Enrich

Privacy Policy

Effective 9 September 2026 · Version 2026-09-09

Enrich performs verification checks on people and businesses at our customers’ request. That means we handle two kinds of personal data under two different responsibilities: data about the people who use our product, for which we answer directly, and data about the people they check, for which our customer answers and we act on their instructions. This policy is organised around that distinction. If you were checked by one of our customers, Section 9 is written for you.

1.Who this policy covers

This policy explains how Timble Technologies Private Limited (Enrich, we) handles personal data in connection with the Enrich platform, API and website (the Service). It covers two distinct groups, and our role differs for each.

Account Users — people who create or use a Enrich workspace on behalf of a customer organisation. For account data we are the data controller (in India, the Data Fiduciary). Sections 2, 3 and 6 to 15 describe how we treat it.

Verification Subjects — people and businesses a customer asks the Service to check. We process this data only on the customer’s documented instructions, to carry out the checks they request. The customer is the controller of that data and we are its processor. If you are a Verification Subject, the organisation that checked you decided why your data was processed and is the right first point of contact. Section 4 explains what we do with subject data, and Section 9 explains how to exercise your rights and how we help you reach the right party.

Many of our customers are regulated financial institutions with their own privacy notices and statutory obligations. Nothing in this policy displaces those; where a customer has told you how it processes your data, that notice governs its processing and this one governs ours.

2.Information we collect about Account Users

Information you give us

  • Account details: name, work email address, organisation name, password (stored only as a salted hash — we never hold the password itself), and role in the workspace.
  • Billing details for your organisation: legal name, billing address and tax identifiers such as a GSTIN, which appear on invoices. Card and bank details are entered directly with our payment processor and are not stored by us.
  • Onboarding information: your regulatory status and intended use cases, where we ask for them.
  • Preferences: interface theme, timezone and country, read from your browser at sign-up to set your workspace’s reporting clock.
  • Your acceptance of our Terms: when you accepted, and which version.
  • Anything you send us in support or security correspondence.

Information we collect automatically

  • Security and access records: sign-in attempts and outcomes, originating IP address, session activity, two-factor events, password resets.
  • Audit records: administrative actions in your workspace — invitations, role changes, API key creation and revocation, approvals of runs — attributed to the user who took them.
  • Usage records: which checks ran, when, by whom, at what credit cost, and API request logs including timing and outcome. These are also your billing record and part of your audit trail.
  • Technical information needed to serve you: browser and device type, and pages requested.

We do not collect precise location, do not use advertising identifiers, and run no third-party analytics or tracking scripts on the Service.

3.How we use Account User data

We use it to:

  • create and secure accounts, authenticate users, and detect and prevent unauthorised access, fraud and abuse;
  • provide the Service, including maintaining your workspace, performing requested checks and delivering results;
  • bill you, issue invoices, collect payment and keep the records tax law requires;
  • maintain the audit trail that lets you and your regulator see what was done, by whom and when;
  • respond to support and security correspondence, and notify you about your account, your runs, incidents and changes to these documents;
  • operate, secure and improve the Service using aggregated, de-identified operational information;
  • comply with law, respond to lawful requests from courts, regulators and law enforcement, and establish or defend legal claims.

Where the law requires a legal basis to be stated, we rely on the contract with you or your organisation, our legitimate interests in operating a secure and reliable service, our legal obligations, and — for optional communications — consent, which you may withdraw at any time.

We do not sell personal data. We do not send marketing to Account Users without consent, and any such message carries a means to opt out.

4.Verification Subject data

When a customer runs a check, the Service processes the personal data the customer submits about the subject together with the data returned by the sources consulted. Depending on the checks requested this can include:

  • identifiers and documents: name, date of birth, PAN, Aadhaar, voter ID, passport, driving licence, Emirates ID, Social Security number, and business identifiers such as CIN, GSTIN or EIN;
  • contact details and their history: mobile numbers, carrier information, email addresses, current and previous addresses;
  • employment and income signals: provident fund and UAN records, employer details, tenure, and estimates derived from them;
  • financial information: credit reports and scores, bank account and UPI verification, existing facilities and repayment history;
  • public records: court and litigation records, regulatory watchlists, sanctions lists, company filings and directorships, vehicle registrations;
  • digital footprint: publicly available social and professional profile information.

What we do with it. We use subject data solely to perform the checks the customer requested, assemble the resulting report, bill the customer for the checks that ran, and maintain the audit trail evidencing what was done. We do not use subject data for any purpose of our own, do not build profiles of subjects across customers, do not sell it, and do not use it to train models. Each customer’s data is segregated from every other customer’s.

Aadhaar. No report the Service generates displays a full Aadhaar number — Aadhaar is always rendered masked to its last four digits. A small number of checks require an Aadhaar number as their input in order to run, and where that is so the number is transmitted to the data provider performing that check and to no one else. Customers are required to use a masked Aadhaar or Virtual ID wherever a check accepts one.

Where it comes from. Results are obtained from licensed verification data providers and from public and government registries, selected for the market the subject belongs to. Each provider receives only the identifiers necessary for the specific check, under a written agreement restricting its use of them. We assess providers for security and regulatory suitability before engaging them, and the current list is available to customers on request under confidentiality.

Short-term caching. To avoid charging a customer twice for an identical lookup and to reduce unnecessary requests to sources, the Service retains the raw response to a check for a short period — currently up to 24 hours — and reuses it if the identical check is requested again within that window. Entries are keyed by a one-way hash of the subject identifier so that a given subject’s entries can be located and erased on request (see Section 9). After the window the entry expires and is removed.

Workspace memory. The Service can retain, within a single customer’s workspace, how that customer prefers work to be done — report formats, commonly requested checks, preferred wording. This is scoped to the workspace, never shared between customers, and filtered so that it cannot retain Verification Subject identifiers. Workspace administrators can review and purge it, and it is deleted when the workspace is deleted.

5.How AI is used

Enrich uses large language models to plan which checks a request requires, interpret the results, and draft the report. Instructions, uploaded documents and check results are transmitted to our AI model provider for that purpose.

Our model providers are enterprise providers engaged on commercial terms that prohibit them from using our inputs or outputs to train or improve their models, and we do not train models on customer or subject data ourselves. Inference is stateless: the provider does not retain conversation history for us between requests beyond any short-lived processing its terms permit. We assess model providers for security and contractual suitability before engaging them, and will identify the current provider to customers on request under confidentiality.

Reports are assessments, not decisions. The Service is built so that a human reviews and approves consequential steps, and our Terms require customers not to act on a report alone where a decision would significantly affect a person. Where a customer deploys the Service within an automated decision process, governance of that process — including any model risk management its regulator requires — remains the customer’s responsibility.

6.Who we share data with

We share personal data only as set out below.

Sub-processors, who process it on our behalf and on our instructions under written terms requiring confidentiality, appropriate security and equivalent data-protection obligations. We describe them by category rather than by name, because publishing a supply chain is itself a security exposure; the current named list, with locations, goes to customers on request under confidentiality, and is provided as a matter of course during a vendor-risk review.

  • Cloud infrastructureHosting, database, and encrypted storage of reports. Location: India.
  • AI model inferencePlanning a run, interpreting results and drafting the report. Location: Contracted regions; see Privacy §5.
  • Verification data providersPerforming the individual checks a run requires. Location: The market the subject belongs to.
  • Payment processingTaking payment for credits and issuing invoices. Location: India.
  • CommunicationsTransactional email — verification codes, password resets, service notices. Location: Contracted regions.
  • Bot protectionDistinguishing human from automated traffic on authentication pages. Location: Global.

We remain responsible for our sub-processors’ acts and omissions, give customers reasonable notice before a new or replacement sub-processor begins processing their data, and handle objections as our Terms describe.

The customer who requested a check receives the results relating to the subjects they checked. Within a workspace, Authorised Users see what their role permits.

Regulators, courts and law enforcement. We may disclose data where required by law, regulation, legal process or a binding governmental or regulatory request; to enforce our Terms; or to protect the rights, safety or property of any person. Where a customer is a regulated entity, its regulator and statutory auditors may inspect records relating to the services provided to it. Where we are lawfully able to, we will notify the affected customer before disclosing.

Professional advisers — auditors, lawyers and insurers — bound by professional confidentiality.

Business transfers. If we are involved in a merger, acquisition, financing or sale of assets, personal data may transfer as part of that transaction, subject to this policy and to any notification a customer’s regulator requires.

We do not share personal data with advertisers or data brokers.

7.Where data is stored and processed

The Service is hosted in India, and Customer Data — accounts, workspaces, run records, reports and audit logs — is stored there. Security and access logs are retained within India in accordance with the CERT-In directions of April 2022.

Some processing necessarily occurs elsewhere: checks on subjects in the United States, Canada and the United Arab Emirates are routed to data providers in those markets, and transactional email and AI inference may be performed in the regions our providers operate. Section 6 states the location of each sub-processor category.

Where personal data is transferred outside the country in which it was collected, we do so in accordance with applicable law — including any restriction the Central Government notifies under India’s Digital Personal Data Protection Act 2023 — and under contractual protections binding the recipient. Customers with data-residency requirements arising from their own regulation should raise them at onboarding so that we can confirm what we can support.

8.How long we keep data

We keep personal data no longer than needed for the purposes above.

  • Account data — while the account is active, and for 30 days after closure so the organisation can export its records, after which it is deleted.
  • Reports, run records and chat history — for as long as the customer keeps them. Customers may delete individual conversations and reports at any time, and everything is deleted 30 days after the workspace closes.
  • Raw check responses — up to 24 hours, as Section 4 describes.
  • Security and access logs365 days, to investigate incidents and abuse and to meet the CERT-In log-retention requirement.
  • Billing and tax records8 years, as company and tax law require.

Customers with statutory record-keeping obligations. If you are a reporting entity under the Prevention of Money-Laundering Act 2002 or subject to comparable rules, you may need audit records retained for longer than the periods above — typically five years from the end of the relationship or transaction. We support longer, configurable retention for such customers under a written agreement; tell us at onboarding rather than relying on the defaults.

Deleted data may persist in encrypted backups for a limited period until those backups expire on their ordinary cycle, and we may retain data longer where the law requires or where it is needed for a legal claim or a regulatory investigation.

9.Your rights

Depending on where you live you may have rights to access the personal data we hold about you, to have it corrected or erased, to restrict or object to its processing, to receive a copy in portable form, to withdraw consent, to nominate someone to exercise your rights on your behalf, and to complain to a supervisory authority. These include rights under India’s Digital Personal Data Protection Act 2023, applicable United States state privacy laws, Canada’s PIPEDA and the UAE’s Personal Data Protection Law.

If you are an Account User, write to support@timbletech.com or use your workspace settings. We will verify your identity and respond within the time the applicable law allows.

If you are a Verification Subject, the organisation that checked you controls that data and is responsible for responding to you; we are contractually obliged to assist them, and we will. If you do not know which organisation checked you, or cannot reach them, write to support@timbletech.com with enough detail to identify the check. We will either put you in touch with the customer or, where the law requires us to act directly, act. We can locate and erase cached check responses for a given identifier and will do so on a valid request.

If you believe a source record about you is inaccurate, the correction must be made at the source — a credit bureau, registry or government database — and we will identify the source of a finding so that you can pursue it there. Where the source is a credit information company, that company’s statutory dispute process applies.

You will not be disadvantaged for exercising any of these rights.

10.Cookies and local storage

We use a small number of cookies and browser storage items, all to make the Service work.

  • enrich_session (cookie, strictly necessary) — keeps you signed in. Marked HttpOnly, Secure and SameSite so that scripts cannot read it, and it expires with your session.
  • Interface preferences (browser local storage) — your light or dark theme, whether the sidebar is collapsed, a cached copy of your own profile so the interface can render before the server responds, and flags recording that you have seen the first-visit welcome and the billing introduction. None of this leaves your browser.
  • Bot protection — on sign-in and sign-up, our bot-protection provider may set cookies to distinguish human from automated traffic.
  • Payment — when you open the payment window, our payment processor’s checkout loads and may set its own cookies, governed by that processor’s privacy notice.

We use no advertising, analytics or cross-site tracking cookies, so there is nothing to opt out of beyond the strictly necessary items above. You may clear local storage from your browser at any time; doing so signs you out and resets your preferences.

11.Security

We protect personal data with technical and organisational measures appropriate to its sensitivity, including: encryption in transit for all connections and at rest for stored reports, credentials and secrets; passwords stored as salted hashes; API keys and third-party credentials stored hashed or encrypted; optional two-factor authentication; role-based access within workspaces; segregation of each customer’s data; account lockout after repeated failed sign-ins; bot protection on authentication pages; audit logging of administrative and security-relevant events; and least-privilege, logged access to production systems by personnel bound by confidentiality and subject to security training.

Section 13 of our Terms sets out these commitments in the form a customer’s vendor-risk function will need, together with our position on certification and security questionnaires.

No system is perfectly secure. Section 12 explains what happens if something goes wrong.

12.Security incidents and notification

We maintain a documented incident response process covering detection, containment, investigation, notification and remediation, and we review it after any significant incident.

On confirming a personal data breach we will notify affected customers without undue delay and in any event within twenty-four hours, and will provide the information reasonably necessary for them to meet their own reporting obligations — including any obligation on a regulated entity to report to its regulator within six hours. We will notify the Data Protection Board of India, CERT-In and any other authority as and when the applicable law requires, and will notify affected individuals directly where the law requires that or where we consider it appropriate.

To report a suspected vulnerability or incident, write to support@timbletech.com. We investigate all good-faith reports and will not pursue action against researchers who report responsibly and do not access, alter or exfiltrate data belonging to others.

13.Children

The Service is for business use by adults. We do not knowingly create accounts for anyone under 18, and customers must not use the Service to check a child except where the law expressly permits it and with the consent the law requires — under India’s Digital Personal Data Protection Act 2023 that means verifiable consent of a parent or lawful guardian. If you believe we hold a child’s data in breach of this, contact us and we will act promptly.

14.Changes to this policy

We may update this policy. The current version and its effective date appear at the head of this page. For material changes we will give notice by email or in the Service before they take effect, and customers who are regulated entities will receive notice sufficient to allow their own change assessment. Continuing to use the Service after the effective date means you accept the updated policy.

15.Grievance redressal and contact

Timble Technologies Private Limited
Pillar Number 181, Shop No. 2, 2nd Floor, Khasra No. 541 & 542, near Arjan Garh Metro Station, Aya Nagar, New Delhi, Delhi 110047
CIN: U80902DL2016PTC305288

Privacy and data-protection requests: support@timbletech.com
Security reports: support@timbletech.com
General support: support@timbletech.com

Grievance Officer, under the Digital Personal Data Protection Act 2023 and the Information Technology Rules. Write to support@timbletech.com marked for the attention of the Grievance Officer. We aim to acknowledge within 3 working days and to resolve within 30 days.

If you remain dissatisfied you may complain to the Data Protection Board of India, or to the supervisory authority where you live.

This policy is governed by the laws of India.