Version 1.3 · Last updated 31 August 2026
SafePik Private Limited ("SafePik", "we") operates SafePik Onboard, software that private security agencies use to record and verify the guards they employ.
The service has three parts: the Onboard app (Android, used by an agency's
enrolment officers), the agency portal at safepik.org/onboard
(used by agency owners), and an internal console used by SafePik staff to
support agencies.
SafePik does not decide what data is collected about a guard, or why. The agency that employs the guard decides, because the law places the verification duty on the agency.
Under the Digital Personal Data Protection Act, 2023:
If you are a guard, your relationship is with the agency that employs you. Section 9 explains how to reach both.
Under section 10(1)(c) of the Private Security Agencies (Regulation) Act, 2005, an agency may not employ a person as a security guard unless their character and antecedents have been verified as the State Government prescribes. Verification is a legal precondition to employment. An agency employing an unverified guard risks a fine and its licence.
The data in section 4 is collected for these purposes and no others:
We do not use this data for advertising, profiling, credit scoring, or automated decision-making. We do not sell it. There is no advertising in the app.
Fields marked ▸ are optional — a guard who does not provide them can still be enrolled.
Identity and personal details — name (first, middle, last), father's name, mother's name ▸, guardian's name ▸, spouse's name ▸, date of birth, place of birth, gender, mobile number ▸, email address ▸, educational qualification ▸, role.
Physical description ▸ — height, build, complexion, hair type, eye type, languages spoken, identification marks. Required by the verification form the agency submits.
Government identifiers ▸ — Aadhaar number, PAN number, bank account number.
Addresses — permanent and current (house number ▸, street ▸, locality ▸, village or town, tehsil ▸, district, State, police station, PIN code ▸), previous address ▸, length of residence ▸, and landlord's details ▸ where the guard rents.
Family and references ▸ — relatives' and guarantors' names, relationships, contact numbers and addresses.
Employment history ▸ — previous employer's name, address, contact details, the guard's role and dates.
Declaration regarding criminal proceedings — whether there is any criminal record, conviction, or pending criminal proceeding against the guard or any member of the guard's family, anywhere in India, and details where the answer is yes. Asked because the verification form the agency submits asks it.
Documents and images — a photograph of the guard captured live on the device camera at the enrolment (the app does not permit a gallery image for this); the guard's signature; and scans of supporting documents ▸ — identity proof, address proof, educational certificates, bank challan.
Record of consent — the exact text shown to the guard, its version, the language, and the time of acceptance. This cannot be altered afterwards by anyone, including SafePik.
Evidence the enrolment took place — GPS coordinates, date and time, and a device identifier recorded at capture. This exists so the agency can establish that an officer physically met the guard.
Data about agency staff — for owners and officers: name, father's name, mobile number, email address, and a record of their actions in the system.
We do not collect fingerprints or any other biometric measurement.
Before anything in section 4 is recorded, the app shows the guard a consent notice in English or Hindi and requires acceptance.
Withdrawal. A guard may withdraw consent at any time through the employing agency, or by contacting us at privacy@safepik.org. Section 9 explains what follows, including what cannot be undone.
Not the police. SafePik does not submit anything to any police force and is not a party to the verification application. The agency applies for verification itself, using its own channels; what it discloses, and to whom, is the agency's action and its responsibility.
The employing agency. The agency sees the complete record of every guard it employs.
SafePik staff. A small number of personnel can access agency records to provide support. Every access and every change is recorded with the person's identity, the time, and — for changes — a written reason.
Service providers. Each is bound by contract and processes only on our instructions.
We do not share personal data with advertisers, data brokers, or any third party for their own commercial use.
Legal disclosure. We may disclose data where required by law or a lawful authority acting within its powers. Where permitted, we will tell the agency first.
7.1 Guard records, documents and images are stored in Google Cloud's Delhi region (asia-south2), in India.
7.2 Application logs are stored in the same Delhi region.
One exception we cannot remove: Google maintains a global record of administrative actions performed on our cloud projects — for example, a SafePik engineer changing a configuration setting. Google does not offer this record in any single region. It contains no guard data, no agency data, and no record of what an agency's staff do in the product.
7.3 Traffic routing and the internet edge. Our web portals are reached through Cloudflare, which routes and protects the traffic. Cloudflare operates a global network, so a request may pass through infrastructure outside India while in transit. Cloudflare does not store guard records; it forwards requests to our servers in India.
For the agency portal at safepik.org/onboard — the portal agency owners and enrolment officers use — Cloudflare retains no record of individual requests.
For our internal console at admin.safepik.org, used only by SafePik staff, Cloudflare retains request records for diagnostic purposes. These contain the web addresses SafePik's own staff visited, which include internal record identifiers. They contain no guard's name, identity number, photograph or document, and they are not generated by anything an agency or a guard does. This is SafePik's own operational data, and it is held outside India.
Our public website uses Cloudflare Web Analytics, which counts page views in aggregate. It sets no cookies and does not track visitors across websites.
7.4 Data held on the enrolment officer's device.
When an enrolment officer enrols you, your information is saved on their device so the enrolment can be completed without a network connection. This includes the details you provide, the photographs and documents captured during enrolment, and your signature.
This copy is temporary. Once our servers confirm they have received your enrolment, the documents and photographs are deleted from the device first, and then the record itself. The app confirms receipt with our servers directly before deleting anything, so an enrolment is never removed on the assumption that it was sent. The officer continues to see your enrolment in the app afterwards, because it is then shown from our servers rather than from their device.
There is no fixed retention period, because retention is not time-based. Deletion happens as soon as receipt is confirmed — usually within moments of submission, or when the device next has a connection if it was offline at the time.
An enrolment that has not reached our servers is not deleted. If submission fails, the record and its documents remain on the device and are retried automatically. This is deliberate: that copy is the only one in existence, and deleting it would mean asking you to repeat the enrolment. Such a record stays on the device until it is successfully submitted.
Data on the device is not included in cloud backups, and is excluded from device-to-device transfer where the device manufacturer permits this to be controlled.
| Data | Retained for |
|---|---|
| Guard records, documents and images (our servers) | The employing agency's active account, plus six months after closure |
| Copies on the officer's device | Until the record is confirmed on our servers — see 7.4 |
| Record of consent | The same period as the record it belongs to |
| Record of who changed what | The same period as the record it belongs to |
| Technical logs | 30 days |
An agency may ask us to delete a guard's record sooner. See section 9.
Before erasing a record we will notify the agency at least 48 hours in advance, as the DPDP Rules, 2025 require.
Under the DPDP Act you have the right to know what data of yours is processed and by whom; to correct what is inaccurate and complete what is incomplete; to erase data no longer needed for its purpose; to nominate another person to exercise these rights on death or incapacity; and to complain.
How to exercise them: https://safepik.org/data-deletion
If you are a guard, contact the agency that employs you — it is the Data Fiduciary and it decides. If you cannot reach them, contact us at privacy@safepik.org and we will identify the agency and pass your request on.
Our timelines. We acknowledge a request within 3 working days and complete it within 15 days of the agency instructing us.
We will respond within 7 days. You may also complain to the Data Protection Board of India.
A person under 18 cannot lawfully be employed as a security guard under PSARA. The app is not intended for, directed at, or usable by children, and we do not knowingly collect personal data of anyone under 18. If we become aware that we have, we will delete it and inform the agency.
No system is perfectly secure and we do not claim otherwise.
If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals within 72 hours, as the DPDP Rules, 2025 require.
| Permission | Why |
|---|---|
| Camera | To photograph the guard and their documents at enrolment |
| Location (precise) | To record where an enrolment took place, as evidence the visit occurred. Captured once, at the moment of capture; the app does not track location |
| Internet | To submit records to our servers |
The app also carries permissions it does not use directly, which arrive with the Google and Android libraries it is built on: network-state detection, a wake lock held while a queued enrolment is uploading, and rescheduling after a device restart. None of them collect personal data.
The app requests no storage or photo-library permission. When an officer attaches a document already on the device, Android's own picker returns only the file chosen, and the app never gains access to the photo library.
We will update this policy when the product changes. The version and date above change with it, and we will tell agencies about material changes before they take effect. Previous versions are available on request.