Last Updated: May 10, 2026
Privacy Policy — At a Glance
A plain-English visual summary of how CYBER COPS India handles your data. The full legal policy follows below.
CYBER COPS India is MSSP-monitored 24/7. You can independently verify our website’s security and safety status using any of the trusted tools below:
ISO 27001:2022 Lead Auditor · CCCI
Diploma in Indian Cyber Law, GLC Mumbai
11+ Years GRC · Fellow IETE
| CYBER COPS India Privacy Policy Effective Date: May 10, 2026 | Version 2.0 | Jurisdiction: India |
| Amendment Notice — Version 2.0 This policy has been revised on 24 March 2026 to align with India’s Digital Personal Data Protection Act, 2023 (DPDPA). Additions include: Lawful Basis for Processing (§3), Consent Mechanism (§4), Data Breach Notification (§10), Cross-Border Data Transfers (§11), updated Cookie Consent (§6), enhanced Data Retention periods (§8), and strengthened Data Principal Rights (§12). All changes are marked in context below. |
1. Introduction
CYBER COPS India (“CCI”, “we”, “us”, or “our”) operates the website https://cybercops.in. We are committed to protecting the privacy and personal data of our visitors in accordance with India’s Digital Personal Data Protection Act, 2023 (DPDPA) and all applicable Indian laws.
This Privacy Policy explains what personal data we collect, the lawful basis on which we process it, how we use and share it, and what rights you have as a Data Principal under the DPDPA.
This policy applies to information collected through https://cybercops.in and our associated Facebook Page (https://www.facebook.com/cybercopsindia.neelabhrai/). It does not govern information collected from other sources.
2. Information We Collect
(a) Non-Personally Identifying Information
Like most websites, we automatically collect non-personal technical data that web browsers and servers make available, including browser type, language preference, referring site, and the date and time of each visitor request. This helps us understand how our website is used and improve our content.
(b) Potentially Personally Identifying Information
We collect Internet Protocol (IP) addresses from logged-in users and from users who leave comments on our blog posts. IP addresses are treated as potentially personally identifying data and are handled accordingly.
(c) Information from Facebook
If you interact with our Facebook Page, certain personal information (such as your Facebook profile details) may become visible to us as Page administrators. We do not control what Facebook collects. Please review Facebook’s Privacy Policy for their data practices. We do not use Facebook Pixel or Facebook Custom Audiences on this website. If this changes, this policy will be updated and a revised consent notice will be displayed.
(d) Information You Voluntarily Provide
If you contact us directly (e.g., via email or a contact form), we may receive your name, email address, and the content of your message.
3. Lawful Basis for Processing [NEW — DPDPA §4]
We process personal data only where a lawful basis under the DPDPA applies. The applicable bases are:
| Lawful Basis | Activity | Data Involved |
| Consent (DPDPA §6) | Placing non-essential analytics cookies; processing voluntarily submitted comments | IP addresses, comment content, analytics identifiers |
| Legitimate Interest (DPDPA §4) | Website security monitoring, MSSP threat detection, fraud prevention | IP addresses, access logs |
| Legal Obligation (DPDPA §4) | Responding to lawful orders from courts or law enforcement | Any data as required by court order |
| Contractual Necessity | Responding to queries submitted via contact form | Name, email, message content |
4. Consent Mechanism [NEW — DPDPA §6]
Where we rely on consent as the lawful basis for processing, we obtain that consent as follows:
- Cookie consent: A cookie consent banner is displayed on your first visit to the website. Non-essential cookies (including analytics cookies) are not placed until you provide explicit consent by clicking ‘Accept’. You may also access granular cookie preferences via the ‘Manage Preferences’ option in the banner.
- Comment submissions: When you submit a comment on a blog post, a clear notice is displayed at the point of submission explaining that your IP address will be recorded and retained. Submission of the comment constitutes informed consent for this specific processing.
- Withdrawal: You may withdraw consent at any time by:
- changing your cookie preferences via the consent banner (accessible via the cookie icon in the footer), or
- submitting a data deletion request to privacy[at]cybercops[dot]in.
- Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
We do not use consent as a condition of accessing any content on this website.
5. How We Use Your Information
We use the information we collect for the following purposes:
- To understand and improve how visitors use our website
- To maintain the security and integrity of our website
- To respond to your queries or comments
- To comply with legal obligations, including responding to lawful orders from courts or law enforcement authorities
We do not sell, rent, or trade your personal data to any third party.
6. Cookies and Tracking Technologies [ENHANCED — DPDPA §6]
We use cookies and similar technologies to enhance your browsing experience, track site usage, and store preferences. A cookie is a small text file stored on your device by your browser.
Types of cookies we use:
| Category | Consent Required | Examples | Purpose |
| Essential | No (exempt) | WordPress session cookies | Required for website to function; cannot be disabled |
| Analytics | Yes — explicit opt-in required | Google Analytics | Understand visitor behaviour; set only after consent |
| Preference | Yes — explicit opt-in required | Language, theme settings | Remember your settings across visits |
Your choices: You may manage your cookie preferences at any time via the consent banner on this website. You may also configure your browser to refuse all cookies. Note that disabling essential cookies will affect website functionality.
7. Disclosure of Information [ENHANCED — Processor Details]
We do not disclose personally identifying information publicly. Disclosure occurs only in the following circumstances:
- Legal requirement: If compelled by a valid court order, summons, or other lawful legal process under Indian law.
- Data Processors: To trusted third-party service providers (data processors) under written Data Processing Agreements (DPAs) that restrict their use of your data to the services provided. Current processors include:
| Processor | Purpose | Data Shared | DPA in Place |
| Website Hosting Provider | Web hosting and infrastructure | Server logs, IP addresses | Yes |
| Google Analytics (opt-in only) | Visitor analytics | Anonymised usage data | Yes (Google Data Processing Terms) |
| MSSP / SiteLock | Security scanning and threat monitoring | Access logs, IP addresses | Yes |
- Aggregated, anonymised data: We may share aggregated, non-identifying statistics about visitor behaviour publicly or with partners.
8. Data Retention [ENHANCED — Specific Periods]
We retain personal data only as long as necessary for the purposes described in this policy or as required by applicable law. Specific retention periods by data category are as follows:
| Data Category | Retention Period | Rationale |
| IP addresses (server logs) | 12 months | Security monitoring and incident response |
| IP addresses (blog comments) | Duration of comment + 12 months post-deletion | Linked to content moderation and legal compliance |
| Contact form submissions | 24 months from last interaction | To respond to queries and maintain correspondence records |
| Analytics data (aggregate) | 26 months (Google Analytics default) | Trend analysis; anonymised after 12 months |
| Consent records (cookie) | 3 years from consent date | Evidence of lawful processing under DPDPA §6 |
We conduct periodic reviews (at least annually) and delete data that is no longer needed. Upon a valid deletion request (see §12), data will be erased within 30 days unless retention is required by law.
9. Data Security
We take the security of your personal data seriously. We employ technically and organisationally appropriate measures to protect your data, including round-the-clock MSSP monitoring of our website infrastructure.
However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security and encourage you to exercise caution when sharing information online.
You may independently verify our website’s security posture via: Google Safe Browsing, Norton SafeWeb, VirusTotal, and URLVoid.
10. Personal Data Breach Notification [NEW — DPDPA §8(6)]
In the event of a personal data breach, CYBER COPS India will:
- Notify the Data Protection Board of India: We will report any breach to the Data Protection Board in the form and manner prescribed under the DPDPA, without undue delay and in any case within the timeline specified by the Board.
- Notify affected Data Principals: Where a breach is likely to result in harm to the rights or interests of affected individuals, we will inform those individuals in a clear and plain manner, describing the nature of the breach, the data affected, the likely consequences, and the remedial steps we are taking.
- Maintain a breach register: We maintain an internal log of all data breaches, including near-misses, as required for accountability under DPDPA §8.
- Remediation: We will promptly take all reasonable steps to contain the breach, prevent recurrence, and cooperate fully with the Data Protection Board during any investigation.
If you believe your data held by us may have been compromised, please contact us immediately at privacy[at]cybercops[dot]in.
11. Cross-Border Data Transfers [NEW — DPDPA §16]
As an Indian-based website, some of your personal data may be transferred to and processed in countries outside India, including the United States, where our third-party service providers operate.
| Service / Recipient | Country | Transfer Mechanism | Data Transferred |
| Automattic / WordPress.com | USA | Standard Contractual Clauses (SCCs) | Server logs, IP addresses |
| Google LLC (Analytics) | USA | Google Data Processing Terms (SCCs) | Anonymised analytics (with consent) |
| Meta Platforms (Facebook) | USA | Meta Data Transfer Agreements | Page interaction data (as Page admin) |
All cross-border transfers are made under appropriate safeguards — currently Standard Contractual Clauses or equivalent transfer mechanisms approved under applicable law. We will update this section if the Government of India issues country adequacy decisions or revised transfer mechanisms under DPDPA §16.
12. Children’s Privacy
Our website is not directed at children under the age of 18. We do not knowingly collect personal data from minors. If you believe a child has provided us with personal data, please contact us at privacy[at]cybercops[dot]in and we will take steps to delete it promptly.
13. Your Rights as a Data Principal [ENHANCED — DPDPA §§11–14]
Under India’s Digital Personal Data Protection Act, 2023, you have the following rights:
| Right | Description | How to Exercise |
| Right to Access (§11) | Obtain a summary of your personal data we hold and details of processing. | Email request to privacy[at]cybercops[dot]in |
| Right to Correction (§12) | Correct inaccurate or incomplete personal data. | Email request with corrected information |
| Right to Erasure (§12) | Request deletion of your personal data, subject to legal obligations. | Email request; we will respond within 30 days |
| Right to Grievance Redressal (§13) | Raise a complaint about our data practices. We will respond within 30 days. | Contact Grievance Officer (see §15) |
| Right to Nominate (§14) | Nominate another person to exercise your rights in the event of your death or incapacity. | Written nomination via email to Grievance Officer |
| Right to Withdraw Consent | Withdraw consent for consent-based processing at any time. | Cookie preference centre or email request |
Identity verification: Before acting on a rights request, we may verify your identity by asking you to confirm details associated with your prior interactions with us (e.g., the email address from which you contacted us, or the content of a submitted comment).
Response timeline: We will acknowledge all requests within 7 days and provide a substantive response within 30 days. Complex requests may take up to 60 days; in such cases, we will notify you of the extension.
Escalation: If your request is not resolved to your satisfaction, you may escalate your complaint to the Data Protection Board of India once the Board is operationally established under the DPDPA.
14. Changes to This Privacy Policy [ENHANCED]
We may update this Privacy Policy from time to time. When we do, we will update the ‘Last Updated’ date at the top of this page. The nature of notice depends on the significance of the change:
- Minor changes: Administrative or clarifying edits — updated date only; no active notification.
- Material changes: Changes that affect the legal basis, types of data collected, or your rights — notified via a prominent website banner for a minimum of 30 days.
- Changes affecting consent-based processing: Where a change affects processing for which we relied on your consent, we will seek fresh consent before commencing the updated processing.
Note: Continued use of the website after a material policy change is posted does not constitute consent to the new terms where the processing is consent-based. Fresh consent will be obtained in such cases.
15. Contact & Grievance Officer [ENHANCED — DPDPA §13]
| Grievance Officer Name: Neelabh Rai, Founder, CYBER COPS India Website: https://cybercops.in Email: [email protected] Response Commitment: All legitimate requests acknowledged within 7 days; resolved within 30 days per DPDPA §13. Escalation: Unresolved complaints may be raised to the Data Protection Board of India (once operationally established) at https://dpboard.gov.in. |
| CYBER COPS India — Researching Bits & Bytes Privacy Policy v2.0 | Last Updated: March 24, 2026 | Governing Law: India (DPDPA 2023) |
