Privacy Policy

Last Updated: May 2026

1. Introduction

Welcome to Infiverix. We are a SaaS platform built to help Indian startups manage DPDP Act compliance. Because data privacy is literally our business, we practice what we preach. We only collect what we need, we secure it heavily, and we never sell your data to third parties.

2. Data We Collect

When you use Infiverix, we collect the following:

  • Account Information: Your name, email, and company domain to provision your workspace.
  • End-User Data (Processed on your behalf): Email addresses of your customers who submit deletion requests via the Infiverix widget.
  • Audit Logs: Timestamps and cryptographic hashes of resolved deletion tickets.

3. How We Use It

Your data is used exclusively to operate the Infiverix platform. This includes:

  • Authenticating your account via Clerk.
  • Sending transactional OTP verification emails to your users (powered by Resend).
  • Maintaining your 30-day SLA compliance dashboard.
  • Generating immutable JSON audit receipts for your records.

4. Data Storage & Security

Data Localization: All core database records and audit logs are securely stored on our AWS infrastructure located exclusively in the Mumbai (ap-south-1) region to comply with Indian data localization preferences.All core database records and audit logs are stored on AWS Mumbai Server keeping your data within India.

We employ strict tenant isolation mechanisms (Row-Level Security) to ensure your data is entirely siloed from other users on the platform.

5. Your Rights under the DPDP Act

As an Indian citizen, you have the right to:

  • Access the personal data we hold about you.
  • Correct any inaccuracies in your data.
  • Right to Erasure: You can request the permanent deletion of your account and associated personal data at any time via your dashboard settings or by contacting us.

6. Jurisdictional Scope & Limitation

Infiverix is an Indian company that operates exclusively under the jurisdiction of the Digital Personal Data Protection (DPDP) Act, 2023 enacted by the Parliament of India.

Infiverix does not operate under, comply with, or make any representations regarding compliance with any international data protection regulations, including but not limited to:

  • The European Union's General Data Protection Regulation (EU GDPR)
  • The UK General Data Protection Regulation (UK GDPR)
  • The California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA)
  • The Personal Information Protection and Electronic Documents Act (PIPEDA, Canada)
  • Any other foreign, international, or extra-territorial data protection framework

Our services, data processing infrastructure, and compliance tooling are designed solely for Indian Data Fiduciaries operating within the territory of India. If you are a business operating outside India, or if your primary user base is outside India, Infiverix is not the appropriate compliance solution for your needs.

All disputes arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts in Ahmedabad, Gujarat, India.

7. Contact Us

If you have any questions about this policy or your data, you can reach our Grievance Officer:
support@infiverix.com