Bankys Logo
Bankys Logo
Legal

Privacy Policy

Last Updated: January 2025

1. Introduction

Bankys ("we," "us," or "our") is committed to protecting your privacy and personal data. As a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) and in compliance with the Reserve Bank of India (RBI) guidelines for financial institutions, we process your personal data with the highest standards of security and transparency.

This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our services, including our mobile application, website, and related financial services (collectively, "Services").

2. Information We Collect

2.1 Personal Information

We collect the following categories of personal data:

  • Identity Data: Full name, date of birth, PAN, Aadhaar number (as required by KYC regulations)
  • Contact Data: Email address, mobile number, residential address
  • Financial Data: Bank account details, UPI information, transaction history, income details, spending patterns
  • Technical Data: IP address, device information, browser type, operating system, usage patterns
  • Biometric Data: Only where explicitly permitted by law and with your explicit consent

2.2 Purpose Limitation

We collect only the personal data that is necessary for the specific purposes disclosed to you at the time of collection, in compliance with the principle of purpose limitation under the DPDP Act.

3. How We Use Your Information

We use your personal data for the following purposes:

  • Service Delivery: To provide, maintain, and improve our financial services, including account management, transaction processing, and personalized financial insights
  • Regulatory Compliance: To comply with KYC requirements, anti-money laundering (AML) regulations, and other legal obligations under RBI guidelines
  • Risk Management: To assess creditworthiness, prevent fraud, and manage financial risks
  • Communication: To send you important updates, service notifications, and respond to your inquiries
  • Marketing: Only with your explicit consent, to send you promotional communications about our services
  • Analytics: To analyze usage patterns and improve our Services (using anonymized or pseudonymized data where possible)

4. Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Consent: Your explicit, informed, and unambiguous consent for specific purposes
  • Legitimate Interest: For fraud prevention, security, and service improvement (where permitted by law)
  • Legal Obligation: To comply with applicable laws, including RBI regulations, KYC/AML requirements, and tax laws
  • Contract Performance: To fulfill our contractual obligations to provide financial services

5. Data Sharing and Disclosure

We do not sell your personal data. We may share your data only in the following circumstances:

  • Service Providers: With trusted third-party service providers who assist us in operating our Services (e.g., cloud storage, payment processors), subject to strict contractual obligations
  • Regulatory Authorities: As required by law, including RBI, Income Tax Department, and other government agencies
  • Credit Bureaus: To report credit information as required by RBI regulations
  • Legal Requirements: When required by court orders, legal processes, or to protect our rights and the safety of our users
  • Business Transfers: In connection with a merger, acquisition, or sale of assets (with prior notice)

All third parties are contractually bound to maintain the confidentiality and security of your data and use it only for the specified purposes.

6. Data Storage and Security

6.1 Data Localization

In compliance with RBI guidelines and the DPDP Act, your personal data is primarily stored on servers located in India. Where data is processed outside India, we ensure appropriate safeguards and contractual protections are in place.

6.2 Security Measures

We implement industry-standard technical and organizational measures to protect your data:

  • End-to-end encryption for sensitive data
  • Multi-factor authentication and access controls
  • Regular security audits and vulnerability assessments
  • Pseudonymization and data masking where appropriate
  • Secure data transmission using TLS/SSL protocols
  • Regular backups and disaster recovery procedures

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by law:

  • Active Accounts: For the duration of your account and up to 7 years after account closure (as required by RBI regulations)
  • KYC Documents: As per RBI guidelines, for the duration of the business relationship and 5 years thereafter
  • Transaction Records: Minimum 5 years as required by banking regulations
  • Marketing Data: Until you withdraw consent or opt-out

Upon expiry of the retention period, we securely delete or anonymize your data in accordance with applicable laws.

8. Your Rights

As a Data Principal under the DPDP Act, you have the following rights:

  • Right to Access: Request a copy of your personal data we hold
  • Right to Correction: Request correction of inaccurate or incomplete data
  • Right to Erasure: Request deletion of your data (subject to legal and regulatory retention requirements)
  • Right to Withdraw Consent: Withdraw your consent at any time, as easily as you gave it
  • Right to Grievance Redressal: File a complaint with our Grievance Officer or the Data Protection Board of India
  • Right to Nominate: Nominate another person to exercise your rights in case of death or incapacity

To exercise these rights, please contact us at privacy @ bankys.in . We will respond to your request within 30 days.

9. Children's Privacy

Our Services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

10. Data Breach Notification

In the event of a data breach that may cause harm to you, we will:

  • Notify the Data Protection Board of India without undue delay (within 72 hours of becoming aware)
  • Notify affected users without undue delay
  • Take immediate remedial measures to contain and mitigate the breach
  • Provide clear information about the nature of the breach and steps being taken

11. Grievance Redressal

If you have any concerns or complaints regarding our data processing practices, you may contact:

Grievance Officer

Bankys

Email: grievance @ bankys.in

You also have the right to file a complaint with the Data Protection Board of India if you are not satisfied with our response.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Posting the updated policy on our website
  • Sending you an email notification (if you have an account)
  • Displaying a prominent notice in our application

Your continued use of our Services after such notification constitutes acceptance of the updated policy.

13. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us at:

Bankys

Email: privacy @ bankys.in

Website: www.bankys.in