Global compliance

Spojiti complies with the data-protection law of every market it serves by holding almost nothing to protect. This page states, per regime, what applies to us, what we do, and what we can and cannot produce when asked.

India — Digital Personal Data Protection Act, 2023

Spojiti is a Data Fiduciary that collects no personal data at sign-up and processes none to deliver the service: no name, phone number, e-mail, device identifier or location is requested, stored or derivable. Payment data for the web rail is processed by Razorpay under its own compliance; we receive a blind-signature token, not the buyer. Under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 we publish a Grievance Officer (contact page), acknowledge grievances within 24 hours and resolve them within 15 days, and we retain what the Rules require for the period they require — which, for a service that holds no user records, is the transaction records of the payment rail and the audit log of our own operators' actions.

European Union — GDPR, ePrivacy, DSA

Data minimisation is the design, not a policy: Article 5(1)(c) is satisfied by construction because no identifier is collected. Where personal data does arise — an IP address on a connection, a payment record on the web rail — the lawful basis is Article 6(1)(b), performance of the contract, and retention is the shortest the purpose allows (connection logs: none persisted; payment records: the statutory accounting period). Our EU representative under Article 27 and our Digital Services Act point of contact are named on the Contact page. Data subject rights are honoured to the extent physically possible: access and portability produce the ciphertext and routing ids we hold, which we cannot link to a person; erasure is a matter of deleting an identity from the device, which the app does on request. Transfers: users in the EU are served from our infrastructure within the EU; no data leaves the region for the service to work.

Where your data lives

Within your region

Relay, media store and Echo box run on hardware we own, on a full rail inside the region that serves you. What the service needs stays within that region, under that region's law.

Every region we serve

Each region has its own rail and its own encrypted backups, restored in a monthly drill. We meet the regional and local regulations of every market we operate in, and this page lists them regime by regime.

Nowhere else

No hyperscaler, no CDN in the message path, no analytics vendor, no advertising network. Push notifications cross Apple's and Google's networks as content-free nudges.

Lawful requests — what we can and cannot produce

We answer every valid legal request, and every answer is bounded by what exists. We can confirm whether a routing id has connected recently and produce the ciphertext queued for it — sealed, undeliverable to us. We cannot produce a name, number, e-mail, contact list, message content, call content, location or the identity behind an Echo pseudonym, because none of these exist on our systems. We publish a transparency report twice a year listing requests received and what was produced.

Other regimes and standards

Cryptography export

Mass-market encryption software published in source form; the app's store listings declare its use of encryption as required by the platforms.

Children

Spojiti is for people 16 and over. Public Echoes carry an 18+ flag that gates adult topics behind an explicit opt-in.

Independent audit

Independent audit in progress — expected by end of 2026, on track. The report covers the full product and is published on this site in full, findings included.