Terms of Service

Effective Date: August 26, 2026

Section 1 — Acceptance of Terms

By creating an account, accessing, or using DPDP Shield, you explicitly agree to be bound by these Terms of Service and our Privacy Policy. If you do not agree, you must discontinue access immediately.

Section 2 — What DPDP Shield Does

DPDP Shield is an assisted DPDPA 2023 compliance platform. It provides compliance self-assessment questionnaires, automated gap analysis, risk prioritization, evidence mapping, consent management tools, a data subject rights portal, vendor/processor management, and LEAP v2 PII detection — all designed to help Indian SMBs document and improve their DPDPA compliance posture.

Our reports, scorecards, and recommendations are for informational and documentation purposes only and do not constitute formal legal advice. We strongly recommend consulting a qualified legal professional for critical compliance decisions. DPDP Shield does not guarantee regulatory compliance or immunity from enforcement action by the Data Protection Board of India.

Section 3 — Account Responsibilities

  • You are solely responsible for maintaining the confidentiality of your account credentials.
  • You must provide accurate, current, and complete details about your company and data practices during onboarding and throughout your use of the platform.
  • One corporate account per legal entity is permitted.
  • You must not use DPDP Shield, the LEAP v2 engine, the Consent SDK, or the Rights Portal for any unlawful, fraudulent, or unauthorized purpose.
  • You are responsible for the accuracy of data you input into the compliance questionnaire and vendor management module. DPDP Shield's output quality is dependent on the accuracy of your inputs.

Section 4 — LEAP v2 PII Scanner — Usage Terms

  • LEAP v2 is a browser-side PII detection tool. Files you upload for scanning are processed locally in your browser and are not transmitted to Kryptasys servers.
  • You may only use LEAP v2 to scan files you own or have explicit authorization to process.
  • You must not use LEAP v2 to scan files containing personal data of individuals without a lawful basis under DPDPA 2023.
  • Scan quota is enforced per plan:
    • Free Plan: 1 compliance assessment scan per month (LEAP scans not included).
    • Starter Plan: 5 LEAP PII scans per billing cycle.
    • Business Plan: Unlimited LEAP scans (custom pricing).
  • Unused scans do not roll over to the next billing cycle.

Section 5 — Subscription & Payments

  • Free Plan: 1 compliance assessment per month. No payment required.
  • Starter Plan: ₹4,999 per month, billed monthly via Razorpay. Includes 5 LEAP scans per cycle.
  • Business Plan: Custom pricing. Contact us at contact@kryptasys.in for a quote.
  • All payments are processed by Razorpay. By subscribing, you also agree to Razorpay's terms of service.
  • PDF invoices are generated and emailed to your registered billing email after each successful payment.
  • Refund Policy: Refund requests must be submitted within 7 days of invoice date to contact@kryptasys.in. No refunds will be issued after 7 days. Partial refunds for unused billing period are at Kryptasys's sole discretion.
  • We reserve the right to suspend or terminate accounts for persistent non-payment.

Section 6 — 14-Day Free Trial

All new accounts receive a 14-day free trial of the Starter plan. No credit card is required. The trial ends automatically after 14 days with no charges applied. Upgrading to a paid plan requires your explicit action on the billing portal — no automatic upgrades occur.

Trial eligibility is determined per legal entity. Attempts to create multiple accounts to extend trial access may result in permanent account suspension under our abuse prevention policy.

Section 7 — Vendor & Processor Data

When you use the Vendor/Processor Management module, you enter details about your third-party vendors and data processors. You are solely responsible for the accuracy of this information and for obtaining any necessary consents or agreements with those vendors. Kryptasys stores this data on your behalf as a Data Processor under DPDPA 2023.

Section 8 — Audit Logs

Your account activity is logged in an append-only, tamper-evident audit trail. These logs are owned by you and are maintained by Kryptasys on your behalf. Audit logs cannot be deleted — including on request — as they form part of your DPDPA compliance evidence record. Audit log data is retained for 5 years.

Section 9 — Support

  • Support requests can be submitted via the in-dashboard Support Center.
  • Standard tickets: Response within 24 business hours.
  • Critical issues (system down, active security incident): Acknowledged within 2 hours.
  • Support is available in English and Hindi.
  • Support ticket content is retained for 12 months after closure.

Section 10 — Account Termination & Suspension

We reserve the right to suspend or permanently terminate accounts that:

  • Violate these Terms of Service.
  • Engage in trial abuse or fraudulent multi-account registrations.
  • Fail to make payment after repeated attempts.
  • Use the platform for unlawful purposes.

Upon termination, your data will be retained for 12 months and then permanently deleted, except for records subject to legal retention requirements (consent logs, audit trails, payment records).

Section 11 — Data Portability

You may request an export of your compliance data, scan history, and account information at any time by contacting contact@kryptasys.in. We will provide your data in a machine-readable format (JSON or CSV) within 30 days.

Section 12 — Intellectual Property

DPDP Shield, LEAP v2, the Consent SDK, the Rights Portal, all compliance templates, report formats, and associated software are owned exclusively by Kryptasys. You may not copy, modify, distribute, sell, lease, reverse engineer, or decompile any portion of our software or services without prior written authorization from Kryptasys.

Section 13 — Limitation of Liability

DPDP Shield assists with compliance documentation and self-assessment. It does not guarantee regulatory compliance or immunity from enforcement. Kryptasys, its founders, and employees are not liable for any statutory penalties, financial losses, or reputational damage imposed by the Data Protection Board of India or any other authority arising from your organization's compliance posture.

To the maximum extent permitted by Indian law, Kryptasys's total liability for any claim arising from your use of the platform shall not exceed the total fees paid by you in the 3 months preceding the claim.

Section 14 — Governing Law

These Terms are governed by the laws of the Republic of India. Any disputes shall be subject to the exclusive jurisdiction of the competent courts in the Delhi NCR region.

Section 15 — Changes to Terms

We reserve the right to revise these Terms. For material changes, we will provide 30 days advance notice via email to your registered address. Continued use after the notice period constitutes acceptance of the revised terms.

Section 16 — Contact

KryptasysDelhi NCR, IndiaEmail: contact@kryptasys.in