1. Purpose and Privacy Commitment
IDYC360 Private Limited (“IDYC360”) provides real-time entity-centric Fraud & AML Intelligence for financial institutions. This Policy defines how IDYC360 protects personal data and financial-institution (“FI”) data processed in connection with its corporate operations, demonstrations, pilots and product deployments.
IDYC360 follows privacy-by-design, data minimisation, purpose limitation, need-to-know access and security-by-design principles. The platform is designed to minimise dependency on directly identifying customer information by supporting pseudonymised or tokenised entity identifiers wherever the use case permits.
2. Scope
This Policy applies to personal data processed by IDYC360 through its websites, business relationships, workforce operations and product environments, and to personal data supplied by an FI for authorised fraud, AML, risk-monitoring, investigation or related purposes.
For an FI deployment, the FI will ordinarily determine the permitted purpose and data scope. IDYC360 will process such data only in accordance with the applicable agreement, documented instructions, approved use case and applicable law. Roles such as Data Fiduciary/Data Processor will be determined contractually for each engagement.
3. Data Categories Relevant to the IDYC360 Platform
Depending on the FI-approved integration and use case, IDYC360 may process the minimum data required from categories such as:
- Pseudonymised/tokenised payer, beneficiary, account or entity identifiers;
- Transaction identifiers, amount, date/time, transaction type/status and payment/channel attributes;
- Counterparty and relationship signals required for graph/network analysis;
- Geographic attributes such as country, state, district, city or PIN-code-level signals where supplied and authorised;
- Device, channel or session risk attributes where supplied by the FI;
- Behavioural and derived features, transaction velocity measures, entity/network features and historical aggregates;
- Risk scores, risk bands, alerts, model explanations, graph/network indicators and investigation/evidence references;
- Business contact information for authorised FI users and IDYC360 business relationships.
IDYC360 does not require raw customer PII merely for the purpose of graph identity where a suitable pseudonymised identifier can support the approved use case. Data fields are configurable for each FI integration and are subject to agreed data minimisation.
4. Purpose of Processing
Data is processed only for legitimate, authorised purposes associated with the contracted service, including real-time fraud-risk evaluation, AML/transaction monitoring, behavioural anomaly detection, graph-based mule/network analysis, geo-behaviour analysis, alert prioritisation, investigation support, explainability, audit evidence, platform security and service operations.
IDYC360 will not sell FI customer data or use FI-provided production data for unrelated advertising, profiling or commercial data brokerage. Production FI data will not be used to train a general/shared AI model unless this is expressly authorised in writing and legally permissible.
5. Lawful Processing and DPDP Alignment
IDYC360 intends its processing practices to support compliance with applicable Indian data-protection requirements, including the Digital Personal Data Protection Act, 2023 and rules/requirements applicable to the relevant processing activity as they come into force.
The relevant FI remains responsible for establishing the appropriate lawful basis/authorisation for data it provides to IDYC360 where the FI determines the processing purpose.
Where consent is the applicable basis, the responsible party must ensure that consent and associated notices meet applicable requirements. Where another legally permitted use applies, processing must remain limited to that authorised purpose.
6. Privacy-by-Design and Data Minimisation
IDYC360 applies the following design principles:
- Collect/process only fields required for the approved fraud/AML use case;
- Prefer pseudonymised/tokenised identifiers over raw identity attributes where feasible;
- Segregate FI/customer environments and restrict cross-customer access;
- Limit use of sensitive fields to explicitly approved processing;
- Prevent unauthorised secondary use;
- Maintain configurable retention and deletion controls;
- Expose only necessary risk intelligence, alerts and evidence to authorised users.
7. Security Safeguards
IDYC360 applies proportionate technical and organisational safeguards designed to protect confidentiality, integrity and availability, including:
- Role-based access control (RBAC)
- Least-privilege access
- Authenticated service/API access
- Encryption in transit
- Encryption at rest where applicable
- Audit/event logging
- Environment segregation
- Secrets/credential controls
- Backup and recovery measures
- Infrastructure monitoring
- Controlled administrative access
Bank/FI deployments may operate on-premise, private-cloud or hybrid infrastructure according to agreed architecture and security requirements. Security controls are reviewed as the platform and regulatory expectations evolve.
8. AI/ML, FPSM and Automated Risk Intelligence
IDYC360 uses proprietary FPSM, behavioural analytics, graph/network intelligence and AI/ML models to generate risk signals. These outputs are designed to support FI fraud/AML decisioning and investigation and are not represented as infallible determinations of wrongdoing.
The platform is designed to provide explainable risk indicators and decision evidence. Final action, customer treatment, escalation or regulatory reporting remains subject to the FI’s approved policies, governance, human oversight and applicable legal/regulatory requirements unless an expressly authorised automated control has been established by the FI.
9. Graph, Mule-Network and Cross-FI Data Controls
Graph intelligence may analyse relationships among pseudonymised entities, transactions and counterparties to identify multi-hop risk, mule-network indicators, circular fund movement and coordinated activity.
IDYC360 does not assume unrestricted access to data held by other financial institutions. Any cross-FI intelligence sharing must be separately authorised and designed to minimise disclosure.
Where ecosystem intelligence is available, IDYC360’s preferred approach is to consume the minimum necessary privacy-preserving risk signals rather than expose raw customer PII, subject to applicable law, contractual controls and the participating institutions’ governance.
10. Data Sharing and Service Providers
IDYC360 will disclose FI/customer data only to authorised personnel or approved service providers where necessary to deliver or secure the service and where appropriate contractual, confidentiality and security obligations are in place.
IDYC360 will not disclose FI data to another FI or third party merely for analytics or competitive purposes.
Any sub-processor/service-provider access to production data will be governed by the applicable customer agreement, data-processing terms and security requirements.
11. Data Location, Transfer and Deployment
Data location and permitted transfer arrangements will be defined for each FI engagement.
IDYC360 supports on-premise/private-cloud deployment to enable institutions to retain stronger control over regulated or sensitive datasets.
Any transfer outside an approved environment or jurisdiction must be authorised and compliant with applicable contractual and legal requirements.
12. Retention, Deletion and Exit
Personal and FI-provided data will be retained only for the period required by the approved purpose, contractual obligations, applicable regulatory requirements or legitimate security/audit needs.
Retention periods will be defined with the FI for production deployments.
At termination or expiry, data will be returned, deleted, anonymised or retained only where legally/contractually required. Backup copies will be handled according to the applicable backup-retention lifecycle and access restrictions.
13. Data Principal Rights and FI Requests
Where applicable, IDYC360 will support the responsible Data Fiduciary/FI in responding to lawful requests concerning access to information, correction, updating, erasure, grievance handling or other applicable data-principal rights.
Requests received directly by IDYC360 that relate to an FI-controlled dataset will ordinarily be referred to the relevant FI unless IDYC360 is independently responsible for responding.
14. Security Incident and Personal Data Breach
Suspected privacy or security incidents must be reported internally without undue delay.
IDYC360 will investigate, contain, preserve relevant evidence, remediate and notify the affected FI/customer in accordance with contractual obligations and applicable law.
Regulatory or data-principal notifications will be made by the responsible party in accordance with applicable requirements and agreed incident-response responsibilities.
15. Employee and Contractor Responsibilities
Personnel with authorised access to personal or FI data must comply with confidentiality, least-privilege and acceptable-use requirements.
- Access is role-based and should be revoked or adjusted when responsibilities change or engagement ends.
- Personnel must not copy, disclose, export or use protected information outside authorised business purposes.
16. Demonstration, Testing and Synthetic Data
IDYC360 should use synthetic, anonymised or appropriately de-identified data for demonstrations, development and performance testing wherever feasible.
FI production data must not be moved into development/demo environments without explicit authorisation and appropriate safeguards.
Published performance claims derived from synthetic testing must be identified as such and must not be represented as production-FI results.
17. Governance, Audit and Review
Management is accountable for implementation of this Policy. Access, processing and relevant security events should be auditable.
Material changes in product functionality, processing purposes, data categories, deployment architecture, law or regulatory expectations will trigger review of this Policy and associated controls.
This Policy will be reviewed at least annually and updated when necessary. Material exceptions require documented management approval and appropriate risk treatment.
18. Grievance and Privacy Contact
Privacy-related questions, complaints or requests concerning IDYC360-controlled data may be directed to:
IDYC360 Private Limited
Email:
[email protected]
For data processed on behalf of a financial institution, individuals may also be directed to the relevant FI’s designated privacy/grievance channel. IDYC360 will cooperate with the FI according to agreed responsibilities.
19. Policy Statement
IDYC360 is committed to enabling financial-crime intelligence without unnecessary exposure of personal information.
Privacy, explainability, security and data minimisation are treated as core design requirements of the IDYC360 platform and will evolve with applicable law, FI requirements and recognised industry practices.
Approval note: This document should be formally approved by IDYC360 management/Board- authorised authority and operationalised before representing the organisation as having an implemented Data Privacy Policy.