Licensing notice Kadyan Paygate India (OPC) Private Limited holds an NPCI Agent Institution licence for Bharat Connect (BBPS). This is the only licence we hold. We are not licensed or regulated by the Reserve Bank of India. Prepaid cards are issued by our RBI-licensed partner banks and issuers, and customer funds are held by those partners, not by us. How we work
Talk to us
ExpensesBill paymentsLoyalty EngagementCardsHow we work Grievance redressalPrivacy & cookies Talk to us
Policy

Privacy and Cookies Policy

What personal data we collect, why, who we share it with, where we keep it, how we protect it, what cookies we use, and the rights you have over all of it.

Version 1.0Effective 13 September 2026Issued by Kadyan Paygate India (OPC) Private Limited

Who we are and what this covers

This policy explains how Kadyan Paygate India (OPC) Private Limited ("we", "us") collects, uses, shares, stores and protects personal data, and how you can exercise your rights over it. It covers our website, our console and mobile app, our API, and our support channels. It is written to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the rules made under it, the Information Technology Act, 2000 and the rules on reasonable security practices, and the Reserve Bank of India's directions on the storage of payment system data.

Two roles, explained plainly. When you visit our website, contact us, or use our platform on your own behalf, we decide how your data is used and we are the data fiduciary. When a business uses our platform to run a programme for its employees or customers, that business decides why the data is collected and we process it on its instructions as a data processor. In the second case, the business is your first point of contact for rights requests, and we support it in responding. We will always tell you which role we are in if you ask.

Our Grievance Officer for data-protection matters is Harsh Kadyan, reachable at merchant.support@kadyanindustries.com. Legal notices may be sent to legal@kadyanindustries.com.

What we collect

CategoryExamplesWhere it comes from
Identity and contactName, designation, company, email address, mobile number, postal addressYou, or the business that onboards you
Verification (KYC) dataOfficially valid documents and their numbers, PAN, photographs, video verification recordings, date of birth, Aadhaar-based verification results where you choose that method, CKYC identifiersYou, DigiLocker, CKYCR, our RBI-licensed partners
Business and ownership dataRegistration numbers, constitutional documents, beneficial-owner details, bank account details, financial statementsThe business, public registries (MCA, GST)
Financial and transaction dataCard identifiers (tokenised), balances, loads, spends, merchant details, bill payment references, consumer numbers, reward and points activity, expense receipts you uploadGenerated on the platform; partner banks; the Bharat Connect network
Technical and device dataIP address, device identifiers, operating system, browser, app version, approximate location derived from IP, log and crash dataYour device, automatically
Usage dataPages and features used, actions taken in the console or app, timestampsYour use of our services
CommunicationsEmails, support tickets, feedback, call recordings where we tell you a call is recordedYou
Cookies and similar technologiesSee the cookies section belowYour browser

We do not deliberately collect data about your religion, caste, health, sexual orientation, political opinions or biometrics, other than the photograph and, where you choose it, the video used for identity verification, which is handled by our licensed partners in accordance with the RBI's KYC directions.

Why we use it and on what basis

Under the DPDP Act we process personal data either with your consent or for a legitimate use the Act recognises. The table shows which applies.

PurposeBasis
Providing the services you or your business asked for: issuing and managing instruments, applying spend controls, running rewards, fetching and paying bills, producing statements and reportsConsent given when you sign up or accept a programme; for employees, the legitimate use relating to employment where the programme is provided by your employer
Verifying identity and complying with anti-money-laundering, sanctions, tax and other legal obligations, and with the requirements of the RBI, NPCI and our licensed partnersLegitimate use: compliance with law, and with judgments, orders and directions of authorities
Detecting and preventing fraud, abuse and security incidentsLegitimate use; and consent where the processing goes beyond what is necessary for the service
Responding to your requests and complaintsConsent implied by your request; legitimate use for grievance handling
Improving the platform, fixing errors and understanding how features are usedConsent, which you may withdraw; analytics cookies are set only with your consent
Sending you service notices about your account, security and changes to termsNecessary to provide the service; these cannot be opted out of while you hold an account
Sending marketing about our servicesConsent only; you may withdraw at any time using the link in every message or by writing to us

Where we rely on consent, the request is presented separately from other terms, in plain language, and you may withdraw it as easily as you gave it. Withdrawal does not affect processing that already took place, and we may still need to retain some data to meet legal obligations described below.

Who we share it with

We share personal data only where necessary, only with recipients bound by contract or law to protect it, and never by selling it. Recipients include:

  • RBI-licensed partner banks and prepaid instrument issuers that issue the cards on our platform and hold the funds. They are data fiduciaries for the instrument they issue and receive the identification and transaction data the RBI's directions require.
  • NPCI Bharat BillPay and the operating units and billers on the Bharat Connect network, to fetch and settle bills you ask us to pay and to handle complaints.
  • Card networks (for example RuPay) to authorise and settle card transactions.
  • Verification providers including the Central KYC Records Registry, DigiLocker, and the income-tax, MCA and GST databases used to verify documents.
  • Service providers that host our infrastructure in India, send emails and SMS, provide analytics under our instructions, and support us with security monitoring and customer support tooling. Each acts on our documented instructions under a written contract.
  • The business that enrolled you, where you use the platform through your employer's or a brand's programme: it sees the data needed to administer its programme — for example the transactions on a corporate card, or points earned — and not data unrelated to that programme.
  • Auditors, professional advisers, and insurers under duties of confidentiality.
  • Regulators, law-enforcement agencies and courts where the law requires or permits disclosure, including the Financial Intelligence Unit – India through our reporting-entity partners.
  • A successor in the event of a merger, acquisition or reorganisation, subject to this policy continuing to apply.

Where and how long we keep it

Location. Personal data and all payment system data are stored on infrastructure located in India, in line with the Reserve Bank of India's directions on the storage of payment system data. We do not transfer personal data outside India except where a service provider needs limited access for support purposes under a contract that requires equivalent protection and where the law permits, and never for payment system data covered by the RBI's localisation requirement.

Retention. We keep personal data only as long as needed for the purpose it was collected, and then delete or anonymise it, subject to the legal minimums below.

DataRetention
Identification and KYC recordsAt least five years after the relationship ends, as the PML Rules require, and longer where a competent authority or partner requires
Transaction recordsAt least five years from the date of the transaction; longer where required for disputes, audit or tax
Complaint and grievance recordsFive years from closure
Account and profile data for active usersFor the life of the account, then per the categories above
Support communicationsThree years from the last interaction
Technical logsTwelve months, unless retained for a security investigation
Marketing consent and preferencesUntil you withdraw consent, plus a record of the withdrawal
Cookie dataAs set out in the cookies section

How we protect it

  • Card numbers are tokenised; full card numbers are never stored on our systems and are handled only within a PCI-DSS scoped environment operated with our partners.
  • Data is encrypted in transit using TLS and at rest using industry-standard encryption. Verification documents and recordings are stored in encrypted, segregated storage with restricted access.
  • Access to personal data is limited to staff who need it for their role, controlled by role-based permissions, protected by multi-factor authentication, and logged. Money movement requires two people.
  • Systems are monitored continuously for security events, tested regularly for vulnerabilities, and patched on a defined schedule. Backups are encrypted and stored in India.
  • Staff and contractors are screened before appointment, bound by confidentiality, and trained in data protection on joining and annually.
  • We maintain an incident-response plan. If a personal data breach occurs, we notify the Data Protection Board of India and each affected individual in the manner and within the time the DPDP Act and its rules require, and we tell you what happened, what data was involved, what we are doing, and what you can do.

No system is perfectly secure. If you believe your account has been compromised, freeze any card from the console or app immediately and write to us with URGENT in the subject line.

Your rights and how to use them

As a data principal under the DPDP Act you have the right to:

  • Access a summary of the personal data we hold about you, the purposes for which it is processed, and the categories of recipients with whom it has been shared.
  • Correction and completion of inaccurate or incomplete data, and updating of data that has changed.
  • Erasure of personal data that is no longer necessary for the purpose it was collected, unless the law requires us to retain it (for example KYC and transaction records for five years).
  • Withdraw consent at any time for processing based on consent.
  • Grievance redressal through our Grievance Officer, and thereafter to the Data Protection Board of India if you are not satisfied with our response.
  • Nominate another person to exercise your rights in the event of your death or incapacity.

To exercise any right, write to merchant.support@kadyanindustries.com from your registered email, or use the Help section in the console or app. We will verify your identity before acting, respond within 30 days, and tell you if we need longer and why. Where we cannot comply — usually because a law requires us to keep the data — we will explain which law and for how long. If you use the platform through a business's programme, we may direct your request to that business as the data fiduciary and will support it in responding.

Children

Our services are provided to businesses and to adults. We do not knowingly process the personal data of anyone under 18 without the verifiable consent of a parent or lawful guardian, and we do not track, monitor behaviourally, or direct advertising at children. If you believe we have collected data from a child without such consent, write to us and we will delete it.

Cookies and similar technologies

Cookies are small text files placed on your device by a website. We also use local storage and similar technologies in the console and app. This section explains which we use, why, and how to control them.

Categories

CategoryPurposeConsent
Strictly necessaryKeep you signed in, remember your session, protect against cross-site request forgery, balance load across servers, and remember your cookie choices. The service cannot work without them.Not required; cannot be switched off
FunctionalRemember preferences such as language, layout and the last programme you viewed.Consent, via the banner or settings
AnalyticsUnderstand which pages and features are used and where errors occur, so we can improve the platform. Data is aggregated and we configure providers not to build cross-site profiles.Consent, via the banner or settings
AdvertisingWe do not use advertising or retargeting cookies on our website or platform.Not applicable

Cookies we set

NameCategoryPurposeDuration
kpg_sessionStrictly necessaryMaintains your authenticated session in the consoleSession
kpg_csrfStrictly necessaryProtects forms against cross-site request forgerySession
kpg_consentStrictly necessaryRecords the cookie choices you made in the banner12 months
kpg_prefsFunctionalStores interface preferences12 months
kpg_analyticsAnalyticsAssigns an anonymised identifier used to count visits and feature use; set only if you accept analytics cookies13 months

Our public website loads fonts from Google Fonts, which may result in your IP address being sent to Google when the font files are requested. No cookies are set by that request. Where we embed third-party content in future, we will update this table.

Managing cookies

  • When you first visit, a banner lets you accept all cookies, reject all but the strictly necessary ones, or choose categories. You can change your choice at any time from the Cookie settings link in the footer.
  • Every major browser lets you block or delete cookies through its settings. Blocking strictly necessary cookies will prevent you from signing in.
  • We honour the Global Privacy Control signal where your browser sends it, treating it as a refusal of analytics and functional cookies.

Our website and platform may link to sites operated by our partners, billers or others. Those sites have their own privacy practices, which we do not control and which you should read.

We may update this policy when our services, the law or our partners' requirements change. Material changes are announced by notice in the console or app and, for changes affecting how we use your data, by email to your registered address before they take effect. The version and effective date are shown at the top of this page, and previous versions are available on request from merchant.support@kadyanindustries.com.

Questions about this policy: merchant.support@kadyanindustries.com · Legal notices: legal@kadyanindustries.com · Grievance Officer: Harsh Kadyan