Privacy Policy

Last Updated: 2026-04-26

This policy is published in English at v1. A Hindi translation will be added after the Delhi pilot.

1. Introduction

This Privacy Policy explains how YVSTG FINTECH PRIVATE LIMITED (CIN: U63999DL2024PTC435709), trading as “Artham” (“we”, “our”, “us”), processes personal data of dealers, distributors, and senders who use the Artham platform. We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDPA”) and as a Business Correspondent agent under Eko's RBI-approved BC umbrella for Domestic Money Transfer (DMT) services.

2. Personal data we process

  • Identity: name, date of birth, Aadhaar (last 4 digits stored), PAN (last 4 digits stored), and KYC document images held in encrypted Cloudflare R2 storage.
  • Contact: phone number, email address.
  • Transaction data: transfer amount, beneficiary bank account (encrypted), timestamps, status, and Eko reference IDs.
  • Device + location: device identifiers, IP address, app version, and (with explicit GPS consent) geofence coordinates at the moment of a transaction.
  • Consent records: purpose, version, and timestamp of every consent granted or withdrawn.
  • Audit metadata: who took which action, when, and from where — stored in immutable audit logs as required by RBI and DPDPA accountability obligations.

3. Purposes of processing (DPDPA §6)

  • Delivering DMT cash-to-account transfer services.
  • KYC and Anti-Money-Laundering compliance with RBI and Eko BC requirements.
  • Settling commissions to dealers and distributors.
  • Detecting and preventing fraud, abuse, and unauthorised access.
  • Responding to grievances, regulatory queries, and legal process; supporting statutory reporting.
  • Operating the platform — security monitoring, debugging, performance, and capacity planning.

We do not use personal data for marketing by default. Marketing communications (including WhatsApp transactional templates flagged for marketing) are sent only after explicit, separate opt-in.

4. Legal basis

Our primary legal basis is your consent under DPDPA §6, captured at first sign-in (separate rows for Terms of Service, this Privacy Policy, and DPDPA processing). For specific obligations — KYC verification, AML reporting, audit retention — we additionally rely on the legitimate uses set out in DPDPA §7 (compliance with applicable law, performance of state functions, and legitimate interests).

5. Who we share data with

We share personal data only with:

  • Eko India Financial Services Pvt. Ltd. — our Business Correspondent principal, for executing settlements and meeting RBI DMT compliance.
  • Cloudflare, Inc. — infrastructure processor (compute, storage, queues, observability).
  • Google (Firebase) — phone-OTP authentication processor.
  • AiSensy (when activated) — WhatsApp transactional notification processor.
  • Regulators and law enforcement — RBI, the Data Protection Board of India, tax authorities, and law-enforcement agencies, on lawful order.

We do not sell personal data. We do not share personal data with third-party advertisers.

6. Cross-border data transfers (DPDPA §16)

Our infrastructure providers (Cloudflare, Firebase, AiSensy) operate globally. Personal data may be processed at edge locations outside India for latency or redundancy. The Central Government has not yet notified a list of restricted countries under DPDPA §16; if it does, we will comply with that notification and update this policy accordingly.

7. Data retention

  • Transaction and audit records: retained for at least 10 years as required by RBI. This RBI retention obligation supersedes any erasure request under DPDPA §17 for these records.
  • KYC documents: retained for 5 years after account closure (RBI KYC Master Direction).
  • Marketing-consent records: retained until consent is withdrawn.
  • Inactive accounts: auto-erased 2 years after the last activity, subject to the RBI carve-out above for transaction and audit data.

8. Your rights as a Data Principal (DPDPA §11–§14)

  • Access: obtain a summary of personal data we hold about you and of how we process it. Use the in-app “Data Request” screen, or email the Nodal Officer.
  • Correction, completion, updation: correct any inaccurate or incomplete personal data via the in-app profile screen.
  • Erasure: request deletion via the in-app “Data Request” screen. Subject to the RBI 10-year retention carve-out for transaction and audit records, and subject to closing any outstanding credit or pending transactions.
  • Grievance redressal: contact our Nodal Officer (details below) or visit /grievance.
  • Nominate: nominate another individual to exercise your rights in the event of your death or incapacity (procedure available via Nodal Officer).
  • Withdraw consent: withdraw any consent at any time via the in-app profile screen. Withdrawal does not affect lawful processing carried out before withdrawal.

9. Consent and withdrawal

At first sign-in we capture distinct consents for the Terms of Service, this Privacy Policy, DPDPA processing, and (optionally) WhatsApp transactional / marketing messages and geofence GPS. Each consent is versioned. If we materially update this policy or change processing purposes, we will re-prompt you for consent at your next sign-in.

10. Children

Artham's services are intended for individuals 18 years and older. We do not knowingly process the personal data of children. If you believe we have inadvertently collected data from a child, contact our Nodal Officer for prompt deletion.

11. Personal-data breach notification (DPDPA §8(6))

In the event of a personal-data breach, our Nodal Officer notifies the Data Protection Board of India and affected Data Principals within the timelines prescribed by the DPDPA and any rules notified by the Government. We maintain internal incident-response runbooks to ensure timely detection and reporting.

12. Grievance redressal

Contact our Nodal Officer directly via the channels listed in section 14 below, or visit our /grievance page.

  • First response: within 24 hours.
  • Resolution target: 7 days for general complaints; 1 day for compliance-severity issues (failed transfer, missing money, fraud).
  • External escalation: if unresolved, you may escalate to the RBI Banking Ombudsman (cms.rbi.org.in) or to the Data Protection Board of India once it is operational.

13. Changes to this policy

We may update this policy as our services evolve or as the law requires. The “Last Updated” date at the top of this page reflects the most recent substantive change. On a material change, we re-prompt you for consent at your next sign-in.

14. Nodal Officer and Data Protection Officer

Our Nodal Officer also serves as our Data Protection Officer for DPDPA matters. To exercise your rights, raise a grievance, or report a personal-data breach:

Name: Jatin Rapra

Phone: +91 72909 91928

Email: team@arthampay.app

Postal address: YVSTG FINTECH PRIVATE LIMITED, House No 723, Ground Floor, Block A, Phase-2, Vijay Vihar, Rohini Sector 5, North West Delhi, Delhi 110085, India

Data Fiduciary: YVSTG FINTECH PRIVATE LIMITED (CIN U63999DL2024PTC435709)

Registered office: House No 723, Ground Floor, Block A, Phase-2, Vijay Vihar, Rohini Sector 5, North West Delhi, Delhi, India - 110085