Legal
Data Storage Policy
Effective 29 September 2026 · Last updated 29 September 2026
This policy explains what data Attestr stores when you use our verification services, for how long, where, and how it is deleted — built around the storage-limitation principle of the Digital Personal Data Protection Act, 2023: keep personal data only as long as the purpose and the consent require.
The technical version of this policy, including API behaviour, is in our developer documentation.
1.What we store
| Category | What it contains |
|---|---|
| Request data | The information submitted for verification and the verification response — may include personal data such as identity details, contact information and government identifiers. |
| Request metadata | Operational details such as request IDs, timestamps, usage counters and billing data. Contains no personal data. |
| Consent metadata | The consent lifecycle — timestamps, validity, purpose, data categories, operations permitted and lifecycle events — plus identifiers the Client provides, which may be personal data. |
2.Storage by consent type
Single-use consent
Personal data fields are masked in a non-retrievable format and kept only as limited transaction metadata. The original request and verification response are processed transiently and not persistently stored — so features that need stored data, such as PDF reports or asynchronous retrieval, are unavailable for single-use consents.
Reusable consent
By default, nothing is stored. Storage happens only if the Client enables the Store operation when registering the consent. When it does:
- request and verified data are encrypted before storage;
- data is kept for 7 working days at no extra cost — or until the consent expires, if that is sooner;
- longer retention requires a paid Data Storage Pack, and storage never extends beyond the consent's validity; and
- a Client can skip storage for any individual request (using the XAttestrSkipStore request header), while request metadata and the audit trail are still recorded.
3.Retention periods
| Data | Retention |
|---|---|
| Single-use request data | Not stored; personal data masked and non-retrievable |
| Reusable request data (Store enabled) | 7 working days by default, extendable with a Data Storage Pack, never beyond consent validity |
| Request and consent metadata | Active and queryable for up to 1 year; archived up to a maximum of 3 years |
| Transaction reports | 1 year — masked data only |
| PDF reports | Only while the consent is active and permits the Report operation |
| Batch exports | Only for consents that permit the Export operation; expired consents are excluded automatically |
| Application security logs | 30 days |
Some services are direct public-record lookups rather than consent-based End User verifications (for example, court case details by case number). The encryption and infrastructure practices in this policy apply to every service.
4.Deletion, expiry and revocation
Automated background jobs delete stored data as soon as a consent expires or is revoked. Only audit metadata — which does not identify the Data Principal — survives, for compliance, security, billing and dispute resolution.
Consent can be revoked, and stored data deleted, through the Attestr dashboard, the Revoke Consent API, or — for consents collected on Attestr-hosted pages — a self-service portal where Data Principals can review and withdraw their own consents. Clients can export a full consent audit trail at any time.
When a Client's agreement ends, its data is returned or securely deleted within 90 days, or sooner on request.
5.Where data is stored
All verification and platform data is stored in India, in the AWS Asia Pacific (Mumbai) region: application services on Amazon Web Services and the database on MongoDB Atlas. Backups are held in India, and the platform fails over only between availability zones within India.
Message delivery is separate from storage: emails (for example, one-time passwords and consent requests) are sent through Mailgun in the United States and SMS through Msg91 in India. These providers receive only the recipient's contact details and the message content.
6.How stored data is protected
- Encryption at rest — AES-256-GCM, with keys managed in AWS Key Management Service and rotated periodically while keeping historical records decryptable.
- Encryption in transit — TLS 1.2 or higher on every connection.
- Backups — continuous database replication plus hourly, encrypted backups.
- Access — least-privilege, role-based access; multi-factor authentication on all cloud-infrastructure access, and optional email-OTP multi-factor authentication for dashboard logins.
- Assurance — Attestr's information security management system is certified to ISO/IEC 27001:2022, and the production platform is independently penetration tested (VAPT).
7.Changes to this policy
We review this policy at least once a year and whenever our storage practices change. Material changes are notified to Clients in advance.