On this page
Scope
The GDPR applies where we process the personal data of individuals in the EU/EEA - regardless of where CIPHER is incorporated. This page describes our GDPR-aligned practices for those users. It sits alongside our Privacy Policy and Compliance page, which also cover India's DPDP Act, 2023 and IT Rules, 2021.
Controller vs processor
In plain terms: for the data your team uploads into the CRM, you are in charge and we act on your instructions. For our own account and marketing data, we are in charge.
- CIPHER as processor - for the end-customer records our customers upload into CIPHER CRM. The customer is the controller; we process that data under their instructions and our agreement.
- CIPHER as controller - for our own website visitors, prospects, account holders and marketing contacts.
Lawful bases (Article 6)
In plain terms: every use of your data has a legal reason behind it - a contract with you, your consent, a genuine business need, or the law.
We rely on the appropriate lawful basis for each purpose:
- Contract - to deliver the service and support our customers.
- Consent - for marketing you opt into (withdrawable at any time).
- Legitimate interest - to secure the platform, prevent abuse and improve the product, balanced against your rights.
- Legal obligation - to meet legal, tax and regulatory duties.
Data-subject rights
In plain terms: you can ask to see, correct, delete, restrict, move or object to your data - email us and we respond within 30 days.
Under the GDPR you can exercise the following rights:
- Access - a copy of your personal data.
- Rectification - correction of inaccurate or incomplete data.
- Erasure (Article 17) - deletion where the law allows.
- Restriction - limit processing in certain cases.
- Portability - your data in a portable, machine-readable form.
- Objection - to certain processing, including direct marketing.
How to exercise them: email hello@ciphercrm.co. We verify your request and respond within 30 days. Where CIPHER is the processor, we route your request to the customer who is the controller.
Sub-processors & DPAs
In plain terms: a few trusted tools help run the service, each under contract. Customers can request a Data Processing Agreement and the sub-processor list any time.
We use a small set of vetted sub-processors (cloud hosting, transactional email, product analytics) under contractual data-protection terms, and we carry out due diligence before engaging them. A Data Processing Agreement (Article 28) is available to customers on request - email hello@ciphercrm.co. The canonical named sub-processor list, with purpose and region, is available on request; see our Compliance page.
International transfers
In plain terms: if EU data ever leaves the EEA, it travels under legal safeguards like Standard Contractual Clauses.
Where personal data leaves the EEA, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) or another mechanism recognised under the GDPR, together with any additional measures required to protect the data.
Breach notification
In plain terms: if a data breach ever happens, we contain it fast and, where GDPR applies, tell the authority within 72 hours.
If a personal-data breach occurs, we investigate and act to contain it, and - where the GDPR applies - we notify the relevant supervisory authority without undue delay and within 72 hours where feasible, and inform affected individuals where required. See our Security page for how we detect and respond to incidents.
Security measures
In plain terms: your data is encrypted in transit, kept behind role-based access and auto-logout, and monitored.
We apply technical and organisational measures appropriate to the risk, including encryption in transit over HTTPS/TLS, role-based access controls, inactivity auto-logout and monitoring. Full detail is on our Security page.
DPO / EU representative & Grievance Officer
Where a Data Protection Officer or EU representative is required for the processing we carry out, the appointed contact details will be published here. For all data-protection queries and grievances today - including under India's IT Rules, 2021 and DPDP Act, 2023 - you can contact CIPHER Craft Pvt. Ltd.:
✉️ hello@ciphercrm.co · 📞 +91 97122 00017 · 📍 Rajkot, Gujarat, India.
Records of processing (ROPA)
We maintain records of the processing activities we carry out. Relevant records can be made available to customers and competent supervisory authorities on request, to the extent required by law.
Changes to this page
We may update this page as our practices or the law change. The Effective and Last updated dates above show the current version. This page cross-links our Privacy Policy, Compliance, Cookie Policy and Security pages.
Also searched as: CIPHER CRM GDPR, CIPHER CRM data protection, CIPHER CRM DPA, CRM GDPR rights, CIPHER CRM sccs, CRM breach notification.