Data Protection
Last Updated: December 9, 2025
Laxhar Tech implements data protection measures compliant with the Digital Personal Data Protection Act, 2023 (DPDPA), Information Technology Act, 2000, and applicable rules.
Secure Indian Servers
Data stored on servers located in India
Encryption
TLS in transit, AES-256 at rest
Access Control
Authorized personnel only, least privilege
DPDPA Compliant
Full compliance with Indian data laws
1. Data Fiduciary Obligations
As a Data Fiduciary under DPDPA 2023, Laxhar Tech (GST: 27EFMPS4211A1ZM) ensures: reasonable security safeguards, data accuracy, purpose limitation, storage limitation, and lawful processing based on consent or legitimate uses under Section 7.
2. Security Measures
Technical Safeguards
- TLS 1.3 encryption for data in transit
- AES-256 encryption for sensitive data at rest
- Firewalls, intrusion detection, continuous monitoring
- Regular vulnerability assessments and penetration testing
- Secure backup and disaster recovery procedures
Organizational Safeguards
- Role-based access control (RBAC) with unique credentials
- Employee training on data protection
- Confidentiality agreements for all personnel
- Regular access reviews and audits
3. KYC Document Handling
Government-issued IDs collected for verification are:
- Encrypted and stored on secured Indian servers
- Accessible only to authorized KYC personnel
- Retained per PMLA Rules (5 years post-relationship)
- Securely deleted when retention period expires
Warning: We never request documents via email or unsecured channels. Use only our official platform.
4. Data Breach Response
In event of a personal data breach likely to cause harm:
- Immediate: Contain and mitigate the breach
- Within 72 hours: Notify Data Protection Board of India as required under DPDPA
- Without undue delay: Notify affected Data Principals
- Post-incident: Implement measures to prevent recurrence
5. Data Principal Rights
Under DPDPA 2023, you may:
- Access summary of your data and processing activities (Section 11)
- Request correction of inaccurate data (Section 12)
- Request erasure when data no longer needed (Section 12)
- File grievances with us or the Data Protection Board (Section 13)
- Nominate someone to exercise rights on your behalf (Section 14)
6. Third-Party Processors
We engage Data Processors who:
- Are contractually bound to DPDPA-compliant data protection
- Process data only for specified purposes
- Implement appropriate security measures
- Are subject to our regular compliance audits
7. Grievance Officer
Per IT Act 2000, IT Rules 2011, and DPDPA 2023:
Grievance Officer
Tanmay Shinde
Laxhar Tech, Mumbai, Maharashtra, India
Acknowledgment: Within 24 hours
Resolution: Within 30 days
Unsatisfied? File complaint with the Data Protection Board of India under DPDPA 2023.
This document supplements our Privacy Policy. For consent-based processing, explicit consent is obtained at the point of collection.