We align our security practices with the following Indian framework:
Information Technology Act, 2000 (IT Act) and rules thereunder: We implement reasonable security practices and procedures as required under the IT Act and applicable rules (including the SPDI Rules) to protect sensitive personal data and prevent unauthorised access, use, or disclosure.
Digital Personal Data Protection Act, 2023 (DPDP Act): We process personal data in accordance with the DPDP Act, including lawful grounds for processing, purpose limitation, data minimisation, and implementation of appropriate technical and organisational measures. We support data principal rights as provided under the law.
Sectoral guidelines: Where our customers operate in regulated sectors (e.g. RBI-regulated entities, healthcare, defence), we design our security and data handling to support their compliance with applicable sectoral guidelines.