1. Identity of the Data Fiduciary
This Consent Notice is issued by Cybervahak Consultants Private Limited (hereinafter referred to as the “Data Fiduciary”, “we”, “us”, or “our”), the entity that determines the purpose and means of processing your personal data through the Quick Scan Breach Guard application (the “Platform”).
2. Purpose of this Notice
This notice is provided to you in accordance with Section 5 of the Digital Personal Data Protection Act, 2023 and Rule 3 of the Digital Personal Data Protection Rules, 2025. It is intended to inform you, the Data Principal, about:
- The categories of personal data we collect from you;
- The specific purposes for which your personal data is processed;
- The goods and/or services enabled by such processing;
- The manner in which you may exercise your rights under the Act; and
- The manner in which you may lodge a complaint with the Data Protection Board of India.
This notice is presented independently of any other information displayed on the Platform and is written in clear and plain language, as required under Rule 3 of the DPDP Rules, 2025.
3. Personal Data We Collect
The following is an itemised description of the categories of personal data we collect and process through the Platform:
| Category | Data Elements | Collection Method |
|---|---|---|
| Email Address | The email address you enter into the breach-check search field on the Platform. | Directly provided by you via the search input field. |
| Password Hash Prefix | When you run a password check, your password is hashed (SHA-1) locally in your browser. Only the first 5 characters of that hash are sent to the password-lookup service (k-anonymity). Your password itself never leaves your device and is not stored by us. | Derived locally from your input in the password field; the prefix only is transmitted. |
| Domain Name (optional) | If you use the domain scan feature, the domain name you submit is processed to enumerate publicly-indexed personnel email addresses associated with that domain. | Directly provided by you via the domain input field. |
| Network Information (IP Address) | Your Internet Protocol (IP) address at the time of using the Platform. | Automatically captured from your network request headers. |
| Device & Browser (User-Agent) | Information about the browser type, version, and operating system you use to access the Platform. | Automatically captured from your HTTP request headers. |
| Usage & Activity Data | Timestamps of searches performed, breach check results, PDF report generation events, and interaction logs. | Automatically generated and recorded when you interact with the Platform. |
4. Purposes of Processing & Services Enabled
Your personal data is processed only for the specific purposes described below. Each purpose is linked to the corresponding data category and the service it enables:
| Purpose | Data Used | Service Enabled |
|---|---|---|
| Breach Detection & Notification | Email Address | Check your email against known data breach databases, stealer logs, and public pastes. |
| Password Exposure Check | Password Hash Prefix | Check whether your password has appeared in known breach corpora without ever transmitting the password itself (k-anonymity model). |
| Domain Exposure Assessment | Domain Name, Returned Personnel Emails | Identify which personnel email addresses for the domain have been involved in known breaches or stealer logs. |
| Report Generation | Email Address, Breach Results | Generate a downloadable PDF report summarising the breach check results for your reference. |
| Security & Abuse Prevention | IP Address, User-Agent | Protect the Platform from misuse, detect fraudulent or abusive activity, enforce rate limits. |
| Service Improvement & Analytics | Usage Data, IP Address, User-Agent | Understand usage patterns and improve Platform performance (data used in aggregate form). |
| Administrative & Audit Purposes | All categories above | Maintain audit trails, comply with legal obligations, support internal administrative functions. |
5. Third-Party Data Sharing
To provide the breach-checking service, we share certain data with the following third-party service providers (Data Processors):
| Third Party | Data Shared | Purpose |
|---|---|---|
| Have I Been Pwned (HIBP) - operated by Troy Hunt | Email Address, Domain Name | Your email address (or, for domain scans, the domain name and returned personnel email addresses) is transmitted to the HIBP API to query their database of known data breaches, stealer logs, and public pastes. HIBP Privacy Policy |
| HIBP Pwned Passwords API (Cloudflare) | First 5 characters of the SHA-1 hash of your password | When you run a password check, your password is hashed (SHA-1) locally in your browser. Only the first 5 characters of the hash are sent to the Pwned Passwords API, which returns a list of matching hash suffixes. The match is evaluated on your device - your full password and full hash are never transmitted (k-anonymity). API Reference |
We do not sell, rent, or trade your personal data to any third party for marketing or advertising purposes. Data is shared with the above third party solely for the purpose of providing the breach-checking service to you.
6. Data Storage & Retention
Your personal data is stored in a secured database hosted on our own vpc.
| Category | Retention Period | Basis |
|---|---|---|
| Search Records (Email, Breach Results, IP Address, User-Agent) | 90 days | Retained for the duration necessary to fulfil the specified purpose; erased thereafter or upon withdrawal of consent. |
| Activity Logs | 90 days | Retained for audit and compliance purposes as required under applicable law. |
In accordance with Section 8(7) of the DPDPA, we shall erase your personal data upon your withdrawal of consent, or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, unless retention is required under applicable law.
8. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:
Right to Access Information (Section 11)
Obtain a summary of your personal data being processed, the processing activities undertaken, and the identities of all Data Fiduciaries and Data Processors with whom your personal data has been shared.
Right to Correction and Erasure (Section 12)
Request correction of inaccurate or incomplete personal data, completion of incomplete data, updating of outdated data, and erasure of personal data that is no longer necessary.
Right to Grievance Redressal (Section 13)
Have readily available means of grievance redressal in respect of any act or omission regarding your personal data. You must first exhaust the grievance redressal mechanism provided by us before approaching the Data Protection Board of India.
Right to Nominate (Section 14)
Nominate any individual who may exercise your rights in the event of your death or incapacity.
Right to Withdraw Consent (Section 6(4))
Withdraw your consent at any time. Withdrawal of consent shall be as easy as the giving of consent. Upon withdrawal, we shall cease processing your personal data and erase it, unless retention is required under applicable law. Withdrawal will not affect the lawfulness of processing carried out prior to the withdrawal.
To exercise any of the above rights, please contact us at contact@cybervahak.com. We shall respond to your request as soon as reasonably possible.
9. Grievance Redressal Mechanism
In accordance with Section 13 of the DPDPA and Rule 14 of the DPDP Rules, 2025, we have established the following grievance redressal mechanism:
- Contact the Grievance Officer: Please write to us at contact@cybervahak.com with details of your grievance.
- Acknowledgement & Resolution: We shall acknowledge your grievance and endeavour to resolve it as soon as reasonably possible.
- Escalation to the Data Protection Board of India: If not satisfied, you may file a complaint with the Data Protection Board of India.
10. Security Measures
We implement reasonable security safeguards, including technical and organisational measures, to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
- Encryption of data in transit using HTTPS/TLS protocols;
- Secure, hashed storage of authentication credentials (bcrypt hashing);
- HTTP-Only and Secure flags on authentication cookies;
- Role-based access controls for administrative functions;
- Regular review and updating of security practices.
11. Consent Declaration
By clicking “Agree & Scan” / checking the consent checkbox and proceeding to use the Platform, you confirm that:
- You have read and understood this Consent Notice in its entirety;
- You freely, specifically, and unambiguously consent to the collection, storage, and processing of your personal data as described in this notice;
- You consent to the sharing of your email address, domain name (where applicable), and the first 5 characters of your password’s SHA-1 hash (for password checks) with Have I Been Pwned (HIBP) for the purpose of checking against known data breach and password exposure databases;
- You understand that you may withdraw your consent at any time, and that such withdrawal will not affect the lawfulness of processing carried out prior to the withdrawal;
- You understand your rights as a Data Principal under the Digital Personal Data Protection Act, 2023;
- You are above the age of 18 years. If below 18, verifiable consent has been obtained from your parent or lawful guardian.
12. Contact Us
For any questions or concerns regarding this Consent Notice, your personal data, or your rights under the DPDPA, please contact:
13. Changes to this Consent Notice
We may update this Consent Notice from time to time to reflect changes in our data processing practices or applicable legal requirements. Any material changes will be communicated to you through the Platform, and where required, fresh consent will be obtained. We encourage you to review this notice periodically.
14. Governing Law
This Consent Notice is governed by the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and any other applicable laws of India. Any disputes arising out of or in connection with this notice shall be subject to the exclusive jurisdiction of the Data Protection Board of India and the courts of India.