This Data Protection Statement describes how CEHPOINT E-services ("Cehpoint", "we", "us") handles digital personal data in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the CERT-In Cyber Security Directions, 2022. It complements our Privacy Policy and Grievance Redressal Policy.
1. Introduction & Legal Framework
We are dedicated to safeguarding the personal data of our users, enterprise clients, independent product testers, developers, and website visitors (collectively designated as Data Principals under Indian law). "Personal data" means any data about an individual who is identifiable by or in relation to such data.
All processing is founded on statutory notice, affirmative verifiable consent, or specified legitimate uses permitted under Section 7 of the DPDP Act 2023.
2. Cehpoint as Data Fiduciary & Processor
Our regulatory capacity is determined by the processing context:
- Data Fiduciary: When Cehpoint determines the purpose and means of processing personal data (e.g. account registration, user credentials, direct platform billing, AI assistant interactions, and security telemetry), Cehpoint acts as the Data Fiduciary.
- Data Processor: Where we process data strictly on behalf of an enterprise client (such as running dedicated penetration tests, analyzing proprietary client code, or hosting private LLM instances under contract), Cehpoint acts as a Data Processor bound by rigorous Data Processing Addenda (DPA).
3. Data Protection Principles
In adherence to global best practices and Indian statutory requirements, our platform architecture enforces six core tenets:
- Lawful, fair, and transparent processing — Personal data is processed exclusively for purposes explicitly notified prior to collection.
- Purpose limitation — Data collected for one specified purpose is never repurposed without fresh, itemized consent.
- Data minimisation — Only data strictly necessary for delivering the contracted engineering or platform service is requested.
- Data accuracy — Reasonable operational steps and self-service dashboards are maintained to keep records accurate and updated.
- Storage limitation — Data is retained strictly during the active lifecycle of the engagement and purged per statutory schedules.
- Integrity, confidentiality, and accountability — Enterprise-grade technical and organisational controls protect against unauthorized disclosure or loss.
4. Statutory Multilingual Notice (DPDP Section 5(3))
Pursuant to Section 5(3) of the DPDP Act 2023, every Data Principal has the statutory right to access their data protection and processing notice in English or any of the 22 Scheduled Languages specified in the Eighth Schedule to the Constitution of India.
Loading statutory notice...
5. Lawful Purposes of Processing
Personal data is processed solely under the following statutory grounds:
| Category of Personal Data | Specific Processing Purpose | Statutory Basis (DPDP Act) |
|---|---|---|
| Identity & Profile (Name, email, mobile number, organization) | Account creation, MFA authentication, client 360 dashboards, role-based access. | Consent (Sec. 6) / Contractual Performance (Sec. 7(b)) |
| Billing & Tax Data (GSTIN, invoicing address, PayU transaction IDs) | Payment processing, tax invoicing, input tax credit validation, GST audits. | Legal Obligation (Sec. 7(c) / CGST Act 2017) |
| Testing Marketplace Reports (Bug summaries, vulnerability telemetry) | Facilitating bug bounties, tester payout disbursement, client validation. | Contractual Performance & Consent |
| AI Platform Prompts & Documents (Grounding data, assistant inputs) | Executing user queries via isolated RAG workflows, generating reports. | Explicit User Request & Consent |
| Security Telemetry & Logs (IP addresses, user-agent, session IDs) | Detecting brute-force attacks, DDoS mitigation, statutory CERT-In audit trails. | Cybersecurity & System Integrity (Sec. 7(g)) |
6. Data Principal Rights & Self-Service Intake Portal
Under Chapter III (Sections 11 to 14) of the DPDP Act 2023, you have enforceable legal rights regarding your personal data. You may exercise them instantly through our interactive intake portal below or by emailing grievance@cehpoint.co.in.
Self-Service Data Principal Rights (DPR) Portal
Submit a statutory request for Access, Correction, Erasure, Consent Withdrawal, or Nomination. Every request receives an automated tracking ticket and statutory SLA acknowledgment.
Track Existing Statutory Request
7. Technical & Organisational Safeguards
Under Section 8(5) of the DPDP Act 2023, Cehpoint implements reasonable security safeguards to prevent personal data breaches:
- Cryptography: Industry-standard TLS 1.3 encryption in transit with perfect forward secrecy; AES-256 encryption for data at rest.
- Credential Protection: Passwords hashed with salted, multi-round
bcryptalgorithms; strict role-based access control (RBAC). - 10-Minute Support Access ID System: On-behalf administrative operations are strictly time-bounded (10-minute auto-expiry) with exhaustive database audit logs.
- Logical Tenant Isolation: Customer data, vector embeddings, and uploaded files are logically isolated by tenant ID.
- Regular Security Audits: Comprehensive internal and third-party Vulnerability Assessment and Penetration Testing (VAPT).
8. CERT-In 6-Hour Reporting & Personal Data Breach Protocol
In accordance with Section 70B of the Information Technology Act, 2000, the CERT-In Cyber Security Directions, 2022, and Section 8(6) of the DPDP Act 2023, Cehpoint maintains an active Computer Security Incident Response Protocol (CSIRP):
🚨 Statutory 6-Hour Cybersecurity Reporting Mandate
Under Direction 20(a) of the CERT-In Directions, any cybersecurity incident of statutory nature (including unauthorized system access, data leaks, ransomware, identity theft, or denial-of-service) is reported to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of notice.
- Statutory Reporting Channel: incident@cert-in.org.in / Helpline: 1800-11-4949
- Cehpoint Incident Command: certin-reporting@cehpoint.co.in / security@cehpoint.co.in
- Mandatory 180-Day Log Preservation: In full compliance with CERT-In directions, all server ICT logs and security records within Indian jurisdiction are securely retained for a minimum of 180 days.
In parallel, in the event of a verified personal data breach impacting Data Principals, Cehpoint will immediately notify the Data Protection Board of India (DPBI) and affected Data Principals with:
- The nature, scope, and estimated number of affected individuals.
- The likely consequences of the breach.
- The immediate containment and remedial actions executed by our security team.
- Recommended measures for affected Data Principals to mitigate potential risks.
- Contact details of our designated Data Protection Officer.
9. Data Retention & Erasure
We retain personal data only for as long as necessary to satisfy the purposes for which it was collected or to comply with statutory legal, tax, and accounting requirements. Financial ledgers and invoices are retained for up to 8 years under the Central Goods and Services Tax Act (CGST). When the statutory purpose is satisfied, data is securely erased or permanently anonymized. See our Data Retention Policy.
10. Cross-Border Processing
Cehpoint processes personal data primarily on sovereign cloud infrastructure located in India. Where international processors or AI inference clusters outside India are leveraged, such transfers strictly comply with Section 16 of the DPDP Act 2023 and Government of India notifications, supported by Standard Contractual Clauses (SCCs) and binding confidentiality covenants.
11. Children's Data Protection (DPDP Section 9)
Cehpoint services are exclusively designed for enterprise businesses, professionals, and adults aged 18 and over. In strict compliance with Section 9 of the DPDP Act 2023:
- We do not knowingly process personal data of children (individuals under 18 years of age) without verifiable parental consent.
- We strictly prohibit and never undertake tracking, behavioral monitoring, or targeted advertising directed at children.
- We do not process personal data in any manner likely to cause detrimental effect on the well-being of a child.
12. Grievance Redressal & DPBI Escalation
Cehpoint has instituted a transparent grievance redressal mechanism under Section 13 of the DPDP Act and Rule 3(2) of the IT Rules 2021:
- Statutory Acknowledgment: Every grievance or DPR ticket is acknowledged within 24 hours.
- Resolution SLA: General complaints resolved within 15 days; complex data protection requests resolved within 30 days.
- Statutory Escalation to DPBI: If you are unsatisfied with our resolution or receive no response within the statutory window, you have the legal right to lodge a formal complaint before the Data Protection Board of India via their digital portal.
13. Registered Corporate Office & DPO Directory
For all statutory notices, legal correspondence, or regulatory inquiries, contact our official corporate establishment:
Legal Entity: CEHPOINT E-services (India)
Registered Corporate Office: Bolpur, Birbhum, West Bengal 731204, India
Goods & Services Tax Identification Number (GSTIN): 19ETGPB5153Q1Z5
Designated Grievance & Data Protection Officer: Jit Banerjee (Director / DPO)
Statutory Grievance Channel: grievance@cehpoint.co.in
CERT-In Emergency Escalation: certin-reporting@cehpoint.co.in
Customer Care: support@cehpoint.co.in · +91-90911-56095