Section 01
Introduction
Company Name operates a business-to-business financial technology platform that provides payment processing, financial analytics, compliance tooling, and related services to corporate clients ("Clients") and their authorised users ("Users"). This Privacy Policy applies to all information we collect when you access or use our platform, APIs, websites, or any associated service (collectively, the "Services").
Where our Clients collect and process personal data using our platform, Company Name acts as a data processor on their behalf, and the Client acts as the data controller. For data we collect independently (e.g., account data, usage analytics), Company Name is the data controller. Both scenarios are explained in this document.
By accessing or using our Services, you acknowledge that you have read and understood this Privacy Policy.
Section 02
Data We Collect
We collect information in three ways: data you provide directly, data generated automatically, and data obtained from third parties.
| Category | Examples | Source |
|---|---|---|
| Account & Identity | Name, work email, job title, company name, phone number, government-issued ID (where required for KYC) | Provided by you |
| Financial Data | Bank account details, payment card data (tokenised), transaction records, account balances | Provided by you / payment processors |
| Compliance & KYB/KYC | Corporate registration documents, beneficial owner information, sanctions screening results | Provided by Client / third-party verification providers |
| Usage Data | API call logs, feature usage, session duration, error events, IP address, browser or SDK version | Automatically collected |
| Communication Data | Support tickets, email correspondence, chat transcripts | Provided by you |
| Device & Technical | Device type, operating system, referrer URL, time-zone settings, cookies and similar identifiers | Automatically collected |
We do not knowingly collect or process sensitive categories of personal data (special category data under GDPR) unless mandated by applicable financial regulation.
Section 03
How We Use Data
We use the data we collect for the following purposes:
- Service delivery — to operate, maintain, and provide the features of our platform, including processing payments, generating financial reports, and executing API integrations.
- Account management — to onboard Clients, verify authorised Users, and manage subscriptions and billing.
- Compliance & fraud prevention — to conduct Know Your Business (KYB) and Know Your Customer (KYC) checks, monitor transactions for suspicious activity, and meet anti-money laundering (AML) obligations.
- Security — to detect, prevent, and investigate security incidents, abuse, or unauthorised access.
- Product improvement — to analyse usage patterns, conduct A/B testing, and develop new features.
- Communications — to send transactional notifications, service updates, and (where you have opted in) marketing communications.
- Legal obligations — to comply with applicable laws, respond to regulatory requests, and defend legal claims.
Section 04
Legal Basis for Processing
Where GDPR or equivalent legislation applies, we rely on the following legal bases:
| Legal Basis | Processing Activity |
|---|---|
| Contract | Providing our Services, processing payments, managing your account |
| Legal Obligation | KYC/KYB verification, AML monitoring, regulatory reporting, fraud detection |
| Legitimate Interests | Product analytics, security monitoring, prevention of fraud and abuse |
| Consent | Marketing emails, optional cookies, participation in surveys |
Where we rely on legitimate interests, we balance those interests against your rights and will not override your fundamental privacy interests.
Section 05
Data Sharing
Company Name does not sell your personal data. We share data only in the following circumstances:
- Service providers — cloud hosting, payment processors, KYC providers, fraud detection engines, and customer support tools, all bound by data processing agreements.
- Financial partners — correspondent banks, card schemes, and payment networks where required to complete a transaction.
- Regulatory & law enforcement — where required by applicable law, court order, or financial regulator (e.g., FCA, RBI, MAS).
- Group companies — subsidiaries and affiliates of Company Name for internal operational purposes, under equivalent data protection standards.
- Business transfers — in connection with a merger, acquisition, or sale of assets, with prior notice to you where required by law.
- With your consent — in any other case, only with your explicit consent.
Section 06
International Data Transfers
Our infrastructure is hosted in data centres across India, the European Economic Area (EEA), and the United States. If we transfer your personal data outside your country of residence, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Adequacy decisions recognised by the relevant data protection authority;
- Binding Corporate Rules or other approved transfer mechanisms.
You may request a copy of the applicable safeguards by contacting our Data Protection Officer.
Section 07
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, including legal and regulatory obligations. Typical retention periods are:
- Transaction & financial records — 7 years from the date of transaction (as required by financial regulation in most jurisdictions).
- KYC / KYB documentation — 5 years from the end of the business relationship.
- Account data — duration of the contractual relationship plus 2 years.
- Usage and log data — up to 12 months, after which data is aggregated or deleted.
- Support correspondence — 3 years from closure of the ticket.
After the applicable retention period, personal data is securely deleted or anonymised.
Section 08
Security
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, or destruction. Our security programme includes:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256);
- Role-based access controls (RBAC) and principle of least privilege;
- Regular penetration testing and vulnerability assessments;
- SOC 2 Type II certification (or equivalent) maintained annually;
- Incident response procedures with defined notification timelines.
Section 09
Your Rights
Depending on your jurisdiction, you may have the following rights with respect to your personal data:
- Right of access — obtain a copy of the personal data we hold about you.
- Right to rectification — correct inaccurate or incomplete data.
- Right to erasure — request deletion of your data, subject to legal retention obligations.
- Right to restrict processing — ask us to limit how we use your data.
- Right to data portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint — complain to your local supervisory authority (e.g., India's Data Protection Board, the UK ICO, or an EU DPA).
To exercise any of these rights, submit a request to privacy@companyname.com. We will respond within 30 days (or as otherwise required by applicable law).
Section 10
Cookies
We use cookies and similar tracking technologies on our web properties. For full details on the types of cookies we use and your choices, please see our Cookie Policy.
Section 11
Children
Our Services are directed exclusively at businesses and their authorised personnel. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us immediately and we will delete it.
Section 12
Policy Changes
We may update this Privacy Policy periodically to reflect changes in our practices or applicable law. When we make material changes, we will notify you by email (to the address associated with your account) and by displaying a prominent notice on our platform at least 30 days before the change takes effect.
Your continued use of the Services after the effective date constitutes acceptance of the revised Policy.
Section 13
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy, please contact:
Registered Address: [Registered Office Address], India
Regulatory enquiries: compliance@companyname.com