CY-DLP Browser Sensor — Privacy Policy
Last updated: 30 July 2026
The CY-DLP Browser Sensor is an enterprise security extension published by
Cybernexa Infotech Private Ltd ("Cybernexa"). It is the browser component of the Cybernexa CY-DLP
Data Loss Prevention platform and is deployed and managed by the organization that
licenses CY-DLP. It works together with the CY-DLP endpoint agent installed on the same device.
What the extension does
The sensor inspects content within web pages on the user's device — text entered into web
applications, file uploads, and AI/GenAI tool prompts — to detect regulated and sensitive data
(such as Aadhaar, PAN, credit-card numbers, and other personally identifiable information) as
defined by the deploying organization's policy. When that policy requires it, the sensor blocks the
action and notifies the local CY-DLP agent.
Data we process, and where it goes
- Inspection is performed locally, on the device, in coordination with the
CY-DLP endpoint agent. Page content is analyzed against the organization's detection policy.
- Event metadata — such as the policy matched, the data category, the
destination, and a timestamp — is reported to the deploying organization's own CY-DLP
management console for their security team.
- The extension communicates only with the local CY-DLP agent (via native messaging) and the
organization's own CY-DLP backend. It does not send data to Cybernexa for Cybernexa's own use.
Categories of data handled
To perform data-loss detection the sensor may process the following categories of data, on the
device, as they appear in page content the user enters or uploads:
- Personally identifiable information (e.g. Aadhaar, PAN, identification numbers)
- Financial and payment information (e.g. credit- and debit-card numbers)
- Authentication information (e.g. credentials entered into login forms)
- Personal communications (e.g. webmail and chat content the user composes)
- User activity (text typed or pasted, and outgoing web requests, for detection)
- Website content (page text and uploads inspected for the above)
This data is analyzed locally for policy matching. Only event metadata (the policy matched, data
category, destination, timestamp) is reported to the deploying organization's own CY-DLP console — the
underlying content itself is not transmitted to Cybernexa.
What we do NOT do
- We do not sell user data.
- We do not use data for advertising.
- We do not use data to determine creditworthiness or for lending purposes.
- We do not use data for any purpose unrelated to the deploying organization's
data-protection policy.
Permissions
- Host access (all sites) — DLP must inspect content on any site where a user
could paste or upload regulated data.
- webRequest / webRequestBlocking — to block a request that would exfiltrate
sensitive data before it is sent.
- nativeMessaging — to exchange detections and policy with the locally
installed CY-DLP agent.
- downloads, storage, tabs — to observe download egress, cache policy locally,
and scope enforcement per browser tab.
Data controller
The organization that deploys CY-DLP is the data controller for the information processed on its
endpoints. Cybernexa acts as the software provider. Handling of this data is governed by the
agreement between Cybernexa and the deploying organization.
Contact
Cybernexa Infotech Private Ltd — security@cybernexa.com
· www.cybernexa.com