Privacy Policy
This policy explains what personal data we collect, why we collect it, how long we keep it, and the rights you have over it.
Last updated 1 September 2026
1. Who we are
CipherCru Innovations Private Limited (“CipherCru”, “we”, “us”, or “our”) is a technology services company incorporated under the Companies Act, 2013, with its registered office at 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India.
We provide custom software development, SaaS product development, AI solutions, cloud engineering, DevOps, managed services, web and mobile development, UI/UX design, API development, consulting, staff augmentation, and digital transformation services to clients in India and internationally.
For the purposes of the Digital Personal Data Protection Act 2023 (“DPDP Act”) and applicable Indian data protection law, CipherCru acts as the Data Fiduciary (controller) in respect of Personal Data it collects and processes for its own purposes as described in this Policy. Where CipherCru processes Personal Data on behalf of its clients in connection with Services it provides, CipherCru acts as a Data Processor, and processing is governed by the applicable Data Processing Agreement with that client.
For the purposes of the General Data Protection Regulation (EU) 2016/679 (“GDPR”), where applicable, CipherCru is the data controller in respect of Personal Data of individuals in the European Economic Area (EEA) and United Kingdom processed for CipherCru's own purposes.
2. Scope of this policy
2.1 What This Policy Covers. This Privacy Policy describes how CipherCru collects, uses, stores, shares, and protects Personal Data, being information that identifies or can identify a living individual, when you visit or interact with the CipherCru website at https://www.ciphercru.com and any associated subdomains or pages (collectively, the “Website”); contact us with an enquiry, submit a project brief, or request a quotation; enter into a commercial engagement with CipherCru as a client, vendor, or partner; correspond with us by email, telephone, messaging platform, or video call; attend or participate in a CipherCru webinar, event, or demonstration; subscribe to CipherCru's marketing communications, newsletters, or updates; or use any SaaS platform, portal, or application operated by CipherCru for client service delivery.
2.2 What This Policy Does Not Cover. This Policy does not govern Personal Data that CipherCru processes as a data processor on behalf of its clients. The collection and use of such data is governed by the applicable client's own privacy policy and by our Data Processing Agreement with that client; if you are a customer or end user of a CipherCru client, please refer to that client's privacy policy. It also does not govern Personal Data collected by third-party websites linked from the Website, for whose privacy practices we are not responsible.
2.3 Applicable Law. This Policy is governed primarily by the laws of India, including the DPDP Act, the Information Technology Act 2000 (“IT Act”), and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (“SPDI Rules”). Where we process Personal Data of individuals located in the European Economic Area, the United Kingdom, or California, we also comply with the GDPR, the UK GDPR, and the California Consumer Privacy Act (“CCPA”) as applicable.
3. Personal data we collect
We collect the following categories of Personal Data, depending on how you interact with us.
3.1 Identity and contact data
- Full name
- Job title and designation
- Company name and type
- Business email address
- Personal email address, where provided
- Telephone number, mobile or office
- Business postal address
- LinkedIn profile URL or other professional profile links
3.2 Commercial and engagement data
- Project enquiry details, requirements, and briefs submitted to us
- Quotation and proposal history
- Executed contracts (MSAs, SOWs) and related correspondence
- Payment history, invoice records, and billing information
- GSTIN, PAN, and other tax identification numbers
- Bank account details provided for payment processing or vendor registration
3.3 Communication data
- Email correspondence with our team
- Records of telephone or video calls, where recorded with consent
- Messages sent via our Website contact forms
- Messages exchanged via Slack, WhatsApp, or other messaging platforms used for project communication
- Meeting notes and project communication records
3.4 Technical and usage data
- IP address and approximate geographic location derived from IP address
- Browser type, version, and operating system
- Device type and identifier
- Pages visited on the Website, time spent, and navigation path
- Referring URL, being how you arrived at the Website
- Campaign parameters, such as utm_source, utm_medium and utm_campaign, in the link that brought you to the Website
- Which calls to action and forms you use on the Website, but never what you type into a form
- Cookies and similar tracking technology identifiers, described in Section 12
- Your cookie consent choices, the date you made them, and whether your browser sent a Global Privacy Control signal
- Log files and access records
3.5 Marketing and preference data
- Marketing communication preferences and opt-in or opt-out records
- Event attendance records
- Content download history, such as whitepapers and case studies
- Survey responses
3.6 Sensitive personal data
We generally do not seek to collect Sensitive Personal Data (as defined under the SPDI Rules) or Special Category Data (as defined under the GDPR), including data concerning health, biometrics, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or criminal records, through the ordinary course of our business. If sensitive data is incidentally provided to us or if we need to process it in connection with a specific engagement, we will seek explicit consent and apply heightened protections.
3.7 Data collected from third parties
We may receive Personal Data about you from publicly available professional directories and databases, such as LinkedIn and company registries; referrals from existing clients or partners; third-party lead generation platforms and business intelligence tools; and conference and event organisers where you have consented to share your information with exhibitors or sponsors.
4. How we collect personal data
4.1 Directly from You. When you complete a contact form, quotation request, or project brief on our Website; email, call, or message us; enter into a contract with CipherCru; provide business card or contact details at events or meetings; subscribe to our newsletter or marketing communications; or participate in surveys, interviews, or feedback sessions.
Enquiries sent through our Website. When you send us an enquiry, we store it in our own enquiry database and in HubSpot, our customer relationship management system, so that it reaches the right member of our team even if one of those systems is briefly unavailable. We store with it the page you sent it from, the page you first arrived on, the campaign parameters of your visit, and the service page and call to action that led you to the form. If you accepted performance and analytics cookies, we also store the Google Analytics and HubSpot identifiers of your browser, which link the enquiry to the pages you viewed.
4.2 Automatically. When you visit our Website, we automatically collect technical and usage data through server logs that record your IP address, browser, and navigation behaviour; through cookies, pixel tags, and similar tracking technologies; and through Google Analytics' cookieless measurement, which sets no cookie. All of these are described in Section 12 and in our Cookie Policy.
4.3 From Third Parties. We may collect Personal Data from referral partners and introducers who share your details with your consent; public professional databases and social networks, where permitted by the applicable platform's terms and applicable law; and third-party marketing and lead generation services.
4.4 Through Project Delivery. In the course of providing Services, we may receive Personal Data contained in client materials, datasets, or systems to which we are granted access for the purpose of performing the Services. Such data is processed as a data processor and governed by our Data Processing Agreement with the relevant client.
5. Legal bases for processing
5.1 Under the DPDP Act (India)
Under the DPDP Act, we process Personal Data of individuals in India on the following lawful bases.
Consent. Where we rely on your consent, we will request it clearly and specifically before processing. You may withdraw your consent at any time, as described in Section 10.4. We rely on consent for sending marketing communications, newsletters, and promotional content; placing non-essential cookies; and recording calls or meetings.
Legitimate Uses (as prescribed). The DPDP Act permits processing for certain legitimate purposes without requiring explicit consent, including performance of a contract to which you are a party or steps at your request prior to entering into a contract; compliance with applicable law or legal obligations; responding to a medical emergency or protecting life; employment and HR-related processing for our employees and contractors; and processing for reasonable purposes notified by the Central Government.
Voluntary Disclosure. Where you have voluntarily provided Personal Data that is clearly intended for a specific purpose.
5.2 Under the GDPR (EEA and UK individuals)
For individuals in the EEA or UK, we process Personal Data under one or more of the following lawful bases under Article 6 GDPR.
- Contract (Article 6(1)(b)). Processing necessary for the performance of a contract with you or to take pre-contractual steps at your request, for example processing your contact details and project requirements to provide a quotation and execute an engagement.
- Legitimate Interests (Article 6(1)(f)). Processing necessary for our legitimate business interests, where those interests are not overridden by your rights and interests. Our legitimate interests include maintaining business relationships; marketing our services to existing and prospective business clients; improving our services; understanding, in aggregate and without cookies, how our Website is used; recording where an enquiry came from, so that we can respond to it and improve how we reach prospective clients; and protecting our legal rights. Where we rely on legitimate interests, we have conducted a balancing test to confirm that our interests do not override your rights.
- Legal Obligation (Article 6(1)(c)). Processing necessary to comply with applicable law, for example retaining financial records for statutory periods.
- Consent (Article 6(1)(a)). Where we have obtained your explicit consent, for example for marketing communications or non-essential cookies, including the HubSpot cookies that link the pages you viewed to an enquiry you send.
6. How we use your personal data
We use the Personal Data we collect for the following purposes.
6.1 Providing and managing services
- To respond to your enquiries, project briefs, and quotation requests
- To route each enquiry to the right member of our team, and to see which of our services and pages it relates to
- To enter into and perform contracts with you (MSAs, SOWs, and related agreements)
- To manage your client account, project communications, and project records
- To issue invoices, process payments, and manage financial records
- To provide post-delivery support, maintenance, and managed services
6.2 Business development and marketing
- To send you information about CipherCru's services, case studies, and capabilities that may be relevant to your business, only where you have consented or where we have a legitimate interest in marketing to you as an existing business contact
- To follow up on enquiries, proposals, and meetings
- To invite you to CipherCru events, webinars, and demonstrations
- To conduct surveys and gather feedback on our services
You may opt out of marketing communications at any time by clicking “Unsubscribe” in any marketing email or by contacting us at privacy@ciphercru.com. Opting out of marketing does not affect our ability to send you transactional or service-related communications necessary for your active engagement.
6.3 Operating and improving our website
- To operate, maintain, and improve the Website
- To analyse usage patterns and understand how visitors interact with the Website
- To measure which sources, pages and calls to action lead to enquiries, and whether those enquiries go on to become qualified opportunities or clients. For browsers whose analytics consent we hold, we report that outcome to Google Analytics against the browser's analytics identifier, never with your name or contact details
- To personalise content and improve user experience
- To detect, investigate, and prevent fraudulent or malicious activity
- To diagnose and resolve technical issues
6.4 Legal and compliance purposes
- To comply with applicable law, court orders, regulatory requirements, and legal processes
- To enforce our Terms of Service, MSA, and other contractual agreements
- To protect the rights, property, and safety of CipherCru, our clients, and the public
- To maintain records required by law, including financial and tax records
- To respond to requests from law enforcement agencies, courts, or regulatory authorities
6.5 Recruitment and HR
- To process applications for employment or contractor positions at CipherCru
- To manage the employment relationship with our employees and contractors
- To administer payroll, benefits, and HR processes
6.6 Research and development
To use aggregated and anonymised data, from which no individual can be identified, to improve our services, develop new offerings, and conduct research and analysis. Anonymised data is not Personal Data and is not subject to this Policy.
7. Sharing and disclosure of personal data
We do not sell your Personal Data to third parties. We share Personal Data only as described below.
7.1 Service providers and sub-processors
We engage trusted third-party service providers who process Personal Data on our behalf to enable us to operate our business. These providers are contractually bound to process Personal Data only on our instructions and to apply appropriate security measures. The categories, with examples of the kind of provider used in each, are as follows.
| Category | Examples | Purpose |
|---|---|---|
| Cloud infrastructure | AWS, Google Cloud, Microsoft Azure | Hosting, storage, and computing |
| Website hosting and enquiry database | Render (website hosting); MongoDB Atlas, hosted on Microsoft Azure in Pune, India (enquiry database) | Hosting the Website, and storing enquiries, cookie consent records, and the status of their delivery to our CRM |
| Email and communication | Google Workspace, Microsoft 365, Zoho | Business email and collaboration |
| Project management | Jira, Notion, Linear, Slack | Project delivery and client communication |
| CRM and sales | HubSpot | Managing enquiries and client relationships, including where an enquiry came from and the pages viewed before it, where cookies were accepted |
| Payment processing | Razorpay, Stripe, PayPal | Processing payments |
| Accounting | Zoho Books, Tally | Financial record-keeping |
| Analytics and tag management | Google Analytics, Google Tag Manager, HubSpot | Measuring how the Website is used, including cookieless measurement, and which sources lead to enquiries and clients. The Cookie Policy lists the cookies involved |
| Video conferencing | Google Meet, Zoom, Microsoft Teams | Client meetings |
| AI service providers | OpenAI, Anthropic, Google, Microsoft | AI-assisted service delivery, described in Section 16 |
| Legal and compliance | Law firms, compliance advisors | Legal advice and regulatory compliance |
We maintain up-to-date sub-processor lists and will update this Policy when we add new sub-processors who process data in a way that is material to your rights.
7.2 Corporate group
We may share Personal Data with CipherCru's parent company, subsidiaries, or affiliates where necessary for group administration, legal compliance, or service delivery.
7.3 Professional advisors
We share Personal Data with our lawyers, accountants, auditors, and insurers where necessary for the provision of professional advice or where required by law.
7.4 Legal and regulatory disclosure
We may disclose Personal Data to law enforcement agencies, courts, regulators, or other governmental authorities where required by applicable law, court order, or legal process; to protect the rights, safety, or property of CipherCru, our clients, or others; to investigate, detect, or prevent fraud, security breaches, or illegal activity; and in connection with legal proceedings or regulatory investigations. Where legally permitted, we will notify you of such disclosures.
7.5 Business transfers
In the event of a merger, acquisition, sale of business, restructuring, or other corporate transaction, Personal Data may be transferred to the successor entity as part of that transaction, subject to the successor entity's undertaking to process the Personal Data in accordance with this Policy or a substantially equivalent policy.
7.6 With your consent
We may share Personal Data with third parties for purposes not described in this Policy where we have obtained your prior written consent.
7.7 What we do not do
- We do not sell, rent, or trade your Personal Data to third parties for their marketing or commercial purposes
- We do not share your Personal Data with advertisers for targeted advertising purposes
- We do not use Google Analytics' advertising features or Google Signals, and we never send Google your name, email address, or any other detail that identifies you directly
- We do not disclose client information to competitors or other clients
8. International transfers of personal data
8.1 Cross-border processing
CipherCru is based in India. Some of our service providers and sub-processors are located in other countries, including the United States, the European Union, Singapore, and the United Kingdom. Our analytics, CRM and website hosting providers, including Google and HubSpot, may process Website and enquiry data in these countries. Our enquiry database itself is hosted in India, on Microsoft Azure in Pune. When we transfer Personal Data internationally, we implement appropriate safeguards to protect it.
8.2 Transfers from India
International transfers of Personal Data from India are subject to the DPDP Act and any rules or notifications issued by the Central Government restricting transfers to specified countries. We will comply with all applicable transfer restrictions and will not transfer Personal Data to countries that are notified as restricted under the DPDP Act.
8.3 Transfers from the EEA or UK
Where we transfer Personal Data of EEA or UK individuals to countries outside the EEA or UK that are not recognised as providing an adequate level of data protection, we rely on one or more of the following transfer mechanisms: Standard Contractual Clauses, incorporating the European Commission's approved SCCs (2021/914/EU) or the UK International Data Transfer Addendum into our contracts with recipients; an adequacy decision, where the European Commission or UK ICO has issued one for the recipient country; or other approved mechanisms under Article 46 GDPR or applicable UK law.
You may request a copy of the transfer safeguards we apply by contacting us at the details in Section 19.
9. Data retention
9.1 Retention principles
We retain Personal Data only for as long as necessary for the purposes described in this Policy, or as required by applicable law. When determining retention periods, we consider the purpose for which the data was collected; our contractual and legal obligations; any regulatory requirements prescribing minimum retention periods; and the potential risk of harm from retaining unnecessary data.
9.2 Retention periods
The following retention periods apply as defaults. Longer periods may apply where required by law or by a specific contract.
| Category of personal data | Retention period | Basis |
|---|---|---|
| Client contact and identity data | Duration of commercial relationship plus 7 years | Legal obligation (tax, audit); legitimate interests |
| Contract records (MSAs, SOWs) | 10 years from contract expiry | Legal obligation; statute of limitations |
| Financial and invoice records | 8 years from the end of the relevant financial year | Tax laws; GST Act; Companies Act |
| Project communication records | Duration of project plus 3 years | Legitimate interests; dispute resolution |
| Website enquiry and contact form data, with its source information, held in our enquiry database and in HubSpot | 2 years from enquiry, or until engagement commences | Legitimate interests |
| Marketing opt-in records | Duration of consent plus 3 years | Evidence of consent |
| Job application data (unsuccessful) | 6 months from rejection | Legitimate interests |
| Employee and contractor data | Duration of engagement plus 7 years | Legal obligations; HR law |
| Google Analytics event data, including cookieless measurement | 14 months | Consent (analytics cookies); legitimate interests (cookieless measurement) |
| Cookies set on your device | The duration listed for each cookie in the Cookie Policy | Varies by cookie type |
| Cookie consent records | 3 years from the consent event | Evidence of consent |
| Technical logs (server and access logs) | 90 days | Security and fraud prevention |
9.3 Deletion and anonymisation
When Personal Data is no longer required and no legal basis for retention exists, we securely delete or anonymise it. Anonymised data, from which you cannot be identified, may be retained indefinitely for research and analytical purposes.
10. Your rights as a data principal or data subject
10.1 Rights under the DPDP Act (India)
Under the Digital Personal Data Protection Act 2023, you have the following rights as a Data Principal.
- Right to Access Information (Section 11). You have the right to obtain confirmation of whether CipherCru is processing your Personal Data; a summary of the Personal Data CipherCru holds about you; and information about the identities of all Data Fiduciaries and Data Processors with whom your data has been shared.
- Right to Correction and Erasure (Section 12). You have the right to correct inaccurate or incomplete Personal Data; to update your Personal Data; and to request erasure of Personal Data that is no longer necessary for the purposes for which it was collected, subject to legal retention obligations.
- Right to Grievance Redressal (Section 13). You have the right to have your grievances addressed promptly and effectively by CipherCru's Grievance Officer, described in Section 18, and to escalate unresolved grievances to the Data Protection Board of India, once established.
- Right to Nominate (Section 14). You have the right to nominate another individual to exercise your rights in the event of your death or incapacity.
10.2 Rights under the GDPR (EEA and UK individuals)
If you are located in the EEA or UK, you have the following rights under the GDPR or UK GDPR.
- Right of Access (Article 15). You have the right to receive a copy of the Personal Data we hold about you, along with information about how we process it.
- Right to Rectification (Article 16). You have the right to have inaccurate Personal Data corrected and incomplete data completed.
- Right to Erasure, the right to be forgotten (Article 17). You have the right to request deletion of your Personal Data where it is no longer necessary for the purposes for which it was collected; where you have withdrawn consent and there is no other legal basis; where you have objected and there are no overriding legitimate interests; where the data has been unlawfully processed; or where deletion is required by law. This right is subject to exceptions for legal claims, freedom of expression, public interest, and compliance with legal obligations.
- Right to Restriction of Processing (Article 18). You have the right to request that we restrict processing of your Personal Data while a dispute about accuracy or legitimacy is resolved.
- Right to Data Portability (Article 20). Where processing is based on consent or contract and carried out by automated means, you have the right to receive your Personal Data in a structured, commonly used, machine-readable format and to transmit it to another controller.
- Right to Object (Article 21). You have the right to object to processing based on our legitimate interests, including for direct marketing purposes. Where you object to direct marketing, we will stop processing your data for that purpose immediately.
- Rights Related to Automated Decision-Making and Profiling (Article 22). You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects or similarly significantly affects you, except where it is necessary for a contract, authorised by law, or you have given explicit consent.
10.3 How to exercise your rights
To exercise any of the rights described in this Section, please submit a written request to privacy@ciphercru.com, with the subject line “Data Principal / Data Subject Rights Request”.
Please include your full name, contact details, a description of the right you wish to exercise and the specific data concerned, and, where applicable, proof of identity to enable us to verify your identity before processing your request.
We will respond to all valid requests within 30 calendar days of receipt. We may extend this period by a further 30 days in complex cases, in which case we will notify you of the extension and the reason within the initial 30-day period. We do not charge a fee for reasonable requests.
10.4 Right to withdraw consent
Where we process your Personal Data on the basis of your consent, you may withdraw that consent at any time by clicking “Unsubscribe” in any marketing email; by contacting us at privacy@ciphercru.com; or by adjusting your cookie preferences from the "Cookie preferences" control in the footer of any page on this site. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
10.5 Right to lodge a complaint
India. If you have concerns about how we process your Personal Data, you may raise a grievance with our Grievance Officer, described in Section 18. Once established, you may also refer your complaint to the Data Protection Board of India.
EEA. You have the right to lodge a complaint with your national data protection authority. A list of EEA supervisory authorities is published by the European Data Protection Board.
UK. You may lodge a complaint with the Information Commissioner's Office (ICO).
11. Rights of California residents (CCPA)
This Section applies to residents of California, USA, to the extent CipherCru's processing activities fall within the scope of the California Consumer Privacy Act as amended by the California Privacy Rights Act (CPRA).
11.1 Categories of personal information collected
In the preceding twelve (12) months, we have collected the following categories of Personal Information as defined by the CCPA.
| CCPA category | Examples collected | Purpose |
|---|---|---|
| Identifiers | Name, email address, IP address, business contact details, analytics identifiers of your browser | Service delivery, communication, marketing |
| Commercial information | Contract records, payment history, project details | Service delivery, billing |
| Internet or other electronic network activity | Website usage data, cookies, campaign parameters, pages viewed before an enquiry | Analytics, security, understanding which sources lead to enquiries |
| Professional or employment-related information | Job title, company name, professional background | Client relationship management |
| Inferences drawn from the above | Interest profiles for marketing personalisation | Marketing |
11.2 Sources of personal information
We collect Personal Information as described in Section 4 of this Policy.
11.3 Business or commercial purpose for collection
We use Personal Information for the business purposes described in Section 6 of this Policy.
11.4 Categories of third parties with whom we share personal information
We share Personal Information with the categories of third parties described in Section 7 of this Policy.
11.5 Your CCPA rights
California residents have the right to:
- Know. Request disclosure of the categories and specific pieces of Personal Information we have collected about you, the categories of sources, the purposes for collection, and the categories of third parties to whom we disclose it.
- Delete. Request deletion of Personal Information we hold about you, subject to exceptions such as completing transactions, legal obligations, and security purposes.
- Correct. Request correction of inaccurate Personal Information.
- Opt out of sale or sharing. We do not sell or share Personal Information for cross-context behavioural advertising as defined by the CCPA. We also honour the Global Privacy Control signal as described in our Cookie Policy. If this changes, we will update this Policy and provide an opt-out mechanism.
- Limit use of sensitive personal information. We do not use or disclose Sensitive Personal Information, as defined by the CPRA, beyond what is necessary to provide our services.
- Non-discrimination. We will not discriminate against you for exercising your CCPA rights.
11.6 Exercising CCPA rights
To exercise your CCPA rights, please contact us at privacy@ciphercru.com. We will verify your identity before processing requests. You may designate an authorised agent to submit requests on your behalf.
12. Cookies and tracking technologies
We use cookies and similar tracking technologies on our Website to operate and improve it and to understand how visitors interact with it. We use Google Analytics, loaded through Google Tag Manager, and the HubSpot tracking code. This Section provides a summary; full details, including the complete inventory of cookies actually in use, are set out in our Cookie Policy.
12.1 What are cookies?
Cookies are small text files placed on your device when you visit a website. They serve various functions, including enabling website functionality, measuring traffic, and supporting personalisation.
12.2 Types of cookies we use
| Category | Purpose | Consent required |
|---|---|---|
| Strictly necessary | Essential for the Website to function, such as session management and security | No, legitimate interest |
| Analytics and performance | Measuring Website traffic, page performance, and user behaviour through Google Analytics and HubSpot. HubSpot's cookies also link the pages you viewed to an enquiry you send | Yes |
| Cookieless measurement | Google Analytics counting page views and actions without setting or reading any cookie, before you choose and if you decline | No, legitimate interest. Nothing is stored on or read from your device |
| Functional | Remembering your preferences and settings, such as language and form pre-fill | Yes |
| Marketing and targeting | Tracking for advertising purposes and retargeting | Yes, where used |
12.3 Managing your cookie preferences
You can manage cookie preferences through our Cookie Preference Centre, which you can open from the "Cookie preferences" control in the footer of any page on this site; through your browser settings, noting that blocking all cookies may affect Website functionality; and through opt-out tools provided by analytics providers. For full details on specific cookies, their durations, and how to opt out, please refer to our Cookie Policy.
13. Security of personal data
13.1 Security measures
CipherCru implements reasonable and appropriate technical and organisational security measures to protect Personal Data against accidental loss, destruction, alteration, unauthorised disclosure, and unauthorised access. These measures include:
- Access controls: role-based access controls limiting access to Personal Data to those who need it for their work, and multi-factor authentication for critical systems;
- Encryption: encryption of Personal Data in transit, using TLS and HTTPS, and at rest where appropriate;
- Secure development practices: security considerations integrated into our software development lifecycle, including code reviews and vulnerability assessments;
- Personnel training: regular security awareness training for all team members who handle Personal Data;
- Vendor management: security due diligence applied to third-party service providers who process Personal Data on our behalf;
- Incident response: a documented data breach response procedure.
13.2 No absolute security
No security measure is infallible. While we take data security seriously, we cannot guarantee absolute security. You use our Website and services at your own risk. In the event of a personal data breach, we will notify affected individuals and relevant authorities as required by applicable law.
13.3 Your security responsibilities
You are responsible for maintaining the security of your own devices, accounts, and credentials used to access CipherCru services. We are not responsible for breaches caused by your own security failures.
13.4 Data breach notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, then under the DPDP Act we will report breaches to the Data Protection Board of India, once operational, as required by applicable rules; and under the GDPR we will notify the relevant supervisory authority within 72 hours where feasible, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights.
14. Children's privacy
Our Website and Services are directed at businesses and professionals and are not intended for use by children under the age of eighteen (18) years, or the applicable minimum age in relevant jurisdictions.
We do not knowingly collect Personal Data from individuals under eighteen (18) years of age. If you are under eighteen (18), please do not submit any Personal Data to us.
If we discover that we have inadvertently collected Personal Data from a child under the applicable age, we will delete that information promptly. If you are a parent or guardian and believe your child has provided us with Personal Data without your consent, please contact us at privacy@ciphercru.com and we will take appropriate steps.
15. Third-party websites and services
Our Website may contain links to third-party websites, services, or platforms, including the websites of our clients, partners, or technology providers. These links are provided for your convenience.
We do not control third-party websites and are not responsible for their privacy practices, content, or terms. This Policy does not apply to any third-party website or service. We encourage you to read the privacy policies of any third-party website you visit.
Similarly, where our services integrate with third-party platforms or APIs, such as payment gateways, cloud providers, or social media platforms, the collection and use of your data by those platforms is governed by their own privacy policies.
16. AI tools and data processing
16.1 Use of AI tools in service delivery
CipherCru may use AI-powered tools and large language model services, including OpenAI, Anthropic Claude, Google Gemini, Microsoft Copilot, GitHub Copilot, and similar platforms, in the course of delivering Services to clients. When we use these tools, we apply the following safeguards: minimisation, meaning we use only the minimum Personal Data necessary when interacting with AI tools and, where possible, use anonymised, synthetic, or non-personal data; review, meaning we do not rely exclusively on AI-generated outputs without human review, particularly where outputs may affect individuals; and terms compliance, meaning we use AI tools only in accordance with the applicable provider's terms of service, including any restrictions on inputting personal or sensitive data.
16.2 Client data and AI
CipherCru does not input client Personal Data into public AI tools without the client's express written authorisation. Where a client project involves the use of AI tools that will process Personal Data, this is addressed in the applicable Data Processing Agreement.
16.3 AI service provider data practices
AI tool providers may process inputs to improve their models or for other purposes, depending on their terms and configurations. We use enterprise-tier API access, where available, that excludes training on inputs. We recommend clients review the privacy terms of any AI tools used in their projects. AI providers' privacy practices are outside CipherCru's control, and CipherCru is not responsible for the data practices of AI providers.
16.4 Automated decision-making
CipherCru does not use automated decision-making or profiling that produces legal effects or significantly affects individuals, beyond routine analytics and personalised marketing, which can be opted out of. Any significant automated decisions would be clearly disclosed and subject to human review.
17. Changes to this Privacy Policy
17.1 Right to Update. We may update this Privacy Policy from time to time to reflect changes in our data practices, applicable law, or business operations. We will post the updated Policy on our Website and update the last-updated date at the top.
17.2 Material Changes. For material changes, being changes that significantly affect how we process your Personal Data or your rights, we will provide additional notice by sending an email notification to the email address associated with your account or engagement with us, where we hold your email address, and by displaying a prominent notice on the Website.
17.3 Continued Use. Your continued use of our Website or Services after the effective date of a revised Policy constitutes your acknowledgment of the changes. We encourage you to review this Policy periodically.
17.4 Archived Versions. Previous versions of this Policy are available on request by emailing privacy@ciphercru.com.
18. Grievance Officer
In accordance with the Information Technology Act 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, and the DPDP Act 2023, CipherCru has appointed a Grievance Officer to address complaints and concerns relating to the processing of Personal Data.
- Organisation
- CipherCru Innovations Private Limited
- Address
- 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India
- privacy@ciphercru.com
Grievance resolution process. Submit your grievance in writing to the Grievance Officer at the contact details above, describing the nature of your concern, the Personal Data involved, and the outcome you seek. We will acknowledge your grievance within 48 hours of receipt, and will resolve or respond substantively within 15 days of receipt. If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India, once operational, or to the applicable court of competent jurisdiction.
19. Contact us
For all general privacy enquiries, data rights requests, and concerns relating to this Privacy Policy, please contact us at:
- Entity
- CipherCru Innovations Private Limited, attention: Privacy Team / Data Protection
- Registered office
- 602, The Elysian, A-31, Swej Farm Circle, Swej Farm, New Sanganer Road, Sodala, Jaipur, Rajasthan 302019, India
- privacy@ciphercru.com
- Website
- https://www.ciphercru.com
EU and EEA individuals. No Article 27 representative is appointed at this time; all enquiries should be directed to the address above. UK individuals: the same applies.
Schedule A: Glossary
- CCPA
- California Consumer Privacy Act (Cal. Civil Code 1798.100 et seq.), as amended by the California Privacy Rights Act (CPRA).
- CipherCru
- CipherCru Innovations Private Limited
- Data Fiduciary
- An entity that determines the purpose and means of processing Personal Data, equivalent to a data controller under the GDPR, as defined in the DPDP Act.
- Data Principal
- The individual to whom Personal Data relates, as defined in the DPDP Act.
- Data Processor
- An entity that processes Personal Data on behalf of a Data Fiduciary, equivalent to a data processor under the GDPR.
- DPDP Act
- The Digital Personal Data Protection Act 2023 (India).
- EEA
- European Economic Area.
- GDPR
- General Data Protection Regulation (EU) 2016/679.
- IT Act
- Information Technology Act 2000 (India).
- Personal Data or Personal Information
- Any information that identifies or can identify a living individual, as defined under the DPDP Act or GDPR as applicable.
- Sensitive Personal Data
- Personal data concerning health, biometrics, genetic data, racial or ethnic origin, political opinions, religious beliefs, financial data, sexual orientation, or criminal records, as defined under the SPDI Rules.
- SPDI Rules
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011.
- UK GDPR
- The GDPR as retained in UK law by the European Union (Withdrawal) Act 2018.
- Website
- https://www.ciphercru.com and all associated subdomains and pages operated by CipherCru.