Statutory Compliance · India

Data Protection Statement (DPDP Act 2023)

How Cehpoint complies with India's Digital Personal Data Protection Act, 2023 — offering 22 Scheduled Indian Languages notices, an interactive Data Principal Rights (DPR) intake portal, CERT-In 6-hour cybersecurity reporting, and statutory grievance redressal.

Effective Date: 15 July 2026 Statutory Authority: DPDP Act 2023 & IT Rules 2021 Registered Office: Bolpur, West Bengal 731204

This Data Protection Statement describes how CEHPOINT E-services ("Cehpoint", "we", "us") handles digital personal data in strict compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, the Information Technology Act, 2000, the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the CERT-In Cyber Security Directions, 2022. It complements our Privacy Policy and Grievance Redressal Policy.

1. Introduction & Legal Framework

We are dedicated to safeguarding the personal data of our users, enterprise clients, independent product testers, developers, and website visitors (collectively designated as Data Principals under Indian law). "Personal data" means any data about an individual who is identifiable by or in relation to such data.

All processing is founded on statutory notice, affirmative verifiable consent, or specified legitimate uses permitted under Section 7 of the DPDP Act 2023.

2. Cehpoint as Data Fiduciary & Processor

Our regulatory capacity is determined by the processing context:

3. Data Protection Principles

In adherence to global best practices and Indian statutory requirements, our platform architecture enforces six core tenets:

  1. Lawful, fair, and transparent processing — Personal data is processed exclusively for purposes explicitly notified prior to collection.
  2. Purpose limitation — Data collected for one specified purpose is never repurposed without fresh, itemized consent.
  3. Data minimisation — Only data strictly necessary for delivering the contracted engineering or platform service is requested.
  4. Data accuracy — Reasonable operational steps and self-service dashboards are maintained to keep records accurate and updated.
  5. Storage limitation — Data is retained strictly during the active lifecycle of the engagement and purged per statutory schedules.
  6. Integrity, confidentiality, and accountability — Enterprise-grade technical and organisational controls protect against unauthorized disclosure or loss.

4. Statutory Multilingual Notice (DPDP Section 5(3))

Pursuant to Section 5(3) of the DPDP Act 2023, every Data Principal has the statutory right to access their data protection and processing notice in English or any of the 22 Scheduled Languages specified in the Eighth Schedule to the Constitution of India.

Loading statutory notice...

5. Lawful Purposes of Processing

Personal data is processed solely under the following statutory grounds:

Category of Personal Data Specific Processing Purpose Statutory Basis (DPDP Act)
Identity & Profile (Name, email, mobile number, organization) Account creation, MFA authentication, client 360 dashboards, role-based access. Consent (Sec. 6) / Contractual Performance (Sec. 7(b))
Billing & Tax Data (GSTIN, invoicing address, PayU transaction IDs) Payment processing, tax invoicing, input tax credit validation, GST audits. Legal Obligation (Sec. 7(c) / CGST Act 2017)
Testing Marketplace Reports (Bug summaries, vulnerability telemetry) Facilitating bug bounties, tester payout disbursement, client validation. Contractual Performance & Consent
AI Platform Prompts & Documents (Grounding data, assistant inputs) Executing user queries via isolated RAG workflows, generating reports. Explicit User Request & Consent
Security Telemetry & Logs (IP addresses, user-agent, session IDs) Detecting brute-force attacks, DDoS mitigation, statutory CERT-In audit trails. Cybersecurity & System Integrity (Sec. 7(g))

6. Data Principal Rights & Self-Service Intake Portal

Under Chapter III (Sections 11 to 14) of the DPDP Act 2023, you have enforceable legal rights regarding your personal data. You may exercise them instantly through our interactive intake portal below or by emailing grievance@cehpoint.co.in.

Self-Service Data Principal Rights (DPR) Portal

Submit a statutory request for Access, Correction, Erasure, Consent Withdrawal, or Nomination. Every request receives an automated tracking ticket and statutory SLA acknowledgment.

Statutory SLA: Acknowledged within 24h · Resolved within 15–30 days

Track Existing Statutory Request

7. Technical & Organisational Safeguards

Under Section 8(5) of the DPDP Act 2023, Cehpoint implements reasonable security safeguards to prevent personal data breaches:

8. CERT-In 6-Hour Reporting & Personal Data Breach Protocol

In accordance with Section 70B of the Information Technology Act, 2000, the CERT-In Cyber Security Directions, 2022, and Section 8(6) of the DPDP Act 2023, Cehpoint maintains an active Computer Security Incident Response Protocol (CSIRP):

🚨 Statutory 6-Hour Cybersecurity Reporting Mandate

Under Direction 20(a) of the CERT-In Directions, any cybersecurity incident of statutory nature (including unauthorized system access, data leaks, ransomware, identity theft, or denial-of-service) is reported to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of notice.

In parallel, in the event of a verified personal data breach impacting Data Principals, Cehpoint will immediately notify the Data Protection Board of India (DPBI) and affected Data Principals with:

  1. The nature, scope, and estimated number of affected individuals.
  2. The likely consequences of the breach.
  3. The immediate containment and remedial actions executed by our security team.
  4. Recommended measures for affected Data Principals to mitigate potential risks.
  5. Contact details of our designated Data Protection Officer.

9. Data Retention & Erasure

We retain personal data only for as long as necessary to satisfy the purposes for which it was collected or to comply with statutory legal, tax, and accounting requirements. Financial ledgers and invoices are retained for up to 8 years under the Central Goods and Services Tax Act (CGST). When the statutory purpose is satisfied, data is securely erased or permanently anonymized. See our Data Retention Policy.

10. Cross-Border Processing

Cehpoint processes personal data primarily on sovereign cloud infrastructure located in India. Where international processors or AI inference clusters outside India are leveraged, such transfers strictly comply with Section 16 of the DPDP Act 2023 and Government of India notifications, supported by Standard Contractual Clauses (SCCs) and binding confidentiality covenants.

11. Children's Data Protection (DPDP Section 9)

Cehpoint services are exclusively designed for enterprise businesses, professionals, and adults aged 18 and over. In strict compliance with Section 9 of the DPDP Act 2023:

12. Grievance Redressal & DPBI Escalation

Cehpoint has instituted a transparent grievance redressal mechanism under Section 13 of the DPDP Act and Rule 3(2) of the IT Rules 2021:

13. Registered Corporate Office & DPO Directory

For all statutory notices, legal correspondence, or regulatory inquiries, contact our official corporate establishment:

Legal Entity: CEHPOINT E-services (India)

Registered Corporate Office: Bolpur, Birbhum, West Bengal 731204, India

Goods & Services Tax Identification Number (GSTIN): 19ETGPB5153Q1Z5

Designated Grievance & Data Protection Officer: Jit Banerjee (Director / DPO)

Statutory Grievance Channel: grievance@cehpoint.co.in

CERT-In Emergency Escalation: certin-reporting@cehpoint.co.in

Customer Care: support@cehpoint.co.in · +91-90911-56095

CEHPOINT E-services · Bolpur, Birbhum, West Bengal 731204, India (GSTIN: 19ETGPB5153Q1Z5). Statutory compliance queries: grievance@cehpoint.co.in. This document constitutes a legally binding compliance policy under the Digital Personal Data Protection Act, 2023.