1. About This Privacy Notice
Welcome to Cector.
Cector — the Central Engine to Connect Operational Ecosystem — is a sector-focused professional networking and collaboration platform. It enables professionals to select a sector (such as Legal, Medical, Finance, Engineering or Fashion) and a sub-sector or domain within it, build a verified professional profile, connect with peers within and across sectors, collaborate on projects and workspaces, engage with professional communities, and communicate through a secure, encrypted messaging environment.
This Privacy Notice ("Notice") is issued by Cector Private Limited, a company incorporated in India and having its registered office at Sector R 29, T044-25-01, Amanora Park Town, Hadapsar, Pune City, Pune- 411028, Maharashtra, India ("Cector", "we", "us" or "our"). It explains how we collect, use, store, share and protect your personal data when you interact with the Cector platform, website, mobile application, or any related services (collectively, the "Services").
Please read this Notice carefully. By using the Services, you acknowledge that you have read and understood this Notice. This Notice does not govern the practices of third-party websites or services linked to or integrated with Cector; we encourage you to review their privacy practices separately.
2. Data Fiduciary
For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDPA”), Cector Private Limited acts as theData Fiduciary in respect of the personal data processed through the Cector platform and Services.
Our contact details are set out below:
| Detail | Particulars |
|---|---|
| Registered Name | Cector Private Limited |
| Registered Office | Sector R 29, T044-25-01, Amanora Park Town, Hadapsar, Pune City, Pune- 411028, Maharashtra, India |
| Country of Incorporation | India |
| Privacy / Data Queries | privacy@cector.in |
| Grievance Officer | Dr. Shubham Kadam, Founder |privacy@cector.in| +91 98348 88564 |
3. Personal Data We Collect
The personal data we collect varies depending on how you use Cector and which features you engage with.
3.1 Account and Identity Information
When you create or maintain a Cector account, we collect:
- Full name
- Mobile number
- Email address
- Profile photograph
- Date of birth
- Gender
- State and city of residence
We use this information to create and manage your account, authenticate you, communicate with you, and maintain the security and integrity of the platform.
3.2 Professional Profile Information
To enable professional networking and discovery, we collect:
- Sector, category and class (e.g. Legal → Cyber Law)
- Current and previous organisation(s)
- Designation and professional role
- Professional experience and skills
- Qualifications and languages
- Professional biography (stated vision/mission)
- Portfolio information, links and materials
This information is used to display your profile, enable you to be discovered by relevant professionals and communities, organise content by sector and category, and personalise your experience. Visibility to other users depends on the feature design and any privacy settings you select.
3.3 Device, Log and Technical Information
When you access Cector through our application or website, we automatically collect:
- Device identifier and type
- Operating system
- IP address
- Login history and session data
- Security logs
- Crash logs and error traces
- Push notification device token and platform
This information is used to maintain platform security, detect and prevent fraudulent or unauthorised activity, enable push notifications, diagnose technical issues, and maintain audit records. Retention periods are set out in Section 8.
3.4 Notification Metadata
When you receive in-platform notifications, we process notification type, payload, and read timestamps. This data is used solely to manage the delivery and status of notifications within the platform.
4. Verification Documents
Cector provides a voluntary credential verification feature that allows you to upload documents evidencing your stated qualifications, employment history and professional licences. If you choose not to use this feature, you may continue to use Cector without restriction, save that you will not receive a verification badge or status on your profile.
4.1 Categories of Documents
- Class 10 marksheet
- Class 12 marksheet
- Diploma certificate
- Graduation certificate
- Postgraduation certificate
- Training certificate
- Skill certificate
- Résumé or curriculum vitae
- Experience letter
- Certificate of achievement
- Freelance portfolio
- Medical registration certificate
- Bar Council enrolment
- Chartered Accountant cert
- Engineering licence / registration
- Other qualification / licence proof
4.2 Processing of Verification Documents
Documents you upload are processed in order to: review and confirm the qualification, employment history, licence or professional status you have represented on your profile; prevent false or misleading professional claims; maintain the trust and authenticity of the Cector professional community; and issue a verification badge or status where the review has been successfully completed.
Verification methodology:Verification review is carried out manually by Cector's internal team. As the platform scales, an AI-assisted review layer may be introduced to support efficiency, with human oversight retained for all consequential determinations. Any material change in the verification methodology will be reflected in an updated version of this Notice prior to implementation.
A verification badge displayed on your profile indicates only that the relevant document has been reviewed and the represented qualification or licence confirmed.The underlying document is not publicly accessible and is not disclosed to other users of the platform.
You may request the deletion of a previously uploaded verification document at any time by contacting us. Retention periods applicable to verification documents are set out in Section 8.
5. Content You Create, Post and Share
5.1 Sector Feed
When you use the Cector feed, we process the posts, images, videos, documents, polls, comments and reactions that you publish or share, together with information about how other users interact with that content. Content you publish on the feed may be visible to other Cector users in accordance with the audience and visibility settings applicable to the relevant feature. You are responsible for ensuring that any personal data relating to a third party that you include in published content is shared in compliance with applicable law.
5.2 Collaboration and Project Workspaces
When you create, join or participate in a project or workspace, we process project names and descriptions, team requirements, project-related messages, shared files and workspace documents, task information, and data regarding the activities of participants within the workspace.
Information shared within a project or workspace is accessible to the other participants in that space. Files and documents shared within a workspace are protected by end-to-end encryption, as described in Section 7. We strongly recommend that you review the membership and intended audience of a workspace before sharing confidential, commercially sensitive or personal information.
5.3 Chat and Messaging
When a team is formed through the Cector sector collaborator feature, a group chat workspace is automatically activated, enabling team members to communicate, discuss their work, and share files and voice content within a protected environment.
All communications through Cector — including one-to-one chats, team group chats, voice content, and all files and images shared within them — are protected by end-to-end encryption. Messages and content are encrypted on-device before upload using theAES-256-GCM / XChaCha20-Poly1305 algorithm. The backend stores only ciphertext; Cector does not hold the technical ability to access, read or reproduce the content of any such communications.
Group encryption keys rotate whenever a member is added to or removed from a team, ensuring that removed members cannot decrypt subsequent messages or files.
The recipient(s) of your messages can access the content you send them. In group chats, content is accessible to all members of that team group.
6. Legal Basis for Processing
Cector processes your personal data on one or more of the following grounds, as applicable under the DPDPA:
- Consent— for optional features such as uploading verification documents, publishing to the feed, or using collaboration and chat features. You may withdraw consent at any time; withdrawal does not affect the lawfulness of processing carried out prior to withdrawal. Following withdrawal, Cector may be unable to provide the relevant feature.
- Voluntarily provided data for a specified purpose(Section 7(a), DPDPA) — where you voluntarily provide personal data, such as account and profile information, for the purpose of using the Services, and have not indicated that you do not consent to its use for that purpose.
- Legitimate uses and legal obligations— including maintaining security logs, responding to lawful requests from competent authorities, and preventing fraud, impersonation or other conduct harmful to the platform or its users.
Where Cector introduces AI-assisted or algorithmic features — including recommendations, ranking, matching or discovery tools — this Notice will be updated to describe that processing and any applicable Data Principal rights before such features are deployed.
7. Security of Your Personal Data
We implement and maintain appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, disclosure or destruction, consistent with Section 8(5) of the DPDPA. These measures include:
7.1 Encryption
- Data in transit: All API traffic is transmitted over HTTPS (TLS). Calls to the push notification provider (Expo) and all vendor communications are made over HTTPS.
- Data at rest: Passwords are stored as bcrypt hashes. OTP codes and refresh tokens are stored as HMAC-SHA256 hashes. Database and object storage encryption at rest is managed by the respective infrastructure providers.
- End-to-end encryption (E2EE): All chat messages, voice content, and workspace documents and files are encrypted on-device before upload using AES-256-GCM / XChaCha20-Poly1305. The backend stores only ciphertext and cannot access the content of communications. Group encryption keys rotate on every membership change, ensuring that removed members cannot access subsequent communications.
- Access tokens: Bearer JWT access tokens are short-lived (15 minutes). Refresh tokens expire after 30 days and are individually revocable.
7.2 Access Controls
- Role-based access controls are enforced at the application layer.
- Chat and team content is accessible only to verified team members.
- Owner-only operations (role management, team invitations) are enforced in code.
- Verification and collaboration file access is tied to document ownership or explicit access rules.
Whilst we maintain these safeguards, no method of electronic transmission or storage is entirely secure. In the event of a personal data breach that is likely to cause harm to you, we will notify you and report the breach to the Data Protection Board of India as required under Section 8(6) of the DPDPA.
8. Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected, or as required by applicable law, whichever is longer. As Cector is an intermediary within the meaning of the Information Technology Act, 2000, and is subject to Rule 4(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, certain categories of personal data must be retained for a minimum period of 180 days following the de-registration or cancellation of a user account, for the purposes of lawful investigation and law enforcement. The retention periods below reflect this obligation.
| Category of Personal Data | Retention Period |
|---|---|
| Account and personal information | Until account deletion, and thereafter for a minimum of 180 days in accordance with Rule 4(2) of the IT Rules, 2021 |
| Professional profile information | Until account deletion, and thereafter for a minimum of 180 days in accordance with Rule 4(2) of the IT Rules, 2021 |
| Verification documents | Until account deletion (or upon earlier request for deletion of a specific document), and thereafter for a minimum of 180 days in accordance with Rule 4(2) of the IT Rules, 2021 |
| OTP records | Automatically expired after 300 seconds (5 minutes); no longer retained thereafter |
| Access tokens (JWT) | Stateless; expire 15 minutes from issuance |
| Refresh tokens | 30 days from issuance; individually revocable |
| Chat, voice and collaboration content | Until deleted by the user or account deletion, and thereafter for a minimum of 180 days in accordance with Rule 4(2) of the IT Rules, 2021 |
| Notification metadata | Until cleared by administrative process or account deletion |
| Device tokens | Until stale token detected (on failed push delivery) or account deletion |
| Security and application logs | 90 days |
| Backups | 90 days |
Upon the expiry of the applicable retention period, we will delete or irreversibly anonymise your personal data. Anonymised data that no longer identifies you or is capable of identifying you is not personal data and is not subject to this Notice.
9. Disclosure and Sharing of Personal Data
We do not sell your personal data, and we do not share it for commercial purposes.
We engage the following categories of service providers who process personal data strictly to the extent necessary to deliver the Services, and under contractual obligations of confidentiality and data protection:
| Vendor / Service | Function | Personal Data Involved |
|---|---|---|
| Amazon Web Services — S3 (Mumbai region, ap-south-1) | Object storage for documents and media | Verification documents, profile photographs, shared files, images, voice content |
| PostgreSQL (application database) | Primary relational database | Account data, profile information, collaboration data, token hashes, notification metadata, chat metadata |
| Render | Application hosting and runtime | All personal data processed by the live application; runtime logs |
| Resend / SendGrid | Transactional email delivery | Name, email address, content of system-generated emails |
| MSG91 / Twilio | SMS and OTP delivery | Mobile number, OTP codes |
| Expo Push API | Mobile push notifications | Device token, notification title, body and data payload |
| Google Maps API | Location-based features | Location data, where applicable |
| Grafana Loki (optional) | Application observability and log monitoring | Application logs, error traces, operational metadata (no message content or personal documents) |
| AWS Backup | Automated backup services | Backup copies of database and stored files |
In addition to the above, we may disclose personal data where required or permitted by applicable law, in response to a valid legal process issued by a competent authority, or where necessary to protect the rights, property or safety of Cector, its users or the public.
10. Cross-Border Transfer of Personal Data
All personal data collected and processed through Cector is stored and processed exclusively within India. Our core infrastructure — including the application database, object storage, and application hosting — is located in India, on the AWS Mumbai region (ap-south-1). All service providers engaged by Cector process personal data within India.
Cector does not transfer personal data outside India. In the event that any cross-border transfer becomes necessary in the future, it will be carried out only in accordance with Section 16 of the DPDPA and any applicable rules or directions issued by the Central Government, and this Notice will be updated accordingly prior to such transfer taking place.
11. Cookies and Similar Technologies
Cector does not currently deploy cookies, analytics tools or similar tracking technologies on its platform or website. Should we elect to deploy such technologies in the future, we will update this Notice and implement any required consent mechanism prior to their use.
12. Minimum Age Requirement
Cector is a professional networking and collaboration platform intended exclusively for individuals who have attained the age of 18 years. Registration is not available to anyone below this age, and we do not knowingly collect or process the personal data of individuals under 18 years of age.
If we become aware that an account has been created by, or personal data has been collected from, an individual below the age of 18, we will terminate that account and delete the associated personal data without delay. If you have reason to believe that a person below the age of 18 has registered on Cector, please notify us immediately using the contact details in Section 16.
13. International Users
Cector is accessible to users located outside India. We do not sell personal data and we do not share it with third parties for commercial purposes, irrespective of where you are located. Personal data collected from international users is processed in accordance with the DPDPA and, to the extent applicable, the data protection laws of the jurisdiction in which you are located.
Users located in the European Economic Area, the United Kingdom or the State of California should note that, as Cector's global user base expands, jurisdiction-specific compliance measures — including lawful basis documentation, designated representatives and opt-out mechanisms — will be implemented and reflected in a supplementary addendum to this Notice.
14. Your Rights as a Data Principal
As a Data Principal under the DPDPA, you have the following rights in relation to your personal data:
- Right to access information — to obtain a summary of the personal data held about you and the processing activities undertaken in relation to it.
- Right to correction and erasure — to have inaccurate or incomplete personal data corrected, and to have personal data erased where it is no longer necessary for the purposes for which it was collected, subject to any overriding legal retention obligation.
- Right to withdraw consent — to withdraw your consent to any processing based on consent, at any time and as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal.
- Right to grievance redressal — to have any grievance relating to the processing of your personal data addressed by our Grievance Officer and, if unresolved to your satisfaction, to escalate the complaint to the Data Protection Board of India.
- Right of nomination — to nominate another individual to exercise your rights under the DPDPA on your behalf in the event of your death or incapacity.
To exercise any of the above rights, please contact us atprivacy@cector.in. We will respond within the period prescribed under applicable law.
15. Changes to This Privacy Notice
We review this Notice periodically and may revise it to reflect changes in our processing activities, our Services or applicable law. Where any revision constitutes a material change to how we process your personal data, we will notify you through the platform, by email, or by such other appropriate means, prior to the change taking effect. The 'Last Updated' date at the head of this Notice records the date of the most recent revision. Your continued use of Cector following notification of a material change constitutes your acknowledgment of the revised Notice.
16. Grievance Redressal and Contact
If you have a complaint, concern or query regarding the processing of your personal data, or wish to exercise any right described in Section 14, please contact our Grievance Officer:
| Grievance Officer | Contact Details |
|---|---|
| Name and Designation | Dr. Shubham Kadam, Founder, Cector Private Limited |
| Registered Address | Sector R 29, T044-25-01, Amanora Park Town, Hadapsar, Pune City, Pune- 411028, Maharashtra, India |
| privacy@cector.in | |
| Phone | +91 98348 88564 |
We will acknowledge your grievance and endeavour to resolve it within the period prescribed by the DPDPA and rules made thereunder. If you remain dissatisfied with our response, you may lodge a complaint with the Data Protection Board of India once it is constituted and operational.