Privacy policy
How GrydFi Technologies Pvt. Ltd. handles personal data, under the Digital Personal Data Protection Act 2023 and the RBI Digital Lending Directions 2025.
Draft — pending legal review. Not yet in force. effective date
Who this covers
This policy applies to the GrydFi website, the GrydFi widget wherever it is embedded, and the GrydFi applications used by borrowers, institutions and platform partners.
For most processing described here GrydFi acts as a Data Fiduciary under DPDPA 2023. Where GrydFi processes data on behalf of a lending institution as its Lending Service Provider, that institution is the Data Fiduciary and GrydFi is its Data Processor, bound by contract to the purposes it sets.
Registered entity: GrydFi Technologies Pvt. Ltd., registered address, CIN CIN.
What is collected
Only what a step needs, and only after you have agreed to that step.
Why it is processed
To show you the institutions whose criteria you meet; to pass your application to the one you choose; to meet obligations RBI and other regulators place on us; to detect fraud and secure the service; and to keep the audit records the law requires us to keep.
It is not processed to advertise to you, and it is not used to train models that profile you for marketing.
Your consent is the basis
Processing rests on the consent you give, for the purpose stated when you give it. Where the law requires processing regardless of consent — record-keeping, reporting, prevention of fraud — that legitimate use is identified to you at the time.
Who it is shared with
The institution you select, when you select it. Verification providers acting on our instruction for a specific check. Regulators and authorities where the law obliges disclosure.
Never sold. Never shared with an institution you did not choose. Never given to a data broker.
How long it is kept
Personal data is kept only as long as the purpose needs, or as long as a law requires — whichever is longer. Records tied to a regulated financial transaction carry statutory retention periods we cannot shorten.
Retention schedule: retention table approved by Legal.
Your rights
Under DPDPA 2023 you may:
Security
Data is encrypted in transit and at rest, access is limited to those who need it for a stated purpose, and every access is logged. Personal data of Indian users is stored in India.
No system is beyond compromise. If a breach affects you, you and the Data Protection Board will be told, as the law requires.
Contact
Data Protection Officer: name, email, phone.
For anything unresolved, see Grievance redressal.