Compliance & data protection
Compliance at CIPHER CRM
Last updated:
CIPHER CRM aligns its data-handling practices with India’s Digital Personal Data Protection Act, 2023 and the IT Rules, 2021, and with the EU GDPR for our EU users. We process data under contract, honour data-subject rights, use vetted sub-processors under contractual safeguards, and offer a Data Processing Agreement (DPA) on request. We do not sell your data.
Regulatory alignment
The laws we design our data-handling around, and how CIPHER supports each one.
- India's DPDP Act, 2023 - The Digital Personal Data Protection Act, 2023 is India's core law for how personal data is collected, used and protected. We collect only the data needed to deliver the service and process it for clear, stated purposes. We support your rights to access, correct and erase personal data, and act on withdrawal of consent. Read the operative detail in our Privacy Policy.
- India IT Rules, 2021 - The Information Technology (Intermediary Guidelines) Rules, 2021 require reasonable security practices and a point of contact for grievances. We apply reasonable technical and organisational security measures - see our Security page. You can raise a data or privacy grievance with our Grievance contact, below.
- EU GDPR (for EU users) - For users in the EU/EEA, we align our handling of personal data with the General Data Protection Regulation. We process personal data on a lawful basis, honour data-subject rights, and support international-transfer safeguards such as Standard Contractual Clauses (SCCs) where relevant. Our Data Protection page covers this in more detail.
Lawful bases & data handling
We process your data on clear legal grounds, and only for what the service needs. We do not sell personal data.
- Contract - Running your CRM - storing your records, delivering the service you signed up for, and supporting your account.
- Consent - Marketing emails and any optional processing you opt into. You can withdraw consent at any time.
- Legitimate interest - Keeping the platform secure, preventing abuse, and improving the product - balanced against your rights.
Data-subject rights
You have rights over your personal data. Here is what they are and how to use them.
- Access - Get a copy of the personal data we hold about you.
- Rectification - Correct data that is inaccurate or incomplete.
- Erasure - Ask us to delete your personal data where the law allows.
- Portability - Receive your data in a portable, machine-readable form.
- Objection - Object to certain processing, or withdraw consent you gave.
How to exercise them: email hello@ciphercrm.co with your request. We verify it and respond within 30 days. Where CIPHER holds data on behalf of a customer, we route the request to that customer as the controller.
Sub-processors & data residency
We use a small set of vetted sub-processors, each under contractual data-protection safeguards.
- Cloud hosting & infrastructure - Reputable industry-standard cloud providers
- Transactional & notification email - Contracted email service provider
- Product analytics - Contracted analytics provider
We can provide the canonical named list - with purpose and region - on request, and we commit to reasonable notice of material changes. International transfers, where they occur, are covered by mechanisms such as Standard Contractual Clauses (SCCs). A Data Processing Agreement covering Article 28 processing terms is available on request.
Breach notification
If a personal-data breach affects your data, we investigate, act to contain it, and notify affected customers and relevant authorities as required by contract and applicable law - including within statutory timelines such as the GDPR's 72-hour reporting window where it applies.
See our Security page for how we monitor for and respond to incidents.
Grievance & data-protection contact
Under India's IT Rules, 2021 and the DPDP Act, 2023, you can raise a data or privacy grievance with our Grievance contact at CIPHER Craft Pvt. Ltd.
- Email: hello@ciphercrm.co
- Mobile: (+91) 97122 00017
- Location: Gujarat, India
We acknowledge grievances and work to resolve them within the timelines set by applicable law.
Compliance questions, answered
- Is CIPHER CRM GDPR compliant? - For our EU/EEA users, CIPHER CRM aligns its personal-data handling with the GDPR: we process data on a lawful basis, honour data-subject rights, use sub-processors under contractual safeguards, and support international-transfer mechanisms such as Standard Contractual Clauses where relevant. We do not claim any certification; we can provide a Data Processing Agreement on request.
- Do you comply with India's DPDP Act? - Yes - CIPHER Craft Pvt. Ltd. is a registered Indian company and we align our practices with India's Digital Personal Data Protection Act, 2023 and the IT Rules, 2021. We collect only the data we need, process it for clear purposes, support access/correction/erasure, and provide a grievance contact.
- Where is my data stored? - CIPHER CRM runs on reputable, industry-standard cloud infrastructure with provider-managed network and physical security controls. For the specific hosting region or data-residency arrangement for your organisation, contact us and we will confirm the details.
- Can I get a DPA (Data Processing Agreement)? - Yes. We offer a Data Processing Agreement covering how we process personal data on your behalf, our sub-processors, and international-transfer safeguards. Email hello@ciphercrm.co with the subject "DPA request" and we will share it.
- How do I request my data or ask for deletion? - Email hello@ciphercrm.co with your request (access, correction, deletion, portability or objection). We verify the request and respond within 30 days. If CIPHER holds the data on behalf of a customer, we route the request to that customer as the data controller.
- Who are your sub-processors? - We use vetted sub-processors for cloud hosting, transactional email and product analytics, each under contractual data-protection safeguards. We can provide the canonical named list, with purpose and region, on request and commit to reasonable notice of material changes.
Compliance boxes ticked? See CIPHER CRM on your own data
-
Free demo
-
no card
-
live in 1-3 days
-
join 192+ businesses on CIPHER CRM.