Trust

Privacy policy

How GrydFi Technologies Pvt. Ltd. handles personal data, under the Digital Personal Data Protection Act 2023 and the RBI Digital Lending Directions 2025.

Draft — pending legal review. Not yet in force. effective date

01

Who this covers

This policy applies to the GrydFi website, the GrydFi widget wherever it is embedded, and the GrydFi applications used by borrowers, institutions and platform partners.

For most processing described here GrydFi acts as a Data Fiduciary under DPDPA 2023. Where GrydFi processes data on behalf of a lending institution as its Lending Service Provider, that institution is the Data Fiduciary and GrydFi is its Data Processor, bound by contract to the purposes it sets.

Registered entity: GrydFi Technologies Pvt. Ltd., registered address, CIN CIN.

02

What is collected

Only what a step needs, and only after you have agreed to that step.

What you tell usPurpose, amount and tenure when you ask to see options; contact details when you choose to be contacted.
Identity and KYCCollected when you proceed with an institution, and released to that institution only.
Financial informationShared through the Account Aggregator framework with your consent, to make matching accurate.
Credit informationBureau data, where you have permitted a check. Comparing options does not require a hard enquiry.
Technical dataDevice, browser and coarse location for security, fraud prevention and service reliability.
03

Why it is processed

To show you the institutions whose criteria you meet; to pass your application to the one you choose; to meet obligations RBI and other regulators place on us; to detect fraud and secure the service; and to keep the audit records the law requires us to keep.

It is not processed to advertise to you, and it is not used to train models that profile you for marketing.

04

Your consent is the basis

Processing rests on the consent you give, for the purpose stated when you give it. Where the law requires processing regardless of consent — record-keeping, reporting, prevention of fraud — that legitimate use is identified to you at the time.

05

Who it is shared with

The institution you select, when you select it. Verification providers acting on our instruction for a specific check. Regulators and authorities where the law obliges disclosure.

Never sold. Never shared with an institution you did not choose. Never given to a data broker.

06

How long it is kept

Personal data is kept only as long as the purpose needs, or as long as a law requires — whichever is longer. Records tied to a regulated financial transaction carry statutory retention periods we cannot shorten.

Retention schedule: retention table approved by Legal.

07

Your rights

Under DPDPA 2023 you may:

AccessAsk what personal data we hold about you and what we have done with it.
CorrectHave inaccurate or incomplete data corrected or completed.
EraseAsk for deletion where no legal obligation requires us to keep it.
WithdrawTake back any consent, at any time, as easily as you gave it.
NominateName someone to exercise these rights if you cannot.
ComplainRaise a grievance with us, and escalate to the Data Protection Board of India if unsatisfied.
08

Security

Data is encrypted in transit and at rest, access is limited to those who need it for a stated purpose, and every access is logged. Personal data of Indian users is stored in India.

No system is beyond compromise. If a breach affects you, you and the Data Protection Board will be told, as the law requires.

09

Contact

Data Protection Officer: name, email, phone.

For anything unresolved, see Grievance redressal.