Privacy Policy

Version 2.2 · Effective 19 September 2026 · Last Updated 20 September 2026

Creative Cyber operates three enterprise platforms and a corporate website under the creativecyber.in domain. This policy applies to all products and services, including the Corporate Website (creativecyber.in), RiskSage, DPDP Assurance, and Practitioner Toolkit.

1. Overview & Data Controller Identity

Creative Cyber ("we", "us", "our") is a cybersecurity and DPDP compliance platform. We are committed to handling all personal data with transparency, integrity, and respect for your rights under India's Digital Personal Data Protection (DPDP) Act, 2023.

This Privacy Policy governs how we collect, use, store, share, and protect personal data across all Creative Cyber platforms and services. By accessing or using any of our platforms, you agree to the terms of this Policy.

Data FiduciaryCreative Cyber
Registered AddressD303, Ushanagar Coop Hsg Society, Village Road, Bhandup, Mumbai 400078, Maharashtra
Grievance OfficerEmail: info@creativecyber.in
Effective Date19 September 2026 (version 2.2; first effective 1 July 2025)
Governing LawDigital Personal Data Protection (DPDP) Act, 2023, India

2. Scope of This Policy

This Policy applies to personal data processed across the following products and digital touchpoints:

PlatformURL / AccessPrimary Audience
Corporate Websitecreativecyber.inPublic visitors, professionals, blog readers
RiskSagerisksage.creativecyber.inCISOs, Risk Officers, IT security teams in BFSI
DPDP Assurancedpdp-assessment.creativecyber.inDPOs, Compliance teams, BFSI enterprises
Practitioner Toolkitpractitioner-toolkit.creativecyber.inRegistered cybersecurity and privacy practitioners
Knowledge Portalcreativecyber.in/knowledgeProfessionals reading gated practitioner guides, checklists and tools

3. Personal Data We Collect

We collect personal data only to the extent necessary to deliver our services. The categories of data collected vary by product.

3.1 Corporate Website (creativecyber.in)

  • Contact form submissions: name, professional email address, organisation name, message content
  • Newsletter subscriptions: email address and preference settings
  • Analytics data: page views, session duration, referral source — our website analytics store only a salted hash of your IP address, never the raw address
  • Technical metadata: browser type, device type, approximate geographic region (country/state level only)

Privacy note: Our custom website analytics system hashes IP addresses using salted SHA-256 before any storage, so raw IP addresses are never retained by that system. Other systems do store the IP address in plain form for fraud prevention and security: contact and enquiry forms, Knowledge Portal registration (Section 3.5), one-time passcodes, administrator security logs, and sign-in, token and audit records on our product platforms (Sections 3.2 to 3.4). See Section 10.

3.2 RiskSage (risksage.creativecyber.in)

  • Account registration data: full name, business email address, job title, organisation name, industry sector
  • Assessment inputs: cyber risk posture data, control gap information, maturity scores entered by the user or organisation
  • Organisation profile: sector, employee count range, existing security frameworks in use
  • Usage telemetry: feature interactions, report generation events, session metadata
  • Security and audit records: the IP address (and, for sign-in sessions, the browser user-agent) is recorded in plain form with sign-in sessions, refresh tokens, audit-log entries, AI-usage records, evidence uploads and risk-model runs
  • Communication preferences and notification settings

3.3 DPDP Assurance Platform (dpdp-assessment.creativecyber.in)

  • Account data: name, designation, work email, organisation name, role (Data Fiduciary / DPO / Compliance Officer)
  • Compliance assessment inputs: responses to DPDP control questionnaires, gap findings, evidence artefacts uploaded by the user
  • Organisational data: business entity details provided for compliance scoping (not customer PII of BFSI clients)
  • Workflow and collaboration data: task assignments, comments, review status within the platform
  • Audit logs: user action logs for accountability and compliance trail purposes, recorded with your IP address and browser user-agent (data-subject-request audit entries also record the IP address)
  • Subscription and billing metadata: plan tier, payment reference IDs (full card details are not stored; payment processing is handled by our payment partner)

Important: DPDP Assurance processes compliance metadata about your organisation — it does not process personal data of your organisation's end customers. If you upload documents containing third-party personal data, you are responsible for ensuring appropriate consent or lawful basis for that upload.

3.4 Practitioner Toolkit (practitioner-toolkit.creativecyber.in)

  • Identity and authentication data: name, email address, professional credentials or certifications declared during registration
  • Profile data: professional bio, area of specialisation, organisation affiliation
  • Single Sign-On (SSO) / centralised identity: the Practitioner Toolkit uses Creative Cyber's centralised identity service, which may share authentication tokens across integrated platforms
  • Toolkit usage data: downloads, tool interactions, assessment history within the toolkit
  • Security and audit records: the IP address and browser user-agent are recorded in plain form with sign-in sessions, one-time tokens (such as invitation, verification and reset), audit-log entries and platform action records; the IP address of each vulnerability-scan agent authentication attempt is also logged
  • Communication and support interactions: messages submitted to support or feedback channels

3.5 Knowledge Portal & Content Gate (creativecyber.in/knowledge)

  • Registration data: professional email address, role and organisation name
  • Content engagement data: which gated articles you unlock and when, together with your IP address and browser user-agent
  • Access credential: once you confirm your email address, a signed token valid for 90 days is kept in your browser's local storage (not a cookie). Our server stores only a hash of that token, its expiry and the status of your access, so that it can check the token each time you open a gated article

Privacy note: on these records the IP address and user-agent are stored in plain form. See Section 10.

3.6 Data Collected Automatically (All Platforms)

  • Session tokens and cookies (see Section 9 for details)
  • Hashed device fingerprint components for rate-limiting and fraud prevention
  • Web server access logs, which include IP addresses and requested URLs
  • Application error and performance logs, kept until the log rolls over (by size, not by date); see Section 7

4. Legal Basis for Processing

Under the DPDP Act, 2023, we process personal data on the following bases:

Legal BasisProcessing ActivityApplicable Platforms
Consent (DPDP Act, S.6)Newsletter subscription, marketing communications, non-essential cookies (GA4)Corporate Website, all products
Consent (DPDP Act, S.6)Knowledge Portal registration, and recording which articles you read under your registered email for follow-up by our team. Consent is given by submitting the registration form, which carries this notice and a link to this PolicyKnowledge Portal
Contractual necessityAccount creation, service delivery, billing, platform featuresRiskSage, DPDP Assurance, Practitioner Toolkit
Legitimate interestsSecurity monitoring, fraud prevention, product improvement, audit logsAll platforms
Legal obligationStatutory record-keeping, regulatory compliance, responding to lawful government requestsAll platforms

5. How We Use Your Personal Data

5.1 Service Delivery

  • Creating and managing your account across our platforms
  • Providing access to RiskSage assessments, DPDP Assurance compliance workflows, and Practitioner Toolkit resources
  • Processing subscription plans, plan upgrades, and billing communications
  • Delivering knowledge articles, reports, and newsletters you have subscribed to

5.2 Security & Platform Integrity

  • Detecting and preventing unauthorised access, fraud, or abuse
  • Rate-limiting requests: page-view and reaction limits use hashed identifiers; form, registration and passcode limits use the IP address, which is held in the server's memory only (it is not written to a database or to disk) and is cleared when the server restarts
  • Maintaining audit trails for compliance accountability within the DPDP Assurance platform
  • SSO session management for users authenticated via the Practitioner Toolkit identity service

5.3 Compliance & Legal

  • Maintaining records required under applicable Indian law, including the DPDP Act, 2023
  • Responding to lawful requests from regulatory authorities or law enforcement
  • Exercising or defending legal rights

5.4 Product Improvement & Analytics

  • Analysing aggregated and anonymised usage data to improve product features
  • Measuring page performance and content engagement via custom analytics and Google Analytics 4
  • Conducting user research with explicit consent of participants

5.5 Communications

  • Sending transactional emails (account confirmations, password resets, plan notifications)
  • Sending newsletters and product updates to subscribers who have given consent
  • Responding to support and contact form queries

5.6 Content Engagement & Lead Attribution

  • When you register to read gated content on our Knowledge Portal, we record which articles you view and associate this with your registered email address, role and organisation
  • We use this to understand which topics are relevant to you, to prioritise follow-up from our team, and to plan future content
  • This data is visible to our internal team through an access-controlled administrator interface

6. Data Sharing & Disclosure

We do not sell your personal data. We do not share your data with third parties for their own marketing purposes. Sharing occurs only in the limited circumstances described below.

6.1 Service Providers (Data Processors)

We engage the following categories of service providers who process data on our behalf, subject to data processing agreements and DPDP-compliant obligations:

  • Email delivery: Zoho SMTP (transactional and notification emails)
  • Analytics: Google Analytics 4 (with IP anonymisation enabled; governed by your cookie consent)
  • Cloud infrastructure: hosting and database providers for platform operations
  • Payment processing: our payment partner for subscription billing (we retain only payment reference IDs, not full card data)

6.2 SSO & Identity Integration

The Practitioner Toolkit uses Creative Cyber's centralised identity service. When you authenticate, your identity token may be shared across linked Creative Cyber platforms to enable seamless access. This is a first-party integration; no identity data is shared with external third parties.

6.3 Legal & Regulatory Disclosure

We may disclose personal data to government authorities, regulatory bodies, or law enforcement when required by law, court order, or to protect the rights, safety, or property of Creative Cyber or others. We will notify affected users to the extent permitted by law.

6.4 Business Transfers

In the event of a merger, acquisition, or asset sale, personal data may be transferred to the successor entity, subject to equivalent privacy protections. Affected users will be notified.

7. Data Retention

We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law.

Data CategoryRetention PeriodBasis
Account data (all products)Duration of account + 2 years after closureContractual; potential dispute resolution
DPDP Assurance compliance records7 yearsRegulatory best practice for compliance artefacts
RiskSage assessment dataDuration of account + 3 yearsLongitudinal risk trending; contractual
Practitioner Toolkit profileDuration of account + 1 yearContractual; SSO audit trail
Contact form submissions2 years from submissionLegitimate interest; support reference
Newsletter subscriptionsUntil unsubscribe + 30 daysConsent-based; processing window
Analytics / page view data13 monthsGA4 default; product analytics
Hashed rate-limit identifiers30 days rollingSecurity and fraud prevention
Application error and performance logsUntil the log rolls over (by size, not by date)Technical operations
Web server access logs on the corporate website and DPDP Assurance server (include IP addresses)About 10 daysSecurity and technical operations
Proxy and web-server access logs on the RiskSage and Practitioner Toolkit servers, and security-tool records (include IP addresses)About 7 daysSecurity and technical operations
Platform audit logs (RiskSage, DPDP Assurance, Practitioner Toolkit), including IP address and browser user-agent2 years, deleted automatically each monthSecurity, accountability and compliance trail
Platform sign-in sessions, refresh tokens and one-time tokens (RiskSage, Practitioner Toolkit), including IP addressKept with the account (see account data above); expired records are not yet deleted automaticallySecurity and account administration
Practitioner Toolkit scan-agent authentication log (IP address of each attempt)90 daysRate limiting and abuse prevention
Database backups (contain the data above, including IP addresses)7 daily copies on the primary servers. A disaster-recovery copy of the RiskSage and Practitioner Toolkit databases on a separate server is not yet deleted automaticallyDisaster recovery and continuity
Knowledge Portal registration and reading records2 years from registration or last activityLead follow-up and content planning; same period as contact form submissions
Billing records7 yearsGST / tax statutory obligations

8. Your Rights Under the DPDP Act, 2023

As a Data Principal under the DPDP Act, 2023, you have the following rights with respect to your personal data held by Creative Cyber:

RightWhat It Means
Right to AccessRequest a summary of your personal data we hold and the purposes for which it is processed.
Right to CorrectionRequest correction of any inaccurate or incomplete personal data.
Right to ErasureRequest deletion of your personal data where it is no longer necessary or where consent is withdrawn. Subject to statutory retention obligations.
Right to Withdraw ConsentWithdraw consent for any processing based on consent (e.g., newsletters, non-essential cookies) at any time, without affecting prior processing.
Right to Grievance RedressalRaise a complaint or grievance with our Grievance Officer within the timelines specified by the DPDP Act.
Right to NominateNominate another person to exercise rights on your behalf in the event of incapacity or death, as permitted under the DPDP Act.

To exercise any of the above rights, contact our Grievance Officer at info@creativecyber.in. We will acknowledge your request within 72 hours and aim to resolve it within 30 days of receipt.

9. Cookies & Tracking Technologies

We use cookies and similar technologies to operate our platforms and, with your consent, to measure usage and behaviour.

Cookie TypeConsent RequiredPurpose
Strictly NecessaryNo — essential to platform operationAuthentication sessions, CSRF protection, rate-limit tokens
FunctionalYesUser preferences, language settings, saved dashboard state
Analytics (GA4)YesPage performance measurement, session analytics, content engagement (IP anonymised)
Analytics (Custom)No — privacy-safe by designCustom page view tracking with hashed, salted IP; no third-party data sharing
Knowledge access token (browser local storage)No — needed for the access you requestedRemembers your confirmed 90-day Knowledge Portal access on that browser
Privacy-policy notice acknowledgement (browser local storage; on our platforms also a small first-party cookie)No — needed to remember that you dismissed the noticeRecords that you have seen the current privacy-policy update notice so we do not show it again until the policy changes materially. It holds only the policy version number (for example 2.2), no personal data. On this website and the Knowledge Portal it is kept in your browser's local storage until you clear your browser data. On RiskSage, DPDP Assurance and the Practitioner Toolkit it is kept in local storage and in a small first-party cookie for up to about a year from your last visit

A cookie consent banner is displayed to users on first visit to our website. You may update your preferences at any time via the Cookie Settings link in our website footer.

10. Data Security

We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. Key measures include:

  • Transport security: all data in transit is encrypted using TLS 1.2 or higher
  • Database security: personal data stored in PostgreSQL with access control and encrypted connections
  • IP address handling: our website analytics, page-reaction and page-view rate-limiting systems store only a salted SHA-256 hash of the IP address. Contact and enquiry forms, Knowledge Portal registration and reading records, one-time passcodes and administrator security logs store the IP address in plain form for fraud prevention, security and lead attribution. RiskSage, DPDP Assurance and the Practitioner Toolkit also store the IP address (and usually the browser user-agent) in plain form in sign-in session, token and audit-log records (Sections 3.2 to 3.4). Our web servers also record IP addresses in standard access logs, kept for about 10 days.
  • Authentication: token-based session management for admin and authenticated product interfaces
  • Infrastructure: services run within containerised environments behind Nginx reverse proxy with restricted exposure
  • Access controls: production credentials and environment variables are managed as secrets
  • Rate limiting: API endpoints are protected against abuse through rate-limiting mechanisms

Despite these measures, no internet-based transmission is completely secure. Contact us immediately at info@creativecyber.in if you suspect any unauthorised access to your account.

11. Cross-Border Data Transfers

Our primary data storage and processing infrastructure is located in India. Where we use third-party service providers (such as Google Analytics 4 or Zoho) that may process data outside India, we ensure that such transfers comply with applicable provisions of the DPDP Act, 2023 and any Rules notified thereunder regarding cross-border data transfer.

12. Children's Privacy

Our platforms are designed for business and professional users. We do not knowingly collect personal data from children (persons under 18 years of age). If you believe we have inadvertently collected data from a minor, please contact us at info@creativecyber.in and we will promptly delete such data.

13. Product-Specific Privacy Notes

13.1 DPDP Assurance — B2B Compliance Tool

DPDP Assurance is a business-to-business (B2B) compliance tool. The data you enter into the platform pertains to your organisation's compliance posture, not to end consumers. Creative Cyber acts as a Data Processor with respect to any personal data you (as a Data Fiduciary) upload or enter into the platform for compliance assessment purposes. A Data Processing Agreement (DPA) is available on request for enterprise customers.

13.2 RiskSage — Risk Assessment Data

Risk assessment results, scores, and reports generated within RiskSage are confidential to your account and are not shared with other users or organisations. Aggregated and fully anonymised benchmarking data (with no organisation-level identifiers) may be used to improve platform risk models.

13.3 Practitioner Toolkit — SSO and Identity

The Practitioner Toolkit authenticates users via Creative Cyber's centralised identity service. Your session token and identity profile may be shared across Creative Cyber platforms where you are authenticated. This is a first-party SSO integration; no identity data is shared with external third parties.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via:

  • A banner notification on the affected platform(s)
  • Email notification to registered account holders
  • Updated "Effective Date" and version number at the top of this document

Version 2.2 (effective 19 September 2026): what changed

  • Extended the IP address and browser user-agent disclosure to RiskSage, DPDP Assurance and the Practitioner Toolkit: sign-in sessions, tokens and audit logs (Sections 3.1 to 3.4 and 10)
  • Added retention periods for platform audit logs, session and token records, the Practitioner Toolkit scan-agent authentication log, proxy and web-server access logs on the platform servers, and database backups (Section 7)
  • Replaced the earlier "anonymised server logs, 30 days" entry, which did not describe how our logs actually work (Section 7)
  • Clarification added 20 September 2026: listed the privacy-policy notice acknowledgement in the cookies and browser storage table (Section 9). It records only that you dismissed the notice; no practice changed

Version 2.1 (effective 19 September 2026): what changed

  • Corrected how we describe IP address handling: our website analytics store only a salted hash, while forms, one-time passcodes, administrator security logs and the Knowledge Portal store the IP address in plain form (Sections 3.1, 3.5, 5.2 and 10)
  • Added the Knowledge Portal and Content Gate, including the access token kept in your browser and what our server stores about it (Sections 2, 3.5 and 9)
  • Added how we record which Knowledge Portal articles you read under your registered email, why, and that we rely on your consent for it (Sections 4 and 5.6)
  • Added retention periods for web server access logs and for Knowledge Portal registration and reading records (Section 7)

Continued use of our platforms after the effective date of any update constitutes acceptance of the revised policy.

15. Grievance Redressal & Contact

If you have any questions, concerns, or wish to exercise any of your rights under this Privacy Policy or the DPDP Act, 2023, please contact:

Grievance OfficerCreative Cyber
AddressD303, Ushanagar Coop Hsg Society, Village Road, Bhandup, Mumbai 400078, Maharashtra
Emailinfo@creativecyber.in
Response TimelineAcknowledgement within 72 hours · Resolution within 30 days

If you are unsatisfied with our response, you may raise a complaint with the Data Protection Board of India as established under the DPDP Act, 2023.

    We use cookies and analytics (Google Analytics) to improve your experience. Under India's Digital Personal Data Protection Act, 2023, we require your consent before collecting any usage data. Privacy Policy