Compliance
Privacy rights, built into the product
LifeWyn is designed to help you exercise your data-protection rights — and to minimise what we hold in the first place.
Your rights
What you can do with your data
Access & portability
Request an export of your data at any time. Your vault content is yours — and because it's client-encrypted, only you can decrypt it.
Correction
Keep your profile and records accurate. Update your information whenever it changes.
Erasure
Request deletion of your account and data. The request is recorded and held for a 30-day grace period in which you can cancel it. Final destruction of account records is carried out by our team rather than automatically, because it cannot be undone.
Consent & transparency
Granular, revocable consent with a timeline of what you've agreed to and why it was revoked, recorded in the hash-chained audit trail.
Frameworks
How we align
GDPR
Access, rectification and portability are built into the product, and erasure is handled as a recorded request. We are built for the GDPR; no supervisory authority or auditor has certified us against it.
India DPDP Act
Built for India's Digital Personal Data Protection Act: purpose limitation, recorded consent with a revocation history, and data-principal request flows. No certification scheme exists to attest to this.
Data minimisation
We collect the minimum needed to operate. Your vault content is encrypted on your device before it reaches us; your account and nominee contact details are not, because the service has to be able to reach those people.
What we have not certified
No third-party audit or certification has been performed. There is no SOC 2 report, no ISO 27001 certificate and no commissioned penetration test. When one happens, it will be published here.
See the full security postureThis page describes our approach and is not legal advice. For specific requests, contact us via the contact page.