Privacy Policy
Privacy Policy
Effective Date: June 13, 2026 Last Updated: June 13, 2026 Version: 1.0
1. About Us
Lixhub is a digital identity verification and KYC platform operated by:
Rabinnson Private Limited WeWork, 13th Floor, Building No. 9, IT Park, Shaikpet, Hi Tech City, Hyderabad – 500081, Telangana, India
Email: lixhub@rabinnson.com Phone: +91 96689-01241 Website: https://rabinnson.com
This Privacy Policy explains how Rabinnson Private Limited ("we", "us", "our") collects, uses, stores, shares, and protects your personal information when you use the Lixhub platform ("Platform", "Services").
By accessing or using Lixhub, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of the Platform.
2. Applicable Laws
This Privacy Policy is governed by and complies with:
- The Information Technology Act, 2000 and the IT (Amendment) Act, 2008
- The Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules")
- The Digital Personal Data Protection Act, 2023 ("DPDP Act")
- The Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and associated UIDAI regulations
- Any other applicable laws and regulations of India
3. Information We Collect
3.1 Personal Information
- Full name
- Email address
- Mobile number
- Date of birth
- Gender
3.2 Identity and KYC Documents
- Aadhaar: We collect only masked Aadhaar (last 4 digits visible) or Virtual ID (VID) as retrieved through UIDAI-authorised channels (DigiLocker). We do not store the full 12-digit Aadhaar number on our servers.
- PAN Card: Permanent Account Number and associated document image
- GSTIN: Goods and Services Tax Identification Number and certificate
- Passport, Driving Licence, Voter ID (where applicable for identity verification)
3.3 Biometric and Visual Data
- Face photograph captured during liveness verification
- Video recording captured during Video KYC (VKYC) sessions
3.4 Organisational Information
- Company/organisation name, registered address, and incorporation details
3.5 Technical and Usage Data
- IP address, browser type, operating system
- Device identifiers
- Session data, access logs, and timestamps
- Cookies and local storage data (see Section 9)
4. Purpose of Collection
We collect the above information solely for the following purposes:
| Data Category | Purpose | |---|---| | Personal Information | Account creation, authentication, and communication | | Aadhaar (masked/VID) | Identity verification via UIDAI-authorised DigiLocker integration | | PAN Card | Business KYC and tax compliance verification | | GSTIN | Organisation KYC and GST compliance verification | | Face photograph | Liveness check and identity match during VKYC | | Video recording | Video KYC session recording for compliance and audit | | Technical data | Platform security, fraud prevention, and service improvement |
We do not collect any information beyond what is necessary for the stated purposes.
5. Aadhaar Data Handling
In compliance with the Aadhaar Act, 2016 and UIDAI regulations:
- No storage of full Aadhaar number: We do not store, transmit, or process the 12-digit Aadhaar number. Only masked Aadhaar or VID is retained.
- UIDAI-authorised channels only: Aadhaar-based verification is performed exclusively through DigiLocker, which is authorised by the Ministry of Electronics & Information Technology (MeitY).
- Explicit consent: Your explicit, informed consent is obtained before any Aadhaar data is fetched via DigiLocker.
- Audit logs: All Aadhaar data access events are logged and retained for a minimum of 5 years as required by UIDAI regulations.
- Purpose limitation: Aadhaar data is used solely for identity verification and is not shared with any third party for marketing, profiling, or any purpose other than KYC verification.
6. How We Use Your Information
- To verify your identity and complete KYC as required by applicable regulations
- To create and manage your account on the Platform
- To provide, maintain, and improve our Services
- To communicate with you about your account, verifications, and Platform updates
- To comply with legal and regulatory obligations
- To detect, prevent, and respond to fraud, security incidents, and misuse
- To maintain audit records as required by law
We will not use your personal information for targeted advertising, sale to third parties, or any purpose not stated in this Policy without your explicit consent.
7. Data Sharing and Third Parties
We share your data only in the following circumstances:
| Recipient | Purpose | Data Shared | |---|---|---| | DigiLocker (MeitY) | Aadhaar and document retrieval | Consent token, user identity | | UIDAI | Aadhaar authentication | Virtual ID / masked Aadhaar only | | Razorpay | Payment processing | Name, email, transaction details | | Cloud Infrastructure Provider | Hosting and storage | Encrypted personal data | | Regulatory Authorities | Legal compliance, court orders | As required by law |
We do not sell, rent, or trade your personal information to any third party.
All third-party processors are bound by data processing agreements that require them to protect your data in accordance with applicable Indian law.
8. Data Retention
| Data Type | Retention Period | |---|---| | KYC documents (PAN, GSTIN) | 5 years from submission or as required by law | | Aadhaar access logs | 5 years (UIDAI requirement) | | Video KYC recordings | 5 years from recording date | | Account and transaction data | Duration of account + 5 years | | Technical/access logs | 1 year |
After the applicable retention period, data is securely deleted or anonymised.
9. Cookies and Local Storage
We use the following storage mechanisms on your device:
| Name | Type | Purpose |
|---|---|---|
| authToken | Local Storage | Stores your JWT session token for authentication |
| refreshToken | Local Storage | Stores your refresh token for session renewal |
| user | Local Storage | Caches your profile data for faster page loads |
| consent | Cookie (30 days) | Records your cookie consent preference |
You may clear local storage and cookies through your browser settings. Clearing authToken will log you out of the Platform.
We do not use advertising cookies or cross-site tracking technologies.
10. Data Security
We implement the following security measures:
- Encryption in transit: All data is transmitted over HTTPS/TLS
- Encryption at rest: Personal and KYC data is encrypted at the storage level
- Access controls: Role-based access ensuring only authorised personnel access sensitive data
- Audit logging: All data access events are logged and monitored
- Incident response: We maintain a 48-hour security incident response SLA
In the event of a data breach that is likely to affect your rights, we will notify you and the relevant authorities within the timeframes prescribed by the DPDP Act, 2023 and CERT-In guidelines.
11. Your Rights
Under the DPDP Act, 2023 and IT Rules, 2011, you have the right to:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your data (subject to legal retention obligations)
- Withdrawal of Consent: Withdraw consent for data processing at any time (this may affect your ability to use the Platform)
- Grievance Redressal: Lodge a complaint with our Grievance Officer
To exercise any of these rights, contact us at lixhub@rabinnson.com with the subject line "Data Rights Request". We will respond within 30 days.
12. Grievance Officer
In accordance with Rule 5(9) of the IT (SPDI) Rules, 2011 and the DPDP Act, 2023, we have designated a Grievance Officer:
Mr. Debasis Nishank Nodal Officer Rabinnson Private Limited WeWork, 13th Floor, Building No. 9, IT Park, Shaikpet, Hi Tech City, Hyderabad – 500081, Telangana, India Email: lixhub@rabinnson.com Phone: +91 96689-01241
Grievances will be acknowledged within 48 hours and resolved within 30 days of receipt.
13. Children's Privacy
The Platform is intended for use by individuals aged 18 years and above and registered business entities. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us immediately at lixhub@rabinnson.com.
14. Cross-Border Data Transfers
Our primary servers are located in India. If any personal data is processed or stored outside India, we ensure such transfers comply with the DPDP Act, 2023 and that the recipient jurisdiction provides adequate data protection standards.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- The "Last Updated" date at the top of this page will be revised
- For material changes, we will notify you via email or a prominent notice on the Platform
- Continued use of the Platform after such changes constitutes acceptance of the updated Policy
16. Contact Us
For any questions, concerns, or requests related to this Privacy Policy:
Rabinnson Private Limited WeWork, 13th Floor, Building No. 9, IT Park, Shaikpet, Hi Tech City, Hyderabad – 500081, Telangana, India Email: lixhub@rabinnson.com Phone: +91 96689-01241
This Privacy Policy is governed by the laws of India. Any disputes arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Hyderabad, Telangana.