Legal
Data Processing Addendum
Effective 29 September 2026 · Last updated 29 September 2026
This Data Processing Addendum ("DPA") governs how Pegadroid IQ Solutions Private Limited ("Attestr" or "Processor") processes Personal Data on behalf of a business that uses Attestr's APIs, dashboard or verification services (the "Client" or "Data Fiduciary"), and how consent obligations under the Digital Personal Data Protection Act, 2023 ("DPDP Act") are allocated between them.
This DPA forms part of the Terms of Service and prevails on matters of data protection and consent. Clients who need a countersigned copy can request one at contact@attestr.com.
1.Roles of the parties
The Client is the Data Fiduciary. It determines the purpose and lawful basis of processing, the nature, scope and categories of Personal Data, and the duration and validity of consent, and complies with all obligations of a Data Fiduciary under the DPDP Act.
Attestr is solely a Data Processor, and a Consent Collection Facilitator where the Client opts for it. It processes Personal Data only on the Client's documented instructions and does not determine the purpose or means of processing. Nothing in this DPA makes Attestr a Data Fiduciary or Joint Data Fiduciary.
2.Subject matter and details of processing
| Item | Details |
|---|---|
| Subject matter | KYC, background verification, identity and credential verification services |
| Duration | The term of the Client's agreement or the validity of the Data Principal's consent, whichever is shorter — unless the law requires longer retention |
| Nature of processing | Collection, receipt, recording, validation, authentication, verification, storage, transmission, access, use, and deletion or erasure |
| Data Principals | The Client's customers and vendors; employees and prospective employees; job applicants and candidates; end users of the Client's services |
| Personal Data | Identity data and government identifiers; contact data; educational, employment, professional and credential data; verification identifiers, authentication data and related metadata |
3.Client's consent obligations
The Client will obtain valid, informed, specific and freely given consent from the Data Principal before:
- initiating any verification;
- submitting Personal Data to Attestr; and
- accessing or storing verification results.
That consent must clearly cover the purpose of verification; the categories of Personal Data processed; the use of government, statutory or authoritative sources (such as DigiLocker, universities and government registries), whether accessed directly or through Attestr's authorised verification data partners; and the sharing of data with Attestr as a processor.
The Client represents and warrants that its consents comply with the DPDP Act, that consent records are maintained and auditable, and that each consent remains valid throughout the related processing.
4.Attestr-hosted consent collection
Where a Client cannot send complete consent details through the API or dashboard, Attestr may, on the Client's request, provide an Attestr-hosted consent collection interface (the "Consent Service"). Consent pages may carry the Client's branding, be white-labelled or co-branded, and be reached by redirect or an embedded flow.
Every consent collected through the Consent Service explicitly identifies the Client as the Data Fiduciary, specifies the purpose and data categories, and is deemed to have been collected by the Client, with Attestr acting on its behalf.
For the Consent Service, Attestr maintains an auditable record of consent events — including timestamp, the consent language shown, and device and session metadata — and makes those records available to the Client for compliance and audit.
5.Consent assertion and input schema
The Client provides a consent declaration with every request made through the APIs or dashboard. Attestr relies on these declarations in good faith and does not independently validate consent; any incorrect or unlawful assertion is solely the Client's responsibility.
Consent information must follow the Consent Data & Input Schema below and in our consent documentation. Requests without the required information are non-compliant and may be rejected or suspended. Attestr may revise the schema to keep it compliant with applicable law, and the Client will implement revisions within a reasonable time.
| Mandatory field | Meaning |
|---|---|
| consent_timestamp | Date and time consent was given (ISO 8601) |
| consent_mode, consent_mode_desc | How consent was taken — e.g. checkbox, OTP, eSign, DigiLocker, physical form, IVR, agent-assisted — and a description |
| consent_purpose, consent_purpose_desc | Purpose of consent — e.g. KYC verification, background verification — and a description |
| consent_type | one_time or ongoing |
| consent_valid_from, consent_valid_till | Validity window, for ongoing consent |
| consent_reference_id | The Client's unique reference for the consent record |
| consent_principal_user_id | The Client's unique identifier for the Data Principal |
| client_privacy_policy_url, client_privacy_policy_version | The Client's privacy policy, and the version in force when consent was taken |
| client_declaration | Always true — the Client's declaration that lawful consent was obtained |
| client_obtained_by | The person or system that obtained consent |
| data_categories | The categories and types of data covered — e.g. personal information, identity, business identity, contact, financial, education, employment, biometric, legal |
6.Data storage, retention and consent lifecycle
One-time consent
Attestr does not store verification outputs or associated Personal Data after the verification completes. Input data may be masked, tokenised or irreversibly transformed and kept only for limited reporting, audit and operational analytics; no Personal Data is kept in a reusable or identifiable form.
Validity-based (ongoing) consent
On the Client's explicit request, Attestr may store verification outputs and associated Personal Data, encrypted, strictly for the duration of the consent's validity and only to enable re-use, re-validation or reference during that period. Storage beyond the default period is subject to additional charges under the commercial terms.
Revocation and deletion
Attestr provides API and dashboard mechanisms to revoke consent and request deletion of stored Personal Data. On valid revocation, stored Personal Data and verification outputs are deleted or irreversibly anonymised within a reasonable time, subject to technical and legal constraints.
Metadata
Non-personal metadata — transaction identifiers, timestamps, logs, and billing and audit records — is retained even after revocation, solely for regulatory compliance, security and fraud prevention, and billing, reconciliation and dispute resolution. It does not permit identification of the Data Principal.
Retention periods are set out in the Data Storage Policy.
7.Sub-processors
Attestr may engage sub-processors to deliver the services, including cloud and infrastructure providers, message-delivery providers, and verification data partners — licensed intermediaries through which Attestr accesses government and authoritative sources for specific checks. Attestr ensures each is contractually bound by data-protection obligations equivalent to its own, permits it to use Personal Data only to perform the requested service, and remains responsible for its acts and omissions. Sub-processors are described on our Sub-processors page; the current named list, including verification data partners, is available to the Client on request, under a non-disclosure agreement.
8.Use limitations and restrictions
Neither party will:
- sell, license, rent, redistribute or commercially exploit Personal Data or verification outputs;
- use Personal Data for marketing, profiling or any purpose other than the authorised verification purpose;
- combine data received under this DPA with third-party datasets for resale, enrichment or monetisation; or
- attempt to re-identify, reverse engineer or reconstruct masked, tokenised or anonymised data.
9.Data Principal rights
The Client is solely responsible for handling Data Principal requests, including consent withdrawal and requests for correction or erasure. Attestr provides reasonable technical assistance and cooperation, where feasible, on the Client's documented instructions.
10.Security measures
Attestr implements industry-standard technical and organisational safeguards, including encryption in transit and at rest, access controls, monitoring and logging, under an information security management system certified to ISO/IEC 27001:2022. The Client acknowledges that no system is entirely free of risk.
11.Audit, monitoring and suspension
Both parties maintain appropriate monitoring and audit mechanisms to demonstrate lawful processing and accountability. Attestr may audit and monitor the Client's use of the services; the Client may reasonably request audit information about Attestr's processing, subject to confidentiality, security and operational limits.
Either party may suspend processing or access where there is suspected misuse, a consent violation, a security risk or regulatory exposure, and both will cooperate in good faith to investigate and correct the issue before normal processing resumes.
The Client will promptly notify Attestr of any data breach or regulatory inquiry involving data processed by Attestr.
12.Personal data breach
Attestr will notify the Client without undue delay on becoming aware of a personal data breach affecting Client data, and within the timeframe in the Client's signed agreement where one applies. The notification will describe the nature of the breach, its likely impact and the mitigation steps taken, followed by a root-cause report and corrective measures. Attestr will cooperate with the Client so that the Client can meet its own notification obligations to the Data Protection Board of India and Data Principals, which remain the Client's responsibility unless the law requires otherwise.
13.Indemnity
The Client will fully indemnify, defend and hold harmless Attestr, its officers, employees and affiliates against claims, losses, penalties, damages and regulatory actions — including legal costs, fines and compensation payable to Data Principals — arising from the Client's failure to obtain or maintain valid consent, misrepresentation of its lawful basis, unlawful use, disclosure, resale or retention of Personal Data, or violation of the DPDP Act or other applicable law.
14.Limitation of liability
To the maximum extent permitted by law, Attestr is not liable for indirect or consequential damages, and its aggregate liability under this DPA does not exceed the fees paid by the Client in the preceding twelve (12) months.
15.Data location and cross-border transfers
Client data processed through the services is stored in India. Some sub-processors process data outside India — for example email delivery (Mailgun, United States) and AI summarisation of publicly available court orders (Runpod, which retains no data after processing) — as listed on our Sub-processors page. Every such transfer complies with the DPDP Act, any restrictions notified by the Central Government under Section 16, and contractual safeguards.
16.Termination
Attestr may suspend or terminate access immediately on consent violations, data misuse, or legal or regulatory exposure. After termination, data is handled under the agreed retention and deletion policies, and Client data is returned or securely deleted within ninety (90) days or sooner on request.
17.Governing law and survival
This DPA is governed by the laws of India, and the courts at Hyderabad have exclusive jurisdiction. The provisions on indemnity, data use restrictions, metadata retention and limitation of liability survive termination.