Data Privacy & Security

Privacy Policy

Last updated: October 2025 • Non-custodial software data processing standards

1. Scope of Privacy Commitment

This Privacy Policy governs the processing of administrative and identification data provided by merchants using Keio's software tools. Keio is committed to safeguarding merchant confidentiality in accordance with applicable data protection standards.

2. Categories of Information Collected

We collect minimal administrative information strictly necessary to provide software access, verify merchant identity, and maintain accounting ledgers. This includes: (a) Merchant administrative contact details (name, email, phone number); (b) Business entity and tax records (PAN, GST details, business identity); and (c) Technical session metadata (IP address, login timestamps, user-agent details for security auditing).

3. Non-Custodial Architecture & Payer Data Exclusion

Keio operates a direct communication protocol. Keio DOES NOT capture, collect, store, or process end-payer banking credentials, card details, PINs, or sensitive personal payment instruments. Payment transactions are executed directly by the end-user through their own chosen UPI applications.

4. Permitted Purposes of Data Processing

Collected merchant data is processed exclusively to: (a) Authenticate and authorize software access; (b) Comply with statutory KYC and risk obligations; (c) Generate accurate automated wallet invoices; and (d) Detect and mitigate unauthorized platform misuse.

5. Absolute Prohibition of Data Monetization

Keio strictly does NOT sell, rent, lease, trade, or monetize merchant data to third parties, advertising brokers, or marketing networks under any circumstances.

6. Disclosure to Legal & Statutory Authorities

Keio may disclose merchant verification records or audit logs only when strictly mandated by valid legal process, judicial summons, governmental directive, or law enforcement request in connection with formal fraud or cybercrime investigations.

7. Security & Cryptographic Safeguards

All network transmissions and API interactions are secured via TLS encryption and authenticated cryptographic hashing (HMAC-SHA256). Administrative access to internal systems is restricted via multi-factor authentication and role-based privilege controls.

8. Merchant Data Rights & Inquiries

Merchants may request access, correction, or review of their registration records at any time by contacting our compliance desk via our official support channels.

9. Policy Updates

Keio may update this Privacy Policy periodically to reflect evolving legal, regulatory, or operational requirements. Updated terms become effective immediately upon publication.