Last updated 8 August 2026

Privacy policy

This explains what Suvidha collects, why, and for how long — written to match the Digital Personal Data Protection Act, 2023, not around it.

What we collect, and why

Every field we ask for is tied to a specific service’s intake schema and a stated purpose — shown to you at consent, before you pay. We don’t collect anything “just in case.” Identity and entity details (PAN, GSTIN, address, photo ID) exist to verify who you and your provider are; order-specific documents exist to deliver that one order.

Sensitivity tiers

Every field we hold is classified S0–S3 by sensitivity. Higher tiers (S2–S3: financial identifiers, statutory numbers, signed documents) are encrypted at rest with per-order keys and are never held with standing access — a provider or reviewer has to be explicitly granted access to a specific order’s documents, and that grant is logged.

Retention

Retention follows the purpose it was collected for, not a blanket policy: most order documents are purged shortly after order close, identity/entity records needed for statutory recordkeeping are held longer under a transaction-record class, and access logs are kept for forensic accountability. Exact classes are shown per field in each order’s consent preview.

Who we share it with

Only the provider assigned to your order, and only the fields their service actually needs. We do not sell personal data, and we do not share it with providers outside the order it belongs to.

Your rights

Access, correction, and erasure requests are handled under the DPDP Act — see Your data rights for how to exercise them.

Contact

Questions about this policy can be sent to our Data Protection Officer at privacy@suvidha.example.