1. Designated Officers & Registered Office
In accordance with Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 8(9) / Section 13 of the Digital Personal Data Protection Act, 2023, CEHPOINT has designated a dedicated Grievance Officer and Data Protection Officer:
Designated Grievance Officer & Data Protection Officer: Jit Banerjee (Director / DPO)
Entity Name: CEHPOINT E-services (India)
Registered Corporate Office: Bolpur, Birbhum, West Bengal 731204, India
Goods & Services Tax Identification Number (GSTIN): 19ETGPB5153Q1Z5
Direct Statutory Email: grievance@cehpoint.co.in / dpo@cehpoint.co.in
Emergency Helpline: +91-90911-56095
2. Scope of Grievances
You may submit any grievance, complaint, or dispute concerning:
- Service Performance: Deliverables not matching specifications, service level agreements (SLAs), or testing marketplace bug reports.
- Billing & Payments: Disputed charges, input tax credit / GST invoices, wallet deductions, or Cehpoint Card statements.
- Digital Personal Data Protection: Requests for access, correction, erasure, nomination, or suspected unauthorized processing under the DPDP Act.
- Platform Content & Conduct: Allegations of unlawful content, copyright infringement, defamatory material, or partner firm misconduct.
- Cybersecurity & Account Access: Suspected compromise, brute-force activity, or unauthorized session access.
3. Online Grievance Intake Portal
To ensure transparent, timestamped tracking and statutory compliance, submit your grievance directly through our automated portal below:
Statutory Grievance & DPR Intake Desk
Every submission generates an immutable tracking ticket with instant 24-hour acknowledgment clock and assigned case officer.
Track Existing Grievance Ticket
4. Statutory Timelines & SLAs
| Grievance Category | Statutory Acknowledgment SLA | Maximum Resolution SLA | Governing Statute |
|---|---|---|---|
| General Grievance / Commercial Dispute | Within 24 Hours | Within 15 Days | IT Rules, 2021 (Rule 3(2)) |
| Unlawful Content Removal Order | Immediate (Within 4 Hours) | Within 36 Hours | IT Rules, 2021 (Rule 3(1)(d)) |
| Data Principal Rights (DPDP Act) | Within 24 Hours | Within 30 Days | DPDP Act 2023 (Sec. 13) |
| Cybersecurity Breach Incident | Immediate Containment | Within 6 Hours (CERT-In) | IT Act 2000 (Sec. 70B) / CERT-In 2022 |
5. Investigation & Redressal Process
- Intake & Ticketing: The grievance is registered in our database with a unique alphanumeric reference and logged with the complainant's IP and timestamp.
- 24-Hour Acknowledgment: Automated acknowledgment is dispatched to the complainant's email containing the ticket reference, assigned investigator, and statutory target date.
- Substantive Investigation: The Grievance Officer reviews all system audit logs, payment processor records, and relevant correspondence. Where a third-party partner is implicated, a written explanation is required within 48 hours.
- Written Resolution: A comprehensive written determination outlining findings, remedial actions executed, or rationale for non-acceptance is transmitted to the complainant.
6. Escalation to Appellate Tribunals & DPBI
If you are not satisfied with the determination of our Grievance Officer, or if a resolution is not provided within the prescribed statutory period, you have the legal right to escalate the matter:
- Data Protection Board of India (DPBI): For matters arising under the DPDP Act 2023, you may lodge a digital appeal before the DPBI under Section 13(3).
- Grievance Appellate Committee (GAC): Under Rule 3A of the IT Rules 2021, you may prefer an appeal against the Grievance Officer's decision within 30 days before the Central Government's Grievance Appellate Committee via gac.gov.in.
- CERT-In Reporting: Matters involving critical cybersecurity breaches may be referred to CERT-In at incident@cert-in.org.in.
7. Statutory Record Retention
In accordance with Rule 3(1)(h) of the IT Rules 2021 and CERT-In Directions 2022, CEHPOINT maintains complete, cryptographically verified audit records and correspondence of every grievance for a minimum period of 3 years from the date of closure, and server telemetry for 180 days.