A
AIVPS
Home Terms AUP
← Back
// LEGAL DOCUMENT · DPDP COMPLIANT

Privacy & KYC

ADHABI DATA CENTRE LLP · Last Updated: 04 October 2026

These policies govern how ADHABI DATA CENTRE LLP collects, verifies, retains, and protects customer data. Drafted in accordance with the Digital Personal Data Protection Act, 2023, DPDP Rules, 2025, and CERT-In Directions 2022.

01 · Privacy Policy

Legal basis: DPDP Act, 2023 · DPDP Rules, 2025 · CERT-In Directions 2022.

1.1 Data Fiduciary

ADHABI DATA CENTRE LLP, a Limited Liability Partnership incorporated under the Limited Liability Partnership Act, 2008, with its registered office at Room No. 112, 1st Floor, Zilla Parishad Market, Salar, Murshidabad, West Bengal — 742401, India.

1.2 Data Collected

Name, email, phone, address, IP, payment reference, KYC verification status, and GSTIN (for business customers). We do not store full Aadhaar number, raw XML, QR payload, or any identity document beyond what is required for verification.

1.3 Purpose

Identity verification is mandatory under CERT-In Directions 2022 for VPS, cloud, and data centre services. Refusal to provide required data results in service rejection.

1.4 Legal Basis

Legal obligation (CERT-In) + contract performance + legitimate interest (fraud/abuse prevention).

1.5 Retention

  • Validated subscriber records — 5 years post-cancellation (CERT-In Direction 8)
  • Billing records — 6–8 years
  • Logs — 180 days
  • Full identity documents — not retained

1.6 Data Principal Rights

Access, correction, and erasure (subject to legal retention). Grievance resolved within 90 days. Contact Grievance Officer: grievance@adhabidatacentre.in

1.7 Erasure Procedure

Submit a written request to the designated email. We will provide 48 hours' notice before erasure, unless retention is required by CERT-In, tax, or PMLA.

1.8 Breach Notification

Affected users and the Data Protection Board are notified within 72 hours.

1.9 Cross-Border Data

Aadhaar-related infrastructure is stored strictly within India.

1.10 Consent Withdrawal

Withdrawal does not affect processing done before withdrawal, nor data retained under legal obligation.

1.11 Sub-Processors

Your personal data is processed using infrastructure provided by third-party data centre operators located within India. We remain the Data Fiduciary. Our colocation providers act as our sub-processors and are contractually bound to maintain equivalent security and confidentiality standards.

1.12 Named Sub-Processors

  • Payment Gateway: Razorpay / PhonePe for payment processing
  • KYC Provider: Authorised DigiLocker-integrated provider for identity verification

1.13 Payment Security

We do not collect or retain payment card details, bank credentials, or UPI PINs. All payment transactions are handled through our secure payment gateway.

1.14 Cookies & Local Storage

We use session cookies to maintain login sessions and preferences. We do not use tracking cookies.

1.15 Expanded Data Rights

You have the right to: (a) inspect your stored account profile; (b) download transaction histories; (c) request password resets; (d) close your account (subject to termination of all active VMs and settlement of balances); (e) request erasure of personal data (subject to legal retention).

1.16 Specific Retention Periods

Data TypeRetention
Developer API logs7 days
Signup OTPs10 minutes (auto-deleted)
Terminated VM history3 months (billing disputes)
Login eventsSecurity audit trail
Regulated data (subscriber records, ICT logs)As per CERT-In

02 · KYC and Identity-Verification Policy

Legal basis: CERT-In Directions 2022 · Directions 8–10 · IT Act, 2000.

2.1 Mandatory Data

Full legal name, validated address, contact number, email, IP allotted, purpose of hire, and ownership pattern.

2.2 Age and Entity Requirement

Customer must be at least 18 years old or a legally recognized business entity holding a valid GSTIN.

2.3 Verification Levels

  • Level 1 (shared/domain/email) — email + mobile + payment
  • Level 2 (VPS/higher limits) — Level 1 + government document/DigiLocker
  • Level 3 (bulk VPS/large IP/proxy/crypto) — Level 2 + manual approval + enhanced monitoring

2.4 Accepted Verification Methods

In order of preference: DigiLocker → government document (DL / Passport / Voter ID) → Aadhaar offline XML/QR → any other government-approved verification method through an authorised provider.

2.5 We Never

  • Collect identity documents through ordinary support channels
  • Ask for verification data by email, WhatsApp, phone, or ticket
  • Store full Aadhaar number, raw XML, QR payload, or biometric data

2.6 Failed Verification

General reason given. One alternative offered. Repeated attempts limited. Genuine cases escalated to manual review.

2.7 Refusal

Refusal to provide CERT-In-required data is grounds for rejection without refund.

03 · Data-Retention and Deletion Policy

Legal basis: CERT-In Directions 2022, Direction 8 · DPDP Act, 2023 · DPDP Rules, 2025 · Income Tax Act, 1961.

Data TypeRetentionLegal Basis
Validated subscriber records5 years post-cancellationCERT-In Direction 8
Transaction/billing records5 years from transactionPMLA / Income Tax
KYC verification status5 years post-cancellationCERT-In + DPDP
Full identity documentsNot retainedDPDP minimisation
Full Aadhaar number / raw XMLNever storedUIDAI regulations
ICT logs180 days rollingCERT-In
Terminated VM history3 monthsBilling disputes

Erasure requests: Honoured except where retention is required by CERT-In, tax, or PMLA. Customer informed of legal retention basis. 48 hours' notice provided before erasure.

04 · Data-Breach and Incident-Response

Legal basis: DPDP Act Section 8(6) · DPDP Rules, 2025 · CERT-In Directions 2022.

  1. Detection → Immediate isolation: Disable compromised accounts, isolate systems, preserve logs.
  2. CERT-In reporting (within 6 hours): incident@cert-in.org.in · phone 1800-11-4949.
  3. DPDP breach notification (within 72 hours): Notify Data Protection Board + affected Data Principals.
  4. KYC provider notification: If provider data/systems involved, notify immediately.
  5. Remediation: Rotate API keys, patch root cause, post-incident review, update controls.

05 · Law-Enforcement Request Procedure

Legal basis: IT Act, 2000 · CERT-In Directions 2022 · Bharatiya Nagarik Suraksha Sanhita, 2023.

  1. A single point of contact is designated for all law-enforcement requests.
  2. Verification required: Written request on official letterhead + officer identity verification + legal authority.
  3. We provide: Validated subscriber records (name, address, contact, IP, purpose, ownership) as required by CERT-In.
  4. We do not provide: Full Aadhaar number, raw XML/QR, or biometrics — unless specifically required by court order.
  5. Timeline: Acknowledge within 24 hours. Data provided within the legally mandated timeframe.
  6. All requests and responses are logged.
© 2026 AIVPS · ADHABI DATA CENTRE LLP
TermsPrivacyAUP