Privacy Policy
EID-Stack Wallet Application
Version: 1.0
Last Updated: 27 February 2026
Executive Summary
Intuitive Data Solutions Pvt Ltd ("IDS") is committed to protecting user privacy and enabling secure, user-controlled digital identity through the EID-Stack Wallet Application ("App").
EID-Stack Wallet is built on Self-Sovereign Identity (SSI) principles, ensuring that users retain ownership and control of their identity data. IDS does not centrally store identity credentials, does not sell or monetize personal data, and processes only the minimum information required to operate, secure, and improve the App.
This Privacy Policy explains:
- what information is processed,
- why it is processed,
- how it is protected, and
- what rights users have,
in accordance with the Digital Personal Data Protection Act, 2023 (India), the General Data Protection Regulation (EU) 2016/679 (GDPR), and other applicable data protection laws.
1. Introduction
Intuitive Data Solutions Pvt Ltd ("IDS", "we", "our", "us") is a private limited company incorporated under the laws of India, with its registered office at:
Registered Office Address:
Innovation Valley, Hill-3, IT Hub, Madhurawada, Visakhapatnam, 530048, Andhra Pradesh
Corporate Office Address:
6B 104, Krishe Emerald, Laxmi cyber-city, Kondapur, Hyderabad – 500084
IDS develops and operates the EID-Stack Wallet Application, a Self-Sovereign Identity (SSI) wallet that enables users to create, store, manage, and share verifiable credentials and decentralized identifiers (DIDs) in a secure manner.
This Privacy Policy describes how information is processed when you use the App.
IDS is committed to compliance with:
- Regulation (EU) 2016/679 (GDPR)
- Digital Personal Data Protection Act, 2023 (India)
- Other applicable global privacy and data protection laws
2. Scope and Applicability
This Privacy Policy applies to:
- The EID-Stack Wallet mobile application (all supported platforms and versions)
- Backend services strictly required for App functionality
- Technical support, diagnostics, security, and operational processes
This Privacy Policy does not apply to:
- Credential issuers, verifiers, or identity providers
- Third-party websites, applications, or services linked from the App
Each third party operates under its own privacy policy. IDS is not responsible for their data practices.
3. Definitions
- Personal Data / Personal Information: Information relating to an identified or identifiable individual.
- Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.
- Self-Sovereign Identity (SSI): A decentralized identity model in which individuals control their identity data.
- Verifiable Credentials: Cryptographically signed digital credentials issued by trusted entities.
- Data Controller / Data Fiduciary: An entity that determines the purpose and means of processing personal data.
- Data Processor: An entity that processes data on behalf of a controller or fiduciary.
4. Privacy by Design & SSI Principles
EID-Stack Wallet is architected with privacy-by-design and privacy-by-default principles, including:
- User ownership and control of identity data
- Decentralized, device-based data storage
- Selective and consent-based disclosure
- Strong cryptographic safeguards
- Minimal, proportionate, and purpose-limited processing
5. Information We Process
5.1 Data Stored Locally on Your Device
The following data is stored exclusively on the user’s device:
- Verifiable credentials
- Decentralized identifiers (DIDs)
- Cryptographic public and private keys
- Credential metadata
- Credential presentation history
This data is encrypted and is not accessible to IDS.
5.2 Information You Provide During Use
When receiving or sharing credentials, users may process:
- Identity attributes
- Government or institutional identifiers
- Address, education, or qualification data
- Supporting documents
This data is exchanged peer-to-peer using SSI protocols and is not centrally stored by IDS.
5.3 Automatically Collected Technical Information
IDS may process limited technical information, including:
- Device type, operating system, and App version
- Crash reports and error logs
- Security and performance diagnostics
- Anonymous or aggregated usage metrics
Credential contents, identity claims, and private keys are never collected.
6. End-to-End Data Lifecycle Overview
In the interest of transparency and regulatory clarity, the following section describes the end-to-end lifecycle of data within the EID-Stack Wallet Application.
6.1 Wallet Creation
Upon installation of the App, the wallet is generated locally on the user’s mobile device. All associated cryptographic keys and wallet components are created and securely stored within the device environment.
IDS does not generate, provision, access, or store wallet data on any centralized server or shared infrastructure.
6.2 Credential Issuance
When a credential is issued to a user:
- The credential is transmitted directly to the user’s wallet application.
- The credential is stored locally within the App on the user’s device.
- No duplicate or backup copy is stored on IDS systems or infrastructure.
6.3 Local Storage
All wallet contents, including:
- Verifiable Credentials
- Decentralized Identifiers (DIDs)
- Cryptographic public and private keys
- Credential metadata and presentation history
remain encrypted and stored exclusively on the user’s device.
IDS does not have access to, visibility into, or technical capability to retrieve wallet contents.
6.4 Credential Presentation and Sharing
When a user chooses to present a credential to a verifier:
- Data is transmitted directly from the user’s device to the verifier.
- Each presentation requires explicit user action and approval.
- IDS does not intermediate, intercept, store, or log the contents of credentials shared during such interactions.
6.5 Optional Backup
If the user enables backup functionality:
- Wallet data may be backed up through the user’s personal cloud account (such as Google Drive or Apple iCloud), subject to the user’s device settings.
- Such backups are controlled exclusively by the user.
- IDS does not access, manage, or retain wallet backup data.
6.6 Device Change or Restoration
In the event of a device change:
- Wallet data may be restored from the user’s personal cloud backup, where enabled.
- IDS does not maintain recovery copies, escrow keys, or restoration databases for wallet contents.
6.7 App Reset or Uninstallation
If the App is reset or uninstalled:
- Wallet data stored on the device is deleted in accordance with device-level processes.
- IDS does not retain any residual copies of identity credentials or wallet data.
7. Purpose of Processing
Information is processed strictly to:
- Operate and maintain the App
- Enable secure credential issuance and verification
- Maintain cryptographic trust
- Detect and prevent security incidents
- Improve reliability and performance
- Comply with legal obligations
IDS does not sell, rent, profile, or monetize personal identity data.
8. Legal Basis for Processing
8.1 GDPR
Processing is based on:
- User consent
- Contractual necessity
- Legitimate interests (such as security and fraud prevention)
- Legal obligations
8.2 India DPDP Act, 2023
Processing is based on:
- Consent of the Data Principal
- Legitimate uses permitted by law
Consent is freely given, specific, informed, and withdrawable.
9. User Choices and Controls
Users can:
- Control credential storage and sharing
- Approve each credential presentation
- Enable or disable biometric or PIN protection
- Opt out of optional analytics
- Delete all wallet data by uninstalling or resetting the App
10. Data Sharing and Disclosure
IDS shares data only in the following circumstances:
10.1 With User Consent
When users explicitly share credentials.
10.2 With Service Providers
With vendors processing limited technical data under strict confidentiality and data-processing agreements.
10.3 Legal Requirements
When required by valid legal orders or authorities.
11. Decentralized Identity Ecosystem
The App may interact with:
- Credential issuers
- Credential verifiers
- DID registries
- Distributed ledger or blockchain networks
IDS does not control the privacy practices of these entities.
12. Data Storage and Security
Security measures include:
- End-to-end encryption
- Secure key management
- Hardware-backed keystores (where available)
- Encrypted local storage
- Biometric or PIN-based access controls
Private keys remain under user control and are unrecoverable if lost.
13. Data Retention
- Wallet data: retained locally until deleted by the user
- Logs and diagnostics: retained only as legally or operationally required
- Backups: controlled by user device settings
14. User Rights
14.1 GDPR
Users may exercise rights including:
- Right of Access
- Right to Rectification
- Right to Erasure ("Right to be Forgotten")
- Right to Restrict Processing
- Right to Data Portability
- Right to Object
- Right to Withdraw Consent
- Right to Lodge Complaint with a Data Protection Authority
14.2 DPDP Act
Users may exercise rights of:
- Access
- Correction
- Erasure
- Grievance redressal
- Nominee appointment
Some rights must be exercised directly with credential issuers due to the SSI architecture.
15. Controller and Processor Roles
- IDS acts as Data Controller / Data Fiduciary for App operations
- IDS may act as Data Processor for credential exchange facilitation
- Credential issuers remain independent data controllers
16. International Data Transfers
Where applicable, IDS applies:
- Standard Contractual Clauses
- Adequacy mechanisms
- Encrypted data transmission
Credential data remains device-resident.
17. Data Breach Notification
IDS will:
- Assess incidents promptly
- Notify authorities, including the Data Protection Board of India, where required
- Inform affected users without undue delay
18. Children’s Privacy
The App is not intended for children under 13 years of age, or higher where required by law. IDS does not knowingly process children’s data.
19. Third-Party Services
The EID-Stack Wallet Application may integrate with:
- Credential issuers
- Identity providers or credential verifiers
- Blockchain networks
- Cloud-based mediator services
Each such integration operates independently and is governed by its own privacy policy.
20. Policy Updates
Updates to this Privacy Policy may be communicated through:
- App notifications
- Website updates
- App store listings
21. SSI Disclaimer
IDS:
- Does not verify issuer data accuracy
- Does not guarantee verifier acceptance
- Cannot recover lost private keys
- Provides software infrastructure only
22. Grievance and Contact Details
Data Protection / Grievance Officer
Organization: Intuitive Data Solutions Pvt Ltd
Email: info@idssoft.com
Address: Innovation Valley, Hill-3, IT Hub, Madhurawada, Visakhapatnam, 530048, Andhra Pradesh
23. Consent and Acceptance
By installing and using the EID-Stack Wallet Application, you acknowledge that you have read, understood, and accepted this Privacy Policy.
End of Privacy Policy