Privacy Policy
Last updated: 2 July 2026
1. Our commitment
We take privacy seriously. Digital signature certification involves sensitive personal data — Aadhaar, PAN, photograph and address. We handle this data with care and only for the specific purpose you consented to.
2. What data we collect
- Personal data at application: full name, PAN, Aadhaar number, mobile, email, address, and date of birth (as required by CCA guidelines).
- Uploaded KYC documents: PAN card image, Aadhaar card image (front and back), passport-size photograph, and additional entity documents for organisations.
- Payment data: handled entirely by Razorpay (PCI-DSS compliant). We do not store card numbers, CVV, or bank credentials.
- Video verification data: a recording captured by the vendor Certifying Authority, retained per their policy (typically 7–10 years for audit).
- Technical data: IP address, browser type, device information and page views (for security and analytics).
3. Why we collect it
- To process your DSC application with the Certifying Authority.
- To fulfil the Controller of Certifying Authorities (CCA) mandatory verification requirements.
- To issue a tax invoice.
- To communicate application status, deliver the token, and provide support.
- To comply with legal obligations (KYC, anti-fraud, tax records).
4. Document retention — our specific commitment
The Aadhaar images, PAN images, passport-size photographs and other identity documents you send us for a DSC application are transmitted to the vendor Certifying Authority to complete your application.
After the vendor Certifying Authority accepts and processes these documents, we do NOT retain copies of Aadhaar images, PAN images, or photographs on our systems.
These document images are deleted from our servers, email archives and WhatsApp business accounts within 30 days of certificate issuance.
Only the following data is retained beyond 30 days: your name, masked Aadhaar (last 4 digits only), PAN number as text, mobile, email, address, and order and payment history — for tax invoicing, renewal reminders and legal compliance.
This is a deliberate policy choice to protect you from data-breach risk. We do not store what we do not need.
5. Who we share your data with
- Vendor Certifying Authority (eMudhra, PantaSign, Capricorn, or the relevant issuer) — to issue the certificate. This is mandatory and cannot be opted out of if you want a DSC.
- Payment processor (Razorpay) — to process payment.
- Courier partner (Delhivery, BlueDart, DTDC, or similar) — name, address and phone, for delivery only.
- Tax authorities (GST department, Income Tax) — as legally required for invoice reporting.
- We do not sell your data to third parties. Ever.
- We do not share your Aadhaar or PAN images with any party other than the vendor Certifying Authority.
6. How we store data
- Servers located in India (Hostinger).
- Encryption in transit (HTTPS/TLS).
- Access limited to authorised employees on a need-to-know basis.
- Regular security reviews.
7. Your rights
- Right to access your personal data.
- Right to correction of inaccurate data.
- Right to deletion (subject to legal retention requirements — for example, invoices must be retained for 8 years under GST law).
- Right to data portability (request your data in a structured format).
- Right to withdraw consent for marketing communications.
- Exercise these rights via email: info@bestdsc.com.
8. Cookies and tracking
- We use minimal essential cookies for session and security.
- No third-party advertising cookies.
- Google Analytics, if enabled, uses IP anonymisation.
9. Data breach notification
If a data breach occurs affecting your data, we will notify you within 72 hours in line with DPDP Act guidelines, and provide details of what happened, what data was affected, and what steps to take.
10. Children's privacy
Our services are for adults aged 18 and over. We do not knowingly collect data from minors.
11. Cross-border data transfer
Your data does not leave India unless required by the vendor CA's infrastructure (for example, some vendor systems may host data in tier-1 jurisdictions). This is limited to what the CA needs to issue your certificate.
12. Grievance officer
- Name: Mr. Ashok Kumar
- Email: info@bestdsc.com
- Response time: within 3 business days.
- Postal address: Kodambakkam, Chennai - 600024.
13. Changes to this policy
We may update this policy from time to time. Material changes will be notified via email. The last updated date is shown at the top of this page.
14. Governing law
This policy is governed by Indian law, including the Information Technology Act 2000 and the Digital Personal Data Protection Act 2023.