Important Notice
This Privacy Policy is a product-level template prepared for SecureCMS by SecuredApp and is intended to describe how SecureCMS handles personal data in connection with its website, dashboard, APIs, SDKs, consent-management services, and related support services. It should be reviewed and approved by the legal/privacy team of the entity that operates SecureCMS before publication. Replace bracketed contact and entity placeholders before use.
This Policy is designed with reference to India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Digital Personal Data Protection Rules, 2025. The notified Rules were published by the Ministry of Electronics and Information Technology (MeitY) on 14 November 2025 and provide a phased commencement framework.
1. About SecureCMS
SecureCMS is a consent management and data governance platform provided by SecuredApp. It enables organizations (each a "Customer" or "Data Fiduciary", as applicable) to configure purposes of processing, collect and manage consent, maintain consent records, support withdrawal of consent, manage data subject requests, maintain policy versions, provide audit trails, and integrate consent enforcement with customer applications and systems.
SecureCMS may process personal data in two principal contexts:
- First, Direct Service Operations (as Data Fiduciary): SecuredApp may process information relating to its own customers, administrators, website visitors, users, and business contacts for operating and securing its own services.
- Second, Customer Processing (as Data Processor):SecureCMS may process personal data submitted by a Customer on the Customer's behalf. In the second context, the Customer generally determines the purposes and means of processing and SecureCMS acts as a Data Processor or service provider to the Customer, subject to the applicable agreement and law.
2. Scope
This Policy applies to personal data processed through SecureCMS-controlled websites, web applications, dashboards, APIs, SDKs, hosted consent interfaces, support channels, and related services. It also describes the privacy practices applicable when SecuredApp receives information directly from individuals or processes information for its business operations.
Where SecureCMS is deployed for a Customer and the Customer controls the purposes of processing, the Customer's own privacy notice and instructions may apply to the Customer's processing. Individuals should contact the relevant Customer/Data Fiduciary for questions about data collected by that Customer through SecureCMS.
3. Categories of Personal Data We May Process
Depending on the service and configuration, SecureCMS may process the following categories:
- Account and identity information: name, work email address, phone/mobile number, username, organization, role, and account identifiers.
- Authentication information: authentication identifiers, Google SSO identifiers where enabled, login metadata, session information, and security-related records.
- Consent information: consent status, purpose, policy/version identifier, timestamp, consent method, withdrawal information, consent receipt/reference ID, and related audit information.
- Technical information: IP address, browser and device information, operating system, application version, approximate location derived from IP where necessary, logs, diagnostics, and security events.
- Integration information: API identifiers, tenant/application identifiers, webhook configuration metadata, integration status, and technical request/response metadata.
- Support and communications information: information contained in support tickets, correspondence, feedback, and service requests.
- Customer-submitted information: personal data that a Customer chooses to process through SecureCMS. This may include identifiers such as email address, mobile number, name, customer reference, or other fields configured by the Customer.
- Cookie and similar technology data: device identifiers and preference/consent information used by the SecureCMS Cookie Management functionality, where enabled.
4. How We Collect Personal Data
- Directly from you: when you create an account, sign in, contact us, request support, or otherwise interact with SecureCMS.
- From your organization or Customer: when your organization provisions your SecureCMS account or submits information for processing.
- Automatically from browsers, devices, applications, APIs, SDKs, and security infrastructure: when you use SecureCMS.
- From third-party identity providers: such as Google, when SSO is enabled and you choose to authenticate using that provider.
- From integrations configured by a Customer: where the Customer is responsible for ensuring that it has an appropriate lawful basis and authority to provide the data.
5. Purposes of Processing
We may process personal data for the following purposes, as applicable:
- Providing, operating, maintaining, and improving SecureCMS.
- Creating and administering customer and user accounts.
- Authenticating users and preventing unauthorized access.
- Collecting, recording, managing, reviewing, and withdrawing consent on behalf of Customers.
- Maintaining consent records, policy versions, audit records, and compliance evidence.
- Processing and routing data subject requests, grievances, and related workflow information as configured by Customers.
- Operating APIs, webhooks, SDKs, integrations, notifications, and enforcement mechanisms.
- Monitoring availability, performance, reliability, and security.
- Detecting, preventing, and investigating fraud, abuse, security incidents, and unauthorized activity.
- Providing customer support, troubleshooting, and service communications.
- Meeting legal, regulatory, contractual, accounting, audit, and record-keeping obligations.
- Protecting the rights, property, safety, and security of SecuredApp, its customers, users, and others.
- Other purposes disclosed at the point of collection or authorized by the applicable Customer and law.
6. Consent and Lawful Processing
SecureCMS provides technical functionality that enables Customers to obtain, record, manage, review, and withdraw consent where consent is the applicable basis for processing. The Customer is responsible for determining the appropriate purpose, notice, lawful basis, consent language, data fields, retention period, and processing configuration for its own activities.
Where SecureCMS processes data for its own purposes, SecuredApp will process the data in accordance with applicable law and the disclosures in this Policy. Where consent is required, we will seek consent in an appropriate manner and provide mechanisms for withdrawal where applicable.
7. Role of SecureCMS and Customers
For customer-submitted personal data, SecureCMS generally acts on documented instructions from the Customer. The Customer remains responsible for determining why the data is processed, ensuring that the processing is lawful, providing required notices, configuring consent and purpose records appropriately, responding to individual requests where it is the responsible Data Fiduciary, and ensuring that integrations and onward disclosures are authorized.
SecureCMS may act as a Data Fiduciary for information collected for its own account management, security, billing, support, website, and business operations. The applicable role depends on the specific processing activity.
8. Sharing and Disclosure of Personal Data
We may disclose personal data only as necessary for legitimate and authorized purposes, including:
- To the Customer/Data Fiduciary that configured or requested the relevant SecureCMS processing.
- To infrastructure, hosting, security, communications, identity, analytics, and other service providers acting under appropriate contractual or technical controls.
- To professional advisers, auditors, insurers, or other vendors where reasonably necessary for business operations and subject to confidentiality obligations.
- To governmental, regulatory, law-enforcement, or judicial authorities where required or permitted by applicable law.
- In connection with a corporate transaction such as a merger, acquisition, restructuring, financing, or sale of assets, subject to applicable legal requirements.
- With your authorization or where otherwise permitted by applicable law.
SecureCMS does not sell personal data for monetary consideration as a standalone data-brokerage activity.
9. Data Security
SecureCMS is designed to apply reasonable security safeguards appropriate to the nature and risk of the processing. Depending on the deployment and service configuration, security measures may include encryption in transit, encryption at rest, access controls, role-based access control, tenant isolation, authentication controls, API authentication, mTLS or IP allowlisting where configured, logging and monitoring, backup controls, vulnerability management, secure development practices, and incident-response procedures.
No method of transmission, storage, or electronic processing can be guaranteed to be completely secure. Customers are responsible for securing their own credentials, API keys, integration endpoints, devices, and systems connected to SecureCMS.
10. Data Minimization and Hashing
SecureCMS is designed to minimize the personal data retained by the platform where the service architecture permits. For certain identity-matching or consent-linking functions, SecureCMS may use cryptographic hashes or pseudonymous identifiers instead of retaining direct identifiers. A hash or pseudonymous identifier should not automatically be treated as anonymous data; its status depends on whether an individual can reasonably be identified using available means.
Where a Customer requires plain personal data to be delivered through an authorized webhook or API integration, such processing will be governed by the Customer's configuration, applicable agreement, security controls, and applicable law. SecureCMS should not be configured to transmit more personal data than is necessary for the specified purpose.
11. Cookies and Similar Technologies
SecureCMS may use cookies, local storage, device identifiers, SDK identifiers, and similar technologies for essential functionality, security, authentication, preferences, analytics, and consent management, depending on the deployment.
Where SecureCMS is used by a Customer to manage cookies on the Customer's website, the Customer is responsible for the website's cookie inventory, purposes, vendor disclosures, consent configuration, and implementation of appropriate notices. SecureCMS provides the technical controls for recording and enforcing the configured choices.
12. Google SSO and Third-Party Authentication
If Google Sign-In/SSO is enabled, SecureCMS may receive authentication information from Google, such as a unique Google account identifier, name, email address, profile information made available through the configured authentication flow, and authentication metadata. SecureCMS uses this information to authenticate the user and associate the user with the relevant SecureCMS account.
SecureCMS does not require access to a user's Google password. Third-party authentication providers process information under their own privacy terms and policies.
13. Data Retention
We retain personal data only for as long as reasonably necessary for the purposes described in this Policy, to provide the services, comply with contractual and legal obligations, maintain security and audit records, resolve disputes, and enforce agreements.
For Customer data, retention may be determined by the Customer's configuration and contractual instructions, subject to applicable law. Consent and audit records may require longer retention where necessary to demonstrate compliance or meet a legal obligation.
When personal data is no longer required, SecureCMS may delete, anonymize, aggregate, or securely dispose of it, subject to applicable retention obligations and backup/technical limitations.
14. Data Subject / Data Principal Rights
Subject to applicable law and the circumstances of processing, individuals may have rights including access to information about their personal data, correction and updating, erasure, grievance redressal, withdrawal of consent where consent is the basis of processing, and nomination/other rights provided by applicable law.
Where SecureCMS processes data on behalf of a Customer, requests relating to that processing should ordinarily be made to the relevant Customer/Data Fiduciary. SecureCMS may assist the Customer in responding to such requests in accordance with its contractual obligations and applicable law.
To exercise rights relating to SecuredApp's own processing, contact us using the details in Section 21. We may need to verify identity before fulfilling a request.
15. Grievance Redressal
If you have a privacy-related concern or grievance about processing performed by SecuredApp for its own purposes, you may contact our designated privacy/grievance contact using the details below. We will review and respond in accordance with applicable law.
For data processed by a SecureCMS Customer, the Customer's designated grievance/contact mechanism may be the appropriate first point of contact.
16. Children's Personal Data
SecureCMS is primarily intended for business and enterprise use. Customers are responsible for determining whether their processing involves children and for configuring age-related notices, consent, verification, and safeguards as required by applicable law.
Where SecureCMS processes children's personal data on behalf of a Customer, the Customer must provide appropriate instructions and ensure that the processing configuration complies with applicable requirements.
17. International Data Transfers and Processing Locations
SecureCMS may use cloud infrastructure and service providers located in India or other jurisdictions, depending on the deployment, hosting arrangement, Customer configuration, and service providers used. Where personal data is transferred or processed outside India, such processing will be subject to applicable law, contractual controls, and any applicable government restrictions or requirements.
Enterprise Customers may require specific hosting or residency arrangements. Such requirements should be documented in the applicable contract or order form.
18. Third-Party Service Providers
SecureCMS may use third-party providers for cloud hosting, databases, authentication, communications, monitoring, security, analytics, customer support, and other infrastructure required to provide the service. We seek to use providers that provide appropriate security and confidentiality commitments and to limit access to personal data to what is necessary.
A current sub-processor/service-provider list may be maintained separately where required by the applicable Customer agreement.
19. Personal Data Breach and Security Incidents
SecureCMS maintains processes for detecting, assessing, containing, investigating, and responding to security incidents in accordance with applicable law and contractual obligations. Where SecureCMS processes Customer data as a Data Processor, we will follow the incident-notification and cooperation requirements agreed with the Customer and applicable law.
Customers should maintain accurate security and privacy contacts so that incident communications can be made without unnecessary delay.
20. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to SecureCMS, applicable law, regulatory requirements, security practices, or business operations. Material changes will be communicated through appropriate channels where required. The latest version will identify its effective date and version number.
21. Contact and Privacy Information
For privacy questions, requests, or grievances relating to SecuredApp's own processing, contact:
22. Definitions
- “Personal Data”
- means data about an individual who is identifiable by or in relation to such data, as applicable under the DPDP Act.
- “Data Principal”
- means the individual to whom the personal data relates, as defined under applicable law.
- “Data Fiduciary”
- means the person who alone or in conjunction with other persons determines the purpose and means of processing personal data, as defined under the DPDP Act.
- “Data Processor”
- means a person who processes personal data on behalf of a Data Fiduciary, as defined under the DPDP Act.
- “Consent Manager”
- has the meaning assigned under the DPDP Act and applicable Rules. SecureCMS should not be described as a registered Consent Manager unless and until the relevant legal entity is registered and authorized to operate in that capacity.
- “Processing”
- includes an automated operation or set of operations performed on digital personal data, as applicable under the DPDP Act.
23. Regulatory Reference & Document Control
This Policy is intended to be read with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as applicable and as they come into force. The DPDP Act was enacted on 11 August 2023. The notified DPDP Rules, 2025 were published on 14 November 2025 and contain phased commencement provisions.
Nothing in this Policy limits any right or obligation that cannot lawfully be limited or excluded under applicable law.
| Version | Effective Date | Owner | Status |
|---|---|---|---|
| 1.0 | 11 August 2026 | SecuredApp / Privacy & Legal | Published |
- Digital Personal Data Protection Act, 2023 — Ministry of Electronics and Information Technology (MeitY).
- Digital Personal Data Protection Rules, 2025 — Ministry of Electronics and Information Technology (MeitY), notified 14 November 2025.