Legal
Privacy Policy
Last updated: 21 August 2026
In short: ProofKosh is operated by ROSTAN Technologies Pvt. Ltd. We collect only the personal data we need to run the service, we host it in India, we never sell it, and we process it on the legal bases set out below. You can access, correct, or erase your data and raise a grievance at any time using the contacts at the end of this policy.
1. Who we are
This website (proofkosh.com) and the ProofKosh application (app.proofkosh.com) are owned and operated by ROSTAN Technologies Pvt. Ltd. ("ProofKosh", "we", "us"). For the personal data we handle to run and market our own business, we act as the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). When our customers use ProofKosh to record the consent and data of their users, we act as a Data Processor on the customer's behalf (see section 7).
2. What data we collect
- Account & contact data — name, work email, company name, and role, when you sign up, book a demo, or contact us.
- Billing data — the details needed to take payment. Card details are handled by our payment processor (Razorpay); we do not store full card numbers.
- Usage & device data — pages visited, actions taken in the app, IP address, browser and device type, collected to keep the service secure and working.
- Analytics cookies — only if you consent. You can change your choice anytime from the "Cookie preferences" link in the footer.
- Customer data in the platform — the consent records, data-rights requests, and audit evidence your business puts into ProofKosh. This belongs to you; we only process it (section 7).
3. Why we use it, and our legal basis
Under the DPDP Act we process personal data on one of two bases — your consent, or a legitimate use permitted by the Act (such as providing a service you asked for). Specifically:
- To provide the service you signed up for — create and run your account, store your compliance records, and process payments.
- To respond to you — handle demo requests, support questions, and enquiries.
- To keep the service safe and reliable — security, fraud prevention, debugging, and preventing misuse.
- Marketing — we send product and marketing emails only where permitted, and every such message lets you opt out. Analytics run only with your consent.
- Legal obligations — to comply with tax, accounting, and other laws that apply to us.
4. Where your data is stored
Personal data of our customers and their users is hosted in India. We use reputable infrastructure and sub-processors and hold data only in regions consistent with the DPDP Act and any restrictions the Central Government notifies. Where a sub-processor operates outside India for a limited support function, we do so only as permitted by law and under appropriate safeguards.
5. How long we keep it
We keep personal data only as long as needed for the purpose it was collected for, or as required by law. When you close your account we delete or anonymise your personal data within a reasonable period, except records we must retain for legal, tax, or audit reasons. Because consent and audit records are, by design, tamper-evident evidence, they are retained for as long as you keep them in your workspace and are removed when you delete them or close your account.
6. Who we share it with
We do not sell your personal data. We share it only with service providers who help us run ProofKosh, under contract and only for that purpose — for example:
- Payments — Razorpay, to process subscriptions.
- Hosting & database — our India-based cloud and database providers.
- Authentication, email & analytics — providers that handle sign-in, transactional email, and (with your consent) usage analytics.
We may also disclose data where required by law, or to protect our rights and the safety of our users.
7. Data our customers put into ProofKosh
When a business uses ProofKosh to collect and store the consent and personal data of its own users, that business is the Data Fiduciary and we are its Data Processor. We process that data only on the customer's documented instructions, protect it under our agreement with them, and return or delete it when the relationship ends. If you are an end user of a business that uses ProofKosh and want to exercise your rights, please contact that business — they control your data. We will support them in responding.
8. Your rights
Under the DPDP Act, in relation to the personal data for which we are the Data Fiduciary, you have the right to:
- Access a summary of the personal data we hold about you and how we process it.
- Correction & erasure — have inaccurate data corrected and data no longer needed erased.
- Withdraw consent at any time, as easily as you gave it (this won't affect processing already done).
- Grievance redressal — raise a complaint with us, and nominate another person to exercise your rights in the event of death or incapacity.
The quickest way to exercise these rights is through our live data-rights portal: file a data-rights request → (we use our own product for this). You can also email us using the details below.
9. Cookies
We use essential cookies to run the site, and analytics cookies only if you consent. You can accept, decline, or change your choice at any time using the Cookie preferences link in the footer of every page.
10. Children
ProofKosh is a business tool and is not directed at children. We do not knowingly process the personal data of a child (under 18) without verifiable parental consent, as required by the DPDP Act. If you believe a child has given us data, please contact us and we will delete it.
11. Security
We use reasonable technical and organisational safeguards — encryption in transit, access controls, and tamper-evident, append-only audit records — to protect personal data. No system is perfectly secure, but if a personal data breach occurs we will notify the Data Protection Board of India and affected individuals as the Act requires.
12. Changes to this policy
We may update this policy as our service or the law changes. We'll revise the "Last updated" date above and, for material changes, give you clear notice.
13. Contact & grievances
For any privacy question, or to raise a grievance about how we handle your data, contact our grievance point of contact:
ROSTAN Technologies Pvt. Ltd.
Grievance / Data Protection contact: privacy@proofkosh.com
General enquiries: hello@proofkosh.com
If your concern is not resolved, you have the right to complain to the Data Protection Board of India.
This policy is provided for transparency and is not legal advice. Back to home