Creative Cyber operates three enterprise platforms and a corporate website under the creativecyber.in domain. This policy applies to all products and services, including the Corporate Website (creativecyber.in), RiskSage, DPDP Assurance, and Practitioner Toolkit.
Creative Cyber ("we", "us", "our") is a cybersecurity and DPDP compliance platform. We are committed to handling all personal data with transparency, integrity, and respect for your rights under India's Digital Personal Data Protection (DPDP) Act, 2023.
This Privacy Policy governs how we collect, use, store, share, and protect personal data across all Creative Cyber platforms and services. By accessing or using any of our platforms, you agree to the terms of this Policy.
| Data Fiduciary | Creative Cyber |
| Registered Address | D303, Ushanagar Coop Hsg Society, Village Road, Bhandup, Mumbai 400078, Maharashtra |
| Grievance Officer | Email: info@creativecyber.in |
| Effective Date | 19 September 2026 (version 2.2; first effective 1 July 2025) |
| Governing Law | Digital Personal Data Protection (DPDP) Act, 2023, India |
This Policy applies to personal data processed across the following products and digital touchpoints:
| Platform | URL / Access | Primary Audience |
|---|---|---|
| Corporate Website | creativecyber.in | Public visitors, professionals, blog readers |
| RiskSage | risksage.creativecyber.in | CISOs, Risk Officers, IT security teams in BFSI |
| DPDP Assurance | dpdp-assessment.creativecyber.in | DPOs, Compliance teams, BFSI enterprises |
| Practitioner Toolkit | practitioner-toolkit.creativecyber.in | Registered cybersecurity and privacy practitioners |
| Knowledge Portal | creativecyber.in/knowledge | Professionals reading gated practitioner guides, checklists and tools |
We collect personal data only to the extent necessary to deliver our services. The categories of data collected vary by product.
Privacy note: Our custom website analytics system hashes IP addresses using salted SHA-256 before any storage, so raw IP addresses are never retained by that system. Other systems do store the IP address in plain form for fraud prevention and security: contact and enquiry forms, Knowledge Portal registration (Section 3.5), one-time passcodes, administrator security logs, and sign-in, token and audit records on our product platforms (Sections 3.2 to 3.4). See Section 10.
Important: DPDP Assurance processes compliance metadata about your organisation — it does not process personal data of your organisation's end customers. If you upload documents containing third-party personal data, you are responsible for ensuring appropriate consent or lawful basis for that upload.
Privacy note: on these records the IP address and user-agent are stored in plain form. See Section 10.
Under the DPDP Act, 2023, we process personal data on the following bases:
| Legal Basis | Processing Activity | Applicable Platforms |
|---|---|---|
| Consent (DPDP Act, S.6) | Newsletter subscription, marketing communications, non-essential cookies (GA4) | Corporate Website, all products |
| Consent (DPDP Act, S.6) | Knowledge Portal registration, and recording which articles you read under your registered email for follow-up by our team. Consent is given by submitting the registration form, which carries this notice and a link to this Policy | Knowledge Portal |
| Contractual necessity | Account creation, service delivery, billing, platform features | RiskSage, DPDP Assurance, Practitioner Toolkit |
| Legitimate interests | Security monitoring, fraud prevention, product improvement, audit logs | All platforms |
| Legal obligation | Statutory record-keeping, regulatory compliance, responding to lawful government requests | All platforms |
We do not sell your personal data. We do not share your data with third parties for their own marketing purposes. Sharing occurs only in the limited circumstances described below.
We engage the following categories of service providers who process data on our behalf, subject to data processing agreements and DPDP-compliant obligations:
The Practitioner Toolkit uses Creative Cyber's centralised identity service. When you authenticate, your identity token may be shared across linked Creative Cyber platforms to enable seamless access. This is a first-party integration; no identity data is shared with external third parties.
We may disclose personal data to government authorities, regulatory bodies, or law enforcement when required by law, court order, or to protect the rights, safety, or property of Creative Cyber or others. We will notify affected users to the extent permitted by law.
In the event of a merger, acquisition, or asset sale, personal data may be transferred to the successor entity, subject to equivalent privacy protections. Affected users will be notified.
We retain personal data only as long as necessary for the purpose for which it was collected, or as required by law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Account data (all products) | Duration of account + 2 years after closure | Contractual; potential dispute resolution |
| DPDP Assurance compliance records | 7 years | Regulatory best practice for compliance artefacts |
| RiskSage assessment data | Duration of account + 3 years | Longitudinal risk trending; contractual |
| Practitioner Toolkit profile | Duration of account + 1 year | Contractual; SSO audit trail |
| Contact form submissions | 2 years from submission | Legitimate interest; support reference |
| Newsletter subscriptions | Until unsubscribe + 30 days | Consent-based; processing window |
| Analytics / page view data | 13 months | GA4 default; product analytics |
| Hashed rate-limit identifiers | 30 days rolling | Security and fraud prevention |
| Application error and performance logs | Until the log rolls over (by size, not by date) | Technical operations |
| Web server access logs on the corporate website and DPDP Assurance server (include IP addresses) | About 10 days | Security and technical operations |
| Proxy and web-server access logs on the RiskSage and Practitioner Toolkit servers, and security-tool records (include IP addresses) | About 7 days | Security and technical operations |
| Platform audit logs (RiskSage, DPDP Assurance, Practitioner Toolkit), including IP address and browser user-agent | 2 years, deleted automatically each month | Security, accountability and compliance trail |
| Platform sign-in sessions, refresh tokens and one-time tokens (RiskSage, Practitioner Toolkit), including IP address | Kept with the account (see account data above); expired records are not yet deleted automatically | Security and account administration |
| Practitioner Toolkit scan-agent authentication log (IP address of each attempt) | 90 days | Rate limiting and abuse prevention |
| Database backups (contain the data above, including IP addresses) | 7 daily copies on the primary servers. A disaster-recovery copy of the RiskSage and Practitioner Toolkit databases on a separate server is not yet deleted automatically | Disaster recovery and continuity |
| Knowledge Portal registration and reading records | 2 years from registration or last activity | Lead follow-up and content planning; same period as contact form submissions |
| Billing records | 7 years | GST / tax statutory obligations |
As a Data Principal under the DPDP Act, 2023, you have the following rights with respect to your personal data held by Creative Cyber:
| Right | What It Means |
|---|---|
| Right to Access | Request a summary of your personal data we hold and the purposes for which it is processed. |
| Right to Correction | Request correction of any inaccurate or incomplete personal data. |
| Right to Erasure | Request deletion of your personal data where it is no longer necessary or where consent is withdrawn. Subject to statutory retention obligations. |
| Right to Withdraw Consent | Withdraw consent for any processing based on consent (e.g., newsletters, non-essential cookies) at any time, without affecting prior processing. |
| Right to Grievance Redressal | Raise a complaint or grievance with our Grievance Officer within the timelines specified by the DPDP Act. |
| Right to Nominate | Nominate another person to exercise rights on your behalf in the event of incapacity or death, as permitted under the DPDP Act. |
To exercise any of the above rights, contact our Grievance Officer at info@creativecyber.in. We will acknowledge your request within 72 hours and aim to resolve it within 30 days of receipt.
We use cookies and similar technologies to operate our platforms and, with your consent, to measure usage and behaviour.
| Cookie Type | Consent Required | Purpose |
|---|---|---|
| Strictly Necessary | No — essential to platform operation | Authentication sessions, CSRF protection, rate-limit tokens |
| Functional | Yes | User preferences, language settings, saved dashboard state |
| Analytics (GA4) | Yes | Page performance measurement, session analytics, content engagement (IP anonymised) |
| Analytics (Custom) | No — privacy-safe by design | Custom page view tracking with hashed, salted IP; no third-party data sharing |
| Knowledge access token (browser local storage) | No — needed for the access you requested | Remembers your confirmed 90-day Knowledge Portal access on that browser |
| Privacy-policy notice acknowledgement (browser local storage; on our platforms also a small first-party cookie) | No — needed to remember that you dismissed the notice | Records that you have seen the current privacy-policy update notice so we do not show it again until the policy changes materially. It holds only the policy version number (for example 2.2), no personal data. On this website and the Knowledge Portal it is kept in your browser's local storage until you clear your browser data. On RiskSage, DPDP Assurance and the Practitioner Toolkit it is kept in local storage and in a small first-party cookie for up to about a year from your last visit |
A cookie consent banner is displayed to users on first visit to our website. You may update your preferences at any time via the Cookie Settings link in our website footer.
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, and destruction. Key measures include:
Despite these measures, no internet-based transmission is completely secure. Contact us immediately at info@creativecyber.in if you suspect any unauthorised access to your account.
Our primary data storage and processing infrastructure is located in India. Where we use third-party service providers (such as Google Analytics 4 or Zoho) that may process data outside India, we ensure that such transfers comply with applicable provisions of the DPDP Act, 2023 and any Rules notified thereunder regarding cross-border data transfer.
Our platforms are designed for business and professional users. We do not knowingly collect personal data from children (persons under 18 years of age). If you believe we have inadvertently collected data from a minor, please contact us at info@creativecyber.in and we will promptly delete such data.
DPDP Assurance is a business-to-business (B2B) compliance tool. The data you enter into the platform pertains to your organisation's compliance posture, not to end consumers. Creative Cyber acts as a Data Processor with respect to any personal data you (as a Data Fiduciary) upload or enter into the platform for compliance assessment purposes. A Data Processing Agreement (DPA) is available on request for enterprise customers.
Risk assessment results, scores, and reports generated within RiskSage are confidential to your account and are not shared with other users or organisations. Aggregated and fully anonymised benchmarking data (with no organisation-level identifiers) may be used to improve platform risk models.
The Practitioner Toolkit authenticates users via Creative Cyber's centralised identity service. Your session token and identity profile may be shared across Creative Cyber platforms where you are authenticated. This is a first-party SSO integration; no identity data is shared with external third parties.
We may update this Privacy Policy from time to time. Material changes will be communicated via:
Continued use of our platforms after the effective date of any update constitutes acceptance of the revised policy.
If you have any questions, concerns, or wish to exercise any of your rights under this Privacy Policy or the DPDP Act, 2023, please contact:
| Grievance Officer | Creative Cyber |
| Address | D303, Ushanagar Coop Hsg Society, Village Road, Bhandup, Mumbai 400078, Maharashtra |
| info@creativecyber.in | |
| Response Timeline | Acknowledgement within 72 hours · Resolution within 30 days |
If you are unsatisfied with our response, you may raise a complaint with the Data Protection Board of India as established under the DPDP Act, 2023.
We use cookies and analytics (Google Analytics) to improve your experience. Under India's Digital Personal Data Protection Act, 2023, we require your consent before collecting any usage data. Privacy Policy