Privacy policy.
This policy describes what personal data GriffynX Intelligence Labs Pvt Ltd processes, on what basis, for how long, and what you may require of us. It applies to griffynx.com, to Discover and X-Ray, and to the Trust API.
Effective 14 September 2026 · GriffynX Intelligence Labs Pvt Ltd
01Who we are and what this covers
GriffynX Intelligence Labs Pvt Ltd (“GriffynX”, “we”, “us”) is a company registered in India. We provide trust intelligence: an assessment of a counterparty computed from evidence gathered across independent sources.
This policy covers our website at griffynx.com, the Discover and X-Ray surfaces at discover.griffynx.com, and the Trust API at api.griffynx.com. Where an institution uses the Trust API to assess its own counterparties, that institution is the data fiduciary in respect of the subject of the enquiry and GriffynX acts as a data processor on its documented instructions.
02What we collect
Enquiry data. The identifiers submitted for assessment — for example an email address, telephone number, social handle, domain or payment identifier — together with the declared purpose of the enquiry and, where supplied, the context described at intake.
Evidence. What independent sources return about a submitted identifier. This may include personal data. It is admitted with its provenance and is retained as described in clause 5.
Account and contact data. For customers and prospective customers: name, work email address, telephone number, country, organisation and the purpose selected on our contact form, together with any message supplied.
Operational data. Audit records of every call, carrying the purpose declared with it; rate-limit counters; and the technical logs necessary to operate and secure the service.
We do not collect or process biometric identifiers, and we do not infer protected or proxy characteristics. No source, typology, route or policy default in our system keys on such an attribute.
03Purpose and lawful basis
Every call to our systems carries a registered purpose, and processing is confined to that purpose. We rely on legitimate interests in the prevention and detection of fraud and financial crime, on the performance of a contract with our customers, and on consent where an individual voluntarily submits their own identifier to Discover.
We do not sell personal data, and we do not disclose it for advertising or for any purpose unrelated to the enquiry it was gathered for.
04How evidence is handled
Raw material returned by a source is referenced by cryptographic hash rather than carried through our systems. It is accessible only to audit and analyst roles, and it is never returned to a customer.
No source is identified to a customer. A finding is expressed as a statement carrying its provenance class and the banded trust of its source, so that a customer receives the substance of the evidence without receiving the evidence itself.
05Retention
Retention is keyed to the data class of the material, the applicable regime, and the purpose for which it was gathered — not to a single blanket period. The most sensitive class of raw material is not stored by default.
Assessments and their audit records are retained for as long as the customer may be required to justify the decision taken upon them. Where a legal hold applies, deletion is suspended and the suspension is itself recorded.
Contact data submitted through this website is retained for as long as necessary to respond to the enquiry and to maintain a record of our correspondence.
06Disclosure
We disclose personal data only to: the sources we query, and only the identifier necessary for the query; infrastructure providers processing on our behalf under contract; and competent authorities where we are legally required to do so.
Evidence gathered for one customer is not disclosed to another. Memory that improves subsequent assessments operates within a customer's own tenancy by default; it extends across tenancies only under a specific legal arrangement.
07Security
Credentials for our sources are held in a managed key vault and read by workload identity; they never enter the layer that serves customers. Customer keys are displayed once and retained only as a salted hash. Transport is encrypted, access is least-privilege, and every analyst action is audited.
08Your rights
Subject to the Digital Personal Data Protection Act, 2023 and to other applicable law, you may request access to the personal data we hold about you, its correction or erasure, a restriction on its processing, and the withdrawal of consent where consent is the basis on which we process.
Where GriffynX acts as a processor for an institution, we will refer your request to that institution and assist it in responding.
To exercise any of these rights, or to nominate another person to do so on your behalf, write to hello@griffynx.com. We will respond within the period the applicable law allows. If you are not satisfied with our response you may complain to the relevant supervisory authority.
09International transfers
Our infrastructure is operated in regions we select for proximity and for regulatory fit, and some sources we query are operated outside India. Where personal data is transferred across a border, we do so on the terms permitted by applicable law and under contract with the recipient.
10Changes and contact
We will post any change to this policy on this page and revise the effective date above. Material changes affecting customers will additionally be notified directly.
Questions about this policy, or about how we process a particular item of personal data, should be sent to hello@griffynx.com or through the contact form.