Privacy Policy

Effective Date: August 26, 2026 • Last Updated: August 26, 2026

Section 1 — Who We Are

Kryptasys is the operator of DPDP Shield (shield.kryptasys.in), an assisted DPDPA 2023 compliance platform for Indian businesses. We help SMBs — including schools, hospitals, and retail businesses — assess and document their compliance posture under the Digital Personal Data Protection Act, 2023.

For any privacy-related query, contact us at: contact@kryptasys.in

Section 2 — What Data We Collect

2.1 Account Data
Name, work email address, and company name collected at signup.

2.2 Company Profile Data
Business sector, employee size, and Data Protection Officer (DPO) details provided during onboarding questionnaire.

2.3 Compliance Assessment Data
Questionnaire responses, compliance scores, evidence mappings, risk prioritization results, and generated gap reports. This data is linked to your account and retained as per Section 6.

2.4 LEAP v2 PII Scan Data
LEAP v2 is a browser-side forensic PII detection engine. It detects Aadhaar numbers, PAN, mobile numbers, email addresses, UPI IDs, and IFSC codes. It also supports tabular file scanning (Excel/CSV formats).
Raw files (log files, spreadsheets) uploaded for scanning are processed ENTIRELY within your browser and are NEVER transmitted to or stored on our servers. Only structured summary data — counts of detected PII pattern types — is stored in your account database for quota tracking and scan history. No actual PII values are stored by us.

2.5 Payment Data
Payments are processed entirely by Razorpay, our payment gateway partner. We do not store your credit card, debit card, UPI, or banking details. We store invoice metadata (plan type, amount, date, Razorpay order ID) for billing records.

2.6 Support Ticket Data
When you raise a support ticket, the content of your message, attachments (if any), and your account details are stored for the purpose of resolving your query. Support ticket data is retained for 12 months after ticket closure.

2.7 Identity Verification Data (Abuse Prevention)
To prevent trial abuse and maintain platform integrity, we store a permanently hashed record (salted SHA-256) of account identity signals at the time of signup. This record contains no readable personal data and cannot be reversed to identify you. It is used solely to detect and prevent fraudulent repeated trial registrations.

2.8 Audit Trail Data
Actions performed on your account (logins, scan submissions, consent records, rights requests) are logged in an append-only audit trail secured with SHA-256 integrity hashing. These logs are immutable and cannot be altered or deleted, including by Kryptasys staff.

2.9 Usage Data
Information about page visits and feature usage for product improvement. We do not use any third-party advertising or behavioral trackers.

Section 3 — How We Use Your Data

  • To deliver DPDPA compliance assessments, scorecards, gap reports, and recommended action plans.
  • To track LEAP v2 scan usage against your plan quota.
  • To process payments and generate PDF invoices via Razorpay.
  • To send transactional emails (account activation, invoice receipts, support updates) via Resend from no-reply@kryptasys.in and billing@kryptasys.in.
  • To send product updates and compliance news, subject to your explicit consent.
  • To detect and prevent fraudulent trial abuse and unauthorized access.
  • To maintain immutable audit trails for your own DPDPA compliance evidence.
  • To comply with regulatory obligations under applicable Indian law.

Section 4 — Data Storage & Security

  • All data is stored on Supabase PostgreSQL databases hosted in the AWS Mumbai (ap-south-1) region.
  • Your data resides entirely within Indian sovereign territory and does not leave India.
  • AES-256 encryption is enforced for data at rest. TLS 1.3 is enforced for all data in transit.
  • Row-Level Security (RLS) is enforced at the database level to ensure strict data isolation between tenants.
  • The platform is hardened against OWASP Top 10 vulnerabilities including brute-force lockout, XSS protection (DOMPurify), session security, and IDOR prevention.
  • Only authorized Kryptasys administrators can access support tickets and account data, solely for the purpose of providing support.

Section 5 — Cookies

DPDP Shield uses only one first-party HTTP session cookie: dpdp-shield-session. This cookie is strictly necessary for user authentication and maintaining your logged-in session. It is not used for advertising, tracking, or profiling purposes.

We do not use any third-party cookies, advertising cookies, or behavioral tracking cookies.

Section 6 — Data Retention

Data TypeRetention Period
Account & company profile data12 months after account closure
Compliance scan data & gap reports12 months after account closure
LEAP scan summary data12 months after account closure
Consent records5 years (DPDPA Section 6(10))
Audit trail logs5 years (immutable, append-only)
Support ticket data12 months after ticket closure
Payment & invoice records7 years (Indian accounting law)
Identity abuse-prevention hashIndefinite (no personal data, hash only)

You may request erasure of your account and associated personal data at any time, except for records we are legally required to retain (consent logs, payment records, audit trails).

Section 7 — Your Rights Under DPDPA 2023

As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following statutory rights:

  • Right to Access — Request a summary of personal data we hold and how it is processed (Section 11).
  • Right to Correction — Request correction of inaccurate, incomplete, or misleading data (Section 12).
  • Right to Erasure — Request deletion of personal data once the purpose of processing is fulfilled (Section 12).
  • Right to Withdraw Consent — Withdraw consent for non-essential processing at any time (Section 6).
  • Right to Grievance Redressal — Raise a complaint with us before escalating to the Data Protection Board of India (Section 13).
  • Right to Nominate — Nominate a person to exercise rights on your behalf in the event of your death or incapacity (Section 14).

To exercise any of these rights, submit a request via our Rights Portal at shield.kryptasys.in/rights, or email contact@kryptasys.in. We will respond within 30 days as required under DPDPA 2023.

Section 8 — Data Breach Notification

In the event of a personal data breach that is likely to result in harm to Data Principals, Kryptasys will:

  1. Notify the Data Protection Board of India as required under DPDPA Section 8(6).
  2. Notify affected users at their registered email address without undue delay.
  3. Provide details of the nature of the breach, data affected, and remediation steps taken.

Section 9 — Third-Party Sub-Processors

We share operational data with the following essential sub-processors to deliver the service:

Sub-ProcessorPurposeData Location
SupabaseCloud database hosting and user authenticationAWS Mumbai (ap-south-1), India
VercelApplication hosting and serverless computeGlobal edge (no personal data stored)
RazorpayPayment processing and invoice settlementIndia
ResendTransactional email deliveryUSA (email content only, no scan data)

We do not sell, rent, or lease your personal or company data to any third party for marketing or advertising purposes.

Section 10 — Contact & Grievance Redressal

Privacy inquiries: contact@kryptasys.in

Designated Grievance Officer:Vivek KumarKryptasys, Delhi NCR, IndiaEmail: contact@kryptasys.in

Grievances will be acknowledged within 48 hours and resolved within 30 days.