Legal

PRIVACY
POLICY.

Last updated: 1 August 2026  ·  Effective: 1 August 2026

1. Who we are

Veriflow ("we", "our", "us") is a verification infrastructure platform operated from Bengaluru, India. Our registered address is available on request at [email protected]. We are an Authentication User Agency (AUA) and KYC User Agency (KUA) licensed by UIDAI.

2. Scope

This policy applies to personal data we process when you use veriflow.in, our APIs, our dashboard, and our verification services. It covers data relating to our customers (businesses that integrate Veriflow) and end-users (individuals whose data is verified through our platform).

3. Data we collect

From customers (API integrators):

  • Company name, business email, GST number, billing details
  • API usage logs (endpoint, timestamp, response code — no PII)
  • Dashboard activity and configuration preferences

From end-users (verification subjects):

  • Identity data submitted for verification (Aadhaar number hash, PAN, bank account details)
  • Biometric data for face match (processed in real time, not stored beyond delivery)
  • DigiLocker documents pulled under explicit user consent
  • Consent timestamp, purpose, and IP address (required under DPDP Act 2023)

4. Legal basis for processing

We process personal data on the following bases under the Digital Personal Data Protection Act 2023 and applicable Indian law:

  • Consent — all Aadhaar OTP and DigiLocker operations require explicit, logged consent from the data principal.
  • Contractual necessity — API account data is processed to deliver the service under our Terms of Service.
  • Legal obligation — audit logs are retained as required by RBI KYC Master Directions and IT Act 2000.

5. Data retention

Verification PII is not stored by Veriflow after delivery to the integrating business unless the customer has opted into audit-log retention. Where opted in, encrypted PII is retained for the period specified in the customer's service agreement (default 90 days). Consent logs are retained for 7 years to meet regulatory requirements.

6. Data residency

All personal data is processed and stored exclusively on AWS ap-south-1 (Mumbai). No personal data is transferred outside the Republic of India. Enterprise customers may request dedicated VPC deployment.

7. Your rights under DPDP Act 2023

As a data principal, you have the right to: access your data, correct inaccurate data, withdraw consent, obtain a summary of processing, and nominate a nominee. Submit requests to [email protected]. We respond within 72 hours.

8. Cookies

Our marketing website uses only essential cookies (session, CSRF). We do not use advertising or tracking cookies. Our API and dashboard do not set cookies on end-user devices.

9. Contact

Data Protection Officer: Siddharth Kumar · [email protected] · +91-80-XXXX-XXXX

Grievance Officer (as required under IT Act 2000 and DPDP Act 2023): [email protected]. Response within 30 days.

DPDP Act 2023
RBI KYC Directions
UIDAI AUA / KUA
ISO 27001
IT Act 2000