Privacy Policy
Device Health Diagnostics & Certification Software
- Introduction
- Data Fiduciary Details
- Design Principles
- Information We Collect
- What We Do Not Collect
- How We Use Information
- Consent
- Notice to Data Principals
- Software Permissions
- Data Storage & Security
- Sharing of Data
- Data Retention & Deletion
- Rights of Data Principals
- Children's Privacy
- Third-Party Services
- Applicable Laws
- Grievance Redressal
- Policy Changes
- Contact Us
Introduction
PRAMAAN is a hardware diagnostics and device health testing software developed and operated by Gadget Guruz Technologies Pvt Ltd ("Company", "we", "our", "us"). PRAMAAN is designed to evaluate the performance, stability, and lifecycle health of electronic devices — including laptops, desktops, and other hardware — and to generate verified device health reports and QC certificates.
This Privacy Policy explains how we collect, use, store, disclose, and protect information when you install, access, or use:
- The PRAMAAN desktop application
- The PRAMAAN website at pramaan.gadgetguruz.com
- The PRAMAAN enterprise dashboard and reporting portal
- Any PRAMAAN APIs, integrations, or related services (collectively, the "Service")
This Policy applies to all categories of users:
- Individual users running diagnostics on their own devices
- Technicians using PRAMAAN for device testing before and after repair
- Enterprises and IT administrators using PRAMAAN for asset health monitoring
- Refurbishers and recyclers using PRAMAAN for device certification before resale or disposal
- Insurance providers using PRAMAAN health scores for device risk classification
- Visitors to the PRAMAAN website or dashboard portals
Data Fiduciary Details
As per Section 2(i) of the DPDP Act, 2023, Gadget Guruz Technologies Pvt Ltd is the Data Fiduciary for all personal and diagnostic data processed through PRAMAAN.
What PRAMAAN Does — Design Principles
PRAMAAN is built on a principle of minimal data collection. It is a hardware diagnostic tool — not a surveillance tool, monitoring tool, or data harvesting platform. Its sole function is to assess the physical health of a device's hardware components and generate a standardised, verifiable health report.
Every permission that PRAMAAN requests from your operating system is used exclusively for hardware diagnostics. See Section 9 for a full list of permissions and the specific reason each is required.
Information We Collect
4.1 Account & Registration Data
When you create a PRAMAAN account or purchase a license, we collect:
| Data Point | Purpose |
|---|---|
| Full name | Account identification and license assignment |
| Company or organisation name | Enterprise license management and reporting |
| Phone number | Account verification and support contact |
| Email address | License delivery, account notifications, support |
| Password (cryptographic hash only) | Secure account authentication — never stored in plain text |
| Purchase details | License issuance, billing reconciliation, and support |
4.2 Device Diagnostic Data
When PRAMAAN runs a diagnostic scan, it collects the following hardware-level data:
| Component | Data Collected | Why It Is Needed |
|---|---|---|
| CPU | Model, clock speed, core count, usage under load, stress scores, thermal throttling | Evaluate processing performance and stability |
| RAM / Memory | Capacity, usage, health indicators, error rate | Assess memory integrity and detect degradation |
| Storage (HDD/SSD) | SMART attributes: sector health, error rates, remaining life, temperature | Evaluate storage reliability and predict failure risk |
| Battery (laptops) | Design vs. current capacity, cycle count, charge/discharge rate, health % | Determine battery health and remaining useful life |
| Thermal System | CPU temp at idle and load, fan speed, throttling events | Assess cooling efficiency and stability |
| Display | Dead pixels, backlight consistency (where applicable) | Identify display hardware defects |
| Network Interface | Adapter status, connection capability test | Confirm network hardware is functional |
| Sensors & Peripherals | Camera/mic hardware presence check (no recording), USB/port status | Verify hardware components are detectable |
| System Configuration | Device model, manufacturer, OS version, firmware/BIOS, serial number | Associate results with the correct device |
4.3 Usage & Performance Data
- Test timestamps and diagnostic session durations
- Feature usage statistics (e.g. which diagnostic modules were run)
- Crash reports and error logs, including software version and failure nature
- Diagnostic model performance metrics
This data is collected in aggregated or pseudonymised form where possible and used solely for improving PRAMAAN's diagnostic accuracy and software stability. It is never used for advertising or sold to third parties.
4.4 Enterprise Asset Data
For enterprise deployments, PRAMAAN may collect and maintain: device inventory, diagnostic history per device, component change logs, repair history records, and lifecycle analytics. This data is visible only to authorised administrators within the customer organisation.
4.5 Certification & Report Data
Each completed diagnostic generates a permanent, verifiable record: a device health score, a detailed QC report, a unique Certificate ID, a verification QR code, and the test timestamp and PRAMAAN version used.
What PRAMAAN Does Not Collect
| Data Type | Why PRAMAAN Does Not Need It |
|---|---|
| Personal files, documents, PDFs | Irrelevant to hardware diagnostics |
| Photos, videos, or audio recordings | Camera/mic tests are hardware presence checks only — no recording occurs |
| Emails, messages, or chat history | Irrelevant to hardware diagnostics |
| Browser history or internet activity | Network tests check adapter functionality only — not traffic content |
| Contact lists or address books | Irrelevant to hardware diagnostics |
| Passwords, PINs, or credentials | PRAMAAN does not interact with authentication systems |
| Financial information or banking data | Payments are handled separately at purchase |
| Precise real-time geolocation | Device location is not relevant to hardware health assessment |
| User activity or behaviour | PRAMAAN is not a monitoring or surveillance tool |
| Data from users under 18 without consent | PRAMAAN is not intended for use by minors |
How We Use the Information — Purpose Limitation
In accordance with Section 4 of the DPDP Act, 2023, all data collected by PRAMAAN is used only for the specific purposes stated below.
| Purpose | Data Used |
|---|---|
| Device health scoring and QC certification | Hardware diagnostic data, system configuration data |
| Generating QC reports and certificates | All diagnostic data, device identifiers, test timestamps |
| IT asset lifecycle management | Enterprise asset data, diagnostic history, component change logs |
| Resale and buyback value estimation | Hardware health scores, battery status, storage SMART data |
| Insurance device risk classification | Overall health score, component health breakdown |
| Fraud prevention in refurbished device markets | Component change logs, hardware configuration history |
| Account management and license issuance | Registration data, purchase details |
| Customer support and troubleshooting | Registration data, crash logs, diagnostic session data |
| Software diagnostic model improvement | Anonymised/aggregated usage and performance telemetry |
| Legal compliance and regulatory obligations | Minimum data necessary as required by applicable law |
Consent (Section 6, DPDP Act 2023)
We process your data only on the basis of free, specific, informed, unconditional, and unambiguous consent, as required by Section 6 of the DPDP Act, 2023.
7.1 How Consent Is Obtained
- A dedicated consent screen is displayed during PRAMAAN installation, before any diagnostic data is collected or transmitted
- At first launch, you are presented with a clear notice of what data will be collected and for what purpose, and asked to provide explicit consent before proceeding
- Consent is not bundled with general terms and conditions — each distinct processing purpose is presented separately
- For enterprise deployments, the enterprise administrator is responsible for ensuring device users are informed of and have consented to the use of PRAMAAN diagnostics
7.2 Withdrawing Consent
You may withdraw consent at any time without affecting the lawfulness of prior processing. To withdraw consent:
- Uninstall PRAMAAN from your device (this terminates all future data collection from that device)
- Submit a data deletion request to [email protected]
- Enterprise administrators may contact their PRAMAAN account manager or email [email protected]
Notice to Data Principals (Section 5, DPDP Act 2023)
Before or at the time of collecting your data, PRAMAAN provides a clear Notice that includes:
- The categories of data being collected
- The specific purpose for which each category is collected
- The identity and contact details of the Data Fiduciary and Grievance Officer
- Any third parties with whom data may be shared
- Your rights as a Data Principal and how to exercise them
- The data retention period applicable to your data
This Notice is presented as a mandatory consent screen at installation and at first launch, and is also incorporated into the PRAMAAN EULA, available at pramaan.gadgetguruz.com/eula.php.
Software Permissions
To perform hardware diagnostics, PRAMAAN requires certain system-level permissions. Below is a complete, transparent list of every permission required and the specific reason it is needed.
| Permission | What PRAMAAN Accesses | What PRAMAAN Does NOT Do |
|---|---|---|
| System hardware access | CPU model, clock speed, core metrics, load under stress | Does not read files or user data stored on the CPU cache |
| Memory (RAM) access | RAM capacity, usage statistics, error indicators | Does not read the content of memory (running processes, open documents) |
| Storage health monitoring | Drive SMART attributes: sector health, error rates, temperature | Does not read, copy, or scan the content of any file on the drive |
| Battery & power access | Battery design vs. current capacity, cycle count, charge rate | Does not control or modify battery charging behaviour |
| Thermal sensor access | CPU and system temperature readings, fan speed | Does not modify thermal settings or fan control |
| Network interface access | Adapter presence and connectivity status | Does not monitor network traffic, websites visited, or data transmitted |
| Display diagnostics | Screen resolution, display hardware status | Does not capture screenshots or record screen content |
| Camera hardware check | Detects whether a camera device is present and functional | Does not capture images, video, or activate the camera in any recording capacity |
| Microphone hardware check | Detects whether a microphone device is present and functional | Does not record audio or activate the microphone in any recording capacity |
| USB/Port status | Connected port types, port health | Does not read data from connected USB devices or peripherals |
| System identifier | Device model, OS version, BIOS/firmware version, serial number | Does not use the identifier for tracking beyond associating with the device's own health records |
Data Storage and Security (Section 8, DPDP Act 2023)
We implement appropriate technical, administrative, and organisational safeguards to protect your data. Our security measures include:
- TLS/HTTPS encryption for all data transmitted between PRAMAAN and our servers
- Encryption of stored data at rest using industry-standard algorithms
- Passwords stored as one-way cryptographic hashes — never in recoverable plain text
- Role-based access controls ensuring only authorised personnel can access data
- Multi-factor authentication for enterprise dashboard access
- Secure server infrastructure on enterprise-grade cloud providers
- Regular security audits, vulnerability assessments, and penetration testing
- Contractual data protection obligations imposed on all third-party sub-processors
In the event of a personal data breach likely to result in a risk to your rights and interests, we will notify the Data Protection Board of India and affected Data Principals within the timelines prescribed under the DPDP Act, 2023.
Sharing of Data
We do not sell, rent, or trade your personal or diagnostic data. Data is shared only in the following specific and limited circumstances:
11.1 Enterprise Administrators
For enterprise deployments, device diagnostic data is shared with authorised enterprise administrators as contracted, governed by the PRAMAAN Enterprise License Agreement and a Data Processing Addendum (DPA).
11.2 Service Providers & Sub-Processors
We engage trusted third-party vendors for cloud infrastructure, software hosting, customer support tools, and analytics. All sub-processors are bound by Data Processing Agreements requiring DPDP-equivalent data protection standards.
11.3 Certificate Verification
PRAMAAN-generated certificates include a Certificate ID and QR code for independent third-party verification. When scanned, the verifier receives a read-only summary of the device health report. No personal data about the device owner is included in the publicly verifiable certificate summary.
11.4 Legal Requirements
We may disclose data when required by applicable law, court order, or regulatory directive, including to the Data Protection Board of India. We will, where legally permissible, notify affected users before such disclosure.
11.5 Business Transfers
In the event of a merger, acquisition, restructuring, or asset sale, PRAMAAN data may be transferred as part of the transaction. We will notify affected Data Principals prior to such a transfer and ensure the receiving entity is bound by equivalent privacy obligations.
11.6 Cross-Border Transfers
If processing involves transferring personal data outside India, such transfers are conducted only to countries notified as permissible by the Central Government under the DPDP Act, or where adequate contractual safeguards are in place. Enterprise customers requiring data residency within India may request this — contact [email protected].
Data Retention & Deletion
We retain data only for as long as necessary to fulfil the stated purpose or to comply with legal obligations. On expiry, data is securely deleted or irreversibly anonymised.
| Data Type | Retention Period |
|---|---|
| Active account data | For the duration of the active account/license |
| Inactive individual user accounts | 3 years from last login, then permanently deleted |
| Diagnostic reports — individual users | Active license period; deleted within 90 days of account closure or on request |
| Diagnostic reports — enterprise | Duration of enterprise license + 1 year; deleted 30 days after contract termination |
| Enterprise asset & lifecycle records | Duration of enterprise contract + 1 year |
| QC Certificates (issued) | 5 years from date of issue (for audit trail and verification) |
| Crash logs and error reports | 12 months on a rolling basis |
| Anonymised usage telemetry | 24 months on a rolling basis |
| Support and communication records | 3 years from resolution of the interaction |
| Data breach incident logs | 5 years from date of incident (regulatory requirement) |
Rights of Data Principals (Sections 11–14, DPDP Act 2023)
As a Data Principal, you have the following statutory rights under the DPDP Act, 2023:
| Right | What It Means | How to Exercise |
|---|---|---|
| Right to Access (S.11) | Request a summary of all personal and diagnostic data we hold about you | Email [email protected] — Subject: 'PRAMAAN Data Access Request' |
| Right to Correction (S.12) | Request correction of inaccurate, outdated, or incomplete registration data | Update in PRAMAAN account settings, or email us |
| Right to Erasure (S.12) | Request deletion of your personal and diagnostic data, subject to legal retention obligations | Email [email protected] — Subject: 'PRAMAAN Data Deletion Request' |
| Right to Grievance Redressal (S.13) | Lodge a complaint and receive a substantive written response within 30 days | Email [email protected] — Subject: 'PRAMAAN Privacy Grievance' |
| Right to Nominate (S.14) | Nominate another individual to exercise your data rights in the event of death or incapacity | Submit a written nomination to [email protected] |
| Right to Withdraw Consent | Withdraw consent at any time without affecting prior lawful processing | Uninstall PRAMAAN and/or email [email protected] |
| Data Portability (anticipated) | Receive a copy of your diagnostic data in a structured, machine-readable format where feasible | Email [email protected] |
All rights requests will be acknowledged within 48 hours and resolved within 30 days. If a request is denied, we will provide written reasons and inform you of your right to escalate to the Data Protection Board of India.
Children's Privacy (Section 9, DPDP Act 2023)
PRAMAAN is intended for professional and enterprise use and is not directed at individuals under the age of 18. We do not knowingly collect data from minors.
As required by Section 9 of the DPDP Act, if a user is or may be under 18, verifiable consent from a parent or lawful guardian must be obtained before any data is collected or processed.
Third-Party Services and Integrations
| Third Party | Role |
|---|---|
| Cloud Infrastructure Provider (e.g. AWS) | Secure server hosting for PRAMAAN data and reports |
| Enterprise ITAM Systems | Integration with customer's existing IT asset management platform (as contracted) |
| Device Repair Workflow Tools | Integration with repair management platforms used by technicians and refurbishers (as contracted) |
| Analytics Platform | Anonymised software performance and usage telemetry only — opt-out available via PRAMAAN settings |
We impose contractual data protection obligations on all third-party processors. However, Gadget Guruz is not responsible for the independent data practices of third-party services beyond what is governed by our agreements with them.
Applicable Laws and Compliance
PRAMAAN's data practices comply with the following applicable laws and standards:
- Digital Personal Data Protection (DPDP) Act, 2023 — India's primary data protection legislation governing personal data processing
- Information Technology Act, 2000 (and IT Amendment Act, 2008) — Governing electronic records, cybersecurity, and data security obligations
- IT (Reasonable Security Practices) Rules, 2011 — Security standards for sensitive personal data
- Applicable enterprise data security standards relevant to enterprise PRAMAAN deployments (e.g. ISO 27001-equivalent controls)
Grievance Redressal (Section 13, DPDP Act 2023)
If you have any complaint, concern, or grievance regarding the collection, use, storage, or disclosure of your data by PRAMAAN, please contact our Grievance Officer:
If you are not satisfied with the resolution provided by our Grievance Officer, you have the right to escalate your complaint to the Data Protection Board of India under Section 18 of the DPDP Act, 2023.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Post the updated Policy on pramaan.gadgetguruz.com with a revised Effective Date and version number
- Display an in-app notification in PRAMAAN and/or send an email notification to registered users for significant changes
- Seek fresh and explicit consent where new or expanded processing activities require it under the DPDP Act
Continued use of PRAMAAN after the Effective Date of any revision constitutes your acceptance of the updated Policy.
Contact Us
For any questions, requests, or concerns about this Privacy Policy or PRAMAAN's data practices:
Subject: 'PRAMAAN Enterprise DPA Request'