Back to HomeSavnex

Privacy Policy

Governing the collection, use, storage, sharing, and protection of your personal data

Effective Date: 1 April 2026

At a Glance โ€” Privacy Summary

This summary is for convenience only. The full legal text below prevails in all cases.

๐Ÿšซ

Do we sell your data?

No. Never.

๐Ÿ“ต

Do we serve ads?

No. The Platform is ad-free.

๐Ÿชช

Do we store your Aadhaar photograph?

No. Used only during face-match KYC and discarded immediately.

๐Ÿ”

Do we store your biometric data?

No. Matching on your device only. We receive only pass/fail.

๐Ÿ”’

Do we store your UPI PIN or bank password?

No. These never pass through our servers.

๐Ÿข

Who is the Data Fiduciary?

Savnex Private Limited (CIN: U62090PB2026PTC066988)

๐Ÿ‘ค

Who is the Privacy Officer?

Varinder Rajoria โ€” [email protected]

๐Ÿ“‹

Who is the Grievance Officer?

Varinder Rajoria โ€” [email protected] โ€” Response within 48 hours

โš–๏ธ

What law governs?

DPDPA 2023, IT Act 2000, and all applicable Indian law

๐Ÿ‡ฎ๐Ÿ‡ณ

Where is data stored?

India only โ€” all servers physically located within India

1. Company Identification and Data Fiduciary

Savnex Private Limited, a company incorporated under the Companies Act 2013, bearing CIN U62090PB2026PTC066988, with its registered office at F279, Industrial Area Phase 8B, Mohali, Punjab โ€” 160071, India ('Savnex', 'we', 'us', 'our'), is the Data Fiduciary as defined under the Digital Personal Data Protection Act 2023 ('DPDPA') in respect of all personal data collected through the Savnex mobile application and associated services (collectively, the 'Platform').

Technology support: Knotsync Private Limited is an IT services company that provides development and operational support to Savnex during its startup phase. The directors of Savnex Private Limited and Knotsync Private Limited are the same individuals. Knotsync does not independently process personal data for its own purposes; any data access is strictly in its capacity as a technical service provider to Savnex under a data processing arrangement.

Regulated service providers: UPI payments and PPI wallet services are provided by Zwitch, an RBI-regulated payment infrastructure provider. BBPS bill settlement services are provided by Setu, an RBI-authorised BBPS aggregator. All regulated financial activity flows exclusively through these licensed partners.

RoleDetails
Privacy OfficerVarinder Rajoria | [email protected] | Monโ€“Fri, 10:00โ€“18:00 IST
Grievance OfficerVarinder Rajoria | [email protected] | Acknowledge 48 hrs, resolve 30 days
Legal Notices[email protected]
General Support[email protected]
PostalVarinder Rajoria, Savnex Private Limited, F279, Industrial Area Phase 8B, Mohali, Punjab โ€” 160071, India

2. Scope and Applicability

This Privacy Policy applies to:

  • All individuals who register a personal account on the Platform, whether in LIGHT state (phone + OTP only) or FULL_KYC state.
  • All merchants and business account holders, including persons holding OWNER, MANAGER, CASHIER, or VIEW_ONLY roles.
  • All visitors to any Savnex website, support portal, or other touchpoint operated by Savnex.
  • All data processors, sub-processors, and third-party partners who process personal data on Savnex's behalf under a Data Processing Agreement.

This Policy does not apply to third-party websites, applications, or services that may be linked from the Platform.

This Policy is to be read alongside Terms and Conditions, Financial Disclaimer, which together constitute the complete legal framework governing your relationship with Savnex.

3. Personal Data We Collect

3.1 Data You Provide

CategorySpecific DataPurposeLegal Basis
Account RegistrationMobile number, full name, preferred languageAccount creation, authenticationConsent
Personal eKYCPAN, Aadhaar (last 4 digits stored), DOB, gender, address, bank account, IFSC, face liveness resultRBI-mandated KYC; fraud preventionLegal obligation + Consent
Business eKYC / KYBBusiness name, entity type, CIN, GSTIN, Udyam number, registered address, business bank accountMerchant onboarding, KYB complianceLegal obligation + Consent
Payment DataUPI VPA, transaction amounts, merchant/customer IDs, BBPS consumer numbersProcessing payments; regulatory reportingContract + Legal obligation
Support CommunicationsMessages, complaint details, feedbackCustomer support; grievance redressalLegitimate use + Consent

3.2 Data Collected Automatically

  • Device identifiers (device ID, OS version, app version) โ€” for security and crash resolution.
  • IP address and approximate location (city/region level, not precise GPS) โ€” for fraud detection and regulatory compliance.
  • In-app event logs โ€” for internal analytics and product improvement.
  • Firebase FCM token โ€” for push notification delivery.
  • Session data (login time, duration, method, logout) โ€” for security monitoring.

3.3 Data We Expressly Do NOT Collect or Store

The following data is never collected, transmitted to, or stored on Savnex servers:

  • Aadhaar photograph โ€” used only transiently during face-match; discarded immediately.
  • Full Aadhaar number โ€” only last 4 digits stored.
  • UPI PIN or bank passwords โ€” never pass through our servers.
  • Biometric raw dataโ€” matching occurs on your device's secure enclave only.
  • Precise GPS location โ€” only city/region for fraud detection.

4. How We Use Your Personal Data

PurposeData UsedLegal Basis
Account creation and OTP authenticationMobile number, name, device IDContract + Consent
KYC / eKYC verificationPAN, Aadhaar OTP eKYC data, liveness result, face match scoreLegal obligation (RBI KYC Master Directions)
Processing UPI paymentsUPI VPA, transaction amount, merchant IDContract + Legal obligation
Bilateral ledger operationsEntry data, acknowledgment timestamps, user IDsContract + Legal obligation
Fraud detectionDevice ID, IP, transaction patterns, session dataLegitimate use + Legal obligation
Regulatory compliance and auditAll financial transaction data, KYC recordsLegal obligation (PMLA, RBI, IT Act, DPDPA)
Product analyticsAnonymised/aggregated event dataLegitimate use

5. Data Sharing and Disclosure

Savnex does not sell personal data. Savnex does not allow advertising networks to collect data from the Platform. Data is shared only as set out below.

CategoryProvider / PartnerPurposeSafeguard
KYC / eKYC ProviderThird-party eKYC provider (disclosed at go-live)PAN verification, Aadhaar OTP eKYC, liveness checkDPDPA-compliant DPA; UIDAI-licensed AUA/KUA
UPI payments and PPI WalletZwitch (RBI-regulated)UPI QR generation, payment processing, PPI wallet management, vault virtual accountsDPA in place; operates under PSS Act 2007 licences
BBPS bill settlementSetu (RBI-authorised BBPS aggregator)Biller fetch, bill payment initiation, payment status webhooksDPA in place; operates under NPCI BBPS framework
Technology / operational supportKnotsync Private LimitedDevelopment support, technical infrastructure โ€” no independent data processing for own purposesInternal data processing arrangement; same director oversight
Cloud InfrastructureCloud provider (India region)Server hosting, database, backupIndia data residency; encryption at rest and in transit

5.2 Regulatory Disclosure

We may disclose personal data without your prior consent where required by law, including to RBI, FIU-IND (PMLA), CERT-In, and NPCI.

6. Data Retention

  • Financial records: 8 years (Companies Act Section 128).
  • KYC records: 5 years after account closure (RBI KYC Master Directions).
  • Server logs: 180 days (CERT-In Directions 2022).
  • Analytics data: Anonymised and aggregated; retained indefinitely.

7. Data Security

  • AES-256 encryption at rest for all personal data.
  • TLS 1.2 / 1.3 for all data in transit.
  • Mandatory CERT-In breach notification within 6 hours of confirmed breach.
  • Periodic vulnerability assessments and penetration testing.

8. Your Rights (DPDPA)

  • Access: Request a copy of your personal data.
  • Correction: Request correction of inaccurate data.
  • Erasure: Request deletion, subject to legal retention obligations.
  • Consent Withdrawal: Withdraw consent at any time via [email protected].
  • Grievance: File a grievance with our Grievance Officer. If unresolved within 30 days, escalate to the Data Protection Board of India.

9. Consent Framework

By registering on the Platform, you provide specific, informed, and unambiguous consent to the processing of your personal data as described in this Policy. KYC data is processed under legal obligation. You may withdraw consent at any time by contacting [email protected]. Withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.

10. Children's Privacy

The Platform is not intended for persons under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected personal data from a child, we will delete it promptly. If you believe a child has provided personal data, contact [email protected].

11. Cross-Border Transfers

All personal data is stored in India. We do not transfer personal data outside India. If future operations require cross-border transfer, it will be done only in compliance with DPDPA provisions and RBI data localisation requirements.

12. Updates to this Policy

We may update this Policy from time to time. Material changes will be notified via in-app notification and SMS 30 days before the effective date of the updated Policy. Continued use of the Platform after the effective date constitutes acceptance.

13. Grievance Redressal

Grievance Officer: Varinder Rajoria | [email protected] | Acknowledge within 48 hours, resolve within 30 days. If unresolved, you may approach the Data Protection Board of India.

Last updated: 1 April 2026 | Version 2.0

Savnex Private Limited | CIN: U62090PB2026PTC066988