Last updated: August 27, 2026
Innovly Private Limited (“we,” “our,” or “the Company”) provides the DLP Secure platform (the “Service”). This Privacy Policy explains how we collect, use, disclose, and protect personal information when you visit our website, use our platform, or engage with our services.
By accessing or using DLP Secure, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
When your organization deploys DLP Secure, our Agent — installed on endpoint devices, with system access — monitors data-transfer activity across the channels enabled in your organization’s policy.
How this data is handled depends on the detection mode your organization has configured:
Cloud-Based Detection: where enabled by your organization, relevant file or communications content is transmitted via an encrypted connection to our servers, where our AI content-classification engine evaluates it against your organization’s configured sensitive-data categories (for example, personal, financial, or health information, or source code). The classification result — together with a record of the detection event (timestamp, device, channel, rule triggered, action taken) — is stored in our database for reporting and audit purposes.
Local Processing: by default, detection occurs entirely on the endpoint device using a local model. File and communications content are analyzed on-device and are not transmitted to our servers in this mode. Only policy-violation alerts or summary metadata, without underlying content, may sync to your organization’s management dashboard, if configured.
Your organization controls which channels are monitored and which detection mode applies, and acts as the data controller (data fiduciary, under Indian law) for its personnel’s data collected through the Service. We process this data as a data processor, on your organization’s instructions.
We do not sell your personal information. We may share data with:
We implement industry-standard security measures, including encryption in transit (TLS 1.2+) — including on the connection between the Agent and our servers — encryption at rest (AES-256), access controls, audit logging, and regular security assessments. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Depending on your jurisdiction, you may have the right to:
If you are an employee or other personnel of an organization using DLP Secure, and you have questions about data collected about you through a monitored device, please contact your organization directly in the first instance, since it controls the Service’s configuration and monitoring policies. We support our enterprise customers in responding to such requests as required by applicable law.
To exercise these rights with respect to your own account, billing, or support data, contact us at contact@innovly.co.
Where applicable law requires it, we take steps to safeguard personal data transferred across borders. For data subject to India’s Digital Personal Data Protection Act, 2023 and its Rules of 2025, cross-border transfer is generally permitted except to countries or territories the Central Government restricts by notification; we will comply with any such restrictions once notified. If you or your personnel are located outside India, other data protection frameworks (such as the GDPR) may also apply to your data; where they do, we rely on mechanisms such as standard contractual clauses as appropriate.
DLP Secure is not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child, we will take steps to delete it promptly.
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on our website and updating the “Last updated” date. Your continued use of the Service constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or our data practices, please contact us: