CrystalPay Fintech Private Limited : Data privacy and Security policy

This document is an electronic record in terms of Information Technology Act, 2000 and rules thereunder as applicable.
This electronic record is generated by a computer/electronic system and does not require any physical or digital signatures

Introduction


CrystalPay Fintech Private Limited (“Company” / “Us” / “We” / “Our”) considers User relationship and data security to be an important component of their service offerings(“Services”) through Our Website and Platform (as defined below). We are committed to maintaining the confidentiality, integrity, and security of any personal information of our Users. We are proud of our privacy practices and the strength of our Platform and Website security and want you to know how We protect your information and use it to provide you with Services. This Data Privacy and Security Policy (“Policy”) enables us guard against identity theft and provide security for User profiles and transactional history. We constantly re-evaluate this Policy and adapt it to meet data security standards and to deal with new challenges.

Definitions


In this Policy: (i) capitalised terms defined by inclusion in quotations and / or parenthesis have the meanings so ascribed; and (ii) the following terms shall have the following meanings assigned to them herein below :

1.Applicable Law


includes all applicable Indian statutes, enactments, acts of the state legislature or parliament, laws, ordinances, rules, bye-laws, regulations, notifications, guidelines, directions, directives and orders of any governmental authority, statutory authority, board, recognised stock exchange, as may be applicable including but not limited to Guideline son Managing Risks and Code of Conduct in Outsourcing of Financial Services by Banks, , any implementing regulation or interpretation issued thereunder including any successor Applicable Law; “Company” / “Us” / “We” / “Our” shall mean CrystalPay Fintech Private Limited, a private limited company registered under Companies Act, 2013 and having its registered office at 47 Nagla Devhansh Dauki Fatehabad Road Agra Uttar Pradesh INDIA (which expression shall, unless it be repugnant to the context or meaning thereof, be deemed to mean and include its successors and permitted assigns);“Crystal Pay count” shall mean the access account created by a User to avail Services on Website and/or Platform; “Person” shall mean any individual (including personal representatives, executors or heirs of a deceased individual) or legal entity, including but not limited to, any partnership, joint venture, corporation, trust, unincorporated organisation, limited liability company, limited liability partnership or governmental authority;

2.Personal Information


shall mean any personally identifiable information provided to Us by a User for creation of a Crystal Pay Account or availing Services through Website and/or Platform; “Services” shall mean the services provided by Company through its Platform including but not limited to financial inclusion services in partnership with banks as business correspondent, distribution of financial products and services including, insurance products, investment services, issuance and sales of wallets and prepaid cards and non-financial nature products and services through the Platform in collaboration with various partners; “User” / “You” / “Your”͖ shall mean any natural or legal person who has access to and is using Platform; and “Website” / “Platform” shall mean shall mean and include www.crystalpay.in, mobile application of Company, any successor website/ applications, any website of Related Entity or any other channel facilitated and permitted by Company including but not limited to App, another digital medium including phone, displays, emails, social media interfaces, messaging interfaces, wallet, payment intermediaries using Company’s interface

3.Collection, Storage and Use of Information


3.1. We collect Your Personal Information when You successfully submit information while creating our Crystal Pay account on Platform (“User Information”). User Information is the data that can be used to uniquely identify or contact a person and/or the business entity that a person represents and shall include, but not be limited to, Your Personal Information and such other information for the purposes of identification and verification.
3.2. Without prejudice to the generality of paragraph 3.1 above, We may request such additional User Information as may be required for accessing and availing any Services through Platforms may be specified in the terms and conditions of use of such Service.
3.3. By creating a Crystal Pay Account and by accessing Services, You authorize Us to collect, store, process, handle and use such User Information, in accordance with this Policy and any other terms and conditions of use of Platform and/or Services (as amended from time to time)
3.4. Personal Information provided by You is used by Us to improve Platform and/or Service. We do not share Your Personal Information with any third parties for commercial use or revenue generation.
3.5. may share Personal Information such as Your name, mobile number and email address with third party service providers appointed by Us to for sending SMS / Email communications to You in relation to Platform and/or Services. We ensure that such third party service providers maintain strict confidentiality of Your Personal Information.

4.Representations and Warranties


4.1. By creating a Crystal Pay Account and accessing Services on Platform, You represent that You are at least the age of majority in Your state or province of residence.
4.2. You shall not, in the use of the Service, violate any Applicable Laws in Your jurisdiction
4.3. You also understand and acknowledge that the use of the Platform requires internet and/or mobile connectivity. You shall bear the costs incurred to access and use the Platform and We shall not, under any circumstances whatsoever, be responsible or liable for such costs.
4.4. You shall be solely responsible for all activities undertaken through Your Crystal Pay Account, whether or not You have authorized such activities or actions and shall, at all times, keep Us indemnified in this regard.
4.5. A breach or violation of any of this Policy will result in an immediate termination of Services and may result in reporting to the law enforcement agencies.
4.6. In addition to other prohibitions as set forth in the Terms of Use, You understand and agree that You are prohibited from using the Platform or its Content:
(i)for any unlawful purpose;
(ii)to solicit others to perform or participate in any unlawful acts
(iii)to violate any international, federal, provincial or state regulations, rules, laws, or applicable ordinances;
(iv)to infringe upon or violate our intellectual property rights or the intellectual property rights of others;
(v)to harass, abuse, insult, harm, defame, slander, disparage, intimidate, or discriminate based on gender, sexual orientation, religion, ethnicity, race, age, national origin, or disability
(vi)to submit false or misleading information
(vii)to upload or transmit viruses or any other type of malicious code that will or may be used in any way that will affect the functionality or operation of the Service or of any related Platform, other Platforms, or the internet
(viii) to collect or track the personal information of others;
(ix)to spam, phish, pharm, pretext, spider, crawl, or scrape;
(x) for any obscene or immoral purpose; or
(xi) to interfere with or circumvent the security features of the Service or any related Platform, other Platforms, or the internet. We reserve the right to terminate your use of the Service or any related Platform for violating any of the prohibited uses

5. Accuracy and Completeness of Information


5.1. You represent and warrant that You shall be responsible for accuracy and correctness of all User Information provided by You for creation of a Crystal Pay Account and for accessing any Services available on Platform.
5.2. For the purposes of internal verification and/or for compliance with Applicable Law including but not limited to e-KYC requirements, You may be required to submit such personal identification documents as may be required by Us from time to time. You shall remain solely responsible for accuracy and validity of all such personal identification documents.

6. Third-Party Services


6.1. We may allow You to access certain Services provided by third-party service providers, which we neither monitor nor exercise any control over.
6.2.You acknowledge and agree that We provide access to such third-party Services on an “as is basis” and “as available” without any warranties, representations or conditions of any kind and without any endorsement. We shall have no liability whatsoever arising from or relating to your use of such third-party Services.
6.3. Any use by You of third-party Services offered through Platform is entirely at Your own risk and discretion and You should ensure that You are familiar with and approve of the terms on which third-party Services are provided by the relevant service provider(s).
6.4. We may also, in the future, offer new services and/or features through Platform (either by Use by third-party service providers). Such new features and/or services shall also be subject to this Policy.

7. Intellectual Property


7.1. All copyright, database right and all other proprietary rights, title and interest in all information presented on Platform (“Intellectual Property”) is owned by and/or licensed to Us or owned or licensed to the provider of Services or is owned by and is or may be protected or covered by copyright, trade mark, intellectual property law and/or other proprietary rights, unless expressly stated otherwise
7.2. use of Platform and/or Services does not confer on You or any other party, any licence or other rights under Intellectual Property or other proprietary rights of Company and/or provider of Services and/or of any third party, whether implied or otherwise.

8. Disclosure of User Information


8.1. Notwithstanding paragraph 3 above, We reserve the right to utilize, share and/or disclose User Information if:
(i) required to do so to comply with orders of governmental authorities that have jurisdiction over it or as otherwise required by Applicable Law after providing You a written intimation prior to such disclosure; and/or
(ii)We determine, in Our sole discretion that disclosure of User Information is necessary to identify, contact, or bring legal action against you

9. Removal of Stored Information


9.1. We ensure that any User Information stored with Us is and remains to be in Your ownership. Upon deletion of Crystal Pay Account, We will, to the reasonable extent possible, remove User Information stored with Us within 3 (three) months from the date of such deletion
9.2. Notwithstanding the above, We reserve the right to retain such User Information that forms part of anonymized and aggregated data derived from User Information which may be used for improvement of our Platform and/or Services, to produce analytical reports, marketing, advertising or such other activities as We may deem fit

10. Indemnification


You agree to indemnify, defend and hold harmless Us and Our parent, subsidiaries, affiliates, partners, officers, directors, agents, contractors, licensors, service providers, subcontractors, suppliers, interns and employees, harmless from any claim or demand, including reasonable attorneys’ fees, made by any third-party due to or arising out of Your breach of this Policy or the documents they incorporate by reference (including terms and conditions of use of Platform and/or Services), or Your violation of any law or the rights of a third-party

11.Security Precautions


To prevent any form of unlawful interception or misuse of User Information, We use reasonable physical, electronic and managerial procedures to safeguard and secure User Information collected. We use reasonable secure and technologically appropriate measures, in compliance with the Information Technology Act, 2000 and the rules related thereto to protect You against loss or misuse of Your User Information including internal reviews of data collection, storage and processing practices and other reasonable security measures which are equivalent to security measures that We use to protect Our own confidential information. However, as You are aware, no internet website or online platform is completely free of security risks and We do not make any representation in respect of the same.

12.Change in Privacy Policy


We reserve the right to update, modify and amend any of the terms of this Policy, at any time without prior intimation to You. We will post these changes on Platform for Your information. These changes will become effective immediately on posting. We shall not be liable for any failure or negligence on Your part to review the updated Policy before accessing Platform and/or availing Services. Your continued use of the Platform, following changes to this Policy, will constitute Your acceptance of those changes.

13. What we collect?


We may collect and/or gain access to and/or record certain information including personal information from or of User in a variety of ways, including, but not limited to, when User access and uses the Services and in connection with other activities, services, features or resources we make available on the Services. These information may relate to and include but not limited to your name, date of birth, gender, father name, mother name, marital status, email address, address (including PIN code, city, state, residence type),phone number (including alternative mobile number, reference mobile number, reference person name),your unique device ID (persistent / non-persistent),photograph/ selfie, your KYC details/ documents, business details/ documents (including business address), PAN Numbers details (including extracting of GST from PAN or from GST Number),hardware type, international mobile equipment identity ("IMEI"), the version of your operating system ("OS"),your device name, your email address (if you have connected to Facebook or Google+),and your location (based on your Internet Protocol ("IP") address) (including demographics (LAT LONG) on various stages, and contact information, applications installed by User through our mobile application, applications uninstalled by User, all other applications installed by User on his/her device, foreground running apps/process (RUN event; We update server about the app downloaded/installed by our mobile application),SMS data and read SMS, network information, User behaviour analysis, demographic information (such as preferences and interests etc),Credit/Debit Card information of User for Internet banking (We do not store credit/debit card information on our servers),credit or affluence related information or assessment and/ or documents, user selected offer, bank statement (upload or net banking), personal bank account numbers and bank account data/ details including e-nach, NEFT, IMPS,UPI ID details, salary and income details. Users can always refuse to supply Personal Information; however, it may prevent them from engaging in certain Services related activities.

14. What we do with the Personal Information we gather?


We may use your Personal Information to :

Administer the Services.

Personalize the Services for User
End to User direct links to the Services.
Process transactions.
Process installation.
Send User our newsletter.
Develop, deliver, and improve our products, services, content, and advertising.
Send important notices, such as communications about purchases/downloads and changes to our Policy
Auditing, data analysis, and research to improve the Services.
Troubleshooting and helping us to understand usage trends
Send alerts to User.
Marketing and promotion of the Services.

15. Collection and use of non-personal information


We may collect non-personal information about Users whenever they use and interact with the Services. Non-personal information may include the information other than the Personal Information (as indicated above) and may also include browser name, the type of computer, and technical information about means used by the User to connect to our Services, such as the information about the operating system and the internet service providers utilized and other similar information. This information is aggregated and used to help us provide more useful information to the User and to understand which part of the Services, its products, and services are of most interest. If we do combine non-personal information with Personal Information, the combined information will be treated as Personal Information for as long as it remains combined.

16. Sharing of information with Authorities


We may share Personal Information as well as non-personal information of the User with the courts, police authorities, or any other government/regulatory/statutory authority, in case these are required by them in relation to any proceedings pending before them.

17. Privacy Policy Statement for Contact Information Collection


At CrystalPay Fintech Pvt Ltd, we are committed to protecting the privacy and security of our users' personal and sensitive information.
We understand that our users may have concerns about sharing their contact information, and we take appropriate measures to safeguard this data. We have implemented strict security measures to protect our users' contact information from unauthorized access, use, or disclosure. We do not sell or share users' contact information with any third-party without their explicit consent, except as required by law or in response to a valid government request.
We are committed to providing clear and transparent disclosures about our data collection and use practices. We understand that our current privacy policy and disclosures may not have met policy requirements and apologize for any confusion or frustration caused. We will review and update our policies to ensure that they meet all applicable policy requirements and provide clear and transparent disclosures to our users.

18. Contacting Us


If You have any queries regarding: (i) this Policy; (ii) information and/or Services available on Platform, or (iii) Your dealings with Us or believe that We have not adhered to it, you may contact Us at support@crystalpay.in

19.Email Opt-Out


You can opt out of receiving Our marketing and update emails. To stop receiving Our promotional emails, please email support@crystalpay.in. It may take about ten days to process Your request. Even if You opt out of getting marketing messages, we will still be sending You transactional messages through email and SMS in relation to Your Crystal Pay Account and Services availed by You