Privacy Policy
Effective Date: August 10, 2026 · Last Updated: August 10, 2026
DISHA 4.0 Human-Centric Operating System (HCOS) · DISHA Intelligence & Security Systems
1. Introduction & Zero-Trust Privacy Commitment
DISHA Intelligence & Security Systems (“DISHA,” “we,” “our,” or “us”) is dedicated to protecting the privacy, cryptographic sovereignty, and data autonomy of all users, tenants, and developers using the DISHA 4.0 Human-Centric Operating System (HCOS), the .dhc hyper-container specification, verification APIs, and enterprise cloud portals (collectively, the “Platform”).
2. Information We Collect
2.1 Account & Identity Information
When you register for a DISHA 4.0 HCOS account, we collect your name, email address, phone number (optional), and institutional affiliation. For enterprise tenants, we collect organizational details including GST/tax identification numbers for billing compliance.
2.2 Cryptographic Proof Metadata
DISHA processes zero-knowledge proof attestations. We store only the cryptographic proof hash, verification status, and timestamp — never the underlying credential payload or personal data used to generate the proof.
2.3 Usage & Telemetry Data
We collect anonymized platform usage metrics including API call counts, feature engagement rates, and performance telemetry. All telemetry is aggregated and cannot be linked back to individual users.
.dhc hyper-container. Only cryptographic proof hashes traverse our verification infrastructure.3. How We Use Your Information
We use collected information for the following purposes:
- Service Delivery: Provisioning and operating your HCOS account, enclave nodes, and API access.
- Billing & Compliance: Processing subscription payments, generating GST-compliant invoices, and maintaining financial records per Indian accounting regulations.
- Security & Fraud Prevention: Detecting and preventing unauthorized access, API abuse, and cryptographic proof tampering.
- Platform Improvement: Analyzing anonymized usage patterns to improve system performance, reliability, and feature development.
- Legal Compliance: Meeting obligations under the DPDP Act, IT Act 2000, and applicable Indian and international regulations.
4. How We Share & Disclose Information
DISHA does not sell, rent, or trade personal information. We may share information only in the following limited circumstances:
- Service Providers: Trusted infrastructure providers (cloud hosting, payment processors) operating under strict data processing agreements.
- Legal Requirements: When required by Indian law, court order, or regulatory authority with proper legal process.
- Institutional Partners: With your explicit consent, sharing verification proof attestations with your designated institutional partner.
5. Data Security & Storage Enclaves
DISHA 4.0 employs multiple layers of cryptographic security to protect your data:
AES-256-GCM Encryption
All data at rest is encrypted using AES-256-GCM with tenant-specific encryption keys.
HSM Enclave Isolation
Sensitive computations occur in hardware-backed security modules with TEE attestation.
Argon2id Key Derivation
Master encryption keys derived using Argon2id KDF with memory-hard parameters.
Immutable Audit Logs
All security events recorded in append-only Poseidon BN254 hash-chained audit ledgers.
6. Your Rights & Data Controls
Under the DPDP Act and applicable privacy regulations, you have the following rights:
- Right to Access: Request a complete export of all personal data we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete personal information.
- Right to Erasure: Request deletion of your personal data, subject to legal retention requirements.
- Right to Data Portability: Export your data in machine-readable formats.
- Right to Withdraw Consent: Withdraw consent for optional data processing at any time.
7. International Data Transfers
DISHA 4.0 primarily processes data within India. Where international data transfers are necessary for service delivery (e.g., global CDN infrastructure), we ensure adequate protection through Standard Contractual Clauses and data processing agreements compliant with the DPDP Act.
8. Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes via email and in-platform notifications at least 30 days before the changes take effect.
Continued use of the Platform after the effective date of any updated Privacy Policy constitutes your acceptance of the revised terms.
9. Privacy Contact & Data Protection Officer
For privacy inquiries, data rights requests, or to contact our Data Protection Officer:
Data Protection Officer
DISHA Intelligence & Security Systems
Document Identifier: DISHA-GOV-PRIV-2026-V1 · Effective August 10, 2026


