1. Overview
This Privacy Policy explains how N-CYPHER collects, uses, shares, stores, and protects personal data when you visit our website, use our services, request proposals, communicate with us, or interact with our tools, automations, integrations, and future SaaS products.
Depending on the context, N-CYPHER may act as a controller for its own business operations or as a processor / service provider handling data on behalf of a client under a commercial agreement and, where applicable, a DPA.
2. Data We Collect
We may collect:
- Identity and contact data: name, company, role, email, phone number, and business address
- Account and billing data: login details, invoices, payment records, tax information, and transaction history
- Communications data: emails, messages, notes, support requests, and feedback
- Technical and usage data: IP address, browser type, device identifiers, pages viewed, logs, and diagnostics
- Cookies and analytics data: session identifiers, preferences, traffic, and usage patterns
- Client business data: prompts, files, lead lists, CRM exports, SOPs, campaign assets, and other materials you submit
- Integration and API data: data passed through third-party services or connected systems
- AI interaction data: prompts, inputs, context, generated outputs, and workflow results
3. How We Collect Data
We collect data directly from you, automatically through cookies and logs, from third parties such as payment processors and analytics vendors, and from authorized integrations or APIs you connect to our systems.
4. How We Use Data
We may use data to provide and improve services, respond to enquiries, build websites and AI workflows, authenticate users, process payments, monitor security, analyze usage, send service communications, comply with law, enforce agreements, and manage disputes.
5. Legal Bases for Processing
Where required by applicable law, we rely on one or more lawful bases, including consent, contract performance, legitimate interests, legal compliance, and other lawful grounds recognized by applicable law. This structure is compatible with GDPR-style transparency and India’s consent-centered DPDP framework.
6. Client Business Data and AI Outputs
When you provide business data for AI processing or custom development, we use it only to perform the services requested, subject to the applicable agreement. Unless we clearly state otherwise in writing or you expressly opt in, we do not use identifiable client confidential data or personal data submitted for custom client projects to train general-purpose models for unrelated customers.
We may use de-identified, aggregated, or operational metadata to maintain, secure, support, and improve our services. AI-generated outputs may be stored for project continuity, debugging, security review, quality assurance, version control, or support. You remain responsible for reviewing outputs before business, legal, financial, hiring, or public use.
7. How We Share Data
We may share data with cloud hosts, payment processors, analytics and communications tools, third-party AI model providers, professional advisors, authorities where required by law, and buyers or successors in connection with a merger, acquisition, financing, or restructuring.
8. Cookies and Analytics
We use cookies and similar technologies for essential functionality, remembering preferences, measuring traffic and performance, understanding how visitors navigate our website, improving experience, and where lawful, supporting marketing or attribution. Where required by law, we request consent before placing non-essential cookies on your device.
9. International Data Transfers
N-CYPHER may process and transfer data in India and other countries where we, our vendors, or our infrastructure providers operate. Where appropriate, we use contractual data-protection clauses, vendor terms, organizational controls, and other lawful transfer mechanisms. If GDPR applies, we may rely on standard contractual clauses or other recognized safeguards as needed.
10. Data Retention
We keep personal data only for as long as reasonably necessary for service delivery, support, subscriptions, enforcement, dispute resolution, security logs, and compliance with tax, accounting, legal, and regulatory obligations. Once retention is no longer required, we may delete, anonymize, or de-identify data, subject to backups, fraud-prevention, and disaster-recovery constraints.
11. Security
We use reasonable technical, organizational, and administrative safeguards designed to protect data against unauthorized access, loss, misuse, alteration, or disclosure. These may include access controls, role-based permissions, contractual vendor controls, encryption where appropriate, logging, backups, and internal confidentiality controls. No system is completely infallible, and we cannot guarantee absolute security.
If a personal-data breach occurs, we will respond in accordance with applicable law and internal incident procedures. Under GDPR, a controller may need to notify the relevant authority within 72 hours where required. Under India’s DPDP framework, a data fiduciary must maintain reasonable safeguards and notify the Board and affected individuals in the prescribed manner.
12. Your Rights
Depending on your location and the law that applies, you may have rights to access, know, correct, complete, update, erase, withdraw consent, port data, object to certain processing, restrict processing in some cases, lodge complaints, and in India, request grievance redressal and nomination rights in the event of death or incapacity.
We may need to verify your identity before acting on a request, and some rights may be limited by law, technical feasibility, contractual obligation, security needs, or legal retention requirements.
13. Marketing Communications
Where lawful, we may send service announcements, newsletters, and marketing communications. You may unsubscribe from non-essential marketing messages at any time. Transactional and service messages, such as invoices, security notices, and support communications, may still be sent where necessary.
14. Children
Our services are intended for businesses, founders, professionals, and organizations and are not directed to children. Under India’s DPDP Act, a child is under 18 years of age, and additional safeguards may apply where children's data is processed. If you believe a child has provided us data in violation of applicable law, contact us and we will review the issue.
15. Third-Party Websites and Services
Our website or services may include links to third-party websites, platforms, and integrations. We are not responsible for the privacy, content, or practices of those third parties, and their own terms and notices will apply.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, technical, operational, or business changes. We will post the updated version on our website and update the Effective Date. Where required, we will provide additional notice or request renewed consent.
17. Contact and Grievance Redressal
For privacy questions, rights requests, or complaints, contact:
N-CYPHER
Noida, Sector 125 (near Amity University)
ncypher2005@gmail.com
https://www.ncypher.in
Grievance Contact / Privacy Contact:
Ayush Goyal
ncypher2005@gmail.com
LinkedIn