Statutory Legal Document

Data Protection
& Privacy Protocol.

EFFECTIVE: MARCH 2026
|
JURISDICTION: REPUBLIC OF INDIA (DPDP ACT)
Master Policy

The Zero-Knowledge
Mandate.

This protocol governs the intake, auditing, and mandatory cryptographic destruction of all candidate records.

Article 1.0

Data Fiduciary Classification

TrustWiz Technologies operates as a Data Fiduciary under the Digital Personal Data Protection (DPDP) Act, 2023. We collect and process Personal Identifiable Information (PII) solely for the objective execution of timeline verification and the minting of a cryptographic Trust-ID.

We categorically reject the monetization of user data. Candidate records are never aggregated, sold to third-party data brokers, or utilized to train external AI models.

Article 2.0

Evidentiary Intake & Scope

To execute an OSINT (Open Source Intelligence) audit, TrustWiz temporarily ingests the following data classifications:

  • Identity Payloads: Legal Name, Contact Information, and securely hashed passwords.
  • Corporate/Financial Records: Severance agreements, ROC strike-off notices, or furlough documentation.
  • Medical Records (Zero-Knowledge): Health discharge summaries submitted strictly for DPDP-compliant timeline validation.
Article 3.0

The 30-Day Cryptographic Purge

This is the immutable core of the TrustWiz security apparatus. We adhere to the DPDP Act's principle of Data Minimization.

Exactly 720 hours (30 days) after a Trust-ID is successfully minted, automated server-level cron jobs irreversibly destroy all physical PDF/image evidence, medical records, and corporate severance files associated with your profile. The active database retains only the sanitized mathematical hash (Trust-ID) and the cleared timeline metadata required for ATS verification.

Article 4.0

Enterprise B2B Transmissions

When an integrated Applicant Tracking System (e.g., Darwinbox, Workday) queries the TrustWiz REST API using your Trust-ID, we transmit a strictly limited JSON payload. We return only the binary clearance state (AUTHENTICATED / REJECTED) and the non-PII classification metadata. Underlying evidentiary documents are never transmitted to corporate partners.

Article 5.0

Statutory Rights & Redressal

Under the DPDP Act, Data Principals possess the immediate right to erasure, correction, and grievance redressal. You may submit a cryptographic takedown request at any time to instantly revoke your Trust-ID and erase all associated ledger metadata.

DPDP Grievance Officer
Sneha Monica
legal@trustwiz.co.in
Physical Registry HQ
No. 47, RKM Layout Margondanahalli,
R M Nagar, Bengaluru 560016