1. Introduction
Abhita Land Solutions Private Limited, having its registered office at Plot No. C/23, Sector 12, Kharghar, near Gokhale School, Navi Mumbai, Maharashtra, India 410210 (the “Company”, “We”, “Us” or “Our”), is committed to safeguarding the privacy of every person whose personal data is processed through the website www.abhitaeservices.com and the Abhita Verification Portal at portal.abhitaeservices.com (collectively, the “Platform”). This Privacy Policy is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Digital Personal Data Protection Act, 2023, and sets out, in clear and unambiguous terms, the manner in which personal data is collected, used, disclosed, retained and protected by the Company.
This Privacy Policy applies to two distinct categories of data principal: first, the business Client that registers upon and uses the Platform (the “Client”); and second, any third party natural person whose personal data is submitted to the Platform by a Client for the purpose of conducting a verification (the “Data Subject”). The rights and obligations applicable to each category are addressed separately below where the context so requires.
2. Information We Collect
2.1. Client Account Information. At the time of registration, the Company collects the Client’s business name, the name and designation of the authorised representative, registered business address, electronic mail address, mobile telephone number, industry classification, Goods and Services Tax Identification Number where applicable, and a scanned copy of the Client’s business licence or incorporation document.
2.2. Payment Information. The Company collects the quantum of credits purchased and the corresponding transaction identifier issued by its payment aggregator. The Company does not at any point collect, transmit through its own servers, or store the Client’s full debit or credit card number, card verification value, or net banking password, all of which are captured directly upon the secure, Payment Card Industry Data Security Standard compliant infrastructure of the Company’s payment aggregator, ICICI Bank Limited.
2.3. Verification Input Data. In the course of availing of the Services, a Client shall submit identifying particulars of a Data Subject, which may include, depending upon the Service selected, the Permanent Account Number, Aadhaar number, vehicle registration number, Goods and Services Tax number, Universal Account Number, or other similar identifying particular of the Data Subject, together with the Data Subject’s explicit consent where such consent is a statutory precondition to the verification, particularly in respect of Aadhaar based verification.
2.4. Technical and Usage Information. The Company automatically collects the internet protocol address, browser type, device identifier, approximate geographic location derived from the internet protocol address, and log data pertaining to a Client’s access to and use of the Platform, for the purposes set out in Clause 3 below.
3. Purpose and Legal Basis of Processing
The Company processes personal data strictly for the following purposes, each of which constitutes a legitimate use consistent with the Digital Personal Data Protection Act, 2023: to evaluate and process a Client’s application for registration; to facilitate the execution of a verification request placed by a Client and to transmit the requisite identifying particulars to the relevant authorised third party data source, including but not limited to Surepass Technologies and such other licensed verification intermediaries as the Company may engage from time to time, and, where the Service so requires, to regulated credit information companies for the retrieval of credit information reports; to process payment for credits purchased through the Company’s payment aggregator; to detect, prevent and investigate fraud, misuse or unauthorised activity upon the Platform; to comply with applicable law, including requests of law enforcement and regulatory authorities; to maintain the security, integrity and audit trail of transactions conducted upon the Platform; and to communicate with the Client in respect of its account, transactions and Service updates.
Where personal data is processed pursuant to the consent of the Client or the Data Subject, such consent may be withdrawn at any time by writing to the Company at the electronic mail address specified in Clause 10 below, without prejudice to the lawfulness of processing carried out prior to such withdrawal.
4. Disclosure of Information to Third Parties
The Company does not sell, rent or trade personal data to any third party for marketing purposes. Personal data may, however, be disclosed to the following categories of recipient strictly to the extent necessary for the purposes set out in Clause 3 above: authorised verification data providers and application programming interface partners engaged by the Company for the purpose of executing a verification request; the Company’s payment aggregator, ICICI Bank Limited, solely for the purpose of processing payment; cloud infrastructure and hosting service providers engaged for the storage and processing of data upon appropriate contractual safeguards; professional advisors including legal counsel and auditors, where necessary for the protection of the Company’s legal rights; and any governmental, regulatory, judicial or law enforcement authority, where disclosure is required under applicable law or in response to a valid legal process.
5. Data Security
The Company has implemented reasonable security practices and procedures, commensurate with the sensitivity of the information involved, including transport layer encryption of all data transmitted to and from the Platform, encryption of sensitive data at rest, role based access control restricting internal access to personal data on a strict need to know basis, and periodic review of security controls. Notwithstanding the foregoing, the Client acknowledges that no method of electronic transmission or storage is entirely infallible, and the Company cannot guarantee absolute security, though it shall promptly notify affected Clients in the event of any data breach likely to result in harm, in accordance with applicable law.
6. Data Retention
Client account information shall be retained for so long as the Client’s account remains active, and for a further period thereafter as is necessary to comply with the Company’s legal, accounting and regulatory obligations, including but not limited to obligations under applicable tax and anti-money laundering law. Verification report files shall be retained upon the Company’s active systems for thirty (30) days from the date of generation, following which the file may be purged, save that the corresponding transaction metadata shall be retained for the statutory limitation period applicable to civil claims in India. Upon the expiry of the applicable retention period, personal data shall be securely deleted or irreversibly anonymised.
7. Rights of the Data Principal
In accordance with the Digital Personal Data Protection Act, 2023, every data principal, whether a Client or a Data Subject, shall have the right to obtain a summary of the personal data processed by the Company and the processing activities undertaken in respect thereof; the right to seek correction, completion and updating of personal data; the right to erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to the Company’s legitimate retention obligations under applicable law; the right to nominate another individual to exercise these rights in the event of death or incapacity; and the right to have readily available means of grievance redressal in respect of any act or omission of the Company regarding the fulfilment of its obligations under applicable data protection law. Any such request may be addressed to the Company at the electronic mail address specified in Clause 10 below, and shall be responded to within a reasonable period not exceeding thirty (30) days.
8. Cookies
The Platform employs strictly necessary cookies and similar tracking technologies to maintain a Client’s authenticated session, to remember Client preferences, and to gather aggregate, non-identifying analytical data regarding usage of the Platform for the purpose of improving the Services. A Client may configure its browser to refuse cookies, provided that certain features of the Platform may not function as intended in the absence thereof.
9. Data Protection Officer and Grievance Redressal
The Company has designated a Grievance Officer for the purposes of the Information Technology Act, 2000 and applicable data protection law, who may be contacted at the electronic mail address specified below in respect of any grievance concerning the processing of personal data. The Company shall acknowledge such grievance within forty eight (48) hours and shall endeavour to resolve the same within thirty (30) days.
10. Contact Us
Abhita Land Solutions Private Limited
Plot No. C/23, Sector 12, Kharghar, near Gokhale School, Navi Mumbai, Maharashtra, India 410210
Electronic Mail: support@abhitaeservices.com
Telephone: +91 77100 73844
11. Amendment of this Policy
The Company reserves the right to amend this Privacy Policy from time to time to reflect changes in law, technology or the Company’s business practices, and shall publish the revised policy upon the Platform together with the date of the last update. Material changes shall, where reasonably practicable, be additionally notified to Clients by electronic mail.
Last updated: 31 August 2026