Legal

Privacy Policy

This Privacy Policy describes how AssureLocker handles personal and business data across its website, verification and evidence services for trade and supply-chain financing, entity and lender services, consent-based information flows, support operations, and DPDP-aligned rights and grievance processes.

Effective date: 28 March 2026

1. Scope and role of AssureLocker

This Privacy Policy explains how AssureLocker and its affiliates, service operators, and authorized platform providers collect, use, disclose, store, and otherwise process personal and business data when you access AssureLocker websites, mobile or web applications, verification and evidence flows, support channels, and services for individuals, businesses, lenders, anchor buyers, attesters, and regulators.

AssureLocker is a verification, evidence, and risk-signal platform for trade and supply-chain financing. Depending on the context, AssureLocker may act as a digital platform operator, data fiduciary, processor, service provider, verification facilitator, or technology service provider for entity and identity verification, evidence and Risk Signals Pack assembly, consent-based information sharing, support, compliance operations, and audit workflows. AssureLocker is a technology service provider; it does not lend, hold or move funds, or make credit decisions.

This policy is intended to be read together with AssureLocker product notices presented at the point of collection, consent prompts, credential-sharing screens, onboarding guidance, and any contractual or regulatory notices provided to institutions, attesters, or regulators.

2. Personal data we collect

We may collect account and identity information such as your name, email address, phone number, login credentials, authentication method, account identifiers, DID and institution-linked identifiers, device and session information, and records necessary to maintain your AssureLocker account and security posture.

For identity and KYC-related services, we may collect profile data, date of birth, address information, biometrics and liveness signals, identity document information, KYC and risk assessment outputs, credential metadata, verification results, audit references, and evidence references or hashes needed to run AssureLocker workflows.

For entity and institutional services, we may collect organization names, registered identifiers, GSTIN, CIN, PAN-linked or signatory-linked onboarding data, role and membership data, consent settings, webhook and API client information, annual declaration data, compliance artefacts, attester interactions, and operational activity logs.

For trade and supply-chain financing workflows, we may process business and trade data such as purchase orders, invoices and e-invoice/IRN references, GST filing and trade-history signals, buyer–supplier relationship data, shipping, logistics and export references, export-trade evidence such as certificate-of-origin details, Legal Entity Identifier (LEI) records and bank-realisation references, and charge or lien search results (for example CERSAI). For higher-risk actions or step-up verification, we may also process device-posture and trusted-device signals to enforce a relying institution's risk policy. Where you consent through an Account Aggregator, with the lender acting as the financial-information user, we receive financial information only to compute the cash-flow aggregates a workflow needs. Consistent with data minimisation, we retain those derived aggregates and do not retain the raw account-level financial statements after processing.

We also collect service, usage, and diagnostic data such as browser or device attributes, IP address, session metadata, referral and callback parameters, API interaction logs, delivery logs, telemetry needed to improve reliability, product analytics, fraud detection signals, and support or grievance records you submit to us.

3. Sources of personal data

We collect personal data directly from you when you sign up, complete onboarding, configure your account, upload or import documents, connect wallets or institutions, submit forms, contact support, file grievances, or use AssureLocker products.

We may also receive data from verification, credentialing, registry, and infrastructure sources connected to the AssureLocker ecosystem, including DigiLocker, identity and address verification providers, company and tax registries (for example MCA21 and GSTN), e-invoice/IRP systems, Account Aggregators (where you act through a consent flow and a lender acts as the financial-information user), charge registries such as CERSAI, credit and trade-data providers, attesters, lenders, anchor buyers, institutions, regulators, payment providers, communications providers, analytics and hosting services, and other systems you authorize or that are lawfully connected to the AssureLocker service stack.

In certain flows, we receive data from institutions, organization administrators, entity members, or other users who interact with you through invitations, verification requests, consent workflows, sharing sessions, grievance processes, or account recovery processes.

4. Why we process personal data

We process personal and business data to provide, secure, and improve AssureLocker services, including account creation, authentication, DID binding, entity and identity verification, KYC/KYB and re-verification workflows, assembling verified evidence and Risk Signals Packs, orchestrating consent-based information flows to lenders and anchor buyers, credential issuance and lifecycle management, consent-based sharing, role management, support operations, fraud prevention, platform administration, analytics, and service continuity.

We also process personal data to comply with applicable law, regulatory obligations, lawful directions, audit and recordkeeping requirements, dispute handling, grievance redressal, abuse detection, platform security, and enforcement of our legal rights and obligations.

Where AssureLocker provides configurable sharing, privacy, or recovery controls, we use your selections to execute your chosen settings, enforce access restrictions, generate audit trails, and route communications or escalation steps to the appropriate product, compliance, or security workflows.

6. Evidence, credential, and verification flows

AssureLocker is built to reduce unnecessary exposure of raw documents and account-level data. Depending on the workflow, we may transform documents, identity evidence, and trade records into credential metadata, hashes, structured claims, assurance outputs, Risk Signals, derived aggregates, tokenised state, session proofs, disclosure packages, and audit receipts. These may be stored, anchored, transmitted, or validated through AssureLocker or connected infrastructure to deliver the service; the immutable registry stores hashes only and never raw personal data. Long-lived issuer-signed credentials and receipts are protected with strong, forward-looking (including post-quantum) cryptographic signatures, and anchored records are tamper-evident — they let a relying party detect alteration, but they are not a guarantee against every form of compromise.

When you create or use evidence- or credential-sharing flows, AssureLocker may process the fields requested, the counterparty, lender, or institution DID, consent choices, expiry periods, delivery metadata, relay or webhook events, and records showing what was shared, with whom, and when. These logs help provide transparency, access control, dispute resolution, and compliance evidence.

Where a lender, institution, or verifier requests data or evidence through AssureLocker, that recipient will independently determine how it uses the information it receives and remains responsible for its own credit and compliance decisions. AssureLocker is not responsible for downstream processing performed by independent lenders, institutions, attesters, verifiers, regulators, or third-party recipients once they lawfully receive data or verification outputs.

7. Wallet, backups, exports, and device-linked material

AssureLocker may allow credential exports, wallet backups, restores, secure vault features, and other account continuity tools. If you choose to use these features, we may process metadata, encrypted artefacts, backup references, recovery information, or device-linked session proof information necessary to make those features work.

You are responsible for keeping your own devices, exported files, backup artefacts, recovery factors, and access credentials secure. If you store AssureLocker material on your own devices, email systems, cloud accounts, or third-party storage, your use of those systems is governed by the relevant third-party terms and security controls.

8. Children and age-related restrictions

AssureLocker is generally designed for adult users and authorized organization representatives. If a flow involves a person who is regarded as a child under applicable law, including the Digital Personal Data Protection Act, 2023 in India, AssureLocker may require parental or lawful guardian involvement, may restrict certain functionality, or may decline to provide the relevant service unless the applicable legal basis and verification requirements are satisfied.

If you believe a child has provided personal data to AssureLocker without appropriate authorization, please contact us through AssureLocker's official support or grievance channels so that we can investigate and take appropriate action.

9. How we share personal data

We may share personal data with affiliated entities, infrastructure providers, cloud and hosting providers, communications providers, authentication providers, payment providers, verification service providers, analytics providers, customer support tools, and other processors or sub-processors who help us run AssureLocker.

We may also share personal data with institutions, attesters, regulators, auditors, legal advisors, law enforcement, dispute-resolution participants, courts, governmental authorities, or other third parties where necessary for the service, required by law, necessary to protect rights and safety, or reasonably necessary for audit, fraud prevention, grievance redressal, or security response.

If AssureLocker is involved in a merger, acquisition, reorganization, financing, asset sale, insolvency event, or similar corporate transaction, personal data may be disclosed or transferred as part of that process subject to appropriate confidentiality and lawful processing safeguards.

10. Retention and deletion

We retain personal data only for as long as reasonably necessary for the purposes described in this policy, for service continuity, or to satisfy legal, contractual, operational, regulatory, anti-fraud, security, or dispute-related obligations. Different categories of data may be retained for different periods depending on the workflow and legal context.

We may delete, aggregate, anonymize, de-identify, or redact data when it is no longer required in identifiable form, subject to legal retention requirements, ongoing disputes, security investigation needs, or audit obligations. Backup and log systems may take additional time to cycle out deleted material.

AssureLocker may provide in-app erasure or deletion request mechanisms for eligible users. As reflected in the current application design, some deletion flows may be moderated, delayed, or restricted where there are legal, security, billing, or institutional dependency reasons for not immediately deleting all records.

11. Your rights and choices

Subject to applicable law and the nature of the AssureLocker service you use, you may have rights to access information about processing, correct or update your data, complete incomplete information, request erasure, withdraw consent, object to or restrict certain processing, receive grievance redressal, and nominate another person to act on your behalf in specified circumstances.

AssureLocker may provide self-service controls for profile updates, sharing preferences, consent settings, security settings, notifications, re-KYC, recovery, account deletion requests, and related actions. Where self-service is not available or not sufficient, you may submit a support, grievance, or compliance request through AssureLocker's official channels.

We may need to verify your identity and authority before acting on a request. We may also deny, defer, or limit a request where doing so is permitted by law, would adversely affect the rights of another person, would undermine fraud or security controls, or would conflict with legal retention and compliance obligations.

12. Security and risk controls

AssureLocker uses technical, organizational, contractual, and procedural safeguards designed to protect personal data against unauthorized access, misuse, loss, alteration, and disclosure. These controls may include authentication measures, role-based access, encrypted transport, credential lifecycle controls, audit logs, security monitoring, least-privilege design, and environment-specific operational controls.

No method of transmission or storage is completely secure. You acknowledge that internet-based services, identity systems, and connected providers carry residual risks. You should maintain strong passwords, protect your devices, use available multi-factor authentication, and promptly notify AssureLocker if you suspect unauthorized access or account compromise.

13. Cross-border processing

Personal and financial data of India-resident individuals and entities is, by default, processed and stored within India. AssureLocker and its service providers may process limited categories of data in other jurisdictions only where lawful and appropriate and subject to applicable law, contractual controls, and reasonable technical and organizational safeguards; data-localisation and residency requirements applicable to our regulated customers take precedence over any cross-border convenience.

14. Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in law, regulation, product functionality, security practices, vendor arrangements, or AssureLocker business operations. Where required, we will provide notice through the website, the application, or other appropriate channels before or when updated terms become effective.

15. Biometric and liveness data

Where a relying institution requires it and the law permits, AssureLocker or its approved providers may perform liveness and face-match checks to confirm that the person presenting an identity is its genuine holder. These checks are used only for that verification purpose and are not used for surveillance, profiling, or advertising.

Biometric and liveness checks may be performed by approved third-party providers acting under contract. Where technically feasible, AssureLocker relies on a match/quality result rather than retaining raw biometric templates; any retention is limited to what is necessary for the verification, audit, and fraud-prevention purpose, and is deleted or de-identified thereafter in line with our retention practices.

You may withdraw consent to biometric processing, subject to the consequence that a relying institution may require an alternative verification pathway or may be unable to complete onboarding. To exercise choices relating to biometric data, use the grievance and contact channels in the section below.

16. Grievance redressal and contact

AssureLocker is operated by Right Vectors India. For data-protection purposes, Right Vectors India is the data fiduciary for the processing described in this policy where AssureLocker acts as fiduciary or controller. If you have questions, requests, or complaints about how your personal data is handled, you can reach our grievance-redressal channel at [email protected] (or by post at 3rd floor, Innov8, SKCL Tech Square, SIDCO Industrial Estate, Guindy, Chennai, TN 600032).

We aim to acknowledge and respond to grievances within the timelines required by applicable law (including the DPDP Act and its rules). If you are not satisfied with our response, you may have the right to escalate to the relevant data-protection authority, including the Data Protection Board of India.

Depending on the workflow, Right Vectors India may act as data fiduciary/controller (for example, for website visitors and holder-wallet users) or as a processor/service provider acting on a contracting institution's instructions (for example, for lender-requested verification), with the institution remaining the regulated entity responsible for its own customers.

Contact and grievances

For questions about these legal terms, privacy requests, or grievance redressal, please use AssureLocker's official support, grievance, or compliance channels made available on the website or inside the AssureLockerapplication. If you are an authenticated holder, the in-app grievance workflow is the fastest path for product-specific issues and rights-related requests.

Legal and privacy contact: [email protected]