Privacy Policy
Last updated: 25 July 2026
1. Who we are
Encrypticle is a cybersecurity education platform operated from Gurugram, India. This Privacy Policy explains what personal information we collect, why we collect it, and how we protect it. This policy is compliant with the Digital Personal Data Protection Act, 2023 (India) and, where applicable, the General Data Protection Regulation (EU).
2. Information we collect
When you use Encrypticle, we collect:
- Account data: email address, name, phone number (optional until cohort enrollment)
- Purchase data: order details, amount paid, GST invoice details (via Razorpay — we do not store card numbers)
- Learning data: which lessons you have viewed, progress markers, questions you post, notes you save
- Technical data: IP address (hashed at rest), browser type, device type, referring URL — used for security, rate limiting, and fraud prevention
- Communication data: support tickets, emails you send us
3. How we use your information
- Authenticate you and manage your account
- Deliver purchased content and course access
- Send transactional emails (OTP codes, receipts, cohort updates)
- Detect fraud, abuse, and unauthorized content redistribution
- Comply with legal obligations (tax records, law enforcement requests)
- Send occasional product updates and promotional emails (you can unsubscribe at any time)
4. Who we share your data with
We share data only with service providers strictly necessary to operate the platform:
- Razorpay — payment processing
- ZeptoMail (Zoho) — transactional email delivery
- MSG91 — SMS OTP delivery (India numbers)
- Bunny.net — video hosting and CDN delivery
- Cloudflare — DNS, DDoS protection, and R2 storage
- Hetzner — server hosting (Singapore region)
We do not sell your personal data to advertisers or brokers. We do not share your data with third parties for their own marketing purposes.
5. Data retention
- Account data: for the lifetime of your account, plus 30 days after deletion
- Purchase records: 7 years, as required by Indian tax law
- Session and OTP data: sessions capped at 48 hours; OTP codes deleted after use
- Server logs: 30 days rolling
- Backups: 30 days on R2
6. Your rights
Subject to applicable law, you have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your account (subject to retention obligations above)
- Export your data in a machine-readable format
- Object to certain types of processing (e.g., marketing emails)
- File a complaint with the Data Protection Board of India
To exercise any of these rights, email privacy@encrypticle.com. We respond within 30 days.
7. Security
We use industry-standard practices to protect your data: TLS for all traffic, hashed session tokens, salted OTP codes, IP hashing at rest, non-root container execution, firewalled internal services, and encrypted backups. That said, no system is 100% secure; you use the Services at your own risk.
8. Cookies
We use a single session cookie (enc_session) that is strictly necessary for authentication. It is HttpOnly, Secure (in production), and SameSite=Lax. We do not use tracking cookies, third-party ad pixels, or cross-site analytics on the authenticated portion of the platform.
9. Children
Encrypticle is intended for users aged 16 and above. We do not knowingly collect data from anyone under 16. If you believe we hold data on a minor, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or an in-platform notice at least 15 days before taking effect.
11. Contact
Questions about this policy? Email privacy@encrypticle.com.