DPDPA 2023 Consent Notice

Consent Notice

Under the Digital Personal Data Protection Act, 2023 (DPDPA), read with the Digital Personal Data Protection Rules, 2025. This notice explains what personal data we collect through Quick Scan Breach Guard, why we collect it, and the rights you hold over it.

Document Version: 1.0Draft for Internal Review

No consent on file yet

You will be asked to consent before your first scan.

1. Identity of the Data Fiduciary

This Consent Notice is issued by Cybervahak Consultants Private Limited (hereinafter referred to as the “Data Fiduciary”, “we”, “us”, or “our”), the entity that determines the purpose and means of processing your personal data through the Quick Scan Breach Guard application (the “Platform”).

Registered Name
Cybervahak Consultants Private Limited
Registered Address
Cybervahak Consultants Private Limited, Office No: 917-918, 9th floor, Ajmera Sikova, LBS Marg, Opp Damodar Park, Ghatkopar West, Mumbai, Maharashtra - 400086

2. Purpose of this Notice

This notice is provided to you in accordance with Section 5 of the Digital Personal Data Protection Act, 2023 and Rule 3 of the Digital Personal Data Protection Rules, 2025. It is intended to inform you, the Data Principal, about:

  • The categories of personal data we collect from you;
  • The specific purposes for which your personal data is processed;
  • The goods and/or services enabled by such processing;
  • The manner in which you may exercise your rights under the Act; and
  • The manner in which you may lodge a complaint with the Data Protection Board of India.

This notice is presented independently of any other information displayed on the Platform and is written in clear and plain language, as required under Rule 3 of the DPDP Rules, 2025.

3. Personal Data We Collect

The following is an itemised description of the categories of personal data we collect and process through the Platform:

CategoryData ElementsCollection Method
Email AddressThe email address you enter into the breach-check search field on the Platform.Directly provided by you via the search input field.
Password Hash PrefixWhen you run a password check, your password is hashed (SHA-1) locally in your browser. Only the first 5 characters of that hash are sent to the password-lookup service (k-anonymity). Your password itself never leaves your device and is not stored by us.Derived locally from your input in the password field; the prefix only is transmitted.
Domain Name (optional)If you use the domain scan feature, the domain name you submit is processed to enumerate publicly-indexed personnel email addresses associated with that domain.Directly provided by you via the domain input field.
Network Information (IP Address)Your Internet Protocol (IP) address at the time of using the Platform.Automatically captured from your network request headers.
Device & Browser (User-Agent)Information about the browser type, version, and operating system you use to access the Platform.Automatically captured from your HTTP request headers.
Usage & Activity DataTimestamps of searches performed, breach check results, PDF report generation events, and interaction logs.Automatically generated and recorded when you interact with the Platform.

4. Purposes of Processing & Services Enabled

Your personal data is processed only for the specific purposes described below. Each purpose is linked to the corresponding data category and the service it enables:

PurposeData UsedService Enabled
Breach Detection & NotificationEmail AddressCheck your email against known data breach databases, stealer logs, and public pastes.
Password Exposure CheckPassword Hash PrefixCheck whether your password has appeared in known breach corpora without ever transmitting the password itself (k-anonymity model).
Domain Exposure AssessmentDomain Name, Returned Personnel EmailsIdentify which personnel email addresses for the domain have been involved in known breaches or stealer logs.
Report GenerationEmail Address, Breach ResultsGenerate a downloadable PDF report summarising the breach check results for your reference.
Security & Abuse PreventionIP Address, User-AgentProtect the Platform from misuse, detect fraudulent or abusive activity, enforce rate limits.
Service Improvement & AnalyticsUsage Data, IP Address, User-AgentUnderstand usage patterns and improve Platform performance (data used in aggregate form).
Administrative & Audit PurposesAll categories aboveMaintain audit trails, comply with legal obligations, support internal administrative functions.

5. Third-Party Data Sharing

To provide the breach-checking service, we share certain data with the following third-party service providers (Data Processors):

Third PartyData SharedPurpose
Have I Been Pwned (HIBP) - operated by Troy HuntEmail Address, Domain NameYour email address (or, for domain scans, the domain name and returned personnel email addresses) is transmitted to the HIBP API to query their database of known data breaches, stealer logs, and public pastes. HIBP Privacy Policy
HIBP Pwned Passwords API (Cloudflare)First 5 characters of the SHA-1 hash of your passwordWhen you run a password check, your password is hashed (SHA-1) locally in your browser. Only the first 5 characters of the hash are sent to the Pwned Passwords API, which returns a list of matching hash suffixes. The match is evaluated on your device - your full password and full hash are never transmitted (k-anonymity). API Reference

We do not sell, rent, or trade your personal data to any third party for marketing or advertising purposes. Data is shared with the above third party solely for the purpose of providing the breach-checking service to you.

6. Data Storage & Retention

Your personal data is stored in a secured database hosted on our own vpc.

CategoryRetention PeriodBasis
Search Records (Email, Breach Results, IP Address, User-Agent)90 daysRetained for the duration necessary to fulfil the specified purpose; erased thereafter or upon withdrawal of consent.
Activity Logs90 daysRetained for audit and compliance purposes as required under applicable law.

In accordance with Section 8(7) of the DPDPA, we shall erase your personal data upon your withdrawal of consent, or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, unless retention is required under applicable law.

7. Cookies & Browser Storage

The Platform uses the following cookies:

CookiePurposeDuration
admin_sessionMaintains authenticated session for administrative users (HTTP-Only, Secure).24 hours

These cookies are strictly necessary for the functioning of the Platform and do not track you for advertising or marketing purposes. No third-party tracking cookies are used.

8. Your Rights as a Data Principal

Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:

Right to Access Information (Section 11)

Obtain a summary of your personal data being processed, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your personal data has been shared.

Right to Correction and Erasure (Section 12)

Request correction of inaccurate or incomplete personal data, completion of incomplete data, updating of outdated data, and erasure of personal data that is no longer necessary.

Right to Grievance Redressal (Section 13)

Have readily available means of grievance redressal in respect of any act or omission regarding your personal data. You must first exhaust the grievance redressal mechanism provided by us before approaching the Data Protection Board of India.

Right to Nominate (Section 14)

Nominate any individual who may exercise your rights in the event of your death or incapacity.

Right to Withdraw Consent (Section 6(4))

Withdraw your consent at any time. Withdrawal of consent shall be as easy as the giving of consent. Upon withdrawal, we shall cease processing your personal data and erase it, unless retention is required under applicable law. Withdrawal will not affect the lawfulness of processing carried out prior to the withdrawal.

To exercise any of the above rights, please contact us at contact@cybervahak.com. We shall respond to your request as soon as reasonably possible.

9. Grievance Redressal Mechanism

In accordance with Section 13 of the DPDPA and Rule 14 of the DPDP Rules, 2025, we have established the following grievance redressal mechanism:

  1. Contact the Grievance Officer: Please write to us at contact@cybervahak.com with details of your grievance.
  2. Acknowledgement & Resolution: We shall acknowledge your grievance and endeavour to resolve it as soon as reasonably possible.
  3. Escalation to the Data Protection Board of India: If not satisfied, you may file a complaint with the Data Protection Board of India.

10. Security Measures

We implement reasonable security safeguards, including technical and organisational measures, to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • Encryption of data in transit using HTTPS/TLS protocols;
  • Secure, hashed storage of authentication credentials (bcrypt hashing);
  • HTTP-Only and Secure flags on authentication cookies;
  • Role-based access controls for administrative functions;
  • Regular review and updating of security practices.

11. Consent Declaration

By clicking “Agree & Scan” / checking the consent checkbox and proceeding to use the Platform, you confirm that:

  1. You have read and understood this Consent Notice in its entirety;
  2. You freely, specifically, and unambiguously consent to the collection, storage, and processing of your personal data as described in this notice;
  3. You consent to the sharing of your email address, domain name (where applicable), and the first 5 characters of your password’s SHA-1 hash (for password checks) with Have I Been Pwned (HIBP) for the purpose of checking against known data breach and password exposure databases;
  4. You understand that you may withdraw your consent at any time, and that such withdrawal will not affect the lawfulness of processing carried out prior to the withdrawal;
  5. You understand your rights as a Data Principal under the Digital Personal Data Protection Act, 2023;
  6. You are above the age of 18 years. If below 18, verifiable consent has been obtained from your parent or lawful guardian.

12. Contact Us

For any questions or concerns regarding this Consent Notice, your personal data, or your rights under the DPDPA, please contact:

Entity
Cybervahak Consultants Private Limited
Address
Cybervahak Consultants Private Limited, Office No: 917-918, 9th floor, Ajmera Sikova, LBS Marg, Opp Damodar Park, Ghatkopar West, Mumbai, Maharashtra - 400086

13. Changes to this Consent Notice

We may update this Consent Notice from time to time to reflect changes in our data processing practices or applicable legal requirements. Any material changes will be communicated to you through the Platform, and where required, fresh consent will be obtained. We encourage you to review this notice periodically.

14. Governing Law

This Consent Notice is governed by the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and any other applicable laws of India. Any disputes arising out of or in connection with this notice shall be subject to the exclusive jurisdiction of the Data Protection Board of India and the courts of India.

- End of Consent Notice -