DISHA-GOV-PRIV-2026-V1

Privacy Policy

Effective Date: August 10, 2026  · Last Updated: August 10, 2026

DISHA 4.0 Human-Centric Operating System (HCOS) · DISHA Intelligence & Security Systems

1. Introduction & Zero-Trust Privacy Commitment

DISHA Intelligence & Security Systems (“DISHA,” “we,” “our,” or “us”) is dedicated to protecting the privacy, cryptographic sovereignty, and data autonomy of all users, tenants, and developers using the DISHA 4.0 Human-Centric Operating System (HCOS), the .dhc hyper-container specification, verification APIs, and enterprise cloud portals (collectively, the “Platform”).

🔒
Evidence-First, Zero-Trust Privacy Framework: Unlike traditional SaaS architectures that ingest, inspect, and monetize user payloads, DISHA 4.0 operates under an Evidence-First, Zero-Trust Privacy Framework. Our underlying cryptography ensures that sensitive user payloads remain encrypted locally, allowing verification of facts and statements via zero-knowledge proofs without exposing raw data.

2. Information We Collect

2.1 Account & Identity Information

When you register for a DISHA 4.0 HCOS account, we collect your name, email address, phone number (optional), and institutional affiliation. For enterprise tenants, we collect organizational details including GST/tax identification numbers for billing compliance.

2.2 Cryptographic Proof Metadata

DISHA processes zero-knowledge proof attestations. We store only the cryptographic proof hash, verification status, and timestamp — never the underlying credential payload or personal data used to generate the proof.

2.3 Usage & Telemetry Data

We collect anonymized platform usage metrics including API call counts, feature engagement rates, and performance telemetry. All telemetry is aggregated and cannot be linked back to individual users.

📊
Zero Raw Data Ingestion: DISHA 4.0 never ingests, stores, or processes raw credential documents, identity documents, or personal data payloads. All sensitive data remains encrypted within the user's local .dhc hyper-container. Only cryptographic proof hashes traverse our verification infrastructure.

3. How We Use Your Information

We use collected information for the following purposes:

  • Service Delivery: Provisioning and operating your HCOS account, enclave nodes, and API access.
  • Billing & Compliance: Processing subscription payments, generating GST-compliant invoices, and maintaining financial records per Indian accounting regulations.
  • Security & Fraud Prevention: Detecting and preventing unauthorized access, API abuse, and cryptographic proof tampering.
  • Platform Improvement: Analyzing anonymized usage patterns to improve system performance, reliability, and feature development.
  • Legal Compliance: Meeting obligations under the DPDP Act, IT Act 2000, and applicable Indian and international regulations.

4. How We Share & Disclose Information

DISHA does not sell, rent, or trade personal information. We may share information only in the following limited circumstances:

  • Service Providers: Trusted infrastructure providers (cloud hosting, payment processors) operating under strict data processing agreements.
  • Legal Requirements: When required by Indian law, court order, or regulatory authority with proper legal process.
  • Institutional Partners: With your explicit consent, sharing verification proof attestations with your designated institutional partner.
🚫
No Data Monetization: DISHA does not and will never sell, license, or monetize user personal data to third parties, advertisers, or data brokers. Our business model is entirely subscription and service-fee based.

5. Data Security & Storage Enclaves

DISHA 4.0 employs multiple layers of cryptographic security to protect your data:

🔐

AES-256-GCM Encryption

All data at rest is encrypted using AES-256-GCM with tenant-specific encryption keys.

🛡️

HSM Enclave Isolation

Sensitive computations occur in hardware-backed security modules with TEE attestation.

🔑

Argon2id Key Derivation

Master encryption keys derived using Argon2id KDF with memory-hard parameters.

📋

Immutable Audit Logs

All security events recorded in append-only Poseidon BN254 hash-chained audit ledgers.

6. Your Rights & Data Controls

Under the DPDP Act and applicable privacy regulations, you have the following rights:

  • Right to Access: Request a complete export of all personal data we hold about you.
  • Right to Correction: Request correction of inaccurate or incomplete personal information.
  • Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
  • Right to Data Portability: Export your data in machine-readable formats.
  • Right to Withdraw Consent: Withdraw consent for optional data processing at any time.
⚙️
Exercise Your Rights: Submit data rights requests via your Account Settings dashboard or by emailing privacy@disha.ai. We respond to all verified requests within 30 days as required by the DPDP Act.

7. International Data Transfers

DISHA 4.0 primarily processes data within India. Where international data transfers are necessary for service delivery (e.g., global CDN infrastructure), we ensure adequate protection through Standard Contractual Clauses and data processing agreements compliant with the DPDP Act.

🌍
Data Residency: Institutional Enterprise customers may elect India-only data residency, ensuring all personal data processing occurs exclusively within Indian data centers. Contact our institutional partnerships team for data residency configuration.

8. Updates to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes via email and in-platform notifications at least 30 days before the changes take effect.

Continued use of the Platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms.

9. Privacy Contact & Data Protection Officer

For privacy inquiries, data rights requests, or to contact our Data Protection Officer:

🔒

Data Protection Officer

DISHA Intelligence & Security Systems

📍Guwahati, Assam, 781001, India

Document Identifier: DISHA-GOV-PRIV-2026-V1 · Effective August 10, 2026

Terms of Service·Institutional Agreements