User Autonomy & DPDP Rights
Version: 1.0 Effective: 2 September 2026 Last Updated: 2 September 2026

User Rights & Data Control Policy

This User Rights & Data Control Policy explains the rights, self-service controls, and autonomy available to users regarding information managed through their centralized ARZAQ account.

Core User Control Principle:
Users have direct self-service control over centralized account profiles, authentication factors, Passkeys, session revocation, optional product integrations, activity log exports, and permanent account deletion. Product-specific data remains governed by individual product policies.

1. Purpose & 2. Scope

This policy details how users can inspect, update, export, correct, and delete personal data associated with their centralized ARZAQ identity, authentication factors, and billing records.

3. User Autonomy & Self-Service

Direct Dashboard Empowerment:

Most account controls (profile updates, Passkeys management, 2FA configuration, session termination, and permanent account deletion) are directly operable via self-service tools inside the Central Account portal without requiring support tickets.

4. Right to Access & 5. Right to Update Information

Users can review and modify account profile information (full name, phone number, gender, recovery email, security preferences) in real time.

6. Contact Verification Safeguards

Modifying critical contact identifiers (primary email or phone) triggers mandatory OTP/link verification challenges to prevent unauthorized account takeovers.

7. Review Activity Logs & 8. Download Audit Trails

Users can inspect sign-in history, IP locations, Passkey challenges, 2FA events, and active sessions, with full capability to export formatted security audit logs directly from the dashboard.

9. Centralized Account Data Portability

We provide machine-readable exports of central account metadata and security event logs to ensure user data portability.

10. Right to Correct & 11. Correction Inquiries

If data inaccuracies cannot be updated via self-service UI, submit a formal correction request to support@arzaqinsights.com.

12. Manage Authentication & 13. Remote Session Revocation

Users can add/delete biometric Passkeys, configure TOTP authenticators, regenerate recovery codes, and instantly revoke unrecognized device sessions globally.

14. Disconnect Connected Services & 16. Withdraw Consent

Users can revoke cross-product integrations at will. Disconnecting a service immediately halts future automated API transfers between the applications.

17. Marketing Opt-Out vs 18. Essential Security Notices

Users can opt out of promotional newsletters. Mandatory transactional communications (OTPs, billing receipts, security incident alerts, terms updates) cannot be opted out while an account is active.

19. Permanent Account Deletion & 20. Immediate Effects

Users can self-delete their central ARZAQ account via settings. Deletion permanently revokes login credentials, terminates active subscriptions, and purges profile records.

21. Product Data Independence

Product Data Lifecycles:

Central account deletion cuts off identity tokens. Individual products govern the deletion of internal operational tables according to their independent privacy schedules.

22. Transparency & 23. Zero Default Data Sharing

We do not share product operational data across apps without explicit user instruction.

26. Lawful Limitations to Deletion

Statutory tax invoices, GST transaction ledgers, and fraud investigation records are retained strictly as required by Indian law.

28. Submitting Formal Privacy Requests & 30. No Fee

Standard account controls and data subject requests are provided free of charge. We respond to verified legal requests within statutory timeframes.

33. Contact Data Governance Team

Privacy & Data Subject Rights Desk
ARZAQ INSIGHTS, D Block, New Ashok Nagar, Delhi 110096, India
Compliance Email: support@arzaqinsights.com

34. Core User-Control Principle Summary

Users possess direct self-service power to view, correct, secure, export, and permanently delete their centralized account identity, with zero default cross-product data merging.