Legal
Privacy Policy
Effective date: 26 July 2026
This document is provided for business use and should be reviewed by qualified legal counsel before publication.
SCRPTA Website: https://scrpta.com Effective Date: 26 July 2026 This Privacy Policy (“Policy”) describes how SCRPTA (“SCRPTA,” “we,” “us,” or “our”) collects, uses, stores, discloses, and otherwise processes personal information in connection with the website located at https://scrpta.com and related marketing pages, forms, demos, content, and informational services (collectively, the “Website”). SCRPTA provides a Compliance Documentation Platform for regulated manufacturers (the “Platform”). This Policy applies to personal information processed through the Website. Processing of personal information in connection with paid Platform services, subscriptions, implementations, or professional services may also be governed by separate written agreements, order forms, data processing agreements, or statements of work (“Product Agreements”). By using the Website, you acknowledge that you have read this Policy. If you do not agree with this Policy, please do not use the Website or submit personal information to us. Our Terms of Use, available at https://scrpta.com/terms-of-use, govern your access to and use of the Website and should be read together with this Policy.
1. Who We Are and How to Contact Us
1.1 The organization responsible for personal information described in this Policy is:
SCRPTA 7/774, I Main Road, Perumbakkam Chennai – 600 100 India
Website: https://scrpta.com Privacy and support contact: support@scrpta.com
1.2 For privacy requests, questions, or complaints regarding this Policy or our processing of personal information, contact us at support@scrpta.com. This is the governing contact for privacy requests under this Policy.
1.3 Depending on your location and applicable law, SCRPTA may act as a “data controller,” “business,” or equivalent under applicable privacy laws in relation to Website personal information. Where we process personal information on behalf of a customer under a Product Agreement, the allocation of roles will be set out in that agreement.
2. Scope of This Policy
2.1 This Policy applies to personal information collected through:
- (a) browsing or otherwise using the Website;
- (b) contact, inquiry, newsletter, event, or similar forms;
- (c) demo, trial, early access, or evaluation requests;
- (d) email or other communications you initiate with SCRPTA in connection with the Website; and
- (e) cookies, analytics, and similar technologies used on the Website, where enabled.
2.2 This Policy does not apply to:
- (a) personal information processed solely under a separate Product Agreement to the extent that agreement provides different or additional terms;
- (b) third-party websites, services, or content linked from or embedded on the Website, which are governed by their own privacy practices; or
- (c) information that does not identify or relate to an identifiable individual, except where such information is combined with personal information in a manner that identifies or is reasonably linkable to an individual.
2.3 The Website is intended for business and professional users. It is not directed to children or to personal consumer use unrelated to business evaluation or commercial engagement.
3. Applicable Privacy Laws
3.1 Depending on your location and the nature of the processing, SCRPTA may process personal information in accordance with applicable privacy and data protection laws, including where applicable:
- (a) the EU General Data Protection Regulation (“GDPR”);
- (b) the United Kingdom General Data Protection Regulation and related UK data protection law (“UK GDPR”);
- (c) the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other applicable U.S. state privacy laws;
- (d) India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules issued thereunder; and
- (e) other privacy, data protection, or electronic communications laws that apply to SCRPTA or to your interaction with the Website.
3.2 References to rights and obligations in this Policy are intended to describe practices that apply where the relevant law applies to you or to the processing at issue. Not all rights or disclosures apply in every jurisdiction.
4. Personal Information We Collect
4.1 Information you provide. When you submit forms or communicate with us, we may collect:
- (a) name;
- (b) company or organization name;
- (c) email address;
- (d) phone number (optional);
- (e) job title;
- (f) country;
- (g) subject and message content; and
- (h) demo-related fields, such as preferred meeting times, product areas of interest, use case descriptions, number of users or sites, current tools or processes, and other information you choose to provide in connection with a demonstration, trial, or evaluation request.
4.2 We collect the categories listed in Section 4.1 through Website forms, including contact forms, demo request forms, and related inquiry forms, as well as through email or other direct communications you send to us.
4.3 Technical information. When you access the Website, we and our service providers may automatically collect:
- (a) Internet Protocol (IP) address;
- (b) browser type and version;
- (c) device type;
- (d) operating system;
- (e) referring website or source;
- (f) approximate location derived from IP address;
- (g) date and time of access; and
- (h) other standard server log and device information.
4.4 Usage information. We may collect information about how you interact with the Website, including:
- (a) pages visited;
- (b) links clicked;
- (c) session duration;
- (d) downloads of publicly available resources, where offered;
- (e) form submission events; and
- (f) other interaction data used to understand Website performance and improve content.
4.5 Communications information. If you correspond with us by email or other channels, we may retain the content of those communications and related metadata as needed to respond to you, maintain records, and improve our services.
4.6 We do not require you to provide sensitive personal information through general Website forms. Please do not submit special-category data, health data, government identifiers, payment card numbers, or other highly sensitive information through Website forms unless SCRPTA has expressly requested that information through a secure and appropriate channel.
5. Sources of Personal Information
5.1 We collect personal information from:
- (a) you, directly, when you submit forms or communicate with us;
- (b) your device and browser, automatically, through cookies, logs, and similar technologies;
- (c) analytics and website performance tools, where enabled; and
- (d) publicly available business sources or referrals, where relevant to a legitimate business inquiry and permitted by law.
5.2 If you provide personal information about another person (for example, a colleague’s contact details for a joint demo), you represent that you have authority to do so and that the other person has been informed of this Policy where required.
6. How We Use Personal Information
6.1 We use personal information for the following purposes:
- (a) to respond to inquiries, contact requests, and support messages;
- (b) to schedule, prepare for, and conduct demonstrations, trials, or evaluations;
- (c) to provide information about SCRPTA, the Platform, and related offerings you have requested;
- (d) to operate, maintain, secure, and improve the Website;
- (e) to understand Website usage, diagnose technical issues, and measure content performance;
- (f) to personalize or improve Website content and user experience where appropriate;
- (g) to send administrative or transactional communications related to your requests;
- (h) to send marketing or product communications where permitted by law and, where required, with your consent or another valid basis, and always with an ability to unsubscribe from marketing emails;
- (i) to maintain business records and manage customer or prospect relationships;
- (j) to detect, prevent, and investigate fraud, abuse, security incidents, or violations of our Terms of Use;
- (k) to comply with legal, regulatory, tax, accounting, and law-enforcement obligations; and
- (l) to establish, exercise, or defend legal claims.
6.2 Where GDPR, UK GDPR, or similar laws apply, we rely on one or more of the following legal bases, as appropriate:
- (a) Consent, where you have given consent for a specific purpose (for example, certain cookies or marketing communications);
- (b) Contractual necessity or steps taken at your request prior to entering a contract (for example, responding to a demo request);
- (c) Legitimate interests, such as operating and securing the Website, improving our products and services, engaging in B2B communications, and conducting analytics in a privacy-aware manner, provided those interests are not overridden by your rights; and
- (d) Legal obligation, where processing is required to comply with applicable law.
6.3 Where the DPDP Act applies, we process personal data for lawful purposes with consent or for legitimate uses recognized under applicable law, and we take reasonable steps to ensure that personal data is processed for the purposes for which it was collected.
6.4 We do not use Website personal information to make automated decisions that produce legal or similarly significant effects about you without human involvement.
8. Analytics
8.1 If enabled, the Website may use analytics and search performance tools, including:
- (a) Google Analytics, to collect aggregated and pseudonymized usage information about how visitors interact with the Website; and
- (b) Google Search Console, to understand search performance, indexing, and technical issues related to the Website.
8.2 These tools may process technical and usage information such as IP address (which may be truncated or anonymized where configured), device and browser information, pages viewed, and referral sources.
8.3 We use analytics to improve Website content, performance, and user experience. We do not use analytics to engage in personally identifiable behavior profiling beyond the purposes described in this Policy.
8.4 Analytics providers process information according to their own privacy policies and terms. Where required, we configure available privacy controls and limit retention or sharing consistent with our purposes.
8.5 You may be able to opt out of certain Google Analytics collection through browser settings, industry opt-out tools, or Google-provided controls, subject to availability and technical limitations.
9. Marketing and Email Communications
9.1 We may send you communications in response to a form submission, information request, demo request, customer relationship, or other interaction with SCRPTA.
9.2 Marketing or product update emails, if sent, will be provided only where permitted by applicable law, including where based on consent or a legitimate interest in B2B communications, and will include an unsubscribe mechanism.
9.3 You may opt out of marketing emails at any time by using the unsubscribe link in the email or by contacting support@scrpta.com. Opting out of marketing does not affect transactional or administrative messages related to an existing request or relationship.
9.4 We do not sell email addresses or other personal information for third-party marketing.
11. Third-Party Services
11.1 The Website may integrate or link to third-party services, including cloud hosting, email delivery, analytics, maps, video embeds, scheduling tools, or social media platforms.
11.2 Each third-party service is governed by its own privacy policy and terms. SCRPTA does not control third-party privacy practices and is not responsible for them.
11.3 Your interactions with third-party services are at your own risk. We encourage you to review the privacy policies of any third-party services you access.
11.4 The presence of a third-party integration or link does not imply endorsement by SCRPTA of that third party’s privacy practices.
12. Data Security
12.1 SCRPTA implements reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include:
- (a) encryption in transit using HTTPS/TLS for Website communications;
- (b) access controls and authentication for systems that process personal information;
- (c) monitoring and logging appropriate to the nature of the systems;
- (d) backups and recovery practices; and
- (e) regular updates and maintenance of systems and dependencies.
12.2 No method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security of personal information.
12.3 You are responsible for maintaining the confidentiality of any credentials issued to you and for using secure methods when communicating with us.
12.4 If we become aware of a personal data breach affecting your personal information that requires notification under applicable law, we will provide notice as required by that law.
13. Data Retention
13.1 We retain personal information only for as long as reasonably necessary for the purposes described in this Policy, including to:
- (a) respond to and follow up on contact and demo requests;
- (b) maintain business relationship and prospect records;
- (c) operate, secure, and improve the Website;
- (d) comply with legal, tax, accounting, and regulatory retention obligations; and
- (e) establish, exercise, or defend legal claims.
13.2 Retention periods vary depending on the nature of the information and context. For example:
- (a) contact and demo request records may be retained for a reasonable business development and follow-up period, and longer where a commercial relationship develops or legal retention duties apply;
- (b) email and support correspondence may be retained as needed to manage the relationship and maintain records;
- (c) analytics and log data may be retained for shorter operational periods, subject to tool configuration; and
- (d) information retained for legal compliance or dispute resolution may be kept for the applicable limitation period.
13.3 When personal information is no longer needed, we will delete it, anonymize it, or securely archive it in accordance with our retention practices and applicable law.
14. International Transfers
14.1 SCRPTA is based in India. Personal information collected through the Website may be processed in India and in other countries where SCRPTA, its affiliates, or its service providers operate.
14.2 If you access the Website from outside India, your information may be transferred to, stored in, or processed in India or other jurisdictions that may have data protection laws different from those in your country.
14.3 Where GDPR, UK GDPR, or similar laws require safeguards for international transfers, we take appropriate steps, which may include standard contractual clauses, data processing agreements, transfer impact assessments where appropriate, and vendor due diligence.
14.4 Where the DPDP Act and related rules apply to cross-border transfers, we will comply with applicable transfer requirements and restrictions.
15. Your Privacy Rights
15.1 Depending on your jurisdiction and the applicable law, you may have rights regarding your personal information, including some or all of the following:
- (a) Access — to request confirmation of whether we process your personal information and to obtain a copy;
- (b) Correction / Rectification — to request that inaccurate or incomplete personal information be corrected;
- (c) Deletion / Erasure — to request deletion of personal information in certain circumstances;
- (d) Restriction — to request that we limit processing in certain circumstances;
- (e) Portability — to receive personal information you provided to us in a structured, commonly used, and machine-readable format, where applicable;
- (f) Withdraw consent — where processing is based on consent, to withdraw consent at any time, without affecting the lawfulness of processing before withdrawal;
- (g) Object — to object to processing based on legitimate interests, including objection to direct marketing;
- (h) Opt out of sale or sharing — under CCPA/CPRA, to opt out of sale or sharing of personal information, noting that SCRPTA does not sell personal information as described in Section 10;
- (i) Non-discrimination — under CCPA/CPRA, not to receive discriminatory treatment for exercising privacy rights; and
- (j) Complaint — to lodge a complaint with a supervisory authority or other competent authority in your jurisdiction.
15.2 GDPR and UK GDPR. If you are in the European Economic Area or the United Kingdom, you may have the rights described above under GDPR or UK GDPR, subject to legal exceptions. You also have the right to lodge a complaint with your local data protection authority.
15.3 CCPA/CPRA. If you are a California resident, you may have rights to know, delete, correct, and opt out of sale or sharing of personal information, and to limit use of sensitive personal information where applicable. We do not sell personal information. To exercise California privacy rights, contact support@scrpta.com.
15.4 DPDP Act (India). If the DPDP Act applies to you, you may have rights as a Data Principal, including rights to access information about your personal data, seek correction or erasure, withdraw consent where processing is based on consent, and nominate another individual in accordance with applicable rules. You may also have the right to grievance redressal. Contact support@scrpta.com to exercise these rights.
15.5 To exercise any privacy right, email support@scrpta.com with sufficient detail for us to verify your identity and understand your request. We may request additional information reasonably necessary to verify that you are the person about whom we collected personal information or an authorized agent.
15.6 We will respond to verifiable requests within the timeframes required by applicable law. If we cannot fulfill a request in whole or in part, we will explain the reasons where permitted.
15.7 Authorized agents may submit requests where permitted by law, subject to verification of the agent’s authority and the consumer’s identity.
16. Children’s Privacy
16.1 The Website is intended for business and professional users and is not directed to children.
16.2 We do not knowingly collect personal information from children under 16 years of age, or under the age of digital consent applicable in a given jurisdiction.
16.3 If you believe that a child has provided personal information to us through the Website, please contact support@scrpta.com and we will take appropriate steps to delete the information where required.
17. Do Not Track and Global Privacy Controls
17.1 Some browsers offer “Do Not Track” signals. Because there is no consistent industry standard for responding to such signals, the Website may not respond to Do Not Track signals at this time.
17.2 Where required by applicable law and where technically feasible, we will honor recognized opt-out preference signals for sale or sharing of personal information. As stated in this Policy, SCRPTA does not sell personal information.
18. Relationship to Product Agreements
18.1 If your organization enters into a Product Agreement with SCRPTA, that agreement may include additional or different terms regarding personal information processed in connection with the Platform, including roles as controller/processor or equivalent, security commitments, subprocessors, and breach notification procedures.
18.2 In the event of a conflict between this Policy and a Product Agreement regarding paid Platform services, the Product Agreement controls for those services to the extent of the conflict.
18.3 This Policy continues to govern personal information collected through the public Website for marketing and general inquiry purposes, unless expressly stated otherwise.
19. Changes to This Policy
19.1 SCRPTA may update this Policy from time to time to reflect changes in our practices, technologies, legal requirements, or business operations.
19.2 When we update this Policy, we will revise the effective date at the top of this page and may provide additional notice where appropriate, such as a notice on the Website or by email if the changes are material and notice is required or appropriate.
19.3 Your continued use of the Website after the updated Policy becomes effective constitutes acknowledgment of the updated Policy, to the extent permitted by applicable law.
19.4 We encourage you to review this Policy periodically.
20. Contact for Privacy Requests
20.1 For all privacy questions, requests, or complaints, contact:
SCRPTA 7/774, I Main Road, Perumbakkam Chennai – 600 100 India
Email: support@scrpta.com Website: https://scrpta.com
20.2 The governing contact for privacy requests under this Policy is support@scrpta.com.
20.3 For Website terms governing access and use, see our Terms of Use at https://scrpta.com/terms-of-use.
20.4 For general inquiries unrelated to privacy rights, you may also use the contact channels described on our Contact page.