Privacy Notice

Compliance with the Digital Personal Data Protection Act, 2023

Applicability: This Privacy Notice applies to how Arkashri collects, uses, shares, and protects personal data in India. It reflects requirements of the Digital Personal Data Protection Act, 2023 (DPDP Act) and the DPDP Rules, 2025.

1. Data Role & Collected Data

Arkashri is a Data Processor for any personal data in Audit Data uploaded by Users (processed strictly per User instructions), and a Data Fiduciary only for Arkashri’s own operational and account data. The User (or its client entity) is the Data Fiduciary for all client audit records and must have lawful basis (consent or other) to upload it.

Arkashri collects only data necessary to operate the Platform and support Users: e.g., account info (email, contact), authentication logs, support communications, and any Audit Data the User uploads. We do not monetize or sell data.

2. Purpose & No AI Training

Data is used to provide the Platform services (e.g., analysis, reporting), maintain accounts, secure the system, comply with legal obligations, and support Users. Audit Data is processed only to facilitate the User’s audit/compliance tasks.

No AI Training: Arkashri does not use customer-uploaded Audit Data to train or fine-tune its AI models or to improve other services. Customer data remains confidential and is used solely for the contracted processing tasks.

3. User Rights (DPDP Act)

Under the DPDP Act, data principals (end-users) have rights to access, correction, erasure, and objection. Users (as Data Fiduciaries) must handle such requests. Arkashri will assist Users to comply with valid requests concerning Audit Data, subject to retention obligations. Note: if data must be retained by law, erasure requests may be limited.

4. Security & Breach Notification

Arkashri implements robust security: encryption of data in transit and at rest, strong access controls, multi-factor authentication, least‑privilege practices, and continuous monitoring. Logs of all changes are kept in WORM storage (write‑once) and cryptographically hashed.

Breach Notification Pipeline (DPDP Rules 2025):

  • 0 Hours Notify affected data principals (concise notice)
  • 0 Hours Notify Data Protection Board (initial report)
  • 72 Hours Submit detailed report to Board (updated facts)

5. Retention & Subprocessors

Audit Data is retained for configured limits. All data will be deleted or returned at end of service, subject to legal holds. Hashes and metadata may be retained beyond deletion of personal data, as they no longer identify individuals.

We use trusted subprocessors for infrastructure:

SubprocessorServiceLocationPurpose
AWS / AzureCloud Auth, VM HostingMumbai/GlobalCompute, storage, DB hosting
OpenAI / LLM APIsAI Inference modelsVariesGenerative AI analysis (Zero-Retention)
CloudflareNetwork, WAFGlobalProtects and accelerates platform