Data Governance

Last Updated: July 30, 2026

PehleVerify India Private Limited is committed to responsible, transparent data governance. This page explains how we structure, protect, and oversee the personal data that flows through our verification platform.

1. Data Governance Framework

Our data governance approach rests on four principles: purpose limitation, data minimization, security by design, and accountable ownership.

Purpose Limitation: Every piece of data collected is tied to a specific verification service selected by the requester. We do not collect data speculatively or repurpose it for unrelated uses.

Data Minimization: We only request the information necessary to perform the specific checks included in the selected service. Optional fields remain optional; checks are skipped rather than forced when information is unavailable.

Security by Design: Data protection is built into our architecture, not added afterward. All identity data is encrypted, access is restricted, and processing happens through audited, certified infrastructure partners.

Accountable Ownership: A named Data Protection Officer oversees compliance, and every data processing action is logged for audit purposes.

2. Data Classification

We classify data we process into three tiers:

Tier 1 — Sensitive Identity Data: Aadhaar numbers, PAN numbers, Voter ID, Driving Licence numbers, Passport numbers, uploaded ID document images, and selfie photographs. This data receives the highest level of protection — encrypted at rest and in transit, access-restricted to automated verification processes only.

Tier 2 — Verification Result Data: Court record findings, credit history summaries, employment verification results, and AI-generated report summaries. This data is retained for the report validity period and protected behind PIN-based access control.

Tier 3 — Operational Data: Account information, payment records, consent logs, and platform usage data. Retained per statutory requirements for accounting and compliance purposes.

3. Data Processing Partners

We work with a limited set of certified infrastructure partners, each contractually bound to process data solely for PehleVerify's stated purposes:

Verification Infrastructure: Certified government-database verification partners with ISO 27001 and SOC II certification, used exclusively to query official sources (UIDAI, Income Tax Department, National Court Registry, CIBIL, and other government databases).

Payment Processing: Cashfree Payments, a PCI-DSS compliant payment gateway. We do not store card or banking details on our own systems.

Cloud Infrastructure: Our platform runs on encrypted cloud infrastructure with data residency and access controls appropriate to the sensitivity of the data processed.

AI Processing: Anthropic's Claude AI is used solely to generate plain-language summaries from verification results. Raw identity documents are never transmitted to this service — only structured verification outcomes.

Communication Infrastructure: SMS and notification delivery partners, used solely for DPDP-mandated consent notifications and service communications.

4. Access Controls

Access to Tier 1 sensitive identity data is restricted to automated system processes required to execute verification checks. PehleVerify personnel do not have standing access to view raw Aadhaar, PAN, or uploaded documents outside of system-level operations necessary for platform maintenance and support.

Reports are protected by unique, non-guessable links combined with a 4-digit PIN, ensuring that only parties explicitly authorized by the requester can view results.

5. Audit and Accountability

Every check initiated on PehleVerify generates an audit trail recording: who initiated the check, when consent was given, what notifications were sent to the subject, and when the report was accessed. These logs support our DPDP Act compliance obligations and allow us to investigate any reported misuse of the platform.

We actively monitor for patterns of platform misuse, including unusually high check volumes from a single account or IP address, which are flagged for manual review.

6. Data Retention and Deletion

Verification reports are retained for 12 months, after which they are permanently and irreversibly deleted from our active systems. Consent logs are retained for 3 years to demonstrate ongoing compliance. Payment records are retained as required under Indian tax law.

Users may request early deletion of their data, subject to statutory retention requirements, by contacting dpo@pehleverify.in.

7. Governance Oversight

Our Data Protection Officer reviews data handling practices on an ongoing basis and is the designated point of contact for any data governance concerns, regulatory inquiries, or data subject requests.

Data Protection Officer: Pranay Mudigonda — dpo@pehleverify.in

8. Contact

For questions about our data governance practices:

Email: dpo@pehleverify.in

PehleVerify India Private Limited
Nizamabad, Telangana, India