Privacy Policy
1. Who We Are
Infynext Global Tech Solutions LLP (“we”, “us”, or “our”) operates:
- cabyl.in — the Cabyl marketing and legal website.
- Cabyl Customer — a mobile app for cable TV subscribers (package ID:
com.infynextglobal.cabyl.user). - Cabyl Staff — a mobile app for cable operator staff and field agents (package ID:
com.infynextglobal.cabyl.staff).
Our Registered Address is: Registered Office: #43-20-26/C, Venkata Raju Nagar, Akkayyapalem, Visakhapatnam – 530016, Andhra Pradesh, India.
Our Corporate Address is: Corporate Office: 4th Floor, Thribhuvanam, State Bank of India Building, behind Hotel Diamond Pearl, Visakhapatnam, Andhra Pradesh 530016, India.
Contact for privacy matters: info@infynextglobal.com.
2. Roles and Responsibilities
The Digital Personal Data Protection Act 2023 (“DPDP Act”) distinguishes between a Data Fiduciary (who determines purposes and means of processing) and a Data Processor (who processes on the fiduciary’s behalf).
- Subscriber records — Customer names, phone numbers, addresses, connection details, payment records, and support tickets are entered and managed by the cable operator who subscribes to Cabyl. The cable operator is the Data Fiduciary for subscriber personal data. We process that data on the operator’s behalf as a Data Processor.
- Operator and staff accounts — We determine the purposes and means of processing personal data that belongs to cable operators, their agents, and super-admins. We are the Data Fiduciary for that data.
- Website visitors — We are the Data Fiduciary for any personal data collected when you visit cabyl.in.
3. What We Collect and Why
We describe data collection by audience. Read the section that applies to you.
A. Website Visitors (cabyl.in)
cabyl.in sets no cookies of its own and makes no backend API calls. We do not use analytics, advertising pixels, or tracking scripts.
The only data collection on the website occurs if you start a live chatwith us using the tawk.to widget. The chat widget does not load until you click the “Chat with us” button — that click is your affirmative consent. See Section 7 (Cookies) for details of what tawk.to collects.
B. Customers of Cable Operators (Cabyl Customer app)
Cabyl Customer is available only to subscribers whose cable operator has set up a Cabyl account. You cannot self-register; your cable operator creates your account using the phone number on your connection.
| Data | Why we collect it |
|---|---|
| Phone number | OTP-based login; sending SMS billing reminders via your operator’s settings. |
| Name, address, area / locality | Entered by your cable operator to identify your connection. |
| Alternate SMS phone | Outbound SMS reminders only, if your operator adds one. |
| Language preference (English / Telugu) | Delivering app content and notifications in your chosen language. |
| Connection & STB identifiers | Identifying your cable subscription. |
| Payment records (amount, method, date, notes) | Showing your payment history; supporting dispute resolution. |
| Support tickets and messages | Providing support through your cable operator. |
| Push notification token and device fingerprint | Delivering payment and billing push notifications to your device. The fingerprint is a device-generated installation ID — it is not linked to your name or phone in push payloads. |
| OTP record (phone + login code) | Verifying your identity at login. The code used for verification is stored as a bcrypt hash. A readable copy of the code is also held briefly in a separate database field so that authorised support staff can help you complete a login — it is never used for authentication, is removed the moment the code is used, and is cleared shortly after the code expires (codes expire within minutes). |
| Device locale | Read at app start to set the default display language. Not stored on our servers. |
Not collected by the Cabyl Customer app: location, contacts, camera, microphone, biometric data, external storage.
C. Cable Operators and Field Staff (Cabyl Staff app and web console)
| Data | Why we collect it |
|---|---|
| Operator: business name, owner name, phone, email, address, city, state, GSTIN | Operator account setup; billing and legal compliance. |
| Operator support phone / WhatsApp number | Shown to customers for support contact. |
| Operator UPI QR image (encodes UPI VPA) | Payment collection. Note: this image is currently served without authentication at a publicly accessible URL. Do not upload a QR image you wish to keep private. |
| Agent: name, phone, area, notes | Field agent management; assignment to connections. |
| Phone number (OTP login) | Authenticating operator and agent accounts. |
| IP address (logged on every mutating action) | Security audit trail. Stored in audit logs. |
| Audit log payloads (action type, IDs, original CSV filenames) | Accountability and fraud investigation. |
Not collected by the Cabyl Staff app: location, contacts, camera, microphone, biometric data, external storage. The staff app has no push notification implementation.
4. Third Parties That Receive Personal Data
We share personal data only with the recipients listed below. We do not sell personal data.
| Recipient | What they receive | Why |
|---|---|---|
| MSG91 (India) | Phone number (with country code), plaintext OTP code, and payment SMS variables: customer name, amount, plan name, valid-until date, agent name, connection number. | OTP authentication and billing SMS reminders. |
| Expo push service (exp.host, United States) | Expo push token, notification title and body (payment amount and date), deep-link data (customer ID, connection number). No name or phone number is included in push payloads. | Delivering push notifications to the Cabyl Customer app. |
| Google (Firebase / FCM) (United States) | FCM registration token as the Android transport layer under Expo Push. Firebase Core is initialised in both apps via the project configuration file — Google receives this initialisation signal even if you never interact with a push notification. | Android push delivery transport. |
| Our hosting provider (VPS operated for Infynext Global Tech Solutions LLP) | All data at rest: database records, uploaded files, server logs. | Infrastructure for running the Cabyl service. |
| tawk.to (website only, after you start a chat) | See Section 7 (Cookies and Live Chat). | Live chat support on cabyl.in. |
| WhatsApp / OS share sheet | When you tap the WhatsApp button, your operating system opens the WhatsApp app at the operator’s number — no customer data is transmitted by our apps. When you share a receipt using your device’s share function, your operating system sends the receipt image (containing your name, phone, and amount) to whichever app you pick. Both actions are entirely user-initiated. | User-initiated contact and receipt sharing. |
5. How Long We Keep Your Data
We describe what the system actually does. We do not make promises we cannot enforce.
| Data | What actually happens |
|---|---|
| Customer profile and connection records | Retained until we process a verified deletion request. There is no automatic deletion. A terminated connection sets the status to “terminated” but leaves the customer record and personal data in place. |
| Payment records | Retained until we process a verified deletion request. Payment records may also need to be kept for statutory or tax obligations even after a deletion request. |
| Support tickets and messages | Retained until we process a verified deletion request. Status transitions (open / resolved / closed) do not delete records. |
| OTP records | Marked as used after login. The readable support copy of the code is cleared when the code is used, and within about a minute of the code expiring. Expired OTP records are then deleted by an automatic retention process, normally within 24 hours of expiry. |
| Audit logs | Retained permanently by design — they are our record of account and billing actions for dispute resolution and fraud investigation. |
| Push notification outbox (delivery records) | Delivery records are retained; an automatic clean-up of completed records exists in our software but is not enabled in the current deployment. |
| Push notification tokens | Deactivated when you log out of the Cabyl Customer app. Permanently deleted when the Expo push service reports that the device is no longer registered. Inactive tokens may additionally be deleted after a set period once that clean-up is enabled in our configuration. |
| JWT session tokens | Logging out removes the token from your device. There is no server-side invalidation — the token remains cryptographically valid until its expiry time. |
| CSV import files | Deleted from disk immediately after the import is processed. In rare cases a failed delete may leave a file temporarily on the server. |
| UPI QR images | Deleted when replaced by a new image or when explicitly deleted. |
6. Your Rights
Under the Digital Personal Data Protection Act 2023, you have the right to:
- Access a summary of the personal data we hold about you.
- Correct inaccurate or outdated personal data.
- Request deletion of your personal data (subject to statutory retention obligations).
- Nominate another person to exercise your rights on your behalf in the event of your death or incapacity.
- Grieve — raise a complaint with our Grievance Officer, and escalate to the Data Protection Board of India if the response is unsatisfactory.
How to Submit a Request
Email us at info@infynextglobal.com or send a WhatsApp message from your registered phone number to +91 93923 67678. Please state your full name, registered phone number, and what you are requesting.
No in-app account deletion exists. Accounts are created by your cable operator, not self-registered. If you want your data removed, you can also ask your cable operator to submit the request on your behalf.
No self-service data export exists. On request, we will provide a written summary of the personal data categories we hold about you. A machine-readable export facility is not currently available.
We will acknowledge deletion and correction requests within 30 days.
Note for tawk.to live-chat data: if you start a chat on cabyl.in, tawk.to stores the conversation on its own servers. To request deletion of that chat record, contact tawk.to directly at tawk.to/privacy-policy.
7. Cookies and Live Chat
cabyl.in sets no cookies
The cabyl.in website does not set any first-party cookies, use local storage, or run any tracking scripts. No cookie banner is shown because there is nothing to consent to until you choose to start a live chat.
tawk.to live chat (only after you click “Chat with us”)
If you click the “Chat with us” button and confirm by clicking “Start chat”, the tawk.to live-chat widget is loaded. That affirmative click is your consent. The widget is not loaded and no tawk.to cookies are set before that click.
Once loaded, tawk.to Inc. (United States) receives and sets:
| Cookie / storage key | Type | Expiry | Purpose |
|---|---|---|---|
tawk_uuid_[propertyId] | Persistent cookie | ~6 months | Assigns a UUID to your browser for returning-visitor recognition. |
twk_idm_key | Session cookie | Browser session | Manages your live-chat connection. |
TawkConnectionTime | Session cookie | Browser session | Manages connection state across browser tabs. |
localStorage keys (e.g. twk_token_*) | Browser local storage | Persistent | Authentication and navigation state for the chat widget. |
tawk.to also collects your IP address, IP-derived geolocation (country, city, region), browser type, device details, page URL, and referrer. Chat transcripts — whatever you type — are stored on tawk.to’s servers in the United States. tawk.to’s sub-processors include Digital Ocean, AWS, Google Cloud Platform, and Cloudflare.
For full details, see tawk.to’s Privacy Policy.
To withdraw your consent, close the browser tab. The session-scoped consent record expires when your tab closes. The persistent tawk_uuid_* cookie can be deleted through your browser’s cookie settings.
8. Security Practices
We implement reasonable security practices and procedures as required by Rule 4 of the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”). Our current measures include:
- TLS encryption in transit for all connections between your device and our servers.
- OTP code hashing — login verification uses only a bcrypt hash of the one-time password. A short-lived readable copy exists solely for support-staff assistance and is cleared on use and shortly after expiry (see Section 3).
- JWT-based role tenancy — each session token carries a role and operator ID resolved server-side; one operator cannot access another’s data.
- Parameterised SQL queries — all database queries use prepared statements to prevent SQL injection.
- Audit logging — mutating actions by operators and agents are logged with the actor’s identity, IP address, and timestamp.
No security measure is perfect. If you discover a potential security issue, please contact us immediately at info@infynextglobal.com.
9. Children
Cabyl is not directed at children. Our apps require OTP login on a phone number; accounts are provisioned by cable operators for their adult subscribers and business staff. We do not knowingly collect personal data from children under 18. If you believe we have inadvertently received a child’s data, please contact us so we can remove it.
10. Cross-Border Data Transfers
Some of our service providers process data outside India:
- Expo push service — servers in the United States.
- Google (Firebase / FCM) — United States.
- tawk.to (website chat only, after consent) — United States, with sub-processors in multiple jurisdictions.
These transfers are made solely to provide the services described in this policy. We engage these providers under data processing terms consistent with applicable law.
11. Grievance Officer
Infynext Global Tech Solutions LLP has designated the following individual as Grievance Officer for privacy matters, as required by the DPDP Rules 2025 and the SPDI Rules:
| Name | K. Surya Narayana |
|---|---|
| Organisation | Infynext Global Tech Solutions LLP |
| Address | Registered Office: #43-20-26/C, Venkata Raju Nagar, Akkayyapalem, Visakhapatnam – 530016, Andhra Pradesh, India |
| info@infynextglobal.com |
We will acknowledge your complaint within 30 days of receipt and work to resolve it.
If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India at dpboard.gov.in.
You may request this Privacy Policy in Telugu or any other language listed in the Eighth Schedule of the Constitution of India by writing to us at info@infynextglobal.com.
12. Changes to This Policy
We may update this Privacy Policy when our data practices change, when the law requires it, or when new features are added. When we make material changes, we will update the effective date at the top of this page. We encourage you to review this policy periodically.
Continued use of Cabyl after a policy update does not constitute consent to new processing. Where a material change requires fresh consent under the DPDP Act, we will obtain it before processing begins.
13. Legal Framework
This Privacy Policy is governed by the laws of India, including:
- Digital Personal Data Protection Act, 2023 and DPDP Rules, 2025 (notified November 2025; substantive obligations enforceable from May 2027).
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (in force).
- Information Technology Act, 2000 (Section 43A).
Disputes arising from this policy are subject to the exclusive jurisdiction of the courts of Visakhapatnam, Andhra Pradesh, India.
14. Contact Us
For any questions about this Privacy Policy or our data practices, please contact:
Infynext Global Tech Solutions LLP
Registered Office: #43-20-26/C, Venkata Raju Nagar, Akkayyapalem, Visakhapatnam – 530016, Andhra Pradesh, India
Email: info@infynextglobal.com
WhatsApp: +91 93923 67678
Cabyl is a product of Infynext Global Tech Solutions LLP. The Cabyl name and TV mark are used under licence.