Skip to content

Legal

Data Storage Policy

Effective 29 September 2026 · Last updated 29 September 2026

This policy explains what data Attestr stores when you use our verification services, for how long, where, and how it is deleted — built around the storage-limitation principle of the Digital Personal Data Protection Act, 2023: keep personal data only as long as the purpose and the consent require.

The technical version of this policy, including API behaviour, is in our developer documentation.

1.What we store

CategoryWhat it contains
Request dataThe information submitted for verification and the verification response — may include personal data such as identity details, contact information and government identifiers.
Request metadataOperational details such as request IDs, timestamps, usage counters and billing data. Contains no personal data.
Consent metadataThe consent lifecycle — timestamps, validity, purpose, data categories, operations permitted and lifecycle events — plus identifiers the Client provides, which may be personal data.

3.Retention periods

DataRetention
Single-use request dataNot stored; personal data masked and non-retrievable
Reusable request data (Store enabled)7 working days by default, extendable with a Data Storage Pack, never beyond consent validity
Request and consent metadataActive and queryable for up to 1 year; archived up to a maximum of 3 years
Transaction reports1 year — masked data only
PDF reportsOnly while the consent is active and permits the Report operation
Batch exportsOnly for consents that permit the Export operation; expired consents are excluded automatically
Application security logs30 days

Some services are direct public-record lookups rather than consent-based End User verifications (for example, court case details by case number). The encryption and infrastructure practices in this policy apply to every service.

4.Deletion, expiry and revocation

Automated background jobs delete stored data as soon as a consent expires or is revoked. Only audit metadata — which does not identify the Data Principal — survives, for compliance, security, billing and dispute resolution.

Consent can be revoked, and stored data deleted, through the Attestr dashboard, the Revoke Consent API, or — for consents collected on Attestr-hosted pages — a self-service portal where Data Principals can review and withdraw their own consents. Clients can export a full consent audit trail at any time.

When a Client's agreement ends, its data is returned or securely deleted within 90 days, or sooner on request.

5.Where data is stored

All verification and platform data is stored in India, in the AWS Asia Pacific (Mumbai) region: application services on Amazon Web Services and the database on MongoDB Atlas. Backups are held in India, and the platform fails over only between availability zones within India.

Message delivery is separate from storage: emails (for example, one-time passwords and consent requests) are sent through Mailgun in the United States and SMS through Msg91 in India. These providers receive only the recipient's contact details and the message content.

6.How stored data is protected

  • Encryption at rest — AES-256-GCM, with keys managed in AWS Key Management Service and rotated periodically while keeping historical records decryptable.
  • Encryption in transit — TLS 1.2 or higher on every connection.
  • Backups — continuous database replication plus hourly, encrypted backups.
  • Access — least-privilege, role-based access; multi-factor authentication on all cloud-infrastructure access, and optional email-OTP multi-factor authentication for dashboard logins.
  • Assurance — Attestr's information security management system is certified to ISO/IEC 27001:2022, and the production platform is independently penetration tested (VAPT).

7.Changes to this policy

We review this policy at least once a year and whenever our storage practices change. Material changes are notified to Clients in advance.