Privacy Policy
Last Updated: February 7, 2025
1. Introduction
This Privacy Policy describes how LAB SYSTEMS (INDIA) PVT LTD (“we,” “our,” or “us”), operating CrypTech Today at https://cryptechtoday.com, collects, uses, discloses, and protects your personal information.
Data Controller: LAB SYSTEMS (INDIA) PVT LTD
Registered Office: B/27 Dharma Nagar, Kurla East, Mumbai, Maharashtra 400029, India
Contact Email: [email protected]
Compliance: This policy complies with India’s Digital Personal Data Protection Act 2023 (DPDPA), EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA/CPRA), and other applicable data protection laws.
By using our website, you explicitly consent to the data practices described in this policy. We only collect personal data with your informed, opt-in consent.
2. Key Definitions
- Personal Data/Information: Any information relating to an identified or identifiable individual (name, email, IP address, device identifiers)
- Processing: Any operation performed on personal data (collection, storage, use, disclosure, deletion)
- Data Controller: LAB SYSTEMS (INDIA) PVT LTD – determines purposes and means of processing
- Data Processor: Third parties who process data on our behalf (hosting providers, analytics services)
- Cookies: Small text files stored on your device to remember preferences and track usage
- Consent: Explicit, informed, freely given agreement to data processing (opt-in only, never pre-checked boxes)
3. Information We Collect
3.1 Information You Provide Directly (User-Submitted Data)
| Category | Data Collected | Purpose |
|---|---|---|
| Newsletter Subscriptions | Email address, name (optional) | Send crypto news updates, market analysis |
| User Accounts | Name, email, username, profile picture (via social login) | Account management, personalized experience |
| Comments | Name, email, website URL (optional), comment text | Facilitate discussions, moderation |
| Contact Forms | Name, email, subject, message content | Respond to inquiries, customer support |
3.2 Information Collected Automatically
- Technical Data: IP address, browser type/version, operating system, device type, screen resolution
- Usage Data: Pages viewed, time on site, clickstream patterns, referral sources, exit pages
- Location Data: Approximate geographic location (country/city level from IP address)
- Cookies & Tracking: Session cookies, analytics cookies, advertising cookies (see Section 6)
3.3 Information from Third-Party Sources
- Social Login Providers: When you log in via Google/Facebook (JNews Social Login), we receive: profile name, email address, profile picture
- Embedded Content: YouTube videos, Twitter feeds, other third-party embeds may collect data per their privacy policies
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
| Processing Activity | Legal Basis (GDPR/DPDPA) |
|---|---|
| Newsletter subscriptions | Explicit Consent (opt-in checkbox) |
| User account creation and login | Contract Performance (necessary to provide service) |
| Analytics and website improvement | Legitimate Interest + Consent (via cookie banner) |
| Advertising and personalization | Consent (opt-in via WP Consent API) |
| Fraud prevention and security | Legitimate Interest (protect users and our systems) |
| Legal compliance (tax, law enforcement) | Legal Obligation (Indian law, court orders) |
⚠️ Important (DPDPA Compliance): Consent is always opt-in. We never use pre-checked boxes or assume consent. You can withdraw consent at any time without penalty.
5. How We Use Your Information
We use collected data for these purposes:
- ✉️ Send newsletters: Crypto news, market updates, analysis (consent-based)
- 👤 Manage accounts: User registration, login, profile management
- 💬 Enable comments: Facilitate discussions, moderate spam
- 📊 Analyze traffic: Understand user behavior, improve content (Google Analytics)
- 🎯 Personalized ads: Display relevant advertisements (JNews Ads, Google Site Kit – consent required)
- 🛡️ Security: Prevent fraud, detect abuse, protect against cyber threats
- 📧 Customer support: Respond to inquiries, resolve issues
- ⚖️ Legal compliance: Comply with tax laws, court orders, law enforcement requests
6. Cookies and Tracking Technologies
We use cookies and similar technologies. You can control cookie preferences via our Cookie Policy and consent banner (powered by WP Consent API).
Cookie Categories:
| Cookie Type | Purpose | Consent Required? | Examples |
|---|---|---|---|
| Essential | Login sessions, security, core functionality | ❌ No (strictly necessary) | WordPress login, CSRF protection |
| Analytics | Track page views, user behavior | ✅ Yes (EU/India) | Google Analytics (_ga, _gid) |
| Advertising | Personalized ads, retargeting | ✅ Yes (required) | JNews Ads, Google Site Kit |
| Social Media | Social login, embedded content | ✅ Yes (on interaction) | Facebook, Google OAuth, YouTube embeds |
How to Manage Cookies:
- Use our cookie consent banner (appears on first visit)
- Adjust browser settings: aboutcookies.org
- Opt out of Google Analytics: Google Analytics Opt-out
⚠️ Note: Blocking essential cookies may prevent core website functionality (login, comments).
7. Information Sharing and Disclosure
🚫 We do NOT sell your personal data to third parties.
We may share data with:
7.1 Service Providers (Data Processors)
| Service | Provider | Purpose | Data Location |
|---|---|---|---|
| Hosting/CDN | AirLift CDN | Website hosting, content delivery | Global (incl. international servers) |
| Analytics | Google Analytics | Traffic analysis, user behavior | USA (Google data centers) |
| Email Services | Newsletter plugin, Mailchimp (inactive) | Newsletter delivery | USA/EU |
| Advertising | JNews Ads, Google Site Kit | Ad serving, revenue optimization | USA/Global |
| Social Login | Google, Facebook | OAuth authentication | USA (per provider policies) |
| Embedded Content | YouTube, Twitter/X | Video hosting, social feeds | USA/Global |
Data Processing Agreements: All processors are bound by contractual obligations to protect your data and comply with GDPR/DPDPA standards.
7.2 Legal Disclosures
We may disclose personal data when required by law or to:
- Comply with legal processes (court orders, subpoenas)
- Cooperate with law enforcement or regulatory authorities
- Protect our rights, property, or safety
- Prevent fraud, abuse, or security threats
- Enforce our Terms of Service
7.3 Business Transfers
In case of merger, acquisition, bankruptcy, or sale of assets, user data may be transferred to the acquiring entity. You will receive 30 days’ advance notice via email and prominent website notice.
8. International Data Transfers
⚠️ Important Notice: Some third-party services transfer data outside India/EU:
- Google Analytics: Data processed in USA (Google LLC data centers)
- AirLift CDN: Global CDN network with international servers
- Social Login Providers: Facebook (USA), Google (USA)
- YouTube/Twitter Embeds: Data sent to USA servers
Safeguards for International Transfers:
- ✅ EU Standard Contractual Clauses (SCCs): GDPR-approved contracts with US processors
- ✅ DPDPA Compliance: Explicit user consent for cross-border transfers
- ✅ Adequacy Decisions: Where applicable (e.g., EU-US Data Privacy Framework participants)
- ✅ Privacy Shield Framework: US processors committed to EU privacy standards
Your Rights: You may object to international transfers. Contact us at [email protected] to discuss alternatives (though this may limit service functionality).
9. Data Retention
We retain personal data only as long as necessary for the purposes described or as required by law:
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Newsletter emails | Until unsubscribe + 90 days | Automated purge after grace period |
| User accounts | While active + 1 year post-deletion request | Manual deletion by admins, logs retained 30 days |
| Comments | Indefinitely (public content) or upon request | Permanent deletion from database |
| Google Analytics data | 26 months, then anonymized | Auto-deletion by Google, no PII after 26 mo |
| Server logs (IP addresses) | 90 days (security/fraud prevention) | Automated rotation and deletion |
| Contact form inquiries | 2 years or until resolved | Manual deletion after resolution + archive period |
| Financial records (tax compliance) | 7 years (Indian law requirement) | Secure archival, then permanent deletion |
Deletion Process: Data is securely erased (overwritten, not just marked for deletion) after retention periods, except where legally required to retain.
10. Your Privacy Rights
You have the following rights under GDPR, DPDPA, and CCPA:
| Right | Description | How to Exercise |
|---|---|---|
| Right to Access (GDPR Art. 15, DPDPA) |
Request a copy of your personal data we hold | Email [email protected] with “Data Access Request” |
| Right to Rectification (GDPR Art. 16, DPDPA) |
Correct inaccurate or incomplete data | Email us or update via account settings |
| Right to Erasure (“Right to be Forgotten”) (GDPR Art. 17, DPDPA) |
Request deletion of your personal data | Email “Deletion Request” — processed within 30 days |
| Right to Withdraw Consent (GDPR Art. 7(3), DPDPA) |
Revoke previously given consent | Unsubscribe links, cookie settings, or email us |
| Right to Data Portability (GDPR Art. 20) |
Receive your data in machine-readable format (CSV/JSON) | Email “Data Export Request” |
| Right to Restrict Processing (GDPR Art. 18) |
Limit how we use your data (while dispute resolved) | Email with specific restriction request |
| Right to Object (GDPR Art. 21) |
Object to processing based on legitimate interest | Email “Processing Objection” |
| Right to Not Be Subject to Automated Decisions (GDPR Art. 22) |
Opt out of automated profiling/decision-making | Email to disable automated processing |
| Right to Know (CCPA) | Know what data we collect, use, share | This policy + email for specifics |
| Right to Opt-Out of Sale (CCPA) | We don’t sell data — N/A | Not applicable (we don’t sell user data) |
| Right to Lodge Complaint (GDPR Art. 77, DPDPA) |
File complaint with data protection authority | India: Data Protection Board (when established) EU: Your national DPA (e.g., ICO UK) US: FTC or state AG |
How to Exercise Your Rights:
- Email us: [email protected] with subject line indicating your request (e.g., “GDPR Data Access Request”)
- Include: Your full name, email address, description of request
- Verification: We may ask for proof of identity (government ID) to prevent unauthorized access
- Response Time: Within 30 days (GDPR/DPDPA) or 45 days (CCPA), extendable by 30 days if complex
⚠️ No Discrimination: We will not discriminate against you for exercising privacy rights (CCPA requirement).
11. Data Security
We implement industry-standard security measures to protect your data:
- 🔒 SSL/TLS Encryption: All data transmitted over HTTPS (encrypted connections)
- 🛡️ Secure Hosting: Server-level firewalls, DDoS protection (AirLift CDN)
- 🔑 Access Controls: Limited admin access, role-based permissions
- 🔐 Password Protection: Hashed passwords (bcrypt), no plaintext storage
- 📊 Regular Backups: Automated backups for disaster recovery
- 🔍 Security Monitoring: Real-time threat detection, malware scanning
- 🚨 Incident Response: Breach notification within 72 hours (GDPR/DPDPA requirement)
⚠️ Limitation: No method of internet transmission is 100% secure. We cannot guarantee absolute security but employ best practices to minimize risks.
Data Breach Notification:
In the event of a data breach affecting your personal information:
- We will notify you within 72 hours (GDPR/DPDPA requirement)
- Notification will describe: nature of breach, data affected, remediation steps, contact information
- We will notify relevant data protection authorities as required by law
12. Children’s Privacy
Our website is NOT intended for individuals under 18 years of age.
- We do not knowingly collect data from children under 18 (India DPDPA), 16 (EU GDPR), or 13 (US COPPA)
- Cryptocurrency content is intended for adults only
- If we discover we have collected data from a minor, we will delete it immediately
- Parents/Guardians: If you believe your child provided us with personal data, contact us immediately at [email protected]
13. Third-Party Links and Services
Our website contains links to external websites and embedded third-party content:
- External Links: We are not responsible for privacy practices of linked sites (cryptocurrency exchanges, news sources, etc.)
- Embedded Content: YouTube videos, Twitter feeds, social media buttons may track you per their privacy policies
- Your Responsibility: Review privacy policies of third-party sites before providing data
Notable Third-Party Policies:
- Google Privacy Policy: https://policies.google.com/privacy
- Facebook Privacy Policy: https://www.facebook.com/privacy/policy/
- YouTube Privacy: https://www.youtube.com/howyoutubeworks/our-commitments/protecting-user-data/
14. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect:
- Changes in our data practices
- New legal requirements (DPDPA rules, GDPR updates)
- New features or services
- User feedback and best practices
How You’ll Be Notified:
- 📧 Email Notification: For material changes affecting your rights (to newsletter subscribers)
- 🔔 Website Banner: Prominent notice on homepage for 30 days
- 📅 “Last Updated” Date: Always displayed at top of this policy
Your Acceptance: Continued use of the website after changes constitutes acceptance. If you disagree, please discontinue use and contact us to delete your data.
15. Contact Us
For privacy-related questions, requests, or complaints:
Data Controller:
LAB SYSTEMS (INDIA) PVT LTD
B/27 Dharma Nagar, Kurla East
Mumbai, Maharashtra 400029, India
Email: [email protected]
Subject Line: “Privacy Inquiry” or specific request type (e.g., “GDPR Data Access”)
Response Time: We aim to respond within 5 business days for general inquiries, 30 days for formal rights requests.
16. Regulatory Authorities
You have the right to lodge a complaint with data protection authorities:
🇮🇳 India (DPDPA):
- Data Protection Board of India (to be established under DPDPA 2023)
- Until then: Ministry of Electronics and Information Technology (MeitY)
- Website: https://www.meity.gov.in/
🇪🇺 European Union (GDPR):
- Contact your national Data Protection Authority (DPA)
- Find your DPA: https://edpb.europa.eu/about-edpb/about-edpb/members_en
- Example (UK): Information Commissioner’s Office (ICO) – https://ico.org.uk/
🇺🇸 United States:
- California: California Attorney General – https://oag.ca.gov/privacy
- Federal: Federal Trade Commission (FTC) – https://www.ftc.gov/
✅ Your privacy matters to us. We are committed to transparency, security, and respecting your data rights under all applicable laws.
Last reviewed: February 7, 2025