Effective Date: 1 January 2026 · Last Updated: 28 July 2026
1. Introduction
SHRONIX TECHNOLOGY PRIVATE LIMITED ("Company", "we", "us", "our") respects your privacy and is committed
to protecting the personal information you share with us. This Privacy Policy explains how we collect, use, store,
disclose, and safeguard your personal data when you use our Shronix eSign Platform (esign.shronix.in).
This Privacy Policy is issued in compliance with:
- The Digital Personal Data Protection Act, 2023 (DPDP Act)
- The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
- Other applicable Indian laws
2. Information We Collect
2.1 Personal Information You Provide
- Account Information: Name, email address, mobile number, company name, designation.
- Profile Information: Profile photo (optional), business address, GST number (where applicable).
- Payment Information: Billing address; payment is processed by approved gateways and we do not store card details.
- KYC Data (for signatories): Aadhaar number (masked, only last 4 digits stored), name as per Aadhaar, date of birth.
- Document Data: PDF documents you upload, stamp paper images, signatory details (name, email, mobile, role).
- Communications: Records of correspondence with our support team.
2.2 Information Collected Automatically
- Usage Data: Pages visited, features used, time spent, click patterns.
- Device Information: IP address, browser type and version, operating system, device identifiers.
- Location Data: Approximate geolocation (city, state) derived from IP address; precise GPS only with your explicit consent during signing.
- Cookies: See our Cookie Policy for details.
2.3 Information from Third Parties
- UIDAI: When you sign using Aadhaar OTP, we receive verification status (success/failure), masked Aadhaar number, and basic demographic data (name, DOB, gender) from UIDAI.
- Payment Gateways: Transaction status and payment confirmation from Razorpay or other gateways.
- SMS/Email Providers: Delivery status of OTPs and notifications.
3. How We Use Your Information
We use your information for the following purposes:
- To create and manage your account.
- To process and facilitate the digital signing of agreements.
- To verify the identity of signatories through Aadhaar OTP or mobile OTP.
- To send notifications about signing requests, reminders, and confirmations.
- To generate audit trails and signature reports.
- To process payments and send invoices.
- To improve our Platform, develop new features, and analyze usage patterns.
- To prevent fraud, abuse, and unauthorized access.
- To comply with legal obligations, court orders, and regulatory requirements.
- To respond to your support requests and inquiries.
4. Legal Basis for Processing
Under the DPDP Act, 2023, we process your personal data based on:
- Consent: You provide explicit consent at the time of registration and signing.
- Contractual Necessity: Processing required to perform the contract (e.g., providing the eSign service).
- Legal Obligation: Compliance with applicable laws (e.g., audit trails, tax records).
- Legitimate Interests: For fraud prevention, system security, and platform improvement.
5. Aadhaar and Sensitive Personal Data
We treat Aadhaar numbers as sensitive personal data and handle them with utmost care:
- We never store the full 12-digit Aadhaar number; only the last 4 digits are retained for reference.
- Aadhaar OTP transmission and verification happen directly through UIDAI-approved channels.
- We do not share Aadhaar data with third parties except as required by law.
- Aadhaar verification logs are stored securely and accessible only to authorized personnel.
6. Data Sharing and Disclosure
We share your data only in the following circumstances:
6.1 With Other Signatories
When you initiate a signing process, your name, email, and mobile number are shared with other signatories
you designate. Documents are shared with the signatories you specify.
6.2 With Service Providers
We engage trusted third-party service providers who assist us in operating the Platform:
- Cloud Hosting: Servers within India for data storage.
- Payment Gateways: Razorpay and other approved payment processors.
- Communication Providers: Zoho, Zeptomail (for email); WhatsApp Business API providers.
- Identity Verification: UIDAI (for Aadhaar OTP).
- Analytics: Google Analytics (anonymized data only).
All service providers are bound by data processing agreements and may not use your data for any purpose
other than providing services to us.
6.3 Legal Disclosure
We may disclose your information if required by law, court order, or government request, including:
- To comply with legal process (subpoenas, search warrants).
- To respond to lawful requests by public authorities (police, tax authorities, regulatory bodies).
- To protect our rights, property, or safety, or the rights, property, or safety of others.
- To enforce our Terms and Conditions.
6.4 Business Transfers
In the event of a merger, acquisition, or sale of all or part of our business, your information may be
transferred to the acquirer, subject to the same privacy protections.
7. Data Storage and Security
We implement industry-standard security measures to protect your data:
- Encryption: TLS 1.3 for data in transit; AES-256 encryption for sensitive data at rest.
- Access Controls: Role-based access; multi-factor authentication for administrative accounts.
- Server Location: All data stored on servers physically located within India.
- Regular Audits: Internal security audits and vulnerability assessments.
- Backup and Recovery: Encrypted daily backups with disaster recovery procedures.
- Employee Training: All employees receive data protection training.
8. Data Retention
We retain your data as follows:
- Account Data: For as long as your account is active.
- Signed Agreements: Indefinitely or as required for legal evidence (typically 7+ years for contractual records).
- Audit Trails: Minimum 7 years for legal compliance.
- Payment Records: Minimum 8 years as per Income Tax Act, 1961 requirements.
- Marketing Data: Until you opt out.
After the retention period, data is securely deleted or anonymized. You may request earlier deletion subject to legal obligations.
9. Your Rights Under DPDP Act, 2023
You have the following rights regarding your personal data:
- Right to Access: Request a copy of your personal data we hold.
- Right to Correction: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data (subject to legal retention requirements).
- Right to Withdraw Consent: Withdraw consent at any time (this may limit your ability to use the Platform).
- Right to Grievance Redressal: File a complaint with our Grievance Officer.
- Right to Nominate: Nominate a representative to exercise rights on your behalf.
To exercise these rights, please email us at connect@shronix.in
with the subject line "DPDP Request". We will respond within 30 days.
10. Children's Privacy
Our Platform is not intended for individuals under 18 years of age. We do not knowingly collect personal data
from minors. If we become aware that we have collected data from a child without parental consent, we will delete it immediately.
11. International Data Transfers
Your data is primarily stored within India. In certain limited cases, data may be transferred to or accessed from
other countries (e.g., when our service providers operate internationally). Such transfers are made only with
appropriate safeguards as per Indian law.
12. Cookies and Tracking
We use cookies and similar technologies to enhance your experience. For details on what cookies we use and how to
manage them, please refer to our Cookie Policy.
13. Marketing Communications
With your consent, we may send you marketing emails about new features, offers, and updates. You can opt out at
any time by clicking the "Unsubscribe" link in our emails or by emailing us. Transactional emails (account-related,
signing notifications) cannot be opted out as they are essential to the service.
14. Third-Party Links
Our Platform may contain links to third-party websites. We are not responsible for the privacy practices of these
third parties. We encourage you to read their privacy policies before sharing any information.
15. Data Breach Notification
In the unlikely event of a data breach that affects your personal data, we will notify you and the appropriate
authorities within 72 hours of becoming aware of the breach, as required by the DPDP Act, 2023.
16. Grievance Officer
In compliance with the Information Technology Rules, 2021 and the DPDP Act, 2023, we have designated a Grievance Officer:
For complete information on raising a grievance, please refer to our Grievance Redressal Policy.
17. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be effective when posted on this page with the
updated "Last Updated" date. We will notify you of material changes via email or in-app notification.
18. Contact Us
For questions about this Privacy Policy or our data practices, contact us at:
Your Consent: By using our Platform, you consent to the collection, use, and disclosure of your
information as described in this Privacy Policy.