TO USE SUCH ANONYMIZED DATA FREELY, WITHOUT ANY RESTRICTIONS OTHER THAN THOSE SET OUT UNDER APPLICABLE LAW.

Where such data is not being used by us to render Services to you, we shall explicitly seek your consent for using the same. You can choose to withdraw this consent at any time, here.

Scrut Automation uses artificial intelligence (AI) to enhance the services we provide, ensuring that customer data is processed accurately, efficiently, and securely. All AI-driven data processing is performed with a strong commitment to safeguarding customer privacy. We implement strict access controls, encryption, and regular audits to prevent unauthorized access to, or misuse of, your information. Our AI models are trained only on data necessary to deliver our services, and we adhere to industry best practices to anonymize and aggregate data wherever possible to protect customer identities.

We do not use customer data to train external models or for any purpose beyond the agreed-upon scope of our services. Any personal data processed by our AI systems is handled in compliance with applicable data protection laws, including GDPR and CCPA where relevant.

YOUR RIGHTS & PREFERENCES AS A DATA SUBJECTSubject to the GDPR and applicable law’s limitations, the rights afforded to you as a data subject are:

  1. RIGHT TO BE INFORMED : You have a right to be informed about the manner in which any of your personal data is collected or used which we have endeavored to do by way of this Policy.

  2. RIGHT OF ACCESS : You have a right to access the personal data you have provided by requesting us to provide you with the same.

  3. RIGHT TO RECTIFICATION : You have a right to request us to amend or update your personal data if it is inaccurate or incomplete.

  4. RIGHT TO ERASURE : You have a right to request us to delete your personal data.

  5. RIGHT TO RESTRICT : You have a right to request us to temporarily or permanently stop processing all or some of your personal data.

  6. RIGHT TO OBJECT : You have a right, at any time, to object to our processing of your personal data under certain circumstances. You have an absolute right to object to us processing your personal data for the purposes of direct marketing.

  7. RIGHT TO DATA PORTABILITY : You have a right to request us to provide you with a copy of your personal data in electronic format and you can transmit that personal data for using another third-party’s product/service.

  8. RIGHT NOT TO BE SUBJECT TO AUTOMATED DECISION-MAKING : You have a right to not be subject to a decision based solely on automated decision making, including profiling.

In case you want to exercise the rights set out above you can contact our Grievance Officer whose details are set out in Section 12 below.

The data provided by you as a Visitor, or when you sign up as a Customer / User or register for our Services will be processed by us for the purpose of rendering Services to you or in order to take steps prior to rendering such Services, at your request. Where such data is not being used by us to render Services to you, we shall explicitly seek your consent for using the same. You can choose to withdraw this consent at any time here.

Additionally, we may process your data to serve legitimate interests.

Accordingly, the grounds on which we can engage in processing are as follows:

NATURE OF DATA GROUNDS
Visitor Data
  • Consent;
  • Performance of a Contract; and
  • Legitimate Interest
  • Performance of a Contract; and
  • Legitimate Interest
Account Registration Data
  • Compliance with applicable laws;
  • Legitimate Interest
Service Usage Data
  • Performance of a Contract; and
  • Legitimate Interest
Data for Marketing our Services
  • Consent; and
  • Legitimate Interest

If you believe we have used your personal data in violation of the rights above or have not responded to your objections, you may lodge a complaint with your local supervisory authority.

Additionally, please note:

  • If you are a Customer/User using one of our Services to collect data about an EU data subject from third parties, it shall be your sole obligation to inform such data subject about the source of such data; and

  • We do not collect any Special Categories of Personal Data. Further, if you are a Customer/User, you hereby agree and acknowledge that you shall not, under any circumstances, whether directly or indirectly, use our Services to collect or process Special Categories of Personal Data or transfer to us any such data.

  • The term “Special Categories of Personal Data” shall have the meaning ascribed to it under the GDPR and shall include, without limitation, data pertaining to a data subject’s race, ethnic origin, genetics, political affiliations, biometrics, health or sexual orientation.

YOUR RIGHTS UNDER CALIFORNIA CONSUMER PRIVACY ACT (CCPA)

Scrut Automation complies with CCPA by giving you the five privacy rights for California consumers:

  1. The right to know about the personal information a business collects about them and how it is used and shared

  2. You have a right to be informed about the manner in which any of your personal data is collected or used which we have endeavored to do by way of this Policy.

  3. The right to delete personal information collected from them.

  4. Scrut Automation gives you the right to request us to delete your personal data.

  5. The right to opt-out of the sale of their personal information.

  6. The right to non-discrimination for exercising their CCPA rights.

Scrut Automation does not sell any data of any of its users/customers/leads. Scrut Automation assures no discrimination against consumers exercising their right of privacy under CCPA.

Scrut Automation assures that it will not ask for waiver of privacy rights from California consumers. In case you want to exercise the rights set out above you can contact our Grievance Officer whose details are set out in Section 12 below.

YOUR RIGHTS UNDER INFORMATION TECHNOLOGY (REASONABLE SECURITY PRACTICES AND PROCEDURES AND SENSITIVE PERSONAL DATA OR INFORMATION) RULES, 2011

Scrut Automation adheres to the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules) to ensure your data is secure. Here’s how Scrut Automation complies with the SPDI Rules:

Right Description
The right to be informed and give consent Before Scrut Automation collects any of your personal data, we will clearly explain what information we need, why we need it, and how we will use it. We will only collect your personal data with your explicit consent.
The right to access your data You have the right to request access to the personal information Scrut Automation holds about you. This includes the ability to review and verify its accuracy and completeness.
The right to correct mistakes If you find any errors or missing information in your data held by Scrut Automation, you have the right to request corrections. We will take reasonable steps to update your information promptly upon verification of your request.
The right to withdraw consent You can withdraw your consent for Scrut Automation to process your sensitive personal data at any time. Once you withdraw consent, we will stop using your data for the purpose originally agreed upon, unless there’s a legal reason for continued processing (like a court order). To withdraw consent, please click (here)

Please contact our Grievance Officer, whose details are presented in Section 12, if you would like to exercise the rights listed above.

RETENTION OF PERSONAL INFORMATION

We will store any personal data we collect from you as long as it is necessary in order to facilitate your use of the Services and for ancillary legitimate and essential business purposes – these include, without limitation, for improving our Services, attending to technical issues, and dealing with disputes.

We may need to retain your personal data even if you seek deletion thereof, if it is needed to comply with our legal obligations, resolve disputes and enforce our agreements.

If you are a customer, please be advised that: (i) you will need to inform your Leads about how you store and deal with any data you collect from them using one of our Services, in compliance with applicable laws including the GDPR; and (ii) after you terminate your usage of a Service, we may, unless legally prohibited, delete all data provided or collected by you from our servers.

TOOLS USED BY OUR CUSTOMERS

If you are a Customer, you are empowered to use proprietary or other third party technologies and integrate with our App. If you do, you agree and acknowledge that it is your sole obligation to inform your stakeholders about any data you collect by using such technologies and the policies by which such collection is bound.

TRANSFER OF INFORMATION

In order for us to facilitate our operations, we may transfer and store the data we collect and process in accordance with this Policy, to our database server in a third-country for Disaster Recovery purpose. Your rights and protections will, under no circumstances, be diluted by this transfer.

Further, in the ordinary course of business, we may employ other companies and people to assist us in providing certain components of our Services in compliance with the provisions of this Policy. To do so, we may need to share your data with them.

Where applicable – if the entities to which these transfers are affected are not situated in countries deemed ‘adequate’ by the European Commission, we shall enter into appropriate Data Protection Addendums with the transferee parties that comprehensively protect your data. We shall also put in place industry-standard technical and organizational measures (including robust data handling policies) to ensure that such transfers are completed in accordance with applicable laws.

Some of the examples of where we may sub-contract processing activities to third parties include—data analysis, marketing assistance, processing credit card payments, and providing customer service.

COMPELLED DISCLOSURE

In addition to the purposes set out in the Policy, we may disclose any data we collected or processed from you if it is required:

  • Under applicable law or to respond to a legal process, such as a search warrant, court order, or subpoena;

  • To protect our safety, your safety or the safety of others or in the legitimate interest of any party in the context of national security, law enforcement, litigation, criminal investigation or to prevent death or imminent bodily harm;

  • If required in connection with legal proceedings brought against Scrut Automation, its officers, employees, affiliates, customers or vendors; or

  • To establish, exercise, protect, defend and enforce our legal rights.

SECURITY OF YOUR PERSONAL INFORMATION

We implement industry-standard technical and organizational measures by using a variety of security technologies and procedures to help protect your data from unauthorized access, use, loss, destruction or disclosure. When we collect particularly sensitive data it is encrypted using industry-standard cryptographic techniques including but not limited to SSL, TLS, RSA, and AES.

We adhere to the ISO/IEC 27001:2022 standard, an internationally recognized framework for Information Security Management Systems (ISMS). Our commitment to ISO 27001 ensures that we follow rigorous security practices and maintain high standards for information security.

In compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, we adhere to the following reasonable security practices and procedures to protect your personal data:

Measure Description
Access Control We ensure that access to personal data is granted only to authorized personnel on a need-to-know basis and that such access is logged and monitored.
Data Encryption Sensitive personal data is encrypted both in transit and at rest using strong encryption methods such as AES-256.
Network Security We employ secure network architecture, including firewalls and intrusion detection systems, to prevent unauthorized access.
Regular Audits We conduct regular security audits and assessments to identify potential vulnerabilities and ensure compliance with our security policies.
Incident Management We have established protocols for managing and responding to security incidents, including data breaches, to mitigate any potential impact on your personal data.
Employee Training We conduct regular training programs for our employees to ensure they are aware of and comply with our security policies and procedures.
Third-Party Compliance We ensure that any third-party service providers who handle personal data on our behalf adhere to equivalent security standards and practices.
Physical and Environmental Security We have implemented robust physical security controls to protect our data centers and other facilities from unauthorized access, damage, and interference.
Business Continuity Management We have developed and tested business continuity plans to ensure the availability of critical information and systems in the event of a disruption.
Risk Assessment and Treatment We conduct regular risk assessments to identify potential security threats and vulnerabilities, and implement appropriate risk treatment plans to mitigate identified risks.
Audit and Compliance We conduct regular internal and external audits to ensure compliance with ISO 27001 standards and continuously improve our ISMS.

GRIEVANCE OFFICER

The name and contact details of our Grievance Officer, who you may contact if you have any concerns, complaints or feedback pertaining to this Policy, are as follows:

ADDRESS: Scrut Automation, Indiqube Ascent
420, Mahakavi Vemana Road, KHB Block Koramangala, Koramangala 4-B Block, 5th Block,
Koramangala, Bengaluru, Karnataka 560034
EMAIL: privacy@scrut.io

Ready to see what security-first GRC really looks like?

Ready to see what security-first GRC really looks like?

Ready to see what security-first GRC really looks like?

See what a real security- first GRC platform looks like

Ready to see what security-first GRC really looks like?

Focus on the traveler experience. We’ll handle the regulations.

Achieve and maintain compliance without the busywork.

Choose risk-first compliance that’s always on, built for you, and never in your way.

Ready to see what security-first GRC
One platform, every framework. No more duplicate work.
You can’t manage user access if you’re always playing catch-up.
Explore the future of enterprise GRC
Tired of chasing vendors for risk assessments?

Join the thousands of companies automating their compliance with Scrut.

The right partner makes all the difference. Let’s grow together.

Make your business easy to trust, put security transparency front and center.

Risk-first security starts with risk-first visibility.
Secure your team from the inside out.
Don't settle for slow, expensive compliance. Get Scrut instead.
Risk-first compliance for forward-thinking teams.
Audits without the back-and-forth. Just seamless collaboration.
Scale fast. Stay compliant. Automate the rest.
Compliance? Done and dusted, in half the time.
Get ahead of GDPR compliance before it becomes a problem.
Outgrowing table-stakes compliance? Create custom frameworks with ease.
Navigate SOC 2 compliance, minus the stress.
PCI DSS compliance, minus the panic.
Take the wheel of your HIPAA certification journey today.
We’ve got what you need to fast-track your ISO 27001 certification.
Make your NIST AI RMF journey as smooth as possible.

Your GRC team, multiplied and AI-backed.

Modern compliance for the evolving education landscape.

Ready to simplify healthcare compliance?

Don’t let compliance turn into a bottleneck in your SaaS growth.

Find the right compliance frameworks for your business in minutes

Ready to see what security-first GRC really looks like?

Real-time visibility into every asset

Ready to simplify fintech compliance?

The Scrut Platform helps you move fast, stay compliant, and build securely from the start.

Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.

Scrut helps you streamline audits, close deals faster, and stay ahead of risk without slowing down your team. Because trust shouldn’t take months to earn.

Scrut helps you set up a security program that scales with your business and stands up to audits. Without last-minute chaos.

Tag, classify, and monitor assets in real time—without the manual overhead.

Whether you're entering new markets or launching new products, Scrut helps you stay compliant without slowing down.

Scrut pulls compliance data straight from the tools you already use—so you don’t have to dig for evidence, chase approvals, or manually track controls.

Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.

With Scrut, you’re not just adding a tool to your offering—you’re adding a competitive edge. Join our Partner Network and help your clients streamline their GRC program.

Gaining trust is your first step to growing and cracking better deals. The Scrut Platform comes pre-built with all the tools you need to showcase a firm security posture and build confidence.

Don’t settle for rigid systems—Scrut ensures your risk management strategy is as flexible as your business needs.

Start building a security-first culture. Save your operations from improper training and a lack of compliance awareness.

Scrut fast-tracks compliance so you can focus on scaling, not scrambling. Automate compliance tasks and accelerate enterprise deals—without the grind.

Automate assessments, track compliance, and get full visibility into third-party risk—all in one place.

Scrut automates compliance tasks, supports proactive risk management, and saves you time, so you can focus on growing your business. Start building trust with customers and scaling confidently.

Leave legacy GRC behind. Meet the AI-powered platform built for teams managing risk and compliance in real time.

Give auditors direct access, keep track of every request, and manage audits effortlessly—all in one place.

Scrut ensures access permissions are correct, up-to-date, and fully compliant.

Whether you need fast results or a fully tailored program mapped to your risks and needs, Scrut delivers exactly what you need, when you need it. Ready to start?

Scrut unifies compliance across all your frameworks, so you can stop juggling systems and start scaling securely.

Manually managing your compliance processes and audits can get inefficient and overwhelming. Scrut automates these outdated, manual processes and eliminates your last-minute worries.

Access automated compliance, real-time risk tracking, and expert-backed support—all in one platform. Get started with Scrut!

Less manual work, more customizability. The Scrut Platform gives you everything you need to align your compliance to your business’s priorities.

The Scrut Platform helps you move fast, stay compliant, and build securely from the start.

Earn trust and back it up with solid evidence. Scrut takes you through the SOC 2 compliance journey step-by-step, navigating every complexity you face.

Manage your PCI DSS compliance with real-time monitoring and effortless automation. Get started with Scrut today!

Securing your PHI shouldn’t be a constant hassle. Scrut automates your workflows—from risk assessments to monitoring—so you can put your compliance worries on the back burner.

Automate security controls, simplify audits, and keep your ISMS aligned with the latest standards. Get started with Scrut!

Tackle potential AI risks with NIST AI RMF-compliant controls and get expert support every step of the way.

Offload the grunt compliance work to us. Execute manual, draining GRC tasks with the reliable AI-powered Scrut Teammates without switching contexts or bottlenecks.

Whether you're managing student data, partnering with educational institute, or expanding to new geographies—Scrut gives you the tools to stay compliant, manage risk, and build trust at every step.

Scaling healthcare doesn’t have to come at the cost of security. Scrut keeps your organization compliant, audit-ready, and protected—no matter how fast you grow.

Scrut automates the hard parts of compliance and security so you can move fast and stay ahead of risks from day one.

The Scrut Platform helps you move fast, stay compliant, and build securely from the start.

Growth in fintech comes with heavy scrutiny. Scrut helps you stay compliant, audit-ready, and secure—without slowing down your momentum.

Book a Demo
Book a Demo
Join the Scrut Partner Network
Join the Scrut Partner Network