HomeLegalPrivacy Policy
PRIVACY POLICY

How we handle the data behind verification.

CHEMALOT exists to verify entities, which means we handle sensitive identity and business data. This policy explains what we collect, why, and how we protect it.

Who this policy is for

This policy applies to the businesses that use CHEMALOT and to the customers, vendors and suppliers whose details are submitted for verification through the platform. It covers the data our customers upload, the data we receive from verification sources, and the data we generate as a result of a check.

What we collect

  • Business identity data such as legal name, registered address, PAN, GSTIN, CIN and MSME registration.
  • Documents submitted for verification, such as registration and incorporation certificates and licences.
  • Bank account details provided for account verification.
  • Verification results, flags and the audit record of each check and decision.
  • Account and contact details for the users who operate the platform on behalf of a customer.

Why we collect it

We use this data for one purpose: to verify entities and keep those verifications current for the customer who requested them. Concretely, that means confirming identifiers against their source, monitoring for changes after approval, surfacing fraud and compliance signals, and producing the audit trail that lets a customer show how a decision was made.

We do not sell personal or business data, and we do not use verification data to build products unrelated to the verification a customer asked for.

How long we keep it

Verification data is retained for as long as the related entity is active on a customer's book, plus the additional window needed to support audit and dispute resolution. When that window closes, data is removed on a defined schedule. Retention periods and the scope of access are described in more detail on our Security page.

How we protect it

  • Data is encrypted in transit between the browser, the platform and verification sources.
  • Documents and entity records are encrypted at rest in storage.
  • Access is scoped by role, so procurement, finance and compliance each see only what their work requires.
  • Every check, override and decision is recorded in a time-stamped audit trail.

Who can access it

Within a customer's organisation, access is controlled by role. Within CHEMALOT, access is limited to the people and services that need it to operate and support the verification service. We share data with verification sources only to the extent needed to perform a requested check.

Your rights and choices

Businesses and individuals whose data is processed through CHEMALOT may request access to that data, correction of inaccuracies, or deletion where there is no lawful or contractual reason to retain it. Requests are handled through the customer that submitted the data, since they control the verification relationship.

Changes to this policy

If we change how we handle data in a way that affects this policy, we will reflect it here. Continued use of the platform after a change means the updated policy applies.

Contacting us about privacy

For any question about how your data is handled, reach us through the contact page. We would rather answer a question early than leave it unanswered.