Skip to content

Legal / Privacy

Your identity data should remain yours.

This policy explains what DUIID needs to operate an identity lifecycle service, what remains private, the choices you control, and how to exercise your rights. We use direct language because privacy should not require a legal decoder.

Manaspurti Technologies Private Limited is the operator of DUIID. Effective 19 July 2026.
Effective: 19 July 2026Version: 1.0Contact: support@duiid.com

1. Scope and responsibility

This policy applies to DUIID websites, applications, support channels, and services operated by Manaspurti Technologies Private Limited (“DUIID”, “we”, “us”, or “our”). It does not govern an external service merely because you record a link, account, or asset relating to that service inside DUIID.

For personal and family use, DUIID generally determines why and how account and service data is processed. For an organization realm, the organization may control member and business data while DUIID processes it under the organization’s instructions. The organization should give its members any additional workplace privacy notice required by law.

Product settings and a signed business agreement take precedence where they provide stronger protection. Nothing in this policy limits rights that applicable law does not allow you to waive.

2. Data we handle

Information you provide

  • Account and contact data: name, email address, language, account preferences, and authentication or recovery setup.
  • Identity and profile data: names, descriptions, links, claims, relationships, roles, and attributes you add to a personal, family, professional, public, or organization identity.
  • Protected resources: credentials, secure notes, documents, keys, certificates, ownership records, recovery material, and other content you choose to protect in DUIID.
  • Access and continuity instructions: delegates, guardians, beneficiaries, approvers, permissions, release conditions, dispute choices, and succession or closure instructions.
  • Communications: support messages, feedback, survey responses, security reports, and information you provide during verification or a rights request.
  • Commercial records: plan, billing contact, transaction status, tax information, entitlements, and invoices. Payment credentials are handled by authorized payment processors rather than stored by DUIID where practical.

Information generated through use

  • Device and security data: device or browser type, operating system, network address, session and authentication events, risk signals, and security-relevant activity.
  • Service and audit data: feature interactions, permission decisions, changes, exports, recovery events, errors, performance, and records required to explain sensitive actions.
  • Approximate location: a coarse location inferred from network information for security, fraud prevention, localization, and legal requirements—not continuous precise tracking.
  • Import and integration data: content and identifiers you instruct DUIID to retrieve, receive, synchronize, or send through a connected service.

Information from other people

A family organizer, employer, collaborator, delegate, verifier, or other authorized person may provide information about you. We record its source and context where appropriate. Do not add someone else’s sensitive data unless you have a lawful reason and the authority to do so.

3. How we use data

We process data only where it supports a defined purpose, including to:

  • create and authenticate accounts, identities, realms, devices, and sessions;
  • store, organize, protect, search, synchronize, export, and delete the resources you direct us to handle;
  • apply sharing, delegation, approval, recovery, continuity, succession, archival, and closure instructions;
  • publish information you deliberately place in a public profile and display the scope of supported verification;
  • detect fraud, abuse, account takeover, unsafe access, policy violations, defects, and threats;
  • provide support, service notices, invoices, rights handling, and security communications;
  • measure reliability and improve usability using data minimized for that purpose;
  • comply with law, enforce our terms, protect people, and establish or defend legal claims.

Depending on your location and the activity, our legal basis may be performance of a contract, your consent, compliance with law, protection of vital interests, or our legitimate interests in operating and securing DUIID without overriding your rights. You may withdraw consent for future processing where consent is the basis.

AI-assisted features

DUIID may offer optional assistance for organizing, drafting, extracting, or explaining information. The interface will identify when an AI feature is used and what information it needs. Protected content is not used to train general-purpose models without a separate, explicit choice. Material identity, access, legal, financial, or legacy decisions require human confirmation.

4. When data is shared

We do not sell personal data or use protected content for behavioral advertising.

Data may be disclosed only to the extent needed:

  • At your direction: to a person, realm, verifier, integration, delegate, guardian, beneficiary, or public audience you choose.
  • To service processors: carefully selected companies that help provide infrastructure, authentication, communications, payments, support, security, verification, or optional AI functions under contractual confidentiality and data-protection obligations.
  • For organization accounts: to authorized administrators according to the organization realm’s ownership and permission model. Organization authority does not extend into a member’s personal realm.
  • For safety and law: when we reasonably believe disclosure is required by valid legal process or necessary to protect rights, safety, service integrity, or people from serious harm. We review demands and challenge overbroad requests where lawful.
  • During a corporate change: as part of due diligence, financing, reorganization, acquisition, or sale, subject to confidentiality, purpose limitation, and notice where required.

We avoid publishing a map of sensitive infrastructure. Customers who need deeper processor, residency, or assurance information may request it through an appropriate trust-review or contractual process.

5. Your visibility and control

DUIID separates private, shared, organization-controlled, and public information. New content is private unless the workflow clearly says otherwise. Before sharing or publishing, the product should show the audience, resource, authority, duration, and material consequence.

  • You can review and revoke active grants, subject to lawful records and actions already completed by a recipient.
  • You can manage connected services and prevent future synchronization.
  • You can export supported account and identity data in a usable format.
  • You can archive, transfer, close, or request deletion through the applicable lifecycle workflow.
  • Security, legal, and service-critical messages cannot always be disabled while an account remains active.

A public profile can be indexed, copied, cached, or archived by others. Removing it from DUIID cannot guarantee deletion of copies outside our control. Verification confirms only the claim and scope displayed; it is not a general endorsement of a person or organization.

6. Security and confidentiality

DUIID uses layered administrative, technical, physical, and product safeguards appropriate to the sensitivity of identity data. These include encryption, isolation, least privilege, controlled administrative access, secure development, monitoring, recovery testing, incident response, and independent assessment where appropriate.

Protected customer content is designed so routine support and operations cannot read it. Access you intentionally grant to another person or service may allow that recipient to see or copy the shared information; encryption cannot revoke a copy already made outside DUIID.

No service can promise absolute security. You should protect enrolled devices and recovery materials, use strong authentication, review security notices promptly, and report suspected compromise to security@duiid.com.

7. Retention and deletion

We retain personal data for the shortest period that supports the stated purpose, account lifecycle, security, contractual obligations, dispute handling, and applicable law. Retention varies by category:

  • active identity data remains while you maintain it or until the governing realm removes it;
  • protected resources follow your deletion, archival, continuity, or organization-retention instructions;
  • security and audit records are retained long enough to detect abuse, investigate incidents, and meet assurance or legal needs;
  • billing and corporate records may be kept for statutory accounting and tax periods;
  • backups expire through controlled rotation and are not restored to bypass a valid deletion request.

We may delay deletion where necessary to prevent fraud, preserve evidence, resolve a dispute, honor a legal hold, or protect a beneficiary or dependent. The product will identify material waiting periods and provide status where disclosure is lawful and safe.

8. Your privacy rights

Depending on applicable law, you may request access, correction, completion, portability, restriction, objection, withdrawal of consent, or erasure. You may also ask how data was used or shared, raise a grievance, appeal a decision, and nominate another person to exercise rights in the event of death or incapacity where law provides that right.

Send a request to support@duiid.com. We will verify your authority without requesting more data than reasonably necessary. Authorized representatives must show their authority. We may limit or refuse a request where law permits, and will explain the reason and available appeal route.

You may complain to the privacy or data-protection authority responsible for your jurisdiction. Relevant frameworks may include India’s digital personal data protection framework and the EU General Data Protection Regulation.

9. International use and transfers

DUIID is based in India and is intended for people and organizations that may operate across borders. Personal data may be processed in countries other than your own where our team or authorized processors operate. We use contractual, organizational, and technical safeguards required for applicable transfers and offer specific residency commitments only when included in your plan or agreement.

10. Children and family identities

A child may not independently open a DUIID account unless the product and law in their location permit it. Family features for dependents are managed by an authorized adult with age-appropriate explanations, limited visibility, and a defined transition to the young person’s control when appropriate.

Parents and guardians must not use family administration as blanket access to a child’s private life. Where we learn that data was collected without the required authority, we will restrict or delete it as appropriate.

11. Changes and contact

We may update this policy as DUIID, the law, or our practices evolve. We will identify the effective date and provide advance notice of material changes through the service or an appropriate contact channel. A change will not silently convert private content into public content or create a new use that requires consent without asking for it.

Privacy questions, grievances, rights requests, and concerns can be sent to support@duiid.com or by writing to Manaspurti Technologies Private Limited, Panaji, Goa, India. Security vulnerabilities should be sent to security@duiid.com.