Data security & confidentiality

Your Data Is Not Our Product.
It Is Our Responsibility.

When you trust DataCare Labs with a failed storage device, you are trusting us with the information inside it. Our recovery process is built around controlled access, ownership verification, offline recovery workflows, secure verification, certified infrastructure and defined data retention.

ISO 27001:2022Information security
SOC-2Audited controls
ISO 14644-1:2015Clean-room standard
ISO 9001:2015Quality management
OTPOwnership verification
Secure eraseSeven-day retention policy

View certifications & controls →

Security is a process, not a promise

Security Is Built Into the Recovery Process.

Data security should not depend on an employee remembering a rule, or on a customer simply trusting a promise. At DataCare Labs, security is built into how a case is received, identified, analysed, recovered, verified, delivered and finally erased.

01

Device received

Your device and case details are logged on arrival.

02

Ownership verified

Customer and case information are linked from the start.

03

Controlled analysis

Engineers diagnose the fault using controlled procedures.

04

Offline recovery

Recovery runs offline wherever the workflow allows.

05

Secure verification

You check your files in your own browser, before any payment.

06

OTP-verified delivery

An OTP confirms the authorised recipient before release.

07

Retention window

Our recovery copy is kept for seven days after delivery.

08

Secure erase

Then it is permanently deleted under our retention policy.

Security measure 01Confidential contact details

Your Contact Details Stay Confidential.

Your name, phone number, email address, business information and case details are used for legitimate service and operational purposes. We do not sell, rent or trade your personal information to third parties.

Personal information is handled according to our Privacy Policy and applicable legal requirements. Promotional messages are sent only with your explicit consent.

Your recovery case is not a lead for someone else.

Read our Privacy Policy →

What we don’t do

  • We don’t sell customer information.
  • We don’t rent customer databases.
  • We don’t trade customer contact information.
  • We don’t use your recovery case as a marketing asset without your permission.
  • We don’t disclose your information except where needed to provide the service, meet legal obligations or protect legitimate rights.

Security measure 02Sector-by-sector offline recovery

We Don’t Simply Copy a Drive.
We Control How It Is Read.

During recovery we work at the storage-media level. Our engineers control how the source device is read during cloning: read behaviour, forward and reverse passes, and careful handling of problem sectors.

Controlled cloning

  • Sector-by-sector processing
  • Controlled read speed
  • Forward and reverse reading
  • Bad-sector management
  • Controlled retries
  • Offline recovery workflow

The cloning and recovery workflow is designed to keep recovery media offline wherever technically practical.

Pass 1 · Forward readSector map
Sectors read0/192
Pending retry0
Unreadable0
  • Read
  • Skipped, slow
  • Recovered on retry
  • Unreadable
Source drive→Sector map→Controlled cloning→Recovery image→File system→Verified data

Security measure 03Secure remote data verification

Verify Your Data Without Installing Anything.

Before delivery you can check your recovered files through our personalised web-based verification system — remotely or in the lab, with no time limit, before any payment is taken.

Browser-based

Open the verification session in a standard web browser.

No third-party installation

No TeamViewer. No AnyDesk. No remote-access software to install.

OTP protected

The session requires OTP-based ownership verification.

One customer per session

Only one authorised person joins the active verification session.

Privacy controls

The remote display and audio can be turned off during the session when needed.

Secure verification session
DataCare Labs — Secure data verification
Awaiting OTP
CustomerAmol K.
OTP
Recovered filesContents not shown
  • /Documents
  • /Photos
  • /Projects
  • /Accounts
Locked until the OTP is verified
  • Identity verified
  • Session authenticated
  • Single-session access

Illustration. No real customer data is shown.

You see your recovered data in your browser. We don’t ask you to install remote-control software just to verify your files.

Security measure 04Ownership verification

The Data Belongs to You.
We Verify That.

Recovering data is only half the responsibility. Releasing it to the right person matters just as much. Ownership verification is built into the critical stages of your case, especially when recovered data is released.

Customer→Case creation→Device identification→Recovery→Data verification→OTP ownership check→Data delivery

OTP verification

An OTP confirms the authorised recipient before data is delivered — whether to your own storage device or as a cloud download link.

Case identity

Customer and case information stay linked throughout the recovery workflow.

Controlled release

Recovered data is not handed to whoever arrives with a claim.

We verify before we release.

Security measure 05Class 100 clean room

Your Drive Is Opened Where Dust Doesn’t Get a Vote.

Class 100 clean-room environment

Certified to ISO 14644-1:2015

Hard drives contain extremely delicate mechanical parts. When a drive has to be opened, the environment matters.

The read/write heads fly nanometres above the platter surface, so a single airborne particle can scratch it and end the recovery. That is why every drive that has to be opened is handled inside our controlled clean-room environment.

Normal environmentHigh particle count
DataCare Labs clean roomControlled particle environment
HEPA filtrationControlled airflowClean workbenchControlled entryEngineer PPEDrive opening station

Six layers around your data

The DataCare Labs Security Architecture

Your data sits at the centre. Six layers of people, process, physical and information controls surround it — hover or tap a layer to see what it covers.

Security measure 06ISO 27001:2022 information security

Security Controls, Not Security Promises.

How information is stored, accessed, transferred and destroyed is governed by information-security controls certified to ISO 27001:2022. The scope and controls are documented and subject to ongoing review and audit.

Access

Who can access information?

Storage

Where and how is information handled?

Transfer

How is recovered information delivered?

Destruction

What happens when the retention period ends?

Statement of Applicability

The Statement of Applicability identifies the information-security controls that apply within the organisation’s defined scope. Ask us if your organisation needs to see it.

Policy→Control→Implementation→Audit→Review→Improvement

Security should be repeatable. It should not depend on who happens to be handling your case that day.

Security measure 07SOC-2 controls

Independent Controls. Greater Accountability.

Our controls are independently assessed under SOC-2 — an additional layer of assurance around how information and systems are managed while your data is in our care.

Access control

Access is granted only to authorised staff.

Monitoring

Relevant activities are subject to defined controls and oversight.

Process control

Security practices are documented and repeatable.

Ask us about compliance documentation →

Security measure 08NDA before collection

Need Contractual Confidentiality?
Ask for an NDA Before We Collect the Drive.

Some customers need confidentiality obligations in place before the device leaves their premises. DataCare Labs can sign an NDA on request, before collection.

NDA request→Review→Sign→Device collection→Recovery

Suitable for

BusinessesEnterprisesLegal mattersIntellectual propertyResearch dataConfidential projectsSensitive corporate information

Request an NDA

Tell us how to reach you. We’ll send our NDA or review yours before collecting the drive.

We reply within working hours (Mon–Sat, 9:30–6:00). Your details are used only to handle this request — see our Privacy Policy.

Security measure 09Seven-day retention, then secure erase

We Don’t Keep Your Data Forever.

After delivery, your recovered data is kept for seven days so you can verify your files and make extra copies. Then it is securely deleted from our systems under our data retention policy.

Day 0 · DeliveryYour recovered data is delivered. Our recovery copy is kept so you can verify your files and make extra copies.

Need it deleted sooner?

Ask us in writing and your data is securely deleted within two days, as set out in our Terms & Conditions.

Recover→Verify→Deliver→Retention window→Secure erase

Your recovery should have an end date.

What happens to your data?

Nine Steps, From Arrival to Erasure.

Every case follows the same documented path — so you always know where your data is and what happens next.

  1. 01
    Your device arrives

    The device and case details are recorded.

  2. 02
    Ownership is established

    Customer information and verification controls are applied to the case.

  3. 03
    Analysis begins

    Engineers diagnose the failure using controlled procedures.

  4. 04
    Recovery begins

    Data is recovered using controlled techniques suited to the fault.

  5. 05
    You verify

    You check your recovered files remotely or in the lab, with no time limit, before any payment.

  6. 06
    You authenticate

    An OTP confirms you are the authorised recipient before release.

  7. 07
    Data is delivered

    To your own storage device, or as a cloud download link released after OTP verification.

  8. 08
    Retention expires

    Our recovery copy reaches the end of its seven-day retention period.

  9. 09
    Secure erase

    The retained recovery copy is permanently deleted under our data retention policy.

Whatever Is on the Drive, We Treat It as Confidential.

Personal information

Names, phone numbers, email addresses and case information.

Business information

Financial files, customer records, documents and operational data.

Intellectual property

Design files, source files, research and proprietary information.

Personal memories

Photos, videos and personal documents.

Enterprise data

Servers, RAID, NAS, databases and business-critical storage.

Confidential information

Legal documents, contracts, research and sensitive projects.

Minimum necessary access

We Don’t Need to Know Your Files.

Our job is to recover your data — not to inspect your personal or business information. Files are opened only as far as recovery, testing and verification require, and access is limited to authorised staff under our confidentiality policy.

  • No unnecessary browsing
  • No unnecessary copying
  • No unnecessary disclosure
  • Controlled access
  • Customer-led verification

Security Across the Entire Lifecycle.

Before recovery

  • Customer identification
  • Device tracking
  • Ownership verification
  • NDA on request
  • Controlled intake

During recovery

  • Controlled access
  • Sector-level cloning
  • Offline recovery workflow
  • Class 100 clean room
  • Secure verification

After recovery

  • Customer verification
  • OTP-controlled release
  • Secure delivery
  • Seven-day retention window
  • Secure erasure

Security for every kind of customer

Whoever You Are, the Same Controls Apply.

Your photographs, documents and personal files are treated as confidential customer data. Files are opened only as far as recovery and verification require.

Certifications

Certified, Audited, Renewed.

Tap a mark to see what it covers, the issuing body and its validity. Certificate numbers are partly masked; ask us for a copy if you need one.

Tap a mark for scope and certificate detailsCertified Standards. Proven Trust.

ISO 9001:2015 quality management certification mark
ISO 9001:2015

Quality Management

ISO/IEC 27001:2022 information security certification mark
ISO 27001:2022

Information Security

SOC-2 system and organization controls certification mark
SOC-2

Controls Audited

ISO 14644-1:2015 cleanroom classification certification mark
ISO 14644-1:2015

Cleanroom Class

Certificate of Incorporation, Ministry of Corporate Affairs, Government of India
Incorporation

Government of India

Security questions customers ask

Fifteen straight answers on confidentiality, verification, retention and deletion — consistent with our Privacy Policy and Terms & Conditions.

Yes. Access is limited to authorised staff under our confidentiality policy, files are opened only as far as recovery and verification require, and our information-security controls are certified to ISO 27001:2022 and independently assessed under SOC-2.
No. We do not sell, rent or trade your personal information to third parties.
Only with your explicit consent, as stated in our Privacy Policy. Your details are otherwise used to handle your case.
Only authorised staff working on your case, and only as far as recovery, testing and verification require.
No. Remote verification runs in your own web browser. You don't need to install TeamViewer, AnyDesk or any other remote-access software.
Yes. You check the recovered files through our web-based verification system, or in the lab, with no time limit and before any payment is taken.
Before your data is released, a one-time password confirms that you are the authorised recipient. The OTP is required both for the verification session and for the cloud download link.
A drive head flies nanometres above the platter, so one dust particle can scratch the surface and end the recovery. Every drive that has to be opened is opened in our Class 100 clean room, certified to ISO 14644-1:2015.
We keep a recovery copy for seven days so you can verify your files and make extra copies. If your copy is damaged in that window, we deliver it again at no extra cost. After seven days it is permanently erased.
Yes. Ask us in writing and your data is securely deleted within two days, as set out in our Terms & Conditions.
Yes, on request, before the drive is collected. Use the NDA request form on this page or tell us when you book a pickup.
The cloning and recovery workflow is designed to keep recovery media offline wherever technically practical.
Seven days after delivery. Then it is securely deleted under our data retention policy.
Recovered data is released only after OTP-based ownership verification of the authorised recipient. It is not handed to whoever arrives with a claim.
ISO 27001:2022 for information security, SOC-2 for independently assessed controls, ISO 9001:2015 for quality management, and ISO 14644-1:2015 for our Class 100 clean room.

Have a security question we haven’t answered? Call +91 9859 070809 — or request an NDA before we collect your drive.

We know what is inside your drive may be more valuable than the drive itself.

That’s why our responsibility doesn’t end when we recover your files.

ReceiveRecoverVerifyDeliverErase

Talk to us first

Have Questions About Data Security?

If your data is confidential, your security questions are valid. Talk to us before you send your device.

DataCare Labs Private Limited

301, Fourth Level, Fortune House, above Chitale Bandhu, Baner, Pune, Maharashtra 411045

support@datacarelabs.com

+91 98590 70809

Monday to Saturday, 9:30 AM – 6:00 PM

Your Data.
Your Ownership.
Our Responsibility.