DPDP Act Compliance
CyberEDT is committed to protecting personal data in accordance with the Digital Personal Data Protection (DPDP) Act, 2023 of India. We believe privacy is a fundamental right and are dedicated to processing personal information lawfully, fairly, securely, and transparently across all CyberEDT products and services.
Our compliance program ensures that individuals maintain control over their personal information while enabling CyberEDT to deliver secure and reliable cybersecurity solutions.
Our Privacy Principles
CyberEDT follows internationally recognized privacy and data protection principles throughout the organization.
Data Minimization
We collect only the personal data that is necessary to provide, secure, improve, and support our services.
Purpose Limitation
Personal data is processed only for the purposes clearly communicated to you at the time of collection.
We never use personal information for unrelated purposes without obtaining additional consent where required.
Accuracy
We strive to ensure that personal information remains accurate, complete, and up to date.
Users may request corrections whenever necessary.
Storage Limitation
Personal data is retained only for as long as necessary to fulfill the intended purpose or comply with applicable legal obligations.
Accountability
CyberEDT maintains internal governance, security controls, and operational procedures designed to ensure compliance with applicable privacy regulations.
What Personal Data We May Collect
Depending on the CyberEDT services you use, we may collect:
- Name
- Email Address
- Account Credentials
- Organization Name
- Profile Information
- Billing Information (where applicable)
- Support Requests
- Security Logs
- Device Information
- Browser Information
- Authentication Records
CyberEDT does not sell personal data to advertisers or unrelated third parties.
Why We Process Personal Data
Personal information may be processed for purposes including:
- Account Management
- Identity Verification
- Platform Security
- Authentication
- Customer Support
- Service Delivery
- Course Enrollment
- Internship Management
- Enterprise Services
- Platform Analytics
- Legal Compliance
Personal data is never processed for unrelated marketing or AI model training without appropriate notice and consent.
Consent
Where consent is required, CyberEDT ensures it is:
- Free
- Specific
- Informed
- Unambiguous
- Revocable
Users may withdraw consent at any time where applicable.
Withdrawal of consent does not affect processing that occurred before withdrawal.
Your Rights
As a Data Principal under the DPDP Act, you may exercise the following rights.
Right to Access
Request information regarding how your personal data is processed.
Right to Correction
Request correction or updating of inaccurate personal information.
Right to Erasure
Request deletion of personal data when it is no longer necessary or where consent has been withdrawn, subject to legal obligations.
Right to Grievance Redressal
Raise privacy concerns or complaints directly with CyberEDT.
Right to Nominate
Nominate another individual to exercise your rights under circumstances permitted by applicable law.
Data Security
CyberEDT protects personal information using multiple layers of security including:
- TLS 1.3 Encryption
- AES-256 Encryption
- Zero Trust Security Architecture
- Multi-layer Access Controls
- Continuous Security Monitoring
- Secure Authentication
- Infrastructure Hardening
- Audit Logging
Cross-Border Data Processing
Where required, CyberEDT ensures that cross-border processing complies with applicable laws and governmental regulations.
Appropriate safeguards are implemented before transferring personal information outside approved jurisdictions.
Third-Party Service Providers
CyberEDT may engage trusted third-party providers for services such as:
- Cloud Infrastructure
- Payment Processing
- Identity Management
- Email Delivery
- Security Monitoring
- Analytics
All providers are evaluated for security and privacy practices before integration.
Data Retention
Personal information is retained only for the duration necessary to:
- Deliver requested services
- Meet contractual obligations
- Comply with legal requirements
- Resolve disputes
- Maintain platform security
When retention is no longer necessary, data is securely deleted or anonymized.
Compliance Status
CyberEDT continuously improves its privacy and compliance program.
| Compliance Area | Status |
|---|---|
| Consent Management | ✔ Implemented |
| Data Minimization | ✔ Implemented |
| Encryption Standards | ✔ Implemented |
| User Rights Management | ✔ Implemented |
| Security Monitoring | ✔ Implemented |
| Data Retention Controls | ✔ Implemented |
| Vendor Security Reviews | Ongoing |
| Continuous Compliance Reviews | Ongoing |
Contact Our Privacy Team
For privacy-related questions or requests, please contact:
Privacy Office
📧 founder@cyberedt.com
Grievance Officer
For complaints regarding personal data processing or to exercise your rights under applicable privacy laws:
CyberEDT Legal & Compliance
📧 founder@cyberedt.com
We review and respond to all privacy requests within the timelines required by applicable law.
Our Commitment
CyberEDT believes trust is earned through transparency, accountability, and responsible data stewardship.
We continuously invest in security, privacy, and compliance to ensure that every learner, professional, organization, and partner can use CyberEDT with confidence.