Policy · 02
Privacy Policy
What personal data CorePhysix Labs collects when you use corephysixlabs.com or buy an engagement, why we need it, who else processes it, how long we keep it and the rights you hold over it.
In brief
- We collect
- Contact, billing and order details, your technical brief and basic site analytics.
- Payments
- Card, UPI and banking details stay with the payment gateway and never reach us.
- Sharing
- No sale of data and no advertising profiles. Processors cover payments, email, hosting and analytics only.
- Your rights
- Access, correction, erasure, withdrawal of consent, nomination and grievance redressal.
- Response
- Data requests answered within 30 days, free of charge.
This summary is for orientation only. The numbered sections below set out the detail required by the Digital Personal Data Protection Act, 2023, and they prevail.
Who this policy covers
This policy applies to everyone who visits corephysixlabs.com, opens an account, contacts us, submits a technical brief or buys an engagement. It is prepared under the Digital Personal Data Protection Act, 2023 (the DPDP Act) and the reasonable security practices rules made under the Information Technology Act, 2000.
Two terms from the DPDP Act are used throughout. You are the Data Principal: the person the data is about. We are the Data Fiduciary: the organisation that decides why and how your data is processed, and that is responsible for protecting it.
This policy does not cover websites we link to, third-party platforms you sign in to separately, or systems that belong to you and that we work in during an engagement. Section 6 explains that last case.
Who is responsible for your data
The Data Fiduciary is COREPHYSIX LABS PRIVATE LIMITED, 4th Floor, 1-98/4/1,Unit 407, Jain Sadguru Images Capital Park, Image Garden Road, Madhapur, Hyderabad, Hyderabad, Telangana, 500081., operating corephysixlabs.com under the name CorePhysix Labs.
Requests and complaints about personal data are handled by the Grievance Officer, whose contact details are in section 15.
What we collect
We collect five categories of data, limited to what is needed to sell and deliver IT services.
- Account data: name, email address, mobile number, business name where you provide one, and a one-way hash of your password. Passwords are never stored in readable form, so we cannot see yours.
- Billing data: billing name, address, city, state, PIN code and, where you provide it, your GSTIN. We need this to issue a valid tax invoice.
- Order data: the engagements you buy, amounts, order numbers, payment status, payment gateway references, invoices and refund records.
- Technical brief: what you enter in the brief so that the work can be done, such as repository and environment names, architecture notes, the problem to be solved, access instructions and any attachments. This is mainly business information, but it often includes names and work email addresses.
- Site and device data: IP address, browser and device type, pages viewed, referring source and approximate location, collected through server logs and, where enabled, analytics.
We do not collect or store card numbers, CVV codes, UPI PINs or net-banking credentials at any point. We do not ask for identifiers such as Aadhaar or PAN unless a specific legal requirement makes it necessary, and if so we will tell you why at the time.
How we use it
Each purpose below is specific. We do not reuse data collected for one purpose for an unrelated one.
| Purpose | Data used |
|---|---|
| Create, confirm and deliver your order | Account, billing, order, brief |
| Issue a GST invoice and keep tax records | Billing, order |
| Contact you about an order: confirmation, questions, handover and support | Account, order |
| Plan and carry out the work | Brief, order |
| Handle a refund, dispute or grievance | Order, billing, correspondence |
| Keep the site running, prevent fraud and fix faults | Site and device data |
| Understand, in aggregate, which pages are useful | Site and device data |
| Send occasional updates about new engagements | Name and email, only if you opted in |
We do not build advertising profiles, we do not use behavioural retargeting, and we do not sell, rent or trade personal data.
Consent and legitimate uses
We process personal data on two grounds under the DPDP Act.
- Consent: free, specific, informed and unambiguous, given when you submit a form, open an account, complete a brief or opt in to updates. Each request explains what the data is for before you give it.
- Legitimate uses: processing needed to perform the contract you enter into when you pay, and processing required by law, such as keeping tax records.
You may withdraw consent at any time, as easily as you gave it, by writing to our Grievance Officer, YEGUVAPALLI BALU PRASAD and KUCHUPAPA SWARUP KUMAR, at grievance@corephysixlabs.com. Withdrawal stops processing from that point. It does not affect processing already carried out lawfully, or records the law requires us to keep. If withdrawal would prevent us from completing an engagement you have paid for, we will tell you before acting on it.
Consent to updates is separate from everything else. Declining it never affects an order, and every update email includes an unsubscribe link, which we act on promptly.
Data in your own systems
We act in one of two roles, depending on where the data sits.
- Your data, held by us. For account, billing, order and brief data held in our systems, we are the Data Fiduciary, and the rest of this policy applies.
- Data about your users, held in your systems. When an engagement requires us to work in your repositories, databases or cloud accounts, you remain the Data Fiduciary. We process that data only on your documented instructions and only for the engagement.
We ask for anonymised, masked or synthetic data by default. Where access to live personal data cannot be avoided, it should be limited to what the work needs, granted for a fixed period and removed at handover.
How long we keep it
We keep personal data only for as long as the purpose requires or the law demands, and then delete it or irreversibly anonymise it.
| Data | Retention period | Reason |
|---|---|---|
| Invoices, order and payment records | 8 financial years | Income tax and GST record-keeping |
| Account profile | While the account is open, then 90 days | So that a deletion made in error can be reversed |
| Technical brief and handover material | 12 months after handover | So that handover material can be sent again on request |
| Support and grievance correspondence | 3 years from closure | Complaint records under the e-commerce rules |
| Consent to updates and unsubscribe records | Until you unsubscribe, plus 12 months | Evidence that the unsubscribe was acted on |
| Server and access logs | 180 days | Security investigation and fault diagnosis |
| Analytics, in aggregate | 26 months | Year-on-year comparison, no longer identifying |
If you ask for erasure, we delete everything that is not held for one of the legal reasons above, and tell you what had to be kept and under which obligation.
How we protect it
We apply reasonable security safeguards to prevent personal data breaches, including the following.
- The site is served over HTTPS, so data is encrypted in transit.
- Passwords are stored as one-way hashes and cannot be recovered, including by us.
- Payment credentials are handled by the payment gateway and never reach our servers.
- Access to customer data is limited to people who need it for their work.
- We ask that credentials for your systems are shared through a secrets manager or your own identity provider, never by email or chat.
No system is completely secure. If you find a weakness in this site, please tell us through the contact details in section 15 and we will investigate and act on it.
Your rights as a Data Principal
Under the DPDP Act, you have the right to:
- Access: a summary of the personal data we hold about you, how we use it, and the categories of processor it has been shared with.
- Correction: have inaccurate data corrected, incomplete data completed and outdated data updated.
- Erasure: have data deleted once it is no longer needed for its purpose, subject to the legal retention periods in section 8.
- Withdraw consent: for any processing based on consent, as easily as you gave it.
- Nominate: another person to exercise these rights on your behalf in the event of your death or incapacity.
- Grievance redressal: a readily available way to complain to us, with published timelines, before approaching the Data Protection Board of India.
The DPDP Act also sets duties for Data Principals: provide authentic information, do not impersonate anyone, and do not file false or frivolous complaints.
How to exercise a right. Write to our Grievance Officer, YEGUVAPALLI BALU PRASAD and KUCHUPAPA SWARUP KUMAR, at grievance@corephysixlabs.com, from the email address on your account if possible, and say which right you wish to exercise. We may ask a few questions to confirm your identity before acting. We respond within 30 days. If a request needs longer, we will tell you within those 30 days, with the reason and an expected date.
There is no charge for exercising any of these rights.
Children
Our engagements are sold to businesses, and this site is not directed at children. We do not knowingly collect personal data from anyone under 18, and we do not track, profile or target advertising at children.
If you believe a child has given us personal data, tell us and we will delete it promptly. Where an account must be operated on behalf of a child, or of a person with a disability who has a lawful guardian, verifiable consent from the parent or guardian is required first, as the DPDP Act requires.
Personal data breaches
If a personal data breach occurs, we will investigate and contain it immediately, and notify the Data Protection Board of India and each affected Data Principal in the form and within the time required by the DPDP Act.
Our notice to you will explain, in plain language, what happened, which data was involved, the likely consequences, what we have done in response and what steps you may wish to take.
Changes to this policy
We update this policy when our processing or the law changes. The revision date at the top of this page shows the current version, and material changes are highlighted here. Where a change requires fresh consent, we will ask for it. Earlier versions are available on request.
Contact and complaints
For privacy questions, data requests or complaints:
- Grievance Officer, YEGUVAPALLI BALU PRASAD and KUCHUPAPA SWARUP KUMAR: grievance@corephysixlabs.com, 7702752958
- General support: support@corephysixlabs.com
- By post: 4th Floor, 1-98/4/1,Unit 407, Jain Sadguru Images Capital Park, Image Garden Road, Madhapur, Hyderabad, Hyderabad, Telangana, 500081.
Complaints are acknowledged within 48 hours and resolved within 15 days. The full escalation process, including external bodies you can approach, is on the grievance redressal page.
If you are not satisfied with our response, you may complain to the Data Protection Board of India after first raising the matter with our Grievance Officer. This policy is governed by the laws of India.