Privacy Policy
Privacy notice for the Prolter SaaS platform
01. Who We Are
This Privacy Policy explains how Prolter (“Prolter”, “we”, “us”, or “our”) collects, uses, stores, discloses, and protects personal data in connection with prolter.com and the Prolter Services.
Prolter is currently operated by Abhinay Sharma, an individual based in India. Prolter is hosted on OVHcloud infrastructure located in Germany. This hosting location may change in the future, subject to applicable law and this Privacy Policy.
02. Scope
This Policy applies to information collected through the Prolter website, account registration, application, customer support, billing, security systems, and related Services.
Customer Data submitted by a Prolter customer about its own clients, contractors, employees, or other individuals may be processed by Prolter on the customer’s instructions. In those circumstances, the customer may be responsible for providing privacy notices and handling individual rights, while Prolter provides assistance as required by applicable law and the applicable Data Processing Addendum (DPA).
03. Information We Collect
- Account information: Name, email address, authentication identifiers, workspace information, and account preferences.
- Billing information: Subscription, transaction, invoice, tax, and payment-status information. Payment-card details are handled directly by our payment provider (Dodo Payments) rather than stored by Prolter.
- Customer Data: Information that you or your authorized users choose to upload or store in Prolter, including client records, projects, tasks, assets, documents, notes, and Credentials.
- Security and activity data: Login events, authentication events, workspace actions, audit-log events, timestamps, IP address, device/browser information, and security-related telemetry where reasonably necessary.
- Support information: Communications, support requests, attachments, and information needed to resolve issues.
- Technical information: Server logs, diagnostic information, performance data, and information generated through use of the Services.
04. Credentials and Sensitive Information
Prolter may store Credentials such as passwords, API keys, tokens, usernames, hosting information, domain information, and similar sensitive information when you choose to use the Credential features.
Credentials are intended to be stored in encrypted form. When an authenticated and authorized user explicitly requests to reveal a stored Credential, the Service may decrypt the Credential server-side and transmit it to the authorized browser session to provide the requested functionality.
Prolter does not intentionally store Credentials in ordinary plaintext database fields. However, no security system can guarantee absolute protection against all threats.
You should not submit highly sensitive information that Prolter does not need to provide the Services, and you should not store information that you are not authorized to process.
05. How We Use Information
We process information only for legitimate operational and platform purposes:
- Provide, operate, maintain, and improve the Services;
- Authenticate users and enforce workspace permissions;
- Provide credential, client, project, task, asset, and team functionality requested by customers;
- Maintain activity and security logs;
- Detect, prevent, investigate, and respond to fraud, abuse, security incidents, and unauthorized access;
- Process subscriptions, billing, refunds, and payment-related support;
- Provide customer support and service communications;
- Comply with legal obligations and respond to lawful requests;
- Protect the rights, safety, security, and property of Prolter, customers, users, and third parties.
06. Legal Bases and Applicable Privacy Laws
Where laws such as the GDPR apply, Prolter may rely on legal bases including performance of a contract, compliance with legal obligations, legitimate interests, and consent where appropriate.
For processing subject to Indian data-protection law, Prolter will process personal data in accordance with applicable requirements, including applicable obligations under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as and when applicable to the relevant processing.
The applicable legal basis may differ depending on the nature of the data, the relationship with the individual, the customer’s role, and the purpose of processing.
07. Customer Data and Controller/Processor Roles
For information about your Prolter account and our own business operations, Prolter may act as a controller or data fiduciary as defined by applicable law.
For Customer Data that a business customer stores in Prolter for its own business purposes, Prolter may act as a processor, service provider, or similar role on behalf of that customer, depending on applicable law.
Where required, a separate Data Processing Addendum governs processing of Customer Data on behalf of a customer.
08. Service Providers and Subprocessors
We use selected third-party providers to operate the Services. These may include hosting/infrastructure, payment processing, email delivery, monitoring, analytics, authentication, security, and support providers.
Infrastructure: Prolter currently uses OVHcloud infrastructure hosted in Germany. OVHcloud states that EU-hosted services can be hosted within the EU and provides contractual data-processing arrangements for applicable services.
Payment Processing: Payment transactions may be processed by Dodo Payments or another payment provider. Such providers may process information under their own privacy policies and contractual terms.
09. Data Location and International Processing
Prolter is operated from India and currently hosts the primary application/database infrastructure in Germany. Depending on the service and provider, limited processing of account, support, security, or billing information may occur in other jurisdictions through service providers.
Where applicable law requires safeguards for international transfers, Prolter will implement appropriate measures required by that law.
10. Security
We use technical and organizational measures designed to protect personal data and Customer Data, including encrypted communications, access controls, authentication controls, logging, restricted administrative access, and encryption of sensitive stored data where applicable.
Security measures are reviewed and improved over time. No online service can guarantee absolute security. For more details, review our Security Overview.
11. Activity and Audit Logs
Prolter may record security, authentication, workspace, permission, asset, project, task, and other relevant activity events. These logs may include user identifiers, event type, affected entity, timestamps, IP or technical information, and other information reasonably necessary for security, auditing, troubleshooting, fraud prevention, and service operation.
Audit records may be retained for as long as reasonably necessary for security, legal, operational, and dispute-resolution purposes.
12. Data Retention
We retain personal data and Customer Data only for as long as reasonably necessary for the purposes described in this Policy, to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and maintain appropriate backups.
Retention periods may vary by data type. After the applicable period, data may be deleted or anonymized, subject to technical backup cycles and legal requirements.
13. Your Rights
Depending on where you live and the law that applies, you may have rights relating to access, correction, deletion, restriction, objection, portability, withdrawal of consent, or other privacy rights.
To make a privacy request, contact [email protected]. We may need to verify your identity before completing a request.
Where Customer Data is processed on behalf of a business customer, you may need to exercise certain rights through that customer, and Prolter may assist the customer as required by applicable law.
14. Children
The Services are intended for business and professional users and are not directed to children. Do not create an account or submit a child’s personal data unless you are legally authorized to do so and the processing is lawful.
15. Cookies and Similar Technologies
Prolter may use cookies, local storage, session technologies, and similar mechanisms that are necessary to authenticate users, maintain sessions, remember preferences, provide security, and measure or improve the Services. Where required, non-essential technologies will be used only with appropriate consent or another lawful basis.
16. Data Breach and Security Incidents
If Prolter becomes aware of a confirmed personal-data or security incident affecting Customer Data, we will investigate and take reasonable steps to contain and mitigate the incident and make notifications required by applicable law.
Where processing is performed on behalf of a customer, Prolter will cooperate with the customer as required under the applicable DPA and law.
17. No Sale of Customer Data
We never sell Customer Data as a business model.
We do not use Customer Data to build advertising profiles or sell customer credentials to third parties. We may use aggregated or anonymized information that no longer identifies an individual to understand service performance, security trends, and product usage, where permitted by law.
18. Changes to this Policy
We may update this Privacy Policy from time to time. We will post the updated version with a revised effective date and, where appropriate, provide additional notice of material changes.
19. Contact Information
For questions or privacy requests regarding this Privacy Policy, please contact us at: