Privacy policy
How Connexolve collects, uses, retains, and protects personal data — written for the Digital Personal Data Protection Act, 2023 (DPDP) and aligned with RBI's data localisation guidelines.
Effective 09 June 2026 · Version 1.0
01Who we are
This Privacy Policy applies to services operated by Connexolve Infotech Private Limited ("Connexolve", "we", "us", "our"), a company incorporated in India under CIN U62011WB2026PTC287766, with registered office at 4-FR, FL-4C, 83 S.P. Mukherjee Road, Kalighat, Kolkata 700026, West Bengal, India.
Connexolve is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 for the personal data processed through our APIs and platform.
02Whose data we process
Connexolve does not market services directly to individual consumers. Personal data we process belongs to three categories of Data Principals:
- Verification subjects — individuals or entities whose data our business customers submit to us for verification. Their consent is collected by our customers before submission.
- Account holders — individuals who register and operate Connexolve accounts on behalf of a business (developers, administrators, billing contacts).
- Website visitors — anyone who visits our documentation, marketing, or console websites.
03Personal data we collect
From verification subjects (via our customers)
Only the identifiers required for the specific verification requested. Examples by category:
- Identity: PAN, Aadhaar reference (no Aadhaar number stored), driving licence number, voter ID (EPIC) number, passport file number, date of birth, photograph (where the source returns one)
- Employment: Universal Account Number (UAN), establishment ID, employer name, mobile number
- Company / business: CIN, LLPIN, DIN, TAN, GST, Udyam Registration Number, IEC, Shop & Establishment number
- Financial: bank account number, IFSC, credit bureau identifiers (with explicit consent)
- Vehicle & utility: registration number, engine/chassis number, electricity consumer ID, property tax assessment number
- Document & biometric: images submitted for forgery detection, face liveness, or face-match checks
We do not store Aadhaar numbers. Where Aadhaar-linked data is required (e.g. eKYC via DigiLocker), processing happens on a transient, no-storage basis using user-consented flows from DigiLocker's authorised channels.
From account holders
Name, work email, company affiliation, role, billing address, GSTIN, payment instrument details (held by our PCI-DSS-compliant payment processors, not by Connexolve).
From website visitors
IP address, browser user-agent, pages visited, and standard analytics events. We do not use third-party advertising cookies or cross-site tracking.
04How we use personal data
We process personal data only for the purposes for which it was provided:
- To perform the verification requested by our customer (the lawful and contracted purpose)
- To return the verification result to the requesting customer
- To detect and prevent fraud, security incidents, and abuse of our platform
- To bill, audit, and comply with tax, anti-money-laundering, and other legal obligations
- To provide customer support and respond to grievances
- To improve service quality through aggregated, de-identified analytics
We do not use personal data for advertising, profiling beyond the verification purpose, or any secondary commercial use.
05How we share personal data
Personal data flows through a defined and limited chain:
- Authorised data sources — to perform a verification, we route the request through licensed API providers who in turn query the relevant government registry (UIDAI, EPFO, MCA, Income Tax Department, RTOs, ECI, DGFT, NSDL, state Shop & Establishment registries, RBI-licensed credit bureaus, etc.). Each data source has its own consent and processing terms.
- Cloud infrastructure providers — our servers and databases run in Indian data regions. We do not store personal data outside India.
- Payment processors — for billing, we use RBI-licensed payment processors (e.g. Razorpay). They process payment instrument data under their own PCI-DSS-compliant terms.
- Government and law enforcement — only on receipt of a legally valid order, summons, or formal request from an authorised Indian authority.
We do not sell or rent personal data. We do not share data with advertising or analytics platforms.
06Data retention
| Data type | Retention | Reason |
|---|---|---|
| Verification request body and response | 30 days | Operational — dispute resolution, debugging, customer support |
| Verification metadata (timestamps, status, endpoint, verification ID) | 7 years | Audit and statutory record-keeping |
| Billing and tax records | 7 years | Companies Act, 2013 and Income Tax Act statutory retention |
| Account holder profile | For the duration of the account, plus 90 days after closure | Reactivation window; then deleted |
| Security logs (IP, user-agent, error events) | 180 days | Security incident investigation |
| Anonymised analytics | Indefinite | Stripped of all personal identifiers |
After the retention period expires, personal data is deleted or irreversibly anonymised within 30 days.
07Your rights as a Data Principal
Under the DPDP Act, you have the right to:
- Access the personal data Connexolve holds about you
- Correct, update, or complete inaccurate or incomplete personal data
- Erase personal data we no longer have a lawful basis to retain
- Withdraw consent previously given for processing (note: this does not affect verifications already completed)
- Nominate another individual to exercise these rights in case of your death or incapacity
- Lodge a complaint with the Data Protection Board of India
To exercise any of these rights, contact our Grievance Officer (details on the Grievance page). We respond within 7 working days and resolve within 30 days at the outer limit.
08Security
We apply appropriate technical and organisational measures to safeguard personal data:
- TLS 1.2+ encryption for all data in transit
- AES-256 encryption for verification data at rest
- Role-based access controls with least-privilege defaults
- Audit logging on every personal-data access
- Regular security reviews and penetration testing
- Server infrastructure in Indian data centres only
09Children's data
Our platform is not directed at children. We do not knowingly process personal data of any individual under 18 years of age. If we become aware that we have processed such data without verifiable parental consent, we will delete it promptly.
10Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified to account holders by email and posted at this URL with a revised effective date. The version history is maintained in our internal compliance log.
11Grievance redressal
For questions or complaints about how Connexolve handles personal data, contact our Grievance Officer:
Grievance Officer
Name: Priyanka Gupta, Director
Email: grievance@connexolve.in
Postal address: Connexolve Infotech Private Limited, 4-FR, FL-4C, 83 S.P. Mukherjee Road, Kalighat, Kolkata 700026, West Bengal, India
We acknowledge complaints within 48 hours and resolve them within 30 days. Detailed escalation procedure is available at our Grievance page.