LEGAL
Privacy policy
Effective Date: 2nd July, 2026 Version: 2.1
1. Introduction
This Privacy Policy ("Policy") applies to your use of the Pazy platform, including the websites/webapps at pazy.io, app.pazy.io, pazy.cards, and treasury.pazy.io, our mobile applications, and all related services (collectively, the "Services"). The Services are operated by DecentGrad Technologies Private Limited ("Pazy", "we", "our", or "us"), a company incorporated in India.
This Policy describes what personal data we collect, why we collect it, who we share it with, how long we keep it, and what rights you have. By using the Services, you acknowledge that you have read and understood this Policy. We may ask for your specific consent for certain processing activities as described below.
The terms "personal data" and "processing" carry the meanings assigned to them under the Digital Personal Data Protection Act, 2023 ("DPDP Act"). This Policy is also issued in compliance with the Information Technology Act, 2000, read with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.
2. How Pazy Handles Your Data
Pazy plays two different roles depending on the context:
2.1 When Pazy is directly responsible to you
If you visit our websites, sign up for or log in to the platform or communicate with us for sales or support — we decide why and how your data is processed. Under the DPDP Act, this makes us a "Data Fiduciary", and the obligations described in this Policy apply directly to us.
2.2 When your organisation is responsible
If a company (your employer, client, or counterparty) uses Pazy to manage its accounts payable, procurement, reimbursements, vendor payments or treasury management, that company decides what data to upload and for what purpose. Pazy processes this data on the company's instructions. Under the DPDP Act, the company is the "Data Fiduciary" and Pazy is a "Data Processor".
If you fall into this second category and want to access, correct, or delete your data, please contact the organisation that uploaded it. We will assist them in handling your request.
2.3 Processing of Customer Data as a Processor
To the extent that Pazy processes customer data as a Data Processor on behalf of a customer organisation, the following shall apply in addition to the data-protection provisions of any agreement between Pazy and the customer: we process customer data only on the documented instructions of the customer, including with regard to cross-border transfers, unless required to do otherwise by law; we ensure that personnel authorised to process customer data are bound by appropriate confidentiality obligations; we implement and maintain appropriate technical and organisational security measures; we engage sub-processors only subject to obligations no less protective than those set out herein, and remain responsible for their performance; we assist the customer, taking into account the nature of processing, in fulfilling its obligations to respond to data principal requests and to maintain security, breach notification and data-protection impact assessments; and we make available to the customer information reasonably necessary to demonstrate compliance, and permit and contribute to audits.
3. Information We Collect
We collect personal data in the following ways, limited to what is necessary for the purposes identified in this Policy:
3.1 Information you provide
Account and contact details: name, work email, phone number, designation, and organisation name — when you register, request a demo, or contact us.
Card application details: name, PAN, Aadhaar, MOA, address, mobile number and all other required documents — when you apply for a business card through pazy.cards. This data is collected directly from you as part of registration requirements.
Support communications: messages, emails, and attachments you send to our support team.
3.2 Information collected automatically
Device and technical data: We collect non-identifiable information such as browser type, operating system, device type, and approximate location (city-level, derived from IP address) when you visit pazy.io and pazy.cards. This information is collected through first-party cookies and does not personally identify you. We do not collect precise GPS location.
Usage data: Pages visited, features used, session duration, clickstream data, and performance metrics — collected through first-party analytics cookies. This data is used solely for understanding usage patterns and improving the platform, and is not used to identify individual users.
3.3 Cookies and tracking technologies
Our websites use cookies for essential functionality, analytics, and (where you consent) marketing purposes. When you first visit our website, we present a cookie consent banner that allows you to accept or decline non-essential cookies. Only strictly necessary cookies are placed without consent.
3.4 Information uploaded by customers
When a customer organisation uses the Services through app.pazy.io or treasury.pazy.io, it may upload personal data of its employees, vendors, contractors, and other counterparties — such as names, email IDs, bank account details, PAN, invoices, and payment records. These platforms are Pazy's core application environments where customers' business payment workflows are processed. Pazy processes this data on the customer's behalf and in accordance with their instructions, and does not independently determine why it is processed.
3.5 Sensitive Personal Data and Government-Issued Identifiers (Aadhaar and PAN)
Certain information we process constitutes Sensitive Personal Data or Information (SPDI) under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, including financial information such as bank account, card or payment-instrument details and passwords. In connection with the issuance of business cards and related Know Your Customer (KYC) requirements, we also collect government-issued identifiers, namely the Permanent Account Number (PAN) and, where required, the Aadhaar number. We treat such data as sensitive and handle it in accordance with the following safeguards and the law applicable to it:
Lawful basis and consent: SPDI and government-issued identifiers are collected only with your consent and for the specific, lawful purpose of identity verification, KYC and statutory compliance in connection with card issuance and payment services. We will not use such data for any purpose that is incompatible with the purpose for which it was collected without obtaining fresh consent.
Aadhaar-specific handling: Where the Aadhaar number is collected, it is collected and used strictly in accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the regulations made thereunder, and applicable RBI directions. We use the Aadhaar number only to the extent required for the permitted verification purpose, and it is maintained securely in accordance with applicable law.
Security measures: SPDI and government-issued identifiers are protected by enhanced security measures, including encryption in transit and at rest, strict role-based access on a need-to-know basis, tokenisation or masking where feasible, and logging of access, consistent with the reasonable security practices required under the Information Technology Act, 2000.
Retention and deletion: SPDI and government-issued identifiers are retained only for as long as necessary to fulfil the verification and statutory purposes for which they were collected, or for the minimum period mandated by applicable financial, KYC and anti-money-laundering regulations, after which they are securely deleted or anonymised.
4. How We Use Your Information
We use the data we collect for the following purposes:
Providing the Services — account management, authentication, transaction processing, card issuance and servicing, and enabling customers' business payment workflows and treasury management.
Communications — transactional alerts, service updates, security notices, and responses to your queries.
Improvement and analytics — understanding usage patterns, diagnosing issues, and enhancing the platform. We use anonymised or aggregated data wherever feasible.
Security and fraud prevention — detecting unauthorised access, investigating suspicious activity, and preventing abuse.
Legal and regulatory compliance — fulfilling obligations under applicable laws and regulations, and responding to lawful requests from governmental or regulatory authorities.
We will not use your personal data for a purpose that is materially different from what was communicated to you, without first obtaining your consent.
5. Sharing of Information
We do not sell or rent your personal data. We share it only in the following circumstances:
Service providers — we use third-party providers for cloud hosting (AWS, Mumbai region), communications, analytics, support, and identity verification. These providers process data on our instructions and are required to protect it appropriately.
Business Payment Cards partners — for business card products, we share necessary data with our RBI-licensed partners to enable card issuance, settlement, and dispute resolution. The RBI-licensed partner processes card user data in accordance with its own policies and applicable RBI directions.
Legal obligations — we may disclose data to regulators, courts, tax authorities, or law enforcement when required by law or a binding order.
At your direction — when you connect integrations with third-party software (accounting, ERP, etc).
The list of service provider categories may change as the Services evolve. An up-to-date list is available on request.
6. Data Retention
We retain personal data only for as long as necessary for the purpose it was collected, or as long as the law requires. After that, we delete it or render it non-identifiable.
For data uploaded by customer organisations, retention is governed by the customer's agreement with us. Customers can extract their data at any time and during the offboarding process. After the offboarding window, we delete the data, subject to any overriding legal obligations.
7. Data Breach Notification
In the event of a personal data breach, we will notify the Data Protection Board of India and affected individuals in the form, manner, and timelines required under the DPDP Act, along with all other interested parties. If a breach affects data uploaded by a customer organisation, we will notify the customer so they can meet their own notification obligations.
8. Information Security
Pazy maintains a comprehensive information security management programme and implements reasonable security practices and procedures designed to protect personal data against unauthorised access, alteration, disclosure, loss or destruction, commensurate with the nature of the information and the risks involved. Pazy is independently certified and audited to recognised standards, including ISO 27001:2022, SOC 1 Type II and SOC 2 Type II.
Our security measures include, as appropriate, encryption of data in transit and at rest, access controls and role-based permissions, network and application security controls, logging and monitoring, secure software-development practices, periodic vulnerability assessment, and personnel confidentiality obligations and training. Notwithstanding these measures, no method of transmission or storage is entirely secure, and we cannot guarantee absolute security.
9. Cross-Border Transfer of Data
Personal data is primarily stored and processed in India. Where we transfer personal data to, or access it from, a country outside India — for example, where a cloud-hosting facility or sub-processor is located abroad — we do so only in accordance with applicable law, and only to countries or recipients that are not restricted under the DPDP Act or any notification issued by the Central Government.
10. Your Rights
Under the DPDP Act, you have the following rights in respect of personal data for which Pazy is the Data Fiduciary:
Right to access — request a summary of the personal data we hold about you and how it is being used.
Right to correction and erasure — ask us to correct inaccurate data, update outdated information, or delete data that is no longer needed — subject to legal retention requirements.
Right to withdraw consent — withdraw your consent for any processing activity at any time.
Right to grievance redressal — raise a complaint with our Grievance Team and receive a response within 30 days.
Right to nominate — appoint someone to exercise your rights on your behalf in the event of your death or incapacity.
Additional rights under other applicable law — where the GDPR or other law applies to you, we will honour any further rights available to you under that law, such as the rights to data portability, restriction of processing, and objection to processing, to the extent they apply.
To exercise any of these rights, please contact our support team (details given below). We may need to verify your identity before processing your request.
If your data was uploaded by your employer or another organisation using Pazy, where Pazy is a Data Processor, please contact them directly. We will assist them in responding to your request.
11. Children's Data
The Services are designed for businesses and their authorised adult personnel. We do not knowingly collect personal data from anyone under 18 years of age. If we become aware that such data has been collected without verifiable parental or guardian consent, we will take steps to delete it. We do not engage in tracking, behavioural monitoring, or targeted advertising directed at children.
12. Changes to This Policy
We may update this Policy to reflect changes in law, regulatory requirements, or our practices. If we make material changes, we will notify you through email, in-app notice, or a banner on our website, and where required, seek fresh consent. The current version, available at pazy.io/privacy-policy with a clearly displayed effective date, supersedes all prior versions of this Policy.
13. Services Provided Through Financial Partners
Certain services made available through the Platform are not provided by Pazy directly but are offered in partnership with, and delivered by, banks and other entities that are licensed or authorised by the Reserve Bank of India (RBI) and/or operate under the framework of the National Payments Corporation of India (NPCI). Pazy is a technology service provider and is not itself the licensed provider of these regulated financial services. These services include Unified Payments Interface (UPI) payments facilitated through partners and the UPI infrastructure operated under NPCI rules; prepaid cards and prepaid payment instruments issued and serviced by an RBI-licensed card-issuing partner in accordance with the RBI Master Directions on Prepaid Payment Instruments and other applicable RBI directions; and treasury services made available through regulated banking, asset-management or other financial-services partners, subject to those partners' own terms and applicable RBI/SEBI regulation.
To enable these services, the personal data necessary for onboarding, identity verification, transaction processing, settlement, dispute resolution and statutory compliance is shared with the relevant licensed partner. Each such partner processes that data as a separate data fiduciary, in accordance with its own privacy policy and the regulatory framework applicable to it, and not under this Policy. We encourage you to review the privacy policy of the relevant partner. Pazy's responsibility in respect of these services is limited to its role as a technology service provider.
14. Relationship with the Master Service Agreement
Where Pazy provides the Services to a customer under a Master Service Agreement or other written agreement (the "MSA"), this Policy is incorporated into and forms an integral part of that agreement as an Annexure, and shall be read together with, and construed harmoniously with, the MSA. In the event of any inconsistency between this Policy and the express terms of the MSA, the terms of the MSA shall prevail to the extent of such inconsistency, save in respect of any matter where applicable data-protection law requires otherwise.
15. Governing Law
This Policy is governed by the laws of India, including the DPDP Act and the Rules made thereunder. Subject to your right to approach the Data Protection Board of India, the courts at Bengaluru, Karnataka shall have exclusive jurisdiction over any disputes arising from this Policy.
16. Contact Us
For general questions about this Policy or our data practices:
General queries: support@pazy.io
Privacy and grievances: grievance@pazy.io
Postal address: DecentGrad Technologies Pvt. Ltd., 2nd floor, Prestige Pinnacle, 113, Bengaluru, Karnataka 560095