Privacy Policy

Document Version: 1.0

Effective Date: June 2026

 1. Introduction

This Data Privacy Notice sets out the requirements for ensuring that Gatipay Technologies Private Limited (“Gatipay”, “we”, “us”, “the website”) collects, uses, handles, retains and discloses personal information in a fair, transparent, and secured way. This notice is applicable to the personal information (including sensitive personal data or information) of all interested parties interacting with our web domain, including customers, partners, job applicants, and third-party vendors.

 2. Objective

This notice provides operational guidance on the processing of personal information—which includes collecting, using, storing, and disclosing such information by Gatipay as necessary to conduct our fintech services and authorized business activities.

 3. Lawful Basis and Data Collection

Only personal information required for authorized business activities shall be collected from the information provider. Gatipay collects and processes personal information strictly where a valid lawful basis exists, primarily through explicit, affirmative consent provided by you at the point of data submission. We do not rely on implied or inferred consent through mere website navigation. You must keep your personal information up to date and intimate to Gatipay of any material changes.

We collect the following types of information:

  • Information you give us directly: Depending on the specific service or facility you request, you may provide detailed personal, financial, and statutory information through web forms, portals, or application dashboards, including:
    • Identity & Demographic Data: Full name, age, date of birth (DOB), gender, and contact details (email address and phone number). 
    • Financial & Transactional Data: Bank account details (including account numbers and IFSC codes), debit/credit card information, financial statements, income details, and business-related transactional history.
    • Statutory & Regulatory Data: Permanent Account Number (PAN), Goods and Services Tax (GST) details, and official valid documents (OVDs) submitted for Know Your Customer (KYC) verification and credit evaluation.
  • Information you give us voluntarily: Additional details provided when you submit feedback, modify email preferences, respond to surveys, or communicate directly with our teams.
  • Information collected automatically: Technical data stored automatically during your visit, such as your Internet Protocol (IP) address, approximate device location, browser type, and interaction metrics (e.g., pages viewed, time spent). We utilize cookies and unique identifiers to optimize user experience and evaluate website ergonomics.

4. Use of Personal Information

Gatipay processes the collected personal and sensitive financial data only for explicit, specified purposes where a valid lawful basis exists. The granularity of our processing activities includes, but is not limited to, the following functional areas:

  • Core Service Delivery & Processing: To register your user profile, administer financial products, route transactions safely, verify multi-party settlement instructions, and manage ongoing digital fintech service delivery.
  • Credit Underwriting, Risk Assessment & Scoring: To assess creditworthiness, calculate risk scores, determine financial eligibility criteria, verify capabilities to handle financial limits, and prevent credit default across our platform offerings.
  • Identity Verification & Statutory Compliance: To fulfill mandatory regulatory obligations including Know Your Customer (KYC) guidelines, Anti-Money Laundering (AML) checks, Combating the Financing of Terrorism (CFT) tracking, and verification of PAN/GST credentials against official central government databases.
  • Fraud Prevention, Detection, and Security Operations: To continually monitor system logs, authenticate digital signatures/access tokens, investigate suspicious or anomalous transactions, protect our infrastructure against cybersecurity incidents, and combat identity theft, fraud, or electronic financial crimes.
  • Regulatory Reporting & Legal Obligations: To compile and submit mandated disclosures, financial tracking sheets, and suspicious transaction reports (STRs) to regulatory, statutory, or judicial authorities—including but not limited to the Reserve Bank of India (RBI), Financial Intelligence Unit-India (FIU-IND), and tax authorities.
  • Operational Communications & System Maintenance: To process, log, and respond to your direct service queries or technical support requests; to resolve platform disputes; to enforce our corporate terms, conditions, and user policies; and to push essential security updates or changes to our financial products.

5. Security and Transit of Information

Gatipay implements reasonable physical, electronic, and managerial security practices and procedures as mandated under applicable Indian laws to safeguard data under our direct infrastructure control. Information provided directly to us is processed and retained via secure cloud servers.

However, you acknowledge that data transmission over the public internet carries inherent global routing risks. Gatipay disclaims liability for data exposure resulting from transmission errors, network interceptions, or unauthorized third-party actions occurring entirely outside Gatipay’s reasonable control and technical network perimeter.

6. Disclosure of Information

The information provided by you may be disclosed in limited, authorized circumstances to:

  • Our professional advisers, including accountants, auditors, and legal counsel on a need-to-know basis.
  • Government, statutory, regulatory, and law enforcement authorities as explicitly required or authorized under prevailing Indian laws.
  • Third-party technical service providers working on our behalf under binding confidentiality agreements that restrict further data disclosure or independent processing.
  • With financial institutions and Financial Partners (including but not limited to banks and Non-Banking Financial Companies), credit information companies, RBI or other regulatory agencies, to facilitate provision of Services, or as may be required under Applicable Laws

 7. Retention of Information

Gatipay shall not retain or store personal information for periods longer than is required for the fulfillment of authorized business purposes, except when the information may lawfully be used or is otherwise required under any prevailing statutory law in force. Post expiry of the retention period, data is securely disposed of or structurally de-identified to ensure permanent anonymity.

 8. Data Principal Rights (Under DPDP Act 2023)

Gatipay respects and accommodates your statutory rights as a Data Principal under Indian law:

  • Right to Correction and Erasure: You have the right to review, correct, update, or request the erasure of any personal information found to be inaccurate, outdated, or deficient.
  • Right to Seek Information: You may request a summary of your specific personal data being processed by Gatipay along with the description of processing activities undertaken.
  • Right to Grievance Redressal: You have a right to raise a complaint or grievance regarding data processing directly with the organization’s designated grievance channel.
  • Right to Withdraw Consent: You may withdraw your consent for data processing at any time by writing to us. If you choose not to provide or subsequently withdraw consent, Gatipay reserves the option to cease providing services for which that specific information was mandated.

 9. Grievance Redressal & Contact Us

Gatipay has established a structured grievance redressal mechanism to address data concerns promptly. If you require any clarifications regarding your personal data, wish to exercise your legal data rights, or have a grievance regarding our data practices, please contact our designated officer at:

Data Protection & Grievance Officer

Gatipay Technologies Private Limited

Email: dpo@gatipay.in