OCR-RUN
DPDP Act, 2023 · Compliance ArchitectureNotice #v2.0-2026

Digital Personal Data Protection & Governance

This document outlines how processes, protects, and governs personal data in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules framed thereunder.

Last revision: 29 July 2026Grievance SLA: ≤ 72 hoursJurisdiction: the courts of India

1. Overview & Statutory Framework

The Digital Personal Data Protection Act, 2023 establishes a comprehensive legal regime in India for the processing of digital personal data. As a Data Fiduciary, we uphold the core principles of purpose limitation, data minimization, storage limitation, and demonstrable accountability.

Free & Affirmative
Consent is granular and never pre-ticked. Optional purposes require clear affirmative opt-in.
Zero Third-Party Ads
We do not sell, rent, or trade your data. Customer documents are never used to train public models.
Automated Purging
Document blobs and extracted outputs are expunged automatically according to your plan schedule.

2. Data Fiduciary & Data Protection Officer (DPO)

Pursuant to Section 8 and Section 9 of the DPDP Act, the details of the Data Fiduciary and its designated Grievance Officer / Data Protection Officer are published below:

Data FiduciaryRegistered office in India
Data Protection Officer (DPO)Grievance & Compliance OfficeEmail: dpo@deepsoch.aiStatutory Redressal SLA: Within 72 hours

3. Data Collection & Minimization

In accordance with Section 6(1) of the DPDP Act, we only collect personal data that is strictly necessary for the specified purpose of providing high-performance document parsing and verification runtimes.

Data We Collect

  • Account Identifiers: Name, email address, password hash (Argon2id), and authentication tokens.
  • Uploaded Documents: PDF files, images, and scanned identity artifacts submitted for OCR processing.
  • Accounting & Operational Metrics: Request ID, timestamp, HTTP status, page counts, output tokens, and execution latency.
  • IP Addresses: Kept strictly for abuse prevention, security defense, and rate-limiting. Automatically purged after 30 days.

Data We Never Collect or Process

  • We never perform biometric identification or facial recognition profiling.
  • We do not set third-party cross-site advertising trackers or tracking pixels without active affirmative consent.
  • We never sell or distribute uploaded documents to external brokers or data brokers.

4. Specified Purposes of Processing

Under DPDP Act Section 6, personal data may only be processed for the specific lawful purpose for which the Data Principal has given consent:

1. Core Runtime & AuthenticationMandatory

Verifying API credentials, executing OCR transformations, maintaining session security, and generating GST-compliant tax invoices.

2. Model Performance & Error TelemetryOptional Opt-In

Analyzing aggregated OCR failure codes and API latency patterns to improve model accuracy and pipeline reliability.

3. Security Advisories & Compliance NotificationsOptional Opt-In

Notifying registered developers of security advisories, major model upgrades, or regulatory privacy policy amendments.

5. Technical & Organizational Safeguards

Section 8(5) of the DPDP Act mandates reasonable security safeguards to prevent personal data breaches:

  • Encryption in Transit & At Rest: All traffic is encrypted using TLS 1.3. Object storage for uploaded documents is protected by authenticated encryption.
  • Key Hashing: API keys are hashed with HMAC-SHA256 and server-side secret peppers. Plaintext keys are never stored in the database.
  • Zero-Plaintext Consent Logs: User consent decisions are logged with pseudonymous HMAC hashes rather than plaintext PII.
  • Isolated Environments: Production parsing sandboxes operate in ephemeral, stateless container environments.

6. Data Principal Rights (Interactive Workflows)

Under Chapter III of the DPDP Act, you possess clear, enforceable statutory rights. You can directly exercise your rights to data export, consent withdrawal, or irreversible erasure using the interactive tools below:

Right to Access & Portability
Section 11
Download your full structured personal data archive (profile, API keys, usage metrics, and consent ledger) as machine-readable JSON.

Signed out. Sign in for complete account data.

Right to Correction & Erasure
Section 12
Irreversibly erase your identity, sessions, API credentials, and historical IP logs in accordance with the Right to be Forgotten.
Right to Modify or Withdraw Consent
Section 6(4)
You have the unconditional right to withdraw consent with the same ease with which it was given.

Sign in to review or change your consent preferences.

7. Data Retention & Storage Limitation

In compliance with Section 8(7) of the DPDP Act, personal data is not retained beyond the period necessary to satisfy the purpose for which it was processed, except where statutory Indian law mandates preservation.

Subscription Tier / CategoryDocument Retention Window
Free and signed-out1 day
Starter7 days
Pro14 days
Business30 days
Abuse Investigation IP Addresses30 days (auto-blanked)
Tax Invoices (CGST Act Section 36)72 months (statutory requirement)

8. Data Processors & Sub-Processors

We engage specialized data processors bound by strict confidentiality and data protection agreements under Section 8(2) of the DPDP Act:

RazorpayPayment Gateway (RBI compliant)
Self-Hosted StorageEncrypted Document Runtime
Transactional SMTPAccount Verification & Invoicing

9. Grievance Redressal & Appellate Escalation

If you have questions, concerns, or grievances regarding your personal data or consent choices, you may submit a formal complaint directly to our Grievance Officer: