Privacy Policy
Contents
- 1. Introduction
- 2. Applicability of this policy
- 3. Definitions
- 4. Why does AuthBridge collect/obtain Personal Data?
- 5.What type of Personal Data does AuthBridge collect via TruthScreen?
- 6. How does AuthBridge obtain Personal Data?
- 7. Representation
- 8. To whom AuthBridge discloses your Personal Data?
- 9. Does AuthBridge transfer the Personal Data?
- 10. How does AuthBridge protect the Personal Data it holds?
- 11. How to withdraw consent or request to update/delete any Personal Data?
- 12. Children’s Privacy
- 13. Rights for EU Data Subjects
- 14. How long does AuthBridge retain your Personal Data?
- 15. Change to this privacy policy
- 16. Contact us
1. Introduction
AuthBridge is committed to protecting the privacy and confidentiality of Personal
Data it collects. The purpose of this Privacy Policy is to explain how AuthBridge
Research Services Private Limited & its subsidiaries (collectively referred to as
“AuthBridge”) collect, process, store, use, transfer, and protect the Personal Data
(as defined herein after) for providing TruthScreen services to its Clients.
2. Applicability of this policy
This Policy is applicable to the Personal Data collected for AuthBridge’s Clients
and their employees/individuals (Verification subjects) for whom the services of
TruthScreen have been taken and ensuring that any Personal Data collected directly
or indirectly for TruthScreen services is processed fairly and lawfully.
3. Definitions
Personal Data: means any information that relates to a natural person, which, either
directly or indirectly, in combination with other information is capable of
identifying such person.
Sensitive Personal Data: Sensitive Personal Data is a specific set of “special category” Personal Data. (Such as – Financial information, medical records, and history etc.)
Verification subject: Individual whose verification is conducted via TruthScreen
Client: who have an engagement with AuthBridge to undertake screening of the Verification Subject
Sensitive Personal Data: Sensitive Personal Data is a specific set of “special category” Personal Data. (Such as – Financial information, medical records, and history etc.)
Verification subject: Individual whose verification is conducted via TruthScreen
Client: who have an engagement with AuthBridge to undertake screening of the Verification Subject
4. Why does AuthBridge collect/obtain Personal Data?
AuthBridge obtains Personal Data in an authorized manner only for providing various
screening services to the Clients.
5.What type of Personal Data does AuthBridge collect via
TruthScreen?
Personal Data collected on TruthScreen application may vary as per Client’s scope of
work agreed with AuthBridge.
The Personal Data collected via TruthScreen will include but not be limited to:
- Individual details (such as -Name, Date of Birth, Gender)
- Birth country, Birth City
- Contact number (mobile, residence), E-mail ID
- family details (parents’ name)
- address details.
- Identity details/ document (Passport/Driving License/PAN card/Voter card/Aadhaar)
- Professional Membership/ Registration number
- Photograph
- Electronic signature
- IP address, GPS
- UAN
- Electricity bill Service number
- Vehicle registration number
- Ration card number
- Marital status
- credit and financial details
- Biometric data (for facial recognition)
6. How does AuthBridge obtain Personal Data?
Personal Data is collected from the Verification Subject or from the Client directly on the platform - TruthScreen or via Application Program Interface (“API”) or indirectly through other business process application serving the Clients.
In some cases, the Personal Data processing for screening might generate some additional Personal Data as an output of the processing which is also protected under this Privacy Policy.
The records of processing activities are maintained in accordance with the contractual requirement of clients or as maybe required under applicable laws.
Individuals who directly enter their Personal Data on TruthScreen application for testing, demo or trial purposes will be required to provide their express consent before providing any Personal Data.
7. Representation
Clients sharing the Personal data of Verification Subjects on TruthScreen, represent
that they have the right to disclose and provide AuthBridge with the Personal Data
and hereby agree to indemnify and hold AuthBridge harmless for any disclosure made.
AuthBridge is not obligated to seek consent of any person whose Personal Data is
provided to AuthBridge on TruthScreen.
It is the responsibility of the Client who are undertaking the TruthScreen API for screening services to ensure that the Verification Subject whose screening is being undertaken, is aware of the processing of his/her Personal Data by AuthBridge and has consented to the same.
It is the responsibility of the Client who are undertaking the TruthScreen API for screening services to ensure that the Verification Subject whose screening is being undertaken, is aware of the processing of his/her Personal Data by AuthBridge and has consented to the same.
8. To whom AuthBridge discloses your Personal Data?
AuthBridge will disclose your Personal Data to its authorized employees who may need
to perform service related to screening activities as requested by the Client.
Personal Data can also be disclosed to the concerned authorities under following circumstances-
Personal Data can also be disclosed to the concerned authorities under following circumstances-
- Where AuthBridge is under an obligation by law or any statutory or regulatory order, notification, or regulations to disclose any Personal Data.
9. Does AuthBridge transfer the Personal Data?
AuthBridge may need to transfer individual’s Personal Data to third party service
providers for providing services on TruthScreen.
Personal Data will be shared/transferred either to retrieve or collect data or information from -
Personal Data will be shared/transferred either to retrieve or collect data or information from -
- Verification source/authorized third party websites
- any other Institutions you are registered with or where your records are available/ obtained from
10. How does AuthBridge protect the Personal Data it
holds?
AuthBridge is certified to ISO/IEC 27001:2013 and has appropriate technical and organizational information security measures in line with this international standard and applicable privacy or any other applicable regulations.
All our data infrastructure is hosted on Amazon Web Services (AWS), a cloud computing platform with best practices for global privacy and data protection. We have legal contract and confidentiality contract signed with them. The access on AWS server is limited to authorized personnel in AuthBridge only.
Any Personal Data/Sensitive Personal Data is classified as confidential as per AuthBridge information classification policy. Risk assessment activity is conducted and based on assessment, suitable security controls are identified and implemented to protect Personal Data/ Sensitive Personal Data from any unauthorized disclosure, access, loss, misuse, or alteration.
The various security measures consist of privacy controls such as purpose limitation, data minimization, Personnel Security including background checks & Privacy awareness, Physical security and IT security controls including but not limited to access controls, system security, network security, communication security, application security, encryption, multi-factor authentication, vulnerability assessments, log monitoring, Incident Management and Internal/ External Audits etc.
11. How to withdraw consent or request to update/delete any
Personal Data?
Most of the screening services provided via the TruthScreen application are
instantaneous. So, once you share your Personal Data it is processed instantly.
Personal Data should not be entered on TruthScreen if Verification Subject does not
want to proceed with the verification.
Where the verification request is not processed instantly, to withdraw consent or
request to update/delete any Personal Data, individual/Verification subjects may
reach out to AuthBridge’s Client they have engagement with. On receiving such
requests from our client, AuthBridge will surely act upon the same.
12. Children’s Privacy
AuthBridge neither knowingly collect Personal Data from anyone under the age of 18
(minors) nor provide any services to them.
In case our Clients require us to do processing of Personal Data of a minor they must inform AuthBridge in advance and provide the parental consent if the Verification Subject is below 18 years of age.
In case our Clients require us to do processing of Personal Data of a minor they must inform AuthBridge in advance and provide the parental consent if the Verification Subject is below 18 years of age.
13. Rights for EU Data Subjects
In general, TruthScreen is not used for verification of Personal Data of EU
subjects. In case, any Personal Data of EU (European Union) subjects is being shared
on TruthScreen, the Data Subjects have the following rights with respect to their
Personal Data, subject to conditions and restrictions set out under applicable laws-
- to know about their Personal Data being processed or request a copy
- to request the correction/update, erasure, or the restriction of the processing
- to object to AuthBridge’s processing or to withdraw consent
- to lodge a complaint with the applicable regulatory/ supervisory authority
14. How long does AuthBridge retain your Personal Data?
AuthBridge retains the Personal Data collected as per the agreement & instructions
of its clients. Also, it may be kept in masked form as prescribed by the Regulatory
Body (where applicable). In case you have any query, please connect with
AuthBridge's client you have engagement with.
15. Change to this privacy policy
We may review and update this Privacy Policy from time to time. To let you know
about the latest revision, we will amend the revision date on top of this page.
16. Contact us
If you wish to contact AuthBridge for any privacy related query/concern, please send
an email at privacy@authbridge.com