Privacy & Data Protection Policy
Effective Date: 18 August 2026
Last Updated: 18 August 2026
PrintAPM respects user confidentiality. This Privacy Policy details our data collection, processing, and strict automated-deletion lifecycles under the Digital Personal Data Protection (DPDP) Act, 2023 and IT Rules, 2011.
1. Data We Process
- User Contact Data: Mobile Number and/or Email Address collected for receipt generation, transaction verification, and support communication.
- Transactional Metadata: Order ID, Payment Gateway Reference ID, timestamp, kiosk identifier, print parameters (page count, color mode), and payment status.
- Technical Logs: Device IP address, browser user-agent, operating system, and system failure logs recorded for fraud prevention and security audits.
- Uploaded Files: Digital files submitted voluntarily by you to fulfill printing commands.
2. Zero-Monetization & Document Privacy Guarantees
- No Commercial Exploitation: PrintAPM will NEVER sell, rent, trade, or share your personal documents with third-party advertisers, data brokers, or marketing platforms.
- Zero AI Training: Uploaded document contents are never utilized, scanned, or processed to train public or proprietary Large Language Models (LLMs) or Machine Learning algorithms.
- Data Minimization: Kiosk operators and platform administrators do not manually inspect or read uploaded files unless specifically authorized by the user for technical troubleshooting.
3. File Storage & Automated Purge Lifecycle
- Encrypted Transmission: All document uploads and downstream transmissions to kiosks use 256-bit SSL/TLS encryption.
- Immediate Deletion upon Print: Once the kiosk hardware successfully confirms print completion, the digital file is immediately scheduled for automated permanent deletion from active file storage.
- Unclaimed File Purge: If a print order is unpaid or if a Print Code expires (15 minutes), the associated digital document is permanently scrubbed within 24 to 48 hours.
- Financial & Audit Logs: Non-file transaction records (Order IDs, timestamps, amounts, refund trails) are retained as required by Indian accounting and taxation regulations.
4. Third-Party Disclosures
Data is shared strictly on a need-to-know basis with:
- Payment Aggregators: Authorized RBI-licensed payment gateways (e.g., Razorpay, Cashfree, Paytm).
- Cloud Infrastructure Providers: ISO/PCI-DSS certified cloud servers located in Indian data regions.
- Statutory Authorities: Law enforcement agencies only upon receipt of a lawful order issued under Section 69 or 91 of the Code of Criminal Procedure / IT Act.
