Legal

Data Storage Policy

Unit Of EVARINTECH SOLUTION LLP

Last updated: 14 September 2026

This Data Storage Policy describes where, how, and for how long CREDIZEN Financial Services stores your personal and financial information. It supplements our Privacy Policy and forms part of our commitment to data transparency.


1. Data Residency

All personal data collected by CREDIZEN — including names, PAN details, mobile numbers, credit reports, and financial documents — is stored exclusively on servers located in India, in compliance with the Digital Personal Data Protection Act, 2023 and RBI data localisation guidelines. We do not transfer personal financial data outside the territory of India without your explicit consent and applicable regulatory approval.

2. Types of Data Stored

Data CategoryStorage LocationEncryption
Account credentials (mobile, token)Indian cloud databaseAES-256 at rest
Personal details (name, PAN, address)Indian cloud databaseAES-256 at rest
Credit reports (uploaded PDFs)Indian object storage (encrypted)AES-256 + TLS 1.3
Order & payment recordsIndian cloud databaseAES-256 at rest
Support ticket historyIndian cloud databaseAES-256 at rest
System logsIndian log management serviceTLS 1.3 in transit

3. Security Measures

We implement the following technical and organisational security controls:

  • Encryption in Transit: All data transferred between your browser and our servers uses TLS 1.3 with 256-bit encryption.
  • Encryption at Rest: Sensitive database fields (PAN, financial data) and uploaded files are encrypted at rest using AES-256.
  • Access Controls: Role-based access control (RBAC) ensures only authorised staff can access case data. All access is logged.
  • Multi-Factor Authentication: All CREDIZEN staff accounts accessing client data require 2FA.
  • Regular Backups: Encrypted daily backups with 30-day retention stored in a geographically separate Indian data centre.
  • Penetration Testing: Annual third-party security audits and vulnerability assessments.
  • Incident Response: Documented data breach response procedure. Affected users notified within 72 hours of breach discovery, as required by law.

4. Data Retention Schedule

Data TypeRetention PeriodBasis
Account & profile dataDuration of account + 5 yearsRegulatory compliance
Credit reports & documents3 years from case closureLegal & audit requirements
Payment & invoice records8 yearsIncome Tax Act, 1961
Support communications2 yearsConsumer protection
Server access logs1 yearSecurity monitoring
Marketing consent recordsUntil withdrawn + 1 yearIT Rules, 2021

After the retention period, data is securely deleted using NIST SP 800-88 compliant methods. Digital files are cryptographically wiped; physical records (if any) are shredded.

5. Third-Party Storage

We use the following third-party services for storage and processing, all of whom are contractually bound to maintain confidentiality and store data within India:

  • Cloud Infrastructure: Indian cloud providers compliant with ISO 27001 and SOC 2.
  • Payment Processing: PCI-DSS Level 1 certified payment gateways. Card details are never stored by CREDIZEN.
  • Email / WhatsApp: Communication APIs with data processed in compliance with their respective privacy frameworks.

6. Data Deletion Requests

You may request deletion of your personal data by emailing privacy@credizen.in. Please note: we are required by law to retain certain records (payments, tax invoices) for statutory periods regardless of deletion requests. We will inform you of any data we are legally required to retain and delete the rest within 30 days of a valid request.

7. Cookies & Local Storage

Our website uses browser local storage to hold your session token and basic profile information for a smooth user experience. This data is stored on your device, not on our servers. You can clear it at any time via your browser settings or by clicking "Logout". We do not use persistent third-party tracking cookies.

Chat with us