LEGAL

Privacy Policy

This policy explains how DigiChain handles personal data and describes your rights under India's Digital Personal Data Protection Act, 2023 (the “DPDP Act”). Please read it together with our Terms & Conditions.

Effective: 23 July 2026Last updated: 23 July 2026Version 2026-07-23

1. Who we are

This platform (“DigiChain”, “we”, “us”, “our”) is operated by DigiChain, [NX One Commercial Tower 2, A-1402 Sector 100, Noida, Uttar Pradesh 201306]. DigiChain is a credential verification service: institutions and employers issue tamper-evident credentials and employment records, a cryptographic fingerprint of each is anchored to the Polygon blockchain, and anyone can then verify authenticity without contacting the issuer.

For questions about this policy or your personal data, contact us at digichainpi@gmail.com. Our grievance-redressal details are in section 12.

2. Our role: Data Fiduciary and Data Processor

The DPDP Act distinguishes a Data Fiduciary (who decides why and how personal data is processed) from a Data Processor(who processes it on a fiduciary's behalf). DigiChain acts in two capacities:

  • As a Data Fiduciary for the personal data of the account holders who use DigiChain — i.e. the staff of an issuing institution or employer, and individuals who claim their own credentials. We decide how that account and usage data is handled.
  • As a Data Processor for the credential and employment-record data that an institution or employer uploads about third parties (students, employees). There, the issuing organisation is the Data Fiduciary: it decides what to issue and must have a lawful basis to do so. DigiChain processes that data only on the organisation's instructions, to provide the service.

If you are a student or employee and wish to exercise rights over a credential issued about you, we will help route your request, but the issuing organisation is the primary point of accountability.

3. Personal data we collect

a. Account & organisation data

  • Name, email address and authentication identifiers of the people who sign in.
  • Organisation name, type (institution / employer), and domain.
  • Verification and role information used to approve an organisation as an authorised issuer.

b. Credential & employment-record data (processed on the issuer's behalf)

  • Subject name and email of the person a credential is about.
  • Academic details (degree, programme, grade, year) or employment details (designation, department, employee ID, dates of joining and leaving, last salary, exit type, rehire eligibility, exit clearance), depending on the record type.

c. Consent, verification & audit records

  • Consent records: which organisation accepted which version of these documents, the accepting user, a timestamp, a hashed (not raw) IP address and browser user-agent — kept as proof of consent as the DPDP Act requires.
  • Verification logs: the credential checked, the outcome, a hashed IP and user-agent — used to give issuers analytics and to detect abuse.

4. What goes on the blockchain

This is important: we do not write personal data to the blockchain. Only a Merkle root — an opaque cryptographic fingerprint of a batch of credentials — is anchored on Polygon. It cannot be reversed into names, grades or any underlying detail. The personal data itself stays in our off-chain database.

Please be aware that data written to a public blockchain is, by design, permanent and cannot be edited or deleted. Because only irreversible fingerprints are anchored, your right to correction and erasure over your actual personal data (which lives off-chain) is unaffected.

5. Purposes and legal basis

We process personal data for these purposes, on these bases under the DPDP Act:

  • To provide the service (issue, anchor, verify and manage credentials) — on the basis of your consent and the performance of our agreement with you.
  • To secure the platform and prevent fraud/abuse — as a legitimate use and to meet our security obligations.
  • To comply with law and respond to lawful requests.
  • To communicate with you about your account, approvals and material changes.

We ask for your organisation's consent through a clear, unbundled, affirmative action (an unchecked box you must tick) before you begin, and we record it. You may withdraw consent as described in section 9.

6. How we share data

We do not sell personal data. We share it only with processors who help us run the service, under contractual confidentiality and security obligations:

  • Authentication — Clerk, for sign-in and organisation management.
  • Database & hosting — our managed PostgreSQL host and cloud hosting provider, where off-chain data is stored and the application runs.
  • Blockchain — the Polygon network and RPC providers, which receive only the non-personal Merkle root and transaction metadata.
  • Key management — a key-management service used to protect issuer signing keys (no credential data is shared with it).
  • Legal / safety — authorities where required by law, or to protect rights and safety.

7. Data retention

We keep personal data only as long as needed for the purposes above or as required by law. Credential and employment records are retained while the issuing organisation's account is active and the credential is relied upon for verification; consent and audit logs are retained for the period needed to demonstrate compliance. When data is no longer needed, we delete or de-identify it. On-chain fingerprints, being non-personal and immutable, remain.

8. Security

We apply reasonable technical and organisational safeguards, including encryption in transit, hashing of IP addresses, storing API keys and signing material only in hashed or encrypted form, access controls, and the architectural choice to keep personal data off-chain. No system is perfectly secure, but we work to protect your data and will notify you and the Data Protection Board of a personal-data breach as the DPDP Act requires.

9. Your rights under the DPDP Act

As a Data Principal, you have the right to:

  • Access a summary of the personal data we process about you and how.
  • Correction, completion, updating and erasure of your personal data.
  • Withdraw consent at any time — this is as easy as giving it. Withdrawal does not affect processing already carried out, and may mean we can no longer provide part of the service.
  • Grievance redressal — a readily available means to raise a complaint (section 12).
  • Nominate another individual to exercise your rights in the event of death or incapacity.

To exercise any right, email digichainpi@gmail.com. If the data was uploaded about you by an institution or employer, we may direct or forward your request to that organisation as the responsible Data Fiduciary.

10. Children's data

DigiChain is intended for organisations and adults. Consistent with the DPDP Act, we do not knowingly process the personal data of a child (a person under 18) without verifiable parental consent, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. Institutions that issue credentials to minors are responsible for obtaining any parental consent required by law before uploading such data.

11. Cross-border processing & cookies

Some of our processors may store or process data outside India. Where they do, we rely on providers with appropriate safeguards and only in a manner permitted by the DPDP Act and any restrictions notified by the Central Government. We use strictly necessary cookies for authentication and security; we do not use advertising or cross-site tracking cookies.

12. Grievance redressal & the Data Protection Board

If you have a concern or complaint about how your personal data is handled, contact our Grievance Officer at digichainpi@gmail.com. We will acknowledge and respond within the timelines required by law. If you are not satisfied with our response, you may lodge a complaint with the Data Protection Board of India established under the DPDP Act.

13. Changes to this policy

We may update this policy. When we make a material change we will revise the version and effective date shown above, and — because consent is specific to the version you accepted — ask your organisation to review and accept the updated documents before continuing to use the service.

14. Contact

DigiChain
[NX One Commercial Tower 2, A-1402 Sector 100, Noida, Uttar Pradesh 201306]
Email: digichainpi@gmail.com

This document is provided for the DigiChain platform and is a general template. It is not legal advice; have it reviewed by qualified counsel and complete the entity, address and grievance-officer details before relying on it in production.