CFA Privacy Centre
This Policy explains what personal data CFA collects, why we use it, when it may be shared, how long it is retained and the choices available to you.
Section 01
This Privacy Policy (“Policy”) applies to Consumer Fraud Awareness (“CFA”, “we”, “us” or “our”) and explains how we process personal data when you access or use cfa.consumerfraudawareness.com, related CFA websites, accounts, forms, communications, tools and services (together, the “Platform”).
This Policy applies to consumers, reviewers, complainants, visitors, registered users, business representatives, subscribers, applicants, professional contacts and other persons whose personal data is processed through the Platform.
For personal data collected directly through CFA, CFA acts as the entity determining why and how that data is processed, except where a notice identifies another entity or where we process information solely on behalf of a customer or service provider.
This Policy should be read together with our Terms of Use, Cookie Policy, Content Policy and Community Guidelines.
Section 02
| Platform | Consumer Fraud Awareness (CFA) |
| Website | cfa.example |
| Controller | CFA Platform Operations |
| Contact | privacy@consumerfaudawareness.com |
| Data Region | India (primary) |
Section 03
We may receive personal data:
Where another person gives us your personal data, we may process it to operate a review, complaint, business response, dispute or legal process. We may contact you to verify, notify, obtain clarification or offer an opportunity to respond.
Section 04
We may process personal data to:
Section 05
CFA processes personal data for lawful purposes connected with the Platform. Depending on the context and applicable law, processing may be based on:
Where we rely on consent, you may withdraw it using the relevant account control, unsubscribe link, cookie setting or privacy request. Withdrawal does not affect processing already completed lawfully and may prevent us from providing a feature that requires the data.
We may provide a separate just-in-time notice where a feature collects information for a purpose not adequately described in this Policy.
Section 06
CFA is designed to publish certain content. A review, rating, complaint, username, profile image, business response, date, status, category and related information may be visible publicly and may appear in search-engine results.
Do not place your telephone number, personal email, residential address, financial details, identification number, medical information or other unnecessary private information in a public text field. Redact unrelated personal data from documents before uploading them
Supporting evidence is not ordinarily published merely because it is uploaded. It may be reviewed by authorised CFA personnel and, where reasonably necessary for the selected process, shared with the relevant business, professional adviser, service provider or authority.
CFA may redact, anonymise, restrict or remove personal information from public content to protect privacy, comply with law or enforce Platform policies. Removal from public view does not always require immediate deletion from restricted records where retention remains reasonably necessary.
Section 07
We may share personal data in the following circumstances:
7.1 With the public
Content submitted for public posting may be available to visitors, search engines, businesses and other users as described above.
7.2 With the relevant business or user
Information reasonably required to verify, respond to, mediate or resolve a complaint may be shared with the person or business involved. We aim to avoid sharing unrelated private information.
7.3 With service providers
We may use vendors for hosting, cloud storage, email, communications, analytics, customer support, content moderation, security, identity verification, payments, document handling and professional services. They may process data only for authorised purposes and subject to appropriate obligations.
7.4 With professional advisers and authorities
We may disclose information to lawyers, auditors, insurers, regulators, courts, law-enforcement agencies, consumer authorities or government bodies where reasonably necessary, legally permitted or required.
7.5 For safety and legal claims
We may share information where we reasonably believe it is necessary to prevent fraud, investigate a security incident, protect rights or safety, enforce agreements, recover amounts due or establish, exercise or defend legal claims.
7.6 Business transfers
Information may be transferred in connection with a merger, acquisition, restructuring, financing, sale of assets or transfer of Platform operations, subject to appropriate safeguards.
CFA does not sell personal data for money. We do not permit service providers to use CFA personal data for their own unrelated advertising purposes.
Section 08
CFA and authorised providers may use cookies, pixels, local storage, SDKs and similar technologies to:
Essential technologies may operate because they are necessary for the Platform. Non-essential analytics, personalisation or advertising technologies will be managed through available consent controls where required.
You may change cookie choices through CFA’s cookie controls or browser settings. Blocking essential cookies may affect account access or Platform functionality. More information is available in our Cookie Policy.
Section 09
We may send service-related messages such as account confirmations, password resets, verification requests, complaint updates, billing notices, security alerts and policy changes. These are not promotional communications and may continue while necessary to provide or secure your account.
Where permitted, we may send fraud alerts, newsletters, educational content, CFA updates, business information or promotional messages. You may opt out using the unsubscribe link, communication setting or contact details below.
Opting out of marketing does not prevent essential transactional or legal communications. We may retain a suppression record to ensure your preference is respected.
Section 10
Payments may be processed by third-party payment service providers. CFA generally receives transaction identifiers, payment status, billing details and limited card information, such as card type and last digits, rather than complete card credentials.
Payment providers process information under their own privacy notices and security standards. CFA may use transaction data for service activation, invoices, refunds, accounting, taxation, fraud prevention and payment disputes.
Section 11
CFA retains personal data only for as long as reasonably necessary for the purpose for which it was collected, including Platform operation, authenticity, safety, legal, accounting and dispute requirements.
| Record type | General retention approach |
|---|---|
| Account and profile records | For the active account period and a reasonable period after closure for security, recovery, dispute and legal purposes. |
| Published reviews and complaints | While relevant to the Platform’s transparency purpose, unless removed, anonymised or retention is no longer lawful or necessary. |
| Evidence and verification documents | For the verification, complaint, moderation or dispute period and a limited period afterward based on risk and legal requirements. |
| Payment, invoice and tax records | For the period required by applicable accounting, taxation and financial laws. |
| Security and technical logs | For a limited period appropriate to security, debugging, fraud prevention and legal requirements. |
| Support and grievance records | For as long as needed to resolve the request and maintain an appropriate audit, legal or service-quality record. |
| Marketing preferences | Until consent is withdrawn, plus a limited suppression record where needed to respect opt-out choices. |
Retention may be extended where information is subject to a complaint, legal hold, investigation, unpaid transaction, regulatory requirement or ongoing claim. Data may also be retained in securely restricted backups until normal deletion cycles complete.
Where appropriate, we may de-identify or aggregate information instead of deleting it, provided it is no longer reasonably capable of identifying you.
Section 12
CFA uses reasonable technical and organisational safeguards designed to protect personal data against unauthorised access, alteration, disclosure, loss, misuse or destruction. Measures may include:
No online service or storage system can be guaranteed completely secure. You are responsible for protecting your password, devices and account recovery channels. Contact us immediately if you suspect unauthorised account access.
Section 13
CFA, its infrastructure and authorised service providers may process or store data in India and other countries. Those countries may have privacy laws that differ from the laws where you live.
Where required, CFA will use reasonable contractual, organisational or technical measures for international processing and comply with restrictions or requirements issued under applicable Indian law.
By using globally delivered features, your data may be transmitted through or processed using systems located outside your state or country, subject to applicable law and this Policy.
Section 14
Depending on applicable law and the context, you may have the following rights:
Access and information
Ask for information about personal data processed by CFA and relevant processing activities.
Correction and completion
Request correction of inaccurate or incomplete personal data.
Erasure
Request deletion where data is no longer required and no lawful retention reason applies.
Withdraw consent
Withdraw consent for future processing where consent is the applicable basis.
Grievance redressal
Raise a privacy grievance and receive a response through CFA’s published process.
Nomination
Nominate another individual to exercise applicable rights in the event of death or incapacity, where supported by law and CFA procedures.
Communication choices
Unsubscribe from optional marketing and manage available notification settings.
Cookie choices
Manage non-essential cookie preferences through available controls.
How to submit a request
Submit a request through Privacy Request or email privacy@consumerfraudawareness.com. Please include your registered email or telephone number, the right you wish to exercise, and sufficient details to locate the relevant data.
CFA may request reasonable identity or authority verification before completing a request. We will not ask for more information than reasonably necessary for verification.
We aim to acknowledge privacy requests within 7 business days and respond or provide a status update within 30 days. A longer period may be required for complex, high-volume or legally restricted requests, in which case we will communicate the reason where appropriate.
Limitations
A request may be limited or declined where permitted by law, including where disclosure would adversely affect another person’s rights, the request cannot be verified, data must be retained by law, or retention is necessary for security, fraud prevention, moderation, public-interest transparency, legal claims or dispute records.
Public content may sometimes be anonymised rather than fully deleted where retaining the underlying consumer experience remains lawful and appropriate.
Section 15
CFA’s account, review, complaint, business and paid-service features are intended for persons aged 18 years or older. We do not knowingly permit a child to create an independent account or submit public content.
Where a feature is lawfully made available to a child, CFA will apply appropriate age checks and obtain verifiable consent from a parent or lawful guardian where required.
A parent or guardian who believes a child has provided personal data without proper authorisation should contact us so that we can investigate and take appropriate action.
Section 16
CFA may link to business websites, social media, payment providers, government resources, professional services and other external platforms. Their privacy practices are governed by their own notices, not this Policy.
When you use a third-party sign-in or integration, the third party may provide CFA with data you authorised, and it may independently collect information about your use. Review the third party’s privacy settings and policy before connecting a service.
Section 17
CFA may publish business information such as business names, categories, websites, general contact channels, locations, registration status and publicly available professional information. This supports company discovery, consumer awareness and profile claiming.
Business representatives may request correction of inaccurate profile data through the claim or contact process. A request to correct personal data does not automatically require deletion of a lawful business listing, consumer review or complaint.
CFA may contact business representatives using professional details to verify a profile, notify them of content, invite a response, address a complaint, communicate service information or protect Platform integrity.
Section 18
CFA maintains procedures to assess and respond to suspected personal-data breaches. Where an incident is confirmed, we may take steps to contain it, preserve evidence, reset credentials, restrict access and notify affected persons or authorities as required by applicable law.
Notices may describe the nature of the incident, likely impact, mitigation steps and actions users should take. Users should follow security instructions promptly and avoid sharing verification codes or passwords with anyone.
Section 19
We may update this Policy to reflect changes in law, technology, security, Platform features or business operations. The “Last updated” date at the top will identify the current version.
Where changes materially affect how we process personal data, we will provide reasonable notice through the Platform, account communications or another appropriate method and seek fresh consent where legally required.
Section 20
Privacy questions, requests and complaints may be submitted using the following channels:
A request should include your name, registered contact details, the relevant account or content reference, a clear explanation of the request and supporting authority where you act for another person or business.
CFA will make reasonable efforts to acknowledge and address grievances within the published response period. If you remain dissatisfied after using CFA’s grievance process, you may pursue any escalation or complaint mechanism available under applicable law.
Before deployment, ensure that the privacy and grievance email addresses above are active, monitored and routed to authorised CFA personnel. The live page should also identify the operating legal entity and postal address in the website’s official company disclosure.
Your Responsibilities
When using CFA, you should:
Need to access, correct or delete your data?
Use CFA’s privacy request channel for account data, consent withdrawal, correction, erasure or grievance assistance.