1. Overview
Konverge Technologies is committed to protecting the privacy and security of all data processed through the NIA-AI platform — a Nutanix Intelligent Autonomy AI system used by MSPs and enterprise IT teams to manage Nutanix infrastructure.
This Privacy Policy explains how we collect, use, store, and protect information when you access NIA-AI. By using the platform, you agree to the practices described here.
NIA-AI operates entirely on-premise. All AI inference runs locally using Qwen2.5:14b on your infrastructure. No cluster data is transmitted to external AI services or cloud providers.
2. Data We Collect
2.1 Account and User Data
- Username, full name, and email address of portal users
- Hashed passwords (bcrypt — never stored in plaintext)
- Role assignments and group memberships
- Last login timestamp and session activity
- TOTP 2FA secrets (encrypted at rest)
2.2 Cluster and Infrastructure Data
- Nutanix cluster configuration: name, IP addresses, AOS version, node count
- Real-time metrics: CPU usage, memory usage, storage utilisation
- VM inventory: names, power states, resource allocation
- Alert data: severity, description, timestamps, resolution status
- LCM software inventory: component versions, update availability
2.3 Operational Data
- Audit logs: all user actions with timestamp, IP address, and resource affected
- API credentials for Nutanix Prism (encrypted in vault)
- Agent tokens for cluster connectivity (revocable, per-cluster)
- Backup metadata: filenames, sizes, timestamps
2.4 Data We Do NOT Collect
- We do not collect or store VM workload data or application content
- We do not transmit cluster data to external cloud services
- We do not use third-party analytics or advertising trackers
- We do not collect payment or financial information through this platform
3. How We Use Your Data
- Platform operation: Authenticate users, manage sessions, enforce role-based access control
- Cluster management: Poll and display cluster health, metrics, alerts, and inventory
- AI-assisted operations: Provide context to the on-premise Qwen2.5:14b model — all processing happens locally on your server
- Security: Detect unauthorised access, maintain audit trails, enforce session timeouts
- Notifications: Send alerts via Email, Slack, or Teams as configured by your organisation
- Platform improvement: Internal analysis of system performance and error logs
4. Data Storage and Security
All NIA-AI data is stored on-premise on infrastructure controlled by Konverge Technologies or the deploying organisation. Security measures include:
- Encryption at rest: Sensitive credentials stored using Fernet symmetric encryption
- Encryption in transit: All communications over HTTPS/TLS
- Password hashing: All user passwords hashed with bcrypt
- Session security: 30-minute inactivity timeout, server-side invalidation
- 2FA: TOTP-based two-factor authentication available for all users
- Audit logging: All administrative actions logged with user identity, timestamp, and IP
- Backup: Automated encrypted backups with configurable retention
5. Data Sharing
Konverge Technologies does not sell, rent, or share your data with third parties except:
- With your explicit consent: If you authorise integration with third-party services such as Slack or Teams for alert notifications
- Legal compliance: If required by applicable Indian law, court order, or regulatory authority
- Service delivery: Sub-processors involved in hosting or support who are bound by equivalent data protection obligations
NIA-AI's AI assistant (Qwen2.5:14b) runs entirely on your on-premise GPU infrastructure. No queries or cluster data are sent to any external AI service.
6. Data Retention
- User accounts: Retained until explicitly deleted by an administrator. Deactivated accounts retain audit history.
- Audit logs: Retained for a minimum of 12 months
- Alert data: Retained for 90 days after resolution
- Session data: Purged after session expiry (30 minutes inactivity)
- Backups: Retained per administrator schedule (default: last 3 backups)
7. Your Rights
Under applicable data protection law, you have the right to access, rectify, erase, restrict processing of, and port your personal data. You also have the right to object to processing.
To exercise any of these rights, contact us at connect@konverge.co.in. We will respond within 30 days.
8. Cookies and Sessions
NIA-AI uses only session cookies strictly necessary for platform operation:
- Session cookie: Maintains your authenticated session. Expires after 30 minutes of inactivity or on logout.
- CSRF token: Protects against cross-site request forgery attacks.
We do not use advertising cookies, tracking pixels, or third-party analytics.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and notify platform administrators via the NIA-AI notification system. Continued use of the platform after changes are posted constitutes acceptance.