This Privacy Policy explains how Ciphercup Technologies Pvt Ltd (“Ciphercup”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you visit ciphercup.com, contact us, request a quote, apply for a job, buy a service package from our shop or work with us as a client. We have written it in plain language so that you can understand what happens to your information and what choices you have. Please read it together with our Terms & Conditions and Cookie Policy.
Last updated: 9 October 2026
1. Who we are and scope of this policy
Ciphercup Technologies Pvt Ltd is a web design and development agency that has been working with businesses since 2014. Our registered office is at #40, 6th Sector, 12th Main, Near BDA Complex, HSR Layout, Bangalore-560 102, Karnataka, India, and we have a branch office at S 40, 8th Floor, Alapatt Heritage Building, MG Road North End, Ernakulam-682 035, Kerala, India.
For the personal data described in this policy, Ciphercup decides why and how the data is processed. This makes us the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the “controller” under the EU General Data Protection Regulation and the UK GDPR (together, “GDPR”). For California residents, we act as a “business” under the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
This policy applies to:
- visitors to ciphercup.com and any of its pages, including our blog;
- people who contact us by form, email, phone or WhatsApp, or request a quote;
- customers who create an account or place an order for a service package through our online shop;
- clients and their staff who we work with on projects;
- job applicants who use our career form or send us a CV.
It does not cover websites, apps or services run by other organisations, even if we link to them, or websites we build for clients (each client is responsible for its own privacy notice).
We process personal data in line with the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the DPDP Act and the rules made under it as they come into force, and, where they apply to you, the GDPR and the CCPA.
2. Personal data we collect
We only collect what we need for the purposes described in this policy. Depending on how you interact with us, this may include the following.
2.1 Information you give us
- Contact and enquiry details: your name, company name, email address, phone or WhatsApp number, city, the service you are interested in, your budget range and the message you send us through our contact or quote forms on the Contact Us page.
- Account details: if you create a customer account in our shop, your name, email address, username and a password (stored only in hashed form; we cannot see it).
- Order and billing details: billing name, billing and service address, phone number, email address, GSTIN (if you provide one for a business invoice), the packages you buy, order notes and the order history linked to your account.
- Payment information: payments are handled by third-party payment gateways. We receive a transaction reference, payment status, amount, date and sometimes the payment method type and the last four digits of a card. We do not receive or store full card numbers, CVV codes, UPI PINs or net-banking passwords.
- Project information: content, logos, images, product details, briefs, feedback and credentials (such as hosting, domain, CMS or social media log-ins) that you share so we can deliver a project.
- Job application details: name, contact details, CV or résumé, portfolio links, education, work history, current and expected salary, notice period and anything else you choose to include.
- Communications: emails, WhatsApp messages, call notes and meeting notes exchanged with us.
2.2 Information collected automatically
- Technical and log data: IP address, browser type and version, operating system, device type, referring page, pages requested, date and time of the request and server response codes. Our web server and our security firewall (Wordfence) record this information to keep the site secure and working.
- Security data: failed log-in attempts, blocked requests, suspected malicious traffic patterns and the IP addresses linked to them.
- Cookie data: identifiers and preferences stored by cookies, such as your cookie consent choice, whether you are logged in and the contents of your shopping cart. See section 5 and our Cookie Policy.
2.3 Sensitive personal data
We do not ask for sensitive personal data such as health information, biometric data, sexual orientation, religious beliefs or financial information beyond what is described above. Passwords that you set for your shop account and any account credentials you share for a project are treated as sensitive and protected accordingly. Please do not send us sensitive personal data that we have not asked for, for example in a CV or a form message.
3. Where we get personal data from
- Directly from you when you fill in a form, create an account, place an order, email, call or message us, or attend a meeting.
- From your device and browser when you use our website, through server logs, the security firewall and cookies.
- From payment gateways, which tell us whether a payment succeeded, failed or was refunded.
- From your employer or colleagues if you are a contact person on a client project.
- From referrers and public sources, such as a person who recommends you to us, or your public business profile or professional networking profile when you approach us as a client or job applicant.
4. How we use personal data and our legal bases
Under the DPDP Act we process personal data on the basis of your consent or for certain “legitimate uses” recognised by the Act (for example, where you have voluntarily provided your data for a specified purpose, or to comply with law). Under the GDPR we must also identify a legal basis for each purpose. The table below sets out both.
| Purpose | Examples | Legal basis |
|---|---|---|
| Responding to enquiries and quote requests | Replying to your form, preparing a proposal, calling you back | Your consent / voluntary provision for that purpose (DPDP); steps at your request before a contract and legitimate interests (GDPR) |
| Processing shop orders and delivering services | Creating your account, confirming orders, issuing GST invoices, onboarding, project delivery, support | Performance of a contract with you (GDPR); voluntary provision for a specified purpose (DPDP) |
| Payments, refunds and accounting | Reconciling payments, processing refunds, maintaining books of account | Contract and legal obligation under tax, GST and company laws |
| Website operation and security | Serving pages, detecting and blocking attacks, preventing fraud and spam | Legitimate interests in a secure, working website (GDPR); legitimate uses and reasonable security safeguards (DPDP, IT Act) |
| Recruitment | Reviewing applications, scheduling interviews, keeping a talent pool (with your consent) | Consent / voluntary provision (DPDP); steps before a contract and consent for the talent pool (GDPR) |
| Service communications | Project updates, renewal reminders for Website Care Plans, important notices | Contract and legitimate interests |
| Marketing communications | Occasional newsletters or offers, if you opt in | Consent, which you can withdraw at any time |
| Analytics (only if enabled in future) | Understanding which pages are useful | Consent through our cookie banner |
| Legal compliance and protecting our rights | Responding to lawful requests, enforcing our terms, handling disputes | Legal obligation and legitimate interests |
We do not use personal data for automated decision-making that produces legal or similarly significant effects on you, and we do not sell personal data.
5. Cookies and similar technologies
Our website uses a small number of cookies. In summary:
- Necessary cookies are set by WordPress, WooCommerce, our Wordfence security firewall and the CookieYes consent tool. They keep you logged in, remember your cart, protect the site from attacks and remember your cookie choice. These cannot be switched off because the site would not work properly without them.
- Functional cookies such as WordPress comment cookies remember details you choose to save.
- Analytics and marketing cookies: we do not install Google Analytics, advertising pixels or similar tracking tools by default. If we decide to use them in future, they will only be set after you give consent through our cookie banner.
Images on our website are delivered from Unsplash’s content delivery network (images.unsplash.com). Like any content delivery network, it receives your IP address and browser user-agent when your browser requests an image. Unsplash processes that data under its own privacy policy.
You can change your cookie preferences at any time by clicking the “Cookie Settings” link in the footer of any page. Our Cookie Policy lists every cookie, its provider, purpose and duration.
6. Who we share personal data with
We share personal data only where necessary and, for service providers, under contracts or terms that require them to protect it and to use it only for the services they provide to us. The categories of recipients are:
- Hosting and infrastructure providers that host our website, databases, backups and email.
- Payment gateways that process payments and refunds for orders. They act under their own terms and the regulations of the Reserve Bank of India and card networks.
- Security providers, including Wordfence (Defiant, Inc.), whose firewall may check IP addresses against threat intelligence data to block malicious traffic.
- Consent management: CookieYes, which records your cookie consent choices.
- Communication tools: email providers, and Meta’s WhatsApp service if you choose to contact us using our WhatsApp click-to-chat link. When you click that link, you leave our website and WhatsApp processes your data under Meta’s own terms and privacy policy.
- Content delivery networks: Unsplash’s image CDN, as described in section 5.
- Third parties needed for your project, such as domain registrars, hosting companies, SMS or payment gateway providers, or plugin and theme vendors, where you ask us to set up or manage those services for you.
- Professional advisers such as chartered accountants, auditors and lawyers, who are bound by confidentiality duties.
- Government and law enforcement authorities, courts and regulators when we are required by law, or when disclosure is necessary to protect our rights, our clients or the public.
- A buyer or successor if our business, or part of it, is reorganised, merged or sold, in which case personal data would remain protected under the commitments in this policy.
We do not sell or rent personal data to anyone, and we do not share it with third parties for their own marketing.
7. International transfers
We are based in India and most of the personal data we hold is processed in India. Some of our service providers, such as hosting, email, security, consent management and CDN providers, may store or process data in other countries, including the United States and member states of the European Union.
When personal data is transferred outside India, we do so in accordance with the DPDP Act and any restrictions notified by the Central Government. When personal data of individuals in the EU or UK is transferred to India or another country that does not have an adequacy decision, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum, or, where appropriate, on a derogation such as the transfer being necessary for a contract you have asked us to enter into. You can contact us for more information about these safeguards.
8. How long we keep personal data
We keep personal data only for as long as we need it for the purpose it was collected, or for as long as the law requires. When the retention period ends we delete it or anonymise it so that it can no longer identify you. Typical retention periods are:
| Type of data | Typical retention period |
|---|---|
| Enquiries and quote requests that do not lead to a project | Up to 24 months from the last contact |
| Shop account details | Until you ask us to delete the account, or 3 years after your last order or log-in, whichever is earlier |
| Orders, invoices, payment and refund records | 8 years from the end of the relevant financial year, to meet accounting, tax and GST record-keeping requirements |
| Project files and communications | For the duration of the project and up to 3 years afterwards, so that we can provide support and handle any disputes |
| Client credentials (hosting, CMS, domain log-ins) | Only while we need them to provide services; we ask clients to change passwords at the end of a project or plan |
| Job applications | Up to 12 months after the recruitment process ends, or longer only if you agree to join our talent pool |
| Security and server logs | Usually 30 to 180 days, and longer only where needed to investigate a specific incident or where required by law |
| Cookie consent record | 12 months, after which you are asked again |
| Marketing preferences | Until you unsubscribe; we keep a suppression record so that we do not contact you again |
We may keep data for longer if it is needed to establish, exercise or defend a legal claim, or if a law or a lawful order requires it.
9. How we protect personal data
We take reasonable security practices and procedures, appropriate to the nature of the data, as required by Section 43A of the IT Act, the SPDI Rules and the DPDP Act. Our measures include:
- HTTPS encryption for all pages of our website, including checkout and account pages;
- a web application firewall and malware scanning (Wordfence), together with hardening measures such as WP Hide & Security Enhancer, rate limiting and protection against brute-force log-in attempts;
- regular updates to WordPress core, themes and plugins, and regular backups stored securely;
- hashed passwords and multi-factor authentication for administrator access where available;
- access to personal data limited to staff who need it for their work, under confidentiality obligations;
- storing client credentials in secure password management tools rather than in plain text or chat messages;
- using payment gateways so that card data never touches our servers.
No method of transmission over the internet or of electronic storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal data breach, we will act promptly to contain it and will notify affected individuals and the relevant authorities, including the Data Protection Board of India and CERT-In, where and as required by law.
10. Your rights
The rights you have depend on the law that applies to you. We aim to honour reasonable requests from anyone, wherever they are located.
10.1 Rights under India’s DPDP Act
- Right to access information about the personal data we process, the processing activities and the identities of others we have shared it with.
- Right to correction, completion, updating and erasure of your personal data, subject to legal retention requirements.
- Right to grievance redressal through our Grievance Officer (see section 15), and, if you are not satisfied, the right to approach the Data Protection Board of India.
- Right to nominate another individual to exercise your rights in the event of your death or incapacity.
- Right to withdraw consent at any time, as easily as you gave it.
10.2 Rights under the GDPR and UK GDPR (EU/UK visitors)
- the right to be informed and to access your personal data;
- the right to rectification of inaccurate data;
- the right to erasure (“right to be forgotten”) in certain circumstances;
- the right to restrict processing;
- the right to data portability, to receive data you provided in a structured, commonly used, machine-readable format;
- the right to object to processing based on legitimate interests, and an absolute right to object to direct marketing;
- the right to withdraw consent at any time, without affecting processing that happened before;
- the right to lodge a complaint with your local data protection supervisory authority, or with the Information Commissioner’s Office in the UK.
10.3 Rights under the CCPA/CPRA (California residents)
- Right to know the categories and specific pieces of personal information we have collected, the sources, the purposes and the categories of third parties we disclose it to.
- Right to delete personal information we have collected from you, subject to certain exceptions.
- Right to correct inaccurate personal information.
- Right to opt out of sale or sharing: we do not sell personal information and do not “share” it for cross-context behavioural advertising, as those terms are defined in the CCPA. We also honour Global Privacy Control signals where technically possible.
- Right to limit use of sensitive personal information: we use sensitive personal information (such as account log-in credentials) only for purposes permitted by the CCPA.
- Right to non-discrimination for exercising any of these rights.
In the preceding 12 months, the categories of personal information we have collected are identifiers, commercial information (orders), internet or network activity information, professional or employment-related information (from job applicants and client contacts) and account log-in credentials. We have disclosed these only to the service provider categories listed in section 6, for business purposes.
11. How to exercise your rights
To make a request, email [email protected] with the subject line “Privacy Request”, or write to our Bangalore office at the address in section 1. Please tell us:
- your name and the email address or phone number you used with us;
- which right you want to exercise and, if possible, which data or interaction it concerns;
- whether you are making the request for yourself or on behalf of someone else.
To protect your data, we will verify your identity before acting on a request, normally by confirming details that match our records. If an authorised agent makes a request for you, we will ask for proof of their authority. You can update most shop account details yourself by logging in to your account.
We will respond within the time limits set by the applicable law, generally within one month for GDPR requests and within 45 days for CCPA requests, and within the period prescribed under the DPDP Act and its rules. If we need more time or cannot meet a request (for example, because we must keep invoices for tax purposes), we will explain why. We do not charge a fee for reasonable requests.
12. Children’s personal data
Our website and services are intended for businesses and adults. We do not knowingly collect personal data from anyone under 18 years of age. Under the DPDP Act, a “child” is a person under 18, and processing a child’s personal data requires verifiable consent from a parent or lawful guardian. Our shop and forms are not designed for children, and you must be at least 18 to place an order or create an account. If you believe a child has given us personal data, please contact us and we will delete it promptly.
13. Withdrawing consent and marketing choices
Where we rely on your consent, you can withdraw it at any time, and doing so will be as easy as giving it. Withdrawal does not affect processing that was lawfully carried out before you withdrew. Ways to withdraw consent include:
- Cookies: click “Cookie Settings” in the footer and change your choices.
- Marketing emails: click the unsubscribe link in any marketing email, or email us.
- WhatsApp or phone updates: tell us in the chat or on the call, or email us, and we will stop.
- Talent pool: email us and we will remove your application.
If you withdraw consent for data that is needed to deliver a service you have ordered, we may not be able to continue that service. We will tell you if this is the case.
14. Data we process on behalf of clients
When we build, host, maintain or market a website for a client, we may have access to personal data of that client’s customers or visitors, for example in a WooCommerce order database, form submissions or a mailing list. In those cases the client is the Data Fiduciary or controller and we act as a Data Processor (or “service provider”). We process that data only on the client’s documented instructions, keep it confidential, apply reasonable security safeguards and delete or return it at the end of our engagement. If you are a customer of one of our clients and want to exercise your rights, please contact that business directly; we will assist them where needed.
15. Grievance Officer
In accordance with the Information Technology Act, 2000, the rules made under it and the DPDP Act, our Grievance Officer can be contacted for any complaint or concern about how we process personal data:
Grievance Officer, Ciphercup Technologies Pvt Ltd
Email: [email protected] (please use the subject line “Grievance”)
Post: #40, 6th Sector, 12th Main, Near BDA Complex, HSR Layout, Bangalore-560 102, Karnataka, India
Phone: +91 99163 58261 (Mon–Sat, 9:30 AM – 6:30 PM IST)
We will acknowledge your grievance and resolve it within the timelines required by Indian law. If you are not satisfied with our response, you may approach the Data Protection Board of India once it is operational for such complaints, or, if you are in the EU or UK, your local supervisory authority.
16. Changes to this policy
We may update this Privacy Policy from time to time, for example when we change the tools we use, add a new service or when the law changes, including as further rules under the DPDP Act take effect. When we do, we will change the “Last updated” date at the top of this page. If the changes are significant, we will make reasonable efforts to tell you, for example by a notice on our website or by email to account holders. Where the law requires your consent to a change, we will ask for it.
17. Contact us
If you have any questions about this policy or our privacy practices, we are happy to help:
- Email: [email protected]
- Phone / WhatsApp: +91 99163 58261
- Kochi landline: 0484-4148253
- Bangalore (registered office): #40, 6th Sector, 12th Main, Near BDA Complex, HSR Layout, Bangalore-560 102, Karnataka, India
- Kochi: S 40, 8th Floor, Alapatt Heritage Building, MG Road North End, Ernakulam-682 035, Kerala, India
You can also reach us through our Contact Us page. Answers to common questions about our services are available on our FAQ page.