Privacy policy

VerifyBG is operated by Bitola Industries Pvt Ltd. This policy explains what we collect, why, and what we do with it. It is written to be read, not to be skipped.

Who the data is about

There are two people in every verification: the requester, who holds an account with us, and the subject, the person being checked. We hold data about both, and both have rights over it.

What we collect

Consent comes first, always

No check runs, and no data about a subject is fetched from any source, until that subject signs a consent form. This is enforced by our servers on every request, not merely by the design of the interface. A requester cannot bypass it.

How long we keep it

Personal data behind a verification is deleted automatically 30 days after the request is raised. After deletion we retain a record that the verification happened and its audit log, with the personal details stripped out, because a compliance log that vanishes along with the data it describes cannot evidence anything.

Who we share it with

Identity and GST structural validation is performed entirely on our own servers, and no subject data leaves our systems for those checks.

Sanctions, PEP and adverse-media screening sends the subject's name, and where supplied their date of birth and identifier, to Didit, a screening provider headquartered outside India. This is what allows us to screen against more than 1,300 published watchlists rather than the two we can hold locally. Only the fields needed to perform the match are sent; we do not send the requester's identity, the stated purpose, or the results of any other check. Where that provider is unavailable we fall back to lists held on our own servers, and the report says so.

Corporate registry checks send the supplied company identifier or name to GLEIF, the Global Legal Entity Identifier Foundation. News screening, when the primary provider is not in use, sends the subject name to GDELT, a public news index.

We send subject identifiers to the verification data sources we are connected to, purely to perform the checks that were consented to. We do not sell personal data, we do not share it for advertising, and we do not build profiles beyond the specific report that was requested.

Your rights under the DPDP Act, 2023

Security

Passwords are hashed with bcrypt. Sessions are held in signed, httpOnly cookies that JavaScript cannot read. The site is served over HTTPS only. Consent and report share links use cryptographically random tokens rather than guessable identifiers, and share links expire.

Accuracy, stated plainly

Court and criminal record data in India is matched by name and whatever identifiers are available. At India's population scale this produces genuine false matches on common names. Every match we show carries a confidence score, low confidence matches are flagged rather than buried, and we tell you when a check could not be run at all rather than implying the subject came back clear.

Contact

For any privacy question, or to exercise a right described here, write to our contact page.