Privacy Policy
Last updated: October 2025 • Non-custodial software data processing standards
1. Scope of Privacy Commitment
This Privacy Policy governs the processing of administrative and identification data provided by merchants using Keio's software tools. Keio is committed to safeguarding merchant confidentiality in accordance with applicable data protection standards.
2. Categories of Information Collected
We collect minimal administrative information strictly necessary to provide software access, verify merchant identity, and maintain accounting ledgers. This includes: (a) Merchant administrative contact details (name, email, phone number); (b) Business entity and tax records (PAN, GST details, business identity); and (c) Technical session metadata (IP address, login timestamps, user-agent details for security auditing).
3. Non-Custodial Architecture & Payer Data Exclusion
Keio operates a direct communication protocol. Keio DOES NOT capture, collect, store, or process end-payer banking credentials, card details, PINs, or sensitive personal payment instruments. Payment transactions are executed directly by the end-user through their own chosen UPI applications.
4. Permitted Purposes of Data Processing
Collected merchant data is processed exclusively to: (a) Authenticate and authorize software access; (b) Comply with statutory KYC and risk obligations; (c) Generate accurate automated wallet invoices; and (d) Detect and mitigate unauthorized platform misuse.
5. Absolute Prohibition of Data Monetization
Keio strictly does NOT sell, rent, lease, trade, or monetize merchant data to third parties, advertising brokers, or marketing networks under any circumstances.
6. Disclosure to Legal & Statutory Authorities
Keio may disclose merchant verification records or audit logs only when strictly mandated by valid legal process, judicial summons, governmental directive, or law enforcement request in connection with formal fraud or cybercrime investigations.
7. Security & Cryptographic Safeguards
All network transmissions and API interactions are secured via TLS encryption and authenticated cryptographic hashing (HMAC-SHA256). Administrative access to internal systems is restricted via multi-factor authentication and role-based privilege controls.
8. Merchant Data Rights & Inquiries
Merchants may request access, correction, or review of their registration records at any time by contacting our compliance desk via our official support channels.
9. Policy Updates
Keio may update this Privacy Policy periodically to reflect evolving legal, regulatory, or operational requirements. Updated terms become effective immediately upon publication.