Legal
Privacy Policy
Effective 29 September 2026 · Last updated 29 September 2026
This Privacy Policy explains how Pegadroid IQ Solutions Private Limited ("Attestr", "we", "us") collects, uses, stores, shares and protects personal data, in line with the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the Digital Personal Data Protection Rules, 2025.
Attestr plays two different roles, and this policy covers both: we are a Data Fiduciary for the personal data of our own customers, prospects and website visitors, and a Data Processor for the personal data our business customers ask us to verify on their behalf.
1.Who we are
Attestr is an identity, risk monitoring and digital KYC platform operated by Pegadroid IQ Solutions Private Limited, a company incorporated under the Companies Act, 2013 (CIN U74999TG2017PTC118280), with its registered office at 8-2-293/K/57/101, Kamalapuri Colony Phase 3, Hyderabad, Telangana 500073, India.
This policy applies to attestr.com, the Attestr dashboard, our APIs and SDKs, Attestr-hosted consent and verification pages, and any other service that links to it.
2.Our two roles under the DPDP Act
When Attestr is a Data Fiduciary
We decide why and how personal data is processed for: people who visit our website or contact us; the individuals who sign up for and use an Attestr account on behalf of a business ("Account Users"); and the billing and business contacts of our customers.
When Attestr is a Data Processor
Businesses ("Clients") use Attestr to verify their own customers, vendors, employees, candidates and users ("End Users"). For that data, the Client is the Data Fiduciary: it decides the purpose, obtains the End User's consent and is responsible to the End User. Attestr processes the data only on the Client's documented instructions and only to provide the service the Client requested. Where a Client opts for it, Attestr also acts as a Consent Collection Facilitator, collecting consent on the Client's behalf through Attestr-hosted consent pages.
Were you verified by a business using Attestr? That business is your Data Fiduciary, and its privacy notice explains why your data was collected. You can still contact us — see Your rights — and we will help route your request to the right business.
Nothing in how we provide our services makes Attestr a Data Fiduciary or Joint Data Fiduciary for End User data.
3.Personal data we collect as a Data Fiduciary
| Category | Examples | How we get it |
|---|---|---|
| Enquiry data | Name, work email, company, phone number, the message you send us | Contact and demo forms, email, phone, events |
| Account data | Name, email, phone, company, role, team members you invite, login credentials (passwords are stored only as bcrypt hashes) | You or your organisation, when an account is created |
| Billing data | Billing name and address, GSTIN and PAN of the business, invoices, payment references | You, and our payment processor (we never see or store full card numbers) |
| Usage and technical data | IP address, browser and device type, API request metadata (request IDs, timestamps, usage counters), security logs | Automatically, when you use our website, dashboard or APIs |
| Support data | Support tickets, emails and call notes | You, when you contact support |
4.Personal data we process for our Clients
Depending on the services a Client uses, we may process the following about End Users — only what the Client's chosen verification needs:
- Identity data — name, date of birth, gender, address, and government identifiers such as PAN, Aadhaar (via DigiLocker), Voter ID, driving licence and passport.
- Contact data — phone number and email address.
- Financial data — bank account and IFSC, UPI ID, and related verification results.
- Education, employment and credential data — qualifications, employment history (including EPFO/UAN records) and professional registrations.
- Biometric data — photographs or selfies, used only for face-match checks the Client requests.
- Business and legal data — business registrations, director details, and court and litigation records.
- Consent data — the consent record the Client provides or we collect on its behalf (see Consent).
This data comes from the Client, from the End User directly (for example through an Attestr-hosted journey), and from government, statutory and other authoritative sources such as DigiLocker, government registries and universities — either directly or through Attestr's authorised verification data partners — always under the End User's consent obtained by the Client.
End Users may include the Client's customers and vendors, employees and prospective employees, job applicants and candidates, and users of the Client's platform.
5.Why we use personal data
As a Data Fiduciary
We process your personal data on the basis of your consent, or for a legitimate use permitted under Section 7 of the DPDP Act — for example, where you voluntarily give us data for a specific purpose, or where the law requires us to process it. We use it to:
- respond to your enquiries and arrange demos;
- create, secure and administer your account and your team's access;
- provide, maintain and support the services you have purchased;
- invoice, collect payments and meet GST, tax and company-law obligations;
- keep our platform secure, detect fraud and abuse, and investigate incidents;
- send service, security and billing communications; and
- send product updates, only where you have opted in — every such email includes an unsubscribe option.
As a Data Processor
We use End User data only to perform the verification, KYC, background-verification, risk-monitoring or consent services the Client instructed, for the duration of the Client's agreement or the validity of the End User's consent, whichever is shorter.
We do not sell, license, rent or commercially exploit personal data or verification outputs; use them for marketing, profiling or any unrelated purpose; combine them with other datasets for resale or enrichment; or attempt to re-identify masked, tokenised or anonymised data.
6.Consent
For End User data, the Client must obtain valid consent — free, specific, informed, unconditional and unambiguous, given by a clear affirmative action — before starting a verification, sharing personal data with Attestr, or accessing or storing results. That consent must cover the purpose, the categories of data, the use of government, statutory and authoritative sources — directly or through Attestr's authorised verification data partners — and the sharing of data with Attestr as a Data Processor.
Clients send us a consent record with each request in the format described in our consent definitions, including when and how consent was taken, its purpose, whether it is one-time or ongoing, its validity period, the data categories covered, and the version of the Client's own privacy policy that applied.
| Consent type | What it allows |
|---|---|
| Single-use | One verification or data retrieval. The consent is consumed once used and cannot be reused; no data is stored for reuse. |
| Multi-use (reusable) | Repeated verification and processing within the consent's validity period, until it expires or is revoked. Each consent lists the operations it permits — verify, fetch, store, report, export or share — and only those operations are carried out. |
Where a Client uses Attestr-hosted consent pages, each page names the Client as the Data Fiduciary and states the purpose and data categories. We keep an auditable record of each consent event — timestamp, the consent language shown, and device and session metadata — and make it available to the Client.
You can withdraw consent at any time. Withdrawal does not affect processing carried out before it. See Your rights for how.
7.How long we keep personal data
End User data is kept according to our Data Storage Policy, which is also published in our developer documentation. In summary:
| Data | Retention |
|---|---|
| Single-use consent requests | Personal data is masked in a non-retrievable form; verification results are not stored after the verification completes. |
| Reusable consents with storage enabled | Encrypted, for 7 working days by default (or until the consent expires, if sooner). Longer storage only if the Client buys a Data Storage Pack, and never beyond the consent's validity. |
| Request and consent metadata (no directly identifying data) | Queryable for up to 1 year, then archived for a maximum of 3 years in total. |
| Transaction reports | 1 year, containing masked data only. |
| PDF reports | Only while the underlying consent remains valid. |
When a consent expires or is revoked, automated jobs delete or irreversibly anonymise the stored personal data and outputs. Non-personal metadata — transaction IDs, timestamps, logs, billing and audit records — is kept for regulatory compliance, security and fraud prevention, billing and dispute resolution; it does not identify the End User.
For data we hold as a Data Fiduciary: enquiry data is kept only as long as needed to respond and manage any resulting relationship; account data for as long as the account is active; invoices and billing records for the periods required under tax and company law; and application security logs for 30 days. On termination of a Client's agreement, Client data is returned or securely deleted within 90 days, or sooner on request, with written confirmation.
8.Where your data is stored
Verification and platform data is stored in India: our application runs on Amazon Web Services and our database on MongoDB Atlas, both in the AWS Asia Pacific (Mumbai) region. Backups are kept in India, and our infrastructure fails over only between data centres within India.
Our website and dashboard front-ends are delivered through Netlify's global content-delivery network, and messages sent through our website's contact form are processed by Netlify. That enquiry data may therefore be processed outside India.
Emails we send — such as one-time passwords, consent requests and notifications — are delivered through Mailgun in the United States, which receives the recipient's email address and the message content. SMS messages are delivered through Msg91 in India. Neither provider receives verification results.
Some processing happens outside India. Our AI court-order summaries are generated on Runpod's GPU cloud: it receives only publicly available court orders — which may name the parties to a case — processes nothing else, and keeps no data after producing the summary. Separately, our tax invoices and billing records — your billing contact name, email, phone, billing address and GSTIN — are maintained in Zoho Books, which uses Zoho's global data centres.
Any transfer of personal data outside India complies with the DPDP Act, including any restrictions the Central Government notifies under Section 16. See our Sub-processors page for who processes data and where.
9.How we protect personal data
Attestr's information security management system is certified to ISO/IEC 27001:2022, and our quality management system to ISO 9001:2015. Our safeguards include:
- encryption of personal data at rest with AES-256-GCM, using keys managed in AWS Key Management Service and rotated periodically;
- TLS 1.2 or higher for all data in transit;
- passwords stored only as bcrypt hashes, and secrets held in AWS Secrets Manager;
- least-privilege, role-based access control, multi-factor authentication on all cloud-infrastructure access, optional email-OTP multi-factor authentication for dashboard logins, and prompt revocation of access when people leave;
- centralised logging, monitoring and real-time alerting;
- continuous database replication with hourly encrypted backups; and
- independent vulnerability assessment and penetration testing (VAPT) of our production platform, with every critical, high, medium and low finding remediated and re-verified.
No system is entirely free of risk, but we review these controls at least annually and after any significant change or incident.
11.Your rights
Under the DPDP Act you have the right to:
- obtain a summary of the personal data processed about you and the processing activities;
- have your personal data corrected, completed or updated;
- have your personal data erased where it is no longer needed or you withdraw consent, unless the law requires us to keep it;
- withdraw consent at any time, as easily as you gave it;
- nominate another person to exercise these rights on your behalf in the event of your death or incapacity; and
- have your grievances redressed.
If Attestr is your Data Fiduciary
Email our Grievance Officer at harika.pogaku@attestr.com with the subject "Data Protection Request". We may need to verify your identity before acting on the request.
If you were verified by a business using Attestr
Please contact that business first — as your Data Fiduciary it is responsible for your request. If you contact us instead, we will tell you which Client the data relates to where we can, forward your request to them, and provide the Client with the technical help needed to act on it. If you gave consent through an Attestr-hosted consent page, you can also review and withdraw it yourself through the self-service link on that page.
We respond to grievances within the period prescribed under the DPDP Rules, 2025, and in any case within 90 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
12.Personal data breaches
If we become aware of a personal data breach, we investigate and contain it immediately. For End User data, we notify the affected Client without undue delay — within the timeframes set out in our Client agreements — with the nature of the breach, its likely impact and the steps taken, and we help the Client meet its own notification obligations. Where Attestr is the Data Fiduciary, we notify the Data Protection Board of India and affected individuals as required under the DPDP Act and Rules.
13.Children's data
Attestr's services are for businesses and are not directed at children. Where a Client's End User is a child or a person with a disability who has a lawful guardian, the Client is responsible for obtaining verifiable consent from the parent or lawful guardian as required under Section 9 of the DPDP Act.
15.Grievance Officer and contact
| Grievance Officer | Harika Pogaku, Co-founder & Chief Information Officer |
| harika.pogaku@attestr.com — subject "Data Protection Request" | |
| Post | Pegadroid IQ Solutions Private Limited, 8-2-293/K/57/101, Kamalapuri Colony Phase 3, Hyderabad, Telangana 500073, India |
16.Changes to this policy
We may update this policy as our services or the law change. The "last updated" date at the top shows when it last changed; for material changes we will notify customers by email or in the dashboard before they take effect. This version replaces our privacy policy published in 2022.