Digital Personal Data Protection & Governance
This document outlines how — processes, protects, and governs personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules framed thereunder.
1. Overview & Statutory Framework
The Digital Personal Data Protection Act, 2023 establishes a comprehensive legal regime in India for the processing of digital personal data. As a Data Fiduciary, we uphold the core principles of purpose limitation, data minimization, storage limitation, and demonstrable accountability.
2. Data Fiduciary & Data Protection Officer (DPO)
Pursuant to Section 8 and Section 9 of the DPDP Act, the details of the Data Fiduciary and its designated Grievance Officer / Data Protection Officer are published below:
3. Data Collection & Minimization
In accordance with Section 6(1) of the DPDP Act, we only collect personal data that is strictly necessary for the specified purpose of providing high-performance document parsing and verification runtimes.
Data We Collect
- Account Identifiers: Name, email address, password hash (Argon2id), and authentication tokens.
- Uploaded Documents: PDF files, images, and scanned identity artifacts submitted for OCR processing.
- Accounting & Operational Metrics: Request ID, timestamp, HTTP status, page counts, output tokens, and execution latency.
- IP Addresses: Kept strictly for abuse prevention, security defense, and rate-limiting. Automatically purged after 30 days.
Data We Never Collect or Process
- We never perform biometric identification or facial recognition profiling.
- We do not set third-party cross-site advertising trackers or tracking pixels without active affirmative consent.
- We never sell or distribute uploaded documents to external brokers or data brokers.
4. Specified Purposes of Processing
Under DPDP Act Section 6, personal data may only be processed for the specific lawful purpose for which the Data Principal has given consent:
Verifying API credentials, executing OCR transformations, maintaining session security, and generating GST-compliant tax invoices.
Analyzing aggregated OCR failure codes and API latency patterns to improve model accuracy and pipeline reliability.
Notifying registered developers of security advisories, major model upgrades, or regulatory privacy policy amendments.
5. Technical & Organizational Safeguards
Section 8(5) of the DPDP Act mandates reasonable security safeguards to prevent personal data breaches:
- Encryption in Transit & At Rest: All traffic is encrypted using TLS 1.3. Object storage for uploaded documents is protected by authenticated encryption.
- Key Hashing: API keys are hashed with HMAC-SHA256 and server-side secret peppers. Plaintext keys are never stored in the database.
- Zero-Plaintext Consent Logs: User consent decisions are logged with pseudonymous HMAC hashes rather than plaintext PII.
- Isolated Environments: Production parsing sandboxes operate in ephemeral, stateless container environments.
6. Data Principal Rights (Interactive Workflows)
Under Chapter III of the DPDP Act, you possess clear, enforceable statutory rights. You can directly exercise your rights to data export, consent withdrawal, or irreversible erasure using the interactive tools below:
7. Data Retention & Storage Limitation
In compliance with Section 8(7) of the DPDP Act, personal data is not retained beyond the period necessary to satisfy the purpose for which it was processed, except where statutory Indian law mandates preservation.
| Subscription Tier / Category | Document Retention Window |
|---|---|
| Free and signed-out | 1 day |
| Starter | 7 days |
| Pro | 14 days |
| Business | 30 days |
| Abuse Investigation IP Addresses | 30 days (auto-blanked) |
| Tax Invoices (CGST Act Section 36) | 72 months (statutory requirement) |
8. Data Processors & Sub-Processors
We engage specialized data processors bound by strict confidentiality and data protection agreements under Section 8(2) of the DPDP Act:
9. Grievance Redressal & Appellate Escalation
If you have questions, concerns, or grievances regarding your personal data or consent choices, you may submit a formal complaint directly to our Grievance Officer:
Email: dpo@deepsoch.ai
Turnaround SLA: All grievances receive formal acknowledgment within 24 hours and resolution within 72 hours.
Under Section 13 of the DPDP Act, if your grievance is not resolved satisfactorily, you have the right to register a complaint with the Data Protection Board of India.