DPDP & GDPR Act Compliance
DPDP & GDPR Compliance Statement
Effective Date: July 15, 2026
AION Defense operates in strict compliance with global and national data protection standards. This statement outlines our alignment with the Digital Personal Data Protection (DPDP) Act, 2023 (India) and the General Data Protection Regulation (GDPR) (EU 2016/679).
1. DPDP Act, 2023 Compliance Framework
Under the DPDP Act, AION Defense acts as a Data Fiduciary, and the registering professional acts as a Data Principal:
- Lawful Consent: No personal or credential data is processed without explicit, unambiguous, and revocable consent, obtained during the initial OTP security gateway.
- Purpose Limitation: Personal data is processed solely for the specified purpose of professional validation and platform security.
- Accuracy & Quality: Data Principals have the right to request rectification, completion, and updating of their registration profiles.
- Data Erasure: In accordance with Section 12 of the DPDP Act, personal data will be permanently erased once the purpose of collection has been fulfilled or consent is withdrawn, unless retention is mandated by defense regulations.
2. GDPR Compliance Framework
To support our European partners and buyers, we implement strict GDPR compliance controls:
- Data Portability: Users can request a secure export of their personal registration data and uploaded audit documents.
- Right to be Forgotten (Anonymization): We support absolute anonymization of Customer and Partner accounts. When activated, all identifying fields (name, email, phone) are securely scrambled in our databases.
- Privacy by Design & Default: Custom compliance inputs and file uploads are marked as hidden by default across standard profiles to protect data privacy.
- Data Protection Officer (DPO): For all data access requests or privacy-related inquiries, you can reach out to our DPO at compliance@defencecart.com.