Laxhar Tech
BrandsLaxhar AccessAccount ConsoleOur JourneyContact

Data Protection

Last Updated: June 23, 2026

Laxhar Tech implements data protection measures compliant with the Digital Personal Data Protection Act, 2023 (DPDPA), Information Technology Act, 2000, and applicable rules.

Secure Indian Servers

Data stored on servers located in India

Encryption

TLS in transit, AES-256 at rest

Access Control

Authorized personnel only, least privilege

DPDPA Compliant

Full compliance with Indian data laws

1. Data Fiduciary Obligations

As a Data Fiduciary under DPDPA 2023, Laxhar Tech (GST: 27EFMPS4211A1ZM) ensures: reasonable security safeguards, data accuracy, purpose limitation, storage limitation, and lawful processing based on consent or legitimate uses under Section 7.

2. Security Measures

Technical Safeguards

  • TLS 1.3 encryption for data in transit
  • AES-256 encryption for sensitive data at rest
  • Firewalls, intrusion detection, continuous monitoring
  • Regular vulnerability assessments and penetration testing
  • Secure backup and disaster recovery procedures

Organizational Safeguards

  • Role-based access control (RBAC) with unique credentials
  • Employee training on data protection
  • Confidentiality agreements for all personnel
  • Regular access reviews and audits

3. KYC Document Handling

Government-issued IDs collected for verification are:

  • Encrypted and stored on secured Indian servers
  • Accessible only to authorized KYC personnel
  • Retained per PMLA Rules (5 years post-relationship)
  • Securely deleted when retention period expires

Warning: We never request documents via email or unsecured channels. Use only our official platform.

4. Data Breach Response

In event of a personal data breach likely to cause harm:

  • Immediate: Contain and mitigate the breach
  • Within 72 hours: Notify Data Protection Board of India as required under DPDPA
  • Without undue delay: Notify affected Data Principals
  • Post-incident: Implement measures to prevent recurrence

5. Data Principal Rights

Under DPDPA 2023, you may:

  • Access summary of your data and processing activities (Section 11)
  • Request correction of inaccurate data (Section 12)
  • Request erasure when data no longer needed (Section 12)
  • File grievances with us or the Data Protection Board (Section 13)
  • Nominate someone to exercise rights on your behalf (Section 14)

6. Third-Party Processors

We engage Data Processors who:

  • Are contractually bound to DPDPA-compliant data protection
  • Process data only for specified purposes
  • Implement appropriate security measures
  • Are subject to our regular compliance audits

Our current processors and sub-processors include:

  • Cloud hosting providers with infrastructure located in India
  • PayGate — payment processing (card details tokenized by the processor)
  • DigiLocker (Government of India) — consent-based identity verification
  • MSG91 — SMS one-time passwords (OTP)
  • Google Analytics — website usage analytics

7. Grievance Officer

Per IT Act 2000, IT Rules 2011, and DPDPA 2023:

Grievance Officer

Tanmay Shinde

Laxhar Tech, Mumbai, Maharashtra, India

[email protected]

Acknowledgment: Within 24 hours

Resolution: Within 30 days

Unsatisfied? File complaint with the Data Protection Board of India under DPDPA 2023.

This document supplements our Privacy Policy. For consent-based processing, explicit consent is obtained at the point of collection.

Laxhar TechLaxhar Tech

Building India's independent technology ecosystem with 9 brands at various stages across multiple industries.

[email protected]
Mumbai, Maharashtra, India

Quick Links

  • Brands
  • Laxhar Access
  • Account Console
  • Our Journey
  • Contact

Our Brands

  • Noura Essence

Trust & Legal

Data Sovereignty
D-U-N-S Registered

GST: 27EFMPS4211A1ZM

© 2026 Laxhar Tech. All rights reserved.
Privacy PolicyTerms of ServiceCookie PolicyData Protection