Privacy notice

What personal data we process on dpdpa.support and www.cynorsense.com, why, how long we keep it, and how to use your rights.

This notice explains what personal data CynorSense Solutions Private Limited (“Cynor Sense”, “we”, “us”) processes when you use our two websites, why, and what you can do about it. It covers:

  • dpdpa.support, the information site for the DPDPA Toolkit by Cynor Sense, where you can also buy the toolkit; and
  • www.cynorsense.com, a separate website that runs on Wix. It hosts the members-only program “DPDPA Compliance Toolkit”, where buyers watch the walkthrough videos and download the toolkit files. The program is by invitation: after you pay on dpdpa.support, we invite the email address you paid with. It is also where we describe our other services.

We decide why and how this personal data is processed, so for this processing we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (the “Act”). Office: 8-2-332/1/B, MBS Plaza, 5th Floor, Road No. 3, Banjara Hills, Hyderabad, Telangana, India – 500034.

When the law applies, and what we do now

The Act’s duties for Data Fiduciaries and the rights of Data Principals (sections 3 to 17, except section 6(9)) apply from 13 May 2027, under notification G.S.R. 843(E). The Digital Personal Data Protection Rules, 2025 on notices, security safeguards, breach intimation, retention, contact details and rights (rules 3 and 5 to 16) apply from the same date. We have written this notice to that standard and we honour the rights described below now, ahead of that date.

In short

WebsiteWhat we process
dpdpa.supportNo accounts. One optional sign-up form: on the duties list page you can give your email address, with a separate unticked box, to get five emails (see “Email updates” below). If you gave us your email address, you can use your rights on our privacy dashboard at dpdpa.support/rights/ after we email you a one-time code; the Your data rights page explains how. Google Analytics, which counts visits and sets cookies, runs only if you say yes in the banner. Your choice is recorded in a consent log on our own server. If you buy, Razorpay takes the payment on its own page. We then send your email address to Wix, which hosts our members area on www.cynorsense.com, so that it can create a member account for you if you have none and invite you to the toolkit program. We send you one email, through Microsoft 365, with the steps to get in. The toolkit files and videos are in the program, not in the email. Before you accept analytics, your browser loads nothing from any other website.
www.cynorsense.comOnly if you are invited to the program or have a member account there: your name, email address, password (held by Wix, not visible to us), your invitation and join record and your progress in the toolkit program; and any messages you send us. www.cynorsense.com runs on Wix, a separate platform from dpdpa.support, with its own cookies, set or controlled by that site; the dpdpa.support banner does not cover it. The toolkit is paid for on the Razorpay page, not on that site.

dpdpa.support: what is processed

On every visit

DataWhyHow long
Your IP address and the technical details your browser sends with every request (such as browser type and the page requested)To deliver the page to your browser. Our web server keeps no access log for dpdpa.support or www.dpdpa.support, so we do not keep a log of your visits.Not kept in an access log.
Your IP address and the page requested, only if an error occurs while our web server handles your requestOur web server keeps an error log, at error level only, to find and fix faults. An entry can contain your IP address only when an error occurs.Until the entry is rotated out: the log is kept in rotating files, up to 3 files of 10 MB, and the oldest file is deleted as new entries arrive.
Encrypted backup copies of our service records (the consent log, the subscriber list, delivery records and requests) and of our consent and grievance systemTo recover your data and our records if they are lost or damaged, as part of keeping them secure.We keep the 14 newest nightly copies; each older copy is deleted.
Your theme choice (“light” or “dark”), saved when you press the theme buttonTo show the site in the theme you picked. It is saved in your own browser’s local storage. It is never sent to us.Until you clear this site’s data in your browser.

The fonts, images, videos and scripts on dpdpa.support, including the animation library (GSAP), are served from our own server, not from third parties. We use Google Search Console, which gives us totals of the Google searches that showed or led to our pages. It does not run on our pages, sets nothing in your browser and gives us no data that identifies you.

Google Analytics: only if you say yes

On your first visit, a banner asks whether we may use Google Analytics. “Accept” and “Reject” are equally easy to press, and nothing is pre-selected. Until you press Accept, nothing from Google loads on dpdpa.support and nothing is sent to Google. If you press Reject or ignore the banner, Google Analytics stays off.

Personal dataWhyHow long
If you accept: the pages you view, and each page's type or topic (for example, an article on children's data); the page or campaign link that brought you here; whether you press a Buy button, play a preview video, read half or three-quarters of an article (with that article's topic and short web name) or scroll most of a page; your clicks on Buy and other buttons, links, tabs, toolkit cards, FAQs and other expandable parts, and where on the page; which sections of a page stay on your screen for at least a second; on our news page, whether a link you open goes to our own article or another site, and which part of the page it is in; which FAQ answers you open; which of our videos you play; which share button you press (LinkedIn, WhatsApp or email); the full web address of any link to another website that you click; when you start and finish the free processing map, and the business type you pick on it (online store or any business), while your other answers stay in your browser; your device type, browser, operating system, screen size and language; the general location (country and city) Google works out from your IP address; a random identifier stored in a cookie in your browser; and your IP address, which Google receives with each requestTo count visits and learn which pages and links help visitors, so we can improve the site and decide what to write next. Google Analytics 4 processes this for us. We have switched off Google signals, advertising storage and ad personalisation, so this data is not used to show you ads.We have set Google Analytics to keep event and user data for 14 months. When you withdraw, we stop collecting from your browser at once; data already collected is deleted when its 14 months end.

The analytics data is linked only to the random identifier in your browser, so we usually cannot find it from your email address. Withdrawing consent deletes the Google Analytics cookies, and so that identifier, from your browser.

We keep a record of each analytics and email-updates choice in a consent log on our own server, a virtual server hosted by Hostinger. New entries are only ever added to the log; existing entries are not changed. It is a log of what you agreed to and when; it is not a “Consent Manager” registered under the Act. We keep it because, if a question arises, we must be able to prove that we gave you the notice and that you consented (section 6(10)).

ChoiceWhat the record holds
Your analytics choice (Accept, Reject or withdrawal)A one-way hash of the random visitor ID created in your browser (the ID itself is never stored), your choice, the notice version label you saw (for example Notice 8 Oct 2026), the language of the page and the date and time. Your browser keeps the visitor ID and your choice in its local storage, so the banner does not appear on every page and a later change can be matched to the same entries.
Your email-updates choice (sign-up, unsubscribe or withdrawal)An identifier made from your email address with a secret key (a keyed one-way hash; the consent log cannot turn it back into the address), the purpose “email updates”, the notice version label you saw (2026-10-v5), the language of the page and the date and time.

The consent log holds no IP address, no email address and no name. It holds the version label; we keep the exact text of every notice version, so we can show what you were shown. Our service keeps your IP address only in its working memory, to limit repeated requests, until the service restarts; it does not write it to the consent log.

Our consent and grievance system. Each choice is also recorded in our consent and grievance system on our own server, which runs the privacy dashboard. For analytics it holds the same one-way hash of the visitor ID. For email updates it holds your email address itself (in lower case) as the identifier, with the purpose, your choice, the notice version and the date and time, because you sign in to the privacy dashboard with that address and the dashboard finds your consent by it. How long we keep it is set out in “How long we keep it” below.

Email updates (only if you tick the box)

On the duties list page (/dpdpa-duties/) you can ask for five emails by giving your email address and ticking a separate box that is not ticked for you. The list itself is free and needs no email address. The exact consent text you see next to the box is our consent notice version 2026-10-v5.

Personal dataWhyHow long
Your email address; where you signed up; the notice version and the page language; dated records of emails sent, unsubscribes, bounces, “stop” replies and purchasesTo send five emails over about 15 days: the DPDPA duties list; three explainers (security, breach reporting, rights and grievances); and the DPDPA Toolkit and its price. Nothing after the fifth; we stop early if you unsubscribe, reply “stop”, an email bounces or you buy. Your email address is kept in our own subscriber list on our server and, as the identifier for your consent, in our consent and grievance system; the consent log holds only a keyed hash of it. The emails are sent through Microsoft 365 from dpdpa@cynorsense.com, each with an unsubscribe link and a one-click unsubscribe header.As set out in “How long we keep it” below.

The random visitor ID in your browser is not stored with your email address, so signing up does not link your analytics data to you.

The privacy dashboard at /rights/

If you gave us your email address, you use your rights on our privacy dashboard at dpdpa.support/rights/. You sign in with that email address and a one-time code that our server emails to you; we do not ask for a password or an identity document. The dashboard runs on our consent and grievance system on our own server. The Your data rights page (dpdpa.support/your-data-rights/) explains the dashboard and links to it; that page has no form, sets nothing in your browser and its step-by-step illustration sends nothing.

  • Manage Consent: switch each consent on or off. Other purposes for which we process data, such as delivering a purchase, tax records and security logs, are listed for your information only: they do not rest on your consent, so they cannot be switched off there.
  • Consent History: every change to your consents, with its date.
  • Requests & Grievances: ask for a summary of your data, a correction or update, erasure, or a nomination, and raise grievances. What you file there reaches our consent and grievance system, which alerts us by email. The person who reads dpdpa@cynorsense.com handles it and replies by email. If you have not heard from us within 7 days, email dpdpa@cynorsense.com.

When you switch off email updates. The withdrawal is recorded in our consent and grievance system, which notifies our server, and our server stops the emails. Our server also checks your consent with that system before each update email it sends.

When data is erased. When the compliance check runs, nightly or when our Data Protection Officer runs it, it creates purge requests for withdrawn consents and erasure requests. Our server then carries it out: it removes your email address from our subscriber list, cancels any update still queued for you, and confirms the result back to the consent and grievance system. We keep what the law requires us to keep (section 12(3) of the Act), as set out in “How long we keep it” below.

Personal dataWhyHow long
The email address you type, and the one-time code we send to itTo check that the request comes from the person who gave us that address, and to find your consents and requests, which are held under that address.The code works once and only for 5 minutes. No copy of the code email is kept in our mailbox. To limit repeated requests, our server keeps a keyed one-way hash of the address with the times codes were sent (at most 5 an hour); entries older than one hour are removed the next time anyone asks for a code. Our consent and grievance system also keeps your IP address in its working memory for the same reason.
Kept in your browser’s session storage after the code is accepted: a sign-in token, your email address, our name and identifier as the Data Fiduciary, the dashboard’s settings, and a token used by the dashboard’s consent QR codeTo keep you signed in on the dashboard while you use it and show you your consents. See the Cookie policy.Until you sign out or close the browser tab. The sign-in token stops working after 24 hours at most.
What you file there: withdrawals, requests for a summary of your data, corrections, erasure requests, nominations (with the details of the person you nominate) and grievancesTo act on your request and keep a record of what you asked and what we did (sections 6(10) and 11 to 14 of the Act). Each one is filed in our consent and grievance system under your email address.As set out in “How long we keep it” below.

If you buy: the Razorpay payment page and delivery

The “Buy” buttons on dpdpa.support are links to a payment page hosted by Razorpay (pages.razorpay.com). Nothing from Razorpay loads on dpdpa.support itself. For a purchase here, we send your email address to Wix after you pay, so that you can get into the members-only program on www.cynorsense.com (see “www.cynorsense.com” below). If that invitation cannot be made automatically, we make it by hand within 24 hours, or our email gives you a single-use code to join.

Personal dataWhyHow long
What you enter on the Razorpay page: your email address, phone number and payment details, and the technical details your browser sends to Razorpay (such as your IP address)To take the payment. Razorpay Software Private Limited collects and processes it, and may store cookies or similar data on razorpay.com to take the payment and prevent fraud. Cynor Sense does not receive or store your card, UPI or bank details. See Razorpay’s privacy policy.Held by Razorpay under its own policy.
Your email address, phone number and the payment ID, passed by Razorpay to our delivery service on dpdpa.support when the payment is confirmed (the phone number is received but not stored)To give you access to the program. We send your email address to Wix, our processor, so that Wix can create a member account for it if it has none and invite it to the program. We then use your email address to send you one email, through Microsoft 365 from dpdpa@cynorsense.com, with the steps to get in. A copy of that email stays in the Sent Items of the dpdpa@cynorsense.com mailbox so we can check what was sent. Our delivery service does not store your phone number, and its records do not hold your email address: they keep the payment ID and a log of dated events (payment received, invitation made or failed, email sent or failed) that holds IDs and outcomes, not addresses.As set out in “How long we keep it” below.
Billing name, address and GSTIN, if you send them to us so that a GST invoice carries your organisation’s detailsTo issue a GST invoice and keep the tax records the law requires.For the period tax law sets; see “How long we keep it”.

www.cynorsense.com: what we process and why

A separate site. www.cynorsense.com runs on the Wix platform. Its cookies are set or controlled by that site (Wix and the apps installed there), not by dpdpa.support, and the dpdpa.support banner does not cover them. Wix.com Ltd and its affiliates (“Wix”) process the data below for us as our Data Processor.

The members area for buyers. After your payment we invite the email address you paid with to the members-only program at www.cynorsense.com/challenge-page/dpdpa-compliance-toolkit. If that address has no member account on www.cynorsense.com, we create one for it so the invitation can be sent, and Wix emails you a link to set a password. In the program you can watch the walkthrough videos and download the toolkit files, now and again later. The program is by invitation only and cannot be bought on that site.

Each row lists the personal data, the purpose, and the goods or service it makes possible.

Personal dataPurposeWhat it enables
Account: your name, email address and passwordTo create your member account and let you sign in. Wix stores and handles your password, including password resets; we cannot see it.Access to the walkthrough videos and toolkit files.
Join record: your invitation to the program, the date, and the details Wix holds for your member account (such as your name and email address)To give you a place in the program, link it to your account, and answer access and charge queries.Joining the program.
Payment details, only if you pay directly on www.cynorsense.comHandled by the payment provider that site’s checkout uses, under its own terms, to complete the payment.Paying for the program on that site.
Program activity: the steps you open or complete inside the toolkit programTo give you access to the program, show your progress and help you if you ask for support.Re-downloading the toolkit files and watching the videos.
Messages: what you write to us through Wix Chat or a site form, if you use them, with the contact details you giveTo reply to you and keep a record of what was agreed.Support, questions, requests and grievances.
Technical data: IP address, browser and device information, pages viewed, and cookiesCollected on www.cynorsense.com by Wix to run the site, keep it secure and give us Wix’s standard visitor statistics (such as site sessions and pages viewed). Apps installed on that site may collect data for their own purposes. See the Cookie policy.A working, secure site; a count of how the site is used.

Other services on www.cynorsense.com (not part of the toolkit)

Personal dataPurposeWhat it enables
Bookings and enquiries for our other services: the details a booking or enquiry form asks for, if you use oneTo respond to your enquiry and deliver the service you booked.The service you asked about.

Emails we send you. From dpdpa@cynorsense.com, through Microsoft 365, we send the one delivery email described above, messages about a duplicate or wrong charge, and replies to your messages. If you have a member account or are invited to the program on www.cynorsense.com, Wix sends that account’s own emails, including the link to set your password. When you email us, we keep your message and email address to reply and to keep a record of what was agreed. The only update emails we send are the five described in “Email updates” above, and only if you ticked the box for them; we also email the one-time code you ask for to sign in to the privacy dashboard. Any other update emails would need your separate consent, and we will update this notice first.

Why we may process this data

  • Purchases, member accounts and messages: you give us payment, join, account, billing and message details for the purpose stated above, and we use them only for that purpose (section 7(a) of the Act).
  • Google Analytics on dpdpa.support: only with your consent (section 6(1)), after showing you a notice of what is collected and why (section 5(1)). You can withdraw it at any time. Optional cookies on www.cynorsense.com are set or controlled by that site, not by dpdpa.support.
  • Email updates on dpdpa.support: only with your consent, given by ticking a separate box (section 6(1)), after showing you a notice of what is collected and why (section 5(1)). You can withdraw it at any time.
  • The privacy dashboard and your requests and grievances: we process your email address, the one-time code and what you send to act on your rights and grievances. From 13 May 2027 the Act requires this (sections 6(6) and 11 to 14 of the Act and Rule 14); we do it now, ahead of that date.
  • Invoices and tax records: you give us these details to buy (section 7(a) of the Act), and tax law requires us to keep the invoice. The Act lets us keep it for the period that law sets (sections 8(7) and 12(3)), and then we erase it.
  • Error logs and backups: to protect personal data and recover it if it is lost. This is part of handling the data you give us (section 7(a)), protected as section 8(5) requires. From 13 May 2027 Rule 6(1) requires logs, monitoring and backups, kept for one year (Rule 6(1)(e)). Today we keep a short error log and 14 nightly backups. We will extend this to one year before that date and update this notice.
  • Consent records: we keep a record of the choice, including a Reject, because we must be able to prove the notice and the consent (section 6(10)).

Who else receives your personal data

  • Google (Google Analytics 4) receives the analytics data described above, only if you accept analytics on dpdpa.support. See Google’s privacy policy.
  • Razorpay Software Private Limited collects what you enter on its payment page (email address, phone number and payment details) to take your payment and return any duplicate or wrong charge, and passes your email address, phone number and payment ID to our delivery service. See Razorpay’s privacy policy.
  • Microsoft (Microsoft 365) sends the delivery email (with the steps to get into the program), the email updates you asked for and the one-time codes on our behalf, from dpdpa@cynorsense.com, and stores, in India, the mailbox that holds the copies of the delivery email and the email updates (no copy of a one-time code is kept).
  • Hostinger hosts, in Mumbai, India, the virtual server that runs dpdpa.support, our delivery service, the consent log, our email-updates subscriber list, our consent and grievance system and the backups.
  • Wix.com Ltd and its affiliates host www.cynorsense.com, including the members area, and store member accounts (name, email address, password), invitations and join records, program access and progress, and messages sent through that site, on our behalf. When you pay, our delivery service sends Wix your email address so that Wix can create the account and the invitation. Apps installed on www.cynorsense.com may also receive data from visitors to that site; none of them runs on dpdpa.support. See Wix’s privacy policy.
  • Authorities, only where a law in force in India requires us to disclose information or a court orders it.

When we use a Data Processor, we remain responsible for the processing it does for us (section 8(1)), and when you withdraw consent we will make it stop processing too (section 6(6)).

Processing outside India

Our own server, hosted by Hostinger, is in Mumbai, India, and our Microsoft 365 mailbox (dpdpa@cynorsense.com) is stored in India. Google and Wix, and apps used on www.cynorsense.com, may store or process personal data on servers outside India. The Act allows this except where the Central Government restricts transfers to a country or territory by notification (section 16(1)), and Rule 15 lets it set requirements for making data available to a foreign State. If a transfer we rely on is restricted, we will stop it or change how we work so that it complies.

How long we keep it

The one-year minimum. From 13 May 2027, Rule 8(3) requires us to keep personal data we process, with the related traffic data and logs, for at least one year from the date of each processing, and then to erase it unless another law requires us to keep it longer. This applies even if you close your account, withdraw consent or ask us to erase your data sooner; during that year we use the data only for the purposes Rule 8(3) allows, not for the purpose you withdrew from. We may erase sooner what we do not need for those purposes, such as your address in our email-updates subscriber list (see below).

Where another law requires a record. Where a law (such as tax law) requires us to keep a record, we keep it for the period that law sets, as the DPDP Act allows (sections 8(7) and 12(3)), and then erase it.

  • dpdpa.support visits: we do not keep an access log of your visits. Error-log entries are deleted as the rotating files fill up (up to 3 files of 10 MB). Your theme choice stays in your own browser until you clear it. If we start keeping access logs, we will update this notice first.
  • Backups: the 14 newest nightly encrypted copies; each older copy is deleted.
  • Google Analytics data: 14 months, set in Google Analytics, then deleted by Google.
  • Consent log entries (analytics and email updates): while the consent is in force and for the one-year minimum after it ends or after a Reject, then we delete them. The visitor ID and your analytics choice stay in your browser until you clear this site’s data.
  • Consent records in our consent and grievance system, including your email address held as the identifier for email updates: while the consent is in force and for the one-year minimum after it ends, then we delete them, unless another law requires us to keep them longer.
  • Email updates: your email address and its records in our subscriber list, and the copies of the emails in the Sent Items of dpdpa@cynorsense.com, until the emails end (after the fifth email, or earlier when you unsubscribe, reply “stop”, an email bounces or you buy), then for the one-year minimum. If your withdrawal or erasure request is carried out by a purge (see “The privacy dashboard at /rights/”), your address is removed from the subscriber list at that point; the dated records, which then hold a keyed identifier instead of your address, the copies in Sent Items and your consent records are kept for the one-year minimum. Then we erase them, unless another law requires us to keep them longer.
  • One-time codes: a code works once, for 5 minutes, to sign in to the privacy dashboard. We do not keep it after it is used or expires.
  • Requests made on the privacy dashboard or by email (withdrawals, erasure requests, requests for a summary, corrections, nominations and grievances, and our replies): for the one-year minimum after we close the request, and after that for as long as another law requires. Then we erase them.
  • Purchases on the Razorpay page: the payment ID, the log of dated events, and the copy of the delivery email in Sent Items, for the one-year minimum. Payment records that tax law needs are kept like invoices (next item). Then we erase them.
  • Members-area account and program activity on www.cynorsense.com: until the account is deleted. To ask us to delete it, email dpdpa@cynorsense.com. We then close it, stop using it, and, once the one-year minimum has passed, delete the member from our Wix site so that Wix erases it under its own retention terms. Your rights below apply to this data too.
  • Invoices and payment records: for the period tax law sets, as the DPDP Act allows (section 8(7)), and for at least the one-year minimum. Then we erase them.
  • Join records on www.cynorsense.com, and messages: for the one-year minimum, and after that for as long as another law requires (section 8(7)). Then we erase them.

Your rights and how to use them

How to make a request. Email dpdpa@cynorsense.com. If you signed up for email updates, you can also use the privacy dashboard at dpdpa.support/rights/ (the Your data rights page explains how): enter the email address you subscribed with and the one-time code we email to it. There you can see your consents and switch them off, ask for a summary of your data, correct or update it, nominate someone, ask us to erase your data and raise a grievance. We identify you by the email address you paid with, used for your member account or subscribed with (an “identifier” under Rule 14(5)). Please write from that address, or tell us that address and the payment ID from your Razorpay receipt (or your www.cynorsense.com order number if you paid there); if you write from another address, we may ask you to confirm the request from the registered one. We do not ask for identity documents. Every reply we send about your rights will include this contact address.

  • Access (section 11): a summary of the personal data we hold about you and what we do with it, and the names of the other Data Fiduciaries and Data Processors we have shared it with, with a description of what was shared.
  • Correction, completion, updating and erasure (section 12): we will correct inaccurate or misleading data, complete incomplete data and update it. We will erase your data unless we must keep it for the purpose you gave it for or to comply with a law (section 12(3)); see “How long we keep it”.
  • Withdrawing consent (section 6(4)): as easily as you gave it. For Google Analytics on dpdpa.support, use the “Cookie and consent settings” link at the bottom of every page and choose Reject. For email updates, use the one-click unsubscribe link in any of our emails, switch it off in Manage Consent on the privacy dashboard, or email us. For cookies on www.cynorsense.com, clear that site’s cookies in your browser, or email us. Withdrawal does not make earlier processing unlawful (section 6(5)). Once you withdraw, we stop that processing within a reasonable time and make our processors stop too, unless a law requires or permits it to continue (section 6(6)).
  • Nominating someone (section 14): you can name one or more individuals to exercise your rights if you die or become unable to exercise them because of unsoundness of mind or infirmity of body. Email us the nominee’s full name, email address and relationship to you, or, if you signed up for email updates, make the nomination on the privacy dashboard; you can change or cancel a nomination the same way (Rule 14(4)).
  • Grievances (section 13): if you are unhappy with how we handled your data or a request, email us with “Grievance” in the subject line, or, if you signed up for email updates, raise it in Requests & Grievances on the privacy dashboard. We will respond within a reasonable period, and in any case within 90 days of receiving it (Rule 14(3)).
  • Complaint to the Data Protection Board of India: from 13 May 2027, once you have used our grievance process (section 13(3)), you can complain to the Data Protection Board of India about a breach of our obligations or your rights (section 27(1)(b)). The Board works as a digital office (section 28(1)); use the complaint method it publishes.

Children

The DPDPA Toolkit is a product for organisations and the people who run their compliance work. It is not directed at children, meaning anyone under 18 (section 2(f) of the Act). We do not knowingly process children’s personal data, and we do not knowingly track, behaviourally monitor or target advertising at children (section 9(3)). If you are a parent or lawful guardian and believe a child has given us personal data, email us and we will erase it.

How we protect it

  • dpdpa.support is a static site served over HTTPS, with no accounts. The privacy dashboard uses a one-time code sent to your email address instead of a password. All scripts on dpdpa.support, including the dashboard’s, come from our own server; Google’s analytics script, which loads only after you accept, comes directly from Google.
  • Our delivery service and consent log run on our own virtual server (hosted by Hostinger), reached over HTTPS through dpdpa.support. The consent log stores a one-way hash instead of the browser’s visitor ID, and a keyed one-way hash instead of your email address. Our consent and grievance system also runs on our own server; it holds your email address only as the identifier for email-updates consent and dashboard sign-in. The email-updates subscriber list is a private file on that server.
  • www.cynorsense.com runs on Wix’s platform, which provides HTTPS and the platform’s security controls.
  • Payments for purchases on dpdpa.support are taken on Razorpay’s payment page; card, UPI and bank details never reach dpdpa.support or us.

If there is a personal data breach

If a personal data breach affects your data, we will tell you without delay by email: at the address you paid with or subscribed with, and, if you have a member account on www.cynorsense.com, at the address on that account. We will describe what happened and when, the likely consequences for you, what we are doing about it, the steps you can take to protect yourself, and who to contact (Rule 7(1)). We will also inform the Data Protection Board of India (section 8(6) and Rule 7(2)).

Language

This notice is in English. If you would like it, or any consent request on our sites, in any of the languages listed in the Eighth Schedule to the Constitution of India, email us and we will provide it in that language (sections 5(3) and 6(3)).

Changes to this notice

When we change this notice, we update the date at the top. Each consent request on dpdpa.support carries its own version label (currently Notice 8 Oct 2026 for analytics and 2026-10-v5 for email updates), and your consent record stores the version you saw. If we change the wording of the analytics request, it gets a new version label and the banner asks you again. If we change the wording of the email-updates request, it gets a new version label too. If we want to use your personal data for a new purpose, we will tell you first and ask for your consent.

Contact

CynorSense Solutions Private Limited, 8-2-332/1/B, MBS Plaza, 5th Floor, Road No. 3, Banjara Hills, Hyderabad, Telangana, India – 500034. Email: dpdpa@cynorsense.com. Phone: +91 8062181669.

Related: Terms of sale · Refunds and cancellations · Cookie policy