Global Data Routing & Compliance

BizLiveGo International Data Transfer Policy

Establishing cross-border data transfer safeguards, cloud hosting topologies, edge CDN caching nodes, Standard Contractual Clauses (SCCs), and regulatory transfer compliance across global jurisdictions.

Data Fiduciary: BizLiveGo | Operator: MD Joshim Biswas | Malda, WB, India - 732206 | Version: 2026.1

1. Statutory Framework

Cross-Border Scope & Authority

BizLiveGo operates as a global profile-building platform with primary servers in India and distributed content delivery nodes operating internationally.

This International Data Transfer Policy operationalizes compliance with Section 16 of the Digital Personal Data Protection (DPDP) Act (India), Chapter V of the GDPR (EU/UK), and the CCPA/CPRA (US).

2. Transfer Architecture

Core Cross-Border Commitments

When personal or commercial profile data is routed across national borders:

  • Equivalent Protection: All destinations must provide data security equivalent to domestic law.
  • Blacklist Compliance: No data is transferred to jurisdictions restricted by the Central Government of India.
  • Encrypted Routing: Data in transit is secured with high-grade TLS 1.3 cryptographic protocols.
3. Legal Safeguards

Approved Cross-Border Transfer Instruments

BizLiveGo relies on recognized statutory mechanisms to authorize international data routing:

1. Standard Contractual Clauses (SCCs)

For transfers originating in the European Economic Area (EEA) or United Kingdom, BizLiveGo and its cloud sub-processors execute European Commission approved Standard Contractual Clauses (SCCs).

Ensures enforceable data subject rights and effective legal remedies across borders.

2. Indian DPDP Act Adequacy

Under Section 16 of the DPDP Act, personal data may be transferred to any country or territory unless expressly restricted or blacklisted by the Central Government through official gazette notification.

Continuous compliance audits monitor foreign regulatory developments.

3. Explicit Derogation & Performance

Certain cross-border transmissions occur pursuant to explicit user consent or contractual necessity to render public profiles, resolve dynamic QR codes globally, and process cross-border payments.

Required to deliver public web accessibility to international visitors.

Critical Transfer Restriction

4. Prohibited Cross-Border Transmission of High-Risk Identifiers

BizLiveGo maintains an absolute ban on uploading high-risk personal identification documents. These records are never routed across international nodes:

Strictly Prohibited Identifiers

Users and clients must never submit for international routing:

  • National identification numbers, passport numbers, or tax registration documents.
  • Unredacted identification card scans, citizen cards, or biometric data files.
  • Raw banking card CVVs, PIN numbers, OTPs, or private authentication passwords.

Voluntary Special Category Directory Data

Voluntary directory listings (such as blood donor registries or matrimonial biodata):

  • Routed internationally across edge CDN caches strictly pursuant to user publication consent.
  • Encrypted at rest using AES-256 standards across all foreign caching nodes.
5. Server Topologies

Global Infrastructure Topologies & Sub-Processor Locations

Where user data is stored, cached, and processed across our cloud stack:

Primary Storage (India)

Core application databases, user account credentials, profile configurations, and permanent backups are hosted in certified enterprise data centers located within India (Mumbai / Bengaluru regions).

Governed by Indian data protection laws.

Edge CDN Caches (Global)

Static media assets, profile layouts, and dynamic QR SVG images are cached across Cloudflare's global edge network (USA, EU, Singapore, Australia) to ensure low-latency loading worldwide.

Ephemerally cached; purgeable via API.

Payment Processors (Multi-Region)

Domestic checkouts are processed via Razorpay/Cashfree (India). International checkouts route to Stripe/PayPal (USA/EU) under PCI-DSS Level 1 tokenized security frameworks.

BizLiveGo never stores raw payment card data.

6. Technical Controls

Cryptographic & Organizational Defenses

To protect cross-border data flows against foreign government interception or unauthorized exfiltration:

  • TLS 1.3 in Transit: End-to-end transport layer security across all international data pipelines.
  • AES-256 at Rest: Strong cryptographic encryption on all remote object storage clusters.
  • Access Control: Administrative access restricted to authorized personnel via multi-factor authentication and role-based permissions.
7. Government Access

Government Access Requests Protocol

If foreign law enforcement or intelligence agencies demand access to BizLiveGo user data:

  • We scrutinize the legal validity and jurisdictional reach of every inbound warrant.
  • We challenge requests that conflict with Indian law or international human rights standards.
  • We notify impacted account owners unless legally prohibited by a binding court order.
8. User Entitlements

Exercising Data Rights for Cross-Border Data (7 to 15 Days SLA)

Your statutory privacy rights follow your data regardless of which country's servers host it:

1. Global Access & Erasure

Data Principals may request access, correction, or permanent erasure of their international records through our Contact Desk or email.

2. Execution SLA

Cross-border erasure and portability directives are fulfilled within 7 to 15 working days. Edge CDN purge APIs evict cached profile fragments across all global points of presence.

3. Transfer Inquiries

Users have the right to request a copy of the Standard Contractual Clauses (SCCs) or contractual transfer mechanisms governing their specific data flows by contacting our DPO.

Quick Summary

International Data Transfer Quick Reference

Consolidated review of cross-border mechanisms, server locations, and compliance standards:

Transfer Dimension Platform Provision Compliance Standard
Primary Hosting Location Production database servers located in India (Mumbai / Bengaluru). DPDP Act Compliance
Edge CDN Distribution Cloudflare edge caching nodes located globally across USA, EU, Asia-Pacific. Encrypted Edge Caching
Transfer Instruments Standard Contractual Clauses (SCCs), DPDP Section 16 adequacy, and explicit consent. Recognized Legal Safeguards
Encryption Standards TLS 1.3 in transit across all international nodes; AES-256 for data at rest. Enterprise Cryptography
Prohibited Identifiers National ID cards, passports, bank card CVVs, and passwords are never routed. Zero-Retention Policy
International Erasure SLA Cross-border purge requests processed and flushed within 7 to 15 working days. Enforced SLA
Processing Fee Zero fees for cross-border data rights or transfer verification inquiries. 100% Free Access

Inquire About Cross-Border Data Transfers

If you have questions regarding where your profile data is routed, wish to inspect our transfer safeguards, or need assistance from our Data Protection Officer, reach out to our privacy desk.

Data Protection Officer: Joshim Biswas | Location: Masimpur, Kaliachak, Malda, West Bengal, India - 732206