Bhuvansh is an invitation-only, identity-verified community platform. This policy explains what we collect, why, how long we keep it, and the rights you have under India's Digital Personal Data Protection Act, 2023 (DPDP Act).
Everyone who creates or uses a Bhuvansh account. Membership requires an invitation from an existing verified member and completion of identity verification (KYC).
| Category | Examples | Why |
|---|---|---|
| Identity | Name, date of birth, gotra, native place | Membership eligibility and the family graph |
| Contact | Phone number, email address | Sign-in, security notices, account recovery |
| KYC documents | PAN, Aadhaar (offline XML only), live selfie | Verifying that every member is a real, identifiable person |
| Profile | Education, occupation, income band, photos | Features you choose to use — jobs, matrimony, mentorship |
| Relationships | Family members, verified connections | The community graph |
| Messages | Direct messages between members | Delivering your messages — see §4 |
| Location | Precise location | Only while you have an active SOS emergency |
| Technical | Device model, OS version, app version, IP address | Security, abuse prevention, crash diagnosis |
We accept Aadhaar only as an offline e-KYC XML or via DigiLocker. We never ask for, store, or display your 12-digit Aadhaar number. Our servers reject any submission containing raw Aadhaar digits. We retain only the verification result and a masked reference.
Messages are encrypted on your device for the recipient's public key before they leave it. We store only ciphertext and cannot read your messages. We can see who messaged whom and when, which we use for abuse handling. If you lose your device and your key, past messages cannot be recovered — by you or by us.
Location is requested only when you trigger an SOS emergency, shared only with responders you are matched to for that emergency, and never used for advertising, analytics, or profiling.
We do not sell your personal data. We do not use it to train third-party models. We do not track you across other apps or websites.
Only where necessary: infrastructure providers hosting our servers in India; a payment processor when you donate (they receive payment details, not your profile); SMS and email providers to deliver codes and notices; and law enforcement where legally compelled. Every processor is bound by contract to use the data only for the service they provide.
| Data | Retention |
|---|---|
| Account and profile | While your account is open, then 30 days after closure |
| KYC verification records | As required by applicable law, then deleted |
| Messages | Until you or the other participant deletes them, or account closure |
| Audit and security logs | Up to 24 months |
| Donation records | As required by tax and financial law |
Under the DPDP Act you may:
We would rather tell you precisely than tell you "everything" and be wrong. When you delete your account, three things happen to different records.
Deleted outright — everything that exists only to serve you. Your profile, professional and financial details, identity documents from verification, matrimony profile and questionnaire answers, private messages and your encryption keys, blood-donor registration and health requests, SOS alerts and their locations, job applications, business listings, notification settings and device registrations. Your account is stripped of your email, phone, name, password and two-factor secret, and can never be signed in to again.
Kept, but no longer linked to you — records that other members depend on. A donation stays in a charity's financial record; a fundraiser with donors stays up; a job posting stays visible so applicants keep their history. In each case the row survives and your identity is severed: we overwrite it with a random identifier that cannot be traced back to you.
Kept, because the law requires it — a small set of records we are not permitted to destroy:
You can see exactly what was removed and what was kept for your own account, with the reason for each retention, at any point after requesting deletion.
If you have a complaint about how your personal data is handled, contact us first — you do not need to go elsewhere before raising it with us.
| bhuvansh.app@nyutechden.com | |
| Telephone | +91 94804 42326 |
| Response time | Within 30 days, as required by the DPDP Act |
| Officer | [NAME — TO BE APPOINTED] |
If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
[LEGAL ENTITY NAME, REGISTERED ADDRESS, CIN — TO BE COMPLETED]
Data is encrypted in transit (TLS 1.2+) and at rest. Access tokens are held in your device's Keychain or Keystore. KYC documents are stored separately with their own encryption keys and restricted access. Two-factor authentication using an authenticator app is available and recommended.
Bhuvansh is not for anyone under 18. We do not knowingly hold data about children. If we learn we have, we delete it.
We will notify you in the app before any material change takes effect, and record your consent to the new version.