← Back to home

Privacy Policy

Effective date: [Effective date]

Draft — pending legal review. This document is a working draft prepared for review. It is not yet legal advice and should be reviewed and approved by qualified counsel before it is relied upon or published to customers.

This Privacy Policy describes how Kiauth OVSE handles personal data, including the special safeguards that apply to Aadhaar-based verification under Indian law.

1. Who we are

Kiauth OVSE (“Kiauth”, “we”, “us”) is a compliance and identity-verification platform operated by Kiauth Digitech Private Limited, an Offline Verification Seeking Entity (OVSE) technical operator, [registered office address], CIN [•].

This Privacy Policy explains how we handle personal data across our website and application at ovse.kiauth.com. It should be read with our Terms & Conditions.

2. Our role: fiduciary and processor

For the account holders who use our platform (property owners, managers, and staff), Kiauth is the Data Fiduciary for the account data they provide.

For guest verification data processed during a check-in, our customer (the hotel/property) is the Data Fiduciary and Kiauth acts as a Data Processor, handling that data only on the customer’s instructions and to provide the service and meet the statutory obligations described below.

3. Data we collect

Account data: name, email address, mobile number, role, and workspace/property details you enter.

Guest verification data (on the customer’s behalf): the guest’s name, date of birth, gender, address, photograph, a reference identifier, booking reference, room, and stay dates. For foreign guests, the additional details required for Form C / FRRO.

Aadhaar data — a hard limit: our verification methods are designed so that only the last four digits of an Aadhaar number are ever present, inside a reference identifier. We do NOT collect, store, log, cache, or transmit the full 12-digit Aadhaar number in any form. If a full Aadhaar-shaped number is ever submitted, it is rejected at our system boundary and never saved.

Technical data: limited logs, device and IP information used for security, fraud prevention, and service reliability.

Payment data: billing is processed by our payment partner (Razorpay). We do not store full card details on our servers.

4. How and why we use data

  • To perform Aadhaar and other identity verification requested by the customer.
  • To create and maintain the legally mandated digital guest register, and to prepare Form C / FRRO records for foreign guests.
  • To provide, secure, and support the platform, including authentication, abuse prevention, and audit logging.
  • To process subscription payments and send service and transactional communications (for example, one-time passwords).

We do not use guest verification data for advertising, and we never sell personal data.

5. Legal bases (DPDP Act, 2023)

We process personal data on one or more of the following bases: the consent of the individual (guest consent is captured at check-in before verification); compliance with a legal obligation (the statutory guest register and FRRO filing); and other legitimate uses permitted under the Digital Personal Data Protection Act, 2023.

Aadhaar-related processing is carried out in accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and applicable UIDAI regulations governing offline verification.

6. Aadhaar offline verification — special safeguards

Aadhaar verification is performed offline: the guest’s UIDAI-signed credential (Offline e-KYC file, Secure QR, or the Aadhaar App credential) is validated inside our own backend against UIDAI’s public certificates.

The Offline e-KYC XML/ZIP, the Share Code, and the Aadhaar credential are never sent to any third-party service — no external OCR/AI vendor, log aggregator, or analytics tool. All parsing and validation happens within our infrastructure. This is a legal constraint under the Aadhaar Act, 2016 (including ss. 29 and 37), not merely a preference.

7. Sharing and sub-processors

We do not sell personal data. We share data only as needed to run the service, with sub-processors bound to protect it and to process it only on our instructions:

  • Cloud database, authentication, and storage hosting (in India).
  • SMS delivery for one-time passwords.
  • Payment processing (Razorpay).
  • Email delivery for account communications.

We may also disclose data where required by law or lawful government request. The Aadhaar offline credential itself is never shared with any of these parties.

8. Data residency

All personal data is stored in India (the Mumbai / ap-south-1 region). Each property’s guest data is isolated from every other property at the database level.

9. Retention and erasure

The guest register is a statutory record and must be retained for the period required by applicable law; it cannot simply be deleted on request.

Other personal data that is no longer necessary is reduced and eventually erased on a schedule, in line with the data-minimisation principle under the DPDP Act — a staged, scheduled process rather than an immediate hard deletion, so that the legally mandated register is preserved while excess personal data is removed.

10. Security

We apply organisational and technical safeguards including per-property database isolation (row-level security), encryption in transit and at rest, managed key handling, least-privilege access controls, and an append-only audit log of sensitive actions. No system is perfectly secure, but we work to protect your data and to notify affected parties and authorities as required if a personal-data breach occurs.

11. Your rights

Subject to applicable law and the statutory retention described above, you may request access to, and correction or erasure of, your personal data, withdraw consent, and nominate another person to exercise your rights. Guests should ordinarily raise such requests with the hotel/property (the Data Fiduciary); we will assist our customers in fulfilling them.

To exercise a right or raise a concern, contact our Grievance Officer below.

12. Grievance Officer

Grievance Officer: [Name]

Email: [grievance@kiauth.com]

Phone: [•]

Address: [registered office address]

We aim to acknowledge and address grievances within the timelines prescribed under applicable law.

13. Cookies

We use a small number of strictly necessary cookies, primarily to keep you signed in. We do not use advertising cookies.

14. Children

The platform is intended for use by businesses and their staff, not by children. Guests are checked in by the property in accordance with its own policies and applicable law.

15. Changes to this policy

We may update this policy from time to time. Material changes will be notified through the platform or by other reasonable means, and the effective date above will be updated.

Terms & ConditionsPrivacy Policy
Privacy Policy — Kiauth OVSE · Kiauth OVSE