How to Read This Policy
This Privacy Policy is written in plain language. Section 3 explains how we protect your data technically. Section 8 explains the important limitation — what EternaSafe is NOT legally. Section 9 explains your rights. If you have one question, it is probably answered in the FAQ at www.eternasafe.in.
1. About This Policy
This Privacy Policy describes how Eternasafe Technologies Private Limited ("EternaSafe", "we", "us", or "our") collects, uses, stores, and protects information when you use our platform at www.eternasafe.in and our mobile application (together, the "Platform").
This Policy is published in compliance with the Digital Personal Data Protection Act, 2023 ("DPDPA") and the Digital Personal Data Protection Rules, 2025. By registering on or using the Platform, you confirm that you have read, understood, and agreed to this Privacy Policy.
| Effective Date | June 1, 2026 |
| Version | 2.0 (Revised June 15, 2026) |
| Company | Eternasafe Technologies Private Limited |
| DPIIT Recognition | Certificate No. DIPP251036 |
| General Contact | info@eternasafe.in |
| Support & Grievances | support@eternasafe.in |
| Website | www.eternasafe.in |
2. Who We Are — Data Fiduciary
Under the DPDPA 2023, Eternasafe Technologies Private Limited is the "Data Fiduciary" — the entity that determines the purpose and means of processing your personal data. We take this responsibility seriously and have designed our platform to collect the minimum data necessary to deliver our service.
| Registered Name | Eternasafe Technologies Private Limited |
| Address | 203, Shri Ram Vatika, Dhaiya, Dhanbad, Jharkhand — 826004 |
| Udyam Registration | UDYAM-JH-04-0083428 |
| DPIIT Recognition | DIPP251036 |
| Grievance Officer | Amardeep Kumar, Co-Founder & CEO |
| Grievance Email | support@eternasafe.in |
| Response Time | Acknowledge within 48 hours · Resolve within 30 days |
3. Our Security Architecture — The Most Important Section
3.1 What Our Architecture Means for You
Important — Please Read This First
EternaSafe is built on a zero-knowledge design. Based on the current architecture, EternaSafe does not have access to users' vault encryption keys and cannot ordinarily access vault contents. Your data is encrypted on your device using your private Unlock Password before being transmitted to our servers. We store only encrypted, unreadable data. This is not a marketing claim — it is how the system is designed.
Specifically, your Unlock Password is:
- Never transmitted to our servers
- Never stored anywhere in our systems
- Known only to you
As a result, EternaSafe employees and administrators cannot read your vault contents. No third party with access to our servers can read your vault contents without your password. If you lose your Unlock Password and your Recovery Key, your vault contents cannot be recovered by anyone.
Note on Future Changes
This architecture reflects our current system design. If future operational changes — including introduction of recovery mechanisms or architectural updates — affect these characteristics, we will notify users with at least 30 days' advance notice and update this Policy accordingly.
3.2 Encryption Standard
All vault contents are encrypted using AES-256 — the same standard used by leading global banks and defence organisations. All data in transit between your device and our servers is protected using industry-standard TLS encryption.
4. What Data We Collect and Why
We collect only the minimum data required to operate the Platform safely. We collect NO data that forms part of your vault contents — those remain inaccessible to us under our current architecture.
4.1 Registration Data
- Your mobile number — for account identification, OTP-based login, and inactivity trigger alerts
- Your name (optional) — for personalising your experience
- Email address (optional) — for account recovery alerts and trigger notifications
Legal Basis (DPDPA): Consent — freely given at time of registration.
4.2 Authentication Data
- OTP records — generated and immediately expired after login verification
- Two-Factor Authentication (2FA) logs — timestamps of verification events
- Login activity logs — date, time, and device type of successful logins
Legal Basis (DPDPA): Legitimate use — necessary for platform security.
4.3 Nominee Data
When you assign nominees, we collect nominee name, mobile number, and relationship to you. This is stored in encrypted form and used solely for nominee notification and verification. Nominees receive only a confirmation SMS at designation — no vault access is given at this stage.
Legal Basis (DPDPA): Consent — given at the time you add a nominee.
4.4 Activity and Audit Data
We maintain a full audit trail on every account and every plan, including login events, vault update events (timestamp only — not content), nominee changes, and inactivity trigger events. This is maintained for your legal protection and ours and is never sold or used for marketing. Retained for a minimum of 7 years as required by law.
Legal Basis (DPDPA): Legitimate use — legal accountability and platform security.
4.5 Payment Data
Payment processing is handled by Razorpay. EternaSafe does not store your card numbers, bank account numbers, or payment credentials. We receive only a transaction confirmation and subscription status.
Legal Basis (DPDPA): Contract — necessary to fulfil your subscription.
4.6 Communication Consent
By registering for and using EternaSafe, you consent to receive service-related communications through email, SMS, WhatsApp, push notifications, and other operational communication channels. This includes inactivity alerts, nominee notifications, security notices, and subscription reminders. You may withdraw consent for non-critical communications through your account settings.
4.7 Data We Do NOT Collect
- Your location data
- Your device contacts
- Your browsing history
- Any biometric data (Version 1)
- The contents of your vault — zero-knowledge encrypted and inaccessible to us
- Any data from third-party platforms or social accounts
5. How We Use Your Data
| Purpose | Data Used | Legal Basis |
|---|---|---|
| Account creation & login | Mobile number, name | Consent |
| OTP / 2FA verification | Mobile number | Legitimate use |
| Operating the inactivity trigger | Login timestamps, mobile, email | Contract |
| Sending multi-channel alerts | Mobile, email, WhatsApp | Contract + Consent |
| Nominee identity verification | Nominee name, mobile, ID proof | Consent |
| Granting nominee access | Verified nominee identity | Legitimate use |
| Processing subscription payments | Sent to Razorpay only | Contract |
| Maintaining audit trail | Event timestamps, device type | Legitimate use |
| Responding to grievances | Contact details you provide | Legal obligation |
| Data breach notification | Mobile, email | Legal obligation (DPDPA) |
6. Data Storage, Security, and Service Availability
6.1 Where Your Data is Stored
- All data is stored on servers located within India (AWS Mumbai Region — ap-south-1)
- EternaSafe currently stores all data within India. In the event that operational requirements necessitate any change to data storage locations, users will be notified with a minimum of 30 days' advance notice and in full compliance with DPDPA requirements
6.2 Third-Party Data Processors
We work with the following third-party processors who handle limited data on our behalf under contractual data protection obligations:
| Cloud Infrastructure | AWS (Amazon Web Services) — Mumbai Region (ap-south-1) |
| Payment Processing | Razorpay — payment gateway for subscription billing |
| SMS Service | Firebase / Twilio — for OTP and alert delivery |
| Email Service | Zoho Mail — for email alerts and communications |
| WhatsApp Alerts | WhatsApp Business API — for inactivity trigger alerts (Paid plans) |
| Analytics | Self-hosted analytics — aggregated, non-personal page view data only |
6.3 Security Measures
- AES-256 zero-knowledge encryption for all vault contents
- Industry-standard TLS encryption for all data in transit
- Encrypted storage of all operational data at rest
- OTP + Two-Factor Authentication (2FA) on all accounts
- Strict access controls — vault data inaccessible to our own administrators under current architecture
- Full audit trail of all access events on every plan
- Regular security reviews and vulnerability assessments
6.4 Backup and Recovery
EternaSafe maintains server-level backups for operational continuity. These backups contain only encrypted data — the same zero-knowledge encrypted blobs stored in production. Backups are stored within India and are subject to the same access controls as primary data. EternaSafe cannot use these backups to recover vault contents if the Unlock Password and Recovery Key are lost — the encryption keys are not stored by us.
6.5 Service Availability
EternaSafe does not guarantee uninterrupted, error-free, or continuous service availability. The Platform may be temporarily unavailable due to scheduled maintenance, technical failures, or circumstances beyond our reasonable control. We will communicate planned maintenance windows in advance wherever possible. Service disruptions do not affect the security or integrity of your encrypted vault contents.
6.6 Data Retention
| Registration & account data | Duration of account + 3 years after deletion |
| Audit trail logs | Minimum 7 years (legal compliance) |
| Payment records | 7 years (Indian tax law) |
| Nominee data | Until you remove the nominee or close your account |
| Waitlist data | 30 days after account creation or opt-out |
| Trigger event records | 7 years from trigger event (legal protection) |
7. When We Share Your Data
We do not sell, rent, or trade your personal data. Ever. We share only in these limited circumstances:
7.1 Third-Party Processors
As listed in Section 6.2, we share minimal operational data with processors who support our service delivery. All processors are contractually bound to data protection standards.
7.2 Legal Requirements
We may disclose non-encrypted operational data (such as account existence, login timestamps, or contact details) if required by a valid court order or statutory directive from an Indian government authority. Based on the current architecture, we are technically unable to disclose vault contents — we do not hold the encryption keys. Any legally compelled disclosure will be of operational data only.
7.3 Nominee Access
When the inactivity trigger activates and a nominee completes verified identity verification with admin oversight, they are granted read-only access to your vault. This is the core intended function of the Platform, designed in accordance with the nomination provisions contemplated under Section 14 of the DPDPA, subject to applicable legal requirements.
Nominees can view and individually download documents. They cannot edit, delete, bulk-download, or transfer access to another person. Access is time-limited and may be revoked if fraud or misuse is suspected.
8. Estate Planning Disclaimer
Critical Limitation — Please Read
EternaSafe is a digital information storage and guidance platform. It is NOT a Will, Trust, Legal Succession Instrument, Probate Replacement, or Determinant of Ownership Rights. Information stored in your account does not constitute a legally valid Will or testament under Indian law. Nominee access to account contents does not override or replace the legal succession process governed by Indian succession law (Indian Succession Act 1925, Hindu Succession Act 1956, or applicable personal law). You are strongly advised to also create a legally valid Will and consult a qualified lawyer for estate planning.
9. Your Rights as a Data Principal (DPDPA 2023)
9.1 Right to Access
You have the right to know what operational data we hold about you. To request a data summary, email support@eternasafe.in. We will respond within 30 days.
9.2 Right to Correction
You may update your registration data (name, email, mobile) at any time through your account settings.
9.3 Right to Erasure
You may request deletion of your account and all associated personal data. Upon verified request, we will delete your operational data within 30 days. Your encrypted vault data will also be purged. Audit trail logs are retained as required by law.
9.4 Right to Withdraw Consent
You may withdraw consent for non-essential processing at any time. Withdrawal of consent for essential processing will result in inability to use the Platform. Email info@eternasafe.in or use the account deletion option.
9.5 Right to Data Portability
Where technically feasible, you may request a copy of your personal operational data in a structured, machine-readable format. Please note that vault contents are stored in encrypted form — any exported vault data will be in its encrypted state and requires your Unlock Password to be decipherable. EternaSafe cannot provide decrypted vault exports as we do not hold the encryption keys under the current architecture.
9.6 Right to Grievance Redressal
Contact our Grievance Officer at support@eternasafe.in within 30 days of any concern. We acknowledge within 48 hours and resolve within 30 days. Unresolved matters may be escalated to the Data Protection Board of India once fully constituted.
9.7 Right to Nominate
Under Section 14 of the DPDPA 2023, you have the right to nominate a person who shall exercise your data rights in the event of your death or incapacity. EternaSafe's nominee functionality is designed in accordance with this nomination provision, subject to applicable legal requirements.
10. Recovery Key — User Responsibility
Critical
EternaSafe does not retain copies of Recovery Keys and cannot regenerate, recover, or retrieve lost Recovery Keys. If you lose both your Unlock Password and Recovery Key, your vault contents are permanently and irrecoverably lost. This is a consequence of our zero-knowledge architecture and applies without exception. Write your Recovery Key on paper and store it in a physically secure location separate from your Unlock Password.
11. Data Breach Response
EternaSafe maintains a data breach response process aligned with DPDPA 2023 obligations. In the event of a breach involving personal operational data:
11.1 Detection & Containment
We monitor our systems continuously for unauthorised access. Upon detection, we immediately isolate affected systems and revoke compromised credentials.
11.2 Regulatory Notification
We will notify the Data Protection Board of India within 72 hours of becoming aware of a breach, as required under DPDPA 2023.
11.3 User Notification
Affected users will be notified via SMS and/or email as soon as practicable following regulatory notification. Notification will include: nature of the breach, data categories affected, steps taken, and recommended user actions.
11.3 Remediation
Following a breach, we will implement technical and organisational measures to remediate the vulnerability and prevent recurrence. A post-incident report will be provided to affected users upon request, covering root cause, scope, and steps taken.
11.4 User Guidance Following a Breach
In the event of a breach affecting operational data, we recommend that affected users: review their account for any unusual activity; update their registered contact details if compromised; monitor their registered mobile number and email for any suspicious activity. Note that your vault contents — being zero-knowledge encrypted — are not accessible to any attacker even in the event of a server breach.
11.5 Note on Vault Contents
Because vault contents are zero-knowledge encrypted, a breach of our servers would expose only encrypted, unreadable data. Vault contents are not considered compromised in the event of a server breach under the current architecture.
12. Security Vulnerability Reporting
EternaSafe welcomes responsible disclosure of security vulnerabilities. To report a security issue: email support@eternasafe.in with subject line "Security Vulnerability Report". Include a clear description and steps to reproduce. We will acknowledge within 48 hours and investigate within 14 days. We request that you do not publicly disclose the vulnerability until we have had an opportunity to address it.
13. Cookies and Analytics
Our website (www.eternasafe.in) uses only essential cookies necessary for basic site function and security. We use self-hosted, privacy-first analytics to understand aggregate page view patterns — this data is not personally identifiable and is not shared with third parties. We do not use Google Analytics, advertising cookies, or behavioural tracking cookies.
14. Children's Data
The Platform is intended for adults (18 years and above). We do not knowingly collect data from individuals under 18. If you believe a minor has registered, contact info@eternasafe.in immediately.
15. Changes to This Policy
When we make material changes, we will notify registered users via SMS or email at least 14 days before the change takes effect. The updated Policy will be published at www.eternasafe.in with a new version number and effective date.
16. Governing Law
This Privacy Policy is governed by Indian law, including the DPDPA 2023, IT Act 2000, and Consumer Protection Act 2019. Disputes are subject to the exclusive jurisdiction of courts in India.
17. Contact Us
General Queries: info@eternasafe.in
Support & Grievances: support@eternasafe.in
Grievance Officer: Amardeep Kumar, Co-Founder & CEO
Response Time: Acknowledge within 48 hours · Resolve within 30 days
Website: www.eternasafe.in
Legal Disclaimer: This Privacy Policy is a working document revised as of June 15, 2026. It has been drafted with reference to the DPDPA 2023, DPDP Rules 2025, and IT Act 2000 and incorporates recommendations from our technology partner's legal review. This document should be reviewed and finalised by a qualified Indian legal professional before final publication. Eternasafe Technologies Private Limited reserves the right to amend this Policy at any time in compliance with applicable law.