Compliant with EU GDPR, CCPA, and India Digital Personal Data Protection (DPDP) Act, 2023 & DPDP Rules, 2025.
Last Updated: September 26, 2026DPDP Act 2023 Compliant
We collect information necessary to deliver and improve our Services. This includes:
We use your personal data to:
Under DPDP Act Sec. 8(5) and Rule 6, we implement reasonable technical and organizational security safeguards, including TLS 1.3/HTTPS encryption in transit, AES-256 encryption at rest, secure Argon2 password hashing, isolated database architecture, HttpOnly session cookies, and automated security log monitoring.
Under India DPDP Act Sec. 11/13 and GDPR Article 17/20, Data Principals have the statutory right to request access to, correction of, consent withdrawal for, or complete deletion of their personal data.
You can manage itemized consent preferences, download 1-click JSON data packages, submit statutory requests, or trigger full account deletion through your interactive Privacy & Governance Center.
Under DPDP Act Sec. 6, consent given by a Data Principal must be free, specific, informed, unconditional, and unambiguous. BotDigit unbundles consent so that optional processing (AI project matching, marketing, and performance analytics) is independent of required core service delivery. You may grant or withdraw optional consent at any time without affecting platform access.
We retain personal data only for as long as necessary to fulfill specified processing purposes or legal compliance (DPDP Sec. 8(7)).
Financial Ledger Exception: When a user requests account deletion, profile PII is anonymized (deleted_[id]@deleted.botdigit.com). However, transaction logs, escrow records, and invoice ledgers in wallet_db are retained to preserve financial ledger integrity and comply with statutory tax and financial auditing laws.
All credit card, debit card, UPI, and bank transfer credentials are processed securely by our integration partners, Stripe and Razorpay, under Payment Card Industry Data Security Standards (PCI-DSS).
Under DPDP Act Sec. 16, cross-border transfers to third-party processors are permitted subject to government notifications and binding Data Processing Agreements (DPAs). You can inspect all verified data processor countries in your Privacy Center.
BotDigit is a professional freelance marketplace and escrow system strictly designed for individuals aged 18 or older (DPDP Sec. 9). We do not knowingly collect personal data from minors. Any account discovered to belong to a minor under 18 will be terminated immediately.
Under DPDP Act Sec. 14 & Rule 14(4), Data Principals have the right to nominate a designated individual to exercise data rights on their behalf in the event of death or incapacity. Nominees can be managed in your Privacy Center.
Under DPDP Act Sec. 13 & Rule 9, Data Principals may raise privacy grievances. All statutory complaints receive formal resolution within a maximum of 30 days. Contact our Data Protection Officer at:
Email: [email protected]
Attn: Data Protection Officer, BotDigit Inc.
Statutory SLA: 30-Day Response Guarantee