Privacy policy
This policy explains what Nexdha collects when you use the Nexdha app, why we collect it, who else sees it, how long we keep it and what you can ask us to do with it. It is written to be read rather than to be survived, so if something here is unclear, write to us and we will explain it in plain terms.
Nexdha is operated by Nexdha AI Fintech Private Limited, a company incorporated in India with its registered office at 3rd Floor, Plot No. C-15/1, Secretariat Colony, Thiruvalluvar Nagar, Alandur, Chennai, Tamil Nadu 600016. In this policy, "Nexdha", "we", "us" and "our" mean that company, and "you" means the person using the app. For the purposes of the Digital Personal Data Protection Act, 2023, Nexdha is the data fiduciary for the personal data described below.
This policy applies to the Nexdha Android app published on Google Play as Nexdha: Bills & Payments, to this website, and to any email or in-app support conversation you have with us.
What this policy covers
1. What we collect
We collect the following categories of information. Some of it you give us directly, some is generated when you make a payment, and some is collected automatically by the app.
Account and profile information
Your name, date of birth, gender if you choose to provide it, the city or address you enter, your profile photo if you upload one, your preferred language, and the username and password or PIN that secure your account. For business accounts we also collect the entity name, constitution, GST number and the details of the authorised person operating the account.
Mobile number and email address
Your mobile number and email address, which we use to create and verify your account, to send one-time passwords, to send payment receipts and to reach you about a transaction. We verify your mobile number by sending a code to it. Verification of your mobile number is necessary to hold an account.
Bank and payment information
The payment instruments you use and the accounts you pay from. For cards, this means the card network, the issuing bank, the card type, the expiry month and year and the last four digits, together with a reference held by our payment gateway that lets a saved card be charged again with your approval. For UPI, this means your UPI handle and the app you approve the payment in. For bank transfers, this means the account number and IFSC you provide.
We do not receive or store your full card number, your CVV or your card PIN, and we do not receive your UPI PIN or your net banking password. Card details are entered on the payment gateway's own page, and those fields never pass through a Nexdha server. Nobody at Nexdha can see them, and no Nexdha employee will ever ask you for them.
Transaction information
For every payment you make: the amount, the date and time, the category, the payment method used, the convenience fee and the tax on it, the status of the payment, the bank reference number such as the UTR, the receipt we issue, and the reason for failure if it fails. We also keep the record of refunds, reversals, chargebacks and any dispute you raise.
Credit-card bill-payment information
Where you use Nexdha to pay a credit card bill, we collect the details needed to route that payment: the card network and issuing bank, the last four digits of the card being paid, the cardholder name as it appears on the statement, the amount due or the amount you choose to pay, and the due date if you enter it or we are able to retrieve it. We use these details to make the payment and to send you reminders you have asked for. We do not use them to assess your creditworthiness, and we do not sell or share them for anybody's marketing.
Receiver and beneficiary information
To pay a bill or an invoice we need to know who is being paid. This means, depending on the category: the biller and your consumer, customer or account number with them; or a beneficiary's name, bank account number and IFSC, or UPI handle; or a landlord's or vendor's name and contact details; or an educational institution and a student identifier. Where the amount is large, or the category calls for it, we may also collect a supporting document such as a rent agreement, fee notice or invoice.
If you give us another person's details so that we can pay them, you confirm that you are entitled to share those details with us for that purpose. We use them only to make and evidence the payment you asked for.
KYC information
To meet identity verification obligations we collect your PAN, and depending on the checks that apply to your account, an officially valid document such as your Aadhaar, passport, driving licence or voter identity card, along with a photograph or selfie for liveness verification. Business accounts also provide their certificate of incorporation or registration, GST registration and the identity documents of the authorised signatory.
Where we collect an Aadhaar number, we hold it in redacted form, so that only the last four digits are visible, and we do not store your Aadhaar biometrics. KYC records are handled as confidential, are available only to staff performing verification and compliance work, and are retained for the period the law requires even after your account is closed.
Device information
The make and model of your device, the operating system and its version, the app version, the device language and region, the screen size, the mobile network operator, whether the device appears to be rooted or emulated, and a device identifier generated for your installation. We use this to make the app work correctly on your device, to diagnose crashes, and to detect fraud, such as one device being used to run many unrelated accounts.
IP address and log information
Each time the app or the website contacts our servers we record the IP address, the date and time, the request made, the response returned, the approximate location derived from the IP address, and the app or browser version. We keep logs of sign-ins, sign-in failures, password and PIN changes, payment attempts, and changes to beneficiaries and account settings. These records are how a disputed transaction gets investigated and how account takeovers get caught.
Location
The app asks for permission to access your device location. We use it to check that a payment is being made from a plausible place, which is one of the stronger signals of fraud available to us; to meet the requirement that we know the location from which financial transactions originate; and to show you billers and services relevant to where you are.
You can refuse the location permission, or withdraw it later in your device settings, and the app will continue to work. If you refuse it, we may fall back on the coarse location derived from your IP address, and a small number of higher-risk payments may need an extra verification step. We collect location only while you are using the app. We do not track your location in the background, and we do not build a location history for advertising.
Camera and photo gallery
The app asks for camera and photo access so that you can complete identity verification: taking a selfie for liveness checking, and photographing or selecting an image of a document such as your PAN card or an officially valid document. You may also use it to attach a copy of a bill or invoice to a payment.
We access only the specific image you capture or choose. We do not scan or index your photo library, and we do not read images you have not selected. If you refuse these permissions you can still use the app, but you will not be able to complete verification steps that require a document or a selfie, and those features will stay unavailable.
Notifications and device identifiers
If you allow notifications, we store the push token issued by Google's Firebase Cloud Messaging for your installation so that we can send you payment confirmations, failure alerts, bill due reminders and security notices such as a sign-in from a new device. We also hold an app-instance identifier and, where available, the Android advertising identifier, which we use for fraud prevention, for measuring whether our own app installs and features work, and for nothing else.
You can turn notifications off in your device settings at any time. We will still send you transaction receipts and important security or legal notices by email or SMS, because those are records of a payment rather than marketing. Marketing messages, where we send them, always carry a way to opt out, and opting out does not affect your account.
2. Device permissions, in one place
These are all the permissions the app asks for, what each is for, and what happens if you say no.
- Location
- Fraud checks, transaction-origin records and locally relevant billers. Optional. Refusing it leaves the app usable; some higher-risk payments may need an extra verification step.
- Camera
- Taking a selfie for liveness verification and photographing KYC documents. Optional. Refusing it means verification steps needing a live capture cannot be completed.
- Photos and media
- Selecting an existing image of a KYC document, a bill or an invoice, and setting a profile photo. Optional, and limited to the file you pick.
- Notifications
- Payment confirmations, failure alerts, bill reminders and security notices. Optional, and revocable in device settings.
- Internet and network state
- Required for the app to reach our servers and to tell you when you are offline.
Android asks you for each of these at the moment the feature needs it, and you can review or withdraw any of them later under Settings, Apps, Nexdha, Permissions on your device.
3. Contacts
The Nexdha app does not request access to your contacts and does not read your address book. When you add a beneficiary, you type or paste the details yourself, or select from beneficiaries you have previously saved inside Nexdha. We do not upload your phone's contact list to our servers, we do not use it to find other Nexdha users, and we do not use it for referrals.
If this ever changes we will ask for the permission explicitly, explain what it is used for before you grant it, and update this policy before the feature ships.
4. Why we collect it
We use the information described above for these purposes and no others.
- To create your account, verify who you are and let you sign in securely.
- To carry out the payments you instruct, and to settle them to the right beneficiary.
- To calculate and show the convenience fee and applicable tax before you confirm.
- To issue receipts, statements and bank references, and to let you export them.
- To send transaction confirmations, failure notices and bill reminders.
- To investigate and resolve failed payments, refunds, reversals, chargebacks and disputes.
- To detect, prevent and investigate fraud, money laundering, account takeover and misuse of the platform.
- To meet our obligations under Indian law, including identity verification, record keeping, tax and reporting requirements, and to respond to lawful requests from authorities.
- To provide customer support, and to keep a record of what was asked and answered.
- To keep the app working: fixing crashes, measuring whether features are used, and improving reliability.
- To tell you about Nexdha features and offers, where you have not opted out.
We do not sell your personal data. We do not rent or trade it. We do not share it with data brokers, and we do not allow third parties to use it to target advertising at you elsewhere.
5. The basis on which we use it
Most of what we do with your information is done because you have consented to it, by creating an account and by granting the specific permissions described above. Consent is asked for in plain language, is specific to a purpose, and can be withdrawn.
Some of it we are required to do regardless of consent: verifying your identity, keeping transaction records, reporting where the law requires reporting, and retaining what financial and tax law says must be retained. Where a legal obligation applies, withdrawing consent does not remove the obligation, and we will tell you when that is the case.
If you withdraw consent for something that is necessary to run your account, such as verification of your mobile number, we may not be able to keep providing the service, and we will say so rather than quietly degrading it.
7. How it is protected
No system is perfectly secure and we would rather describe what we actually do than make claims that sound absolute.
- In transit. All traffic between the app or website and our servers is encrypted using TLS version 1.2 or higher. Unencrypted connections are refused.
- At rest. Databases and backups are encrypted on disk. Particularly sensitive fields, including KYC document references and identity numbers, are encrypted separately so that access to storage alone does not reveal them.
- Card data. Full card numbers, CVV and PINs are never stored by us in any form. Card entry happens on the payment gateway's own page, and we hold only a reference and the last four digits.
- Access control. Access to production data is limited to the small number of staff whose work requires it, is granted by role rather than by person, requires multi-factor authentication and is logged.
- Authentication of payments. Every payment is approved by you with your bank or in your UPI app. We cannot initiate a payment without that approval.
- Monitoring. We keep audit logs of sign-ins, permission changes and payment activity, and we monitor for patterns that suggest fraud or account takeover.
- People. Staff are bound by confidentiality obligations, are trained on handling customer data, and lose access when they change role or leave.
If a breach occurs that affects your personal data, we will notify the Data Protection Board of India and affected users as required by law, describe what happened and what data was involved, and tell you what to do about it. We will not wait until we have a complete picture before telling you something has happened.
Your part matters too. Keep your device locked and its software updated, keep your Nexdha password or PIN to yourself, and never share an OTP with anybody, including anyone claiming to be from Nexdha. We will never ask you for your OTP, your full card number, your CVV or any PIN, whether by call, message or email.
8. How long we keep it
We keep information for as long as your account is open, and after that only for as long as we are required or genuinely need to.
- Transaction records
- Eight years from the end of the financial year in which the transaction took place, to meet financial record-keeping and tax requirements under Indian law.
- KYC records
- Five years from the closure of your account, or from the date of the transaction, whichever is later, as required by anti-money laundering rules. Longer if a matter is under investigation.
- Account and profile data
- While your account is open. Deleted or anonymised within 30 days of account deletion, except what must be retained under the rows above.
- Access and server logs
- At least 180 days, as required of intermediaries under Indian information technology rules, and up to 12 months for security investigation.
- KYC document images
- Retained for the KYC period above, then deleted. Held encrypted and accessible only to compliance staff.
- Support conversations
- Three years from the close of the conversation, so that a recurring problem or a reopened dispute has a history.
- Marketing preferences
- Kept indefinitely in minimal form, so that an opt-out stays honoured and we do not start messaging you again later.
- Disputed or investigated matters
- Until the dispute, chargeback, investigation or legal proceeding is concluded, and then for the applicable period above.
When a retention period ends, the data is deleted or irreversibly anonymised. Anonymised and aggregated figures, which cannot be traced back to you, may be kept for reporting and analysis.
9. Deleting your account and data
You can close your Nexdha account and ask us to delete your data at any time, and you do not have to give a reason.
From the app
Open the app, go to Profile, then Settings, then Delete account, and confirm. We will ask you to verify the request with an OTP so that nobody else can close your account.
By email
Write to support@nexdha.com from the email address on your account, or from any address if you include your registered mobile number, with the subject "Delete my account". We will verify that the request is really from you before acting on it.
What happens next
- We acknowledge the request within 48 hours and confirm what will be deleted and what must be retained.
- Your account is closed and access is stopped straight away. Any payment already in flight will complete or be reversed, because it cannot be left half done.
- Your profile, saved beneficiaries, saved payment instruments, uploaded images and marketing preferences are deleted or anonymised within 30 days.
- Transaction and KYC records are retained for the statutory periods in section 8, in restricted storage used only for legal and regulatory purposes, and are then deleted.
- Backups are overwritten on their normal cycle, which completes within 90 days of deletion.
- We confirm in writing when the deletion is done.
Deleting your account does not reverse payments already made, and does not cancel any amount you owe your card issuer or bank for a payment Nexdha has already settled.
If you want your data removed but not your account closed, tell us which parts. We will delete anything not needed to run the account or required by law.
10. Your rights
Under the Digital Personal Data Protection Act, 2023 and Indian information technology rules, you have the following rights. Exercising any of them is free, and we will not treat your account differently for it.
- To know what we hold
- Ask for a summary of the personal data we hold about you, what we are doing with it and who we have shared it with.
- To get a copy
- Ask for your data in a portable, machine-readable format. Transaction statements can also be exported from the app at any time.
- To correct it
- Have inaccurate or incomplete data corrected or completed. Most profile fields you can edit yourself in the app.
- To erase it
- Have data deleted where it is no longer needed for the purpose it was collected for and no law requires us to keep it. See section 9.
- To withdraw consent
- Withdraw consent for any processing based on it, including permissions and marketing, as easily as you gave it.
- To opt out of marketing
- Refuse promotional messages while continuing to receive transaction and security notices.
- To nominate
- Nominate another person to exercise these rights on your behalf if you die or become incapacitated.
- To complain
- Raise a concern with us and, if we do not resolve it, take it to the Data Protection Board of India.
To exercise any of these, write to support@nexdha.com. We will acknowledge within 48 hours and respond substantively within 30 days. If a request would take longer, we will tell you why and give you a date. If we cannot do what you have asked, we will explain the reason rather than simply declining.
We may need to verify your identity before acting on a request, because acting on an impersonated request would be the worse outcome. We will ask only for what is needed to be sure it is you.
Please give accurate information and do not impersonate anybody else when making a request. Under the Act, a knowingly false or frivolous complaint can attract a penalty imposed by the Board.
11. Children
Nexdha is for people aged 18 and over. We do not knowingly collect personal data from children, we do not offer accounts to them, and we do not direct any advertising at them. If you believe a child has created an account or that we hold a child's data, write to support@nexdha.com and we will delete it and close the account.
Paying a school or college fee for a child is a payment made by you, the adult account holder. Where a student identifier or name is needed to route the fee, we use it only for that payment and treat it as beneficiary information under section 1.
12. Changes to this policy
We will update this policy when what we do changes. The effective date and version at the top always tell you which version you are reading.
For a material change, such as collecting a new category of data, asking for a new permission, using data for a new purpose or sharing it with a new kind of recipient, we will notify you in the app or by email at least 14 days before it takes effect, so that you can read it and decide. Where the change requires your consent, we will ask for it rather than assume it. Minor corrections and clarifications take effect when published.
Continuing to use Nexdha after a change takes effect means you accept the updated policy. If you do not, you can withdraw the relevant consent or close your account under section 9.
13. Contacting us
For anything about this policy, about your data, or to exercise any of the rights in section 10, write to us. Email reaches us fastest and gives us a record we can act on.
Nexdha AI Fintech Private LimitedEmail support@nexdha.com
3rd Floor, Plot No. C-15/1
Secretariat Colony, Thiruvalluvar Nagar
Alandur, Chennai
Tamil Nadu 600016, India
Please mark your email "Privacy" so it reaches the right people quickly. We acknowledge within 48 hours and reply substantively within 30 days.
If you are not satisfied with how we have handled your concern, you may complain to the Data Protection Board of India, established under the Digital Personal Data Protection Act, 2023.