Privacy Policy
At iSaral Business Solutions Pvt Ltd, we recognize the critical importance of privacy, especially when handling identity documents for cryptographic verification. This Privacy Policy details how we collect, safeguard, and process your personal information when you use our portal to apply for Digital Signature Certificates (DSC).
1. Information We Collect
To successfully process your DSC applications (via our Individual, Organization, or Foreign national application streams), we collect the following classification of data:
- Personal Identity Records: Full name, date of birth, identity proofs (such as PAN cards, Aadhaar details, passports, or national IDs).
- Contact Documentation: Email address, physical shipping address for USB token deliveries, and mobile verification numbers.
- Corporate Attributes: Organization registration proofs, partnership deeds, or authorization letters when applying for corporate digital signatures.
2. How We Use Your Data
Your sensitive credentials are used strictly for legal validation purposes. Specifically, we utilize your data to:
- Validate your legal identity against government registries under official statutory mandates.
- Submit the authenticated information to authorized Certifying Authorities (CAs) to provision your DSC.
- Coordinate the physical courier delivery of your FIPS-compliant USB cryptographic hardware tokens (e.g., ProxKey, mToken).
3. Data Retention and Key Security
iSaral Business Solutions Pvt Ltd never generates, distributes, or retains your personal private encryption keys. Cryptographic keys are safely populated directly inside your secure hardware token. Personal data records submitted during the enrollment phase are retained only for the window required to satisfy registration compliance and compliance auditing rules.
4. Information Sharing and Disclosure
We do not lease, sell, or trade your personal data to third-party marketing networks. Your data is shared exclusively with:
- Licensed Certifying Authorities (CAs) processing your application.
- Regulating bodies or government agencies where mandated under applicable information technology laws.
- Logistics and delivery partners tasked with sending your hardware tokens to your address.
5. Data Protection Safeguards
We employ industry-standard secure socket layers (SSL/TLS encryption) across all web portals and entry modules. Access to your documentation inside our systems is strictly compartmentalized, ensuring only authorized verification managers handle your data.
6. Your Rights and Preferences
You maintain the right to review, update, or correct mistakes in the profile documentation you submit to us before it is pushed to the Certifying Authority. For structural modifications or compliance questions, please contact our support team directly.
7. Policy Revisions
This policy may adjust incrementally to match systemic framework changes issued by the Controller of Certifying Authorities (CCA). Any modifications will be posted immediately to this web link.