This Global Privacy Policy explains how CEHPOINT E-services ("Cehpoint", "we", "us", "our") collects, uses, discloses, and safeguards personal information when you interact with our websites, AI engineering services, client portal (cehpoint.co.in/app), testing marketplace, Cehpoint Card, developer APIs, or enterprise solutions. We act as a Data Fiduciary under India's DPDP Act 2023 and as a Data Controller under the EU/UK GDPR.
1. Scope & Legal Framework
This policy covers all visitors, clients, software developers, and independent testers across:
- AI & Automation Platform: Multi-agent workflows, autonomous assistants, document reader tools, RAG grounding databases, and developer gateway APIs.
- Services Portal & Client 360: Project scopes, milestone tracking, 10-minute Support Access ID authentication, invoicing, and wallet credits.
- Product Testing Marketplace: Coordinated vulnerability disclosure, bug bounty submissions, and tester identity verification.
Our practices comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the European Union's General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).
2. Categories of Personal Data Collected
| Data Category | Specific Data Points Collected | Source & Collection Channel |
|---|---|---|
| Account & Profile | Full name, business email, phone number, company/organization name, job title, encrypted password hash, MFA credentials. | Direct submission during registration or profile update. |
| Commercial & Billing | Invoicing address, GSTIN, transaction receipts, payment gateway reference IDs (PayU / Stripe), Cehpoint Card transaction ledger. (Full card/bank details are processed directly by PCI-DSS certified gateways). | Generated during transactions and checkout. |
| Usage & Telemetry | IP address, browser user-agent, operating system, pages visited, session duration, clickstream telemetry, API query counts. | Automated server logs and session cookies. |
| Customer Content & Prompts | AI prompts, code snippets, project briefs, uploaded knowledge base documents, bug reports, and support chat transcripts. | Directly uploaded or submitted by user into platform tools. |
3. Lawful Bases & Purposes of Processing
We process personal data only when underpinned by a valid lawful basis:
- Performance of Contract: To provision your user account, execute contracted AI development or penetration testing, issue billing statements, and provide customer support.
- Affirmative Consent: Where you opt in to receive marketing briefings, subscribe to platform notifications, or upload custom datasets for AI model grounding.
- Legal & Statutory Obligations: Complying with Indian GST tax invoicing mandates (CGST Act 2017), CERT-In 180-day log preservation directions, and judicial orders.
- Legitimate Interests: Protecting platform cybersecurity, mitigating brute-force abuse, optimizing server capacity, and preventing fraudulent transactions.
4. Cookies & Tracking Technologies
We deploy strictly necessary cookies for session management, CSRF defense, and load balancing. Functional and analytical cookies are governed by our affirmative consent banner. We never sell cookie data or deploy behavioral cross-site tracking pixels. Review our comprehensive Cookie Policy.
5. AI Platform Data, Prompts & Isolation
When you interact with Cehpoint AI assistants, tools, or gateway endpoints:
- Tenant Isolation: Your prompts and custom vector knowledge bases are logically isolated to your tenant organization. Data from one client is never mixed with another.
- No Model Training on Customer Data: We do NOT use your proprietary enterprise prompts, documents, or client bug reports to train public AI foundation models.
- Third-Party Inference: Where external frontier model APIs (e.g. Google Gemini, OpenAI, Anthropic) are utilized, transmissions are encrypted via TLS 1.3 and bound by zero-data-retention enterprise terms where supported.
6. Processors & Third-Party Transfers
We disclose personal data strictly on a need-to-know basis to vetted processors operating under contractually enforceable confidentiality and security covenants:
| Processor Category | Entities & Role | Jurisdiction & Transfer Safeguards |
|---|---|---|
| Payment Gateways | PayU Payments Pvt Ltd / Stripe (PCI-DSS compliant transaction processing). | India / USA (Encrypted API, tokenized settlement). |
| Cloud Infrastructure | Oracle Cloud Infrastructure (OCI) & Hetzner Cloud (Compute, storage, databases). | India / Germany (ISO 27001, SOC 2, Standard Contractual Clauses). |
| Authentication & Mail | Google Workspace (OAuth sign-in and transactional email relay). | Global (EU-US Data Privacy Framework / Model Clauses). |
7. Data Retention & Disposal
We retain personal data strictly for the duration necessary to deliver services or satisfy statutory rules. Tax and financial ledgers are retained for 8 years under the CGST Act. Inactive user accounts may be erased upon verified request or following our Data Retention Policy.
8. Data Principal & Subject Rights
Regardless of your geographical location, you may exercise your statutory rights by submitting a ticket on our Data Principal Rights Portal or emailing grievance@cehpoint.co.in. All requests are acknowledged within 24 hours.
9. European Union & UK GDPR Addendum
πͺπΊ EEA & UK Data Subject Rights Addendum
If you are a resident of the European Economic Area (EEA) or the United Kingdom, Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018 grant you specific statutory protections:
Article 6 Legal Bases Matrix:
- Contractual Performance (Art. 6(1)(b)): Provisioning platform instances, client workspaces, and developer API keys.
- Legitimate Interests (Art. 6(1)(f)): Hardening network infrastructure, auditing system reliability, and fraud detection.
- Legal Obligation (Art. 6(1)(c)): Complying with cross-border tax records and statutory cybersecurity notifications.
- Consent (Art. 6(1)(a)): Voluntary opt-in subscriptions and non-essential analytical cookies.
Your 8 Data Subject Rights (Articles 15β22):
- Right of Access (Art. 15): Obtain confirmation as to whether your data is being processed and receive a comprehensive copy.
- Right to Rectification (Art. 16): Require the prompt correction of inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten", Art. 17): Request the permanent deletion of personal data when no overriding legitimate grounds exist.
- Right to Restriction of Processing (Art. 18): Restrict active processing while accuracy or legitimacy is verified.
- Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV).
- Right to Object (Art. 21): Object at any time to processing predicated on legitimate interests or direct marketing.
- Rights Regarding Automated Decisions & Profiling (Art. 22): Right not to be subject to decisions based solely on automated processing that significantly affect you.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local EU Data Protection Authority or the UK Information Commissioner's Office (ico.org.uk).
International Data Transfers (Articles 44β49): Where data originating in the EEA or UK is transferred to India or third countries, such transfers are executed under the European Commission's Standard Contractual Clauses (SCCs) and UK International Data Transfer Addenda (IDTA), complemented by robust technical encryption measures.
10. California Privacy Rights (CCPA / CPRA Addendum)
πΊπΈ California Consumer Privacy Act (CCPA / CPRA) Disclosure
This section applies exclusively to California residents under the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA):
Notice at Collection & 12-Month Disclosure:
- Identifiers Collected: Real name, email address, IP address, unique online identifier.
- Commercial Information: Records of services purchased, platform credits, invoices.
- Internet or Network Activity: Browsing telemetry, access timestamps, feature interactions.
- Professional / Employment Information: Company name, job title, developer credentials.
π« "DO NOT SELL OR SHARE MY PERSONAL INFORMATION" PLEDGE:
CEHPOINT does NOT sell personal information for monetary consideration, nor do we share personal information for cross-context behavioral advertising. We have not sold or shared consumer personal information in the preceding 12 months.
California Resident Rights:
- Right to Know & Access: Request disclosure of the specific pieces of personal information collected over the preceding 12 months.
- Right to Delete: Request deletion of personal information collected from you, subject to statutory exceptions.
- Right to Correct: Request correction of inaccurate personal records.
- Right to Limit Sensitive Data: We do not use or disclose sensitive personal information for purposes other than those specified in Cal. Civ. Code Β§ 1798.121.
- Right to Non-Discrimination: We will never deny services, charge different prices, or provide a disparate level of quality because you exercised your CCPA rights.
To exercise your California rights, email grievance@cehpoint.co.in with the subject line "CCPA Consumer Request" or submit via our online portal.
11. Technical & Cybersecurity Safeguards
CEHPOINT deploys robust defense-in-depth measures: end-to-end TLS 1.3 transport encryption, AES-256 database storage encryption, strict role-based access control, hashed passwords (bcrypt), automated penetration tests, and an isolated 10-minute Support Access ID framework. In the event of a cybersecurity incident, we report to CERT-In within 6 hours per statutory rules.
12. Protection of Minors
Our platform and engineering services are strictly directed to individuals aged 18 and older. We do not knowingly solicit, collect, or process personal data from children under 18 years of age without verifiable parental consent.
13. Corporate Office & Contact Directory
For inquiries, rights requests, or regulatory communications, reach our registered headquarters:
Entity Name: CEHPOINT E-services (India)
Registered Corporate Office: Bolpur, Birbhum, West Bengal 731204, India
Goods & Services Tax Identification Number (GSTIN): 19ETGPB5153Q1Z5
Data Protection Officer / Grievance Officer: Jit Banerjee (Director / DPO)
Data Protection Email: grievance@cehpoint.co.in / dpo@cehpoint.co.in
Corporate Support: support@cehpoint.co.in · +91-90911-56095