ZyroAI
Trust Center
Legal · DPDP Act 2023

Privacy Policy

Last updated · 21 May 2026 · Effective DPDP Act commencement

Contents

1. Who we are 2. What we collect 3. Why we process 4. Where data lives 5. Retention 6. Your rights (DPDP) 7. Security 8. Contact + Grievance
100% India data residency. All personal data stored in Mumbai region · AES-256-GCM at rest · TLS 1.2+ in transit.

1. Who we are

ZyroAI Technologies Pvt Ltd, Bangalore (Karnataka, India), is the data processor for identity verification on behalf of our customers (banks · NBFCs · brokers · fintechs). Your bank / fintech is the data fiduciary; we process under their instructions.

2. What we collect

CategoryWhenSource
ID document imageYou upload during KYCYou
Selfie · live-capture videoLiveness stepYour camera
Voice sample (optional)Voice biometric stepYour microphone
Extracted text (name · DOB · ID #)Auto-OCRFrom your document
Mobile · email (optional)Form inputYou
Device fingerprint · IPService useYour browser/app
Verification result · reason code · LLM rationaleGeneratedZyroAI ML

3. Why we process

PurposeDPDP Section 7
Identity verification for your bankConsent
Fraud · deepfake · sanctions screeningLegitimate use
RBI · SEBI · PMLA complianceLegitimate use
Continuous model improvement (opt-in)Consent · opt-in by tenant

We do not sell data. We do not use it for advertising.

4. Where data lives

Storage · Mumbai region (asia-south1) · AWS / GCP India. Cross-border · zero personal data leaves India. Encryption · AES-256-GCM at rest · TLS 1.2+ in transit. Access · only your bank (via webhook) and ZyroAI engineers under least-privilege.

5. Retention

DataRetention
Verification record + audit log8 years (PMLA Sec 12(a))
Selfie / document image90 days post-verification
Live-capture video30 days
Failed-verification PII30 days
Anonymized metricsIndefinite

6. Your rights under DPDP Act 2023

RightHow
AccessEmail dpdp@zyroai.com with verification reference
CorrectionSame email · officer-mediated
ErasureSame email · within 30 days
Withdraw consentSame email · immediate
Grievancegrievance@zyroai.com · 7-day SLA
NomineeEmail with nominee details

7. Security

Data breach · we will notify affected data principals and the Data Protection Board within 72 hours per DPDP Sec 8(6).

8. Contact + Grievance

General privacy
DPDP rights
Grievance
Data Protection Officer

Grievance Officer · designated under DPDP Sec 13.
Response SLA · 7 working days. Escalation · Data Protection Board of India.

Public listing · Grievance Officer details published at /grievance. Monthly aggregate complaint statistics at /transparency.