Telecom Compliance & KYC
LAST UPDATED · 22 JUNE 2026
Hello by Flow operates within India's telecom regulatory framework. This page summarises the compliance regime that applies to the Service and to you as a subscriber.
Regulators we comply with
- Department of Telecommunications (DoT), Ministry of Communications, Government of India — licensing, lawful interception, subscriber verification.
- Telecom Regulatory Authority of India (TRAI) — quality of service, consumer protection, anti-spam (TCCCPR 2018).
- Indian Computer Emergency Response Team (CERT-In) — incident reporting under CERT-In Directions 2022.
- Ministry of Electronics & IT (MeitY) — IT Act 2000, intermediary guidelines, DPDPA 2023.
KYC — what we collect and why
Under DoT's Subscriber Verification Guidelines and Customer Acquisition Form (CAF) requirements, every phone number issued in India must be tied to a verified subscriber.
Business subscribers
- Certificate of Incorporation (MCA) or partnership deed.
- GSTIN or PAN of the entity.
- Government-issued ID of the Authorised Signatory.
- Board resolution / authorisation letter (for accounts with more than 10 lines).
- Registered address proof.
Individual subscribers
- One of: Aadhaar (offline-XML preferred), Passport, Driving Licence, Voter ID, NREGA Job Card.
- For Aadhaar — only the masked variant (last 4 digits visible) is retained.
- Optional live selfie for face match (recommended).
- Current address proof if different from ID.
Verification process
Documents are checked for: (a) tamper detection, (b) cross-validation with issuing authority APIs where available (UIDAI, MCA, NSDL), (c) sanctions/PEP screening, (d) face match against the selfie. Approved within seconds for clean submissions; flagged ones go through manual review.
Lawful interception & disclosure
Under Section 5(2) of the Indian Telegraph Act, 1885 and the IT Act, 2000, we are legally required to provide call detail records and content to authorised Law Enforcement Agencies on receipt of a properly issued order. We do not provide bulk access. Every request is logged and reviewed by our DPO.
Data localisation
Subscriber data and CDRs for Indian numbers are stored on infrastructure located within India per the National Telecom Policy. Cross-border processing is restricted to anonymised metadata.
CERT-In incident reporting
We report cyber security incidents to CERT-In within 6 hours per the 28 April 2022 directions.
Numbering plan
Hello by Flow numbers in India are allocated from the DoT-approved numbering blocks. Mobile (10-digit), landline (with city code), and 1800-toll-free series are supported.
Anti-spam (TCCCPR 2018)
All promotional traffic is templatised, header-registered, and consent-scrubbed via the DLT (Distributed Ledger Technology) registries operated by access providers. Unregistered promotional traffic is blocked at the network edge.
Contact
Compliance Officer: compliance@hellobyflow.com
Nodal Officer (24×7): nodal@hellobyflow.com
