Privacy Policy

Privacy Policy

This Privacy Policy explains how Decipher Consultancy Services ("we", "us", "our"), operating the dcomply platform, collects, uses, shares, and protects your personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Last Updated: April 5, 2026
Version 2.0
DPDP Act 2023 Compliant

1. About This Policy

This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules framed thereunder. It governs the collection, storage, processing, and transfer of personal data by Decipher Consultancy Services, the company behind the dcomply platform.

By accessing or using dcomply (accessible at dcomply.com), you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this policy, please do not use our services.

Scope: This policy applies to all users of the dcomply platform, including visitors to our website, registered users, trial users, and enterprise customers. It covers data collected through our website, platform, APIs, and any communication channels.

2. Data Fiduciary Information

Under the DPDP Act, the Data Fiduciary is the entity that determines the purpose and means of processing your personal data. For the dcomply platform:

Company Name
Decipher Consultancy Services
Platform
dcomply (dcomply.com)
Role under DPDP Act
Data Fiduciary (Section 2(i))
Registered Office
295, Block C, Sushant Lok III, Sector 57, Gurugram, Haryana - 122003
Grievance Officer
Subesh Kumar
Contact
+91 9911202099 | [email protected]

3. Personal Data We Collect

We collect personal data through various channels depending on how you interact with dcomply:

A. Registered Users (Platform)

  • Account Information: Full name, email address, phone number, job title, and organisation name provided during registration
  • Platform Usage Data: Compliance assessment responses, uploaded documents (privacy policies, contracts), audit reports generated, consent records managed, and DSR workflows initiated
  • Technical Data: IP address, browser type and version, device information, operating system, login timestamps, and session identifiers
  • Payment Information: Billing name, billing address, and payment method details (processed securely through Razorpay; we do not store card numbers)

B. Website Visitors

  • Analytics Data: Pages visited, time spent on pages, referral source, click patterns, and scroll depth
  • Contact Form Submissions: Name, email, phone number, company name, and enquiry details when you submit a form
  • Cookie Data: Information collected through cookies and similar tracking technologies (see Section 13)

C. Communication Data

  • Support Interactions: Correspondence via email, support tickets, or chat, including attachments and resolution notes
  • Marketing Preferences: Your opt-in/opt-out choices for newsletters, product updates, and promotional communications

Sensitive Personal Data: dcomply does not intentionally collect sensitive personal data (such as health data, biometrics, or caste information). If such data is incidentally present in documents you upload for compliance analysis, it is processed solely for that stated purpose and handled with additional safeguards.

4. Purpose of Processing

We process your personal data only for specific, clearly defined purposes:

PurposeDescriptionDPDP Act Basis
Service DeliveryOperating the dcomply platform, providing compliance tools, generating reports, and managing your accountSection 4 (Consent)
Compliance AssessmentAnalysing your uploaded documents and organisational data to generate DPDP compliance reports and recommendationsSection 4 (Consent)
Customer SupportResponding to your queries, resolving technical issues, and providing onboarding assistanceSection 7 (Legitimate Use)
Billing & PaymentsProcessing subscription payments, issuing invoices, managing refunds, and maintaining financial recordsSection 7 (Legitimate Use)
Product ImprovementAnalysing usage patterns (in aggregate) to improve platform features, fix bugs, and enhance user experienceSection 7 (Legitimate Use)
Legal ComplianceMeeting obligations under Indian law, responding to regulatory requests, and maintaining audit trailsSection 7 (Legitimate Use)
CommunicationSending transactional emails (account confirmations, billing receipts) and, with your consent, marketing communicationsSection 4 / Section 7
SecurityDetecting fraud, preventing unauthorised access, and protecting the integrity of our platform and user dataSection 7 (Legitimate Use)

We adhere to the principle of purpose limitation, your data will not be processed for any purpose beyond what is stated here without obtaining fresh consent.

5. Lawful Basis for Processing

Under the DPDP Act, we process personal data based on the following lawful grounds:

  • Consent (Section 4 & 6): Where you have given free, specific, informed, and unambiguous consent for processing your data for a stated purpose. You may withdraw consent at any time.
  • Legitimate Uses (Section 7): Where processing is necessary for purposes such as performing a contract with you, complying with legal obligations, responding to medical emergencies, or employment-related purposes.
  • State Instrumentality (Section 7(b)): Where processing is necessary for the State to provide benefits, services, or issue permits/licences (not applicable to dcomply's typical operations).

Data Minimisation: We only collect personal data that is strictly necessary for the stated purpose. We do not collect excessive or irrelevant data, in line with the data minimisation principle under the DPDP Act.

6. Your Rights as a Data Principal

Under the DPDP Act, you (the "Data Principal") have the following rights over your personal data:

Right to Access (Section 11)

You may request a summary of your personal data being processed by us, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your data has been shared.

Right to Correction (Section 11)

You may request correction of inaccurate or misleading personal data, completion of incomplete data, and updating of data that is no longer current.

Right to Erasure (Section 12)

You may request deletion of your personal data when it is no longer necessary for the purpose for which it was collected, or when you withdraw your consent.

Right to Withdraw Consent (Section 6(6))

You may withdraw your consent at any time with the same ease as it was given. Withdrawal does not affect the lawfulness of processing done prior to withdrawal.

Right to Grievance Redressal (Section 13)

You may raise a complaint with our Grievance Officer. We are obligated to acknowledge within 48 hours and resolve within 30 days. If unresolved, you may escalate to the Data Protection Board of India.

Right to Nominate (Section 14)

You may nominate another individual to exercise your rights under this policy in the event of your death or incapacity, as provided under Section 14 of the DPDP Act.

To exercise any of these rights, please contact our Grievance Officer at [email protected] or call +91 9911202099. We will respond within the timeframes prescribed by the DPDP Act.

8. Data Security Measures

We implement reasonable security safeguards as required under Section 8(4) of the DPDP Act to protect your personal data from unauthorised access, alteration, disclosure, or destruction:

  • Encryption at Rest: All stored data is encrypted using AES-256 encryption
  • Encryption in Transit: All data transmitted uses TLS 1.3 protocol
  • Access Control: Role-based access control (RBAC) with principle of least privilege
  • Multi-Factor Authentication: Available for all user accounts
  • Regular Audits: Periodic security assessments and vulnerability testing
  • Data Residency: Data stored on servers located in India
  • Incident Response: Documented incident response plan with defined escalation procedures
  • Employee Training: All team members undergo security awareness training and sign NDAs

For detailed information about our security practices, please visit our Security Page or Trust Centre.

9. Data Retention

We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our retention schedule:

Data CategoryRetention PeriodAfter Expiry
Account & Profile DataDuration of account + 90 daysPermanently deleted
Compliance Assessment Data3 years from last activityAnonymised or deleted
Uploaded DocumentsUntil deleted by user or 1 year after account closurePermanently deleted
Consent Records7 years (regulatory requirement)Archived then deleted
Payment & Billing Data8 years (as per Indian tax laws)Securely destroyed
Support Tickets2 years from resolutionAnonymised
Contact Form Submissions1 year from submissionPermanently deleted
Website Analytics26 monthsAggregated and anonymised
Security & Audit Logs3 yearsSecurely destroyed

Upon account deletion or consent withdrawal, we permanently delete your personal data within 30 days, except where retention is mandated by law.

10. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data. We may share your data with the following categories of third parties, solely for the purposes described:

Third PartyPurposeSafeguards
Cloud Infrastructure ProviderHosting and data storageData Processing Agreement, ISO 27001 certified, data stored in India
Payment Processor (Razorpay)Processing subscription paymentsPCI-DSS compliant, no card data stored on our servers
Email Service ProviderSending transactional and marketing emailsData Processing Agreement, encrypted transmission
Analytics ProviderUnderstanding website usage patternsAnonymised/aggregated data only

All third-party Data Processors are bound by written Data Processing Agreements that require them to:

  • Process data only on our instructions and for the specified purpose
  • Implement appropriate technical and organisational security measures
  • Not sub-contract processing without our prior written approval
  • Delete or return all personal data upon termination of the agreement
  • Assist us in complying with Data Principal rights requests

We may also disclose your data if required by law, court order, or governmental authority, or to protect our legal rights.

11. Cross-Border Data Transfers

Your personal data is primarily stored and processed on servers located in India. Where any transfer of data outside India is necessary (e.g., for email delivery or analytics), we ensure:

  • Transfers are made only to countries or territories not restricted by the Central Government under Section 16(1) of the DPDP Act
  • Appropriate contractual safeguards, including Data Processing Agreements, are in place with all overseas processors
  • The receiving entity maintains security standards equivalent to those required under the DPDP Act

Data Localisation: All primary customer data, compliance assessments, and uploaded documents are stored exclusively on servers within India, in compliance with data localisation requirements.

12. Children's Data Protection

dcomply is a B2B compliance platform designed for business use. We do not knowingly collect personal data from children under the age of 18 years. In compliance with Section 9 of the DPDP Act:

  • We require verifiable parental or guardian consent before processing any child's personal data
  • We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children
  • We do not undertake any processing that could cause detrimental effect on the well-being of a child
  • If we become aware that a child's data has been collected without proper consent, we will delete it immediately

If you believe we have inadvertently collected a child's personal data, please contact our Grievance Officer immediately.

13. Cookies & Tracking Technologies

Our website and platform use cookies and similar technologies to enhance your experience:

Types of Cookies We Use

  • Essential Cookies: Required for the platform to function (authentication, session management, security). These cannot be disabled.
  • Analytics Cookies: Help us understand how visitors interact with our website (page views, traffic sources, user journeys). Collected in aggregate form.
  • Functional Cookies: Remember your preferences such as language, display settings, and recently viewed pages.
  • Marketing Cookies: Used with your explicit consent to deliver relevant advertisements and measure campaign effectiveness. You can opt out at any time.

Managing Cookies

You can manage your cookie preferences through our cookie consent banner displayed on your first visit. You may also configure your browser to block or delete cookies. Note that blocking essential cookies may impair platform functionality.

14. Data Breach Notification

In the event of a personal data breach, we follow the notification requirements under Section 8(6) of the DPDP Act:

  • Board Notification: We will notify the Data Protection Board of India about the breach in the prescribed form and manner
  • Individual Notification: We will inform affected Data Principals about the breach, its nature, the data involved, and the remedial measures taken
  • Breach Details: Notifications will include the nature of the breach, approximate number of affected individuals, likely consequences, and the measures taken to mitigate the impact
  • Breach Register: We maintain a comprehensive register of all data breaches, including those that do not meet the notification threshold, for internal audit purposes

15. Your Duties as a Data Principal

Under Section 15 of the DPDP Act, Data Principals also have certain duties:

  • You must provide accurate and complete information when submitting personal data to us. Do not provide false or misleading data.
  • You must not impersonate another person when providing personal data.
  • You must not suppress material information when exercising your rights (e.g., the right to correction or erasure).
  • You must not file false or frivolous complaints with the Data Protection Board.
  • You must comply with all applicable laws when using dcomply and providing your data.

Non-compliance with these duties may result in penalties of up to Rs. 10,000 under the DPDP Act.

16. Grievance Officer

In accordance with the DPDP Act, we have appointed a Grievance Officer to address your concerns regarding your personal data:

Subesh Kumar. Grievance Officer
[email protected] +91 9911202099 295, Block C, Sushant Lok III, Sector 57, Gurugram, Haryana - 122003

Resolution Process

  • Acknowledgement: We will acknowledge your complaint within 48 hours of receipt
  • Investigation: We will investigate your concern thoroughly and keep you informed of progress
  • Resolution: We aim to resolve all grievances within 30 days of acknowledgement
  • Escalation: If you are not satisfied with our resolution, you may file a complaint with the Data Protection Board of India as per the procedure laid down in the DPDP Act

17. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes:

  • We will update the "Last Updated" date at the top of this policy
  • We will notify registered users via email for significant changes
  • We will display a prominent notice on the dcomply platform
  • Where required under the DPDP Act, we will seek fresh consent for new processing activities

We encourage you to review this policy periodically. Your continued use of dcomply after changes are published constitutes acceptance of the updated policy.

Questions About Your Privacy?

We take your data privacy seriously. If you have any questions or concerns, our Grievance Officer is here to help.