Privacy Policy

Privacy Policy

This Privacy Policy explains how Decipher Consultancy Services ("we", "us", "our"), operating the dcomply platform, collects, uses, shares, and protects your personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act").

Last Updated: September 15, 2026
Version 2.1
DPDP Act 2023 Compliant

1. About This Policy

This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules framed thereunder. It governs the collection, storage, processing, and transfer of personal data by Decipher Consultancy Services, the company behind the dcomply platform.

By accessing or using dcomply (accessible at dcomply.com), you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this policy, please do not use our services.

Scope: This policy applies to all users of the dcomply ecosystem, including dcomply.in (marketing site), app.dcomply.in (compliance platform), and academy.dcomply.in (online learning). It covers visitors, registered users, trial users, enterprise customers, and academy learners, and applies to data collected through our websites, platform, APIs, and any communication channels.

2. Data Fiduciary Information

Under the DPDP Act, the Data Fiduciary is the entity that determines the purpose and means of processing your personal data. For the dcomply platform:

Company Name
Decipher Consultancy Services
Platform
dcomply (dcomply.com)
Role under DPDP Act
Data Fiduciary (Section 2(i))
Registered Office
295, Block C, Sushant Lok III, Sector 57, Gurugram, Haryana - 122003
Grievance Officer
Subesh Kumar
Contact
+91 9911202099 | [email protected]

3. Personal Data We Collect

We collect personal data through various channels depending on how you interact with dcomply:

A. Registered Users (Platform)

  • Account Information: Full name, email address, phone number, job title, and organisation name provided during registration
  • Platform Usage Data: Compliance assessment responses, uploaded documents (privacy policies, contracts), audit reports generated, consent records managed, and DSR workflows initiated
  • Technical Data: IP address, browser type and version, device information, operating system, login timestamps, and session identifiers
  • Payment Information: Billing name, billing address, and payment method details (processed securely through Razorpay; we do not store card numbers)

B. Website Visitors

  • Analytics Data: Pages visited, time spent on pages, referral source, click patterns, and scroll depth
  • Contact Form Submissions: Name, email, phone number, company name, and enquiry details when you submit a form
  • Cookie Data: Information collected through cookies and similar tracking technologies (see Section 13)

C. Communication Data

  • Support Interactions: Correspondence via email, support tickets, or chat, including attachments and resolution notes
  • Marketing Preferences: Your opt-in/opt-out choices for newsletters, product updates, and promotional communications

D. Academy Learners (academy.dcomply.in)

  • Enrolment Information: Full name (as it should appear on your certificate), email address, phone number, and organisation name
  • GST Billing Details: Billing address, city, state, and GSTIN (where you request a GST tax invoice). These fields are mandatory under Indian GST law for issuing a valid invoice
  • Learning Records: Course enrolments, lessons viewed, progress percentage, exam attempts, exam scores, and time spent
  • Certificate Records: Certificate credential UID, issue date, course title, learner name as printed, and the publicly verifiable certificate URL
  • Payment References: Razorpay payment identifier and Zoho invoice identifier (linked to your enrolment; we do not store card numbers or CVV)
  • Coupon Usage: Coupon codes redeemed and any partner attribution associated with your enrolment

Sensitive Personal Data: dcomply does not intentionally collect sensitive personal data (such as health data, biometrics, or caste information). If such data is incidentally present in documents you upload for compliance analysis, it is processed solely for that stated purpose and handled with additional safeguards.

4. Purpose of Processing

We process your personal data only for specific, clearly defined purposes:

PurposeDescriptionDPDP Act Basis
Service DeliveryOperating the dcomply platform, providing compliance tools, generating reports, and managing your accountSection 4 (Consent)
Compliance AssessmentAnalysing your uploaded documents and organisational data to generate DPDP compliance reports and recommendationsSection 4 (Consent)
Customer SupportResponding to your queries, resolving technical issues, and providing onboarding assistanceSection 7 (Legitimate Use)
Billing & PaymentsProcessing subscription payments, issuing invoices, managing refunds, and maintaining financial recordsSection 7 (Legitimate Use)
Product ImprovementAnalysing usage patterns (in aggregate) to improve platform features, fix bugs, and enhance user experienceSection 7 (Legitimate Use)
Legal ComplianceMeeting obligations under Indian law, responding to regulatory requests, and maintaining audit trailsSection 7 (Legitimate Use)
CommunicationSending transactional emails (account confirmations, billing receipts) and, with your consent, marketing communicationsSection 4 / Section 7
SecurityDetecting fraud, preventing unauthorised access, and protecting the integrity of our platform and user dataSection 7 (Legitimate Use)

We adhere to the principle of purpose limitation, your data will not be processed for any purpose beyond what is stated here without obtaining fresh consent.

5. Lawful Basis for Processing

Under the DPDP Act, we process personal data based on the following lawful grounds:

  • Consent (Section 4 & 6): Where you have given free, specific, informed, and unambiguous consent for processing your data for a stated purpose. You may withdraw consent at any time.
  • Legitimate Uses (Section 7): Where processing is necessary for purposes such as performing a contract with you, complying with legal obligations, responding to medical emergencies, or employment-related purposes.
  • State Instrumentality (Section 7(b)): Where processing is necessary for the State to provide benefits, services, or issue permits/licences (not applicable to dcomply's typical operations).

Data Minimisation: We only collect personal data that is strictly necessary for the stated purpose. We do not collect excessive or irrelevant data, in line with the data minimisation principle under the DPDP Act.

6. Your Rights as a Data Principal

Under the DPDP Act, you (the "Data Principal") have the following rights over your personal data:

Right to Access (Section 11)

You may request a summary of your personal data being processed by us, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your data has been shared.

Right to Correction (Section 11)

You may request correction of inaccurate or misleading personal data, completion of incomplete data, and updating of data that is no longer current.

Right to Erasure (Section 12)

You may request deletion of your personal data when it is no longer necessary for the purpose for which it was collected, or when you withdraw your consent.

Right to Withdraw Consent (Section 6(6))

You may withdraw your consent at any time with the same ease as it was given. Withdrawal does not affect the lawfulness of processing done prior to withdrawal.

Right to Grievance Redressal (Section 13)

You may raise a complaint with our Grievance Officer. We are obligated to acknowledge within 48 hours and resolve within 30 days. If unresolved, you may escalate to the Data Protection Board of India.

Right to Nominate (Section 14)

You may nominate another individual to exercise your rights under this policy in the event of your death or incapacity, as provided under Section 14 of the DPDP Act.

To exercise any of these rights, please contact our Grievance Officer at [email protected] or call +91 9911202099. We will respond within the timeframes prescribed by the DPDP Act.

8. Data Security Measures

We implement reasonable security safeguards as required under Section 8(4) of the DPDP Act to protect your personal data from unauthorised access, alteration, disclosure, or destruction:

  • Encryption at Rest: All stored data is encrypted using AES-256 encryption
  • Encryption in Transit: All data transmitted uses TLS 1.3 protocol
  • Access Control: Role-based access control (RBAC) with principle of least privilege
  • Multi-Factor Authentication: Available for all user accounts
  • Regular Audits: Periodic security assessments and vulnerability testing
  • Data Residency: Data stored on servers located in India
  • Incident Response: Documented incident response plan with defined escalation procedures
  • Employee Training: All team members undergo security awareness training and sign NDAs

For detailed information about our security practices, please visit our Security Page or Trust Centre.

9. Data Retention

We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our retention schedule:

Data CategoryRetention PeriodAfter Expiry
Account & Profile DataDuration of account + 90 daysPermanently deleted
Compliance Assessment Data3 years from last activityAnonymised or deleted
Uploaded DocumentsUntil deleted by user or 1 year after account closurePermanently deleted
Consent Records7 years (regulatory requirement)Archived then deleted
Payment & Billing Data8 years (as per Indian tax laws)Securely destroyed
Support Tickets2 years from resolutionAnonymised
Contact Form Submissions1 year from submissionPermanently deleted
Website Analytics26 monthsAggregated and anonymised
Security & Audit Logs3 yearsSecurely destroyed
Academy Enrolment & ProgressLifetime of the certificate (for public verification)Redacted on request (see Section 17)
Academy Exam Attempts3 years from last attemptAnonymised or deleted
Academy CertificatesRetained indefinitely for public credential verificationName redaction available on request; UID + course + issue date preserved

Upon account deletion or consent withdrawal, we permanently delete your personal data within 30 days, except where retention is mandated by law or, for academy certificates, where retention is necessary to preserve the integrity of the public credential-verification system (see Section 17).

10. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your personal data. We may share your data with the following categories of third parties, solely for the purposes described:

Third PartyPurposeSafeguards
Cloud Infrastructure ProviderHosting and data storageData Processing Agreement, ISO 27001 certified, data stored in India
Payment Processor (Razorpay)Processing subscription paymentsPCI-DSS compliant, no card data stored on our servers
Email Service ProviderSending transactional and marketing emailsData Processing Agreement, encrypted transmission
Analytics ProviderUnderstanding website usage patternsAnonymised/aggregated data only
Zoho Books (Zoho Corporation)Generating GST-compliant tax invoices for academy course purchases and platform subscriptionsIndia-region data centre, contact and invoice data only, no card data

All third-party Data Processors are bound by written Data Processing Agreements that require them to:

  • Process data only on our instructions and for the specified purpose
  • Implement appropriate technical and organisational security measures
  • Not sub-contract processing without our prior written approval
  • Delete or return all personal data upon termination of the agreement
  • Assist us in complying with Data Principal rights requests

We may also disclose your data if required by law, court order, or governmental authority, or to protect our legal rights.

11. Cross-Border Data Transfers

Your personal data is primarily stored and processed on servers located in India. Where any transfer of data outside India is necessary (e.g., for email delivery or analytics), we ensure:

  • Transfers are made only to countries or territories not restricted by the Central Government under Section 16(1) of the DPDP Act
  • Appropriate contractual safeguards, including Data Processing Agreements, are in place with all overseas processors
  • The receiving entity maintains security standards equivalent to those required under the DPDP Act

Data Localisation: All primary customer data, compliance assessments, and uploaded documents are stored exclusively on servers within India, in compliance with data localisation requirements.

12. Children's Data Protection

dcomply is a B2B compliance platform designed for business use. We do not knowingly collect personal data from children under the age of 18 years. In compliance with Section 9 of the DPDP Act:

  • We require verifiable parental or guardian consent before processing any child's personal data
  • We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children
  • We do not undertake any processing that could cause detrimental effect on the well-being of a child
  • If we become aware that a child's data has been collected without proper consent, we will delete it immediately

If you believe we have inadvertently collected a child's personal data, please contact our Grievance Officer immediately.

13. Cookies & Tracking Technologies

Our website and platform use cookies and similar technologies to enhance your experience:

Types of Cookies We Use

  • Essential Cookies: Required for the platform to function (authentication, session management, security). These cannot be disabled.
  • Analytics Cookies: Help us understand how visitors interact with our website (page views, traffic sources, user journeys). Collected in aggregate form.
  • Functional Cookies: Remember your preferences such as language, display settings, and recently viewed pages.
  • Marketing Cookies: Used with your explicit consent to deliver relevant advertisements and measure campaign effectiveness. You can opt out at any time.

Managing Cookies

You can manage your cookie preferences through our cookie consent banner displayed on your first visit. You may also configure your browser to block or delete cookies. Note that blocking essential cookies may impair platform functionality.

14. Data Breach Notification

In the event of a personal data breach, we follow the notification requirements under Section 8(6) of the DPDP Act:

  • Board Notification: We will notify the Data Protection Board of India about the breach in the prescribed form and manner
  • Individual Notification: We will inform affected Data Principals about the breach, its nature, the data involved, and the remedial measures taken
  • Breach Details: Notifications will include the nature of the breach, approximate number of affected individuals, likely consequences, and the measures taken to mitigate the impact
  • Breach Register: We maintain a comprehensive register of all data breaches, including those that do not meet the notification threshold, for internal audit purposes

15. Your Duties as a Data Principal

Under Section 15 of the DPDP Act, Data Principals also have certain duties:

  • You must provide accurate and complete information when submitting personal data to us. Do not provide false or misleading data.
  • You must not impersonate another person when providing personal data.
  • You must not suppress material information when exercising your rights (e.g., the right to correction or erasure).
  • You must not file false or frivolous complaints with the Data Protection Board.
  • You must comply with all applicable laws when using dcomply and providing your data.

Non-compliance with these duties may result in penalties of up to Rs. 10,000 under the DPDP Act.

16. Grievance Officer

In accordance with the DPDP Act, we have appointed a Grievance Officer to address your concerns regarding your personal data:

Subesh Kumar. Grievance Officer
[email protected] +91 9911202099 295, Block C, Sushant Lok III, Sector 57, Gurugram, Haryana - 122003

Resolution Process

  • Acknowledgement: We will acknowledge your complaint within 48 hours of receipt
  • Investigation: We will investigate your concern thoroughly and keep you informed of progress
  • Resolution: We aim to resolve all grievances within 30 days of acknowledgement
  • Escalation: If you are not satisfied with our resolution, you may file a complaint with the Data Protection Board of India as per the procedure laid down in the DPDP Act

17. Academy Learners & Certificates

This section supplements the rest of this Privacy Policy for users of academy.dcomply.in, our online learning platform. The general provisions above (rights, security, breach notification, grievance) apply equally; the notes below address academy-specific practices.

17.1 What We Collect at Enrolment

See Section 3(D) above for the full list. In short: your name (as it should appear on your certificate), email, phone, organisation, GST billing details (address, city, state, GSTIN), payment references (Razorpay + Zoho invoice IDs), learning progress, exam attempts, and certificate records.

17.2 Why Certificate Records Are Retained Longer

Academy certificates carry a publicly verifiable credential URL that anyone (employers, regulators, clients) can use to confirm authenticity. To keep this verification system trustworthy, we retain certificate records (credential UID, course title, learner name as printed, issue date) indefinitely, even after you close your academy account.

This retention is necessary for the legitimate use of preserving the integrity of a public credential system on which third parties rely.

17.3 Your Right to Name Redaction on a Certificate

You may, at any time, request that your name be redacted from a certificate record. On such a request:

  • Your name will be removed from the public certificate page and replaced with a redaction notice
  • The credential UID, course title, and issue date remain visible so the underlying credential can still be verified
  • Enrolment and progress records tied to your account will be deleted or anonymised
  • Redaction is irreversible — we cannot restore the certificate to its original form after redaction

To request redaction, email our Grievance Officer at [email protected] with the certificate credential UID.

17.4 GST Billing Data

When you request a GST tax invoice, your billing address, city, state, and GSTIN are collected and shared with Zoho Books to generate a compliant invoice. This data is retained for 8 years as required under Indian tax law, independently of any account deletion request.

17.5 Marketing to Academy Learners

Academy enrolment creates a customer relationship. We may send you course updates, new-course launch notices, and educational newsletters. You may opt out of any non-transactional email at any time using the unsubscribe link.

18. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes:

  • We will update the "Last Updated" date at the top of this policy
  • We will notify registered users via email for significant changes
  • We will display a prominent notice on the dcomply platform
  • Where required under the DPDP Act, we will seek fresh consent for new processing activities

We encourage you to review this policy periodically. Your continued use of dcomply after changes are published constitutes acceptance of the updated policy.

Questions About Your Privacy?

We take your data privacy seriously. If you have any questions or concerns, our Grievance Officer is here to help.