BharatOne Services and Affiliates Pvt. Ltd. ("BharatOne", "Company", "we", "our", or "us") is committed to maintaining the highest standards of data protection, operational security, privacy, and responsible information management across its websites, applications, APIs, digital platforms, franchise network, merchant ecosystem, and associated services.
This Data Protection & Localization Statement ("Statement") outlines BharatOne's commitment to protecting personal information, merchant data, operational records, transaction information, and business-related information while supporting data localization practices in accordance with applicable Indian laws and regulatory requirements.
1. Purpose
This Statement is intended to:
- Promote responsible collection, processing, storage, and handling of information.
- Protect customer, merchant, retailer, franchise, and partner information.
- Maintain operational and information security across BharatOne's digital ecosystem.
- Support transparency regarding data localization practices.
- Foster customer trust and platform integrity.
- Support compliance with applicable Indian laws, regulations, and industry standards.
2. Information Protection Commitment
BharatOne implements commercially reasonable administrative, technical, organizational, and physical safeguards to protect information against unauthorized access, disclosure, misuse, alteration, destruction, or accidental loss.
Protected information may include:
- Customer personal information.
- Merchant and franchise information.
- Retailer registration records.
- Government service application data.
- Financial and payment transaction records.
- Settlement and reconciliation information.
- Customer support communications.
- API and system logs.
- Operational and technical information.
- Business records and contractual documentation.
Security measures may include:
- Role-based access controls.
- Multi-factor authentication where applicable.
- Encryption of sensitive information during transmission and storage where appropriate.
- Secure application development practices.
- Continuous monitoring and audit logging.
- Network and infrastructure security controls.
- Fraud detection and prevention mechanisms.
- Periodic security reviews and risk assessments.
3. Data Localization Commitment
BharatOne is committed to storing and processing regulated customer, payment-related, operational, and transactional information within the geographical boundaries of the Republic of India wherever required under applicable laws, regulatory directions, or contractual obligations with banking institutions, payment system providers, government authorities, and technology partners.
BharatOne does not intentionally transfer or store regulated customer or payment-related information outside India except:
- Where expressly permitted or required by applicable law;
- Pursuant to a lawful governmental or regulatory request;
- Or where necessary to provide specific services in compliance with applicable legal and contractual requirements.
4. Third-Party Service Providers and Technology Partners
BharatOne collaborates with banks, regulated payment system providers, payment gateways, telecom operators, cloud service providers, identity verification providers, government departments, technology vendors, API providers, and other authorized ecosystem participants to deliver its services.
Where appropriate, BharatOne seeks to engage service providers that maintain reasonable standards of:
- Information security.
- Confidentiality.
- Data protection.
- Operational resilience.
- Regulatory compliance.
- Business continuity.
Third-party providers are expected to process information only for authorized business purposes and in accordance with applicable agreements and legal obligations.
5. Responsible Information Handling
Information collected through BharatOne's platforms may be used for legitimate business purposes, including:
- Customer onboarding and account management.
- Merchant and retailer registration.
- Identity verification and authentication.
- Government service facilitation.
- Payment processing.
- Settlement and reconciliation.
- Fraud detection and risk management.
- Customer support.
- Regulatory reporting.
- Analytics and service improvement.
- Internal operational management.
- Compliance with applicable legal and regulatory obligations.
BharatOne does not sell customer personal information to unauthorized third parties.
6. User Responsibilities
Users are responsible for:
- Maintaining the confidentiality of usernames, passwords, PINs, and One-Time Passwords (OTPs).
- Using trusted devices and secure internet connections.
- Protecting their account credentials against unauthorized access.
- Reviewing transaction details before confirmation.
- Immediately reporting suspicious activities, fraudulent transactions, or unauthorized account access.
- Complying with BharatOne's Terms of Service and applicable laws.
Users should never disclose confidential authentication credentials to unauthorized individuals.
7. Data Retention
BharatOne retains customer and operational information only for as long as necessary to:
- Provide requested services.
- Fulfil contractual obligations.
- Comply with applicable legal and regulatory requirements.
- Resolve disputes.
- Prevent fraud.
- Maintain audit trails and business records.
Upon expiry of applicable retention periods, information may be securely deleted, anonymized, or archived in accordance with BharatOne's internal policies and applicable law.
8. Continuous Improvement
BharatOne continuously reviews and enhances its security controls, privacy practices, operational procedures, and information management framework based on:
- Technological advancements.
- Emerging cybersecurity threats.
- Operational experience.
- Regulatory developments.
- Industry best practices.
- Partner and customer requirements.
- Internal audits and risk assessments.
9. Compliance
BharatOne endeavors to conduct its operations in accordance with applicable Indian laws and regulations, including, where relevant:
- Digital Personal Data Protection Act, 2023.
- Information Technology Act, 2000.
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent applicable).
- Consumer Protection Act, 2019.
- Applicable directions, circulars, and guidelines issued by the Reserve Bank of India (RBI), National Payments Corporation of India (NPCI), and other competent regulatory authorities, where applicable to BharatOne's services or its regulated partners.
10. Contact Information
For questions relating to privacy, data protection, information security, or data localization, please contact: