bankai

Data Protection & Privacy Policy

This policy governs how Bankai Informatics Private Limited collects, processes, stores, and protects personal and business data across all operations, platforms, and products.

Last updated: April 3, 2026

Introduction

Bankai Informatics Private Limited ("Company", "We", "Our", "Us" or "Bankai") is a technology company headquartered in Ahmedabad, India, providing end-to-end Fintech solutions including but not limited to AI powered Digital Core Banking Platform, AI/ML based Fintech Solutions, Loan Origination System, SaaS Based Banking & Managed Cloud Services.

As part of our operations, we collect, process, store, and share personal and business data of our employees, clients, website visitors, vendors, consultants, and other stakeholders. This Data Privacy & Protection Policy ("Policy") governs how such information is handled across all our operations, platforms, and products.

By accessing our website (www.bankaiinformatics.co.in), using our products and platforms, or engaging with us in any capacity, you acknowledge and agree to the terms of this Policy. If you do not agree to the terms of this Policy, do not use our website.

Purpose

  • The purpose of this Policy is to:

  • Ensure lawful, fair, and transparent collection and processing of personal information.

  • Define guidelines for data storage, usage, disclosure, and disposal.

  • Protect the rights and privacy of individuals associated with the Company.

  • Ensure compliance with applicable Indian laws including the Information Technology Act, 2000, IT (SPDI) Rules, 2011, and the Digital Personal Data Protection Act, 2023 ("DPDP Act").

  • Establish accountability mechanisms for data governance across all functions.

  • Ensure that personal data is collected only to the extent necessary for legitimate business purposes (Data Minimization).

  • Ensure that personal data is processed only for specified, lawful, and communicated purposes (Purpose Limitation).

  • Promote privacy-by-design principles across products, services, and business processes.

Scope

  • This Policy applies to:

  • All employees, trainees, consultants, interns, contractors, vendors, and business partners of Bankai Informatics Private Limited.

  • Website visitors accessing www.bankaiinformatics.co.in.

  • Prospects and clients engaging through contact forms, "Ask Our Experts", brochure download requests, or event registrations.

  • Users of Bankai's AI/ML, cloud, cybersecurity, digital banking and related technology platforms, products and services offered by the Company from time to time.

  • Information in physical and electronic formats, across all offices including the Ahmedabad Corporate Office and Centre of Excellence.

Definitions

  • Personal Data / Personal Information: Any information that relates to an identified or identifiable natural person i.e Personally Identifiable Information (PII), including but not limited to:

  • Full name, residential or business address, email address, contact number.

  • Government-issued identification information where required for employment, contractual, compliance, verification, or regulatory purposes.

  • IP address and device identifiers.

  • All the information collected by the company from its webpage as displayed on https://www.bankaiinformatics.co.in/contact-us.

  • Product or service interest (collected via "Product/Services you're interested in" field on contact forms).

Data Principal: The individual to whom personal data relates.

Data Fiduciary: Bankai Informatics Private Limited, in its capacity as the entity that determines the purpose and means of processing personal data.

Data Processor: Any third party that processes personal data on behalf of the Company under a contractual arrangement.

Processing: Any operation performed on personal data including collection, recording, storage, use, disclosure, transmission, erasure, or destruction.

Consent

The Company collects and processes personal data only with valid, informed, and specific consent of the individual or on such other lawful basis as may be permissible under applicable law, except where processing is permitted by applicable law without consent.

  • Personal data may also be processed where necessary for:

  • Performance of contracts.

  • Compliance with legal obligations.

  • Protection of lawful interests.

  • Employment administration.

  • Fraud prevention, cybersecurity and risk management.

  • Any other lawful purpose permitted under applicable law.

Data Minimization and Purpose Limitation

The Company shall collect and process only such personal data as is reasonably necessary for the purposes identified at the time of collection or otherwise permitted under applicable law.

Personal data shall not be used for purposes incompatible with those for which it was originally collected unless permitted by applicable law or authorized by the relevant individual.

What Data We Collect

  • Website Visitors & Prospects: When you visit www.bankaiinformatics.co.in or submit any form, we may collect:

  • Full name.

  • Email address.

  • Phone number.

  • Product or service interest.

  • IP address, browser type, device information.

  • Website usage statistics and navigation behaviour.

  • Cookie identifiers, analytics identifiers and website interaction metadata.

  • Clients & Vendors:

  • Business contact information.

  • Contractual and commercial data.

  • Communication records.

  • Transaction and billing information.

  • Automatically Collected Data:

  • IP addresses and geolocation data.

  • Browser type and version.

  • Device and OS information.

  • Session duration and pages viewed.

  • Cookies and tracking pixels.

Where non-personal information, analytics information, usage information, device information, or anonymized information is combined with personal data in a manner that identifies or can reasonably identify an individual, such combined information shall be treated as personal data and protected in accordance with this Policy for so long as it remains identifiable.

Purpose of Data Usage

  • The Company uses collected data for the following purposes:

  • Responding to enquiries submitted via website contact forms, "Ask Our Experts", and event registrations.

  • Sending requested brochures and product documentation.

  • Human Resource and employment management.

  • Payroll processing, statutory compliance, and benefits administration.

  • Client relationship management and contract execution.

  • Vendor onboarding and management.

  • Fraud detection and network security monitoring.

  • Internal analytics and service improvement.

  • Compliance with legal, regulatory, and contractual obligations.

  • Audits, investigations, and dispute resolution.

Data Sharing and Disclosure

The Company does not sell, rent, or trade personal data to third parties for commercial or marketing purposes.

Data may be shared in the following circumstances:

Authorized Service Providers: With technology vendors, cloud service providers, CRM systems, analytics platforms, or payroll processors engaged by the Company, subject to confidentiality obligations.

Third-Party Due Diligence: The Company shall conduct reasonable due diligence on vendors, subcontractors, cloud service providers, consultants, and business partners that may access, store, process, or transmit personal data. Such third parties shall be subject to contractual obligations relating to confidentiality, information security, privacy, data protection, breach notification, and compliance with applicable laws.

  • Legal & Regulatory Requirements: The Company may disclose personal data where reasonably necessary:

  • To comply with applicable laws, regulations, legal processes, judicial orders, or governmental requests.

  • To cooperate with regulatory authorities, law enforcement agencies, or statutory bodies.

  • To establish, exercise, or defend legal rights and claims.

  • To investigate suspected fraud, security incidents, misconduct, or unlawful activities.

  • To enforce contractual rights, policies, and agreements.

  • To protect the rights, property, confidentiality, security, or safety of the Company, its employees, clients, users, business partners, or third parties.

  • To prevent or mitigate actual or potential losses, damages, liabilities, or risks.

  • To facilitate merger, acquisition, restructuring, financing transaction, asset sale, or similar corporate transaction, subject to appropriate confidentiality and security safeguards.

Data Retention

  • The Company retains personal data only for as long as necessary for the purposes for which it was collected:

  • Website enquiry and contact form data: up to 3 years from last interaction or as required for sales/client follow-up.

  • Employee records: duration of employment plus 7 years or as required under applicable law.

  • Client and vendor data: duration of contractual relationship plus applicable legal retention period.

  • System and access logs: minimum 1 year, or as required under applicable security policies.

Upon expiry of the applicable retention period, data shall be securely deleted, anonymized, or disposed of in accordance with internal data disposal protocols.

The Company may retain personal data beyond standard retention periods where required for litigation, regulatory investigations, audits, dispute resolution, legal claims, or compliance obligations.

Data Localization: The Company stores and processes personal data and customer data within the territory of India. The Company does not intentionally transfer, host, or process personal data outside India unless required by applicable law, regulatory requirements, or specific contractual arrangements approved by the relevant client and permitted under applicable law. Appropriate safeguards shall be implemented to ensure the security and confidentiality of such data at all times.

Information Security

The Company implements administrative, technical, physical, and operational safeguards to protect personal data from unauthorized access, misuse, loss, alteration, or disclosure.

  • Technical Controls:

  • Encryption of personal data in transit using secure communication protocols such as TLS/SSL and protection of data at rest through appropriate encryption and security controls, where applicable.

  • Multi-factor authentication for system access.

  • Firewalls, intrusion detection, and antivirus systems.

  • Secure cloud infrastructure (relevant to DevSecOps, Cloud Security, and Containerization services offered internally and to clients).

  • Privileged Access controls based on role and least privilege principles.

  • Administrative Controls:

  • Mandatory data privacy training for all employees.

  • Confidentiality obligations in employment and vendor contracts.

  • Periodic security audits and vulnerability assessments.

  • Physical Controls:

  • Restricted access to server rooms and data storage facilities.

  • CCTV surveillance at office premises.

  • Secure disposal of physical documents containing personal data.

Privacy by Design: The Company incorporates privacy and data protection considerations into the design, development, testing, deployment, maintenance, and enhancement of its products, applications, platforms and business processes. New products, integrations, and processing activities shall be reviewed to ensure compliance with applicable privacy, security, and regulatory requirements.

Employee Responsibilities

  • Maintain strict confidentiality of personal data of colleagues, clients, and other stakeholders.

  • Use Company data strictly for authorized business purposes.

  • Prevent unauthorized access, sharing, or downloading of personal data.

  • Immediately report any suspected data breach, security incident, or unauthorized disclosure to the IT/Security team and Grievance Officer.

  • Comply with all applicable IT, cybersecurity, and data privacy policies.

  • Not store personal data on personal devices or unauthorized cloud storage.

  • Violation of this Policy may result in disciplinary action including termination of employment and/or legal proceedings.

Confidential Banking and Financial Information: The Company recognizes that banking, payment, lending, KYC, customer onboarding, transaction, and financial information may be subject to enhanced confidentiality and regulatory obligations. Access to such information shall be restricted to authorized personnel on a need-to-know basis and protected through appropriate technical, administrative, and physical safeguards.

Cookies and Website Tracking

  • The Bankai informatics website (www.bankaiinformatics.co.in) uses cookies, Google Tag Manager and similar tracking technologies to:

  • Enhance user experience and website functionality.

  • Analyze website traffic and usage patterns.

  • Track the performance of marketing campaigns.

  • Enable contact forms and brochure download functionality.

  • Maintain website security.

  • Types of cookies used:

  • Essential Cookies: Required for website functionality (forms, navigation).

  • Analytics Cookies: Traffic analysis via integrated analytics tools.

The Company website uses cookies, analytics tools, tag management tools, and similar technologies. Users may disable cookies through their browser settings. Certain features of the website (such as contact forms) may not function effectively if cookies are disabled. We do not use cookies to collect sensitive personal data.

Rights of Individuals

  • Subject to applicable law, individuals have the following rights regarding their personal data:

  • Right to Access: Request access to personal data held by the Company.

  • Right to Correction: Request correction of inaccurate or incomplete data.

  • Right to Erasure: Request deletion of personal data where legally permissible.

  • Right to Withdraw Consent: Withdraw consent for processing at any time. However, withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal and may affect the Company's ability to provide certain services where such processing is necessary.

  • Right to Grievance Redressal: Lodge a complaint with the Grievance Officer.

  • Right to Data Portability: Request a copy of personal data in a structured format (to the extent applicable under DPDP Act, 2023).

  • Right to Nominate: Individuals may nominate another person to exercise their rights under applicable law in the event of death or incapacity, to the extent permitted by applicable law.

Requests may be submitted to the designated Grievance Officer (see Section 16). The Company shall respond within a reasonable time as required by applicable law. Individuals may opt out of receiving promotional communications at any time through available unsubscribe mechanisms or by contacting the Company.

Processing of Children's Personal Data: The Company recognizes its obligations with respect to the processing of personal data of children (see Section 9, DPDPA, 2023) and for the purpose of this policy, a child means any individual who has not completed eighteen years of age. The Company shall not process the personal data of a child without obtaining verifiable consent from the parent or lawful guardian of such child prior to such processing. The Company shall implement appropriate technical and organizational measures to verify that consent has been obtained from a person who is a parent or lawful guardian of the child whose data is sought to be processed and shall not undertake any processing of a child's personal data that is likely to cause harm to or have a detrimental effect on the well-being of such child. The Company shall not track or monitor the behavior of children or target advertising directed at children. Where the Company becomes aware that personal data of a child has been collected without the requisite parental consent, it shall take immediate steps to delete such data without undue delay.

Data Breach Management

  • In the event of a personal data breach, the Company shall:

  • Immediately contain and assess the scope of the breach.

  • Notify affected individuals, clients, regulators, or competent authorities where required under applicable law, contractual obligations, or regulatory requirements.

  • Document the breach, its causes, and remedial actions taken.

  • Implement corrective measures to prevent recurrence.

Employees must report any suspected or confirmed data breach immediately to the IT Security team and the Grievance Officer.

Security Incident Management

The Company maintains documented procedures for identifying, reporting, investigating, managing, mitigating, and remediating information security incidents and personal data breaches. Security incidents shall be investigated promptly and appropriate corrective actions shall be implemented to prevent recurrence.

Product-Specific Data Handling

The Company develops, deploys, supports, and maintains technology products and platforms including core banking systems, digital lending solutions, omnichannel banking platforms, AI-powered analytics solutions, KYC systems, HRMS solutions, cloud platforms, cybersecurity solutions, and related technologies.

  • Personal data processed through such platforms shall be subject to:

  • Role-based access controls.

  • Authentication and authorization mechanisms.

  • Encryption and security safeguards.

  • Audit logging and monitoring.

  • Secure software development practices.

  • Incident response and breach management procedures.

  • Client-specific contractual obligations.

  • Applicable legal and regulatory requirements.

Where the Company processes personal data solely on behalf of its clients, the Company shall act as a Data Processor and shall process such information only in accordance with documented client instructions and applicable contractual obligations.

Business Continuity and Disaster Recovery: The Company maintains business continuity and disaster recovery measures designed to support the availability, resilience, and recovery of critical systems, applications, and data. Recovery procedures shall be periodically reviewed, tested, and updated based on operational and business requirements. Where personal data is processed by the Company solely on behalf of a client, the client shall remain responsible for determining the legal basis, purpose, and authorization for such processing, and the Company shall process such data only in accordance with documented instructions and contractual obligations.

Legal and Regulatory Compliance

  • This Policy is governed by and interpreted in accordance with:

  • Information Technology Act, 2000.

  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

  • Digital Personal Data Protection Act, 2023 (DPDP Act).

  • Reserve Bank of India guidelines (applicable to fintech and banking product deployments).

  • Applicable Reserve Bank of India (RBI) circulars, directions, and guidelines relating to information security, outsourcing, digital lending, payment systems, and data management, where applicable.

  • Contractual obligations agreed with banks, financial institutions, NBFCs, payment service providers, and other regulated entities.

  • Any other applicable Indian or international data protection laws relevant to specific geographies where Bankai operates.

International Data Protection Compliance: The Company recognizes and respects applicable privacy, data protection, cybersecurity, and consumer protection laws across jurisdictions in which it operates or provides services. In addition to compliance with Indian laws, including the Digital Personal Data Protection Act, 2023, the Company seeks to align its data processing practices with internationally recognized privacy principles and, where applicable, regulatory requirements including but not limited to the General Data Protection Regulation (GDPR) and other applicable privacy frameworks as may be applicable to Bankai for compliance related to the specific territories wherein it operates.

Amendments to the Policy

The Company reserves the right to amend, modify, or update this Policy at any time to reflect changes in legal, regulatory, operational, or business requirements. The updated Policy will be published on www.bankaiinformatics.co.in. Continued use of Company services or platforms after such update constitutes acceptance of the revised Policy. This Policy will also be reviewed and updated as and when the Rules under the Digital Personal Data Protection Act, 2023 are notified by the Central Government.

Grievance Officer

For any concerns, complaints, access requests, or clarifications regarding this Policy or personal data, individuals may contact:

  • The Grievance Officer shall be responsible for:

  • Receiving and addressing privacy-related complaints and grievances.

  • Coordinating responses to requests made by Data Principals.

  • Managing privacy incidents and breach notifications.

  • Liaising with regulatory authorities where required.

  • Monitoring compliance with this Policy and applicable data protection laws.

Name: Rupal Sharma Designation: Senior Data Protection Officer Organization: Bankai Informatics Private Limited Address: 7 – Times Corporate Park, Thaltej-Shilaj Road, opp. Copper Stone, Ahmedabad, Gujarat - 380059 Email: is-team@bankaiinformatics.co.in

Governing Law, Dispute Resolution & Jurisdiction

Governing Law: These Terms shall be governed by and construed in accordance with the laws of India.

Dispute Resolution: Any dispute arising from these Terms or Website usage shall first be attempted to be resolved amicably through mutual discussions. If unresolved within thirty (30) days, the dispute shall be referred to arbitration under the Arbitration and Conciliation Act, 1996 (as amended).

Arbitration Details: Arbitration shall be conducted by a sole arbitrator appointed mutually. The language of arbitration shall be English, and the seat and venue shall be Ahmedabad, Gujarat, India.

Jurisdiction: You unconditionally consent to the exclusive jurisdiction of the courts situated in Ahmedabad, Gujarat, India for any claims or disputes, agreeing not to plead forum non conveniens.

Data Accuracy Obligation

Data Principals are responsible for ensuring that personal data provided to the Company is accurate, complete, and up to date. The Company shall not be responsible for any consequences arising from inaccurate, incomplete, or outdated information supplied by the individual.