1. Who We Are — Data Fiduciary Identity

The Data Fiduciary for all personal data processed through the Praxate platform is:

Xserv Labs Pvt Ltd
CIN: [CIN — INSERT BEFORE PUBLISH]
Registered address: [REGISTERED ADDRESS — INSERT BEFORE PUBLISH]
Email: [email protected]
Website: praxate.com

"Data Fiduciary" has the meaning given in the Digital Personal Data Protection Act 2023 (India) — it is the entity that determines the purpose and means of processing personal data. Xserv Labs Pvt Ltd is the operator of the Praxate CCTV analytics service.

Our customers (businesses that subscribe to Praxate) are "Data Principals" with rights described in section 6 below. The employees, visitors, and individuals whose biometric data is processed through the Praxate software at a customer's premises are also Data Principals in respect of that processing.

2. What Data We Process and Why — Five Processing Purposes

Praxate processes video footage and, where face recognition is enabled, biometric data (specifically, mathematical face embeddings — numerical vectors derived from facial geometry). We do not retain raw face photographs beyond the instant of enrollment unless a customer explicitly opts in. Raw images are deleted from on-premises storage immediately after the face embedding is generated.

We process personal data for exactly five purposes. Each purpose requires separate, informed consent under DPDP Act 2023 §6. Three are necessary for the core service to function; two are optional.

Purpose What we process Type
Employee Attendance
attendance
Face embeddings of enrolled employees. Generates entry/exit timestamps for the attendance log. Required
Visitor Tracking
visitor_tracking
Face embeddings of enrolled visitors. Generates visitor entry/exit records for security logs. Embeddings stored encrypted; raw images deleted immediately after creation. Required
Unknown-Person Alerts
stranger_alerts
Video frames containing unrecognised persons. Processed locally on the customer's hardware; alert metadata (timestamp, camera ID, bounding box) dispatched to the customer's designated contacts. No face embedding is stored for unrecognised persons beyond the alert event window. Required
Behaviour Analytics
behaviour_analytics
Aggregated, anonymised statistics — zone occupancy counts, dwell times, movement flows. No individual identification. This purpose can be declined without affecting attendance or alert features. Optional
Live Monitoring Feed
live_monitoring
Real-time annotated video stream showing identity overlays on enrolled persons. Requires attendance and visitor_tracking purposes. This purpose can be withdrawn independently. Optional

No purpose beyond these five exists. We do not use customer face data to train or improve our own machine-learning models. We do not sell, share, or transfer face embeddings or raw video to any third party except as described in section 5 (sub-processors).

3. Legal Basis for Processing (DPDP Act 2023 §6)

Our legal basis for all personal data processing is consent under DPDP Act 2023 §6. Consent is:

Consent is recorded with: the exact purposes accepted, the version of the consent text shown (version 1), a UTC timestamp, and a one-way-hashed record of the session. A reference number is displayed to the customer immediately after consent is recorded.

We do not rely on "legitimate interest", "contract necessity", or any basis other than consent for biometric data. Biometric data is classified as sensitive personal data under DPDP Act 2023 and requires explicit, purpose-specific consent.

4. Retention Periods

We retain personal data only as long as necessary for the stated purpose (DPDP Act 2023 §8(1)). The table below reflects the technical policy enforced in the Praxate software.

Data type Retention period Basis
Face embeddings (encrypted mathematical vectors) 30 days after the last access event for that person Active employment / active visitor relationship. Deleted when purpose ends.
Raw face photographs at enrollment Deleted immediately after the face embedding is created Data minimisation — DPDP §5 and GDPR Art. 5(1)(e). Raw images serve no purpose once the embedding exists.
Camera footage (short-term clip buffer) 7 days on-premises rolling buffer Alert evidence window. Footage is stored solely on the customer's dedicated hardware.
Alert snapshots (still frames, on-premises) 30 days from the alert event Alert evidence. Deleted automatically by the on-premises retention job.
Attendance event logs 1 year Statutory payroll record requirements under Indian labour law.
Consent records (audit trail) Duration of the customer relationship + 3 years Statutory evidence of consent under DPDP Act 2023 §6. Not deletable — the record proves consent was given or withdrawn.
All personal data on account cancellation 30 days from the date of account cancellation or consent withdrawal DPDP Act 2023 §8(7) erasure obligation.

Retention enforcement is automated. The on-premises Praxate software runs scheduled retention jobs that delete data past its retention window. Customers can also trigger early deletion via the Account page or by contacting the DPO.

5. Sub-Processors and Data Transfers

Face embeddings, raw video, and biometric data never leave the customer's on-premises hardware. All face recognition inference runs locally on the dedicated hardware we provision for each customer. No face data is sent to any cloud service, including our own cloud infrastructure.

The following sub-processors receive non-biometric data on our behalf under data processing agreements:

Sub-processor What they receive Region
Cloudflare Network tunnel metadata, TLS termination, DDoS protection. Does not receive face data or video content. Global edge; India PoPs for Indian customers
Amazon Web Services (AWS Mumbai) Cloud licensing and account management API. Receives: account metadata (company name, email, license tier). Does not receive face data, video, or embeddings. ap-south-1 (Mumbai, India)
Razorpay Payment processing. Receives: billing details (name, email, card/bank details). Does not receive face data or video. India

We do not use AWS Rekognition or any cloud-based face recognition service. This is an architectural constraint, not a policy choice — our system design physically prevents biometric data from leaving the customer's network.

We do not transfer personal data outside India except as required for the Cloudflare global CDN (which processes only network metadata, not personal data content).

6. Your Rights as a Data Principal (DPDP Act 2023 §§11–14)

Under the Digital Personal Data Protection Act 2023 you have the following rights. To exercise any right, contact the DPO at [email protected]. We will respond within 30 days.

Right of Access (§11)

Request a summary of the personal data we hold about you, the processing purposes, and the third parties with whom it has been shared.

Right to Correction (§12(a))

Request correction of inaccurate or incomplete personal data. For face embeddings, re-enrollment with fresh images will replace existing embeddings.

Right to Erasure (§12(b))

Request deletion of personal data when it is no longer necessary for the stated purpose, or upon withdrawal of consent. Erasure completed within 30 days.

Right to Grievance Redressal (§13)

Lodge a complaint with our DPO. If unsatisfied with our response, you may escalate to the Data Protection Board of India under §75.

Right of Nominee (§14)

Designate a nominee to exercise your rights in the event of death or incapacity. Contact the DPO to register a nominee.

Right to Withdraw Consent (§6(4))

Withdraw consent at any time with the same ease as giving it. See section 9 for the withdrawal procedure.

There are no fees for exercising these rights. We will not discriminate against you for exercising them.

7. Children's Data (DPDP Act 2023 §9)

Praxate is intended for use in commercial and professional premises. It is not directed at or intended to process the personal data of persons under 18 years of age.

Our consent flow requires every subscribing organisation to affirmatively attest that they will not enrol or process the biometric data of any person under 18 without first obtaining verifiable parental or guardian consent, as required by DPDP Act 2023 §9. Violation of this attestation constitutes a material breach of the service agreement.

If we become aware that biometric data of a minor has been processed without valid parental consent, we will erase the data immediately and notify the customer. Repeat violations may result in immediate account suspension.

8. Security Measures

We implement the following technical and organisational measures to protect personal data (DPDP Act 2023 §8(4), GDPR Art. 32):

In the event of a personal data breach that is likely to result in risk to Data Principals, we will notify affected customers and, where required, the Data Protection Board of India, without undue delay.

9. How to Withdraw Consent and Request Erasure

Withdrawal is as easy as giving consent — this is a statutory requirement under DPDP Act 2023 §6(4).

To withdraw consent and request erasure of all personal data:

  1. Log in to your Praxate account at app.praxate.com.
  2. Navigate to Account → Data and Privacy.
  3. Click "Withdraw consent and delete all data".
  4. Confirm the withdrawal. You will receive a reference number by email.

Alternatively, email [email protected] with the subject line "Consent Withdrawal — [your company name]". We will initiate the erasure workflow within 24 hours and complete it within 30 days (DPDP §8(7)).

Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal. After withdrawal, all face embeddings, raw video buffers, and personal data will be deleted from both the on-premises hardware and our cloud records within 30 days. Consent records (which prove withdrawal occurred) are retained for 3 years for statutory compliance purposes.

Billing ceases from the next billing cycle after withdrawal.

10. Grievances and the Data Protection Board

If you have a complaint about how we handle your personal data:

  1. Contact our DPO first. Email [email protected]. We will acknowledge within 48 hours and resolve within 30 days.
  2. If unsatisfied, you may escalate to the Data Protection Board of India under DPDP Act 2023 §75. The Board's contact details will be published by the Central Government upon operationalisation of the Act.

11. Changes to This Policy

We will notify customers of any material changes to this policy (changes to processing purposes, new sub-processors, or changed retention periods) via email at least 14 days before the change takes effect. Material changes require fresh consent — the consent_version will be incremented and customers on the previous version will be prompted to re-consent before any new processing scope applies.

Minor changes (typographical corrections, clarifications that do not affect scope) may be made without prior notice. The "Version" and "Effective date" fields at the top of this page will be updated.

12. Contact — Data Protection Officer

Data Protection Officer
Ali Mohd
Xserv Labs Pvt Ltd
Email: [email protected]
Address: [REGISTERED ADDRESS — INSERT BEFORE PUBLISH]
Response time: 30 days for data subject requests; 48 hours for acknowledgement.