Statutory Legal Framework

Privacy Policy

How VSign (Verasys Limited) protects your identity, KYC documents, and cryptographic credentials under the Information Technology Act 2000 and CCA guidelines.

1Introduction & Scope

Verasys Limited ("Verasys", "VSign", "we", "us", or "our") is a licensed Certifying Authority (CA) operating under the Controller of Certifying Authorities (CCA), Ministry of Electronics and Information Technology, Government of India. This Privacy Policy governs the collection, processing, storage, and protection of personal data and KYC documents submitted by applicants for Digital Signature Certificates (DSC), eSign, and PKI services.

2Information We Collect

To verify subscriber identities and issue legally valid digital certificates in accordance with the IT Act 2000, we collect:

  • Identity & Demographic Data: Full name, date of birth, gender, nationality, postal address, email address, and mobile number.
  • Statutory Verification Credentials: Permanent Account Number (PAN), Aadhaar Offline XML / eKYC, Organization Registration (GST, Incorporation Certificate), and authorized signatory proof.
  • Biometric / Video Verification: Short video recording and facial verification as mandated by CCA Identity Verification Guidelines (IVG).
  • Technical Audit Logs: IP address, timestamp, browser headers, and transaction metadata required to maintain non-repudiation audit trails.

3Purpose of Data Processing

Your personal information is strictly utilized for:

  • Verifying identity and issuing Digital Signature Certificates (Class 3, DGFT, Document Signer).
  • Maintaining public Certificate Revocation Lists (CRL) and Online Certificate Status Protocol (OCSP) verification repositories.
  • Complying with statutory audits, regulatory requirements, and directives of the CCA and law enforcement agencies.
  • Preventing identity theft, fraudulent applications, and unauthorized certificate generation.

4Data Protection & Security Measures

All applicant records and cryptographic operations are secured inside high-security data centers compliant with ISO 27001 standards. Private keys are generated and protected using FIPS 140-2 Level 3 Hardware Security Modules (HSMs). We do not sell, rent, or trade your personal information to any third parties for advertising or commercial marketing.

5Retention & Statutory Archival

Under CCA mandates and the IT Act 2000, Certifying Authorities are legally obligated to retain subscriber application records, verification evidence, and audit logs for a minimum statutory period (at least 7 years post certificate expiration) to support legal dispute resolution and non-repudiation verification.

Privacy & Grievance Redressal

If you have any questions or concerns regarding our privacy practices, you may reach out to our designated Grievance Officer:

Grievance Officer: Poonam More

Email: poonam.more@verasys.in / admin@vsign.in

Helpdesk: 022-43156000 / 9930-55-8585

Address: 2nd Floor, Bhavna Building, V.S. Marg, Prabhadevi, Mumbai - 400025