Legal

Privacy Policy

How Cehpoint collects, uses, shares and protects your personal data across the AI platform, the services portal and the testing marketplace.

Last updated: 15 July 2026 Applies to all Cehpoint products & services

This Privacy Policy explains how Cehpoint ("Cehpoint", "we", "us") collects, uses, discloses and safeguards your information when you use our websites, the AI platform, the services portal (cehpoint.co.in/app), the product-testing marketplace, the Cehpoint Card, our APIs and any related services (together, the "Services"). We are the data fiduciary for the personal data we process about you.

We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian law. Please read this alongside our Cookie Policy and Data Protection statement.

1. Scope

This policy covers three main surfaces of the Cehpoint ecosystem:

2. What personal data we collect

CategoryExamples
Account dataName, email, phone, organisation, password (hashed), role, profile details.
Transaction dataOrders, wallet/credit balance, invoices, GST details, Cehpoint Card activity, amounts and payment status. Full card/bank numbers are handled by our payment processor, not stored by us.
Usage dataPages visited, features used, device/browser type, IP address, approximate location, log and diagnostic data.
Content you providePrompts, files, messages, project briefs, testing reports, feedback and anything you upload to the Services.
CommunicationsSupport tickets, enquiry/callback forms, emails and chat with our team.

We collect data when you create an account, use the Services, make a payment, upload content, contact us, or through cookies and similar technologies.

3. How we use your data

Our legal bases include your consent, performance of a contract with you, our legitimate business interests, and compliance with legal obligations, as recognised under the DPDP Act and applicable law.

4. Cookies and tracking

We use strictly necessary cookies (for login/session and security) and, where enabled, analytics cookies to understand usage. You can control cookies through your browser. See our Cookie Policy for details.

5. AI platform data

When you use AI features, your prompts and any content you submit are sent to the AI model(s) that power the response. Depending on your configuration this may include third-party model providers acting as our processors. We use your AI inputs and outputs to deliver the feature, maintain safety and support, and — where you have enabled it — to ground responses on your own uploaded knowledge base. We do not sell your prompts. Where you connect your own data for "grounding", it is kept logically isolated to your account/key. Please do not submit sensitive personal data you do not want processed by an AI model.

6. Third parties and processors

We share personal data only as needed to run the Services, with providers bound by confidentiality and data-protection obligations:

Provider typePurpose
PayU and other payment gatewaysProcessing payments and refunds. They handle card/bank/UPI details under their own privacy terms; we receive only transaction status and limited metadata.
GoogleSign-in/authentication, and, where enabled, analytics and email delivery.
AI model providersGenerating AI responses for prompts and content you submit to AI features.
Hosting, email, SMS and infrastructure vendorsDelivering, hosting and securing the Services.
Testers / clients in the marketplaceLimited data shared to enable a testing engagement (e.g. a tester's report is shared with the commissioning client).

We may also disclose data to comply with law, enforce our terms, or in connection with a merger, acquisition or restructuring, subject to this policy. We do not sell your personal data.

7. Data retention

We keep personal data only for as long as necessary for the purposes above, including the life of your account and thereafter as required to meet legal, tax, accounting, dispute-resolution and security obligations. Financial and invoice records are typically retained for the period required under Indian tax law (generally up to 8 years). When data is no longer needed we delete or anonymise it.

8. Your rights

Subject to the DPDP Act and applicable law, you may:

To exercise any right, email grievance@cehpoint.co.in. We may verify your identity before acting on a request.

9. Security

We use reasonable technical and organisational safeguards — including encryption in transit, access controls, hashed passwords and tenant isolation — to protect personal data. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If a personal data breach affects you, we will notify you and the authorities as required by law.

10. Children

The Services are intended for users aged 18 and over and are not directed at children. Where we knowingly process a child's data, we do so only with verifiable parental/guardian consent as required by the DPDP Act, and we do not undertake tracking, behavioural monitoring or targeted advertising to children.

11. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above reflects the latest version. Material changes will be notified through the Services or by email. Continued use after an update constitutes acceptance of the revised policy.

Contact us

If you have any questions, requests or complaints about this document or how we handle your information, contact:

Cehpoint · West Bengal, India — registered office address available on request. Questions about this document? Email support@cehpoint.co.in. This page is provided for general information and forms part of the agreement between you and Cehpoint; it is not a substitute for independent legal advice.