Skip to main content
State Emblem of India & Departmental Crest
CyberCheckIndia

GIGW 3.0 & STQC Pre-Audit Suite

Statutory Compliance & Data Governance

Privacy Policy & Cookie Disclosures

Effective Date: September 29, 2026 • Document Version: 3.1 • Compliant with GIGW 3.0, CERT-In, Digital Personal Data Protection (DPDP) Act 2023, EU GDPR / ePrivacy, and Google Publisher Policies.

1. Overview & Regulatory Framework

CyberCheck India ("we", "our", or "the Platform"), operated by Abhix Tech Labs, provides automated statutory pre-audit readiness evaluation, security header analysis, and network performance benchmarking for Indian government websites, public sector undertakings (PSUs), government contractors, and webmasters.

We are dedicated to maintaining the highest benchmarks of transparency, confidentiality, and data hygiene. This Privacy Policy outlines how information is gathered, processed, secured, and retained in rigorous adherence with:

  • Guidelines for Indian Government Websites (GIGW 3.0) — Ministry of Electronics and Information Technology (MeitY).
  • Digital Personal Data Protection (DPDP) Act, 2023 (India).
  • Information Technology Act, 2000 & Reasonable Security Practices Rules (SPDI Rules 2011).
  • EU General Data Protection Regulation (GDPR) & UK Data Protection Act 2018.
  • Google AdSense & Publisher Policies for advertising compliance and consent management.

2. Information We Collect & Processing Grounds

We practice data minimization and do not collect unsolicited personal data. Information processed falls strictly into the following categories:

  • User Authentication & Profile Data: When registering or logging in via OAuth 2.0 (Google, Microsoft Entra ID, or GitHub), we store your public display name, verified email address, and authentication provider ID. This information is utilized exclusively to maintain your user account, calculate audit credits, and preserve your scan history in your private dashboard.
  • Audit Target Domains & URLs: Public domain names, hostnames, and URLs submitted for automated assessment are processed in our secure diagnostic engine. Because this data belongs to public web endpoints, it is analyzed strictly to inspect machine-verifiable criteria (such as HTTPS/TLS configurations, DNS records, WCAG DOM contrast, and CERT-In defense headers).
  • Diagnostic Telemetry: When utilizing tools such as What Is My IP, Global DNS Propagation Checker, or the Internet Speed Test, your public IP address, Autonomous System Number (ASN), and ISP details are processed purely transiently in memory to return diagnostic results. They are never sold or tied to personal profiles.
  • Payment & Order Transactions: Financial billing for report unlocks or subscription packages is managed directly by RBI-authorized, PCI-DSS Level 1 compliant payment aggregators (Razorpay). CyberCheck India never accesses, records, or stores credit card numbers, CVVs, or bank netbanking passwords.

3. Google AdSense & Advertising Cookies Notice

To maintain our webmaster utilities, DNS inspectors, and bandwidth diagnostics as free citizen tools, we display advertisements provided by Google AdSense and authorized third-party ad networks. Under Google Publisher Policies, we explicitly disclose the following:

• Third-Party Vendors & Google: Third-party vendors, including Google, use cookies to serve ads based on a user's prior visits to CyberCheck India or other websites on the Internet.

• DoubleClick & Advertising Cookies: Google's use of advertising cookies enables it and its partners to serve ads to users based on their visits to our site and/or other sites across the Internet.

• Opting Out of Personalized Advertising: You have the absolute right to opt out of personalized advertising at any time. You can disable personalized Google ads by visiting Google Ads Settings.

• Industry Opt-Out Portals: Alternatively, you can opt out of a third-party vendor's use of cookies for personalized advertising by visiting:

4. Complete Cookie & Local Storage Inventory

Below is the comprehensive catalog of first-party and third-party cookies utilized on CyberCheck India:

Cookie IdentifierProviderCategoryPurpose & DescriptionDuration
next-auth.session-tokenCyberCheck IndiaStrictly NecessaryMaintains authenticated user session and dashboard security across page loads.30 Days
__Host-next-auth.csrf-tokenCyberCheck IndiaStrictly NecessaryPrevents Cross-Site Request Forgery (CSRF) attacks during authentication.Session
FCCDCF / FCNECGoogle CMPConsentStores user privacy consent choices under the IAB Europe TCF v2.2 framework.13 Months
__gads / __gpiGoogle AdSenseAdvertisingMeasures ad impressions, limits frequency, and combats ad fraud.13 Months
IDE / DSIDGoogle DoubleClickMarketingDelivers relevant ads across non-Google sites based on previous interest profiles.1 Year
_ga / _ga_*Google AnalyticsPerformanceAggregated anonymous usage statistics to optimize page load speeds and reliability.2 Years

5. Data Principal Rights (DPDP Act 2023, GDPR & CCPA/CPRA)

As a Data Principal under India's Digital Personal Data Protection Act, 2023, and applicable international laws (including GDPR and CCPA/CPRA), you possess sovereign rights over your data:

Right to Information & Access

Obtain confirmation of whether your data is being processed, and request a structured copy of personal records.

Right to Correction & Erasure

Correct inaccurate personal data or request permanent deletion of your account and diagnostic logs.

Right to Withdraw Consent

Withdraw consent for non-essential processing at any time without retroactive penalty.

Non-Discrimination & No Sale of Data

We do NOT sell or share personal data for monetary consideration. Exercising your rights incurs zero fee or degraded service.

6. Data Security, Encryption & Retention Policy

CyberCheck India adheres to CERT-In Web Application Security Guidelines and ISO/IEC 27001 best practices:

  • Transport Layer Security: All client-to-server traffic is encrypted using TLS 1.3 with mandatory HTTP Strict Transport Security (HSTS).
  • Encryption at Rest: Database assets, generated PDF compliance dossiers, and audit telemetry are encrypted at rest using AES-256.
  • Retention Schedules: Free diagnostic reports and ephemeral speed test logs are auto-purged on rolling 30-day windows. Registered user scan archives are retained for the duration of the account or until explicitly deleted by the user.

7. Protection of Children & Age of Digital Consent

CyberCheck India is an enterprise statutory compliance diagnostic tool intended exclusively for webmasters, developers, IT procurement managers, and government auditors aged 18 years or older. In accordance with Section 9 of the DPDP Act 2023 and COPPA (USA), we do not knowingly solicit, collect, or process personal data from children or individuals under the age of digital consent.

8. Grievance Redressal & Nodal Officer Details

In accordance with GIGW 3.0 Clause 6.1.1, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, and the DPDP Act 2023, you may escalate any data protection queries or exercise your legal rights by contacting our designated officer:

DesignationData Protection & Grievance Officer
Operating EntityAbhix Tech Labs
Telephone Assistance+91 95992 27596