Loading...
Loading...
Understand how Paywize stores, processes, protects, and manages data within its technology platform, including applicable data-residency and partner requirements.
This Policy describes Paywize’s approach to data storage, processing, security, residency, and governance in connection with its technology platform and services.
Paywize is a Technology Service Provider (TSP) that provides API-driven infrastructure enabling businesses to integrate with licensed banking and payment partners.
Paywize applies data-security and residency controls based on Applicable Law, contractual obligations, internal security requirements, and requirements communicated by applicable licensed partners.
Where regulated payment-system data is processed or maintained by a licensed banking or payment partner, the relevant partner remains responsible for its statutory and regulatory data-residency obligations.
Where Paywize maintains certifications or compliance attestations such as ISO/IEC 27001 or PCI DSS, references in this Policy apply only to the certified or assessed scope and should be read together with the applicable certificate or attestation.
This Policy applies to:
Where data is independently processed or controlled by a licensed banking or payment partner, that partner’s own data-residency, privacy, security, and retention requirements will also apply.
Paywize maintains data-residency controls for information processed through its technology platform in accordance with applicable legal, contractual, security, and licensed-partner requirements.
Where payment-system data is subject to mandatory localization requirements applicable to a licensed banking or payment partner, Paywize’s technology configuration will support the relevant partner’s requirements within the scope of Paywize’s services.
The location and treatment of specific data categories depend on the nature of the data, applicable service, hosting architecture, contractual requirements, and Applicable Law.
Where Paywize technology supports workflows involving UPI, IMPS, BBPS, RuPay, or other payment-network services, the underlying regulated service is provided through applicable licensed banking and payment partners.
Paywize configures its technology and data-handling processes to support applicable partner, payment-network, security, and localization requirements communicated for those integrations.
Specific payment-network data, tokens, credentials, or transaction information are handled in accordance with applicable technical specifications, partner requirements, contractual obligations, and Applicable Law.
Where Paywize systems are within the scope of cardholder-data processing, applicable card-data security controls are implemented in accordance with Paywize’s PCI DSS obligations and the assessed scope of its environment.
Card-related regulated services and card issuance, acquiring, or processing activities are provided by applicable licensed or authorised partners.
Data categories may include:
Where regulated payment-system data is controlled by a licensed partner, such data remains subject to that partner’s regulatory and contractual requirements.
Paywize uses cloud, hosting, and infrastructure providers selected based on security, availability, contractual, data-residency, and compliance requirements.
Where Paywize is required by Applicable Law, contractual obligations, or licensed-partner requirements to maintain particular data within India, the relevant production, backup, and disaster-recovery environments are configured accordingly.
Paywize evaluates the security and compliance posture of infrastructure providers, including applicable industry certifications and independent assurance reports.
Paywize evaluates cross-border transfers of personal, business, or platform data based on Applicable Law, contractual obligations, data classification, security requirements, and partner requirements.
Where a category of data is legally or contractually required to remain within India, Paywize applies appropriate controls designed to prevent unauthorised cross-border transfer of that data.
Where cross-border processing is legally permitted, Paywize may implement appropriate contractual, organisational, and technical safeguards.
Third-party service providers handling Paywize data are subject to due diligence and contractual requirements appropriate to the nature and sensitivity of the information they process.
Requirements may include:
Vendors may be subject to periodic security, compliance, and risk reviews based on their risk classification and services provided.
Paywize retains information only for periods reasonably necessary for the purposes for which it was collected, to provide its technology services, meet contractual obligations, resolve disputes, maintain security and audit records, or comply with Applicable Law.
Retention periods vary by data category, purpose, contractual requirement, licensed-partner requirement, and applicable legal obligation.
Where Paywize processes information on behalf of or in support of a licensed partner, applicable partner retention requirements may also apply.
Data that is no longer required may be securely deleted, anonymised, or otherwise disposed of in accordance with Paywize’s information-security procedures, subject to applicable retention obligations.
Paywize’s designated information-security, privacy, risk, and compliance functions oversee implementation of this Policy within their respective responsibilities.
Paywize’s information-security controls are mapped, where applicable, to recognised security frameworks and applicable certification requirements.
Employees, contractors, and authorised service providers are required to comply with applicable Paywize information-security, privacy, access-control, and data-handling requirements.
Violations may result in:
Paywize Technologies Pvt. Ltd. operates as a Technology Service Provider (TSP). Paywize provides APIs, software, integration, orchestration, reconciliation, reporting, and related technology capabilities.
Where Paywize technology enables access to regulated banking or payment services, the underlying regulated service is provided by the applicable licensed banking or payment partner.
Data-residency, payment-system-data, regulatory-reporting, settlement, or other statutory obligations applicable to the licensed partner remain the responsibility of that regulated entity. Paywize implements appropriate technology and security controls within the scope of its role and applicable contractual obligations.
Depending on the nature of the interaction, Paywize may process information for its own legitimate business and platform purposes or process certain information in connection with services provided to Merchants or licensed partners.
The applicable role, processing purpose, and responsibilities may vary depending on the product, data category, and contractual arrangement.
Paywize Technologies Pvt. Ltd. is a Technology Service Provider (TSP). Paywize maintains data-security and residency controls appropriate to the information processed within its technology platform and its applicable legal and contractual obligations.
Where underlying regulated banking or payment services are provided by licensed partner institutions, regulatory data-residency and payment-system obligations applicable to those institutions remain subject to their respective responsibilities and Applicable Law.