Privacy Policy

Version v1.0 · Last updated: 22 August 2026. Issued by SAFELEX Trust, Bengaluru, Karnataka, for the Safe Cheque platform.

SAFELEX Trust ("we", "us", "our") respects your privacy and is committed to protecting the personal data you share through Safe Cheque. This policy explains what data we collect, why we collect it, how long we keep it, who processes it on our behalf, and your rights as a data principal.

Scope and applicable law

This policy governs all personal data collected through Safe Cheque and is issued under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, read with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. SAFELEX Trust is the Data Fiduciary for the personal data described here.

Data we collect

We collect information necessary to identify the parties to a cheque transaction, validate cheque details, and generate agreements and notices. This may include your name, mobile number, email address, Aadhaar last four digits and verification status, PAN, bank account last four digits and IFSC, cheque images, agreement and witness records, and technical logs such as IP address and device information. When you sign an agreement we also store a verbatim snapshot of the exact agreement text you signed together with its SHA-256 fingerprint, and — only if you allow the browser prompt — an approximate signing location rounded to about 1 km, captured once at that moment. We do not collect or store your full Aadhaar number. Text extraction from cheque images (OCR) runs in your browser; the image itself is stored only in our access-controlled storage.

How we use your data

We use your data to operate the platform, verify identities between transaction parties, generate and store agreements and legal documents, maintain an audit trail of document versions, communicate with you about your transactions, prevent fraud and abuse, and comply with legal obligations.

Consent and withdrawal of consent

We process your personal data on the basis of the consent you give when you create an account, submit cheque details, or accept an invite, and for certain legitimate uses permitted under the DPDP Act, 2023 (such as compliance with law and defence of legal claims). You may withdraw your consent at any time by writing to support@safelex.org from your registered email address, or by requesting account deletion from your account settings. Withdrawal is as easy as giving consent, takes effect prospectively, and does not affect processing already carried out. Where withdrawal makes it impossible to continue providing the service, we will close your account and delete or anonymise your data in line with the retention schedule below; records that are part of a signed agreement or an active dispute are retained for the periods stated there.

Data retention schedule

We keep each category of personal data only as long as stated below. When a period ends, the data is deleted or irreversibly anonymised.

CategoryRetention periodWhy
Account and profile data (name, email, mobile, role)While the account is active, plus 90 days after a deletion request is processedAccount operation; short tail for reversal of erroneous deletion and dispute handling
Identity verification data (Aadhaar last four digits, verification status and timestamp, PAN)8 years from the date of the last cheque transaction the identity was used forEvidentiary value of party identity in Section 138 proceedings
OTP and verification logs (mobile/email OTP events, verification attempts)12 months from the eventFraud prevention, abuse investigation and security audit
Cheque particulars and cheque images8 years from the cheque date, unless you request earlier deletion and there is no active or anticipated disputeSection 138 limitation and evidentiary needs under the Bharatiya Sakshya Adhiniyam, 2023
Agreements, witness attestations and e-signature records8 years from the date of signature, unless earlier deletion is requested and no dispute is activeContract evidence and Section 138 / 142 proceedings
Signed agreement text snapshot (verbatim copy of the exact agreement wording at the moment you signed, and its SHA-256 fingerprint)8 years from the date of signature, matching the agreement record it belongs toTamper-evident proof of the exact wording each party agreed to, for Section 138 / 142 proceedings under the Bharatiya Sakshya Adhiniyam, 2023
Signing location (approximate) — coarse coordinates rounded to about 1 km, captured once at the moment of signing, with a timestamp and a status of captured, declined or unavailable8 years from the date of signature, matching the agreement record it belongs toStrengthens the evidentiary record of the signature if the agreement is disputed. This is a one-time reading at the signing action only — not continuous or background location tracking. Signing proceeds normally if you decline the location prompt; only the fact that you declined is recorded
Dishonour events, demand notices, petition drafts and escalations8 years from the date of the recordStatutory limitation and legal record-keeping
Invite records (mobile/email of invited counterparty or witness, token status)24 months from invite creation, or until the linked agreement is deleted, whichever is earlierProof of service of the invite and delivery trail
Document audit log (who generated or downloaded which document version, when)8 years from the log entryIntegrity of the audit trail supporting the documents above
Technical logs (server, error and security logs, IP addresses)90 daysSecurity monitoring, debugging and abuse prevention
Support and grievance correspondence3 years from closure of the ticketGrievance-redressal record under the DPDP Rules, 2025 and IT Rules, 2021

Where a dispute, complaint, notice or court proceeding is active or reasonably anticipated, the relevant records are retained until it is finally concluded, together with any appeal or limitation period, even if a shorter period is stated above.

Sub-processors

We do not sell your personal data. We use the following third parties to run the platform, each under contractual confidentiality and security obligations:

  • Supabase — managed database, authentication and file storage for profiles, cheque records, agreements and cheque images.
  • Lovable — application hosting, server-side rendering and delivery of transactional and authentication emails from our notify.safecheque.in sender domain.
  • Google — optional "Sign in with Google" authentication; used only if you choose that sign-in method, and limited to your Google account email and name.

Invites you choose to send yourself via WhatsApp, SMS or your own email client are sent through your own device and accounts; those providers' own privacy policies apply to that message. This list is kept current — if we add a sub-processor, this section is updated and the version number above changes.

Data sharing and security

Your data is stored in encrypted form, transmitted over HTTPS, and protected by row-level access controls and role-based permissions. Access is limited to you, the counterparty or witness to your transaction (limited to the fields needed for that transaction), authorised SAFELEX Trust administrators, and the sub-processors listed above. We may disclose data where required by law or by a court, regulator or law-enforcement authority.

Your rights

Under the Digital Personal Data Protection Act, 2023, you have the right to access a summary of your personal data and its processing, to correction and completion, to erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to grievance redressal. To exercise any of these rights, contact the Grievance Officer below. We may need to verify your identity before acting on a request.

Grievance Officer / Data Protection Contact

[Name], Grievance Officer / Data Protection Contact

SAFELEX Trust — Safe Cheque

Email: support@safelex.org

Phone: +91 8550-099119

We acknowledge every grievance or data-principal request within 48 hours of receipt and aim to resolve it within 30 days. If you are not satisfied with the outcome, you may escalate the matter to the Data Protection Board of India under the DPDP Act, 2023.

Governing law

This policy is governed by the laws of India, and the jurisdiction clause in our Terms of Use (courts at Bengaluru, Karnataka) applies to any dispute arising from it.