Crest Crest
Product How It Works Integrations Pricing Blog
Sign In Get Early Access
Product How It Works Integrations Pricing Blog
Sign In Get Early Access

Legal

Privacy Policy

Last updated: 1 July 2026

Crest Technologies Pvt Ltd ("the Company," "we," "us," or "our"), registered at Cyber Gateway, Block C, HITEC City, Madhapur, Hyderabad, Telangana 500081, India, operates the website gocrest.org and the Crest predictive drive-failure detection service (together, "the Service"). This Privacy Policy explains what information the Company collects, how it is used, and the rights available to you. Contact us at [email protected] with any questions.

1. What Crest Collects - and What It Does Not

The Company's core service is ingesting drive telemetry from infrastructure environments. Understanding the data boundary is important:

1a. Drive telemetry (product data)

When SRE and platform teams deploy the Crest agent on their storage hosts, the agent reads and transmits the following device-level metadata to the Company's processing backend:

  • SMART attribute values and delta readings (e.g., reallocated sector counts, pending sectors, uncorrectable errors, power-on hours, temperature, power cycle counts);
  • NVMe health log entries and vendor-specific endurance counters;
  • Drive model identifier and a hashed drive serial number (the hash is one-way and cannot be reversed to recover the original serial);
  • Host identifier (customer-configurable label or hostname) and timestamps of each telemetry collection cycle.

This telemetry is device and hardware metadata only. The Company does not read, receive, or process file contents, user data, application data, database contents, network traffic, or any personal information stored on the monitored drives. Drive telemetry is personal information only in narrow circumstances (e.g., where a host identifier resolves to an identifiable individual); the Company treats it with the same care as personal information regardless.

1b. Information you submit directly

When you contact the Company via the website contact form, request early access, or correspond by email, the Company collects:

  • Name, work email address, company name, and job role;
  • The content of your message or request;
  • Fleet size estimate and any technical details you choose to share.

1c. Technical and usage data collected automatically

The Company collects standard server log data when you visit gocrest.org: IP address, browser type, operating system, referring URL, pages visited, and timestamps. The Company also uses cookies and similar technologies as described in the Cookie Policy.

2. Purposes and Legal Basis

The Company uses collected information to:

  • Operate the predictive failure detection service - specifically, to run the failure probability model against ingested telemetry and deliver risk alerts and scores to the subscribing team;
  • Respond to enquiries and early access requests from SRE teams and infrastructure buyers;
  • Improve the accuracy of the failure prediction model using aggregate and anonymised telemetry patterns (see Section 3 on model training);
  • Send operational communications (service status updates, security notices) to account contacts;
  • Maintain security and prevent abuse of the Service;
  • Meet applicable legal obligations.

The Company processes personal information where: you have provided it in the course of requesting or using the Service (contractual necessity); you have consented (e.g., marketing communications); or the Company has a legitimate interest (e.g., improving prediction accuracy using aggregated anonymised patterns) that is not overridden by your interests.

3. Drive Telemetry and Model Training

The Company does not use identifiable drive telemetry from a specific customer environment to train or improve its failure prediction model without explicit written agreement. Aggregate, de-identified patterns - for example, statistical failure rate distributions across drive model families - may be used to improve model accuracy. Where a customer selects the on-premise deployment option (available on Team and Fleet plans), all telemetry processing and model inference occur within the customer's own infrastructure; no telemetry leaves the customer's environment.

4. Sharing and Processors

The Company shares information with:

  • Service providers acting as data processors on the Company's behalf, under written agreements that restrict their use of data to providing the contracted service only;
  • Integration partners you configure (for example, when you connect the Service to PagerDuty or Slack, the alert payload - which includes drive identifier, host label, and risk score - is transmitted to that platform under your direction);
  • Competent authorities where required by applicable law or valid legal process.

The Company does not sell personal information to third parties.

5. International Transfers

The Company is incorporated and operates from India. If you access the Service from outside India, your information may be transferred to and processed in India, where data protection law may differ from your jurisdiction. The Company applies the safeguards described in this policy regardless of where processing occurs.

6. Retention and Security

Drive telemetry submitted through the cloud agent is retained for 90 days by default, after which it is deleted unless a longer retention period has been agreed in writing. Contact form submissions and early access enquiries are retained for as long as necessary to manage the customer relationship and comply with applicable record-keeping obligations, then deleted.

The Company applies technical and organisational security measures to protect personal information, including TLS 1.3 encryption for data in transit and AES-256 encryption for data at rest in cloud deployments. Customers using the on-premise deployment option retain full control over data residency and encryption within their own infrastructure.

7. Your Rights Under the Digital Personal Data Protection Act, 2023 (India)

India's Digital Personal Data Protection Act, 2023 ("DPDP Act") governs the Company's processing of personal data of Indian residents. As a data principal, you have the following rights:

  • Right to access: You may request a summary of the personal data the Company holds about you and the purposes for which it is processed.
  • Right to correction and erasure: You may request correction of inaccurate or incomplete personal data, and erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to any retention obligations under applicable law.
  • Right to grievance redressal: You may raise a complaint if you believe the Company has not complied with its obligations under the DPDP Act. The Company will acknowledge your complaint within a reasonable time and respond in writing.
  • Right to nominate: You may nominate another person to exercise your rights on your behalf in the event of your death or incapacity, in accordance with the DPDP Act.
  • Right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect the lawfulness of processing prior to withdrawal.

To exercise any of these rights, email [email protected] with sufficient information to identify your account or the data concerned. The Company will respond within 30 days.

8. International Good-Practice Rights Baseline

Subject to applicable local law, individuals outside India who interact with the Service may also have rights to access, correct, delete, or restrict processing of their personal information, and to object to certain uses or receive their data in a portable format. To make any such request, contact [email protected]. The Company will respond within a reasonable period, typically 30 days, and will apply good-faith effort to honour requests consistent with its legal obligations.

9. Cookies

The Company uses cookies and similar technologies on gocrest.org. See the Cookie Policy for full details including how to manage cookie preferences.

10. Changes and Contact

The Company may update this Privacy Policy from time to time. Material changes will be reflected by an updated "Last updated" date at the top of this page.

Crest Technologies Pvt Ltd
Cyber Gateway, Block C, HITEC City, Madhapur
Hyderabad, Telangana 500081, India
Email: [email protected]
Phone: +91 40 4718 6200
Terms of Service Cookie Policy
Crest

Predictive drive failure detection for SRE and infrastructure teams. Know before it fails.

Product

  • Product
  • How It Works
  • Integrations
  • Security
  • Pricing

Company

  • About
  • Blog
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
© 2026 Crest Technologies Pvt Ltd | Cyber Gateway, Block C, HITEC City, Madhapur, Hyderabad, Telangana 500081, India | [email protected] | +91 40 4718 6200
Privacy Terms Cookies Cookie preferences