Skip to main content

Legal · Effective 18 August 2026

Privacy Policy

This Privacy Policy describes how cyfare.net ("CYFARE", "we", "us", "our"), operated by an individual sole proprietor in India, collects, uses, stores, shares and protects personal data when you use the Platform. This Policy is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDP Act"). CYFARE acts as the "Data Fiduciary" for personal data processed through the Platform.

1. Data We Collect

We collect only what is necessary:

We do not knowingly collect personal data of children below 18 years. We do not seek to collect sensitive personal data except S32 verification documents, which are processed with explicit consent and strict access controls.

2. Purposes & Lawful Basis

Personal data is processed for specific, clear and lawful purposes with your consent (given at registration, checkout or submission), or for legitimate uses permitted under Section 7 of the DPDP Act: providing and operating the services; authentication and account security; processing orders and payments; fraud, abuse and security incident prevention; verification of S32 eligibility; responding to support and legal requests; and complying with legal obligations, lawful directions of courts, or requisitions of authorized government agencies under applicable law (including the IT Act, 2000 and the Bharatiya Nagarik Suraksha Sanhita, 2023).

3. How Scanning Data Is Handled

Files submitted to malware scanning tools are processed transiently to produce the requested report, are not used for profiling or advertising, and are retained only as long as technically required to deliver the result and maintain security logs, after which they are deleted.

4. Sharing & Disclosure

We do not sell, rent or trade your personal data. Disclosure is limited to:

5. Data Storage, Retention & Security

Data is stored on infrastructure located in India and/or with reputable cloud providers, protected by reasonable security practices and procedures as required by the SPDI Rules, including access controls, encryption in transit (TLS), hashing of passwords and least-privilege access. Personal data is retained only while your account is active or as needed for the purposes above and to comply with legal obligations (for example, transaction records under tax law), after which it is erased or anonymized.

6. Your Rights (Data Principal Rights)

Under the DPDP Act, 2023 you have the right to: (a) access information about your personal data and its processing; (b) request correction, completion, updating and erasure; (c) withdraw consent (without affecting the lawfulness of prior processing); (d) grievance redressal; and (e) nominate a person to exercise your rights in the event of death or incapacity. To exercise any right, email legal@cyfare.net. Withdrawal of consent or erasure requests may limit our ability to provide services that depend on that data.

7. Cookies & Similar Technologies

The Platform uses only functional cookies/local storage needed for sessions, authentication, security and preferences. We do not use third-party advertising trackers. You may disable cookies in your browser, though parts of the Platform may then not function.

8. Cross-Border Transfer

Personal data is primarily processed in India. Where processing involves infrastructure outside India, it occurs subject to the restrictions of the DPDP Act, 2023 and any government notifications thereunder, and with contractual safeguards.

9. Grievance Redressal & Data Protection Contact

For any question, complaint or request regarding your personal data, contact the Grievance Officer at legal@cyfare.net. Grievances are acknowledged within 24 hours and resolved within 15 days, in accordance with the SPDI Rules and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. If you remain unsatisfied, you may approach the Data Protection Board of India in accordance with the DPDP Act, 2023.

10. Changes to this Policy

We may update this Policy from time to time. Material changes will be notified by posting the revised Policy on this page with a new effective date. Continued use of the Platform after the effective date constitutes acceptance.

Data Fiduciary: [Proprietor Full Name], Sole Proprietor, trading as CYFARE, [Registered Address], India · Contact: legal@cyfare.net