PRIVACY
Legal

Privacy Policy

We are committed to protecting your privacy and the privacy of your customers. This policy explains exactly what data we collect, why we collect it, and how we keep it safe.

Effective: 1 January 2025 Last Updated: 14 May 2025 GDPR & PDPB Aligned
01

Overview

Code Crafts Digisoft Pvt. Ltd. ("we", "our", or "us") operates a B2B financial technology platform that enables partners — retailers, distributors, and API integrators — to offer banking, payment, and remittance services across India.

This Privacy Policy applies to:

  • Our registered partners and their authorised users who access the platform.
  • End-customers whose transaction data is processed through our platform on behalf of partners.
  • Visitors to our website at codecraftsdigisoft.com.
ℹ️ Data Fiduciary

Under India's Digital Personal Data Protection Act 2023 (DPDPA), Code Crafts Digisoft acts as a "Data Fiduciary" for partner data and a "Data Processor" for end-customer data processed on behalf of partners. Partners remain the Data Fiduciary for their customers' data.

02

Data We Collect

We collect the following categories of personal and business data:

Category Examples Source
Partner Identity Business name, owner name, PAN, GSTIN, Aadhaar (masked) Provided by partner during KYC
Contact Data Email, mobile number, registered address, office address Provided by partner
Financial Data Bank account details, IFSC code, wallet balance, transaction history Provided & generated through use
End-Customer Data Mobile number, Aadhaar number (encrypted), account number, transaction amount Transmitted via API during transaction
Device & Usage IP address, device fingerprint, browser type, API endpoint calls, timestamps Automatically collected
Communications Support tickets, chat messages, emails, call recordings (with consent) Generated during support interactions

We do not collect full Aadhaar numbers. Only the last 4 digits are stored where required for transaction reference. Full biometric data (fingerprints) is never stored by us — it is processed in real-time by UIDAI's authentication servers.

03

How We Use Your Data

We use the data we collect for the following purposes:

  • Platform Operations: Processing transactions, settlement of commissions, generating reports, and providing dashboard analytics.
  • KYC & Compliance: Verifying partner identity, conducting due diligence, and fulfilling regulatory reporting obligations under RBI, NPCI, and UIDAI guidelines.
  • Fraud Prevention: Detecting unusual patterns, flagging suspicious transactions, and preventing financial crime.
  • Customer Support: Responding to queries, resolving disputes, and improving service quality.
  • Security: Protecting platform integrity through authentication, access controls, and intrusion detection.
  • Communications: Sending transaction alerts, settlement notifications, product updates, and promotional communications (with consent where required).
  • Product Improvement: Analysing aggregated usage patterns to improve platform features and performance. This analysis is always performed on anonymised or pseudonymised data.
  • Legal Obligations: Maintaining records as required by law and responding to lawful requests from regulatory authorities.

We do not use your data for automated decision-making that produces legal or similarly significant effects without human review.

04

Legal Basis for Processing

We process personal data on the following legal bases under applicable Indian and international data protection law:

  • Contract Performance: Processing necessary to fulfill our obligations under the Partner Agreement, including transaction processing and settlement.
  • Legal Obligation: Processing required to comply with applicable laws including PMLA, RBI directions, UIDAI regulations, and tax laws.
  • Legitimate Interests: Fraud prevention, platform security, and improving our services — where these interests are not overridden by your rights.
  • Consent: Marketing communications and optional analytics features. You may withdraw consent at any time without affecting prior processing.
ℹ️ Sensitive Data

Financial account data and transaction records are classified as sensitive personal data under IT (Reasonable Security Practices) Rules 2011. We apply enhanced security controls and access restrictions for such data.

05

Data Sharing & Disclosure

We share your data only in the following circumstances and with the following categories of recipients:

  • Banking Partners: Data is shared with our empanelled banks and Business Correspondent networks strictly to process transactions you initiate. Banks are bound by RBI data protection guidelines.
  • NPCI / UIDAI: Transaction data is transmitted to NPCI for IMPS, BBPS, and UPI processing, and to UIDAI for Aadhaar authentication. Both are statutory bodies with their own data protection obligations.
  • Technology Sub-processors: We use cloud infrastructure providers, SMS gateways, and analytics tools that may process limited data on our behalf. All sub-processors are contractually bound to our data protection standards and process data only on our instructions.
  • Regulatory Authorities: We will disclose data to the RBI, UIDAI, NPCI, income tax authorities, FIU-IND, or any other lawful authority upon receipt of a valid legal direction.
  • Audit & Legal: Our statutory auditors and legal advisors may access data strictly under professional privilege obligations.
⚠️ No Sale of Data

We do not sell, rent, or trade your personal data or your customers' data to any third party for commercial purposes. Ever. This is a core commitment of Code Crafts Digisoft.

Cross-border transfers: All data is stored and processed within India. We do not transfer personal data outside India unless required by applicable law and with appropriate safeguards in place.

06

Aadhaar & Biometric Data

Our AEPS, Aadhaar Pay, and cash deposit services use Aadhaar-based biometric authentication. We treat this data with the highest level of sensitivity:

  • Biometric data (fingerprints) is captured at the Point of Sale device and transmitted directly to UIDAI's authentication servers over encrypted channels. We never store biometric data on our servers.
  • Aadhaar numbers transmitted through our API are encrypted using AES-256 encryption at the source and are masked (showing only the last 4 digits) in all logs and records.
  • Aadhaar authentication is performed solely for the purpose of the financial transaction requested and for no other purpose.
  • We comply strictly with the Aadhaar Act 2016 and all UIDAI circulars governing AUA/KUA usage.
  • Any attempt to use our platform to harvest, store, or misuse Aadhaar data will result in immediate termination and referral to UIDAI and law enforcement.
⚠️ Legal Notice

Unauthorised collection, storage, or use of Aadhaar data is a criminal offence punishable under Section 29 of the Aadhaar Act 2016, with imprisonment of up to 3 years and fines up to ₹10 lakh. Partners misusing Aadhaar data through our platform will face immediate legal action.

07

Cookies & Tracking Technologies

Our website and partner dashboard use cookies and similar technologies for the following purposes:

Cookie Type Purpose Duration
Essential Session management, authentication, CSRF protection Session / 24 hours
Functional Remembering preferences, language settings, dashboard layout 30 days
Analytics Understanding which features are used (aggregated, anonymised) 90 days
Marketing Showing relevant content on our website (only with consent) 90 days

Essential cookies cannot be disabled as they are required for the platform to function. For all other cookies, you can manage your preferences through your browser settings or our cookie consent banner.

Our APIs do not use cookies. API authentication is handled exclusively through API keys and JWT tokens transmitted in request headers.

08

Data Security

We implement bank-grade security controls to protect your data:

  • Encryption in Transit: All data transmitted between your systems and ours uses TLS 1.2 or higher. API endpoints enforce HTTPS exclusively.
  • Encryption at Rest: Sensitive fields in our database are encrypted using AES-256. Database-level encryption is also applied.
  • Access Control: Data access follows the principle of least privilege. Staff access to production data requires multi-factor authentication and is logged and audited.
  • Vulnerability Management: We conduct regular penetration testing and vulnerability assessments. Critical vulnerabilities are patched within 24 hours of discovery.
  • Data Segregation: Partner data is logically segregated. Your data is never accessible to other partners.
  • Incident Response: We maintain a documented incident response plan. In case of a data breach affecting you, we will notify you within 72 hours of discovery as required by applicable law.
ℹ️ Responsible Disclosure

If you discover a security vulnerability in our platform, please report it responsibly to [email protected]. We commit to acknowledging all reports within 24 hours and working with you to resolve valid vulnerabilities promptly.

09

Data Retention

We retain data for the minimum period necessary to fulfill the purposes described in this policy, comply with legal obligations, and resolve disputes:

Data Type Retention Period Basis
Transaction Records 10 years from transaction date PMLA 2002, RBI guidelines
KYC Documents 5 years after account closure PMLA 2002
Partner Account Data Duration of partnership + 5 years Legal obligation & disputes
Support Communications 3 years Legitimate interests
API Access Logs 2 years Security & fraud investigation
Website Analytics 90 days (aggregated) Legitimate interests
Marketing Preferences Until consent withdrawn + 30 days Consent

After the applicable retention period, data is securely deleted or anonymised using industry-standard methods. You may request early deletion of data not subject to mandatory retention obligations — see Your Rights below.

10

Your Data Rights

Under applicable Indian data protection law and where relevant, GDPR, you have the following rights with respect to your personal data:

  • Right to Access: Request a copy of the personal data we hold about you and information about how it is used.
  • Right to Correction: Request correction of inaccurate or incomplete personal data.
  • Right to Erasure: Request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to legal retention obligations.
  • Right to Data Portability: Request your data in a machine-readable format where technically feasible.
  • Right to Object: Object to processing of your data for marketing or where we rely on legitimate interests, subject to our overriding legitimate grounds.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time. Withdrawal does not affect prior processing.
  • Right to Lodge a Complaint: File a complaint with the Data Protection Board of India once constituted, or with CERT-In for cybersecurity-related concerns.

To exercise any of these rights, email [email protected] with "Data Rights Request" in the subject line. We will respond within 30 days. We may need to verify your identity before processing your request.

⚠️ Limitations

Certain data cannot be deleted due to mandatory regulatory retention requirements (see Retention section). We will always tell you if a deletion request cannot be fully honoured and the reason why.

11

Children's Privacy

Our platform is a B2B service intended solely for registered business entities and their adult representatives. We do not knowingly collect personal data from individuals under the age of 18.

If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected] and we will delete it promptly.

Partners must not process transactions on behalf of minors and must ensure their agent networks comply with age verification requirements.

12

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send a notification to your registered email address for significant changes.
  • Display a prominent notice on the partner dashboard for 30 days after a significant update.

Your continued use of the platform after changes take effect constitutes acceptance of the revised policy. If you disagree with a material change, you may terminate your partnership in accordance with the Terms & Conditions.

13

Contact & Grievance Officer

For any privacy-related queries, data rights requests, or concerns, please contact us:

  • Privacy Email:[email protected]
  • Address: 409, 4th floor, Shipra Path, Mansarovar, Jaipur Rajasthan, India - 302020
ℹ️ Grievance Officer

As mandated under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, we have appointed a Grievance Officer. Privacy complaints must be acknowledged within 24 hours and resolved within 15 days of receipt. Contact details are available on our Contact page.

We take every privacy concern seriously. Our goal is not just legal compliance but genuine respect for the trust you and your customers place in us.

Your privacy is our priority.

Have questions about how we handle your data? Our privacy team responds within 24 hours — always.