Privacy Policy
for WebFinex TechFusion Private Limited & https://bluswap.co/
Last updated: August 25, 2026
1. Introduction
This Privacy Policy describes how WebFinex TechFusion Private Limited ("bluSwap", "bluSwap®", "we", "us", "our"), a company incorporated under the Companies Act, 2013 (CIN: U62099GJ2023PTC142852; GSTIN: 24AADCW5761A1ZL), acting as a "Data Fiduciary" under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), collects, uses, processes, stores, and protects information in connection with:
our website located at bluswap.co and www.bluswap.co (the "Website");
our dashboards, applications, and onboarding portals (including finex.bluswap.co);
our Payment OS and related products, including BankLynk™ (Connected Banking), PSaaS, OptiPay™ (AI Smart Checkout & Routing) and Universal Checkout; and
any other services offered by bluSwap that link to this Policy, (collectively, the "Services").
Registered Office: #301, 3rd Floor, Tryksha Desire, Nr. Kirtidham Derasar, Opp. Shivshakti Bus Stop, Chandkheda, Ahmedabad – 382424, Gujarat, India.
Corporate Office: #108 Startup Huts, 3rd Floor, 27th Main Road, Sector 2, HSR Layout, Bangalore – 560102, Karnataka, India.
This Policy does not apply to third-party websites, applications, or services that may be linked to or integrated with the Services, including those of partner banks, PSPs, NPCI, or merchants using bluSwap's infrastructure. We encourage you to review the privacy policies of any such third parties separately.
This Policy should be read together with our Terms of Service, Cancellation and Refund Policy, Account Aggregator Policy, and Anti-Money Laundering Policy.
2. Key Definitions (aligned to the DPDP Act, 2023)
"Data Principal" means the individual to whom the Personal Data relates. Where the individual is a child, "Data Principal" includes their parent or lawful guardian.
"Data Fiduciary" means bluSwap (WebFinex TechFusion Private Limited), which determines the purpose and means of processing Personal Data.
"Data Processor" means any person who processes Personal Data on behalf of bluSwap, such as our cloud hosting or KYC verification vendors.
"Personal Data" means any data about an individual who is identifiable by or in relation to such data.
"Processing" means a wholly or partly automated operation or set of operations performed on digital Personal Data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, indexing, sharing, disclosure, erasure, or destruction.
"Consent Manager" means a person registered with the Data Protection Board of India who enables a Data Principal to give, manage, review, or withdraw consent through an accessible, transparent, and interoperable platform (where applicable to our Services).
"Significant Data Fiduciary" means a Data Fiduciary notified as such by the Central Government based on factors like volume/sensitivity of data processed, risk to Data Principal rights, and impact on sovereignty and electoral democracy — carrying additional obligations such as appointing a Data Protection Officer and undertaking Data Protection Impact Assessments.
3. Who This Policy Applies To
This Policy applies to:
Visitors to our Website;
Banks, NBFCs, and financial institutions that partner with bluSwap for TSP/PSaaS infrastructure;
Businesses, merchants, and platforms ("Business Users") that use bluSwap's Services to collect, disburse, reconcile, or route payments;
End-customers of Business Users, to the extent their transaction data passes through bluSwap's infrastructure;
Employees, contractors, vendors, consultants, and job applicants of bluSwap.
4. Personal Data We Collect
We collect only the Personal Data reasonably necessary for specified, lawful purposes, consistent with the data minimisation principle under the DPDP Act.
4.1 Business and KYC Information
For banks and Business Users onboarding onto our infrastructure: entity name, constitution, PAN, GST registration, CIN/LLPIN, KYC/KYB documents, proof of identity and address, authorized signatory details, and other documents required for onboarding, risk-graded KYB, and regulatory screening.
4.2 Financial and Payment Information
Bank account numbers, IFSC codes, virtual account details, UPI IDs/VPAs, NEFT/IMPS/RTGS details, and transaction metadata such as amount, currency, timestamp, payment mode, and transaction status.
4.3 Technical, Log, and Device Information
IP address, browser type, device identifiers, operating system, geo-location (where permitted), pages visited, referring/exit URLs, API call logs, request/response metadata, and error logs generated through use of our dashboards, APIs, or smart routing/reconciliation systems.
4.4 Communications Data
Information you provide when contacting our support team (support@bluswap.co), submitting a partnership/business inquiry (info@bluswap.co), subscribing to updates, or participating in surveys.
4.5 Information from Third Parties
Information received from partner banks, NPCI, PSPs, card networks, credit bureaus, or Account Aggregators (with your consent, under our AA Policy), to the extent necessary to complete a transaction, perform verification, or assess risk.
We do not knowingly collect sensitive categories such as biometric data, health records, religious or political beliefs, or genetic information, unless specifically required for a regulated onboarding process and permitted under applicable law.
5. Notice and Purpose of Processing
In accordance with Section 5 of the DPDP Act, before or at the time of requesting your consent, we will provide (or have provided, through this Policy) an itemised notice describing the Personal Data to be collected and the purpose of processing. We use your Personal Data to:
Onboard and verify banks, Business Users, and their authorized representatives;
Provision and operate Services such as virtual accounts, collections, payouts, escrow, smart routing, tokenization, and reconciliation;
Facilitate real-time transaction processing across UPI, NetBanking, RuPay, and other rails;
Perform risk assessment, fraud detection, AML/KYC screening, and compliance checks under applicable law;
Monitor system health, improve uptime, and optimize routing and success rates (e.g., via OptiPay™);
Communicate with you regarding onboarding status, service updates, security alerts, and support;
Send product updates, newsletters, or marketing communications (only where you have opted in, and you may unsubscribe at any time);
Enforce our Terms of Service and this Policy, and investigate suspected fraud, misuse, or illegal activity;
Comply with directions from the Reserve Bank of India ("RBI"), NPCI, law enforcement, or other regulators.
We will not process Personal Data for any purpose beyond what was notified to you, except where processing is permitted without consent under Section 7 of the DPDP Act (for example, compliance with law, response to a medical emergency, or purposes related to employment).
6. Consent
Where we rely on your consent to process Personal Data, that consent will be free, specific, informed, unconditional, and unambiguous, indicated through a clear affirmative action (e.g., a checkbox or explicit sign-up action), and limited to the Personal Data necessary for the specified purpose, consistent with Section 6 of the DPDP Act. Every request for consent will be presented in clear and plain language, giving you the option to access it in English or any language listed in the Eighth Schedule to the Constitution of India.
You have the right to withdraw your consent at any time, as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out before withdrawal, but may mean we can no longer provide certain Services that depend on that processing. To withdraw consent, write to us at the contact details in Section 16, or through any Consent Manager platform we may make available.
Certain processing (e.g., transaction records required for RBI compliance, or disclosures to law enforcement) does not require your consent, as permitted under the DPDP Act and other Applicable Laws.
7. Cookies and Similar Technologies
Our Website and dashboards may use cookies and similar technologies to recognize your browser, remember preferences, and understand usage patterns. You can configure your browser to refuse cookies, though this may limit certain features of the Services. We may use third-party analytics tools (e.g., for aggregate usage statistics); these providers do not receive your name, financial details, or other directly identifying Personal Data through such tools.
8. Sharing and Disclosure of Information
We do not sell your Personal Data. We may share it with:
Banking and PSP partners integrated into bluSwap's infrastructure, strictly to complete the transaction, collection, payout, or reconciliation you or your platform initiated;
NPCI and card networks, as required to route UPI, RuPay, or NetBanking transactions;
Regulators and government authorities, including the RBI, the Data Protection Board of India, law enforcement, or courts, where required under Applicable Law, court order, or lawful government request — we do not independently contest the validity of such requests;
Data Processors and service providers (e.g., cloud hosting, KYC verification vendors, SMS/email providers) engaged under a valid contract, who are bound to use data only for the purpose specified and to maintain reasonable security safeguards;
Affiliates and successors, in connection with any merger, acquisition, restructuring, or sale of assets, subject to equivalent privacy protections;
Auditors, Data Protection Officers, and certification bodies, for ISO, VAPT, PCI-DSS, or DPDP Act compliance audits.
Any Business User or bank receiving data through bluSwap's infrastructure to fulfil a transaction is independently responsible for its own use of that data (acting as an independent Data Fiduciary in its own right), and we are not liable for the data practices of such third parties beyond our contractual obligations with them.
9. Data Security and Breach Notification
We maintain reasonable security safeguards appropriate to the sensitivity of the Personal Data we process, as required under Section 8(5) of the DPDP Act and the Information Technology Act, 2000, including ISO-aligned security controls, periodic VAPT (Vulnerability Assessment and Penetration Testing), risk-graded onboarding checks, and encryption of sensitive data in transit and at rest.
In the event of a personal data breach, we will, as required under Section 8(6) of the DPDP Act, intimate the Data Protection Board of India and affected Data Principals in the form and manner prescribed under applicable rules, including the nature, extent, and likely consequences of the breach and the measures taken to mitigate risk.
No method of transmission over the internet or electronic storage is completely secure. While we work to protect your information using industry-standard safeguards, we cannot guarantee absolute security, and you acknowledge this inherent risk when using the Services.
10. Data Retention
We retain Personal Data only for as long as necessary to fulfil the purpose for which it was collected, or as required to comply with any legal obligation, in line with Section 8(7) and Section 8(8) of the DPDP Act. Where required for a specified purpose and there is no legal obligation to retain it, we will erase Personal Data (and cause our Data Processors to erase it) if you do not approach us to exercise your rights within such period as may be prescribed, or upon the purpose ceasing to be served — for example:
Transaction and KYC records: retained for the periods mandated by RBI/PMLA and other Applicable Laws;
API and system logs: typically retained for up to 12 months, unless a longer period is required by law or an active investigation;
Marketing/communication preferences: retained until you withdraw consent or unsubscribe.
11. Your Rights as a Data Principal
Under Chapter III of the DPDP Act, you have the right to:
Right to access information — obtain a summary of the Personal Data we process about you, the processing activities undertaken, and the identities of Data Processors and other Data Fiduciaries with whom your Personal Data has been shared, along with a description of the data shared.
Right to correction and erasure — request correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, updating of Personal Data, and erasure of Personal Data that is no longer necessary for the purpose for which it was processed, unless retention is required by law.
Right of grievance redressal — raise a grievance with us regarding the processing of your Personal Data (see Section 13) before approaching the Data Protection Board of India.
Right to nominate — nominate another individual to exercise your rights under the DPDP Act in the event of your death or incapacity.
Right to withdraw consent — at any time, as described in Section 6.
We will respond to verified requests within the timelines prescribed under the DPDP Act and its rules. Please note that exercising certain rights (such as erasure) may limit or prevent our ability to provide Services to you, and will not affect the lawfulness of processing carried out before the request.
12. Links to Other Websites
The Website may contain links to third-party websites, banking partner portals, or NPCI/PSP resources for your convenience. We do not control and are not responsible for the privacy practices of these third parties. We recommend reviewing their respective privacy policies.
13. Grievance Redressal
If you have questions, complaints, or concerns about this Policy or how your Personal Data is handled, please contact our Grievance Officer:
Grievance Officer: Debasish Das
Company: WebFinex TechFusion Private Limited
Registered Office: #301, 3rd Floor, Tryksha Desire, Nr. Kirtidham Derasar, Opp. Shivshakti Bus Stop, Chandkheda, Ahmedabad – 382424, Gujarat, India.
Email: support@bluswap.co
We aim to acknowledge and address grievances within the timelines prescribed under the DPDP Act, the Information Technology Act, 2000, and applicable RBI guidelines. If you are not satisfied with our response, you may file a complaint with the Data Protection Board of India, established under the DPDP Act, subject to its prescribed procedure.
If bluSwap is notified as a Significant Data Fiduciary under Section 10 of the DPDP Act, we will additionally appoint a Data Protection Officer based in India, who will be the point of contact for grievance redressal, and undertake periodic Data Protection Impact Assessments and independent data audits as required.
14. Changes to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or Services (including new products under our Payment OS). Material changes will be notified through a prominent notice on the Website or by email, and where required by law, we will seek fresh consent. Non-material changes take effect upon publication. Continued use of the Services after any update constitutes acceptance of the revised Policy.
15. Governing Law and Jurisdiction
This Policy is governed by the laws of India, including the DPDP Act, 2023 and the Information Technology Act, 2000. Any disputes arising out of or relating to this Policy shall be subject to the exclusive jurisdiction of the competent courts at Ahmedabad, Gujarat, India, without prejudice to the Data Protection Board of India's jurisdiction over DPDP Act complaints.
16. Contact Us
For any questions about this Privacy Policy, please reach out to:
WebFinex TechFusion Private Limited
Registered Office: #301, 3rd Floor, Tryksha Desire, Nr. Kirtidham Derasar, Opp. Shivshakti Bus Stop, Chandkheda, Ahmedabad – 382424, Gujarat, India.
Corporate Office: #108 Startup Huts, 3rd Floor, 27th Main Road, Sector 2, HSR Layout, Bangalore – 560102, Karnataka, India
Email: support@bluswap.co / info@bluswap.co
Website: https://www.bluswap.co