Legal & Regulatory Compliance

Global Privacy Policy

How CEHPOINT collects, uses, protects, and governs your personal data across the AI platform, services portal, and product-testing marketplace β€” conforming to India's DPDP Act 2023, EU/UK GDPR, and California's CCPA/CPRA.

Effective Date: 15 July 2026 Jurisdiction: India, European Union, United Kingdom & USA (California) Registered Office: Bolpur, West Bengal, India

This Global Privacy Policy explains how CEHPOINT E-services ("Cehpoint", "we", "us", "our") collects, uses, discloses, and safeguards personal information when you interact with our websites, AI engineering services, client portal (cehpoint.co.in/app), testing marketplace, Cehpoint Card, developer APIs, or enterprise solutions. We act as a Data Fiduciary under India's DPDP Act 2023 and as a Data Controller under the EU/UK GDPR.

1. Scope & Legal Framework

This policy covers all visitors, clients, software developers, and independent testers across:

Our practices comply with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, the European Union's General Data Protection Regulation (Regulation (EU) 2016/679 - GDPR), the UK GDPR, and the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA).

2. Categories of Personal Data Collected

Data Category Specific Data Points Collected Source & Collection Channel
Account & Profile Full name, business email, phone number, company/organization name, job title, encrypted password hash, MFA credentials. Direct submission during registration or profile update.
Commercial & Billing Invoicing address, GSTIN, transaction receipts, payment gateway reference IDs (PayU / Stripe), Cehpoint Card transaction ledger. (Full card/bank details are processed directly by PCI-DSS certified gateways). Generated during transactions and checkout.
Usage & Telemetry IP address, browser user-agent, operating system, pages visited, session duration, clickstream telemetry, API query counts. Automated server logs and session cookies.
Customer Content & Prompts AI prompts, code snippets, project briefs, uploaded knowledge base documents, bug reports, and support chat transcripts. Directly uploaded or submitted by user into platform tools.

3. Lawful Bases & Purposes of Processing

We process personal data only when underpinned by a valid lawful basis:

4. Cookies & Tracking Technologies

We deploy strictly necessary cookies for session management, CSRF defense, and load balancing. Functional and analytical cookies are governed by our affirmative consent banner. We never sell cookie data or deploy behavioral cross-site tracking pixels. Review our comprehensive Cookie Policy.

5. AI Platform Data, Prompts & Isolation

When you interact with Cehpoint AI assistants, tools, or gateway endpoints:

6. Processors & Third-Party Transfers

We disclose personal data strictly on a need-to-know basis to vetted processors operating under contractually enforceable confidentiality and security covenants:

Processor Category Entities & Role Jurisdiction & Transfer Safeguards
Payment Gateways PayU Payments Pvt Ltd / Stripe (PCI-DSS compliant transaction processing). India / USA (Encrypted API, tokenized settlement).
Cloud Infrastructure Oracle Cloud Infrastructure (OCI) & Hetzner Cloud (Compute, storage, databases). India / Germany (ISO 27001, SOC 2, Standard Contractual Clauses).
Authentication & Mail Google Workspace (OAuth sign-in and transactional email relay). Global (EU-US Data Privacy Framework / Model Clauses).

7. Data Retention & Disposal

We retain personal data strictly for the duration necessary to deliver services or satisfy statutory rules. Tax and financial ledgers are retained for 8 years under the CGST Act. Inactive user accounts may be erased upon verified request or following our Data Retention Policy.

8. Data Principal & Subject Rights

Regardless of your geographical location, you may exercise your statutory rights by submitting a ticket on our Data Principal Rights Portal or emailing grievance@cehpoint.co.in. All requests are acknowledged within 24 hours.

9. European Union & UK GDPR Addendum

πŸ‡ͺπŸ‡Ί EEA & UK Data Subject Rights Addendum

If you are a resident of the European Economic Area (EEA) or the United Kingdom, Regulation (EU) 2016/679 (GDPR) and the UK Data Protection Act 2018 grant you specific statutory protections:

Article 6 Legal Bases Matrix:

  • Contractual Performance (Art. 6(1)(b)): Provisioning platform instances, client workspaces, and developer API keys.
  • Legitimate Interests (Art. 6(1)(f)): Hardening network infrastructure, auditing system reliability, and fraud detection.
  • Legal Obligation (Art. 6(1)(c)): Complying with cross-border tax records and statutory cybersecurity notifications.
  • Consent (Art. 6(1)(a)): Voluntary opt-in subscriptions and non-essential analytical cookies.

Your 8 Data Subject Rights (Articles 15–22):

  1. Right of Access (Art. 15): Obtain confirmation as to whether your data is being processed and receive a comprehensive copy.
  2. Right to Rectification (Art. 16): Require the prompt correction of inaccurate or incomplete personal records.
  3. Right to Erasure ("Right to be Forgotten", Art. 17): Request the permanent deletion of personal data when no overriding legitimate grounds exist.
  4. Right to Restriction of Processing (Art. 18): Restrict active processing while accuracy or legitimacy is verified.
  5. Right to Data Portability (Art. 20): Receive your personal data in a structured, commonly used, machine-readable format (JSON/CSV).
  6. Right to Object (Art. 21): Object at any time to processing predicated on legitimate interests or direct marketing.
  7. Rights Regarding Automated Decisions & Profiling (Art. 22): Right not to be subject to decisions based solely on automated processing that significantly affect you.
  8. Right to Lodge a Complaint: You have the right to lodge a complaint with your local EU Data Protection Authority or the UK Information Commissioner's Office (ico.org.uk).

International Data Transfers (Articles 44–49): Where data originating in the EEA or UK is transferred to India or third countries, such transfers are executed under the European Commission's Standard Contractual Clauses (SCCs) and UK International Data Transfer Addenda (IDTA), complemented by robust technical encryption measures.

10. California Privacy Rights (CCPA / CPRA Addendum)

πŸ‡ΊπŸ‡Έ California Consumer Privacy Act (CCPA / CPRA) Disclosure

This section applies exclusively to California residents under the California Consumer Privacy Act of 2018 (CCPA) as amended by the California Privacy Rights Act of 2020 (CPRA):

Notice at Collection & 12-Month Disclosure:

  • Identifiers Collected: Real name, email address, IP address, unique online identifier.
  • Commercial Information: Records of services purchased, platform credits, invoices.
  • Internet or Network Activity: Browsing telemetry, access timestamps, feature interactions.
  • Professional / Employment Information: Company name, job title, developer credentials.

🚫 "DO NOT SELL OR SHARE MY PERSONAL INFORMATION" PLEDGE:
CEHPOINT does NOT sell personal information for monetary consideration, nor do we share personal information for cross-context behavioral advertising. We have not sold or shared consumer personal information in the preceding 12 months.

California Resident Rights:

  • Right to Know & Access: Request disclosure of the specific pieces of personal information collected over the preceding 12 months.
  • Right to Delete: Request deletion of personal information collected from you, subject to statutory exceptions.
  • Right to Correct: Request correction of inaccurate personal records.
  • Right to Limit Sensitive Data: We do not use or disclose sensitive personal information for purposes other than those specified in Cal. Civ. Code Β§ 1798.121.
  • Right to Non-Discrimination: We will never deny services, charge different prices, or provide a disparate level of quality because you exercised your CCPA rights.

To exercise your California rights, email grievance@cehpoint.co.in with the subject line "CCPA Consumer Request" or submit via our online portal.

11. Technical & Cybersecurity Safeguards

CEHPOINT deploys robust defense-in-depth measures: end-to-end TLS 1.3 transport encryption, AES-256 database storage encryption, strict role-based access control, hashed passwords (bcrypt), automated penetration tests, and an isolated 10-minute Support Access ID framework. In the event of a cybersecurity incident, we report to CERT-In within 6 hours per statutory rules.

12. Protection of Minors

Our platform and engineering services are strictly directed to individuals aged 18 and older. We do not knowingly solicit, collect, or process personal data from children under 18 years of age without verifiable parental consent.

13. Corporate Office & Contact Directory

For inquiries, rights requests, or regulatory communications, reach our registered headquarters:

Entity Name: CEHPOINT E-services (India)

Registered Corporate Office: Bolpur, Birbhum, West Bengal 731204, India

Goods & Services Tax Identification Number (GSTIN): 19ETGPB5153Q1Z5

Data Protection Officer / Grievance Officer: Jit Banerjee (Director / DPO)

Data Protection Email: grievance@cehpoint.co.in / dpo@cehpoint.co.in

Corporate Support: support@cehpoint.co.in · +91-90911-56095

CEHPOINT E-services Β· Bolpur, Birbhum, West Bengal 731204, India (GSTIN: 19ETGPB5153Q1Z5). Regulatory inquiries: grievance@cehpoint.co.in.