5. Law Enforcement Guidelines
Effective date: April 03, 2025 Company: RAB CORP Pvt Ltd Service: SYNC Law enforcement contact: law.enforcement@rabcorp.co.in Physical address in India: B401 Ashwini Paradise, Gangadham chowk Kondhwa Bibvewadi road Pune 37
5.1 Purpose
These Law Enforcement Guidelines explain how RAB CORP Pvt Ltd receives, verifies, processes, preserves, and responds to lawful requests from courts, competent authorities, government agencies, law enforcement authorities, CERT-In, and other legally authorised bodies in relation to SYNC.
These Guidelines are designed to support lawful investigations and cyber security responsibilities while protecting User privacy, end-to-end encryption, due process, and Applicable Law.
5.2 Designated channel for requests
Law enforcement and government requests should be sent to:
Email: law.enforcement@rabcorp.co.in Postal address: B401 Ashwini Paradise, Gangadham chowk Kondhwa Bibvewadi road Pune 37 Emergency / 24x7 contact when applicable: 9881241237
If SYNC becomes an SSMI, we will appoint a nodal contact person resident in India for 24x7 coordination with law enforcement agencies and officers, as required under the IT Rules.
5.3 Types of requests we may receive
We may receive and process, subject to verification and Applicable Law:
court orders;
reasoned written intimations from authorised government officers;
information requests from lawfully authorised government agencies;
preservation requests;
cyber security requests or directions from CERT-In;
Section 69 interception, monitoring, decryption, or first-originator related orders;
emergency safety or child protection requests;
notices relating to unlawful Content or communication links;
Grievance Appellate Committee orders;
summons, warrants, production orders, or other legal process; and
requests under any other applicable statute or binding legal authority.
5.4 Verification of authority
Before responding, we may verify the request, including:
identity, designation, official email, contact details, and authority of the requesting officer or body;
legal basis and statutory provision invoked;
whether the request is in writing and properly signed or authenticated;
whether the requesting body has jurisdiction;
whether the request clearly states the purpose;
whether the request specifies the Account, message ID, group ID, channel ID, URL, electronic location, phone number, email, user handle, timestamp, or other identifier;
whether the request is necessary, proportionate, specific, and limited to information under our control or possession;
whether any special procedure, approval, or safeguard is required; and
whether the request conflicts with privacy, encryption, child safety, or other legal obligations.
We may seek clarification, narrowing, or additional documents where a request is unclear, overly broad, informal, unverifiable, technically infeasible, or inconsistent with Applicable Law.
5.5 Information that may be available
Depending on the feature, retention period, and technical design, we may have access to some of the following categories of information:
Account registration details such as phone number, email address, display name, handle, profile information, account creation date, verification status, and account status;
device and login information such as IP addresses, device identifiers used by the app, app version, authentication logs, push notification tokens, and security event logs;
messaging metadata such as sender and recipient identifiers, group or channel identifiers, message identifiers, timestamps, delivery status, message type, file type, and encrypted payload metadata;
group, channel, or broadcast information such as name, description, admin, membership, invite status, and settings;
Reports, grievances, support communications, voluntarily reported Content, screenshots, attachments, and moderation records;
removed or disabled Content and associated records preserved under our policies or Applicable Law;
cyber security logs and incident records;
user verification details where applicable; and
other information under our control or possession.
Availability of information depends on retention, deletion, technical feasibility, encryption design, and Applicable Law.
5.6 Information that may not be available due to E2EE
For supported end-to-end encrypted private one-to-one chats and supported group chats, we do not have routine access to plaintext message content. We cannot provide plaintext private message content that we do not possess. We cannot decrypt supported E2EE messages on demand if we do not hold the necessary keys. We do not create or provide encryption backdoors.
We may provide information that is lawfully available to us, such as metadata, account information, encrypted payloads where retained, logs, group information, support records, and voluntarily reported Content. If a User has reported a message, the reported message or media may be available to us because the reporting User voluntarily submitted it for review.
5.7 Response timelines
We will respond to lawful requests within timelines required by Applicable Law. This may include:
providing information under our control or possession, or assistance to a lawfully authorised government agency, as soon as possible and not later than seventy-two hours after receipt of a valid written order, where applicable;
removing or disabling access to unlawful information within three hours of actual knowledge arising from a valid court order or reasoned written intimation by an authorised government officer, where Applicable Law requires;
reporting applicable cyber security incidents to CERT-In within six hours of noticing the incident or being brought to notice, where CERT-In directions apply;
preserving removed or disabled Content and associated records for one hundred and eighty days or longer where required; and
complying with specific deadlines in court orders, government directions, or CERT-In directions, subject to legal and technical feasibility.
5.8 Takedown and actual knowledge requests
Requests to remove or disable access to information should include:
the legal basis and statutory provision invoked;
the nature of the unlawful act;
the specific URL, message ID, group ID, channel ID, file identifier, Account identifier, or other electronic location;
the exact scope of requested action;
the name, designation, authority, and contact details of the requesting officer or court;
any required authorisation or review record; and
the deadline and legal consequence of non-compliance.
Where actual knowledge arises in the manner recognised by Applicable Law, we will remove or disable access to the specified information within the applicable timeline to the extent the information is hosted, stored, published, transmitted, or otherwise under our control.
5.9 Section 69 and first-originator requests
If we are required as an SSMI providing messaging services to enable identification of the first originator of information, we will process such requests only where permitted under Applicable Law. Such requests must be supported by a judicial order passed by a court of competent jurisdiction or an order passed under Section 69 by the Competent Authority under the applicable procedure and safeguards.
Such orders may be processed only for legally permitted purposes, including prevention, detection, investigation, prosecution, or punishment of offences relating to sovereignty and integrity of India, security of the State, friendly relations with foreign States, public order, incitement to such offences, or offences relating to rape, sexually explicit material, or child sexual abuse material punishable with imprisonment for a term of not less than five years.
We may reject, challenge, or seek clarification of requests where less intrusive means appear effective, the request is not legally valid, the scope is overbroad, the required information is unavailable, or the request is inconsistent with Applicable Law.
Compliance with a valid first-originator order does not require us to disclose the contents of any electronic message, information related to other Users, or information beyond what Applicable Law requires.
5.10 Preservation of evidence
We may preserve Content, encrypted payloads, metadata, Account information, logs, Reports, moderation records, and associated records when:
a valid preservation request is received;
Content is removed or disabled under the IT Rules;
a grievance, lawful request, or investigation requires preservation;
child safety, cyber security, public order, or serious harm is involved;
an internal investigation is pending; or
Applicable Law requires retention.
Preserved information may be retained for at least one hundred and eighty days for investigation purposes, or longer where required by a court, government agency, law enforcement authority, CERT-In, or Applicable Law. We aim to preserve evidence without alteration or vitiation and with appropriate access controls.
5.11 Emergency requests
Where there is an imminent risk of death, serious physical harm, child sexual exploitation, serious cyber security incident, or other urgent threat, authorised law enforcement may submit an emergency request to law.enforcement@rabcorp.co.in with the subject line “EMERGENCY LAW ENFORCEMENT REQUEST”.
Emergency requests should include the nature of emergency, specific identifiers, information requested, legal authority, officer identity, contact details, and certification that the request is made in good faith due to imminent harm. We may disclose limited information in good faith where permitted by Applicable Law and may require follow-up legal process.
5.12 Notice to Users
We may notify Users about requests for their information where legally permitted and reasonably appropriate. We may withhold notice where prohibited by law, court order, government direction, risk of harm, child safety concern, cyber security need, or risk to an investigation.
5.13 Data minimisation and proportionality
We aim to disclose only information that is responsive to a valid request and within our control or possession. We may narrow, challenge, or seek clarification of overbroad requests. We may redact unrelated information, protect third-party privacy, and maintain records of disclosures.
5.14 CERT-In and cyber security cooperation
We will comply with applicable CERT-In directions, including designation of a Point of Contact where required, reporting of specified cyber incidents within applicable timelines, providing information or assistance when lawfully directed, synchronising relevant systems as required, and maintaining ICT logs securely for the required period within Indian jurisdiction where applicable.
5.15 Transparency reporting
We may publish periodic transparency or compliance reports, subject to Applicable Law and confidentiality restrictions. Reports may include aggregate numbers of grievances, law enforcement requests, government requests, takedown requests, appeals, content actions, child safety actions, and proactive or technical moderation actions where applicable.
We will not include sensitive investigative information, personal data, or legally restricted details in public transparency reports.
5.16 Costs
Where permitted by Applicable Law, we may seek reimbursement for costs associated with responding to unusually burdensome, broad, repetitive, or technically complex requests. We will not use cost recovery to obstruct valid urgent safety requests.
5.17 Contact details
Law enforcement email: law.enforcement@rabcorp.co.in Grievance Officer: Ashish Bhawkar, Ashish.bhawkar@rabcorp.co.in CERT-In / cyber security point of contact: 9881241327 Postal address: B401 Ashwini Paradise, Gangadham chowk Kondhwa Bibvewadi road Pune 37
03 April 2026