Last Updated: May 2025
1. INTRODUCTION
Aryaka Networks, Inc. and its Affiliates (“Aryaka,” “we,” “our,” or “us”) respect your privacy and are committed to protecting your Personal Data. As a global provider of Unified SASE (Secure Access Service Edge) solutions operating across more than 100 countries, we understand the importance of complying with data protection laws. This Privacy Policy explains how we collect, use, disclose, and safeguard your Personal Data when you visit our website, use our services, software application or otherwise interact with us.
We encourage you to read this Privacy Policy before using this website. Our privacy commitment extends to our Affiliates and all our brands (which include, but are not limited to, Aryaka Networks, Velrush, MyAryaka, and Aryaka).
2. SCOPE AND APPLICABILITY
This Privacy Policy applies to all Personal Data processed by Aryaka in connection with our business activities and to all users of our websites, applications, and services worldwide.
3. DEFINITIONS
- Personal Data/Personal Information: Any information that identifies an individual or relates to an identifiable individual.
- Processing: Any operation performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, dissemination, or otherwise making available.
- Data Subject: The individual to whom the Personal Data relates.
- Data Controller: The entity that determines the purposes and means of processing Personal Data (Aryaka in this context).
- Data Processor: An entity that processes Personal Data on behalf of the Data Controller.
- Sensitive Personal Data: Special categories of Personal Data that reveal racial or ethnic origin, political opinions, religious beliefs, health data, biometric data, or sexual orientation.
- Affiliates: Aryaka and any other entity that, directly or indirectly through one or more intermediaries, controls, is controlled by, or is under common control with, Aryaka. As of the date of publication hereof, Aryaka’s Affiliates are Aryaka Networks India Private Limited, Aryaka Networks Singapore Private Limited, Aryaka Networks UK Limited, Aryaka Networks LMS, LLC, and Velrush Business Networks Private Limited.
- Services: Services, for the purposes of this Privacy Policy, refers to all channels of interactions with Aryaka online or offline, including our website, applications, platforms, etc.
4. PERSONAL DATA WE COLLECT
Aryaka respects your privacy and does not access or collect any information or data that passes through your secure network as part of the Services we provide. All data transmitted within or outside your organization through the secure network is encrypted and remains unprocessed by Aryaka. We only collect the Personal Information you choose to provide on our SaaS platform – MyAryaka, our websites, or when you contact us through various channels. This information enables us to deliver the Services you request. Please note that if certain information is not provided, we may be unable to fulfill some Service requests. If you share Personal Information about others with us or our service providers in connection with the Services, you confirm that you have the necessary authority to do so and to allow us to use that information in line with this Privacy Policy.
We collect the following categories of Personal Data:
1. Information You Provide to Us
- Identifiers: such as first and last name, job title, company name, email address, telephone number, postal address, and professional or trade-related information.
- Account Data: Username, password, account preferences, the content you may add to your account created with Aryaka.
- Preferences: Such as language, interests, and other feedback/preferences that you might express during your use of our Services.
- Communication Data: Communications with us including emails, calls, and online chats including communication via Chatbot either on the websites, our call centres or through third party platforms.
2. Information We Collect Automatically
- Technical Data: IP address, login data, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform.
- Usage Data: Information about how you use our website and Services.
- Geolocation Data: Device location and approximate location derived from IP address.
- Device Data: Information about the device used to access our Services. This includes data obtained through cookies and similar technologies, as described in our Cookies Policy.
3. Information from Third Parties
- Marketing and Communications Data: Your preferences in receiving promotional communication such as newsletter, surveys, etc., from us and our third parties.
- Professional Data: Information from marketing partners, industry databases, and publicly available sources such as social media.
5. SENSITIVE INFORMATION
Aryaka does not collect or process any Sensitive Personal Information. We ask that you not send us, and you not disclose, any Sensitive Personal Information (e.g., Social Security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership) on or through the Services or otherwise to us.
6. HOW WE USE YOUR PERSONAL DATA
We use your Personal Data for the following legitimate business purposes:
6.1. Administering Our Services
- To provide and maintain our Services and its functionalities such as arranging access to your account and verifying information.
- To manage your account and provide customer support.
- To process transactions and send related information to you.
- To personalize your experience on our platform.
- To allow you to send Services-related content to another person through the Services if you choose to do so.
6.2. Business Operations
- To improve and develop our products and Services.
- To conduct data performance analysis and research for testing new system features to evaluate their impact, system and log maintenance, technical support, system debugging, and hosting data.
- To maintain the security and integrity of our systems.
- To fulfil our contractual obligations towards you.
6.3. Communications
- To communicate with you about our Services.
- To respond to your inquiries and requests.
- To provide technical notices and updates.
- To send service-related announcements.
6.4. Marketing
- To send promotional communications (with consent where required).
- To deliver relevant content and advertisements.
- To measure the effectiveness of our marketing campaigns.
- To invite you to event or webinars conducted in collaboration with marketing partners.
7. LEGAL BASES FOR PROCESSING
We process your Personal Data based on one or more of the following legal bases, depending on the nature of the interaction, the type of data, and the applicable data protection laws:
7.1. Consent: Where you have provided clear and informed consent for your Personal Data to be processed for specific purposes. You have the right to withdraw your consent at any time, where applicable.
7.2. Contractual Necessity: Where the processing is necessary to enter into or perform a contract with you, or to take steps at your request prior to entering into a contract.
7.3. Legal Obligation: Where we are required to process your Personal Data to comply with applicable laws, regulations, or legal processes.
7.4. Legitimate Interests: Where the processing is necessary for our legitimate business interests or those of a third party, provided such interests are not overridden by your rights and freedoms.
7.5. Vital Interests: Where the processing is necessary to protect the life or safety of an individual.
7.6. Public Interest: Where the processing is necessary for tasks carried out in the public interest or in the exercise of official authority.
7.7. Legitimate Uses Under Applicable Law: In certain jurisdictions, we may process your Personal Data without consent where such processing is allowed by law for specified legitimate uses, including compliance obligations, employment-related purposes, or emergencies.
We ensure that our reliance on each legal basis is carefully assessed and documented in accordance with relevant data protection regulations.
8. DATA SUBJECT RIGHTS
Depending on your jurisdiction, you may have certain rights under applicable data protection laws concerning the Personal Data we collect and process about you. We are committed to ensuring that individuals can exercise these rights in a fair, transparent, and accessible manner.
8.1. For All Users
Regardless of where you reside, and subject to applicable laws, you may have the following rights:
- Right to Access: You have the right to request access to the Personal Data we hold about you. This includes the right to obtain information about the nature, processing purposes, and categories of Personal Data, as well as the recipients or categories of recipients with whom your data has been shared.
- Right to Rectification: If you believe that any Personal Data, we hold about you is incorrect or incomplete, you have the right to request that we correct or update such data without undue delay.
- Right to Deletion (Right to be Forgotten): Under certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected, or you withdraw your consent, you may request that we delete your Personal Data.
- Right to Object: You may object to our processing of your Personal Data when such processing is based on legitimate interests, including for direct marketing purposes. We will review your request and, unless we have compelling legitimate grounds to continue processing, we will cease the processing activity.
- Right to Withdraw Consent: Where we rely on your consent to process your Personal Data, you have the right to withdraw that consent at any time. This withdrawal will not affect the lawfulness of processing based on consent before its withdrawal.
8.2. Additional Rights for EEA, UK, and Swiss Residents
In addition to the rights listed above, residents of the European Economic Area (EEA), United Kingdom (UK), and Switzerland may have enhanced protections under the General Data Protection Regulation (GDPR) and similar laws:
- Right to Data Portability: You have the right to receive a copy of your Personal Data in a structured, commonly used, and machine-readable format. Where technically feasible, you may also request that we transmit this data directly to another data controller.
- Right to Restriction of Processing: You may request that we restrict the processing of your Personal Data in specific circumstances; for example, if you contest the accuracy of the data or if the processing is unlawful but you oppose erasure.
- Right to Not Be Subject to Automated Decision-Making: You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or significantly affects you. We do not currently engage in such processing without human involvement.
8.3. Additional Rights for California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):
- Right to Know: You have the right to request that we disclose the categories of personal information we have collected about you, the sources of the information, the purposes for which we use it, the categories of third parties with whom we share it, and the specific pieces of personal information we hold about you.
- Right to Opt-Out of Sale or Sharing: You have the right to opt out of the sale or sharing of your personal information with third parties for purposes such as cross-context behavioural advertising.
- Right to Limit Use of Sensitive Personal Information: You may direct us to limit the use and disclosure of sensitive personal information to what is necessary to perform our Services or provide the goods you have requested.
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising any of your privacy rights under California law, including the denial of services or the charging of different prices or rates.
8.4. Additional Rights for Residents of Virginia, Colorado, Connecticut, and Other U.S. States
Certain U.S. state laws—including those in Virginia (VCDPA), Colorado (CPA), and Connecticut (CTDPA)—grant you additional rights, which may include:
- Right to Confirm Processing: You may request confirmation as to whether we are processing your Personal Data and access to such data if it is being processed.
- Right to Opt Out of Targeted Advertising: You have the right to opt out of the processing of your Personal Data for the purposes of targeted advertising, sometimes referred to as cross-context behavioural advertising.
- Right to Opt Out of Profiling: You may opt out of the processing of your Personal Data for profiling in furtherance of decisions that produce legal or similarly significant effects concerning you.
To exercise any of these rights, please contact us using the details provided in the “CONTACT US” section below.
9. CROSS-BORDER DATA TRANSFERS
9.1. Your Personal Information may be stored and processed in any country or region where we have facilities or engage service providers. By using the Services, you understand that your Personal Information will be transferred to countries outside of your country or region of residence, including to the United States, which may have data protection rules that are different from those of your country or region. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries or regions may be entitled to access your Personal Information.
9.2. Some countries outside of the EEA/UK are recognized by the European Commission and/or the UK government as providing an adequate level of data protection according to EEA/UK standards: the list of the EEA’s adequate jurisdictions is available here, and the list of the UK’s adequate jurisdictions is available here. For transfers from the EEA or the UK to countries not considered adequate by the European Commission or the UK government (as applicable), we have put in place adequate measures, such as the standard contractual clauses adopted by the relevant authority to protect your Personal Data. You may obtain a copy of these measures by contacting us in accordance with the “CONTACT US” section below.
9.3. For transfers from mainland China to abroad, we undertake such transfers in accordance with applicable local laws, including to base such transfers on a relevant transfer mechanism or exemption as provided for under local laws. If you would like to exercise your rights with respect to your Personal Information against us or recipients located outside of your country or region of residence, please contact us in accordance with the “CONTACT US” section below.
10. DATA RETENTION
We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained as outlined in this Privacy Policy unless a longer retention period is required by applicable law. The criteria used to determine our retention periods include:
- The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have a relationship with us or keep using the Services);
- The length of time we have an ongoing relationship with you and provide you with Services;
- Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records or communications for a certain period before we can delete them); or
- Whether retention is advisable considering our legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations).
11. DATA SECURITY
We seek to use reasonable organizational, technical, and administrative measures to protect Personal Information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “CONTACT US” section below.
12. CHILDREN’S PRIVACY
The Services are not directed to individuals under the age of sixteen (16), and we do not knowingly collect Personal Information from individuals under 16.
13. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar tracking technologies to collect information about your browsing activities. These technologies help us analyse website traffic, customize content, and deliver targeted advertisements. Please read our Cookies Policy to learn how we use information that we and our service providers collect automatically, including through cookies, pixel tags, and similar tracking technologies and to understand your choices with respect to such collection and use.
14. THIRD-PARTY SHARING
We may share your Personal Data with the following categories of recipients:
14.1. Service Providers
- Cloud hosting providers that provide website, platform hosting, IT and related infrastructure, email delivery, analytics and other services.
- Customer support services to collect data related to issues in the Services and provide a communication channel.
- Payment processors for transactions on the Aryaka platform.
- Analytics providers that help us with aggregating/anonymizing Personal Data, and fraud prevention services.
- Marketing and communication platforms including advertising networks and promotional partners.
14.2. Business Partners
- Resellers and distributors through whom you may have purchased our Services.
- Integration partners or technology service providers we may have partnered with for providing various functionalities in our Services.
- Consultants and professional advisors, such as accountants, actuaries, auditors, experts, consultants, lawyers, banks, and financial institutions for legal and compliance obligations.
14.3. Corporate Affiliates
For all the purposes listed above Aryaka and its Affiliates are responsible for the management of any jointly used Personal Information.
14.4. Legal Requirements
- Law enforcement, public, regulatory and government authorities, courts, tribunals, or third parties where necessary to comply with applicable law and regulations.
- Third parties such as an acquiring entity and its advisors, in connection with a sale or business transaction with appropriate notice to you.
We require all third parties to respect the security of your Personal Data and to treat it in accordance with applicable laws. By using the Services, you may elect to disclose Personal Information on message boards, chat, profile pages, blogs and other services to which you are able to post information and content (including, without limitation, our social media), or through which you are able to send messages through the Services. Please note that any information you post or disclose in this context will become public and may be available to other users and the general public.
15. THIRD PARTY SERVICES
This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties. This includes any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our Affiliates.
In addition, we are not responsible for the information collection, use, disclosure or security policies or practices of other organizations, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with the apps or our social media.
16. DATA BREACH NOTIFICATION
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the appropriate regulatory authorities without undue delay, in accordance with applicable laws. We will take all necessary measures to contain the breach, minimize harm, and investigate its cause. Where required, we will also provide guidance on steps you can take to protect yourself.
17. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any material changes by posting the updated Privacy Policy on our website and updating the “Last Updated” date.
18. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of your Personal Data, please feel free to contact us using the information below:
Aryaka Networks, Inc., located at 4699 Old Ironsides Drive, Ste 470 Santa Clara, CA 95054.
You can also reach us at: privacyofficer@aryaka.com.
19. REQUESTS AND COMPLAINTS
If you would like to exercise your rights that you may have based on the applicable laws of your jurisdiction, please feel free to contact us in accordance with the “18” section above. We will respond to your request consistent with applicable law.
In your request, please make clear what Personal Information you would like to have changed, whether you would like to have your Personal Information suppressed from our databases or otherwise let us know what limitations you would like to put on our use of your Personal Information. For your protection, we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.
Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion (e.g., when you make a purchase or enter a promotion, you may not be able to change or delete the Personal Information provided until after the completion of such purchase or promotion). Further, certain Personal Information may be exempt from requests pursuant to applicable data protection laws or other laws and regulations.
Depending on your jurisdiction, you may also lodge a complaint with a data protection authority for your country or region, or where an alleged infringement of applicable data protection law occurs. We have listed the relevant data protection authorities in the below jurisdictions:
- EEA Residents: Your national Data Protection Authority (http://ec.europa.eu/justice/data-protection/article-29/structure/data-protection-authorities/index_en.htm)
- UK Residents: The Information Commissioner’s Office (www.ico.org.uk)
- California Residents: The California Privacy Protection Agency (www.cppa.ca.gov)
We would, however, appreciate the chance to address your concerns before you approach a regulatory authority, so please contact us in the first instance.