Privacy Policy This details how SifrSec collects, uses, stores, shares, and protects personal information when you use our website or contact us. Effective Date: 27 September, 2026 Last Updated: 27 September, 2026 1. Executive Overview & Brand Identity Entity Name: SifrSec (sifrsec.com) Legal Status: Formally registered Micro Enterprise under the Ministry of Micro, Small and Medium Enterprises (MSME), Government of India. Core Tagline: "Deciphering Cybersecurity" Primary Mission: To bridge the gap between academic theory and real-world security engineering by raising the standard of cybersecurity awareness, practical technical training, and open research. 2. What We Do (Core Operational Pillars) SifrSec operates across three primary domains: High-Impact Technical Training & Workshops: Delivering live, hands-on cybersecurity seminars for academic institutions and organizations. Training focus: Essential digital hygiene, threat mechanics, phishing simulations, hardware attack vectors (BadUSB, microcontrollers), mobile security (malicious APK analysis), and practical defense tactics. Issuing official MSME-backed Certificates of Attendance and Merit. Educational Resources & Digital Academy: Developing structured, self-paced roadmaps, lab walkthroughs, and practical security guides. Transitioning toward scalable digital learning platforms and recorded educational tracks. Open-Source Security & Independent Threat Research: Building and maintaining community-driven offensive and defensive tools. Investigating emerging threat vectors, documenting architectural flaws, and publishing independent vulnerability research (e.g., CVE disclosures coordinated via CERT/CC). 3. Data Collection & Privacy Framework SifrSec adheres to the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000 of India. A. Data Collected Workshop Attendees & Form Applicants: Full Name, Email Address, Phone Number, College/University Name, Academic Year, and Department/Branch, and any other necessary event-related details. Resource Downloads: Email addresses entered manually by users requesting specific guides, code repositories, or tools. Transaction/Payment Information: Handled externally by third-party processing partners (e.g., Razorpay). SifrSec does not collect or store raw financial credentials or credit card details. Automated Data: SifrSec does not run invasive tracking cookies or collect background telemetry on its web platforms. While we don't use tracking/advertising cookies, standard technical server logs (such as IP addresses and access timestamps necessary for infrastructure security and rate limiting) are handled by infrastructure/hosting providers. B. Purpose & Use of Data Collected data is strictly used for: Managing workshop registrations and verifying student credentials. Generating and distributing digital Certificates of Attendance/Merit. Delivering requested educational resources and security advisories. Sending promotional communications and marketing updates regarding upcoming SifrSec initiatives (with opt-out mechanisms). Coordinating administrative logistics and verification rosters with partners and host institutions. We may share limited personal information with website hosting, email, communications, security, infrastructure, and logging providers C. Third-Party Integrations & Infrastructure Google Forms / Workspace: Registration intake and structured data collection. Razorpay: Online fee collection and payment gateway processing. Host Institutions: Sharing attendee lists (Name, Branch, Year) with college organizers for administrative and verification compliance. Support Contact: support@sifrsec.com D. Children's Privacy The website is intended for business and professional audiences. It is not directed to children, and we do not knowingly collect personal information from children. If you believe a child has provided information to us, contact us so we can take appropriate steps. E. Feedback and suggestions If you provide feedback, suggestions, ideas, feature requests, security comments, or other input, you grant SifrSec a worldwide, royalty-free, perpetual, irrevocable right to use, modify, incorporate, and commercialize that feedback without restriction or compensation. Do not include confidential information unless a separate agreement covers it. F. Your rights Depending on applicable law, you may have the right to access, correct, or request deletion of your personal information; withdraw consent; object to or restrict certain processing; request information about our use of your information; or raise a privacy complaint. To exercise a right, email support@sifrsec.com. We may need to verify your identity, and some requests may be limited by legal, security, contractual, or technical requirements. 4. Third-party links The website may link to third-party websites, repositories, social media platforms, or services. We are not responsible for their privacy practices, security, or content. Review their privacy policies before using them. 5. Changes to this policy We may update this policy from time to time. We will post the updated version on this page and revise the “Last updated” date. Your continued use of the website after a change is posted means you acknowledge the updated policy. 6. Contact us For privacy questions or data requests, email support@sifrsec.com.