Privacy Policy

Last Updated: October 8, 2025

1. Introduction

BlackBear Labs ("we," "our," or "us") operates a KYC verification and identity verification platform for P2P crypto trading in India. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our services.

We are committed to protecting your personal data in compliance with the Information Technology Act, 2000, the Digital Personal Data Protection Act, 2023 (DPDP Act), and other applicable Indian laws.

2. Information We Collect

2.1 Personal Identification Information

  • Full name, date of birth, gender
  • PAN (Permanent Account Number) details
  • Aadhaar number and related information
  • Photographs and biometric data
  • Address and contact information
  • Nationality and place of birth

2.2 Technical Information

  • IP address, browser type, and device information
  • API usage logs and timestamps
  • Cookies and similar tracking technologies

2.3 Financial Information

  • Payment transaction details (processed via Razorpay)
  • Credit purchase history
  • Billing information

3. How We Use Your Information

We use the collected information for:

  • Identity Verification: To verify your identity documents (PAN, Aadhaar) through our verification services
  • AML Screening: To conduct Anti-Money Laundering checks and compliance screening
  • Service Delivery: To provide and maintain our KYC verification platform
  • Fraud Prevention: To detect and prevent fraudulent activities
  • Legal Compliance: To comply with legal obligations under Indian law
  • Customer Support: To respond to your queries and provide technical assistance
  • Service Improvement: To analyze usage patterns and improve our services

4. Legal Basis for Processing (DPDP Act Compliance)

Under the Digital Personal Data Protection Act, 2023, we process your personal data based on:

  • Consent: You provide explicit consent when using our verification services
  • Legitimate Purpose: Processing is necessary for KYC verification and AML compliance
  • Legal Obligation: Compliance with Prevention of Money Laundering Act (PMLA) and other applicable laws

5. Data Sharing and Disclosure

We may share your information with:

  • Verification Partners: Third-party services (like DIDit) for identity verification
  • Payment Processors: Razorpay for processing payments
  • Government Authorities: When required by law or in response to legal requests
  • Business Clients: Your verification results are shared with the platform that requested verification
  • Service Providers: Cloud hosting and IT infrastructure providers under strict data protection agreements

We do NOT sell your personal data to third parties.

6. Data Security

We implement industry-standard security measures to protect your data:

  • 256-bit SSL/TLS encryption for data transmission
  • Encrypted storage of sensitive personal data
  • ISO 27001 certified data centers
  • Regular security audits and vulnerability assessments
  • Access controls and authentication mechanisms
  • Regular data backups and disaster recovery procedures

7. Data Retention

We retain your personal data for the following periods:

  • Verification Records: 7 years (as per PMLA requirements)
  • Account Information: Duration of your account plus 3 years
  • Transaction Records: 7 years (as per Indian tax laws)
  • Technical Logs: 90 days

After the retention period, data is securely deleted or anonymized.

8. Your Rights (DPDP Act)

Under the DPDP Act, 2023, you have the following rights:

  • Right to Access: Request a copy of your personal data
  • Right to Correction: Request correction of inaccurate data
  • Right to Erasure: Request deletion of your data (subject to legal retention requirements)
  • Right to Withdraw Consent: Withdraw your consent at any time
  • Right to Data Portability: Receive your data in a structured format
  • Right to Grievance Redressal: Lodge a complaint with our Data Protection Officer

To exercise these rights, contact us at privacy@blackbearlabs.in

9. Cookies and Tracking Technologies

We use cookies and similar technologies to:

  • Maintain user sessions and authentication
  • Analyze website usage and performance
  • Remember your preferences
  • Improve user experience

You can control cookies through your browser settings. However, disabling cookies may affect service functionality.

10. International Data Transfers

Your data is primarily stored in India. If data is transferred outside India, we ensure adequate safeguards through:

  • Standard Contractual Clauses (SCCs)
  • Adequacy decisions by Indian authorities
  • Explicit consent where required

11. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from minors. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately.

12. Changes to Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes via:

  • Email notification to your registered email address
  • Prominent notice on our website
  • In-app notification

Continued use of our services after changes constitutes acceptance of the updated policy.

13. Contact Us

For questions about this Privacy Policy or our data practices, contact:

Data Protection Officer

BlackBear Labs

Email: privacy@blackbearlabs.in

Support: support@blackbearlabs.in

Website: www.blackbearlabs.in

© 2025 BlackBear Labs. All rights reserved.