This policy explains how Getnomik Private Limited ("Digivault", "we") handles personal data when you use Digivault, in line with the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (DPDP Act). We keep it short and plain on purpose.
1. Who is who
- Professionals (our customers) decide which documents to request or share. For the documents in their requests, the Professional is responsible for the purpose and use of that data, and Digivault acts as their processor.
- Recipients are people who upload or view documents through a Digivault link. If you are a Recipient, the organisation named on your request page is collecting your documents. Please contact them about how they use your documents.
- For Professional account and billing data, Digivault decides how it is used.
2. What we collect
- Professional account data: name, work email, mobile number, password (stored only as a one-way hash), organisation name, professional type, city, state, and optionally GSTIN, legal name, billing address, postal code and logo. If you sign in with Google, we receive your name and email from Google.
- Recipient data: your email address (for verification codes) and the documents you upload, with their file name, type, size and checksum.
- Activity and security data: audit events (such as request created, code sent, document uploaded, viewed, downloaded, link revoked), IP address, browser/device information and timestamps.
- Billing data: plan, payment status, amount and payment reference. Card, UPI and bank credentials are handled by Razorpay and are not stored by us.
- Support messages you send us.
Documents may contain sensitive identifiers such as PAN or Aadhaar. We do not read them for any purpose other than operating and securing the service.
3. Why we use it
- to create and run your account and deliver the document request and sharing service you asked for;
- to verify identity by email code and to protect links, accounts and documents;
- to keep audit records, prevent abuse and investigate security incidents;
- to send service emails (verification codes, requests, confirmations, reminders, billing notices);
- to process payments, issue invoices and meet tax and legal obligations;
- to improve reliability of the service, using aggregate or non-document data.
We rely on your consent, on performing the service you requested, and on legal obligations. We do not sell personal data and do not use your documents for advertising or to train AI models.
4. How long we keep it
- Documents: kept until the retention period set by the Professional's organisation ends (counted from when the request expires), then deleted automatically. A Professional can also delete a document at any time.
- Verification codes and temporary sessions: a few minutes to hours.
- Audit logs: kept for security and accountability, and as long as needed to meet legal duties.
- Account data: while your account is active, then for a reasonable period afterwards unless a law requires longer (for example, tax and billing records).
5. Who we share it with
Only as needed to run the service, with providers bound to protect it: our hosting and database provider, our email delivery provider, Razorpay for payments, and Google if you choose Google sign-in. We may disclose data if required by law or a valid order from an authority, or to protect rights and safety. Documents are shared only with the Professional who requested them and with Recipients that Professional chooses.
6. Cookies
We use only essential cookies: a secure session cookie to keep you signed in, a security (CSRF) cookie, and short-lived verification sessions for Recipients. We do not use advertising or cross-site tracking cookies.
7. Security
Documents are kept in private storage and are never exposed through public links. Access is checked on our servers every time, links are random and expire, verification codes are single-use, files are validated and scanned, and key actions are logged. No method of storage or transmission is completely secure, so we cannot guarantee absolute security. If a breach affects your personal data, we will notify you and the relevant authority as the law requires.
8. Your rights
Under the DPDP Act you can ask to access a summary of your personal data, correct or update it, erase it, withdraw consent, and nominate someone to act for you, and you can complain to us and to the Data Protection Board of India. Recipients should first contact the Professional who requested their documents; we will help that Professional act on your request. To exercise your rights, email support@getnomik.com. We may need to verify your identity first and will respond within a reasonable time.
9. Children
Digivault is for professionals and businesses and is not directed to children. Where a Professional collects documents about a child, the Professional is responsible for obtaining verifiable consent from a parent or guardian as the law requires.
10. Where data is stored
Data is stored on servers chosen by us and may be processed by our providers in or outside India, with appropriate safeguards and as permitted by law.
11. Changes
We may update this policy. We will post the new version here with a new effective date and tell you about material changes in the product or by email.
12. Contact and grievance officer
Grievance Officer, Getnomik Private Limited
Getnomik Private Limited, Ahmedabad, Gujarat, India
support@getnomik.com