Bureau Privacy Policy | Data Security & Privacy Guidelines

How Bureau Protects Your Personal Data

Privacy Policy
Updated 28-Jan-2026

1. Introduction:

Bureau, Inc., BureauID India Private Limited and Junoon Tech Pte. Ltd. (either together or as applicable “Bureau”, “we”, “us”, or “our”) provide various offerings related to identity verification, compliance and fraud prevention solutions, including software, technology, analytics, or any other services made available by Bureau to its customers (“Customers”) (“Services”) via mobile or web applications, application programming interface (APIs), software development kits (SDKs), or any other access channels (“Platform”).

This Privacy Policy (“Policy”) explains how we collect, use, share, transfer, and protect personal data (“Personal Data”) across the jurisdictions and regions where we operate, including India, the United States of America, Singapore, the Philippines, Indonesia, MEA, and the European Union/EEA.

This Policy applies to Personal Data we collect:

If you are an end-user of one of our Customers, your primary relationship is with that Customer. In those cases, Bureau acts as a Processor on behalf of that Customer (the controller). Where we determine the purpose and means of processing, Bureau is the Controller. For the purposes of this Policy, Controller / Processor is as defined under applicable data protection laws. Bureau may act as either depending on the engagement and the jurisdiction.

This Policy supports the implementation of ISO/IEC 27001:2022 Annex A controls including 5.34 (Privacy and Protection of PII), 5.31 (Legal, Statutory and Regulatory Requirements), 5.33 (Protection of Records), and 8.10 (Information Deletion).

2. Scope and Applicability

This Policy applies to Personal Data we collect:

Bureau uses your information to deliver and improve its Services, particularly in verifying identity and preventing fraud. We analyze data to detect patterns of fraudulent activity and provide our customers with insights to help them meet operational and compliance requirements.

If you are an end-user of one of our Customers, your main relationship is with that Customer. In those cases, Bureau acts as a Processor on behalf of that Customer (the Controller). Where we determine the purpose and means of processing, Bureau is the Controller. In cases where Bureau operates as a Processor, while providing Personal Data directly to us is not mandatory, the absence of such information may restrict our ability to perform the Services on behalf of our Customers. For the purposes of this Privacy Policy, Controller / Processor as defined under applicable data protection laws. Bureau may act as either depending on the engagement and the jurisdiction.

3. Categories of Data We Collect

Identity and contact data

Government issued IDs

Biometrics

Payment and transaction Information

Device and technical data

Behavioural and usage data

Derived data:

Where permitted by law, we may obtain additional information about you from third-party providers or partners. This may include consumer reporting agencies, fraud prevention services, data brokers, government databases, and marketing or analytics providers, and may be combined with the information we already hold about you.

4. How We Use Your Personal Data

We use the Personal Data we collect to:

5. Legal Bases for Processing

We process personal and sensitive data on the following bases:

6. How We Collect Data

7. Sensitive Data and Biometrics

We process biometrics and other sensitive data only when required for the Service (e.g., eKYC), we have a lawful basis (consent or legal obligation), and strict safeguards are in place (encryption, access controls).

8. Sharing and Recipients

We may share Personal Data with:

9. International Transfers

Bureau operates globally, with infrastructure in India, Singapore, and the US. Personal Data may be transferred across borders. For EU/EEA transfers, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions. For other countries (India, Indonesia, Philippines, Singapore, US), we apply contractual and technical safeguards consistent with local laws. We may update our infrastructure location from time to time. Transfers from India are conducted in accordance with the Digital Personal Data Protection Act, 2023 and any government-notified restrictions on cross-border transfers.

10. Data Subject Rights

Depending on your jurisdiction, you may have rights to:

When you exercise any of the above rights, we may require you to submit additional information or Personal Data to verify your identity. Requests to exercise the above rights may be made through our Data Protection Officer (DPO) or the grievance channel as set out in Section 15 of this Policy.

11. Data Retention

Personal Data is retained in accordance with BI-PRIV-POL-002 – Data Retention and Deletion Policy, which defines category-wise retention periods, legal basis, ownership, and secure deletion mechanisms.

Where Bureau acts as a Processor, retention is governed by Customer instructions and applicable legal requirements.

Legal hold, regulatory preservation, or contractual obligations may override standard retention periods.

12. Security

We use organizational, technical, and physical safeguards, including encryption in transit and at rest, access control and multi-factor authentication, regular audits and penetration testing, and incident response planning. We regularly seek new ways to further enhance the security of our Services.

13. Cookies

We use cookies and similar technologies to improve your experience, secure our Services, and understand how they are used. Some cookies are essential for the operation of our Services, while others help us analyze trends, personalize content, and deliver relevant communications. You can manage or disable cookies in your browser settings, but certain features or Services may not work as intended if cookies are disabled.

14. Breach Notification

We will notify Customers, regulators, and (where required) affected individuals of data breaches as soon as we become aware in line with applicable laws (e.g., CERT-IN 6-hour rule, GDPR 72-hour rule).

All security incidents are managed in accordance with BI-IR-POL-001 – Information Security Incident Response Policy.

15. Contact and DPO

To exercise your rights or raise a concern,

contact: dpo@bureau.id
Name: Dayanand Kumbhar
Email: dayanand@bureau.id

16. Children’s Privacy

Our Services are not directed to children under applicable age limits (13 – 16 years, depending on applicable laws). If you learn that your child has shared Personal Data with us without your consent, please contact us (see Section 15 of this Policy) so we can remove it promptly.

17. Changes

We may update this Policy to reflect changes in our Services, legal requirements, or business practices. Updates take effect once posted on our website, unless the law requires otherwise. By continuing to use our Services or accessing the Platform after an update, you accept the revised Policy. We encourage you to review it regularly. If any change significantly affects your rights, we will provide additional notice, such as by email or a clear notice on our website.

18. Reference

18.1 Internal BI-ISMS-POL-001 – Information Security Management Policy