Skip to content

Legal

Data Processing Addendum

Effective 29 September 2026 · Last updated 29 September 2026

This Data Processing Addendum ("DPA") governs how Pegadroid IQ Solutions Private Limited ("Attestr" or "Processor") processes Personal Data on behalf of a business that uses Attestr's APIs, dashboard or verification services (the "Client" or "Data Fiduciary"), and how consent obligations under the Digital Personal Data Protection Act, 2023 ("DPDP Act") are allocated between them.

This DPA forms part of the Terms of Service and prevails on matters of data protection and consent. Clients who need a countersigned copy can request one at contact@attestr.com.

1.Roles of the parties

The Client is the Data Fiduciary. It determines the purpose and lawful basis of processing, the nature, scope and categories of Personal Data, and the duration and validity of consent, and complies with all obligations of a Data Fiduciary under the DPDP Act.

Attestr is solely a Data Processor, and a Consent Collection Facilitator where the Client opts for it. It processes Personal Data only on the Client's documented instructions and does not determine the purpose or means of processing. Nothing in this DPA makes Attestr a Data Fiduciary or Joint Data Fiduciary.

2.Subject matter and details of processing

ItemDetails
Subject matterKYC, background verification, identity and credential verification services
DurationThe term of the Client's agreement or the validity of the Data Principal's consent, whichever is shorter — unless the law requires longer retention
Nature of processingCollection, receipt, recording, validation, authentication, verification, storage, transmission, access, use, and deletion or erasure
Data PrincipalsThe Client's customers and vendors; employees and prospective employees; job applicants and candidates; end users of the Client's services
Personal DataIdentity data and government identifiers; contact data; educational, employment, professional and credential data; verification identifiers, authentication data and related metadata

6.Data storage, retention and consent lifecycle

One-time consent

Attestr does not store verification outputs or associated Personal Data after the verification completes. Input data may be masked, tokenised or irreversibly transformed and kept only for limited reporting, audit and operational analytics; no Personal Data is kept in a reusable or identifiable form.

Validity-based (ongoing) consent

On the Client's explicit request, Attestr may store verification outputs and associated Personal Data, encrypted, strictly for the duration of the consent's validity and only to enable re-use, re-validation or reference during that period. Storage beyond the default period is subject to additional charges under the commercial terms.

Revocation and deletion

Attestr provides API and dashboard mechanisms to revoke consent and request deletion of stored Personal Data. On valid revocation, stored Personal Data and verification outputs are deleted or irreversibly anonymised within a reasonable time, subject to technical and legal constraints.

Metadata

Non-personal metadata — transaction identifiers, timestamps, logs, and billing and audit records — is retained even after revocation, solely for regulatory compliance, security and fraud prevention, and billing, reconciliation and dispute resolution. It does not permit identification of the Data Principal.

Retention periods are set out in the Data Storage Policy.

7.Sub-processors

Attestr may engage sub-processors to deliver the services, including cloud and infrastructure providers, message-delivery providers, and verification data partners — licensed intermediaries through which Attestr accesses government and authoritative sources for specific checks. Attestr ensures each is contractually bound by data-protection obligations equivalent to its own, permits it to use Personal Data only to perform the requested service, and remains responsible for its acts and omissions. Sub-processors are described on our Sub-processors page; the current named list, including verification data partners, is available to the Client on request, under a non-disclosure agreement.

8.Use limitations and restrictions

Neither party will:

  • sell, license, rent, redistribute or commercially exploit Personal Data or verification outputs;
  • use Personal Data for marketing, profiling or any purpose other than the authorised verification purpose;
  • combine data received under this DPA with third-party datasets for resale, enrichment or monetisation; or
  • attempt to re-identify, reverse engineer or reconstruct masked, tokenised or anonymised data.

9.Data Principal rights

The Client is solely responsible for handling Data Principal requests, including consent withdrawal and requests for correction or erasure. Attestr provides reasonable technical assistance and cooperation, where feasible, on the Client's documented instructions.

10.Security measures

Attestr implements industry-standard technical and organisational safeguards, including encryption in transit and at rest, access controls, monitoring and logging, under an information security management system certified to ISO/IEC 27001:2022. The Client acknowledges that no system is entirely free of risk.

11.Audit, monitoring and suspension

Both parties maintain appropriate monitoring and audit mechanisms to demonstrate lawful processing and accountability. Attestr may audit and monitor the Client's use of the services; the Client may reasonably request audit information about Attestr's processing, subject to confidentiality, security and operational limits.

Either party may suspend processing or access where there is suspected misuse, a consent violation, a security risk or regulatory exposure, and both will cooperate in good faith to investigate and correct the issue before normal processing resumes.

The Client will promptly notify Attestr of any data breach or regulatory inquiry involving data processed by Attestr.

12.Personal data breach

Attestr will notify the Client without undue delay on becoming aware of a personal data breach affecting Client data, and within the timeframe in the Client's signed agreement where one applies. The notification will describe the nature of the breach, its likely impact and the mitigation steps taken, followed by a root-cause report and corrective measures. Attestr will cooperate with the Client so that the Client can meet its own notification obligations to the Data Protection Board of India and Data Principals, which remain the Client's responsibility unless the law requires otherwise.

13.Indemnity

The Client will fully indemnify, defend and hold harmless Attestr, its officers, employees and affiliates against claims, losses, penalties, damages and regulatory actions — including legal costs, fines and compensation payable to Data Principals — arising from the Client's failure to obtain or maintain valid consent, misrepresentation of its lawful basis, unlawful use, disclosure, resale or retention of Personal Data, or violation of the DPDP Act or other applicable law.

14.Limitation of liability

To the maximum extent permitted by law, Attestr is not liable for indirect or consequential damages, and its aggregate liability under this DPA does not exceed the fees paid by the Client in the preceding twelve (12) months.

15.Data location and cross-border transfers

Client data processed through the services is stored in India. Some sub-processors process data outside India — for example email delivery (Mailgun, United States) and AI summarisation of publicly available court orders (Runpod, which retains no data after processing) — as listed on our Sub-processors page. Every such transfer complies with the DPDP Act, any restrictions notified by the Central Government under Section 16, and contractual safeguards.

16.Termination

Attestr may suspend or terminate access immediately on consent violations, data misuse, or legal or regulatory exposure. After termination, data is handled under the agreed retention and deletion policies, and Client data is returned or securely deleted within ninety (90) days or sooner on request.

17.Governing law and survival

This DPA is governed by the laws of India, and the courts at Hyderabad have exclusive jurisdiction. The provisions on indemnity, data use restrictions, metadata retention and limitation of liability survive termination.