Data Protection Agreement
How PayzonIndia collects, processes, secures, and protects your data and your customers' data across every service we deliver.
Last Updated: September 1, 2026
Protecting Data is Core to What We Build
This Data Protection Agreement ("DPA") explains how PayzonIndia Pvt. Ltd. collects, uses, stores, and safeguards personal data in connection with our web, app, API, hosting, KYC verification, and digital marketing services. It applies to data belonging to our clients as well as end-users whose data we may process on a client's behalf while delivering these services.
Minimal Collection
We collect only the data required to deliver your project, verification, or hosting service
Encrypted at Rest
Sensitive data including KYC documents is stored using industry-standard encryption
Limited Access
Only authorized personnel on a need-to-know basis can access client and end-user data
Compliance First
Aligned with India's IT Act, 2000 and the Digital Personal Data Protection Act, 2023
Detailed Data Protection Terms
1. Roles We Play
For services like web hosting, cyber security, and API/portal development, PayzonIndia typically acts as a Data Processor, handling data strictly under the client's instructions. For our own client relationship data (billing, contact and account information), we act as the Data Controller and are responsible for how that information is used.
2. Data We Collect
- Business and contact details: name, company, email, phone number, billing address
- KYC and verification documents: Aadhaar, PAN, GST, corporate registration details submitted for verification services
- Technical data: server logs, IP addresses, and API usage logs generated through hosting and API products
- Project data: content, credentials, and assets shared for the purpose of building or maintaining your service
3. Purpose of Processing
Data is processed strictly to deliver the contracted service — building and maintaining your website or application, completing Aadhaar/PAN/GST/corporate verification, provisioning and securing hosting infrastructure, running marketing campaigns you've authorized, and communicating project updates, invoices, and support responses. We do not sell personal data to third parties under any circumstance.
4. Data Security Measures
- Encryption of sensitive data (KYC documents, credentials) both in transit (TLS/SSL) and at rest
- Role-based access controls limiting data visibility to authorized team members only
- Firewalls, intrusion detection, and continuous monitoring across our hosting and server infrastructure
- Automated, encrypted backups with disaster recovery protocols for hosted client data
- Periodic internal security audits and vulnerability assessments
5. Data Retention
Personal and project data is retained only for as long as necessary to fulfil the purpose it was collected for, or as required by applicable law (for example, financial records under Indian tax regulations). KYC verification data is retained in line with regulatory recordkeeping requirements and deleted or anonymized thereafter unless you request earlier deletion, subject to any legal obligation to retain it.
6. Sub-Processors & Third Parties
We may share limited data with vetted third-party providers strictly necessary to deliver our services — for example, payment gateways, SMS/DLT providers, cloud infrastructure partners, and government verification APIs (Aadhaar, PAN, GST, MCA). These providers are bound by confidentiality and data protection obligations, and are engaged only to the extent required for the specific service.
7. Your Rights as a Data Subject
- Request access to the personal data we hold about you
- Request correction of inaccurate or outdated information
- Request deletion of your data, subject to legal or contractual retention requirements
- Withdraw consent for marketing communications at any time
- Raise a grievance with our designated Grievance Officer regarding data handling
8. International Data Transfers
Our infrastructure and data are primarily hosted within India. Where a client's project requires data to be processed by an overseas cloud or software partner, we ensure such transfers occur only with appropriate safeguards and in compliance with applicable Indian data protection law.
9. Breach Notification
In the unlikely event of a data breach affecting personal data we control or process, we will assess the impact promptly and notify affected clients without undue delay, along with the steps being taken to contain and remediate the incident, in accordance with applicable law.
10. Regulatory Compliance
This Agreement is framed in accordance with the Information Technology Act, 2000 (and associated rules), and the Digital Personal Data Protection Act, 2023 of India. Our verification services additionally operate under the applicable guidelines for Aadhaar, PAN, and GST data handling issued by the relevant government authorities.
How Your Data Flows With Us
Data Collected
We gather only what's needed at onboarding — business details, KYC documents, or account credentials
Processed Securely
Data is processed on protected servers with encryption, access controls, and activity logging
Retained & Deleted
Data is retained only as long as legally or contractually required, then securely deleted
Have a Data Protection Query?
Reach our Grievance Officer for any data access, correction, or deletion request
Important Note
For enterprise and API clients processing end-user data at scale, a dedicated Data Processing Addendum may be signed as part of your service agreement, and its terms will take precedence over this general Agreement wherever they conflict. Registered Office: Sector B Plot 1, Patel Nagar, Raisen Road, Bhopal (MP) - 462022.

