In order to provide our users with the best quality Services, we need to access and retain certain information about you. The collection, handling, retention and deletion of such information we gather from you is governed by this NeoFinity User Privacy Policy ("Policy") as detailed below. This Policy refersto, incorporates, and includes our Terms of Service.
NeoZAP Application is developed by NeoFinity Services Private Limited, a company incorporated under the Companies Act, 2013 with its registered office at 1094P, Oahfeo Workspaces Frappe, Sector 46, Gurgaon, Haryana, 122001, India.
This policy describes how NeoZAP and Its affiliates/Entities/Subsidiaries/Associates, including but not limited to NeoFinity Services Private Limited (collectively NeoZAP, we, our, us, as the context may require), collect, store, use, and otherwise process your Personal Information through the NeoFinity website, NeoZAP Application, SDK, chatbot, notifications, or any other medium used by NeoZAP to provide its services to you (hereinafter referred to as the Platform).
By downloading or using NeoZAP services, visiting the NeoFinity website, providing your information, or availing our product/services, you expressly agree to be bound by this Privacy Policy and the applicable service/product terms and conditions. We value the trust you place in us and respect your privacy, maintaining the highest standards for secure transactions and protection of your Personal Information.
This Privacy Policy is published and shall be construed in accordance with the provisions of the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which require publishing of the privacy policy for collection, use, storage, transfer, and disclosure of Personal Information including Sensitive Personal Information (collectively referred to as Personal Information), excluding information freely available in the public domain.
Please note, we do not offer any product/service under our Platform outside India. If you do not agree with this Privacy Policy, please do not use or access our Platform.
We may collect your Personal Information when you use our services or Platform or otherwise interact with us during the course of our relationship. We collect Personal Information that is relevant and necessary for providing the services requested by you and for improving the NeoZAP Platform.
Personal and Sensitive Personal Information collected includes but is not limited to:
We and our service providers or business partners may also collect your Persona Information from third parties or publicly available sources for verification, fraud prevention, or regulatory compliance.
Information may be collected at various stages such as:
NeoZAP may process your Personal Information for purposes including but not limited to:
In accordance with Section 6 of the Digital Personal Data Protection Act, 2023, we process your Personal Information only on the basis of your free, specific, informed, unconditional, and unambiguous consent, given through a clear affirmative action — or on another lawful basis permitted under the Act (such as a legitimate use specified in Section 7, legal obligation, or compliance with a judgment/order).
How we obtain consent:
Withdrawal of consent:
You may withdraw any consent previously given, at any time, with ease comparable to the ease with which it was given, through:
Withdrawal of consent is prospective and does not affect the lawfulness of processing carried out before withdrawal. Where a service or feature relies on specific processing for which consent has been withdrawn, that service or feature may become unavailable to you, and we will inform you of this consequence at the time you act to withdraw.
Third-party data: If you provide Personal Information of any other individual (for example, nominee or contact details), you represent and warrant that you have obtained their informed consent to share such information with us for the purposes set out in this Policy.
Personal Information collected through the NeoZAP Platform is primarily stored and processed on servers located within India.
In limited circumstances, certain Personal Information may be transferred to, processed, or accessed by service providers or sub-processors in jurisdictions outside India (for example, cloud infrastructure, crash analytics, or customer communication tools). Any such transfer will be undertaken:
Payment system data regulated under the RBI circular dated 6 April 2018 is stored only in India, in accordance with applicable regulatory requirements.
All Personal Information collected by NeoZAP is stored on servers located within India.
We retain Personal Information only for as long as necessary for the purposes for which it was collected, or for the retention periods mandated by applicable law, whichever is longer.
Indicative retention periods (subject to legal and regulatory requirements in force from time to time):
| Category of Data | Retention Period |
|---|---|
| KYC records, customer identification documents, and transaction records | 5 years from the date of cessation of the business relationship or the date of the transaction, whichever is later (as required under Rule 3 of the PML (Maintenance of Records) Rules, 2005) |
| Account and profile information | Duration of the active account + 3 years after account closure, unless longer retention is required by law |
| Payment and financial transaction logs | 8 years from the date of the transaction (aligned with taxation record-keeping requirements) |
| Device, log, and cookie data | Up to 24 months from collection, unless required longer for fraud investigation or security |
| Marketing preferences and consent records | Duration of the account + 3 years, or until consent is withdrawn, whichever is later |
| Grievance records and correspondence | 3 years from closure of the grievance |
| KYC/account data of rejected or unsuccessful applications | 5 years from the date of rejection |
Data may be retained beyond these periods where necessary to comply with a legal obligation, respond to a lawful request from an authority, detect or prevent fraud, or pursue or defend legal claims. After the applicable retention period ends, we will delete, anonymize, or de-identify your Personal Information in accordance with our internal data deletion standards.
We implement reasonable security practices and undergo internal/external security reviews to protect Personal Information. We use secure servers, firewalls, access controls, and encryption where applicable. However, no system is completely impenetrable, and we do our best to implement industry-standard safeguards.
When using third-party services through our Platform, Personal Information may be collected by those providers and will be governed by their privacy policies. We do not control and are not responsible for third-party privacy practices.
Under the Digital Personal Data Protection Act, 2023, you have the following rights in respect of your Personal Information:
How to exercise your rights:
There is no fee for exercising your rights. We may, however, charge a reasonable fee for manifestly unfounded, excessive, or repeated requests.
The NeoZAP Platform is intended for use by persons who are eighteen (18) years of age or older. We do not knowingly collect, store, or process Personal Information of children (persons under the age of 18) as defined under the Digital Personal Data Protection Act, 2023.
If you are under 18, you must not create an account, attempt KYC, or transact on the Platform. Any account found to belong to a person under 18 will be suspended and the associated Personal Information will be deleted, except where retention is required by law (e.g., under the Prevention of Money Laundering Act, 2002).
Where, in limited and specifically notified circumstances, we process Personal Information of a child or a person with disability, we will do so only after obtaining verifiable consent from the parent or lawful guardian in the manner prescribed under the DPDPA, 2023 and the rules made thereunder. We will not undertake tracking, behavioral monitoring, or targeted advertising directed at children.
If you believe a child has provided us with Personal Information, please write to support@neofinity.in so we can take prompt action.
We may update this Privacy Policy from time to time to reflect changes in our services, technology, legal requirements, or business practices.
Superseded versions of this Policy will be archived and made available on request to privacy@neofinity.in. Continued use of the Platform after the effective date of a revised Policy constitutes acceptance of the revised terms. If you do not agree with a material change, you may withdraw consent and discontinue using the Platform, subject to our retention obligations.
Should NeoFinity Services Private Limited be classified as a Significant Data Fiduciary under Section 10 of the Digital Personal Data Protection Act, 2023, a Data Protection Officer (DPO) based in India and reporting to the Board of Directors will be designated. The DPO will be responsible for overseeing compliance with the DPDPA and serving as the point of contact for data principals and the Data Protection Board.
Current DPO / Data Protection Contact:
Name: Tamanna
Email: dpo@neofinity.in
Postal Address: Neofinity Services Private Limited, Neofinity HQ, Suncity Success Tower, Golf Course Extension Road, Sector 65, Gurugram – 122102, Haryana, India
You may contact the DPO directly for any queries relating to the processing of your Personal Information, exercise of your rights under the DPDPA, or data protection concerns that are not resolved through our standard support channels.
In accordance with the Information Technology Act, 2000, the Consumer Protection (E-Commerce) Rules, 2020, and the Digital Personal Data Protection Act, 2023, the following officer has been designated to address your grievances:
Name: Ajay Yadav
Designation: Grievance Officer
Email: grievance@neofinity.in
Phone: +91 90028 39002
Postal Address: NeoFinity Services Private Limited, NeofinityHQ, Suncity Success Tower, Golf Course Extension Road, Sector 65, Gurugram – 122102, Haryana, India
Working Hours: Monday to Friday, 10:00 AM to 6:00 PM IST (excluding public holidays)
Our Response Commitment:
We will acknowledge your grievance within forty-eight (48) hours of receipt.
We will resolve your grievance within fifteen (15) days of receipt, or within such shorter timeline as may be prescribed by applicable law.
Escalation: If you are not satisfied with the resolution provided by the Grievance Officer, or if your grievance is not resolved within the prescribed timeline, you may escalate your complaint to the Data Protection Board of India established under the Digital Personal Data Protection Act, 2023, at the address and through the mechanism notified by the Government of India. For RBI-regulated concerns, you may also approach the relevant regulator or the RBI Integrated Ombudsman Scheme, as applicable.
For questions or concerns regarding this Privacy Policy or processing of Personal Information, please write to us at support@neofinity.in.
At NeoFinity we’re spearheading a revolution in financial services by building fintech products that give mobile first product experience to the next generation of users.
Contact Us
support@neofinity.in
+91 90028 39002
Corporate Office - Neofinity HQ, Suncity Success Tower, Golf Course Extension Road, Sector - 65, 122102
Registered Address - Neofinity, 1094, Sector - 46, Gurugram - 122001
Copyright © 2026. All rights reserved.