Privacy & KYC
ADHABI DATA CENTRE LLP · Last Updated: 04 October 2026
01 · Privacy Policy
Legal basis: DPDP Act, 2023 · DPDP Rules, 2025 · CERT-In Directions 2022.
1.1 Data Fiduciary
ADHABI DATA CENTRE LLP, a Limited Liability Partnership incorporated under the Limited Liability Partnership Act, 2008, with its registered office at Room No. 112, 1st Floor, Zilla Parishad Market, Salar, Murshidabad, West Bengal — 742401, India.
1.2 Data Collected
Name, email, phone, address, IP, payment reference, KYC verification status, and GSTIN (for business customers). We do not store full Aadhaar number, raw XML, QR payload, or any identity document beyond what is required for verification.
1.3 Purpose
Identity verification is mandatory under CERT-In Directions 2022 for VPS, cloud, and data centre services. Refusal to provide required data results in service rejection.
1.4 Legal Basis
Legal obligation (CERT-In) + contract performance + legitimate interest (fraud/abuse prevention).
1.5 Retention
- Validated subscriber records — 5 years post-cancellation (CERT-In Direction 8)
- Billing records — 6–8 years
- Logs — 180 days
- Full identity documents — not retained
1.6 Data Principal Rights
Access, correction, and erasure (subject to legal retention). Grievance resolved within 90 days. Contact Grievance Officer: grievance@adhabidatacentre.in
1.7 Erasure Procedure
Submit a written request to the designated email. We will provide 48 hours' notice before erasure, unless retention is required by CERT-In, tax, or PMLA.
1.8 Breach Notification
Affected users and the Data Protection Board are notified within 72 hours.
1.9 Cross-Border Data
Aadhaar-related infrastructure is stored strictly within India.
1.10 Consent Withdrawal
Withdrawal does not affect processing done before withdrawal, nor data retained under legal obligation.
1.11 Sub-Processors
Your personal data is processed using infrastructure provided by third-party data centre operators located within India. We remain the Data Fiduciary. Our colocation providers act as our sub-processors and are contractually bound to maintain equivalent security and confidentiality standards.
1.12 Named Sub-Processors
- Payment Gateway: Razorpay / PhonePe for payment processing
- KYC Provider: Authorised DigiLocker-integrated provider for identity verification
1.13 Payment Security
We do not collect or retain payment card details, bank credentials, or UPI PINs. All payment transactions are handled through our secure payment gateway.
1.14 Cookies & Local Storage
We use session cookies to maintain login sessions and preferences. We do not use tracking cookies.
1.15 Expanded Data Rights
You have the right to: (a) inspect your stored account profile; (b) download transaction histories; (c) request password resets; (d) close your account (subject to termination of all active VMs and settlement of balances); (e) request erasure of personal data (subject to legal retention).
1.16 Specific Retention Periods
| Data Type | Retention |
|---|---|
| Developer API logs | 7 days |
| Signup OTPs | 10 minutes (auto-deleted) |
| Terminated VM history | 3 months (billing disputes) |
| Login events | Security audit trail |
| Regulated data (subscriber records, ICT logs) | As per CERT-In |
02 · KYC and Identity-Verification Policy
Legal basis: CERT-In Directions 2022 · Directions 8–10 · IT Act, 2000.
2.1 Mandatory Data
Full legal name, validated address, contact number, email, IP allotted, purpose of hire, and ownership pattern.
2.2 Age and Entity Requirement
Customer must be at least 18 years old or a legally recognized business entity holding a valid GSTIN.
2.3 Verification Levels
- Level 1 (shared/domain/email) — email + mobile + payment
- Level 2 (VPS/higher limits) — Level 1 + government document/DigiLocker
- Level 3 (bulk VPS/large IP/proxy/crypto) — Level 2 + manual approval + enhanced monitoring
2.4 Accepted Verification Methods
In order of preference: DigiLocker → government document (DL / Passport / Voter ID) → Aadhaar offline XML/QR → any other government-approved verification method through an authorised provider.
2.5 We Never
- Collect identity documents through ordinary support channels
- Ask for verification data by email, WhatsApp, phone, or ticket
- Store full Aadhaar number, raw XML, QR payload, or biometric data
2.6 Failed Verification
General reason given. One alternative offered. Repeated attempts limited. Genuine cases escalated to manual review.
2.7 Refusal
Refusal to provide CERT-In-required data is grounds for rejection without refund.
03 · Data-Retention and Deletion Policy
Legal basis: CERT-In Directions 2022, Direction 8 · DPDP Act, 2023 · DPDP Rules, 2025 · Income Tax Act, 1961.
| Data Type | Retention | Legal Basis |
|---|---|---|
| Validated subscriber records | 5 years post-cancellation | CERT-In Direction 8 |
| Transaction/billing records | 5 years from transaction | PMLA / Income Tax |
| KYC verification status | 5 years post-cancellation | CERT-In + DPDP |
| Full identity documents | Not retained | DPDP minimisation |
| Full Aadhaar number / raw XML | Never stored | UIDAI regulations |
| ICT logs | 180 days rolling | CERT-In |
| Terminated VM history | 3 months | Billing disputes |
Erasure requests: Honoured except where retention is required by CERT-In, tax, or PMLA. Customer informed of legal retention basis. 48 hours' notice provided before erasure.
04 · Data-Breach and Incident-Response
Legal basis: DPDP Act Section 8(6) · DPDP Rules, 2025 · CERT-In Directions 2022.
- Detection → Immediate isolation: Disable compromised accounts, isolate systems, preserve logs.
- CERT-In reporting (within 6 hours): incident@cert-in.org.in · phone 1800-11-4949.
- DPDP breach notification (within 72 hours): Notify Data Protection Board + affected Data Principals.
- KYC provider notification: If provider data/systems involved, notify immediately.
- Remediation: Rotate API keys, patch root cause, post-incident review, update controls.
05 · Law-Enforcement Request Procedure
Legal basis: IT Act, 2000 · CERT-In Directions 2022 · Bharatiya Nagarik Suraksha Sanhita, 2023.
- A single point of contact is designated for all law-enforcement requests.
- Verification required: Written request on official letterhead + officer identity verification + legal authority.
- We provide: Validated subscriber records (name, address, contact, IP, purpose, ownership) as required by CERT-In.
- We do not provide: Full Aadhaar number, raw XML/QR, or biometrics — unless specifically required by court order.
- Timeline: Acknowledge within 24 hours. Data provided within the legally mandated timeframe.
- All requests and responses are logged.