Information Security Policy
Effective Date: 07th June 2026
This Information Security Policy (“Policy”) describes the operational, administrative, and reasonable security practices followed by Bharosak, operated by Anvay Ventures, for protecting information processed through https://bharosak.com/ and related services.
This Policy should be read together with Bharosak’s:
Privacy Policy,
Terms of Service,
Data Retention and Operational Policy,
Disclaimer,
and other applicable policies.
1. PURPOSE OF THIS POLICY
The purpose of this Policy is to:
promote responsible information handling,
reduce unauthorized access risks,
protect operational records,
support secure service delivery,
maintain customer trust,
and establish reasonable information security practices.
Bharosak recognizes the importance of protecting user information and aims to implement commercially reasonable safeguards appropriate for its operational scale and services.
2. SCOPE
This Policy applies to:
website operations,
communication systems,
operational processes,
verification workflows,
customer records,
consent records,
payment-related handling,
and information processed by Bharosak.
This Policy applies to:
employees,
representatives,
contractors,
support personnel,
service providers,
and authorized operational users handling Bharosak-related information.
3. INFORMATION COVERED
Information handled by Bharosak may include:
personal information,
verification records,
uploaded documents,
communication records,
payment references,
consent confirmations,
call recordings,
operational logs,
and related business records.
Documents voluntarily submitted may include:
PAN card,
Aadhaar copy (preferably masked),
Driving licence,
Voter ID,
Vehicle RC,
bank-related information,
and other supporting records.
4. SECURITY OBJECTIVES
Bharosak aims to maintain reasonable safeguards to support:
confidentiality,
integrity,
operational availability,
and responsible handling of information.
Security objectives include:
preventing unauthorized access,
reducing accidental disclosure risks,
minimizing misuse,
maintaining operational reliability,
and supporting lawful business practices.
5. ACCESS CONTROL
Bharosak aims to restrict access to sensitive information on a need-to-know basis.
Operational access may be limited through:
account credentials,
password-protected systems,
role-based access practices where applicable,
restricted communication access,
and operational supervision.
Only authorized personnel may access information reasonably required for operational duties.
6. PASSWORD AND ACCOUNT SECURITY
Personnel handling Bharosak systems are expected to:
maintain secure passwords,
avoid password sharing,
protect account credentials,
and use reasonable account security practices.
Where applicable, Bharosak may implement:
multi-factor authentication,
login protections,
or account monitoring practices.
7. DOCUMENT HANDLING PRACTICES
Bharosak aims to handle submitted documents responsibly and operationally securely.
Operational practices may include:
restricted document access,
limited sharing,
controlled internal handling,
secure communication methods where reasonably available,
and periodic operational review.
Users are encouraged to:
avoid sharing unnecessary sensitive information,
submit masked Aadhaar copies wherever possible,
and provide only information reasonably required for verification purposes.
8. COMMUNICATION SECURITY
Bharosak may communicate with users through:
email,
WhatsApp,
phone calls,
SMS,
or other operational communication channels.
While Bharosak aims to use reliable communication platforms, users acknowledge that:
internet communication is not fully secure,
third-party communication platforms operate independently,
and no transmission method can guarantee absolute security.
9. CALL RECORDINGS
Calls made for:
verification authorization,
customer support,
quality assurance,
dispute resolution,
compliance,
or operational purposes
may be recorded and retained for legitimate business purposes.
Call recordings are intended to support:
audit trails,
operational transparency,
customer support,
and fraud prevention.
Access to recordings shall be reasonably restricted.
10. THIRD-PARTY SERVICE PROVIDERS
Bharosak may use third-party providers including:
verification partners,
API providers,
payment gateways,
cloud platforms,
communication providers,
analytics tools,
and operational software services.
While Bharosak aims to work with commercially reliable providers, Bharosak does not control independent third-party infrastructure or systems.
Users acknowledge that:
· certain information may be processed through third-party platforms,
· and third-party risks may exist outside Bharosak’s direct control.
11. PAYMENT SECURITY
Payments may be processed through authorized third-party payment gateways.
Bharosak does not intentionally store:
complete card details,
banking passwords,
UPI PINs,
CVV numbers,
or sensitive financial authentication credentials.
Users should never share confidential banking credentials with Bharosak representatives.
12. DATA RETENTION AND STORAGE
Information may be retained only for:
operational purposes,
consent verification,
customer support,
fraud prevention,
legal compliance,
dispute resolution,
and legitimate business requirements.
Retention periods may vary depending on operational and legal needs.
Further details are available in Bharosak’s Data Retention and Operational Policy.
13. SECURITY INCIDENT RESPONSE
In the event of suspected:
unauthorized access,
operational misuse,
data exposure,
fraud,
or security incidents
Bharosak may take reasonable actions including:
restricting access,
reviewing logs,
suspending operations,
contacting affected parties where reasonably necessary,
cooperating with lawful authorities,
and implementing corrective measures.
Bharosak does not guarantee prevention of all cyber threats, attacks, or security incidents.
14. FRAUD PREVENTION
Bharosak may monitor operational activity to:
detect suspicious behavior,
reduce fraud risks,
identify misuse,
and maintain service integrity.
Bharosak reserves the right to:
suspend requests,
reject transactions,
preserve records,
or cooperate with authorities
where unlawful or suspicious activity is reasonably suspected.
15. OPERATIONAL LIMITATIONS
While Bharosak aims to implement commercially reasonable safeguards, users acknowledge that:
no digital platform is fully secure,
no communication channel is completely risk-free,
and no security system can guarantee absolute protection.
Users use Bharosak’s services and submit information at their own discretion and risk.
16. USER RESPONSIBILITIES
Users are responsible for:
safeguarding their own devices and accounts,
submitting only necessary information,
ensuring lawful consent,
avoiding unauthorized sharing,
and using Bharosak responsibly.
Users should:
avoid sharing passwords or OTPs unnecessarily,
use secure internet connections,
and immediately report suspicious activity.
17. EMPLOYEE AND OPERATIONAL AWARENESS
Bharosak may implement reasonable operational awareness practices relating to:
confidentiality,
responsible information handling,
operational security,
communication practices,
and fraud prevention.
Access to operational information may be reviewed periodically.
18. POLICY REVIEW AND MODIFICATIONS
Bharosak reserves the right to:
revise,
update,
modify,
or replace
this Policy at any time without prior notice.
Updated versions shall become effective upon publication on the website.
Continued use of Bharosak’s services constitutes acceptance of revised policies.
19. CONTACT DETAILS
For information security concerns, users may contact:
Anvay Ventures
Brand: Bharosak
Website: https://bharosak.com/
Email: support@bharsak.com
Phone: +91-8985704717
Users are encouraged to promptly report:
suspicious activity,
unauthorized communication,
security concerns,
or suspected misuse.
20. GOVERNING LAW
This Policy shall be governed by the laws of India.
Any disputes relating to this Policy or Bharosak’s operational practices shall be subject to the jurisdiction of competent courts located in India.
21. ACKNOWLEDGEMENT
By accessing Bharosak’s website, submitting information, uploading documents, making payments, or using related services, users acknowledge that they have read, understood, and agreed to this Information Security Policy.


