Skip to content

Scope, fee and working days are published on every engagement

CorePhysix Labs Technology lab

Revised 11 September 2026

Policy · 02

Privacy Policy

What personal data CorePhysix Labs collects when you use corephysixlabs.com or buy an engagement, why we need it, who else processes it, how long we keep it and the rights you hold over it.

In brief

We collect
Contact, billing and order details, your technical brief and basic site analytics.
Payments
Card, UPI and banking details stay with the payment gateway and never reach us.
Sharing
No sale of data and no advertising profiles. Processors cover payments, email, hosting and analytics only.
Your rights
Access, correction, erasure, withdrawal of consent, nomination and grievance redressal.
Response
Data requests answered within 30 days, free of charge.

This summary is for orientation only. The numbered sections below set out the detail required by the Digital Personal Data Protection Act, 2023, and they prevail.

01

Who this policy covers

This policy applies to everyone who visits corephysixlabs.com, opens an account, contacts us, submits a technical brief or buys an engagement. It is prepared under the Digital Personal Data Protection Act, 2023 (the DPDP Act) and the reasonable security practices rules made under the Information Technology Act, 2000.

Two terms from the DPDP Act are used throughout. You are the Data Principal: the person the data is about. We are the Data Fiduciary: the organisation that decides why and how your data is processed, and that is responsible for protecting it.

This policy does not cover websites we link to, third-party platforms you sign in to separately, or systems that belong to you and that we work in during an engagement. Section 6 explains that last case.

02

Who is responsible for your data

The Data Fiduciary is COREPHYSIX LABS PRIVATE LIMITED, 4th Floor, 1-98/4/1,Unit 407, Jain Sadguru Images Capital Park, Image Garden Road, Madhapur, Hyderabad, Hyderabad, Telangana, 500081., operating corephysixlabs.com under the name CorePhysix Labs.

Requests and complaints about personal data are handled by the Grievance Officer, whose contact details are in section 15.

03

What we collect

We collect five categories of data, limited to what is needed to sell and deliver IT services.

  • Account data: name, email address, mobile number, business name where you provide one, and a one-way hash of your password. Passwords are never stored in readable form, so we cannot see yours.
  • Billing data: billing name, address, city, state, PIN code and, where you provide it, your GSTIN. We need this to issue a valid tax invoice.
  • Order data: the engagements you buy, amounts, order numbers, payment status, payment gateway references, invoices and refund records.
  • Technical brief: what you enter in the brief so that the work can be done, such as repository and environment names, architecture notes, the problem to be solved, access instructions and any attachments. This is mainly business information, but it often includes names and work email addresses.
  • Site and device data: IP address, browser and device type, pages viewed, referring source and approximate location, collected through server logs and, where enabled, analytics.

We do not collect or store card numbers, CVV codes, UPI PINs or net-banking credentials at any point. We do not ask for identifiers such as Aadhaar or PAN unless a specific legal requirement makes it necessary, and if so we will tell you why at the time.

04

How we use it

Each purpose below is specific. We do not reuse data collected for one purpose for an unrelated one.

PurposeData used
Create, confirm and deliver your orderAccount, billing, order, brief
Issue a GST invoice and keep tax recordsBilling, order
Contact you about an order: confirmation, questions, handover and supportAccount, order
Plan and carry out the workBrief, order
Handle a refund, dispute or grievanceOrder, billing, correspondence
Keep the site running, prevent fraud and fix faultsSite and device data
Understand, in aggregate, which pages are usefulSite and device data
Send occasional updates about new engagementsName and email, only if you opted in

We do not build advertising profiles, we do not use behavioural retargeting, and we do not sell, rent or trade personal data.

05

Consent and legitimate uses

We process personal data on two grounds under the DPDP Act.

  • Consent: free, specific, informed and unambiguous, given when you submit a form, open an account, complete a brief or opt in to updates. Each request explains what the data is for before you give it.
  • Legitimate uses: processing needed to perform the contract you enter into when you pay, and processing required by law, such as keeping tax records.

You may withdraw consent at any time, as easily as you gave it, by writing to our Grievance Officer, YEGUVAPALLI  BALU PRASAD and KUCHUPAPA SWARUP KUMAR, at grievance@corephysixlabs.com. Withdrawal stops processing from that point. It does not affect processing already carried out lawfully, or records the law requires us to keep. If withdrawal would prevent us from completing an engagement you have paid for, we will tell you before acting on it.

Consent to updates is separate from everything else. Declining it never affects an order, and every update email includes an unsubscribe link, which we act on promptly.

06

Data in your own systems

We act in one of two roles, depending on where the data sits.

  • Your data, held by us. For account, billing, order and brief data held in our systems, we are the Data Fiduciary, and the rest of this policy applies.
  • Data about your users, held in your systems. When an engagement requires us to work in your repositories, databases or cloud accounts, you remain the Data Fiduciary. We process that data only on your documented instructions and only for the engagement.

We ask for anonymised, masked or synthetic data by default. Where access to live personal data cannot be avoided, it should be limited to what the work needs, granted for a fixed period and removed at handover.

07

Who processes it with us

We share personal data with service providers (processors) that help us run the business, only for the purpose stated, and only under terms that require them to protect it. They are listed by category, because a provider may change while the category and safeguards stay the same.

CategoryWhat it receivesWhy
Payment gatewayName, contact details, amount, order referenceTo process a UPI payment and confirm or refund it
Email deliveryName, email address, message contentTo send order confirmations, handover material and replies
Hosting and infrastructureAll data the site storesTo run the website, database and backups
Website analyticsSite and device data, pseudonymisedTo see which pages are used and which are not working

Outside those categories, personal data is shared only with the people working on your engagement, limited to the brief and the access the work needs; with our accountants and auditors for statutory filings; and with a government authority, court or law enforcement agency where valid legal process requires it. In that case we ask for the request in writing, check that it is lawful, disclose only what is required and tell you unless we are legally prevented from doing so.

No processor may use your data for its own purposes.

Transfers outside India

Some service providers, particularly for email delivery and analytics, may process data outside India. Where that happens, we transfer data only to countries not restricted by the Central Government under section 16 of the DPDP Act, limit the transfer to what the purpose requires, and require the provider to protect it to the standard set out in this policy. If a restriction changes, we will move the processing.

08

How long we keep it

We keep personal data only for as long as the purpose requires or the law demands, and then delete it or irreversibly anonymise it.

DataRetention periodReason
Invoices, order and payment records8 financial yearsIncome tax and GST record-keeping
Account profileWhile the account is open, then 90 daysSo that a deletion made in error can be reversed
Technical brief and handover material12 months after handoverSo that handover material can be sent again on request
Support and grievance correspondence3 years from closureComplaint records under the e-commerce rules
Consent to updates and unsubscribe recordsUntil you unsubscribe, plus 12 monthsEvidence that the unsubscribe was acted on
Server and access logs180 daysSecurity investigation and fault diagnosis
Analytics, in aggregate26 monthsYear-on-year comparison, no longer identifying

If you ask for erasure, we delete everything that is not held for one of the legal reasons above, and tell you what had to be kept and under which obligation.

09

How we protect it

We apply reasonable security safeguards to prevent personal data breaches, including the following.

  • The site is served over HTTPS, so data is encrypted in transit.
  • Passwords are stored as one-way hashes and cannot be recovered, including by us.
  • Payment credentials are handled by the payment gateway and never reach our servers.
  • Access to customer data is limited to people who need it for their work.
  • We ask that credentials for your systems are shared through a secrets manager or your own identity provider, never by email or chat.

No system is completely secure. If you find a weakness in this site, please tell us through the contact details in section 15 and we will investigate and act on it.

10

Cookies and browser storage

We use a small number of cookies and similar browser storage, in two groups.

  • Strictly necessary: session and security cookies that keep you signed in, keep checkout working between pages and protect forms against cross-site request forgery. The site does not work without them, so they do not require consent.
  • Analytics: used only where analytics is enabled, to count page views and find pages that are not working. They are pseudonymised and, where consent is required, set only after you give it.

The engagements in your scope basket are stored in your own browser rather than on our servers, so clearing your site data removes them. You can block or delete cookies in your browser settings at any time.

11

Your rights as a Data Principal

Under the DPDP Act, you have the right to:

  • Access: a summary of the personal data we hold about you, how we use it, and the categories of processor it has been shared with.
  • Correction: have inaccurate data corrected, incomplete data completed and outdated data updated.
  • Erasure: have data deleted once it is no longer needed for its purpose, subject to the legal retention periods in section 8.
  • Withdraw consent: for any processing based on consent, as easily as you gave it.
  • Nominate: another person to exercise these rights on your behalf in the event of your death or incapacity.
  • Grievance redressal: a readily available way to complain to us, with published timelines, before approaching the Data Protection Board of India.

The DPDP Act also sets duties for Data Principals: provide authentic information, do not impersonate anyone, and do not file false or frivolous complaints.

How to exercise a right. Write to our Grievance Officer, YEGUVAPALLI  BALU PRASAD and KUCHUPAPA SWARUP KUMAR, at grievance@corephysixlabs.com, from the email address on your account if possible, and say which right you wish to exercise. We may ask a few questions to confirm your identity before acting. We respond within 30 days. If a request needs longer, we will tell you within those 30 days, with the reason and an expected date.

There is no charge for exercising any of these rights.

12

Children

Our engagements are sold to businesses, and this site is not directed at children. We do not knowingly collect personal data from anyone under 18, and we do not track, profile or target advertising at children.

If you believe a child has given us personal data, tell us and we will delete it promptly. Where an account must be operated on behalf of a child, or of a person with a disability who has a lawful guardian, verifiable consent from the parent or guardian is required first, as the DPDP Act requires.

13

Personal data breaches

If a personal data breach occurs, we will investigate and contain it immediately, and notify the Data Protection Board of India and each affected Data Principal in the form and within the time required by the DPDP Act.

Our notice to you will explain, in plain language, what happened, which data was involved, the likely consequences, what we have done in response and what steps you may wish to take.

14

Changes to this policy

We update this policy when our processing or the law changes. The revision date at the top of this page shows the current version, and material changes are highlighted here. Where a change requires fresh consent, we will ask for it. Earlier versions are available on request.

15

Contact and complaints

For privacy questions, data requests or complaints:

  • Grievance Officer, YEGUVAPALLI  BALU PRASAD and KUCHUPAPA SWARUP KUMAR: grievance@corephysixlabs.com, 7702752958
  • General support: support@corephysixlabs.com
  • By post: 4th Floor, 1-98/4/1,Unit 407, Jain Sadguru Images Capital Park, Image Garden Road, Madhapur, Hyderabad, Hyderabad, Telangana, 500081.

Complaints are acknowledged within 48 hours and resolved within 15 days. The full escalation process, including external bodies you can approach, is on the grievance redressal page.

If you are not satisfied with our response, you may complain to the Data Protection Board of India after first raising the matter with our Grievance Officer. This policy is governed by the laws of India.

Next step

Have a system that needs building, fixing or securing?