Cybercyko Technologies Pvt Ltd — Legal

Privacy
Policy

Effective: 25 Oct 2025Last Updated: 25 Oct 2025DPDP Act 2023 Compliant

Cybercyko Technologies Pvt Ltd (“Cybercyko”, “we”, “our”, “us”) respects your privacy and is committed to protecting personal data processed in connection with our website cybercyko.com and our products including Cybercyko Wallet.

01

Introduction

This Policy explains how we collect, use, disclose, transfer and secure personal information. It complies with India's Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

By accessing our Services, you agree to this Policy.

02

Definitions

TermMeaning
Personal DataAny data about an identifiable individual.
Sensitive Personal Data (SPDI)Includes passwords, financial information, biometric data, health information, and any data declared sensitive under applicable law.
Data PrincipalThe individual to whom the data relates.
Data FiduciaryCybercyko Technologies Pvt Ltd.
ProcessingAny operation performed on Personal Data such as collection, storage, use, disclosure, or deletion.
03

Information We Collect

We collect Personal Data through direct interactions, automated technologies, and third-party integrations.

a. Information You Provide

  • Name, company, designation, email address, and contact number.
  • Login credentials and authentication details.
  • Support requests, feedback, or communications.
  • Billing or contractual data (for enterprise clients).

b. Information Collected Automatically

  • Device identifiers, IP address, browser type, operating system.
  • Access logs, timestamps, geolocation (approximate).
  • Usage metrics, API calls, session length, and error diagnostics.

c. Information from Third Parties

  • Data provided by client organisations using our IAM platform.
  • Data from analytics providers, marketing partners, or authentication sources (e.g., OAuth, SAML IdP).

We collect only data necessary for the purposes stated below.

04

Purpose and Legal Basis of Processing

PurposeLegal Basis
Provide and operate our IAM solutions, manage user accountsPerformance of Contract
Authenticate users, authorise access, and ensure system securityLegitimate Interest / Contract
Provide customer support and technical assistanceContract / Legitimate Interest
Conduct R&D, testing, AI-based analytics on anonymised dataLegitimate Interest / Consent
Send service updates, notifications, or marketing (opt-in)Consent
Ensure compliance with legal and regulatory obligationsLegal Obligation
Detect, prevent and investigate security breaches or fraudLegitimate Interest
05

Data Retention

We retain Personal Data only for as long as required for lawful purposes or as mandated by regulation.

Data CategoryTypical Retention Period
Account & login logs90 days to 1 year
Support tickets & communications12 months after closure
Client contractual records7 years post-termination
Analytics & telemetry data180 days (aggregated afterwards)
Marketing dataUntil consent withdrawal
06

Disclosure and Sharing of Information

We may share Personal Data only under strict contractual and legal safeguards:

  • Service Providers: Hosting, cloud (AWS/Azure), email, analytics, and security vendors under NDAs.
  • Business Partners / Resellers: To deliver joint solutions with proper consent.
  • Legal Authorities: If required by law, court order, or government regulation.
  • Corporate Transactions: During merger, acquisition, or asset transfer with prior notice.

We never sell Personal Data to any third party.

07

Cross-Border Transfers

Data may be processed or stored on servers located outside India. Cybercyko ensures adequate safeguards including:

  • Contractual clauses ensuring equivalent data protection.
  • Encryption of data in transit and at rest.
  • Access restriction to authorised personnel only.
08

Data Security

Cybercyko implements Reasonable Security Practices and Procedures, consistent with ISO 27001 and SOC 2 Type II standards:

  • Multi-layered network, application and data security controls.
  • Role-based access and MFA.
  • Continuous monitoring and periodic vulnerability assessments.
  • Regular employee privacy and security training.
  • Incident-response and breach-notification mechanisms.
09

Data Breach Notification

In the unlikely event of a data breach that impacts your Personal Data, Cybercyko will:

  1. 1.Investigate and contain the breach immediately.
  2. 2.Notify affected users and the Data Protection Board of India (if required) within statutory timelines.
  3. 3.Provide guidance on remedial actions.
10

Your Rights

As a Data Principal, you have the right to:

  • Access your Personal Data held by us.
  • Correct or update inaccurate data.
  • Erase data no longer necessary for processing.
  • Withdraw consent for data processed based on consent.
  • Request information about data-sharing and processing.

Requests can be sent to info@cybercyko.com

11

Cookies and Analytics

Our website uses cookies and similar technologies to:

  • Enable secure sign-in sessions.
  • Analyse site usage and performance.
  • Remember preferences.
  • Deliver relevant content.

We may use third-party analytics tools (e.g., Google Analytics, Microsoft Clarity). You may manage or disable cookies in your browser, but certain features may not work properly.

12

Third-Party Links and Integrations

Our Services may contain links or integrations to external websites or identity providers (e.g., Google Workspace, Azure AD, Okta). Cybercyko is not responsible for the privacy practices of such third parties. Please review their respective policies.

13

Children's Privacy

Our Services are intended for persons aged 18 and above. We do not knowingly collect data from minors. If such information is inadvertently received, we will delete it promptly.

14

Updates to this Policy

Cybercyko may modify or update this Policy from time to time. Material changes will be communicated via:

  • Updated "Effective Date" on this page.
  • Email notice (if you maintain an active account).

Continued use of the Services after such updates constitutes acceptance of the revised Policy.

15

Governing Law and Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of the Republic of India. Any disputes shall be subject to the exclusive jurisdiction of the courts at Andhra Pradesh, India.

16

Contact and Grievance Redressal

In accordance with Rule 5(9) of the SPDI Rules and Section 13 of the DPDP Act 2023, a Grievance Officer has been appointed to address concerns related to personal data processing.

Grievance Officer

NameGrievance Officer, Cybercyko Technologies Pvt Ltd
AddressMalikipuram, Andhra Pradesh, India

We will acknowledge your grievance within 48 hours and endeavour to resolve it within 30 days of receipt, in accordance with applicable law.

COMPANY

Registered under the Companies Act, India

Contact Email - contact@cybercyko.com

Contact Phone : +91 9701991478

Andhra Pradesh

Connect with us: