Quick summary
What we do: We offer document verification and identity/record-check services that call only publicly available Government APIs or approved integration channels. All verification actions are performed only after explicit, informed consent from the user.
Scope of services (concise)
- Use of public/open Government APIs and published datasets for verification and information that is lawfully available.
- Integration with government authentication flows only through authorised channels where required.
- We do not perform or offer any alteration, correction, or modification of government records.
Consent, sensitive data & Aadhaar
We obtain explicit consent before collecting or submitting any personally identifying information for verification. Where Aadhaar or other sensitive identifiers are involved, we follow the statutory restrictions and authentication regulations that govern use of Aadhaar and any sensitive attribute (we do not store core biometrics or sensitive data beyond permitted, transient logs).
Security & privacy
We maintain technical and organisational measures including:
- Encryption in transit (TLS) and at-rest for stored minimal data.
- Role-based access controls and audit logging for verification requests.
- Data minimisation — we store only what is necessary for the verification and for lawful audit purposes.
Data retention & third parties
We retain verification logs and minimal metadata for compliance and dispute-resolution for a limited period (specified in our privacy policy). Third-party subprocessors (cloud, API gateways) are bound by contractual obligations and are required to maintain equivalent security and compliance standards.
Grievance & DPO
For any privacy, legal, or compliance concern:
- Designated Nodal / DPO: dpo@bestlink.cloud
- Postal: Legal & Compliance Team, Bestlink.cloud
- We will respond to legitimate grievance requests per applicable law and will cooperate with regulators or courts when required.
Liability, compliance & governing law
We do not warrant that results from public APIs are error-free; government datasets are the authoritative source. We disclaim liability to the fullest extent permitted by law for any direct/indirect damages arising from use of our verification output. We reserve the right to pursue civil or criminal remedies in cases of misuse, tampering, or unauthorised access. The services and this notice are governed by the laws of India and disputes are subject to courts having jurisdiction in India.
Why this practice is lawful (summary)
In summary, using publicly published Government APIs and datasets for verification — with explicit user consent and while complying with statutory limits on sensitive data such as Aadhaar — is a lawful operational model (subject to the detailed rules and restrictions in the statutes and policies cited below).
- Open Government Data / APIs portal — official Government APIs and datasets.
- Open API Policy for e-Governance — guidance on publishing and using e-governance APIs.
- Aadhaar Act and related authentication/sharing regulations — statutory restrictions & consent rules for Aadhaar use.
- Digital Personal Data Protection Act, 2023 — statutory framework for processing digital personal data and consent rules.
- Information Technology Act, 2000 — offences for tampering, unauthorised access and cyber-related liabilities.