DISHA-GOV-TOS-2026-V1

Terms of Service

Effective Date: July 10, 2026  · Last Updated: August 10, 2026

DISHA 4.0 Human-Capital Operating System (HCOS) · DISHA Intelligence & Security Systems

1. Acceptance of Terms

By accessing, installing, integrating, or utilizing the DISHA 4.0 Human-Capital Operating System (HCOS), the DISHA Hyper-Container (.dhc) specification, developer SDKs, verification APIs, or subscription services (collectively, the “Platform”), you (“User,” “Tenant,” or “Subscriber”) agree to be bound by these Terms of Service (“Terms”).

If you are entering into these Terms on behalf of an enterprise, educational board, state department, or corporate entity, you represent and warrant that you have full legal authority to bind such entity.

⚠️
If you do not agree to these Terms, you must immediately cease all access to and use of the Platform.

2. Core Architectural Philosophy & Zero-Trust Verification

2.1 Provenance & Data Integrity

DISHA 4.0 operates on an Evidence-First, Zero-Trust architectural framework. All incoming inputs (DishaSignal) are subjected to cryptographic verification and policy gating prior to execution.

🔐
Zero-Knowledge Assertions: The Platform utilizes Poseidon Sponge Field Hashing over the BN254 scalar field (𝔽q) and Groth16 zk-SNARK verification circuits to validate statements without disclosing underlying sensitive payloads.

2.2 Local Encryption & User Autonomy

All .dhc hyper-containers are protected via Argon2id key derivation and AES-256-GCM encryption. The Platform does not store unencrypted user payload keys unless explicitly authorized within isolated Hardware Security Module (HSM) tenant enclaves.

3. Account Registration, Seats & Tenant Governance

3.1 Account Integrity

Tenants are responsible for maintaining the confidentiality of their credentials, API tokens, and private cryptographic keys. Any activity originating from an authenticated tenant account is deemed the action of that tenant.

3.2 Seat Allocations & User Provisioning

Subscriptions provide seat allocations as defined in the applicable plan tier (Community, Pro, or Enterprise). Tenant Admins must ensure that seat usage remains within purchased bounds. Sharing account credentials across multiple individuals is strictly prohibited.

3.3 Audit Trails

All user provisioning, role assignments, and security policy modifications are recorded in immutable, tamper-evident audit logs (user_provisioning_audit_logs).

4. Subscription Tiers, Billing & Localized Payments

4.1 Billing Currency & Taxes

All subscription fees, modular add-on packs (e.g., API Bandwidth Packs, ZK-SAD Circuit Expansions, Audit Vaults), and renewal charges are denominated and billed in Indian Rupees (₹ INR). Applicable statutory taxes, including Goods and Services Tax (GST at 18% or applicable rates), are itemized on all Pro-Forma and Tax Invoices.

🏦
RBI E-Mandate Compliance & Auto-Renewal: In compliance with Reserve Bank of India (RBI) digital payment guidelines, auto-renewals trigger an automated pre-debit notification via SMS/Email at least 24 hours prior to debit for recurring charges exceeding statutory limits.

4.2 Pro-Forma Invoice & Billing Cycle

Subscriptions commence immediately upon payment confirmation or issuance of an authorized Pro-Forma Tax Invoice. Plans are billed on a recurring monthly or annual basis.

4.3 Payment Pathways

Payments may be processed via UPI AutoPay, RuPay/Credit/Debit cards, NetBanking, or corporate e-NACH/NEFT mandates.

4.4 Refunds & Cancellations

You may toggle auto-renewal off at any time via the User Billing Portal. Subscription fees are non-refundable for active billing periods unless required by applicable law or explicit SLA default.

5. Acceptable Use Policy (AUP)

You expressly agree NOT to engage in any of the following restricted activities:

  • 🚫Attempting to reverse-engineer, decompile, or extract the underlying cryptographic circuits or private keys from .dhc container verification routines beyond open SDK allowances.
  • 🚫Generating malicious or forged zero-knowledge proof points (A, B, C) to bypass authorization logic.
  • 🚫Utilizing the Platform to transmit, store, or process illegal content, malicious payloads, or unauthorized personal sensitive data in violation of applicable data protection laws.
  • 🚫Exceeding allocated API quota limits through distributed denial-of-service (DDoS) attacks or automated scraping scripts designed to bypass rate-limiting controls.

6. Intellectual Property & Patent Claims

6.1 Platform Ownership

DISHA Intelligence & Security Systems and its licensors retain all rights, title, and intellectual property in the DISHA 4.0 HCOS, .dhc hyper-container standards, Poseidon field implementation frameworks, and associated patent claims (including Volume I–IV specifications).

6.2 User Data Ownership

Users retain complete, exclusive ownership of all raw data payloads encrypted within their .dhc containers. DISHA claims no ownership over user credentials or zero-knowledge witness claims generated on local enclaves.

7. Service Level Agreements (SLA) & Dunning Lifecycle

7.1 Uptime Commitment

Commercial Pro and Enterprise tiers are backed by a 99.9% API verification availability target.

7.2 Payment Failure & Dunning

In the event of a payment gateway failure or rejected recurring debit, the following automated dunning lifecycle is initiated:

7-Day Dunning Grace Period Timeline

!
Day 0Payment Failure

Gateway rejection or e-mandate failure detected. Notification dispatched.

R1
Day 1Retry #1 + Grace Period Begins

First automated retry. Account enters 7-Day Grace Period. APIs remain functional.

R2
Day 3Retry #2 + Multi-Channel Alert

Second retry. Email, SMS, and WhatsApp notifications dispatched.

R3
Day 5Retry #3 + Final Warning

Third and final retry. Critical warning issued across all channels.

🔒
Day 7Soft-Lock Transition

Account transitions to SOFT_LOCKED state. Read-only administrative access only.

🔔
Automated retries are executed on Day 1, Day 3, and Day 5 alongside multi-channel notifications (Email, SMS, WhatsApp). Uncollected accounts after Day 7 transition to a Soft-Locked state with read-only administrative access.

8. Limitation of Liability & Warranties

TO THE MAXIMUM EXTENT PERMITTED BY LAW, DISHA 4.0 HCOS IS PROVIDED “AS IS” AND “AS AVAILABLE” WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED. DISHA INTELLIGENCE & SECURITY SYSTEMS SHALL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR LOSS OF DATA, REVENUE, OR CRYPTOGRAPHIC KEYS RESULTING FROM USER NEGLIGENCE OR UNMATCHED ENVIRONMENT CONDITIONS.

9. Governing Law & Dispute Resolution

These Terms are governed by and construed in accordance with the laws of India. Any disputes, claims, or proceedings arising out of or in connection with these Terms shall be subject to the exclusive jurisdiction of the courts located in:

⚖️
Exclusive Jurisdiction: Guwahati, Assam, India — All legal proceedings, arbitration, and dispute resolution shall be conducted under the exclusive jurisdiction of courts in Guwahati, Assam, India.

10. Contact & Governance Enquiries

For questions regarding these Terms of Service or regulatory compliance, please contact:

🏛️

DISHA Intelligence & Security Systems

Legal & Compliance Officer

📍

Address

Guwahati, Assam, 781001, India

✉️
🔒

Compliance Email

compliance@disha.ai
📋

Document ID

DISHA-GOV-TOS-2026-V1
✉️ Send Legal Enquiry

Document: DISHA-GOV-TOS-2026-V1 · Last Updated: August 10, 2026 · © DISHA Intelligence & Security Systems