blank

How Bureau Protects Your Personal Data

Privacy Policy

Updated 15 September 2026

1. Introduction:

Bureau, Inc., BureauID India Private Limited and Junoon Tech Pte. Ltd. (either together or as applicable “Bureau”, “we”, “us”, or “our”) provide various offerings related to identity verification, compliance and fraud prevention solutions, including software, technology, analytics, or any other services made available by Bureau to its customers (“Customers”) (“Services”) via mobile or web applications, application programming interface (APIs), software development kits (SDKs), or any other access channels (“Platform”).

This Privacy Policy (“Policy”) explains how we collect, use, share, transfer, and protect personal data (“Personal Data”) across the jurisdictions and regions where we operate, including India, the United States of America, Singapore, the Philippines, Indonesia, MEA, and the European Union/EEA.

This Policy applies to Personal Data we collect:

  • directly from individuals (such as applicants, customers, job applicants, or website visitors);

  • from our Customers who use our Services to process their end-users’ data; and

  • from third parties such as public sources, partners, and authorized data providers.

If you are an end-user of one of our Customers, your primary relationship is with that Customer. In those cases, Bureau acts as a Processor on behalf of that Customer (the controller). Where we determine the purpose and means of processing, Bureau is the Controller. For the purposes of this Policy, Controller / Processor is as defined under applicable data protection laws. Bureau may act as either depending on the engagement and the jurisdiction.

This Policy supports the implementation of ISO/IEC 27001:2022 Annex A controls including 5.34 (Privacy and Protection of PII), 5.31 (Legal, Statutory and Regulatory Requirements), 5.33 (Protection of Records), and 8.10 (Information Deletion).

2. Scope and Applicability
This Policy applies to Personal Data we collect:

  • directly from individuals (such as applicants, customers, job applicants, or website visitors);

  • from our Customers who use our Services to process their end-users’ data; and

  • from third parties such as public sources, partners, and authorized data providers.

Bureau uses your information to deliver and improve its Services, particularly in verifying identity and preventing fraud. We analyze data to detect patterns of fraudulent activity and provide our customers with insights to help them meet operational and compliance requirements. 

If you are an end-user of one of our Customers, your main relationship is with that Customer. In those cases, Bureau acts as a Processor on behalf of that Customer (the Controller). Where we determine the purpose and means of processing, Bureau is the Controller. In cases where Bureau operates as a Processor, while providing Personal Data directly to us is not mandatory, the absence of such information may restrict our ability to perform the Services on behalf of our Customers. For the purposes of this Privacy Policy, Controller / Processor as defined under applicable data protection laws. Bureau may act as either depending on the engagement and the jurisdiction.

3. Categories of Data We Collect
Identity and contact data

  • Government issued IDs

  • Biometrics 

  • Payment and transaction Information 

  • Device and technical data

  • Behavioural and usage data

  • Derived data: 

Where permitted by law, we may obtain additional information about you from third-party providers or partners. This may include consumer reporting agencies, fraud prevention services, data brokers, government databases, and marketing or analytics providers, and may be combined with the information we already hold about you. 

4. How We Use Your Personal Data

We use the Personal Data we collect to:

  • Provide and improve our Services, including maintaining, updating, and enhancing features.

  • Communicate with you about service updates, account or subscription notices, and changes.

  • Enable your participation in the interactive features you choose to use.

  • Protect legitimate interests, such as fraud prevention, product improvement, or security.

  • Analyze and improve our Services by gathering insights to monitor usage and enhance performance.

  • Ensure security and reliability by detecting, preventing, and addressing fraud, abuse, or technical issues.

  • Fulfill obligations such as contracts, billing, and compliance requirements.

  • Share relevant updates like offers or news about similar services.

  • Support you by offering customer assistance and honouring your choices.

5. Legal Bases for Processing

We process personal and sensitive data on the following bases:

  • Consent: when you (or our Customers, as data Controllers) give explicit permission for specific processing.

  • Contractual Requirements: when needed to perform obligations under a contract with our Customers, partners, or API users.

  • Legal Obligations: when required by applicable laws or regulations (e.g., AML, fraud prevention, reporting).

  • Legitimate Interests: when improving Services, preventing fraud, or ensuring security, without overriding your rights.

6. How We Collect Data

  • Directly: from you when you use our Services, upload documents, or contact us.

  • From Customers: our Customers provide end-user data to perform verification and fraud risk checks.

  • From third parties: public sources, data providers, credit bureaus, and sanctions/PEP lists.

7. Sensitive Data and Biometrics

We process biometrics and other sensitive data only when required for the Service (e.g., eKYC), we have a lawful basis (consent or legal obligation), and strict safeguards are in place (encryption, access controls).

8. Sharing and Recipients
We may share Personal Data with:

  • Customers (Controllers of their users’ data);

  • Service providers (e.g., hosting, analytics, ID verification);

  • Regulators and authorities, if legally required;

  • Affiliates and acquirers, if part of a corporate transaction.

9. International Transfers

Bureau operates globally, with infrastructure in India, Singapore, and the US. Personal Data may be transferred across borders. For EU/EEA transfers, we rely on Standard Contractual Clauses (SCCs) or adequacy decisions. For other countries (India, Indonesia, Philippines, Singapore, US), we apply contractual and technical safeguards consistent with local laws. We may update our infrastructure location from time to time. Transfers from India are conducted in accordance with the Digital Personal Data Protection Act, 2023 and any government-notified restrictions on cross-border transfers.

10. Data Subject Rights

Subject to the law that applies to you, and to the role in which Bureau processes your Personal Data, you have the rights set out below. Where Bureau is the Controller — for example if you are a Bureau employee, contractor, job applicant, website visitor or business contact — you may exercise these rights directly with us.

  • Be informed (GDPR Article 13 and Article 14): to receive this notice at or before the point at which we collect your Personal Data, including where we obtained it from a source other than you.

  • Access (GDPR Article 15): to confirmation of whether we process your Personal Data, a copy of that data, and information about the purposes, the categories of data, the recipients, the retention period and the source.

  • Rectification (GDPR Article 16): to correction of inaccurate Personal Data and completion of incomplete Personal Data.

  • Erasure (GDPR Article 17): to deletion of your Personal Data where one of the grounds in Article 17(1) applies.

  • Restriction of processing (GDPR Article 18): to have processing limited to storage while a dispute over the accuracy or the lawfulness of processing is resolved.

  • Notification to recipients (GDPR Article 19): to have each recipient to whom we disclosed your Personal Data informed of a rectification, erasure or restriction, unless that proves impossible or involves disproportionate effort.

  • Data portability (GDPR Article 20): to receive Personal Data you provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller where technically feasible.

  • Objection (GDPR Article 21): to object to processing based on legitimate interests. Where you object to direct marketing, we will stop processing your Personal Data for that purpose.

  • Automated decision-making and profiling (GDPR Article 22): not to be subject to a decision based solely on automated processing, including profiling, that produces legal effects concerning you or similarly significantly affects you, and to obtain human intervention, express your point of view and contest the decision. Bureau's verification and risk outputs are provided to our Customers, who decide what action to take; where such a decision is made by a Customer, this right is exercised against that Customer.

  • Withdrawal of consent (GDPR Article 7(3)): where processing is based on consent, to withdraw that consent at any time and as easily as it was given, without affecting the lawfulness of processing carried out before withdrawal.

  • Complaint (GDPR Article 77): to lodge a complaint with us and with your supervisory authority.

If you are an end-user of one of our Customers, Bureau acts as a Processor and your rights are exercised against that Customer as the Controller. Please contact that Customer in the first instance. If you contact us instead, we will tell you so without undue delay and will assist that Customer in responding to you, as required by GDPR Article 28(3)(e). We will not act on your request directly unless the Customer instructs us to do so.

Under India's Digital Personal Data Protection Act, 2023, if you are a Data Principal you have the right to obtain a summary of your Personal Data and of our processing of it (section 11), to correction, completion, updating and erasure (section 12), to grievance redressal (section 13), and to nominate another individual to exercise your rights in the event of your death or incapacity (section 14).

California residents have rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act, including to know, delete and correct Personal Data and to opt out of its sale or sharing. Residents of Singapore have rights under the Personal Data Protection Act. Where a right described above is not available to you under the law that applies to you, that narrower position applies; nothing in this Policy reduces a right your law gives you.

Requests to exercise the above rights may be made through our Data Protection Officer or the grievance channel set out in Section 15 of this Policy. Where we have reasonable doubts about your identity we may require additional information to verify it. The following applies to every request:

  • No charge: we do not charge a fee for responding to a request. Where a request is manifestly unfounded or excessive, in particular because it is repetitive, we may charge a reasonable fee or refuse to act, and we will explain why and how you may challenge that decision (GDPR Article 12(5)).

  • Timeline: we respond within one month of receiving your request. Where the request is complex, or where you have made a number of requests, we may extend that period by up to two further months; we will tell you within the first month if we do so, and why (GDPR Article 12(3)).

  • Identity verification: we will ask only for the information necessary to confirm the identity of the person making the request (GDPR Article 12(6)).

  • If we do not act: we will tell you within one month of the reasons, and that you may lodge a complaint with a supervisory authority and seek a judicial remedy (GDPR Article 12(4)).

11. Data Retention

Personal Data is retained in accordance with BI-PRIV-POL-002 – Data Retention and Deletion Policy, which defines category-wise retention periods, legal basis, ownership, and secure deletion mechanisms.

Where Bureau acts as a Processor, retention is governed by Customer instructions and applicable legal requirements.

Legal hold, regulatory preservation, or contractual obligations may override standard retention periods.

12. Security

We use organizational, technical, and physical safeguards, including encryption in transit and at rest, access control and multi-factor authentication, regular audits and penetration testing, and incident response planning. We regularly seek new ways to further enhance the security of our Services.

13. Cookies

We use cookies and similar technologies to improve your experience, secure our Services, and understand how they are used. Some cookies are essential for the operation of our Services, while others help us analyze trends, personalize content, and deliver relevant communications. You can manage or disable cookies in your browser settings, but certain features or Services may not work as intended if cookies are disabled. 

14. Breach Notification

We will notify Customers, regulators, and (where required) affected individuals of data breaches as soon as we become aware in line with applicable laws (e.g., CERT-IN 6-hour rule, GDPR 72-hour rule).

All security incidents are managed in accordance with BI-IR-POL-001 – Information Security Incident Response Policy.

15. Contact and DPO

To exercise your rights or raise a concern, contact: dpo@bureau.id

Data Protection Officer: dpo@bureau.id

Grievance Officer: dpo@bureau.id

The Grievance Officer is the readily available means of grievance redressal for the purposes of section 13 of the Digital Personal Data Protection Act, 2023. Grievances are handled under our Procedure for Handling Grievance Requests and Consent Revocation.

16. Children’s Privacy

Our Services are not directed to children under applicable age limits (13 – 16 years, depending on applicable laws). If you learn that your child has shared Personal Data with us without your consent, please contact us (see Section 15 of this Policy) so we can remove it promptly.

17. Changes

We may update this Policy to reflect changes in our Services, legal requirements, or business practices. Updates take effect once posted on our website, unless the law requires otherwise. By continuing to use our Services or accessing the Platform after an update, you accept the revised Policy. We encourage you to review it regularly. If any change significantly affects your rights, we will provide additional notice, such as by email or a clear notice on our website.

18. Reference

18.1 Internal

  • BI-ISMS-POL-001 – Information Security Management Policy

  • BI-PRIV-POL-002 – Data Retention & Deletion Policy

  • BI-IR-POL-001 – Incident Response Policy

  • BI-ACCESS-POL-002 – Access Control Policy

  • BI-TPRM-POL-002 – Third Party Risk Management Policy