India’s Digital Personal Data Protection Act, 2023 is supplemented by the Digital Personal Data Protection Rules, 2025. Safe4Sign’s website practices are designed with this framework in mind; specific obligations apply according to the law and its notified commencement timeline.
Our data-handling principles
Ask for information relevant to the enquiry or service.
Use access controls and operational safeguards appropriate to the data handled.
Explain why form information is requested and how to contact us.
Keep information only as long as reasonably required for the relevant purpose and obligations.
Consent and notice on website forms
Public enquiry forms include a privacy acknowledgement or consent statement before submission. Users should provide accurate information and should submit another person’s data only when authorised to do so.
Data Principal requests
Where applicable under law, individuals may have rights relating to access to information about processing, correction or updating, erasure, grievance redressal and nomination. Requests can be initiated through our published contact email; identity or request details may be verified before action is taken.
Security incidents
If a personal-data incident occurs, Safe4Sign will assess the event and take steps required under applicable law, contractual obligations and the nature of the incident, including containment, remediation and notifications where legally required.
Processors and third-party services
Some services may involve hosting providers, email services, software vendors, payment or communication providers, or licensed Certifying Authorities. Information shared with them should be limited to what is reasonably required for the relevant purpose and governed by the applicable arrangement.
Official references
For authoritative text and commencement information, refer to the Ministry of Electronics and Information Technology (MeitY) publications for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
This page is a general website policy summary and not a legal opinion or certification of regulatory compliance. Business-specific DPDP obligations should be reviewed against the actual processing activity and current law.
