1. Introduction
This Data Protection & Handling Policy (“Policy”) describes how Bofin.tech, operated by JANGRAS PRIVATE LIMITED (Jangras Corporation) (“Bofin”, “we”, “our”, “us”) collects, processes, stores, transfers, and protects personal and sensitive data of users, clients, partners and end-users when you use our services, APIs, platforms or website.
2. Scope
This Policy applies to all personal data processed by Bofin in any manner — data collected directly, received from partners, generated by usage, or obtained from public/third-party sources. It covers data of:
- Visitors of bofin.tech website
- Clients / businesses integrating Bofin APIs or infrastructure
- End-users serviced by our clients/partners
- Employees, applicants, vendors, and service providers
3. Categories of Data Collected
Depending on context, Bofin may collect the following categories of data:
- Identity & Contact Data – name, email, phone, company, address, identification documents (if required)
- Technical & Device Data – IP address, device/browser information, cookies, session & log data
- Usage & Transaction Data – API usage logs, transaction histories, service usage metrics
- Partner-Shared Data – data received from banks, NBFCs, payment gateways or fintech partners
- Employment / Vendor Data – if you apply for job or work with Bofin
- Other Data – any additional data necessary for compliance, risk management or service delivery
4. Purpose of Processing
We process personal data for purposes including but not limited to:
- Providing, operating and maintaining Bofin services and platform
- Identity verification, compliance checks (KYC/AML), fraud prevention and risk management
-
- Analytics, performance monitoring, product improvement and optimization
- Customer support, onboarding, account management
- Regulatory, audit, reporting and legal compliance obligations
- Employment, vendor management or partnership processes (if applicable)
5. Lawful Basis for Processing
We process personal data on one or more of the following legal bases (depending on context and jurisdiction):
- Consent – when explicit consent is obtained
- Contractual Necessity – when processing is required to provide services or fulfil contractual obligations
- Legal Obligation – to comply with applicable laws, regulations, audits or statutory requirements
- Legitimate Interest – for business operations, fraud prevention, service improvement, security, risk management
6. Data Sharing & Third-Party Processors
Bofin may share data with:
- Licensed banks, NBFCs, payment gateways, financial institutions — for service delivery
- Third-party vendors, hosting providers, cloud services — under strict data-processing agreements
- Regulators, government or law-enforcement agencies — when legally required
- Internal departments and authorised personnel/employees — for legitimate business purposes
We do not sell your personal data.
7. International / Cross-Border Data Transfers
If data is transferred or stored outside your home country, we ensure that appropriate safeguards, contractual protections, and legal compliance measures are in place to protect your data rights.
8. Data Retention & Deletion
We retain personal data only as long as necessary for the purposes for which it was collected — for service delivery, compliance, audits, fraud prevention, or legal obligations. After the retention period ends or when data is no longer needed, we securely delete or anonymize it.
9. Data Security & Protection Measures
Bofin implements appropriate technical and organizational safeguards including, but not limited to:
- Encryption of data at rest and in transit
- Access controls and restricted access to sensitive data
- Regular security assessments and audits
- Secure storage environment and vendor compliance requirements
- Incident response plan and breach notification procedures
10. Rights of Data Subjects
Depending on applicable law, you may have certain rights regarding your personal data, including:
- Right to access your data
- Right to correct / rectify inaccurate or outdated information
- Right to request deletion (“right to be forgotten”)
- Right to restrict or object to processing
- Right to data portability (where applicable)
- Right to withdraw consent at any time (for consent-based processing)
- Right to be informed about data processing, sharing, retention policies
11. Grievance & Complaints
If you have concerns, complaints, or requests regarding personal data processing, please contact our Data/Privacy team:
Email: [email protected]
Company: JANGRAS PRIVATE LIMITED (Jangras Corporation)
Website: https://www.bofin.tech
12. Changes to This Policy
We may update or revise this Policy from time to time to reflect changes in law, technology, business practices, or services. The latest version will always be available on our website. Continued use constitutes acceptance of updated Policy.