DPDP disclosures
The Digital Personal Data Protection Act, 2023 sets out how personal data must be handled in India. This page states how VerifyBG meets it, and is honest about what is still in progress.
Our role
For subject data, the requester who raises a check is the Data Fiduciary deciding the purpose. VerifyBG acts as a Data Processor executing that check, and as a Data Fiduciary in its own right for the account data of requesters.
Lawful basis
We rely on consent, and only consent. There is no legitimate-interest processing of subject data on this platform. See the consent framework for exactly how it is obtained and recorded.
Notice
Subjects are shown an itemised, plain-language notice of every check category before they sign, along with the retention period and their rights. The notice is not buried in a link or a scrollbox.
Data principal rights, and how to use them
- Right to access: account holders can download a complete machine-readable export from the dashboard, with no request form or waiting period.
- Right to correction: any finding can be disputed from the report, and the dispute is permanently attached to it.
- Right to erasure: requesting deletion schedules all your data for the next purge run.
- Right to withdraw consent: a subject may withdraw at any time. Withdrawal is recorded, stops all further processing immediately, and schedules the data for deletion.
- Right to grievance redressal: write to our contact page.
Cross-border transfer
Sanctions, PEP and adverse-media screening is performed by Didit, a provider based outside India. Performing that check necessarily transfers the subject's name, and where supplied their date of birth and an identifier, outside the country. We send only the fields required to perform the match, and never the results of other checks, the stated purpose, or the requester's identity.
This transfer happens under the same consent that authorises the check itself. A subject who does not consent has nothing transferred, because no check runs at all. The provider is named here rather than described generically so that a data principal can look them up and make their own judgement.
Corporate registry verification queries GLEIF, an international register, which likewise involves sending the supplied identifier or company name outside India. All other checks, including identifier structural validation and the locally held sanctions lists, run entirely on our own servers.
Data minimisation in practice
We collect only the fields a requester enters, and only the checks the chosen tier includes. A subject's PAN is used to perform the identity check but is never sent back to the requester's browser. Data exports exclude raw third-party responses, because those can contain information about people other than the person exporting.
Retention
A fixed 30 day clock starts when a request is created. An automated sweep purges subject identifiers, check results and raw source responses once it expires, and anonymises the consent record while keeping proof that consent existed.
Security measures
- Passwords hashed with bcrypt at cost factor 12.
- Sessions in signed httpOnly cookies, unreadable by client-side script.
- HTTPS enforced, with HSTS and a restrictive content security policy.
- Rate limiting on authentication, consent and request creation.
- Record access scoped by ownership at the database query level, so one account cannot address another's records.
- Random tokens for consent and share links, with expiry and revocation on shares.
What is not yet in place
We would rather state this than imply completeness we have not reached:
- Consent is authenticated by an email one-time code where an address is available, and by a typed signature otherwise. Neither is Aadhaar eSign; that integration is planned, and every record states which method was actually used.
- Breach notification currently runs as a manual process, not an automated pipeline.
- Registry lookups (PAN, MCA, GST) against government records are not yet connected to a licensed data provider. Identity and GST checks currently validate structure and check digits offline, which catches fabricated identifiers but does not confirm them against the registry. Reports state this on every such result.
- Disputes and withdrawals are actioned by a named administrator through an internal console, not automatically. Every such action is recorded against that person in the audit log.
- We have not yet completed an independent third-party security audit.
Grievance officer
The grievance officer for Bitola Industries Pvt Ltd can be reached through our contact page. We aim to acknowledge within 72 hours.