Data Governance & CompliancePrivacy Policy & Data Governance

Compliant with EU GDPR, CCPA, and India Digital Personal Data Protection (DPDP) Act, 2023 & DPDP Rules, 2025.

Last Updated: September 26, 2026DPDP Act 2023 Compliant

01. Information We Collect

We collect information necessary to deliver and improve our Services. This includes:

  • Account Profile Data: Name, email address, password hash, profile photos, and role identification details.
  • Verification Data: Documents, identity logs, and proof of residence required to support regulatory AML/KYC checks.
  • Financial Data: Wallet addresses, transaction logs, and payout configurations for escrow settlement.
  • Log & Usage Data: IP addresses, browser types, interaction logs, and device operating system context.

02. How We Use Information

We use your personal data to:

  • Administer and optimize the BotDigit escrow and workspace platform.
  • Verify accounts, secure access control via multi-factor authentication (MFA), and detect fraud.
  • Facilitate real-time collaborative features in workspace channels.
  • Provide active support, process payouts, and send essential email verification alerts.

03. Third Party Sharing

BotDigit does not sell, rent, or trade your personal data. We only share information with trusted third-party services that enable platform functionality, such as database servers, email delivery services, identity verification providers, and payment processors. All sharing complies strictly with data processors' privacy terms.

04. Security Safeguards

Under DPDP Act Sec. 8(5) and Rule 6, we implement reasonable technical and organizational security safeguards, including TLS 1.3/HTTPS encryption in transit, AES-256 encryption at rest, secure Argon2 password hashing, isolated database architecture, HttpOnly session cookies, and automated security log monitoring.

05. Your Data Rights & Deletion Procedures

Under India DPDP Act Sec. 11/13 and GDPR Article 17/20, Data Principals have the statutory right to request access to, correction of, consent withdrawal for, or complete deletion of their personal data.

Self-Service Privacy Center & Account Erasure

You can manage itemized consent preferences, download 1-click JSON data packages, submit statutory requests, or trigger full account deletion through your interactive Privacy & Governance Center.

07. Data Retention & Financial Integrity

We retain personal data only for as long as necessary to fulfill specified processing purposes or legal compliance (DPDP Sec. 8(7)).

Financial Ledger Exception: When a user requests account deletion, profile PII is anonymized (deleted_[id]@deleted.botdigit.com). However, transaction logs, escrow records, and invoice ledgers in wallet_db are retained to preserve financial ledger integrity and comply with statutory tax and financial auditing laws.

08. Payment Processor Data & Compliance

All credit card, debit card, UPI, and bank transfer credentials are processed securely by our integration partners, Stripe and Razorpay, under Payment Card Industry Data Security Standards (PCI-DSS).

09. Cookies & Tracking Technologies

Detailed information regarding cookie classifications and your controls is available in our dedicated Cookie Policy.

10. Cross-Border Data Transfers

Under DPDP Act Sec. 16, cross-border transfers to third-party processors are permitted subject to government notifications and binding Data Processing Agreements (DPAs). You can inspect all verified data processor countries in your Privacy Center.

11. Minors & Age Policy (18+ Platform)

BotDigit is a professional freelance marketplace and escrow system strictly designed for individuals aged 18 or older (DPDP Sec. 9). We do not knowingly collect personal data from minors. Any account discovered to belong to a minor under 18 will be terminated immediately.

12. Right to Nominate

Under DPDP Act Sec. 14 & Rule 14(4), Data Principals have the right to nominate a designated individual to exercise data rights on their behalf in the event of death or incapacity. Nominees can be managed in your Privacy Center.

13. Data Protection Officer & Grievance Redressal

Under DPDP Act Sec. 13 & Rule 9, Data Principals may raise privacy grievances. All statutory complaints receive formal resolution within a maximum of 30 days. Contact our Data Protection Officer at:

Email: [email protected]
Attn: Data Protection Officer, BotDigit Inc.
Statutory SLA: 30-Day Response Guarantee

HomeJobs
Get Started
ExploreSign In