Privacy Policy
Last Updated: October 24, 2023
1. Our Core Philosophy: Data Sovereignty
At Wisi Pay, we build infrastructure that you own. Unlike traditional aggregators, our primary delivery model is self-hosted technology. This means:
- Self-Hosted Tech: When you deploy Wisi Core on your own servers (AWS/GCP/Azure), we do not have access to your customer's transaction data. The data resides entirely within your VPC.
- Hosted APIs: For services we host (like Compliance Suite or LedgerLink), we act as a Data Processor, while you remain the Data Controller.
2. Information We Collect
We collect information to provide and improve our services.
A. Account Information
Name, email, company details, and billing information when you sign up for our services.
B. API Usage Data
Logs of API calls, timestamps, latency metrics, and error codes to monitor system health and billing. We scrub PII (Personally Identifiable Information) from these logs wherever possible.
C. End-User Data (Hosted Services Only)
If you use our Compliance Suite, we process KYC documents (IDs, photos) solely for verification purposes. This data is encrypted at rest and in transit.
3. How We Use Information
We use your data to:
- Authenticate your access to the Wisi Pay dashboard.
- Process API requests for Compliance and LedgerLink services.
- Send critical technical alerts (e.g., "Bank Gateway Down").
- Generate billing invoices based on usage volume.
We do not sell your data to third parties. Ever.
4. Data Retention
For our hosted services, we retain logs for 90 days for debugging purposes, after which they are archived or deleted. Transactional metadata required for compliance (e.g., KYC audit trails) is retained for 5 years as mandated by RBI/PMLA guidelines.
5. Security
We employ banking-grade security measures:
- Encryption: AES-256 for data at rest; TLS 1.3 for data in transit.
- Access Control: Strict Role-Based Access Control (RBAC) for our internal teams.
- Audits: Regular VAPT (Vulnerability Assessment and Penetration Testing) by third-party security firms.
Contact Us
If you have any questions about this Privacy Policy, please contact our Data Protection Officer at:
[email protected]