Privacy Policy
Effective Date: June 11, 2026
Last Updated: June 11, 2026
1. Overview
BINA AI Pvt Ltd ("we", "us", "our") operates the Milne Se Pehle platform at milnesepehle.in. This Privacy Policy explains how we collect, use, store, share, and protect your personal data in accordance with the Information Technology Act, 2000, the IT (SPDI) Rules, 2011, and other applicable Indian data protection laws including the Digital Personal Data Protection Act, 2023 to the extent in force.
By using the platform, you consent to the practices described in this Policy. If you do not agree, please discontinue use immediately.
2. Personal Data We Collect
2.1 Data You Provide Directly
- Full name as on Aadhaar.
- Mobile number registered with Aadhaar.
- Consent confirmation via OTP.
- Payment information processed through third-party gateways (full card details are not stored by us).
- Correction request details and supporting evidence submitted via email.
2.2 Data Collected About Subjects (Others Flow)
When an Initiating User enters the name and mobile number of a Subject, the following is collected about the Subject:
- Name and mobile number as entered by the Initiating User.
- OTP confirmation result, indicating the Subject's identity and consent.
- Basic identity confirmation result from official sources (partial name, state, Aadhaar confirmed status).
Data about the Subject is collected only after OTP confirmation. If the OTP is not confirmed, the name and mobile number entered are deleted within 24 hours.
2.3 Data Retrieved from Official Sources
Upon explicit consent via OTP, we retrieve the following:
- Aadhaar identity verification result from UIDAI. Aadhaar numbers are never stored. Only the result (confirmed / not confirmed) is retained.
- PAN details from official government sources.
- ITR filing data from the Income Tax Department.
- Criminal and FIR records from the eCourts portal.
- Credit score, active loan, and repayment history from authorised credit bureaus. Used solely for certificate issuance, not for credit assessment, lending, or scoring purposes.
- Employment history from EPFO/UAN records.
- Educational qualification data from DigiLocker, NTA, and issuing universities.
- Physical address details from field visits (Bandhan plan only).
- Professional reference information collected during verification.
2.4 Data Collected Automatically
- IP address and device information.
- Browser type, operating system, and session duration.
- Pages visited, clicks, and navigation patterns.
- Certificate access logs including date, time, and mobile number of viewer.
3. How We Use Your Personal Data
- To conduct verification and issue your certificate.
- To enable certificate sharing with specified individuals.
- To process payments securely.
- To communicate regarding verification status, certificate, and account updates via WhatsApp, SMS, email, and phone.
- To send promotional communications where consent has been given.
- To resolve disputes, process correction requests, and handle grievances.
- To comply with legal obligations under applicable Indian law.
- To improve the platform using anonymised and aggregated data only.
We do not use your personal data to train or improve artificial intelligence or machine learning models. We do not use your personal data for automated decision-making that produces legal or similarly significant effects without human oversight.
4. Sensitive Personal Data and Information (SPDI)
Financial data, identity documents, and criminal record information constitute SPDI under the SPDI Rules, 2011. We handle all SPDI with the following protections:
- Collected only with explicit written consent obtained via OTP verification.
- Used only for the verification purpose for which it was collected.
- Not transferred to third parties except as necessary for authorised verification and payment processing.
- Stored with encryption standards compliant with applicable Indian law, including IS/ISO 27001 or equivalent industry standards.
- Aadhaar numbers are not stored at any point.
5. Data Security and Limitation of Liability for Breaches
We implement industry-standard technical and organisational security measures to protect your personal data, including:
- Encryption of data in transit using TLS/SSL protocols.
- Encryption of sensitive data at rest.
- OTP-based authentication for all account actions.
- Access controls on a strict need-to-know basis.
- Regular security assessments and penetration testing.
- Compliance with IS/ISO 27001 or equivalent applicable information security standards.
The Company shall not be held liable for any data breach, unauthorised access, or data loss where such incident occurs despite the Company having implemented reasonable security practices and procedures as required under Rule 8 of the IT (SPDI) Rules, 2011. Liability shall arise only in cases of gross negligence or wilful misconduct by the Company.
In the event of a personal data breach, we will notify affected users and the relevant authority within 72 hours of becoming aware of the breach where technically feasible, in accordance with applicable law.
6. How We Share Your Data
We do not sell, rent, or trade your personal data. We share only as follows:
6.1 Authorised Verification Partners
- Official Government of India APIs and portals including UIDAI, Income Tax Department, eCourts, EPFO, DigiLocker/NTA.
- Authorised private credit bureaus and data vendors licensed by the RBI or relevant authorities.
- Authorised field agents for physical address verification (Bandhan plan only), bound by confidentiality obligations.
6.2 Payment Processors
Payment information is shared with authorised third-party gateways. We do not store full card or account details.
6.3 Certificate Access
Your certificate is accessible only to you and to individuals to whom you explicitly grant access. You may revoke access at any time.
6.4 Legal Requirements
We may disclose personal data if required by law, court order, or government authority, or to protect the rights, property, or safety of the Company, its users, or the public.
7. Data Retention
- Verification data and certificate remain active for as long as your account is active or until deletion is requested.
- Accounts not accessed for 2 continuous years will have their data securely deleted unless a deletion request was submitted earlier.
- Unconfirmed Subject OTP data is deleted within 24 hours.
- Server and access logs (IP, session, certificate access) are retained for a maximum of 1 year then permanently deleted.
- Anonymised and aggregated data (no personally identifiable information) may be retained indefinitely.
- Data required for legal compliance including tax and financial records is retained for the period mandated by law.
8. Your Rights
8.1 Right to Access
Request a summary of personal data we hold by writing to support@milnesepehle.in. Response within 30 days.
8.2 Right to Correction
Raise a correction request at support@milnesepehle.in with supporting evidence. Response within 7 business days.
8.3 Right to Deletion
Request deletion by writing to support@milnesepehle.in. Data deleted within 7 calendar days subject to legal retention requirements. Deletion results in permanent deactivation of your certificate.
8.4 Right to Withdraw Consent to Communications
Withdraw consent to promotional communications at any time by writing to support@milnesepehle.in. Withdrawal processed within 7 business days. Transactional communications necessary for account functioning are not affected. An in-app withdrawal option is under development; the email mechanism described is the current method.
8.5 Right to Nominate
Under the Digital Personal Data Protection Act, 2023, you may nominate another individual to exercise your data rights in the event of your death or incapacity. To register a nominee, write to support@milnesepehle.in with the nominee's name and contact details.
9. Third-Party Communications Platforms
We use WhatsApp (Meta Platforms Inc.) for transactional and promotional communications. Communications sent via WhatsApp are subject to WhatsApp's own terms of service and privacy policy. The Company is not responsible for Meta's data practices. By consenting to WhatsApp communications, you accept that messages are transmitted via Meta's infrastructure.
10. Public Content and Social Media
Content posted by users or third parties about the Company or its services on social media, review platforms, news outlets, blogs, or any other public medium does not represent the official views, policies, or communications of BINA AI Pvt Ltd. The Company does not monitor, endorse, verify, or take responsibility for third-party public content.
The Company reserves the right to take legal remedies against any person who publishes false, defamatory, or malicious content about the Company, its platform, its directors, employees, or agents.
11. Cookies and Tracking
We use cookies to maintain session state, understand navigation patterns, and deliver a secure experience. We do not use third-party advertising or behavioural tracking cookies. You may control cookie settings through your browser. Disabling certain cookies may affect platform functionality.
12. Minors
The platform is intended for individuals entering or considering matrimonial arrangements. We do not knowingly collect personal data from minors. The registered holder of a mobile number used to access the platform is responsible for all activity conducted through that number. If we become aware that a minor's data has been collected without appropriate consent, we will delete it promptly.
13. Third-Party Links
The platform may link to third-party websites including payment gateways and government portals. We are not responsible for their privacy practices. We encourage independent review of their policies.
14. Data Localisation
All personal data is stored on servers within India. We do not transfer personal data outside India except as required for API calls to government or authorised systems, and only in compliance with applicable law.
15. Grievance Officer
Name: Sampath Kolanukonda
Designation: Co-founder and Grievance Officer, BINA AI Pvt Ltd
Email: support@milnesepehle.in
Platform: milnesepehle.in
Response Time: Within 30 days of receipt of grievance.
16. Governing Law
This Privacy Policy is governed by the laws of India. Disputes shall be subject to the exclusive jurisdiction of the courts in Dehradun, Uttarakhand, India.
17. Amendments
We may update this Privacy Policy at any time. The updated Policy will be posted on milnesepehle.in with the revised effective date. Continued use constitutes acceptance.
18. Contact Us
BINA AI Pvt Ltd
Platform: milnesepehle.in
Email: support@milnesepehle.in
Jurisdiction: Dehradun, Uttarakhand, India
Prepared in compliance with: Information Technology Act, 2000; IT (SPDI) Rules, 2011; Aadhaar Act, 2016; Credit Information Companies (Regulation) Act, 2005; Digital Personal Data Protection Act, 2023 (to the extent in force). Provisions under DPDPA will be updated upon enforcement of subordinate rules.
BINA AI Pvt Ltd · milnesepehle.in · support@milnesepehle.in