1. Scope and roles
EXPERIA360 PRIVATE LIMITED operates the technology platform. Depending on the contracted service and data, it may act as a processor or independent controller. Banks, KYC providers and other regulated providers apply their own notices and legal obligations.
2. Information processed
The platform may process organization identity, authorized-user details, KYC and authority evidence, beneficiary and settlement-account information, product requests, support context, device and security events, API activity and audit records. Raw cardholder data is outside the intended application data model.
3. Purposes
Information is used to create and secure tenants, verify organizations and users, evaluate product access, operate approved workflows, prevent misuse, investigate incidents, meet contractual obligations and retain evidence required by law or policy.
4. Sharing
Information is shared only as needed with contracted banks, verification or infrastructure providers, professional advisers, authorities where legally required, and customer-authorized recipients. A logo or integration profile alone does not mean data is shared with that bank.
5. Security and credentials
The intended design encrypts sensitive configuration, masks protected identifiers, scopes requests to a tenant, applies role controls and records privileged actions. Users must never place bank secrets, OTPs or private keys in public forms or browser code.
6. Retention and deletion
Retention must follow the executed customer agreement, legal duties, dispute and fraud requirements, provider terms and documented deletion schedules. Financial and KYC records may not be immediately erasable where retention is legally required.
7. Rights and contact
Applicable rights may include access, correction, grievance handling and other rights under governing law. The production notice must publish a verified privacy or grievance contact and registered corporate particulars before accepting live users.