The Future Of Digital Trust Is Being Built Today.

1. Introduction

Authenticate India Innovations Pvt. Ltd. and its affiliated entities ("AuthenticateIndia", "Company", "we", "our", or "us") are committed to protecting privacy, safeguarding personal data, and maintaining transparent processing practices.

This Privacy Policy explains how AuthenticateIndia collects, handles, stores, uses, discloses, transfers, retains, secures and otherwise processes personal data when you access or use the AuthenticateIndia website, mobile application, APIs, onboarding systems, dashboards, verification tools and related services (collectively, the “Platform”).

This Policy should be read together with any specific consent notice, service-specific terms, onboarding disclosure or other notice presented for a particular Requested Service.

2. Scope

  • Individual users
  • Business / organization users
  • Agents / referral partners
  • Merchants / enterprise customers
  • Website visitors
  • API users and authorized representatives

This Policy does not apply to independent third-party websites, gateways or services linked from the Platform. Users should review their applicable third-party privacy notices.

3. Personal Data We May Process

Category Examples
Personal Identification Name, mobile, email, signature, date of birth, identity/residence identifiers such as Aadhaar or other officially valid documents, PAN and related information.
Contact Phone, email, state, city and location details.
Business / Organization Company/business details, business category, operational location and authorized representative information.
KYC / Verification OTP status, Video KYC submissions, document status, validation and verification responses.
Financial Bank account details for agents and transaction/payment information where applicable.
Online Activity Location, IP address, device/operating-system information, browser/device metadata and technical usage data.
Communication Chats, emails, telephone conversations, grievances and other correspondence.
Activity Action logs, transaction logs and verification transaction logs.
Commercial / Support Billing records, invoices, reconciliation information and support requests.
Security Security event logs, anti-fraud signals and security-related information.
Referral Referral codes and referrer details where provided.

4. Information Provided During Registration / Onboarding

4.1 Individual Users

  • Mobile number and OTP verification status
  • Name where lawfully obtained through an authorized verification workflow
  • Email address
  • City / location
  • Video KYC submissions where applicable
  • Consent acknowledgements
  • Referral code/referrer details where applicable
  • Identity, residence and other information required for the Requested Service

4.2 Organization / Business Users

  • Authorized person's mobile number and OTP status
  • Authorized person's name
  • Company/business details
  • Business category
  • City/operational location
  • Email address
  • Video KYC of authorized representative where applicable
  • Consent acknowledgements
  • Referral details where applicable

5. Information Generated Through Platform Use

  • Login history
  • Device/browser metadata
  • IP address
  • Timestamps
  • Activity logs
  • Verification transaction logs
  • Billing records
  • Support requests
  • Security event logs

6. Information From Third Parties

Where lawfully enabled and required for service delivery, we may receive information from affiliates, vendors, verification agencies, regulators, governmental authorities or other authorized sources, including:

  • Payment confirmations
  • KYC workflow responses
  • API service status data
  • Anti-fraud signals
  • Public or authorized data responses

Personal data may also be collected directly from you, from affiliates or third parties, or from publicly accessible sources where permitted by applicable law.

7. Government / Verification Data and Data Minimization

  • Full government-source records are not intended for persistent storage unless legally required, contractually necessary, technically essential or expressly disclosed.
  • Verification transactions may be stored as activity evidence, request logs, reference IDs, timestamps or status records.
  • Results may be processed transiently to complete the Requested Service.
  • Records may be retained where necessary for audit, security, fraud prevention, legal compliance, contractual obligations or dispute resolution.

8. Purposes of Processing

Purpose Examples / Use Cases
Verification & Authentication Identity verification, e-KYC, document status/validation and contact verification.
Registration & Account Management Account creation, onboarding and service administration.
OTP & Video KYC Authentication and review of applicable KYC submissions.
Legal / Regulatory Compliance Regulatory reporting, audits, supervisory reviews, legally required disclosures, data audits and related compliance activities.
Expiry Reminders Document expiry analysis and renewal reminders.
Fraud & Security Crime/fraud prevention, identity-theft prevention, unauthorized-transaction prevention, security monitoring and risk assessment.
Customer Support Customer service and communications by email, chat, telephone and other means.
Billing / Reconciliation Billing, invoicing, payment confirmations and reconciliation.
Audit Trail Maintaining activity, transaction and security evidence.
Product Improvement Product improvement, performance and analytics subject to applicable law.
Communications OTPs, alerts, security notifications, billing messages, policy updates and service notices.
Rights / Disputes Enforcing or defending legal/regulatory rights, handling claims, legal notices and disputes.

9. Legal Basis / Grounds

  • User consent where required
  • Performance of contract or steps requested before contract
  • Compliance with legal obligations
  • Permitted legitimate business purposes such as security, fraud prevention and service administration
  • Authorized enterprise-customer instructions
  • Other processing permitted or required by applicable law

Where consent is required, users may withdraw it subject to legal, contractual and operational limitations.

10. Data Sharing / Disclosure

Recipient Purpose
Regulatory / Statutory Authorities Legal and regulatory compliance, required reporting, audit trails and supervisory reviews.
Government / Law Enforcement Lawful requests, legal notices, court orders and legally required disclosures.
Technology / Hosting / Cloud Providers Secure storage, infrastructure, technology support and service delivery.
Payment Aggregators / Gateways / Systems Processing transactions initiated by users and related confirmations.
Verification / KYC / Contact Verification Agencies Identity, authenticity and contact verification.
Fraud / Risk Providers Fraud prevention, identity-theft prevention and risk assessment.
Legal / Advisory Professionals Legal, audit, tax, compliance and dispute matters.
Courts / Dispute Forums Legal notices, court orders and dispute resolution.
Enterprise Customers Where you are their authorized user and disclosure is necessary for the enterprise service.
Affiliates / Agents / Support Teams Supporting Requested Services in accordance with law and internal controls.

Some third parties receiving data may have independent legal obligations to provide notices or obtain consent. Users should review their privacy notices where applicable.

11. Cross-Border Processing

Some vendors or infrastructure providers may process data outside your state or country, subject to contractual safeguards and applicable law.

12. Cookies & Similar Technologies

  • Login sessions
  • Security
  • Preferences
  • Performance analytics
  • Fraud detection

Users may manage browser cookie settings, although some features may be affected.

13. Security Measures

  • Encryption in transit and at rest
  • Restricted role-based access
  • Secure authentication controls
  • Administrative monitoring and audit logging
  • Tamper-resistant controls
  • Secure backup procedures
  • Incident response processes
  • Vendor security reviews

No system is completely immune from risk; AuthenticateIndia continually strengthens its technical and organizational controls.

14. Data Storage & Retention

We retain personal data only for as long as reasonably necessary for the relevant purposes, contractual obligations and applicable legal requirements.

  • Account maintenance
  • Security monitoring
  • Fraud prevention
  • Contractual obligations
  • Legal/regulatory compliance
  • Tax and accounting records
  • Internal audits
  • Dispute resolution
  • Audit and evidentiary requirements

Retention duration varies by data category and purpose. After expiry, data may be deleted, anonymized, archived or securely restricted, subject to legal obligations.

15. Data Protection Principles

  • Lawfulness and fairness
  • Purpose limitation
  • Data minimization
  • Accuracy where relevant
  • Storage limitation
  • Security and confidentiality
  • Accountability

16. User Rights & Choices

  • Access to certain personal information
  • Access, update and review of personal data
  • Correction of inaccurate data
  • Update of profile details where allowed
  • Erasure where applicable
  • Withdrawal of consent where processing is consent-based
  • Account closure requests
  • Clarification regarding processing practices
  • Nomination of another individual to exercise applicable rights where permitted by law, including incapacity
  • Raise grievances

Some records may be non-editable or may not be erasable where required for audit integrity, fraud prevention, compliance, security or evidentiary purposes.

17. Account Data Integrity Controls

Certain onboarding, consent, transaction and verification records may be stored in controlled or non-editable formats to preserve audit reliability, transaction integrity, fraud prevention and compliance defensibility. Profile updates may be permitted only through approved workflows.

18. Consent Withdrawal

Where processing is based on consent, you may withdraw consent through the consent-management mechanism made available by AuthenticateIndia, including Consent Connect where provided.

Withdrawal does not affect the lawfulness of processing performed before withdrawal. If consent is necessary for a Requested Service, withdrawal may prevent continued provision of that service or maintenance of the related account.

Withdrawal may result in discontinuation or closure of the relevant service/account and may affect linked services, credits, Platform access, standing instructions or other benefits/obligations, subject to applicable terms and law.

19. Grievance Redressal

Contact Details
Data Protection Officer / Privacy Contact Kaushal Patel
Email team@aiipl.org
Mobile +91-8238413839
Address B-4, Miraj Business Centre, Opp. Cinemall, Nr. Natubhai Circle, Vadodara-390007, Gujarat, India
Subject Privacy Request / Grievance

If you are not satisfied with the resolution, you may pursue any complaint or remedy available under applicable law before the competent authority or forum.

20. Communications

  • OTPs
  • Account alerts
  • Security notifications
  • Billing messages
  • Important policy updates
  • Service notices
  • Marketing communications, where applicable, with opt-out options

21. Children's Privacy

The Platform is not intended for children below the age permitted by applicable law to independently contract or consent. If minor data is identified as having been collected without a lawful basis, reasonable steps may be taken to address or remove it, subject to applicable law and retention requirements.

22. Third-Party Links

The Platform may link to third-party websites or tools. AuthenticateIndia is not responsible for independent third-party privacy practices. Users should review their policies separately.

23. Data Breach / Security Incidents

In the event of a material security incident, AuthenticateIndia may take appropriate remedial measures including containment, investigation, risk mitigation, notifications where legally required and corrective action.

24. Consent & Acknowledgment

Where a consent notice or checkbox is presented, by providing consent the user acknowledges:

  • They have read and understood the applicable Notice and consent to processing described in it.
  • Consent is provided voluntarily without coercion or improper influence.
  • They will provide and, where applicable, help maintain accurate, updated, complete and consistent personal data.
  • AuthenticateIndia may process data for certain purposes without consent where applicable law permits or requires, including legal claims and regulatory disclosures.
  • Withdrawal of consent may affect services where consent is necessary.

The applicable consent statement may be made available in a preferred local language where such facility is provided.

25. Changes to This Policy

AuthenticateIndia may revise this Policy periodically. Updated versions become effective upon publication or notice through the Platform unless a different effective date is stated. Continued use after an effective update constitutes acknowledgment to the extent permitted by applicable law.

26. Contact / Privacy Requests

Field Details
Company Authenticate India Innovations Pvt Ltd
Address B-4, Miraj Business Centre, Opp. Cinemall, Nr. Natubhai Circle, Vadodara-390007, Gujarat, India
Email team@aiipl.org
Mobile +91-8238413839
Website www.authenticateindia.com
Subject Line Privacy Request

27. Relationship With Specific Consent Notices

This is the consolidated Platform-level Privacy Policy. For a specific verification, authentication, KYC or other Requested Service, AuthenticateIndia may provide a separate notice and request for consent describing the relevant data, purposes, recipients, rights and consent choices. Such notice should be read together with this Policy.

28. Document Control

Field Value
Document Privacy Policy – Consolidated Privacy Policy & Data Processing Notice
Document ID AI-PPL-2026-0001-2.0
Supersedes AI-PPL-2026-0001-1.0
Effective / Issue Date 24 September 2026
Issued By Kaushal Patel
Organization Authenticate India Innovations Pvt. Ltd.
Review Periodically and upon material changes