TraceIT

Privacy Policy

Applies to the TraceIT web application at traceit-tottech.com, the TraceIT mobile application, and the TraceIT relay agent.
Effective 15 August 2026 · Last updated 15 August 2026

TraceIT is a monitoring service. It watches servers, integration platforms and business applications on behalf of the organisations that use it, and tells them when something is wrong. This policy explains what data that involves, why we hold it, and what you can ask us to do with it.

1. Who we are

TraceIT is operated by Tottempudi Software Solutions Private Limited, registered at 7-58, Flat No. Sri Sai Mallikarjuna Residency, Nagarajupalli Road, Martur, Bapatla, Andhra Pradesh 523301, India. Corporate Identity Number U62013AP2025PTC118560.

2. Two kinds of data, and our different roles

Account data — we are the controller. Who signed in, which organisation and workspace they belong to, and what they did in the product.

Monitoring data — we are the processor. Measurements about our customers’ own systems. This belongs to the customer. If you are an end user of a business that uses TraceIT, that business — not us — decides how this data is used, and you should approach them first.

3. What we collect

Account and identity: name, email address, assigned role, which organisation and workspaces you can reach, and authentication records including sign-in failures.

Monitoring data: server identity (hostname, IP address, operating system, group), resource measurements (CPU, memory, disk, network), integration platform activity (API names, request and error counts, response times, deployment state), licence and consumption figures, and scheduled job history.

These describe machines and services. Where a hostname, address or service name identifies an individual — uncommon but possible — it is treated as personal data.

Contact data: email addresses configured to receive alerts and reports, and roster entries (name, role, email, Microsoft Teams sign-in, telephone number, on-call flag) entered by an administrator so the right person can be reached when a system fails.

Security and audit records: who changed what and when, failed sign-in attempts, and blocked outbound requests with the originating address.

Diagnostic and crash reports: error message, stack trace, version and device or browser type. These are first-party. They are stored in our own database and are not sent to Sentry, Crashlytics, Bugsnag or any other third-party service — no such SDK is present in the product.

End-user network address. Where a customer embeds our web SDK in their own application, we record the network address (IP address) that each batch of events arrives from. We take it from the connection itself and never from anything the application sends us, because a value supplied by the thing being measured is a claim rather than a measurement.

It is stored shortened. An IPv4 address is kept with its last part removed (for example 203.0.113.42 is stored as 203.0.113.0) and an IPv6 address is cut to its first half. From the full address we derive the country, the region and the network operator, and we store those. This shortened form is what every chart and report in the product uses. Where we have no data set that can place an address, we leave the country, region and operator empty rather than guess one.

We derive an approximate location — country and region — from the network connection your device makes to TraceIT, and attach it to product analytics events. We do not store your device’s network address alongside those events, and TraceIT has no access to GPS or device location.

The full address is kept for one purpose and one week. A copy of the unshortened address is held separately, for investigating abuse and intrusion — for example when a customer’s application key is found in use on a site that is not theirs. It is deleted after the period shown in section 6 by the same scheduled job that enforces every other period on this page. It is not used for analytics, for advertising, or for anything else.

Which applications this applies to. Only ones a customer has registered and embedded our web SDK into. The TraceIT mobile app does not send telemetry events, so no address is collected from a phone. Address and derived location are treated as personal data: they are isolated per organisation in the database like every other customer record, and they are excluded from the reports and exports that do not need them.

Uploaded files. An inventory file you upload is encrypted the moment it is stored, under a key held separately for your organisation. Once its contents have been read into connectors it is deleted outright, which is the default and is what this deployment does.

Passwords inside an uploaded file. Any value in that file that looks like a credential — a password column, an API key, a connection string with a password in it — is replaced with a marker before the file is stored at all, by the same step that keeps those values away from the AI model reading it. The real values are held separately, encrypted under your organisation’s own key, are never sent to a browser, and are used only to make the connections you approve. If you never finish onboarding, the stored file is removed 30 days after upload rather than kept indefinitely.

4. What we do not collect

  • We do not sell personal data. Not to anyone, in any circumstances.
  • We do not serve advertising and share nothing with advertising networks or data brokers.
  • We do not read the contents of your business systems. TraceIT measures whether services are healthy and how much they are used. It does not read the records, documents or messages held inside them.
  • We do not track you across other websites or applications.
  • We do not collect location, contacts, photographs, or the contents of your device.
  • The mobile app sends no push notifications. The messaging component is present in the package and is not configured, so nothing can deliver a message to you. It does request the Android notification permission as part of that component — section 9 lists every permission the installed app asks for and why, including the ones that arrive this way and are not used.

5. Credentials

To monitor a system TraceIT needs a way to reach it. Credentials are encrypted at rest under a key held separately per organisation, are never displayed again once saved, and are never written to logs, alerts, reports or error messages. Where the relay agent is used they can remain inside your own network. Outbound connections are refused by default to loopback, link-local and private addresses, so a credential cannot be used to reach somewhere it should not.

6. How long we keep it

These are the periods the system actually enforces, read from its own retention policies.

CategoryRetention
Detailed measurements (raw metrics)30 days, compressed after 7
Minute rollup35 days
Hourly rollup400 days
Mobile analytics events30 days
Crash reports (events)90 days
End-user address, truncated (with country, region and network)30 days, with the mobile and web analytics events it belongs to
End-user network, truncated to the /24 — abuse and intrusion investigation only7 days
Crash reports (grouped issues)90 days
Alert and incident history400 days
Notification log (who was paged, and when)180 days
Records collected from a connected system (for example, payment attempts)30 days
Uploaded inventory file that was never activated30 days from upload
Audit logKept indefinitely, by design
Security eventsKept indefinitely, by design
Current health state per systemOne row per system; replaced in place, removed with the system
Account dataDeleted with the tenant; cascades to every table above

2 categories are kept indefinitely, deliberately — not because no period was chosen, but because a period would defeat what they are for. They are removed when the account is deleted, which cascades to every table above.

  • Audit log. An audit trail that expires is not an audit trail. It is the record of who changed what, and the questions it answers — often in a dispute — arrive long after the change.
  • Security events. A pattern of failed sign-ins or refused admin requests is only visible over a long window, and an intrusion is frequently investigated years later. Expiring this would delete the evidence of the thing it exists to detect.

7. Who we share data with

Only the providers below, and only to the extent needed. Each is bound to protect it and use it for no other purpose. The list is derived from what the software actually contacts.

ProviderWhat it doesWhere
Contabo GmbHRuns the production server and databaseMumbai, India
Microsoft 365 (SMTP)Delivers alert emails and scheduled reportsMicrosoft's Asia-Pacific datacentre geography (may include locations outside India)
Browser push services (Google, Apple, Mozilla)Deliver push notifications to your browser, where you have enabled them. Which one is used is decided by your browser, not by us. They receive the notification payload and a subscription identifier — never your monitoring data.United States and the vendor’s own regions
Healthchecks.ioExternal heartbeat that raises the alarm if TraceIT itself stops running. Receives a signal only — no customer data.United States
Microsoft Teams (incoming webhook)Only where a customer configures a channel. Receives the alert and report content sent to that channel.The customer's own Microsoft tenant
Google PlayDistributes the mobile applicationUnited States

The web application loads no fonts, scripts or assets from a third-party domain, so browsing it discloses nothing to anybody else.

8. Diagnostics in the product itself

TraceIT reports its own errors to itself so faults in the product can be fixed. It is on by default and set for the whole organisation, not per user, because a fault that only some people hit is exactly the fault worth seeing. An organisation administrator can turn it off at any time in Settings. It reports faults in TraceIT — never activity in your own systems.

It also requires the deployment itself to have diagnostics configured — an explicit flag, an application key and an endpoint. Both conditions must hold: your organisation’s setting cannot switch on collection in a deployment that has none configured.

9. The mobile app

The app shows the same dashboards as the web application over an encrypted connection, and refuses to connect to an unencrypted address. It contains no advertising and no third-party trackers. This is every permission the installed package requests, read from the built app rather than from our source — some arrive with a component the app is built with rather than from a feature you can use, and those say so:

  • INTERNET — Connect to TraceIT over HTTPS.
  • ACCESS_NETWORK_STATE — Tell the reader when the device is offline.
  • POST_NOTIFICATIONS — Show alerts from your monitored estate on this device. Alerts are delivered over TraceIT’s own connection to the deployment — not through Google’s push service — so they arrive on closed and shipboard networks. Notifications are only shown after you turn them on in the app.
  • FOREGROUND_SERVICE — Hold the alert connection open. Android does not allow a background process to keep a long-lived connection, so while alerts are on the app runs a visible service and shows a permanent “monitoring active” notice. That notice is required by Android and is the reason alerts can be delivered without Google.
  • FOREGROUND_SERVICE_DATA_SYNC — Declares what that service does: hold a connection and fetch queued alerts. Android requires the type to be stated.
  • RECEIVE_BOOT_COMPLETED — Restore the alert connection after the phone restarts or the app updates — only if you had turned alerts on. Without it a reboot would silently stop alerts arriving.
  • REQUEST_IGNORE_BATTERY_OPTIMIZATIONS — Ask you, once, to exempt TraceIT from battery optimisation. Without the exemption Android may freeze the alert connection and alerts stop arriving with nothing on screen to say so. You can decline, and you can revoke it in Android settings at any time.
  • WAKE_LOCK — Let the alert connection be checked and restarted while the screen is off. Android suspends a sleeping phone, and without this the fifteen-minute check that notices a dropped connection would simply not run until you next picked the phone up — which is exactly when alerts are least likely to be seen.
  • DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION — Generated by Android’s own libraries and namespaced to this app. It is a signature-level permission that only this app can hold, used so internal broadcasts cannot be received by other apps. It grants no access to anything on the device.

10. How we protect it

Traffic is encrypted in transit. Credentials are encrypted at rest per organisation. Each organisation’s data is isolated in the database, so a query for one cannot return another’s rows. Access is limited by role, every change is recorded in an audit log, a web application firewall sits in front of the service, and backups are taken and verified before every deployment.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant supervisory authority as required and without undue delay.

11. Your rights

Depending on where you live you may ask what we hold about you and receive a copy, have it corrected or deleted, object to or restrict processing, receive it in a portable form, withdraw consent, and complain to your data protection authority.

If your request concerns monitoring data and you are an employee or customer of an organisation that uses TraceIT, contact that organisation first — they control it.

Account deletion. Write to the address below from the address on the account. We will confirm what will be deleted and what must be retained, and act within 30 days. How to delete your account sets out the route, what is deleted, what we have to keep and why, and what is not ours to delete.

12. International transfers

Your data is stored and processed in India. Processing is governed by India’s Digital Personal Data Protection Act 2023. Where personal data of individuals in the UK or the EEA is processed on a customer’s behalf, we rely on the Standard Contractual Clauses adopted by the European Commission (Implementing Decision (EU) 2021/914), the UK International Data Transfer Addendum for data originating in the United Kingdom, and a transfer risk assessment reviewed when our providers change.

13. Children

TraceIT is a tool for IT and operations professionals. It is not directed at children, is not intended for anyone under 16, and we do not knowingly collect data from them.

14. Changes

We may update this policy as the service changes. The effective date above always shows the current version. If a change materially affects how we handle your personal data we will notify account holders by email before it takes effect.

15. Contact

support@traceittech.com
Tottempudi Software Solutions Private Limited
7-58, Flat No. Sri Sai Mallikarjuna Residency, Nagarajupalli Road,
Martur, Bapatla, Andhra Pradesh 523301, India
CIN: U62013AP2025PTC118560

We aim to acknowledge a request within 5 working days and answer it within 30 days. If you are in India and are not satisfied you may complain to the Data Protection Board of India; in the UK or EEA, to your local supervisory authority.