Privacy notice: India
Applies together with the main Privacy Policy. Governing privacy law: Digital Personal Data Protection Act, 2023 and Rules, 2025.
Version 2026-10-08 · Effective 8 October 2026 · IAEX NETWORK (proprietor: Abhishek Tiwari)
This notice is given under section 5 of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 (together the "DPDP law"), and applies to you as a Data Principal when we process your digital personal data in India, or outside India in connection with offering services to you in India. Some provisions of the DPDP law come into force in stages; we apply the standards described here from today. Read it with Part A.
Our role
IAEX NETWORK (proprietor: Abhishek Tiwari) is the Data Fiduciary. Our licensed payment partners and verification providers are separate Data Fiduciaries for their own legal duties, or our Data Processors where they act only on our instructions under a contract. We have not been designated a Significant Data Fiduciary.
The personal data and purposes this notice covers
The data and purposes are listed in Part A, sections 2 and 3: account and contact details, identity and business verification data, screening results, transaction data, and technical and security data. We process them to create and run your account, verify you, instruct and record your payments, issue certificates and statements, prevent fraud and comply with law.
Consent and the other lawful uses
Where we ask for your consent we ask for it separately, in clear and plain language, with a choice to agree or decline, and we record it. You can withdraw consent as easily as you gave it, from your account settings or by writing to connect@iaexnetwork.com. Withdrawal does not affect processing already done, and if you withdraw consent for data that is necessary to provide a service, we will tell you what we can no longer do, and may close that service. We also process data without consent for the legitimate uses the DPDP law permits, mainly: data you voluntarily gave for a stated purpose and did not object to; compliance with a law or a court or regulatory order (for example the Prevention of Money-laundering Act, 2002 and its Rules, the Foreign Exchange Management Act, 1999, tax laws, and CERT-In directions); and responding to a medical emergency or disaster where relevant.
Your rights as a Data Principal
| Right | How we honour it |
|---|---|
| Access | A summary of the personal data we process and the processing we do, the identities of other Data Fiduciaries and Processors we have shared it with and a description of the data shared. |
| Correction, completion, updating | We correct inaccurate or misleading data, complete incomplete data and update it. For verified records we may ask for a document that supports the change. |
| Erasure | We erase your data when you withdraw consent or the purpose is served, unless a law requires us to retain it (Part A, section 6). We also ask our Processors to erase it. |
| Grievance redressal | Write to the Grievance Officer. We acknowledge within 7 days and respond within 30 days, and never later than the 90 days the DPDP Rules allow. |
| Nominate | You may nominate another individual to exercise your rights if you die or become unable to. Send us the nominee's details and consent through the data-request form. |
Please exercise these rights through the data-request form. Under the DPDP law you must not impersonate another person, suppress material information when providing data, or file false or frivolous complaints.
Grievance Officer and the Data Protection Board
Grievance Officer: Abhishek Tiwari, connect@iaexnetwork.com, Plot No. 26, First Floor, Back Left Side, Block A-1, Mohan Garden, Uttam Nagar, New Delhi 110059, India. If we do not resolve your grievance within the period above, or you are not satisfied, you may complain to the Data Protection Board of India through its digital office, after first using our grievance process.
Children and persons with a disability
Vaulte is for people aged 18 or over. If we learn that we hold personal data of a child, or of a person who has a lawful guardian, we will not process it without verifiable consent of the parent or lawful guardian, will not track or monitor the child, and will not use it for targeted advertising.
Breach notification
If a personal data breach happens we tell each affected Data Principal without delay, in plain language, with what happened, the likely consequences, what we have done, safety steps you can take and who to contact. We also inform the Data Protection Board without delay and give it the detailed report within 72 hours. We report cyber incidents to CERT-In within 6 hours as its directions require.
Storage and transfers
Transfers outside India happen as the DPDP law permits: to any country except those the Central Government restricts by notification, subject to stricter laws such as Reserve Bank of India rules on storage of payment-system data in India and any other sector law. We keep records in India or hold the data with the licensed Indian partner where those rules require.
Other Indian laws
Until the DPDP law fully replaces it we also follow the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. We keep KYC and transaction records for the periods in the Prevention of Money-laundering (Maintenance of Records) Rules, 2005 and the Foreign Exchange Management Act, and GST records for the period the Central Goods and Services Tax Act requires.