VASHIX
Request Early Access
VASHIX

Photo and video verification designed for Indian enterprise.

Early AccessSecure Cloud
C2PA 2.1·Encrypted·Data Protection

Product

  • Solutions
  • How It Works
  • Trust Score
  • Book a Demo
  • ROI Calculator
  • Changelog
  • Status PageOnline

Developers

  • Documentation
  • API Reference
  • Android SDK Guide
  • C2PA 2.1 Specification

Company

  • About
  • Blog
  • DPDP Compliance
  • Contact
  • hello@vashix.com
  • Careers

Vashix is in early access. Core verification is live. Compliance certifications are in progress.

© 2026 Vashix · All rights reserved

Privacy PolicyTerms of ServiceRefund & CancellationData Processing AgreementSecurityAccount Deletion

Made in India 🇮🇳

Legal

Data Processing Agreement

Standard DPA between Vashix (Data Processor) and your organisation (Data Fiduciary) under DPDP Rules 2025, Rule 6(1)(f).

Designed for DPDP Rules 2025Rule 6(1)(f) Contract

Download Standard DPA

Ready-to-sign PDF. Covers all DPDP Rules 2025 requirements for Data Processor contracts.

Download PDFRequest Custom DPA →

1. Definitions & Roles

✓Data Fiduciary: Your organisation (the insurer / NBFC / enterprise)
✓Data Processor: Vashix
✓Data Principal: The claimant / adjuster whose photo data is captured
✓Personal Data: GPS coordinates, timestamps, device identifiers, motion sensor data, photos

2. Purpose of Processing

✓Vashix processes personal data strictly on your instructions for claims photo verification
✓Vashix determines nothing about the purpose — you do (Data Fiduciary obligation)
✓Processing limited to: capture verification, trust score generation, audit log creation

3. Security Safeguards — Rule 6

✓Rule 6(1)(a): Encryption at rest and in transit
✓Rule 6(1)(b): Role-based access control, API key scoping, adjuster isolation
✓Rule 6(1)(c): Full audit log per capture — every API call logged with timestamp, IP, user
✓Rule 6(1)(d): Redundant storage with availability targets per your service plan
✓Rule 6(1)(e): Security logs retained minimum 1 year
✓Rule 6(1)(f): This DPA constitutes the mandatory contract provision

4. Data Residency — Rule 14

✓Processing on secure cloud infrastructure
✓Zero data transfer outside India — no CDN edge in foreign jurisdiction
✓Sub-processors: cloud infrastructure provider, Cloudflare, Razorpay, Resend
✓No foreign sub-processors
✓Data residency confirmation available on request. For formal audit requirements, independent technical verification is recommended.

5. Breach Notification — Rule 7

✓Vashix detects anomalies and fires webhook within minutes
✓72-hour DPB notification deadline auto-calculated
✓Pre-filled incident report generated for Data Protection Board submission
✓Your team files the report — Vashix provides the data

6. Data Principal Rights — Rule 13

✓Erasure available via dashboard or support request
✓Cryptographic receipt generated as proof of deletion
✓Security audit logs retained per Rule 6(1)(e) even after erasure (disclosed in consent notice)
✓Access request exports available via dashboard

7. Data Retention — Rule 8

✓Retention period configurable per plan (7 / 90 / custom days)
✓Automatic hard-delete of photo data and personal metadata at expiry
✓Security logs retained 1 year minimum regardless of plan

8. Governing Law & Jurisdiction

✓Governed by Indian law
✓Jurisdiction: Courts of Mumbai, Maharashtra
✓Disputes resolved under Arbitration and Conciliation Act, 1996

Enterprise clients receive a custom DPA reviewed by our legal counsel, tailored to your organisation's compliance requirements. Contact hello@vashix.com

Legal References

DPDP Rules 2025 (Official Gazette)DPDP Act 2023 (MeitY)Data Protection Board of India