Data Policy — How VerifiedApostille Handles KYC & Document Data
Learn how VerifiedApostille collects, stores, and protects your KYC details and soft copies of submitted documents under Indian law (IT Act 2000/2008 & the DPDP Act 2023), and why we never sell your data.
Effective date:
This Data Policy explains how Verifiedapostille Attestation Services Private Limited (“we”, “us”, or “our”) collects, stores, uses, and protects the personal data, KYC (Know Your Customer) details, and soft copies of documents you submit while using our apostille and attestation facilitation services. It should be read together with our Privacy Policy and Terms & Conditions.
1) What data we collect
- KYC details — your name, address, phone number, email, and identity details (e.g., Aadhaar, PAN, passport number) required to process your case and comply with government/embassy requirements.
- Soft copies of submitted documents — scanned or photographed copies of certificates (educational, personal, commercial) you upload or send to us for notarisation, apostille, or attestation.
- Order & communication data — order IDs, quotations, invoices, consent records, and messages exchanged with our support team.
- Basic technical data — limited usage/log data as described in our Privacy Policy and Cookie Policy.
2) Why we collect it
We collect and process this data solely to:
- Verify your identity and the authenticity of the documents you submit.
- Prepare, track, and complete Notary → SDM → MEA (and, where applicable, embassy) processing steps on your behalf.
- Generate quotations, invoices, consent letters, and other case-related paperwork.
- Communicate updates about your order and respond to support queries.
- Meet legal, regulatory, and audit obligations under Indian law.
3) Legal basis & applicable Indian law
Our handling of your KYC details and document copies is governed by Indian law, including:
- The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which require “reasonable security practices” for sensitive personal data such as identity documents.
- The Digital Personal Data Protection Act, 2023 (DPDP Act), which governs the collection, storage, use, and processing of digital personal data in India, and grants you rights over your personal data.
- Sector rules of the Ministry of External Affairs (MEA), Notary, and State Home Departments (SDM), where applicable to the attestation/apostille process.
We process your data on the basis of your consent (given when you submit an order/KYC details to us) and, where relevant, to comply with a legal obligation or perform the service you requested.
4) How we store & protect your data
- Soft copies of documents and KYC data are stored on access-controlled systems, with transport encryption (HTTPS/TLS) for uploads and transfers.
- Access is restricted to authorised team members who need it to process your specific case.
- We retain your KYC details and document copies only for as long as needed to complete your case, satisfy legal/audit requirements, and handle any post-service queries or disputes — after which they are deleted or anonymised, unless a longer retention period is required by law.
- Physical/original documents you send us are handled and returned per the process described at the time of booking; we do not retain physical originals beyond what is required to complete your case.
5) We do not sell your data or use it for advertising
We do not sell, rent, or trade your KYC details, document copies, or any personal data to any third party. We do not use your KYC details or submitted documents for advertising, marketing profiling, or any purpose unrelated to completing the service you requested. Your documents and personal information are used strictly to process your apostille/attestation case and related support.
6) When we share your data
To complete your requested service, we may need to share limited, necessary details (e.g., your document copies, name, and contact details) with:
- Government offices and authorities involved in the process — Notary, Sub-Divisional Magistrate (SDM)/Home Department, and the Ministry of External Affairs (MEA).
- Embassies/consulates, where your case requires embassy attestation or legalisation.
- Authorised courier/logistics partners, for physical document pickup/delivery.
- Payment gateway providers, solely to process your payment.
- Translation or notarisation partners, only where your case requires translation or additional notarisation.
These parties receive only the information necessary to complete the specific step of your case — never for any other purpose.
7) Third-party incidents are not our responsibility
We take reasonable care in selecting government counters, embassies, courier, translation, payment, and other third-party partners needed to complete your requested service. However, if a data breach, leak, or misuse of your information occurs on the systems of a government office, embassy, courier company, payment gateway, or any other independent third party we rely on to complete your case, such an incident is caused by that third party's systems and is not caused by, and does not belong to, Verifiedapostille Attestation Services Private Limited. We will nonetheless assist you in good faith — including notifying you where legally required and cooperating with any lawful investigation — to the extent reasonably possible.
8) Your rights
Subject to applicable law (including the DPDP Act, 2023), you may request to:
- Access the personal data and document copies we hold about you.
- Correct inaccurate KYC details.
- Request deletion of your data, once your case is complete and no legal/audit retention requirement applies.
- Withdraw consent for future processing (this may affect our ability to continue or complete a pending case).
To exercise any of these rights, contact us using the details below.
9) Cross-border processing
Where your case involves an embassy or destination country outside India, limited document/KYC details necessary for that specific legalisation step may be shared with that embassy or an authorised representative outside India, solely to complete your requested service.
10) Updates to this policy
We may update this Data Policy from time to time to reflect changes in law (including the DPDP Act, 2023 and its rules) or our practices. The “Effective date” above reflects the latest version. Continued use of our services means you agree to the updated policy.
11) Contact us
For any questions about this Data Policy, or to exercise your data rights, contact us at:
📧 contact@verifiedapostille.com