Privacy Policy
Last updated 31 August 2026 · Cypliance, Ahmedabad, Gujarat, India
This policy explains what we collect, why, who else sees it, and what you can ask us to do about it. It covers cypliance.com and the Cypliance service.
Who is responsible
Cypliance is the data controller — under Indian law, the Data Fiduciary — for the personal data described here. Reach us at support@cypliance.com.
What we collect and why
| Data | Why we hold it | Kept for |
|---|---|---|
| Name, email, company, phone | To create your account, deliver reports, and contact you about a scan | While your account is open, then 12 months |
| Password, stored only as a hash | To sign you in | While your account is open |
| Two-factor secret and backup codes | To protect the account holding your reports | Until you turn two-factor off |
| The systems you asked us to test, and your authorisation record — including the signer's name, role, time, IP address and browser | Proof that testing was authorised. This is a legal record and we cannot operate without it | 7 years |
| Scan results and findings about your systems | To produce and re-serve your reports | While your account is open, then 12 months |
| Payment records — plan, amount, currency, provider reference, invoice | To fulfil your purchase and meet tax and accounting obligations | 8 years, as Indian tax law requires |
| Server logs — IP address, request, time | Security, abuse prevention, debugging | 90 days |
| Support messages you send us or the assistant | To answer you | 24 months |
We do not use advertising cookies, we do not track you across other websites, and we do not sell personal data to anyone.
Why we are allowed to hold it
- To perform our contract with you — your account, your scans, your reports.
- Legal obligation — invoices and tax records.
- Legitimate interests — keeping the service secure, preventing abuse, and holding evidence that testing was authorised. Without an authorisation record, a security testing service cannot responsibly exist.
Who else sees your data
We use a small number of processors, each for one job:
| Who | What they receive | Where |
|---|---|---|
| Razorpay | Payment details for rupee transactions. Card data goes directly to them and never passes through our servers | India |
| Stripe | Payment details for dollar and euro transactions, on the same basis | USA / EU |
| Google Workspace | Email we send you and email you send us | USA / EU |
| Oracle Cloud | Hosting of the service and its database | India |
| AI model providers | Text from findings, for summarising and explaining them. Never your credentials or your customers' data | USA |
We disclose data to anyone else only where the law requires it, and we will tell you unless we are legally barred from doing so.
Transfers outside India
Some processors above operate outside India. Where data moves internationally we rely on the provider's standard contractual clauses and equivalent safeguards. If you are in the EU or UK, those clauses are the transfer mechanism.
Findings about your systems
Scan results describe exactly how your systems could be attacked. We treat them as confidential: they are visible only to your account, they are not used to train any AI model, and they are never shared with another customer or published as research without your separate written permission.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, or stop a particular use of it. Write to support@cypliance.com and we will respond within 30 days.
Two limits worth stating honestly: we cannot delete invoices we are legally required to keep, and we cannot delete an authorisation record while it may still be needed to show that testing was lawful. Everything else can go.
If you are in the EU or UK you may complain to your data protection authority. In India you may complain to the Data Protection Board once it is constituted under the Digital Personal Data Protection Act, 2023.
Security
Passwords are stored as salted PBKDF2-HMAC-SHA256 hashes, never in readable form. Session tokens are stored only as hashes. Traffic is encrypted in transit. Two-factor authentication is available and we encourage every account to use it. Access to production data is limited to those who need it to run the service.
If a breach affects your personal data we will notify you and the relevant authority as required by law.
Children
The service is for organisations and is not directed at anyone under 18. We do not knowingly collect children's data.
Changes
We will post any change here and, where it materially affects you, email account holders before it takes effect.