Privacy Policy

Effective / Last Updated: 26 July 2026

This Privacy Policy explains how ARK Tech & Logistics("Testiy", "we", "us", "our") collects, uses, stores, shares, and deletes personal data when you use www.testiy.com, our chat, audits, Community, and related services (the "Services"). It is designed to meet expectations under India's Digital Personal Data Protection Act, 2023 (DPDP), and — where applicable — the EU/UK GDPR and similar laws. By creating an account or using the Services, you acknowledge this Policy. Where consent is required, we obtain it at signup via a required checkbox and expandable notice.

1. Controller / Data Fiduciary

The organisation responsible for personal data processed through Testiy is:

ARK Tech & Logistics

106 C, Karuvanchery, Parakkad, Thrissur, Kerala 680620, India

Email: support@testiy.com

Phone: +91 7736824838

Under DPDP terminology we act as a Data Fiduciary. Under GDPR terminology we act as a controller for account, billing, Community, and Service operation data. Processors acting on our instructions are listed in Section 12.

2. Scope & who this covers

This Policy applies to:

  • Visitors to our marketing pages and logged-in users of chat, audits, and dashboards
  • Community members (seekers, agencies, employers) and applicants interacting with vacancies/services
  • People who verify a certificate via a public verification link
  • People who contact support

It does not cover third-party websites we link to (embassies, employer sites, payment provider portals after redirect). Their policies apply separately.

3. Categories of personal data we collect

3.1 Account & identity

  • Name, email address, password hash (or OAuth identifiers), date of birth
  • Phone number when you provide it (for example Community registration)
  • Profile photo and Community profile fields (headline, bio, skills, location label, experience, education)
  • Legal consent metadata (terms/privacy acceptance timestamps and version)

3.2 Documents & verification inputs

  • Files you upload: PDFs/images of passports, permits, offers, contracts, bank statements, itineraries, insurance, invitation letters, and similar
  • Extracted text, metadata (for example PDF producer, edit history signals), OCR outputs, and risk scores derived from those files
  • Destination country, visa type, and other intake answers you enter in chat

3.3 Transactional data

  • Plan purchased, amount, currency, GST details as applicable, payment status, transaction IDs
  • Payment method tokens handled by the gateway — we do not store full PAN/card numbers

3.4 Community activity

  • Posts, comments, likes, follows, blocks, reports
  • Vacancies, service listings, applications, inquire messages and conversation metadata
  • Digest notification preferences

3.5 Technical & security data

  • IP address, user agent, device/browser type, approximate location derived from IP, timestamps
  • Diagnostics, error logs, rate-limit counters, fraud/abuse signals
  • Cookies and local/session storage keys needed for auth and consent handoff

4. Sources of data

  • You: forms, uploads, chat messages, Community content, support emails
  • Your devices: cookies, logs, analytics events
  • Auth providers: e.g. Google (name, email, avatar) when you choose OAuth
  • Payment providers: confirmation of payment success/failure and limited billing metadata
  • Other users: tags, replies, reports, applications referencing your profile

5. Purposes of processing

  • Create and secure accounts; authenticate sessions
  • Perform document verification audits; generate Reports and Certificates; operate verify links
  • Provide Free Chat / pathway guidance and product navigation
  • Process payments and prevent fraud/chargeback abuse
  • Operate Community (profiles, feed, messaging, digests) for eligible members
  • Customer support and service communications
  • Improve safety, quality, and reliability (including aggregated analytics)
  • Comply with law, enforce Terms, and respond to lawful requests

We do not sell personal data to data brokers or advertisers. We do not use your uploaded passport/bank PDFs for unrelated advertising profiling.

6. Legal bases (overview)

  • Contract / service delivery: processing needed to provide the audit, chat, Community, or support you requested
  • Consent: account creation notice (DPDP/GDPR expandable disclosure); optional digests where consent-based; cookies where required
  • Legitimate interests / employment of reasonable security: abuse prevention, logging, integrity of Services (balanced against your rights)
  • Legal obligation: tax, accounting, or responding to valid court orders

7. India — Digital Personal Data Protection Act, 2023 (detailed)

Where DPDP applies to digital personal data about individuals in India, we process such data for lawful purposes connected to the Services. Key points:

  • Notice & consent: Before or at account creation we present Terms, this Policy, and a clear notice of data categories and purposes. Signup cannot complete without affirmative acceptance.
  • Purpose limitation: We process for the purposes stated in Section 5 and closely related purposes (security, debugging).
  • Data minimisation: We ask only for fields needed for the flow (e.g. DOB for age gate; documents for the audit you start).
  • Accuracy: You should keep profile and contact data accurate; you may request corrections.
  • Retention: See Section 14. Source files are not kept indefinitely; account and billing records may be kept as required.
  • Rights: Subject to DPDP and implementing rules, you may request access, correction, erasure, and withdrawal of consent (withdrawal may mean we cannot continue providing the Service).
  • Children: Services are for adults 18+. We do not knowingly onboard children.
  • Significant Data Fiduciary: If designated under future rules, we will publish additional obligations and contact points as required.

8. EU/EEA & UK GDPR (detailed)

If you are in the EEA/UK (or GDPR otherwise applies), we process personal data under:

  • Art. 6(1)(b) contract — delivering paid/free Services you request
  • Art. 6(1)(a) consent — signup disclosures; certain optional processing
  • Art. 6(1)(f) legitimate interests — securing the platform, preventing fraud, aggregate product analytics (you may object)
  • Art. 6(1)(c) legal obligation — where we must retain records or disclose under law

Where we process special-category data (e.g. data revealing health from a medical certificate you chose to upload), we rely on explicit consent and/or necessity for the establishment/exercise of legal claims only when applicable — generally we ask you not to upload unnecessary special-category data.

Your GDPR rights include:

  • Access, rectification, erasure, restriction, portability
  • Objection to legitimate-interest processing and to direct marketing
  • Withdrawal of consent without affecting prior lawful processing
  • Complaint to a supervisory authority in your Member State

9. Special categories & sensitive documents

Passports, bank statements, and employment records are highly sensitive. We process them only to perform the Service you initiate. Prefer redacting unrelated account numbers where the audit does not require them. Do not upload other people's documents without authority.

10. Cookies, local storage & similar technologies

  • Essential: session/auth cookies, CSRF/security, load balancing
  • Functional: remembering UI preferences; temporary signup consent handoff in sessionStorage for OAuth
  • Analytics: e.g. Vercel Analytics or similar aggregated traffic metrics
  • Product analytics: a first-party visitor id cookie (tid) and page/chat/checkout events so we can improve conversion and support. Events may include approximate location (city/country/region derived from IP via our hosting provider). We prefer hashed IP identifiers for join/dedupe; raw IP is minimized and retained only as needed for security/admin review under DPDP retention limits.

You can control cookies via browser settings; blocking essential cookies may break login.

11. Community & public verification pages

Community profiles and posts are visible to other logged-in Community members as designed. Do not publish data you want to keep private. Messaging content is visible to conversation participants and may be reviewed for abuse.

Public certificate verification pages expose limited fields (for example verification code status, issue date, high-level result) to anyone with the link. Treat links as confidential if needed.

12. Sharing with processors & third parties

We share personal data only as needed with:

  • Infrastructure: cloud hosting, object storage, databases (e.g. Supabase), CDN/edge (e.g. Vercel)
  • Auth: Supabase Auth; Google if you choose Google sign-in
  • Payments: Razorpay (or successor gateway) under PCI standards
  • Email: transactional email providers for receipts, reports, digests
  • AI model providers: where chat/audit pipelines call external models, prompts may include necessary user content under processor terms
  • Professional advisers / authorities: when required by law or to protect rights and safety

We require processors to protect data and use it only on our instructions, except where they act as independent controllers (e.g. Google for your Google account).

13. International transfers

Servers and vendors may be located in India, the EU, the United States, or other countries. Where GDPR transfer rules apply, we use appropriate safeguards (for example standard contractual clauses or vendor mechanisms) and assess transfer risk. Contact us for more detail on current subprocessors.

14. Retention & deletion

  • Uploaded source files: processed for the audit window; we aim to purge active processing copies after report delivery according to product design. Re-upload may be required if you need a new run.
  • Reports / certificates / case records: retained so you can access history and so we can support verify links, disputes, and compliance — typically for the life of the account plus a limited archival period unless you validly request erasure and law allows.
  • Account data: kept while your account is active; deleted or anonymised after closure subject to legal holds (tax, fraud).
  • Community content: kept while your membership is active; may remain visible in others' threads in limited form after deletion (e.g. “Deleted user”) where technically necessary.
  • Logs: security logs retained for a rolling window (typically weeks to months) then deleted or aggregated.

15. Security measures

  • TLS encryption in transit; encryption at rest for stored objects where offered by providers
  • Access controls and least-privilege for staff reviewing paid human-audit queues
  • Auth session protection via industry-standard cookie practices
  • Monitoring for abuse and anomalous traffic

No method of transmission or storage is 100% secure. Please use a strong unique password and protect your devices.

16. Your rights & how to exercise them

Email support@testiy.comwith the subject "Privacy Request" and specify access, correction, erasure, consent withdrawal, or objection. We may need to verify your identity. We respond within timelines required by applicable law (and generally aim for 30 days under GDPR practice).

Related product policies: Terms · Refunds · Delivery.

17. Children

Testiy is not directed to individuals under 18. If you believe a child provided data, contact us and we will delete it where required.

18. Automated decision-making & AI

Verification scoring and chat replies may use automated systems, including large language models. Paid human-review tiers add expert oversight. Automated outputs can be wrong; they do not by themselves produce legal effects equivalent to a government visa decision.

You may request human review of a paid audit outcome through support where your plan includes human verification.

19. Marketing communications

Transactional emails (receipts, report ready, security alerts) are part of the Service. Optional Community digests can be controlled in profile settings where available. We do not sell email lists.

20. Changes to this Policy

We may update this Policy to reflect product, vendor, or legal changes. We will update the effective date and, for material changes, provide additional notice (banner or email) where appropriate. Continued use after the effective date means you acknowledge the updated Policy. Where consent is required for new processing, we will request it.

21. Contact, DPO & complaints

Privacy / support: support@testiy.com

Entity: ARK Tech & Logistics, Thrissur, Kerala, India

India: you may also escalate to the Data Protection Board of India once fully operational under DPDP rules. EEA/UK: you may lodge a complaint with your local supervisory authority. We would appreciate the chance to resolve concerns first.