Privacy Policy
This policy explains what personal data DECTIFY handles, why, who we share it with, and what you can require of us. Where a country's law adds to this, the country supplement governs.
Start here, then read your country page. This is the umbrella policy. Individuals in India should also read India Privacy and Data Protection; individuals in Australia should also read Australia Privacy and Data Protection. Where a country supplement and this policy differ, the supplement prevails for people in that country.
1. Who we are
DECTIFY Technologies Private Limited ("DECTIFY", "we", "us"), a company incorporated in India with registered office at New Delhi, is responsible for the personal data described in this policy. Our contact for privacy matters is privacy@dectify.in, and our statutory officers are named at Grievance Redressal.
2. The two kinds of data, and why the difference matters
Almost every question about DECTIFY and privacy turns on this distinction.
| Data we control | Customer Data | |
|---|---|---|
| What it is | Data about visitors to our website, people who contact us, job applicants, and the staff of our customers who administer an account. | Video, images, plates, biometric templates, alerts and case records captured by a customer's Deployed System. |
| Our role | We decide why and how it is processed. We are the Data Fiduciary (India) / APP entity (Australia). | The customer decides why and how. We process only on their documented instructions, as Data Processor. |
| Who you ask about it | Us, at privacy@dectify.in. | The organisation operating the cameras. We will route your request to them and assist. |
| Governed by | This policy. | That customer's own privacy notice, plus our Data Processing Addendum and Biometric, ANPR and Facial Recognition Policy. |
Sections 3 to 9 of this policy concern data we control. Section 10 explains what we do with Customer Data.
3. Personal data we collect
3.1 When you use our website
- Technical data. IP address, browser and device type, operating system, referring page, pages viewed and time on them, and approximate location derived from IP address.
- Cookies and similar technologies. As described in the Cookie Policy. Everything beyond the strictly necessary category is off until you switch it on.
3.2 When you contact us or request a demonstration
- Name, business email, telephone number, employer, job title, country, and whatever you choose to put in the message field.
- A record of the correspondence and of any meeting or demonstration that follows.
3.3 When you apply for a job
- Contact details, CV, work history, qualifications, right-to-work information, references, and interview notes. Recruitment data is described further in our candidate privacy notice, provided at the point of application.
3.4 When you administer a customer account
- Name, work email, role, credentials and multi-factor authentication registration, access logs, support tickets, and training and certification records.
3.5 What we do not collect
We do not buy personal data from data brokers, we do not build advertising profiles about individuals, and we do not collect biometric data about website visitors. We do not knowingly collect data from children through our website; it is directed at businesses and public bodies, not children.
4. Why we use it, and on what basis
| Purpose | Basis in India (DPDP Act 2023) | Basis in Australia (Privacy Act 1988) |
|---|---|---|
| Operating and securing the website | Legitimate use — voluntary provision for a stated purpose | APP 3 — reasonably necessary for our functions |
| Responding to your enquiry or demo request | Consent, given by submitting the form | APP 3, APP 6 — primary purpose of collection |
| Providing and supporting the Platform | Performance of contract with the customer | APP 3, APP 6 — primary purpose |
| Billing, tax and statutory records | Compliance with legal obligation | APP 3 — required or authorised by law |
| Security monitoring and fraud prevention | Legitimate use | APP 3, APP 11 — protection of information |
| Analytics to improve the website | Consent, via cookie settings | APP 6 — with consent |
| Marketing to business contacts | Consent, withdrawable at any time | APP 7, and the Spam Act 2003 (Cth) |
| Recruitment | Consent and pre-contractual steps | APP 3 — necessary for our functions |
Where we rely on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out. Where we rely on a legal obligation, we will tell you which one if you ask.
5. Who we share it with
We share personal data only with:
- Service providers who process it on our behalf under written contract — hosting, email delivery, customer relationship management, support ticketing, analytics and payment processing. The current list, with location and function, is at Sub-processors.
- Professional advisers — auditors, lawyers, insurers and bankers — where they need it and are bound by confidentiality.
- Authorities, where we are legally compelled. Our handling of those demands, including when we push back and when we notify you, is set out at Government and Law Enforcement Requests.
- An acquirer, in a merger, acquisition or asset sale, subject to this policy continuing to apply to the transferred data.
We do not sell personal data. We do not disclose it to data brokers, advertising networks, insurers, credit bureaux or employment-screening services. We do not trade it for anything of value.
6. Where it goes
We host in India and Australia by region, and use service providers in other countries as listed at Sub-processors. Cross-border transfers are made only to countries not restricted by the Central Government under section 16 of the DPDP Act, 2023, and, for personal information originating in Australia, only where Australian Privacy Principle 8 is satisfied — by contractual commitments requiring the recipient to handle the information consistently with the APPs, or with the individual's informed consent.
Because DECTIFY has no Australian entity, personal information provided to us by Australian individuals is disclosed to an overseas recipient — us, in India. What that means for you is explained at Australia Privacy and Data Protection.
7. How long we keep it
We keep personal data only as long as needed for the purpose it was collected for, or as long as a law requires. Specific periods are in the Data Retention Schedule. In summary: enquiry records for twenty-four (24) months from last contact; unsuccessful candidate records for twelve (12) months; account administration records for the contract term plus seven (7) years for statutory and tax purposes; security logs for one hundred and eighty (180) days as the CERT-In Directions require; website analytics as stated in the Cookie Policy.
8. How we protect it
We apply encryption in transit and at rest, role-based access control with least privilege, mandatory multi-factor authentication on all administrative accounts, network segregation, continuous vulnerability scanning, immutable audit logging, and an incident response process tested at least annually. Personnel receive security and privacy training on joining and annually thereafter. Our controls and certifications are described at Compliance and Security Updates.
No system is perfectly secure. If a breach occurs that is likely to cause harm, we will notify affected individuals and the relevant regulator — the Data Protection Board of India, and the Office of the Australian Information Commissioner — within the time each requires. Our CERT-In reporting obligation runs to six (6) hours.
9. Your rights
Wherever you are, you may ask us to:
- Confirm and access — tell you whether we hold data about you and give you a copy, together with a summary of processing and the identities of those we shared it with.
- Correct — fix data that is inaccurate, misleading, incomplete or out of date.
- Erase — delete data we no longer need, subject to legal retention requirements.
- Withdraw consent — as easily as it was given.
- Complain — to us first, and then to a regulator if you are not satisfied.
- Nominate — in India, appoint another person to exercise your rights on your behalf in the event of death or incapacity, under section 14 of the DPDP Act.
- Be anonymous or use a pseudonym — in Australia, where it is lawful and practicable, under Australian Privacy Principle 2.
To exercise a right, write to privacy@dectify.in. We respond within thirty (30) days in Australia and within the period prescribed under the DPDP Rules in India, and we will tell you if we need longer and why. We do not charge for a request, and we do not treat you less favourably for making one. We may need to verify your identity before acting.
If your request concerns footage or a biometric record captured by a customer's cameras, see section 10 — we will route it, but the customer decides.
10. Customer Data: what we do and do not do
When a customer operates DECTIFY systems, that customer determines what is captured, who is enrolled, who may search, and how long it is kept within the bounds we set. Our commitments in respect of that data are contractual and absolute:
- The customer owns it. We claim no ownership and acquire no independent right to use it.
- We do not sell it. Not to anyone, for any purpose, at any price.
- No shared database. We do not pool, federate or cross-match Customer Data between customers, and we do not build the infrastructure to do so.
- No training without opt-in. We do not use Customer Data, including biometric templates, to train or fine-tune models unless that customer has affirmatively enrolled in writing, per product.
- Every search is logged. Query, user, timestamp, stated purpose and result are recorded in an audit log the customer's administrator can read and we cannot edit.
- Bounded retention. Data is deleted on the schedule published at Data Retention Schedule unless the customer's own legal obligation requires otherwise.
- Access only to support. Our engineers access a customer tenancy only to resolve a reported issue, to address a security incident, or at the customer's request — and every such access is logged to that customer.
If you think you were recorded. Contact the organisation operating the cameras — its notice should be posted at the site. If you cannot identify it, write to privacy@dectify.in with the location, date and approximate time, and we will identify the responsible customer and pass your request on, or tell you that no DECTIFY system operates there. We cannot search a customer's footage on your behalf without that customer's instruction.
11. Automated decision-making
We do not make decisions producing legal or similarly significant effects about you by automated means. Our Products produce probabilistic Outputs for customers, and our Terms and Conditions prohibit customers from taking adverse action against an individual on an Output alone without human review. How we build, test and monitor those models is described at India AI and Responsible Technology and Australia AI and Responsible Technology.
12. Changes to this policy
We will post any change here and update the version and effective date at the top. Where a change materially affects how we handle your data, we will give notice by email or in-product before it takes effect. Prior versions are available from privacy@dectify.in on request.
13. Complaints
Raise a complaint with us at privacy@dectify.in or through Grievance Redressal. If you are not satisfied with our response, you may complain to the Data Protection Board of India, or, in Australia, to the Office of the Australian Information Commissioner at oaic.gov.au. You do not have to come to us first, but it is usually faster.
Contact
Questions about this document: legal@dectify.in
DECTIFY Technologies Pvt. Ltd., New Delhi, India