Privacy Policy
This Privacy Policy explains how Decipher Consultancy Services ("we", "us", "our"), operating the dcomply platform, collects, uses, shares, and protects your personal data in accordance with the Digital Personal Data Protection Act, 2023 ("DPDP Act").
1. About This Policy
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules framed thereunder. It governs the collection, storage, processing, and transfer of personal data by Decipher Consultancy Services, the company behind the dcomply platform.
By accessing or using dcomply (accessible at dcomply.com), you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. If you do not agree with any part of this policy, please do not use our services.
Scope: This policy applies to all users of the dcomply platform, including visitors to our website, registered users, trial users, and enterprise customers. It covers data collected through our website, platform, APIs, and any communication channels.
2. Data Fiduciary Information
Under the DPDP Act, the Data Fiduciary is the entity that determines the purpose and means of processing your personal data. For the dcomply platform:
3. Personal Data We Collect
We collect personal data through various channels depending on how you interact with dcomply:
A. Registered Users (Platform)
- Account Information: Full name, email address, phone number, job title, and organisation name provided during registration
- Platform Usage Data: Compliance assessment responses, uploaded documents (privacy policies, contracts), audit reports generated, consent records managed, and DSR workflows initiated
- Technical Data: IP address, browser type and version, device information, operating system, login timestamps, and session identifiers
- Payment Information: Billing name, billing address, and payment method details (processed securely through Razorpay; we do not store card numbers)
B. Website Visitors
- Analytics Data: Pages visited, time spent on pages, referral source, click patterns, and scroll depth
- Contact Form Submissions: Name, email, phone number, company name, and enquiry details when you submit a form
- Cookie Data: Information collected through cookies and similar tracking technologies (see Section 13)
C. Communication Data
- Support Interactions: Correspondence via email, support tickets, or chat, including attachments and resolution notes
- Marketing Preferences: Your opt-in/opt-out choices for newsletters, product updates, and promotional communications
Sensitive Personal Data: dcomply does not intentionally collect sensitive personal data (such as health data, biometrics, or caste information). If such data is incidentally present in documents you upload for compliance analysis, it is processed solely for that stated purpose and handled with additional safeguards.
4. Purpose of Processing
We process your personal data only for specific, clearly defined purposes:
| Purpose | Description | DPDP Act Basis |
|---|---|---|
| Service Delivery | Operating the dcomply platform, providing compliance tools, generating reports, and managing your account | Section 4 (Consent) |
| Compliance Assessment | Analysing your uploaded documents and organisational data to generate DPDP compliance reports and recommendations | Section 4 (Consent) |
| Customer Support | Responding to your queries, resolving technical issues, and providing onboarding assistance | Section 7 (Legitimate Use) |
| Billing & Payments | Processing subscription payments, issuing invoices, managing refunds, and maintaining financial records | Section 7 (Legitimate Use) |
| Product Improvement | Analysing usage patterns (in aggregate) to improve platform features, fix bugs, and enhance user experience | Section 7 (Legitimate Use) |
| Legal Compliance | Meeting obligations under Indian law, responding to regulatory requests, and maintaining audit trails | Section 7 (Legitimate Use) |
| Communication | Sending transactional emails (account confirmations, billing receipts) and, with your consent, marketing communications | Section 4 / Section 7 |
| Security | Detecting fraud, preventing unauthorised access, and protecting the integrity of our platform and user data | Section 7 (Legitimate Use) |
We adhere to the principle of purpose limitation, your data will not be processed for any purpose beyond what is stated here without obtaining fresh consent.
5. Lawful Basis for Processing
Under the DPDP Act, we process personal data based on the following lawful grounds:
- Consent (Section 4 & 6): Where you have given free, specific, informed, and unambiguous consent for processing your data for a stated purpose. You may withdraw consent at any time.
- Legitimate Uses (Section 7): Where processing is necessary for purposes such as performing a contract with you, complying with legal obligations, responding to medical emergencies, or employment-related purposes.
- State Instrumentality (Section 7(b)): Where processing is necessary for the State to provide benefits, services, or issue permits/licences (not applicable to dcomply's typical operations).
Data Minimisation: We only collect personal data that is strictly necessary for the stated purpose. We do not collect excessive or irrelevant data, in line with the data minimisation principle under the DPDP Act.
6. Your Rights as a Data Principal
Under the DPDP Act, you (the "Data Principal") have the following rights over your personal data:
Right to Access (Section 11)
You may request a summary of your personal data being processed by us, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your data has been shared.
Right to Correction (Section 11)
You may request correction of inaccurate or misleading personal data, completion of incomplete data, and updating of data that is no longer current.
Right to Erasure (Section 12)
You may request deletion of your personal data when it is no longer necessary for the purpose for which it was collected, or when you withdraw your consent.
Right to Withdraw Consent (Section 6(6))
You may withdraw your consent at any time with the same ease as it was given. Withdrawal does not affect the lawfulness of processing done prior to withdrawal.
Right to Grievance Redressal (Section 13)
You may raise a complaint with our Grievance Officer. We are obligated to acknowledge within 48 hours and resolve within 30 days. If unresolved, you may escalate to the Data Protection Board of India.
Right to Nominate (Section 14)
You may nominate another individual to exercise your rights under this policy in the event of your death or incapacity, as provided under Section 14 of the DPDP Act.
To exercise any of these rights, please contact our Grievance Officer at [email protected] or call +91 9911202099. We will respond within the timeframes prescribed by the DPDP Act.
7. Consent Management
dcomply follows the consent requirements laid down in Section 6 of the DPDP Act:
- Clear Notice: Before collecting your data, we provide a clear notice in English and Hindi explaining what data we collect, why, and how it will be used
- Granular Consent: We seek separate consent for each distinct purpose of processing. Consent for one purpose does not extend to another
- Easy Withdrawal: You can withdraw your consent at any time through your account settings or by contacting us. The process for withdrawal is as simple as the process for giving consent
- No Bundling: We do not bundle consent with access to our services. You can decline optional data processing without losing access to core platform features
- Audit Trail: We maintain detailed records of when, how, and for what purpose consent was obtained, along with the specific notice provided at the time
Consent Records: All consent events are logged with timestamps, the specific notice text displayed, the purpose, and the method of consent. These records are retained for 7 years for regulatory compliance and audit purposes.
8. Data Security Measures
We implement reasonable security safeguards as required under Section 8(4) of the DPDP Act to protect your personal data from unauthorised access, alteration, disclosure, or destruction:
- Encryption at Rest: All stored data is encrypted using AES-256 encryption
- Encryption in Transit: All data transmitted uses TLS 1.3 protocol
- Access Control: Role-based access control (RBAC) with principle of least privilege
- Multi-Factor Authentication: Available for all user accounts
- Regular Audits: Periodic security assessments and vulnerability testing
- Data Residency: Data stored on servers located in India
- Incident Response: Documented incident response plan with defined escalation procedures
- Employee Training: All team members undergo security awareness training and sign NDAs
For detailed information about our security practices, please visit our Security Page or Trust Centre.
9. Data Retention
We retain your personal data only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law. Our retention schedule:
| Data Category | Retention Period | After Expiry |
|---|---|---|
| Account & Profile Data | Duration of account + 90 days | Permanently deleted |
| Compliance Assessment Data | 3 years from last activity | Anonymised or deleted |
| Uploaded Documents | Until deleted by user or 1 year after account closure | Permanently deleted |
| Consent Records | 7 years (regulatory requirement) | Archived then deleted |
| Payment & Billing Data | 8 years (as per Indian tax laws) | Securely destroyed |
| Support Tickets | 2 years from resolution | Anonymised |
| Contact Form Submissions | 1 year from submission | Permanently deleted |
| Website Analytics | 26 months | Aggregated and anonymised |
| Security & Audit Logs | 3 years | Securely destroyed |
Upon account deletion or consent withdrawal, we permanently delete your personal data within 30 days, except where retention is mandated by law.
10. Data Sharing & Third-Party Processors
We do not sell, rent, or trade your personal data. We may share your data with the following categories of third parties, solely for the purposes described:
| Third Party | Purpose | Safeguards |
|---|---|---|
| Cloud Infrastructure Provider | Hosting and data storage | Data Processing Agreement, ISO 27001 certified, data stored in India |
| Payment Processor (Razorpay) | Processing subscription payments | PCI-DSS compliant, no card data stored on our servers |
| Email Service Provider | Sending transactional and marketing emails | Data Processing Agreement, encrypted transmission |
| Analytics Provider | Understanding website usage patterns | Anonymised/aggregated data only |
All third-party Data Processors are bound by written Data Processing Agreements that require them to:
- Process data only on our instructions and for the specified purpose
- Implement appropriate technical and organisational security measures
- Not sub-contract processing without our prior written approval
- Delete or return all personal data upon termination of the agreement
- Assist us in complying with Data Principal rights requests
We may also disclose your data if required by law, court order, or governmental authority, or to protect our legal rights.
11. Cross-Border Data Transfers
Your personal data is primarily stored and processed on servers located in India. Where any transfer of data outside India is necessary (e.g., for email delivery or analytics), we ensure:
- Transfers are made only to countries or territories not restricted by the Central Government under Section 16(1) of the DPDP Act
- Appropriate contractual safeguards, including Data Processing Agreements, are in place with all overseas processors
- The receiving entity maintains security standards equivalent to those required under the DPDP Act
Data Localisation: All primary customer data, compliance assessments, and uploaded documents are stored exclusively on servers within India, in compliance with data localisation requirements.
12. Children's Data Protection
dcomply is a B2B compliance platform designed for business use. We do not knowingly collect personal data from children under the age of 18 years. In compliance with Section 9 of the DPDP Act:
- We require verifiable parental or guardian consent before processing any child's personal data
- We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children
- We do not undertake any processing that could cause detrimental effect on the well-being of a child
- If we become aware that a child's data has been collected without proper consent, we will delete it immediately
If you believe we have inadvertently collected a child's personal data, please contact our Grievance Officer immediately.
13. Cookies & Tracking Technologies
Our website and platform use cookies and similar technologies to enhance your experience:
Types of Cookies We Use
- Essential Cookies: Required for the platform to function (authentication, session management, security). These cannot be disabled.
- Analytics Cookies: Help us understand how visitors interact with our website (page views, traffic sources, user journeys). Collected in aggregate form.
- Functional Cookies: Remember your preferences such as language, display settings, and recently viewed pages.
- Marketing Cookies: Used with your explicit consent to deliver relevant advertisements and measure campaign effectiveness. You can opt out at any time.
Managing Cookies
You can manage your cookie preferences through our cookie consent banner displayed on your first visit. You may also configure your browser to block or delete cookies. Note that blocking essential cookies may impair platform functionality.
14. Data Breach Notification
In the event of a personal data breach, we follow the notification requirements under Section 8(6) of the DPDP Act:
- Board Notification: We will notify the Data Protection Board of India about the breach in the prescribed form and manner
- Individual Notification: We will inform affected Data Principals about the breach, its nature, the data involved, and the remedial measures taken
- Breach Details: Notifications will include the nature of the breach, approximate number of affected individuals, likely consequences, and the measures taken to mitigate the impact
- Breach Register: We maintain a comprehensive register of all data breaches, including those that do not meet the notification threshold, for internal audit purposes
15. Your Duties as a Data Principal
Under Section 15 of the DPDP Act, Data Principals also have certain duties:
- You must provide accurate and complete information when submitting personal data to us. Do not provide false or misleading data.
- You must not impersonate another person when providing personal data.
- You must not suppress material information when exercising your rights (e.g., the right to correction or erasure).
- You must not file false or frivolous complaints with the Data Protection Board.
- You must comply with all applicable laws when using dcomply and providing your data.
Non-compliance with these duties may result in penalties of up to Rs. 10,000 under the DPDP Act.
16. Grievance Officer
In accordance with the DPDP Act, we have appointed a Grievance Officer to address your concerns regarding your personal data:
Subesh Kumar. Grievance Officer
Resolution Process
- Acknowledgement: We will acknowledge your complaint within 48 hours of receipt
- Investigation: We will investigate your concern thoroughly and keep you informed of progress
- Resolution: We aim to resolve all grievances within 30 days of acknowledgement
- Escalation: If you are not satisfied with our resolution, you may file a complaint with the Data Protection Board of India as per the procedure laid down in the DPDP Act
17. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes:
- We will update the "Last Updated" date at the top of this policy
- We will notify registered users via email for significant changes
- We will display a prominent notice on the dcomply platform
- Where required under the DPDP Act, we will seek fresh consent for new processing activities
We encourage you to review this policy periodically. Your continued use of dcomply after changes are published constitutes acceptance of the updated policy.
Questions About Your Privacy?
We take your data privacy seriously. If you have any questions or concerns, our Grievance Officer is here to help.