Legal
Privacy Policy
How Cyber Mobility Shield collects, uses, stores, and protects personal data on cybermobilityshield.com, including rights under India's Digital Personal Data Protection Act, 2023 (DPDP Act).
1. Overview
Cyber Mobility Shield (“we”, “us”, “our”) operates cybermobilityshield.com and related training and tool workspaces. This Privacy Policy explains how we handle personal data when you visit our website, submit the contact form, or create a training portal account.
We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act), and the rules notified thereunder.
2. Data fiduciary and contact
For personal data collected through this website and our training portal, Cyber Mobility Shield acts as the Data Fiduciary.
Privacy & Grievance Desk: contact@cybermobilityshield.com
Postal address: Aligarh, Uttar Pradesh, India
3. Personal data we collect
- Contact form: name, email, optional company, subject, and message content.
- Training portal sign-up: name, email, password (stored hashed by our authentication service), optional company, designation, phone country code, phone number, and training interests.
- Training portal sign-in: email and password.
- Technical data: IP address, browser type, device information, and server logs generated when you use the site (for security and reliability).
- Cookies and local storage: theme preference (light/dark) stored in your browser; we do not use advertising cookies on this site today.
4. Purposes of processing
- Respond to enquiries submitted through the contact form.
- Provide access to the training catalog and learner profile features.
- Operate, secure, and improve our website and services.
- Comply with legal obligations and respond to lawful requests.
- Communicate service-related notices (for example, account or security updates).
5. Lawful basis and consent (DPDP Act)
Under the DPDP Act, we rely primarily on your consent when you submit the contact form or register for a training account. By submitting those forms, you confirm you have read this Privacy Policy and consent to processing for the purposes described above.
We may also process personal data where necessary to comply with law, respond to grievances, or protect the security and integrity of our systems — permitted grounds under the DPDP Act.
You may withdraw consent for non-essential processing by contacting us. Withdrawal does not affect processing already completed lawfully, and may limit our ability to provide certain services (for example, training portal access).
6. Data retention
- Contact submissions: retained as long as needed to respond, manage the relationship, and meet record-keeping requirements, then deleted or anonymised unless law requires longer retention.
- Training accounts: retained while your account is active and for a reasonable period afterward for audit, dispute, and security purposes.
- Server and security logs: retained for a limited period appropriate to security monitoring, typically not longer than 12 months unless required for an investigation.
8. Security
We apply administrative, technical, and organisational measures appropriate to the risk, including encrypted transport (HTTPS), access controls, and secure credential handling for training accounts.
No method of transmission or storage is completely secure. If you believe your interaction with us is compromised, contact us immediately.
9. Your rights as a Data Principal (DPDP Act)
Subject to the DPDP Act and applicable exceptions, you may have the right to:
To exercise these rights, email us at contact@cybermobilityshield.com with the subject line "DPDP Data Principal Request". We may need to verify your identity before fulfilling a request.
If you are not satisfied with our response, you may escalate to the Data Protection Board of India as provided under the DPDP Act once operational procedures are notified.
- Obtain a summary of personal data we process about you and the processing activities undertaken.
- Request correction, completion, or updating of inaccurate or incomplete personal data.
- Request erasure of personal data when retention is no longer necessary or consent is withdrawn (subject to legal retention needs).
- Nominate another individual to exercise your rights in the event of death or incapacity, in the manner prescribed under law.
- Grievance redressal: raise a complaint with our Grievance Desk; we will respond within timelines prescribed under the DPDP rules.
10. Children
Our services are intended for business and professional users. We do not knowingly collect personal data from individuals below 18 years of age without verifiable parental or guardian consent as required under the DPDP Act. Contact us if you believe we have collected a minor’s data.
11. Changes to this policy
We may update this Privacy Policy when our practices or legal requirements change. The “Last updated” date at the top of this page will reflect material revisions. Continued use of the site after an update constitutes notice of the revised policy where consent is not required anew.
