ARTHAZEYRO TECHNOLOGIES PRIVATE LIMITED ("Company," "Zeyro," "we," "us," or "our"), operates the website and platform available at Zeyro (or such other domain as may be designated by the Company) and any related dashboards, APIs, SDKs, documentation, and developer tools made available in connection therewith (collectively, the "Platform").
This Privacy Policy explains how we collect, use, disclose, transfer, and otherwise process personal data in connection with: (a) your use of the Platform as a Business User, prospective customer, or website visitor; and (b) Zeyro's role as a technology infrastructure provider processing Financial Information on behalf of Business Users in connection with the Services.
This Privacy Policy is drafted with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the Information Technology Act, 2000 and rules made thereunder, and, where applicable, the RBI Account Aggregator framework administered under the Sahamati specification.
By using the Platform, you consent to the collection and processing of information as described in this Privacy Policy. If you do not agree, please do not use the Platform.
1. SCOPE OF THIS POLICY
1.1 This Policy applies to personal data collected by Zeyro through:
the Platform (website, onboarding forms, dashboard, developer console, contact/enquiry forms); and
Zeyro's operation of the Services on behalf of Business Users, to the extent Zeyro processes End User Financial Information as a data processor.
1.2 This Policy does not govern, and Zeyro is not responsible for, the data processing practices of:
Business Users themselves, in respect of how they collect consent from and process data of their own End Users;
Account Aggregators, Financial Information Providers, Financial Information Users, credit bureaus, or GST systems that Business Users integrate with independently; or
any third-party website or service linked from the Platform.
You are encouraged to review the privacy practices of any Business User or third party you interact with separately from Zeyro.
1.3 Zeyro's Services and Platform are intended for use by businesses and their authorized personnel, not by individual consumers for personal use. Where Zeyro processes End User Financial Information on behalf of a Business User, it does so strictly as a data processor, acting on the instructions of that Business User, who remains the data fiduciary/controller responsible for obtaining valid consent from its End Users.
2. INFORMATION WE COLLECT
2.1 Information Collected Directly From You (Business Users, Website Visitors)
Name, work email, phone number, job title
Company name, company size, industry, company website
Onboarding responses (use case, data sources of interest, deployment preference, expected API usage)
Account credentials, API keys, workspace configuration
Billing and payment information (processed via our payment processor; card details are not stored by Zeyro)
Communications with our sales, support, or solutions architecture teams
2.2 Information Collected Automatically
IP address, device and browser information, operating system
Cookies and similar tracking technologies (see Clause 7)
Usage data: pages visited, features used, API call patterns, error logs
Session and authentication logs, for security and fraud-prevention purposes
2.3 Customer Data Processed on Behalf of Business Users
Where you are a Business User of the Services, you (or your integrated data sources — Account Aggregators, UPI rails, GST systems, bureaus, document uploads) may submit Financial Information relating to your End Users to the Platform for processing, which may include:
Bank statement and UPI transaction data
GST filings and business financial data
Bureau data (where provided by you)
Documents submitted for document intelligence processing
We process such Financial Information solely as instructed by you, for the purpose of generating Outputs (scores, risk signals, narratives) as described in our Terms of Service. We do not independently determine the purpose of processing such End User data.
2.4 Information We Do Not Collect
We do not knowingly collect information from individuals under 18 years of age, and our Platform is not directed at consumers. We do not collect sensitive personal data (as defined under applicable law) through the website itself; any such data processed in connection with the Services is processed solely as instructed by, and on behalf of, the relevant Business User.
3. HOW WE USE INFORMATION
We use the information described above to:
create and manage your Zeyro account and workspace;
provide, operate, maintain, and improve the Platform and Services;
generate Outputs based on Customer Data submitted by Business Users, strictly per their instructions;
respond to enquiries, provide customer support, and communicate service updates;
send product updates, security notices, and (with consent, where required) marketing communications;
detect, investigate, and prevent fraud, abuse, and security incidents;
comply with applicable legal, regulatory, and contractual obligations;
conduct internal analytics, research, and product development, using aggregated or de-identified data wherever possible; and
with your consent, use de-identified outcome data to improve model performance across our consortium dataset (see Clause 4).
4. MODEL IMPROVEMENT AND DE-IDENTIFIED DATA
4.1 Where a Business User elects to submit outcome labels (e.g., loan repayment outcomes) via the outcome-submission feature of the Services, Zeyro may use such data — after hashing user references and removing directly identifying fields — to train, validate, and improve its scoring models and consortium datasets.
4.2 We do not use identifiable End User Financial Information for our own independent marketing, advertising, or profiling purposes.
4.3 Business Users may opt out of contributing data to consortium model training, subject to the terms of their order form or partner agreement.
5. DISCLOSURE OF INFORMATION
5.1 We do not sell, rent, or trade personal data or Customer Data.
5.2 We may share information in the following circumstances:
Sub-processors and infrastructure providers: cloud hosting, data storage, key management, analytics (limited to operational/security analytics), email, and support tooling providers, engaged under contractual confidentiality and data protection obligations, and permitted to process data solely to enable our provision of Services.
Business Users: where you interact with the Platform as an End User via a Business User's product, relevant Outputs are shared with that Business User as instructed.
Legal and regulatory disclosure: where required by applicable law, regulation, court order, or a valid request from a governmental or regulatory authority (including RBI, DPDP Board, or law enforcement).
Corporate transactions: in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality obligations on the receiving entity.
With your consent: for any other purpose to which you expressly consent.
6. DATA STORAGE, SECURITY, AND CROSS-BORDER TRANSFER
6.1 Data localization. Zeyro stores and processes Customer Data and Financial Information within India, consistent with RBI data localization requirements and Account Aggregator framework obligations, unless otherwise agreed in writing with a Business User.
6.2 Security measures. We implement administrative, technical, and physical safeguards designed to protect data against unauthorized access, disclosure, alteration, or destruction, including:
Encryption in transit (TLS 1.3) and at rest (AES-256)
Role-based access control (RBAC) and the principle of least privilege
Network segmentation and VPC isolation
Audit logging of data access events
Periodic security reviews and vulnerability assessments
Secrets management via dedicated key-management infrastructure
6.3 No system can be guaranteed 100% secure. While we take reasonable measures to protect information, we cannot guarantee absolute security, and any transmission of data over the internet is at your own risk.
6.4 Cross-border transfer. Where any limited transfer of non-Financial-Information personal data (e.g., business contact details of Business User personnel) occurs outside India for operational purposes (such as use of a global cloud or support tool), we ensure appropriate contractual safeguards are in place consistent with the DPDP Act.
8. DATA RETENTION
8.1 Business User account data is retained for as long as your account remains active, and for a reasonable period thereafter to comply with legal, tax, audit, and dispute-resolution obligations.
8.2 Raw Financial Information / Customer Data submitted for processing is retained only for as long as necessary to compute Outputs and is purged in accordance with our data minimization practice — by default within [48 hours / X days] of feature extraction, unless a longer period is required by applicable law, contractual agreement with the Business User, or ongoing dispute.
8.3 De-identified/hashed outcome data used for consortium model training may be retained for longer periods necessary for model development, in de-identified form.
8.4 Upon a valid deletion request or account termination, we will delete or anonymize personal data within a reasonable period (and in any event within the timeframe required under applicable law), except where retention is required for legal compliance, fraud prevention, or the resolution of disputes.
9. YOUR RIGHTS
Subject to applicable law (including the DPDP Act), you may have the right to:
access and obtain a copy of personal data we hold about you;
request correction of inaccurate or incomplete data;
request erasure of your personal data, subject to legal retention requirements;
withdraw consent for processing based on consent, without affecting the lawfulness of processing carried out prior to withdrawal;
nominate another individual to exercise your rights in the event of death or incapacity; and
lodge a grievance with our Grievance Officer (Clause 12) or, where unresolved, with the Data Protection Board of India or applicable regulator.
To exercise these rights, contact us at [email protected]. We may request identity verification before actioning a request.
Note: Where personal data forms part of End User Financial Information processed on behalf of a Business User, requests relating to that data should generally be directed to the relevant Business User in the first instance, as they are the data fiduciary. We will support the Business User in fulfilling such requests as required under our processor obligations.
10. CHILDREN'S DATA
The Platform is intended for business use and is not directed at individuals under 18 years of age. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will take steps to delete it promptly.
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Material changes will be notified via the Platform or by email to registered Business Users. The "Last updated" date at the top of this Policy indicates when it was last revised. Continued use of the Platform after an update constitutes acceptance of the revised Policy.
12. GRIEVANCE REDRESSAL AND CONTACT
If you have questions, concerns, or grievances relating to this Privacy Policy or our data practices, please contact:
General queries: [email protected]
Attention: Swaraj Chouriwar
Designation: Grievance Officer
Email: [email protected]
Address: Plot No. 254/A Nandniwas, New Ramdaspeth, Nagpur - 440010
We will endeavor to acknowledge grievances within twenty-four (24) hours and resolve them within fifteen (15) days, in accordance with applicable law.
13. GOVERNING LAW
This Privacy Policy is governed by the laws of India. Any disputes arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts at Gandhinagar, India, subject to the dispute resolution provisions of our Terms of Service.
