Information Security Policy

Effective Date: 07th June 2026

This Information Security Policy (“Policy”) describes the operational, administrative, and reasonable security practices followed by Bharosak, operated by Anvay Ventures, for protecting information processed through https://bharosak.com/ and related services.

This Policy should be read together with Bharosak’s:

  • Privacy Policy,

  • Terms of Service,

  • Data Retention and Operational Policy,

  • Disclaimer,

  • and other applicable policies.

1. PURPOSE OF THIS POLICY

The purpose of this Policy is to:

  • promote responsible information handling,

  • reduce unauthorized access risks,

  • protect operational records,

  • support secure service delivery,

  • maintain customer trust,

  • and establish reasonable information security practices.

Bharosak recognizes the importance of protecting user information and aims to implement commercially reasonable safeguards appropriate for its operational scale and services.

2. SCOPE

This Policy applies to:

  • website operations,

  • communication systems,

  • operational processes,

  • verification workflows,

  • customer records,

  • consent records,

  • payment-related handling,

  • and information processed by Bharosak.

This Policy applies to:

  • employees,

  • representatives,

  • contractors,

  • support personnel,

  • service providers,

  • and authorized operational users handling Bharosak-related information.

3. INFORMATION COVERED

Information handled by Bharosak may include:

  • personal information,

  • verification records,

  • uploaded documents,

  • communication records,

  • payment references,

  • consent confirmations,

  • call recordings,

  • operational logs,

  • and related business records.

Documents voluntarily submitted may include:

  • PAN card,

  • Aadhaar copy (preferably masked),

  • Driving licence,

  • Voter ID,

  • Vehicle RC,

  • bank-related information,

  • and other supporting records.

4. SECURITY OBJECTIVES

Bharosak aims to maintain reasonable safeguards to support:

  • confidentiality,

  • integrity,

  • operational availability,

  • and responsible handling of information.

Security objectives include:

  • preventing unauthorized access,

  • reducing accidental disclosure risks,

  • minimizing misuse,

  • maintaining operational reliability,

  • and supporting lawful business practices.

5. ACCESS CONTROL

Bharosak aims to restrict access to sensitive information on a need-to-know basis.

Operational access may be limited through:

  • account credentials,

  • password-protected systems,

  • role-based access practices where applicable,

  • restricted communication access,

  • and operational supervision.

Only authorized personnel may access information reasonably required for operational duties.

6. PASSWORD AND ACCOUNT SECURITY

Personnel handling Bharosak systems are expected to:

  • maintain secure passwords,

  • avoid password sharing,

  • protect account credentials,

  • and use reasonable account security practices.

Where applicable, Bharosak may implement:

  • multi-factor authentication,

  • login protections,

  • or account monitoring practices.

7. DOCUMENT HANDLING PRACTICES

Bharosak aims to handle submitted documents responsibly and operationally securely.

Operational practices may include:

  • restricted document access,

  • limited sharing,

  • controlled internal handling,

  • secure communication methods where reasonably available,

  • and periodic operational review.

Users are encouraged to:

  • avoid sharing unnecessary sensitive information,

  • submit masked Aadhaar copies wherever possible,

  • and provide only information reasonably required for verification purposes.

8. COMMUNICATION SECURITY

Bharosak may communicate with users through:

  • email,

  • WhatsApp,

  • phone calls,

  • SMS,

  • or other operational communication channels.

While Bharosak aims to use reliable communication platforms, users acknowledge that:

  • internet communication is not fully secure,

  • third-party communication platforms operate independently,

  • and no transmission method can guarantee absolute security.

9. CALL RECORDINGS

Calls made for:

  • verification authorization,

  • customer support,

  • quality assurance,

  • dispute resolution,

  • compliance,

  • or operational purposes

may be recorded and retained for legitimate business purposes.

Call recordings are intended to support:

  • audit trails,

  • operational transparency,

  • customer support,

  • and fraud prevention.

Access to recordings shall be reasonably restricted.

10. THIRD-PARTY SERVICE PROVIDERS

Bharosak may use third-party providers including:

  • verification partners,

  • API providers,

  • payment gateways,

  • cloud platforms,

  • communication providers,

  • analytics tools,

  • and operational software services.

While Bharosak aims to work with commercially reliable providers, Bharosak does not control independent third-party infrastructure or systems.

Users acknowledge that:

  • · certain information may be processed through third-party platforms,

  • · and third-party risks may exist outside Bharosak’s direct control.

11. PAYMENT SECURITY

Payments may be processed through authorized third-party payment gateways.

Bharosak does not intentionally store:

  • complete card details,

  • banking passwords,

  • UPI PINs,

  • CVV numbers,

  • or sensitive financial authentication credentials.

Users should never share confidential banking credentials with Bharosak representatives.

12. DATA RETENTION AND STORAGE

Information may be retained only for:

  • operational purposes,

  • consent verification,

  • customer support,

  • fraud prevention,

  • legal compliance,

  • dispute resolution,

  • and legitimate business requirements.

Retention periods may vary depending on operational and legal needs.

Further details are available in Bharosak’s Data Retention and Operational Policy.

13. SECURITY INCIDENT RESPONSE

In the event of suspected:

  • unauthorized access,

  • operational misuse,

  • data exposure,

  • fraud,

  • or security incidents

Bharosak may take reasonable actions including:

  • restricting access,

  • reviewing logs,

  • suspending operations,

  • contacting affected parties where reasonably necessary,

  • cooperating with lawful authorities,

  • and implementing corrective measures.

Bharosak does not guarantee prevention of all cyber threats, attacks, or security incidents.

14. FRAUD PREVENTION

Bharosak may monitor operational activity to:

  • detect suspicious behavior,

  • reduce fraud risks,

  • identify misuse,

  • and maintain service integrity.

Bharosak reserves the right to:

  • suspend requests,

  • reject transactions,

  • preserve records,

  • or cooperate with authorities

where unlawful or suspicious activity is reasonably suspected.

15. OPERATIONAL LIMITATIONS

While Bharosak aims to implement commercially reasonable safeguards, users acknowledge that:

  • no digital platform is fully secure,

  • no communication channel is completely risk-free,

  • and no security system can guarantee absolute protection.

Users use Bharosak’s services and submit information at their own discretion and risk.

16. USER RESPONSIBILITIES

Users are responsible for:

  • safeguarding their own devices and accounts,

  • submitting only necessary information,

  • ensuring lawful consent,

  • avoiding unauthorized sharing,

  • and using Bharosak responsibly.

Users should:

  • avoid sharing passwords or OTPs unnecessarily,

  • use secure internet connections,

  • and immediately report suspicious activity.

17. EMPLOYEE AND OPERATIONAL AWARENESS

Bharosak may implement reasonable operational awareness practices relating to:

  • confidentiality,

  • responsible information handling,

  • operational security,

  • communication practices,

  • and fraud prevention.

Access to operational information may be reviewed periodically.

18. POLICY REVIEW AND MODIFICATIONS

Bharosak reserves the right to:

  • revise,

  • update,

  • modify,

  • or replace

this Policy at any time without prior notice.

Updated versions shall become effective upon publication on the website.

Continued use of Bharosak’s services constitutes acceptance of revised policies.

19. CONTACT DETAILS

For information security concerns, users may contact:

Anvay Ventures
Brand: Bharosak
Website: https://bharosak.com/

Email: support@bharsak.com
Phone: +91-8985704717

Users are encouraged to promptly report:

  • suspicious activity,

  • unauthorized communication,

  • security concerns,

  • or suspected misuse.

20. GOVERNING LAW

This Policy shall be governed by the laws of India.

Any disputes relating to this Policy or Bharosak’s operational practices shall be subject to the jurisdiction of competent courts located in India.

21. ACKNOWLEDGEMENT

By accessing Bharosak’s website, submitting information, uploading documents, making payments, or using related services, users acknowledge that they have read, understood, and agreed to this Information Security Policy.