Skip to content

Legal & trust

Privacy Policy

Last updated: 29 August 2026

1. Who this policy covers

In short:This covers three different groups, and your rights depend on which one you are in.

This policy applies to personal data processed by Papertrail Services Private Limited (CIN U74999UP2019PTC113147) ("Papertrail", "we", "us"), operating gopapertrail.ai.

It covers three distinct groups. Customers are the organisations that hold an account with us and their authorised users. Candidates are the individuals whose background is verified at a customer's request. Visitors are anyone who browses this website without doing either.

The distinction matters legally, not just editorially. Depending on the nature and purpose of the processing, Papertrail may act as a Data Fiduciary or as a Data Processor under India's Digital Personal Data Protection Act, 2023.

When an organisation engages us to verify a candidate, that organisation generally determines the purpose and scope of the check, and we process the candidate's personal data as a Data Processor on its instructions. Where we are a processor, requests about that data are directed to the employer, and we will tell you who they are.

For website visitors, customer accounts, billing, platform security, fraud prevention, audit records and other processing where we decide the purpose and means ourselves, we act as a Data Fiduciary.

2. What we collect

In short:Account details from customers, verification inputs from candidates, and ordinary technical data from visitors.

From customers: name, work email, phone number, job title, employer, billing details, and records of how the account is used — which checks were initiated, by whom, and when.

From candidates: only the personal data reasonably necessary for the verification the employer requested and permitted by law. Depending on that package this may include name, date of birth, contact details, current and previous addresses, government identifiers (Aadhaar, PAN, passport, driving licence, voter ID), education records, employment history and UAN, references, and where the role requires it, credit and court-record search inputs. Where a field visit forms part of an address check, a geo-tagged photograph of the premises. Which identity documents apply depends on the check, the customer's requirements and applicable law — no candidate is asked for all of them.

From visitors: IP address, browser and device type, pages viewed, referring page, and cookie identifiers. See the Cookie Policy for what is set and when.

We do not buy personal data from data brokers, and we do not collect candidate data speculatively. A candidate's record exists in our systems because a specific employer initiated a specific check with that candidate's consent.

3. Why we are allowed to process it

In short:Consent for verification, contract for your account, and legitimate uses for security and legal obligations.

Verification of candidates runs on consent. Under the DPDP Act, that consent must be free, specific, informed and unambiguous. We seek it per purpose rather than as a single blanket authorisation, and we record the notice that was shown at the time it was given.

Where we act as a Data Processor, the customer is responsible for determining the lawful basis for the verification and, where required, for ensuring the candidate has received the necessary notice and given valid consent. We support that process; we do not replace it.

Customer account data is processed to perform the contract we have with the customer organisation.

A small set of processing rests on another lawful basis permitted by applicable law — including complying with legal obligations, keeping records the law requires us to keep, protecting the security of the service, and preventing fraud or misuse of the platform.

Automated and AI-assisted tools support verification work — see section 4. Where a result may materially affect a candidate, a person reviews it before an adverse finding is treated as final.

4. How we use it

In short:To run the checks that were asked for, to operate and secure the platform, and for nothing else.

Candidate data is used to perform the verification the employer requested and to produce the report, including the evidence behind each finding. It is not used for any other purpose.

We do not sell or rent personal data, and we do not disclose candidate personal data to third parties for their own marketing. Disclosing an identifier to a university registrar or a court-record index in order to run the check you consented to is not a sale — it is how the verification is performed. Section 5 lists everyone data can reach.

AI and automated technologies. We use automation and machine learning to support verification — extracting text from a document you supplied, matching a name across transliteration variants, classifying records, and flagging potential discrepancies for review. These tools are used to deliver the verification service and are subject to contractual, security and access controls.

An automated or AI-assisted output may contain errors, and it is not by itself a determination that anyone is suitable or unsuitable for a role. Where a result may materially affect a candidate, a person reviews it before an adverse finding is treated as final. The hiring decision is always the employer's.

Customer data is used to provide the service, to bill for it, to provide support, and to send service communications. Marketing email is sent only with a separate opt-in and always carries an unsubscribe link.

Aggregate statistics that cannot identify any individual — such as median turnaround by check type — may be used to improve and describe the service.

5. Who we share it with

In short:The sources a check is verified against, a short list of infrastructure providers, and nobody else.

Verification sources. Carrying out a check necessarily means presenting an identifier to the source that holds the record. Depending on the check, that may include educational institutions, current or former employers, government and public records, courts and court-record repositories, sanctions and watchlist sources, credit information providers, and other authorised or lawfully available sources. Only the data necessary to perform that specific check is disclosed.

The instructing customer. The verification report and its evidence are returned to the employer who initiated the check and consented-to by the candidate.

Sub-processors. We use a limited set of infrastructure and service providers, each under a written processing agreement that restricts them to our instructions. A current list of our sub-processors is available to customers on request.

Legal disclosure. We may disclose personal data where compelled by a valid legal order. Where we are permitted to tell you, we will.

Corporate transactions. We may disclose personal data where reasonably necessary in connection with a merger, acquisition, restructuring, financing or sale of assets, subject to applicable law and appropriate confidentiality safeguards.

We do not disclose a candidate's data to any other employer, ever. A case belongs to the customer who initiated it.

6. Where it is stored

In short:Primarily in India. Some providers may process limited data elsewhere.

Papertrail primarily stores and processes personal data on infrastructure located in India, operated by established cloud providers under written processing agreements. Backups are held in the same jurisdiction as the primary data.

Depending on the service, certain providers or sub-processors may process limited personal data outside India where that is necessary to deliver it. Any such processing is subject to applicable law, contractual safeguards and appropriate security measures.

We do not claim that every copy of every record remains physically within India at all times, because a provider operating across jurisdictions may not permit that guarantee. Where data residency is a requirement for you, ask us and we will tell you exactly how your data is handled.

Details of our hosting arrangements, including provider and region, and a current list of material sub-processors, are available to customers on request.

7. How long we keep it

In short:Verdicts and the evidence behind them have different clocks, and both are subject to defined retention and deletion periods.

We hold verification findings separately from the evidence that produced them, because they justify different retention periods.

Underlying evidence — identity document images, certificate scans, payslips, field-visit photographs — is retained only as long as needed to support the report and any dispute window, and then deleted. The specific period is set by the agreement with the customer who commissioned the check, and is never longer than that agreement or applicable law allows.

The finding itself, and the audit record showing what was checked, when, against which source and with what consent, is retained for the period the customer's agreement and applicable law require.

Deletion is performed in accordance with this retention policy. Where required for legal proceedings, a regulatory requirement, dispute resolution or a fraud investigation, data may be retained beyond the ordinary period for as long as that requirement lasts.

Backups. Data removed from active systems may persist for a limited period in backup and disaster-recovery copies, and is overwritten or deleted as those copies age out on their normal cycle. Deletion from live systems is not instantaneous across every copy, and we would rather say so than imply otherwise.

Customer account data is retained for the life of the account and for the statutory period afterwards for tax and contractual records.

8. Your rights

In short:Access, correction, erasure, grievance redressal, and withdrawal of consent.

The availability and scope of a right may depend on the nature of the processing and on whether Papertrail is acting as a Data Fiduciary or a Data Processor for the data in question.

Under the DPDP Act you have the right to obtain a summary of the personal data we process about you and the processing activities undertaken; to have inaccurate or incomplete data corrected, completed or updated; to have data erased where it is no longer needed for the purpose it was collected for and no legal obligation requires its retention; to nominate another individual to exercise these rights in the event of death or incapacity; and to a grievance redressal mechanism.

Withdrawal of consent. Where processing rests on consent, you may withdraw it at any time and as easily as you gave it. Withdrawal is recorded and applied to further processing to the extent applicable law requires. It cannot undo processing already lawfully completed, cannot recall information already disclosed to a source or to the instructing employer before withdrawal took effect, and does not override an independent legal retention obligation. Where a check is already in progress with a third-party source, we will stop what is within our control.

A note specific to verification. A discrepancy does not necessarily mean the data we hold is inaccurate. If a verified finding differs from what you declared, the right to correction lets you correct inaccurate personal data we hold about you — it does not require us to replace a verified finding with an unverified statement. Where you dispute a result we will provide a mechanism to correct inaccurate data and, where appropriate, to record your explanation alongside the finding.

Where we act as a processor. The employer who commissioned the check is generally the Data Fiduciary and is responsible for answering requests about that data. We will identify them to you, pass your request on, and give them reasonable assistance in responding. We cannot decide on their behalf.

9. Security

In short:Encryption, least-privilege access, and a logged trail of who saw what.

We apply encryption in transit and encryption at rest to the systems that hold personal data. Access to case files is role-based, granted on the principle of least privilege, and monitored.

Government-issued identity numbers are masked, truncated, encrypted or otherwise protected wherever the full identifier is not required for the verification or for a legal purpose.

We operate vulnerability management, access reviews and a documented incident response process. Suspected vulnerabilities can be reported under our Responsible Disclosure Policy.

No system is perfectly secure. We maintain an incident-response process for personal data breaches: we assess, contain, investigate and remediate, and we notify the Data Protection Board of India, affected individuals, customers and any other relevant party where applicable law requires it, within the timelines that law prescribes.

10. Verification results and third-party sources

In short:A result reflects what the sources held when we asked. We do not control those records.

Verification results depend on information obtained from candidates, employers, educational institutions, government and public records, courts, authorised databases and other third-party sources.

We do not control the accuracy, completeness, availability or response time of records held by those third parties. A registry can be out of date, a record can be mis-indexed, and a source can decline to respond.

A verification result therefore reflects the information available to us from the relevant sources, and the procedures we performed, at the time of the check.

A result showing that no record was found does not establish that no record exists anywhere. Equally, an employment or education record being unavailable from one source does not establish that the underlying event never happened. Where a check cannot be completed or a source cannot be reached, we report that limitation rather than inferring a finding from the silence.

11. Customer responsibilities

In short:The employer decides why a check runs, and carries the obligations that come with that.

Where we act as a Data Processor, the customer is the Data Fiduciary and is responsible for:

determining the purpose and scope of the verification; having a lawful basis for requesting it; giving candidates the notice the law requires; obtaining valid consent where consent is the basis; providing accurate instructions and candidate information; using reports only for the purpose they were commissioned for; complying with applicable employment, anti-discrimination, privacy and data-protection law; and responding to candidate rights requests where it is the Data Fiduciary.

The customer is responsible for employment, engagement, promotion and termination decisions concerning candidates. Papertrail does not make those decisions and does not advise on them.

Our obligations to the customer, and theirs to us, are set out in full in the agreement between us — which may include a master services agreement, order form or data processing addendum. This section describes the division of responsibility; it does not replace that agreement.

12. Children

In short:The service is not for anyone under 18.

The platform is intended for use in employment contexts and is not directed at children. Under the DPDP Act a child is anyone who has not completed 18 years, and we do not knowingly process a child's personal data. If you believe we have, contact us and we will take appropriate steps to delete or otherwise address it, subject to any legal obligation requiring its retention.

13. Contact and grievances

In short:A named officer, a real address, and a response commitment.

For any question about this policy or to exercise a right, contact our Grievance Officer:

Name: Shahid Ali Designation: Grievance Officer Email: [email protected] Phone: +91 92050 41396 Address: Papertrail Services Private Limited, B-85, Sector 64, Noida, Uttar Pradesh 201301, India

We will acknowledge your request promptly and address it within the timelines required by applicable law and our grievance-redressal process. Where we are acting as a Data Processor for a customer, we may route the request to that customer and give them reasonable assistance in answering it.

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

14. Changes to this policy

In short:We will date every change and tell you about material ones.

We may update this policy as the service or the law changes. The date at the top of this page always reflects the current version. Where a change materially affects how we process your personal data, we will give notice by email or in the product before it takes effect. Previous versions are available to customers on request.