LEGAL & TRUST

Privacy Policy — Kryptasys

Last updated: August 12, 2026. Learn how we handle your information and protect your data under India's DPDPA 2023. Version 1.0 (May 2025) is available upon request at contact@kryptasys.in.

1. Introduction

Welcome to Kryptasys ("Kryptasys", "we", "us", or "our"). We are committed to protecting the privacy and security of your digital information. This Privacy Policy details our practices concerning data collection, processing, and storage, and describes how we support compliance with the Digital Personal Data Protection Act, 2023 (DPDPA) of India.

This policy applies to our marketing website (kryptasys.in), our product DPDP Shield (shield.kryptasys.in), and all related services, features, and tools operated by Kryptasys.

2. Zero Code Exposure Guarantee

Zero Code Exposure Guarantee

Kryptasys does not require you to share your codebase, database schemas, source files, or proprietary application configurations. Our compliance assessment is entirely questionnaire-based. Your actual code and internal data systems never leave your premises. What we store is limited to your assessment responses, compliance scores, and remediation task assignments, nothing more.

This design ensures your proprietary codebase and sensitive systems remain inside your secure perimeter. DPDP Shield works by asking structured questions about your data practices, not by scanning or receiving your actual systems. Kryptasys never gains visibility into your source code, database schemas, secrets, or internal intellectual property.

3. Information We Collect

We believe in data minimization. We only collect the minimal information necessary to deliver our services, and do not deploy analytics tracking or third-party advertising cookies.

  • Waitlist & Inquiries: When you sign up for our waitlists (e.g. for LEAP v2) or send us an email, we collect your name, work email address, and company details to communicate with you.
  • Contact Form Submissions: When you submit our contact form, we collect your name, organization, email, phone number, inquiry type, and message. This data is stored securely within Indian infrastructure (Supabase, Mumbai region) and used solely to respond to your inquiry.
  • Privacy Rights Requests: When you submit a statutory rights request via our Privacy Rights portal, we collect your name, email, request type, and request details. This data is stored securely and processed by our Grievance Redressal Officer within the statutory timeframes under DPDPA 2023.
  • Diagnostic Logs (Opt-in): In the event of system errors during local scans, you may optionally choose to send us anonymized debug summaries. These never contain raw system code or databases.
  • Subscription and Billing Details: If you purchase paid services in the future, billing and transaction processing will be handled securely via PCI-DSS compliant third-party payment aggregators. Kryptasys does not store your credit card or net banking credentials.

4. DPDPA Alignment & Roles

Under India's Digital Personal Data Protection Act, 2023 (DPDPA), legal obligations are mapped to specific roles:

  1. Kryptasys as a Data Processor: For the SaaS portals and waitlists we operate directly, we act as a Data Fiduciary. For the hosted services we operate where your compliance data is processed, we act as a software provider helping manage your compliance; you remain the sole Data Fiduciary for the data scanned.
  2. Supporting Fiduciary Obligations: DPDP Shield provides features specifically designed to help Data Fiduciaries meet DPDPA requirements, including automating processing consent trackers, establishing data processing registries, and enabling audit logs.
  3. Indian Data Residency: Any data processed or stored by Kryptasys portals is hosted exclusively on servers physically located within India (Mumbai region), in compliance with data localization principles under DPDPA 2023.

5. Data Security & Storage

We implement robust technical and organizational measures to safeguard your information against unauthorized access, loss, or misuse:

  • Encryption: Data in transit is encrypted using TLS 1.3. Data at rest is protected with AES-256 encryption.
  • Access Controls: Strict role-based access control (RBAC) and Row-Level Security (RLS) policies govern data access within our production databases.
  • Data Retention: Account details and assessment scores are retained as long as your account remains active. Waitlist details are retained until you request removal.

6. Your Rights & Redressal

Under the DPDPA 2023, Data Principals possess explicit rights regarding their personal data:

  • Right to Access & Summary: Request a summary of personal data held about you by Kryptasys.
  • Right to Correction & Erasure: Request correction of inaccurate information or erasure of your personal data when no longer necessary.
  • Grievance Redressal: Submit grievances directly to our Grievance Redressal Officer.

7. Contact Information

If you have questions or grievances regarding this Privacy Policy or our data practices, please contact us:

Grievance Redressal Officer: Vivek Kumar
Email: contact@kryptasys.in
Address: Kryptasys, Delhi NCR, India 🇮🇳