Legal
Terms of Service
Effective 29 September 2026 · Last updated 29 September 2026
These Terms of Service ("Terms") govern access to and use of the Attestr website, dashboard, APIs, SDKs, hosted journeys and related services (together, the "Services") provided by Pegadroid IQ Solutions Private Limited ("Attestr", "we", "us").
By creating an account, purchasing a service pack or using the Services, you agree to these Terms on behalf of the business you represent (the "Customer", "you").
1.Your agreement with Attestr
Your agreement with Attestr consists of these Terms; any order, purchase order or statement of work agreed with us (an "Order"); our Data Processing Addendum; our Data Storage Policy; and the product documentation at docs.attestr.com.
If you have signed a separate Master Service Agreement or other written agreement with Attestr, that signed agreement prevails over these Terms wherever they differ. Otherwise, if these Terms conflict with an Order, these Terms prevail; on matters of data protection and consent, the Data Processing Addendum prevails.
2.Key definitions
- Permitted User — an employee or contractor of the Customer whom the Customer authorises to use the Services.
- Output — any result, report, verified data or other content the Services return.
- Credits — prepaid service units held in the Customer's wallet and consumed as the Services are used.
- Personal Data, Data Principal, Data Fiduciary, Data Processor, Consent and Processing — as defined in the Digital Personal Data Protection Act, 2023 (the "DPDP Act").
- End User — a Data Principal whose Personal Data the Customer submits to, or collects through, the Services.
3.Accounts and access
- The Services are for businesses. You must be at least 18 and authorised to bind the Customer.
- Provide accurate account, business and billing information and keep it up to date.
- Login credentials, API keys and tokens are confidential. You are responsible for all activity under your account, and for ensuring only Permitted Users use the Services. We recommend enabling email-OTP multi-factor authentication for every dashboard user.
- Tell us immediately at contact@attestr.com if you suspect unauthorised access to your account, credentials or Outputs.
4.The Services
Attestr provides digital onboarding, e-KYC, business verification, background verification, risk assessment and monitoring, consent management and related data services, through the dashboard, APIs, SDKs and hosted journeys.
Many Outputs depend on government, statutory and other third-party data sources. Attestr retrieves and presents that information with reasonable skill and care, but does not control those sources and cannot guarantee their accuracy, completeness or availability. Outputs support your decisions; the decisions remain yours.
We may improve or change the Services from time to time. We will notify you in advance of any change that materially affects the Services you use, and plan its rollout accordingly.
5.Prepaid packs, fees and payment
- Prepaid model. Services are purchased as fixed-value prepaid packs, each specific to one service. On successful payment, the corresponding Credits are added to your wallet.
- Usage. Credits are deducted automatically from the relevant pack as you use that service.
- Validity. Credits are valid for one (1) year from the date of purchase. Unused Credits expire at the end of that year without refund or carry-forward, unless agreed otherwise in writing.
- No transfers. Credits in one service pack cannot be transferred to, exchanged for or used against any other service.
- Data storage. Storing verification data for longer than the free default period described in our Data Storage Policy requires a Data Storage Pack.
- No surprise renewals. We do not auto-renew a pack or increase the price of a purchased pack without your consent.
- Taxes. Fees are exclusive of GST and other applicable taxes, which are charged additionally. We issue GST-compliant tax invoices and report them as required. If you are required to deduct tax at source, pay the net amount and share the TDS certificate within a reasonable time.
- Invoiced customers. Where we invoice against a purchase order, undisputed invoices are payable within thirty (30) days. Raise any dispute in writing within seven (7) days of receiving the invoice, after which it is deemed accepted. Credits are added once the invoice is paid.
- Refunds. Fees for purchased packs are non-refundable except as required by law or agreed in writing.
6.Licence and intellectual property
Subject to these Terms and payment of fees, Attestr grants you a limited, non-exclusive, non-transferable, non-assignable and non-sublicensable licence for your Permitted Users to use the Services during your subscription.
The Services — including software, databases, methodologies, documentation, reports and the selection, arrangement and presentation of information in them — and all related intellectual property remain the exclusive property of Attestr and its licensors, even where an Output was built to your specifications. Each party keeps ownership of its own intellectual property; no other rights are granted.
7.Acceptable use
You may use the Services and Outputs only for your internal business purposes relating to verification, due diligence, compliance and fraud prevention, and for presentations to your own clients strictly for their internal verification and fraud-prevention purposes. You must not, and must ensure your Permitted Users do not:
- verify or monitor any individual without valid consent or another lawful basis;
- copy, sell, sublicense, publish, redistribute or commercially exploit Outputs or verified data, or share them with anyone other than Permitted Users, without our prior written consent;
- use Personal Data or Outputs for marketing, profiling or any purpose other than the authorised verification purpose;
- combine Outputs with third-party datasets for resale, data brokerage or enrichment, or attempt to re-identify masked, tokenised or anonymised data;
- scrape, reverse engineer, decompile, circumvent rate limits or security controls, or probe or test the Services' security without our written permission;
- use the Services to build a competing product or dataset; or
- use the Services in breach of any law, including the DPDP Act, the Information Technology Act, 2000 and any KYC or sector regulations that apply to you.
8.Data protection and consent
Roles
For End User Personal Data, you are the Data Fiduciary and determine the purpose and lawful basis of processing, the categories of data and the duration and validity of consent. Attestr acts solely as your Data Processor — and, where you opt for it, as a Consent Collection Facilitator — and processes Personal Data only on your documented instructions and only to provide the Services. Nothing in these Terms makes Attestr a Data Fiduciary or Joint Data Fiduciary.
Your consent obligations
- Obtain valid, informed, specific and freely given consent from each End User before initiating a verification, sharing Personal Data with Attestr, or accessing or storing results. The consent must cover the purpose, the data categories, the use of government, statutory or authoritative sources (such as DigiLocker, universities and government registries) — directly or through Attestr's authorised verification data partners — and the sharing of data with Attestr as your Data Processor.
- Send a consent assertion with every request, in the Consent Data & Input Schema described in our consent documentation. Requests without the required consent information may be rejected or suspended. We may revise the schema to stay compliant with the law, and you agree to adopt revisions within a reasonable time.
- Maintain complete, auditable consent records, and keep each consent valid for as long as the related processing continues.
- Attestr relies on your consent assertions in good faith and does not independently validate them. An incorrect or unlawful assertion is your sole responsibility.
Storage, retention and deletion
Personal Data is stored and deleted as described in our Data Storage Policy: single-use verifications are not retained in identifiable form; reusable consents are stored only on your request, encrypted, and never beyond the consent's validity. You can revoke consent and request deletion through the API or dashboard.
Data localisation
All data and documents generated as part of the Services are stored in India.
Everything else
Sub-processors, End User rights requests, audits, breach notification and the remaining data-protection terms are set out in our Data Processing Addendum, which forms part of these Terms.
9.Service levels and support
- The APIs return real-time responses, and Attestr targets more than 99% uptime, excluding planned maintenance and Force Majeure.
- We schedule updates for periods of low usage and give advance notice of planned downtime.
- Standard support hours are Monday to Friday, 9 AM to 6 PM IST. Critical and high-priority (P0/P1) issues are handled by phone and WhatsApp with a 4-hour response time, 24/7; other issues (P2–P4) through dashboard tickets or email with a 24-hour response time.
A signed agreement or Order may set specific service levels, which then apply.
10.Confidentiality
Each party will keep the other's confidential information confidential, use it only for the purposes of this agreement, protect it with at least reasonable, industry-standard care, and disclose it only as these Terms permit or the law requires. Attestr's confidential information includes the Services' details and software, your credentials, fees and pricing. On termination, or on request, each party will return or destroy the other's confidential information.
Neither party will announce or publicise the relationship without the other's prior written consent, except as required by law.
11.Warranties and disclaimers
Each party warrants that it is validly existing and that its acceptance of these Terms is duly authorised. Attestr warrants that it has the skills, systems and capability to provide the Services, holds the licences and approvals required to do so, and will apply commercially reasonable security measures to your data.
Except as expressly stated in these Terms, the Services and Outputs are provided on an "as is" and "as available" basis, and Attestr disclaims all other warranties to the fullest extent permitted by law.
12.Indemnities
You will indemnify Attestr, its officers, employees and affiliates against claims, losses, penalties, damages and regulatory actions — including legal costs, fines and compensation payable to Data Principals — arising from your failure to obtain or maintain valid consent, a misrepresented lawful basis, your unlawful use, disclosure, resale or retention of Personal Data, or your breach of the DPDP Act or other law.
Attestr will indemnify you against losses from any third-party claim that the Services or Outputs infringe that party's copyright, provided you notify us promptly and give us sole control of the defence and settlement.
13.Limitation of liability
To the maximum extent permitted by law: (a) neither party is liable for any loss of profit, revenue or business, or for any indirect, incidental, special or consequential loss; and (b) each party's total aggregate liability arising out of or in connection with the Services is limited to the fees paid by you to Attestr in the twelve (12) months before the event giving rise to the claim.
These limits do not apply to liability for fraud, wilful misconduct, gross negligence, breach of confidentiality, or death or personal injury caused by negligence, or to your obligations under the Acceptable Use and Data Protection sections and your indemnity above.
14.Term, suspension and termination
- These Terms apply from when you first use the Services until your account is closed or the agreement is terminated.
- Either party may terminate on thirty (30) days' written notice.
- Either party may terminate immediately if the other commits a material breach that is not cured within thirty (30) business days of written notice, or becomes insolvent or subject to insolvency or similar proceedings.
- Attestr may suspend or terminate access immediately where there is suspected misuse, a consent violation, a security risk or legal or regulatory exposure. We will work with you in good faith to resolve the issue before restoring access.
- On termination, your access ends and Credits are handled as set out in your Order or as mutually agreed. Your data is returned or securely deleted within ninety (90) days, or sooner on request, with written confirmation on request.
- Sections that by their nature should survive — including fees owed, intellectual property, data protection, confidentiality, indemnities and limitation of liability — survive termination.
15.Force majeure
Neither party is liable for delay or failure caused by events beyond its reasonable control — including governmental action, war, civil unrest, terrorism, pandemic, natural disaster, strikes, or failure of communication or computer systems on which the Services depend. If a force majeure event substantially prevents performance for sixty (60) consecutive days, either party may terminate. Force majeure does not excuse payments already due.
16.Governing law and disputes
These Terms are governed by the laws of India. The parties will first try to resolve any dispute through discussion between senior executives. If it is not resolved, either party may refer it to arbitration by a sole arbitrator appointed under the Arbitration and Conciliation Act, 1996. The seat and venue of arbitration is Hyderabad, and the proceedings will be in English. Subject to arbitration, the courts at Hyderabad, Telangana have exclusive jurisdiction.
17.Using our website
Content on attestr.com is for general information and may change without notice. You may not scrape or systematically copy it, or use it in a way that damages or disrupts the website. Links to third-party sites are provided for convenience; we are not responsible for their content.
18.General
- Changes. We may update these Terms. We will post the updated Terms here and notify account holders of material changes in advance by email or in the dashboard. Continued use after changes take effect means you accept them.
- Relationship. The parties are independent contractors; nothing creates a partnership, agency or joint venture.
- Assignment. You may not assign these Terms without our written consent.
- Severability and waiver. If a provision is unenforceable, the rest remains in effect. Not enforcing a right is not a waiver of it.
- Notices. Send notices to Attestr at contact@attestr.com and 8-2-293/K/57/101, Kamalapuri Colony Phase 3, Hyderabad, Telangana 500073, India. We send notices to your account email.
19.Contact
Pegadroid IQ Solutions Private Limited (CIN U74999TG2017PTC118280), 8-2-293/K/57/101, Kamalapuri Colony Phase 3, Hyderabad, Telangana 500073, India. Email contact@attestr.com.