Dashboard Account Aggregation Services Private Limited (herein after called as “the Company”) is an NBFC-Account Aggregator (NBFC - AA), registered with Reserve Bank of India.
Saafe is the brand name of the product of the Company. Saafe is an empowering one-stop solution for providing a real-time aggregated view of financial assets for Individuals and Enterprises from multiple financial institutions (Banks & NBFCs, Mutual funds, Insurance providers), EPFO, Income tax and GSTN. This state-of-the-art API driven solution puts you in the driver’s seat of managing your finances and personal wealth.
Saafe enables an Individual & Enterprise to share their financial information securely and digitally with any other regulated financial institution in the AA network. Saafe is data blind and is not allowed to share such information without the consent of the Individual / Enterprise.
Dashboard Account Aggregation Services Private Limited recognizes the importance of maintaining the customer’s privacy. The Company is committed to maintaining the confidentiality, integrity and security of all information of our customers / users. This Privacy Policy describes how the Company collects and handles certain information it may collect and/or receive from the user / customer via the use of this Platform. This Privacy Policy applies to current and former visitors to our Platform. By visiting and/or using our Platform, you are accepting and consenting to the practices described in this Privacy Policy.
2. Scope of the Policy
This policy governs the access to, and use of the Company’s mobile application and Website (“Platform”) and the Services rendered.
This Privacy policy, along with the “Terms of Use” constitutes an “electronic record” in the form of an “electronic contract” as defined under the Information Technology Act, 2000 between “Company” and the user of Platform. This Privacy Policy does not require any physical, electronic or digital signature.
The terms “Company” / “We” / “Us” / “Our” used in this policy refer to Dashboard Account Aggregation Services Private Limited and the terms “You”/ “Your”/ “Yourself” used in these “Terms of Use” refers to the End-User of the Platform/Services.
This Privacy Policy forms an integral part of the “Terms of Use” of the Platform. If you do not agree with the terms of this Privacy Policy, please do not use this Platform.
By visiting this Platform, you (a) unconditionally accept, and agree to be bound by the “Terms of Use” of the Platform, read with this Privacy Policy; (b) expressly consent to the collection, receipt, possession, storage, usage, dealing, handling or transfer of your personal information by Company in accordance with the terms of this Privacy Policy.
The Privacy Policy can undergo changes from time to time at the discretion of the Company. Therefore, it is suggested that you regularly check the Platform to be apprised of the latest changes made to the Privacy Policy.
Terms used in this Policy shall have the same meaning as ascribed to them in the Master Direction- Non-Banking Financial Company - Account Aggregator (Reserve Bank) Directions, 2016 (hereinafter called "AA Master Directions") and subsequent amendments thereto, unless the context indicates otherwise.
This Privacy Policy is designed to familiarize users of this Platform with (a) type of information that users may share with the Company, or that the Company may collect from users; (b) practices and policies of the Company relating to collection, storage, dealing, transfer, disclosure etc. of information pertaining to users; (c) purpose of collection and usage of such information, and related matters.
This Privacy Policy explains how we protect sensitive personal data or information provided by You through the Platform and how we store and use that information, to deliver the services on the Platform.
3. Collection of “Information” and Usage Information
During your usage of our Platform and for purpose of rendering Services, we may collect any of the following information:
Data pertaining to your identity and related data, such as your first and last name, username or similar identifiers, gender, title, passwords, identity document and proof of addresses, purchases or orders of or through our Services, feedback, survey responses, etc.
Contact data, including email addresses, phone numbers, delivery addresses, business addresses, etc.
Data about your device, including but not limited to:
Location – location data recorded on your device; and
Device Information – including hardware model, operating system and version, IMEI and serial numbers, user profile information, IP addresses, browser types and versions, time zone settings, and Wi-Fi and mobile networks.
Usage data, including information about how you use our Services; and
Marketing and communications data, including your preferences in receiving marketing from us and our third parties and your communication preferences.
We also collect, use, and share aggregated data such as statistical data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data under applicable laws. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific feature of the Services. However, if we combine or connect aggregated data with your personal data, we treat the combined data as personal data, which will be treated in accordance with other terms of this Policy.
Please note that in accordance with applicable laws, we do not store or use any financial data that you choose to share with third parties or otherwise transmit through our Services (“Financial Data”). You may use our Services to transmit and share Financial Data with third parties; however, we will not have access to such data. For more information on how your Financial Data is transmitted through our Services, please review our Terms.
Where we need to collect personal data by law, or under the terms of the arrangement we have with you, and if you fail to provide that data as and when requested by us, we may not be able to perform our obligations under the arrangement we have with you or are trying to enter into with you (for example, to provide you with features of the Services). In this case, we may have to cancel or limit your access to the Services, but we will notify you if this is the case at the time.
The Company may collect, store and use Information for any purpose as may be permissible under Applicable Laws, including but not limited to the following:
To fulfill/complete your requests for the services offered, subscribed or availed by you on the Platform.
To protect integrity of the Platform, improve our platform, prevent or detect fraud or abuse of our Platform.
To personalize your experience and better our responses to match your requirements, wherever possible.
To improve our digital properties based on visitor profiles, servicing patterns, and their exact requirements.
To improve customer service based on the feedback provided by the User.
Use analytics to track the traffic patterns, sources of traffic, user preferences, referrals, etc., and use such analytics to improve the services.
To send periodic emails/SMS to email address/phone numbers provided. These details are used to send you information and updates about your order or request, in addition to receiving periodic news/updates/promotions / related products or services provided by the Company and informative and educative material(s) that we deem appropriate.
To trace computer resources of any person for the purposes of determining compliance with the provisions of the Information Technology Act, 2000 and / or any other law for the time being in force.
The mobile number obtained may be used for, but not limited to, send to or directly read SMS from the mobile, enabling auto read is for any of the following purposes or during the events such as, but not limited to: Sign Up, Forgot PIN, Account Discovery, Account Linking, Update or Revoke Consent, Delink Accounts, Close Account.
4. Cookies
We use cookies and/or other tracking technologies to distinguish you from other users of the Services and to remember your preferences. This helps us to provide you with a good experience when you use our Services and also allows us to improve the Services.
We collect data by way of ‘cookies’. Cookies are small data files which are sent to your browser from the Platform and are stored on your computer or device (hard drive). The cookies shall not provide access to data in your computer or device such as email addresses or any other data that can be traced to you personally. The data collected by way of cookies will allow us to administer the Services and provide you with a tailored and user-friendly service. The cookies shall enable you to access certain features of the Services. Most web browsers and devices can be set to notify when you receive a cookie or prevent cookies from being sent. If you do prevent cookies from being sent, it may limit the functionality that we can provide when you visit the Platform or try to access some of the Services.
Additionally, you may encounter cookies or other similar devices on certain pages of the Services that are placed by third parties. We do not control the use of cookies by third parties. If you send us personal correspondence, such as emails or letters, or if other users or third parties send us correspondence about your activities in relation to the Services, we may collect such information into a file specific to you.
Further details are also available in our Cookie Policy.
5. Disclosure and Retention of User Information
The Company considers Information about its customers an important part of its business. Accordingly, the Company shall not engage in the sale of Information relating to Users to third parties. However, the Company may share user information with third parties in the circumstances specified herein below, after reasonably assuring itself that such third parties have undertaken to maintain confidentiality of Personal Information relating to the users:
Third Party Service Providers: The Company may engage third party service providers to render various services (other than the core service of Account Aggregation) and perform various functions in relation to the business undertaken on the Platform. For instance, the Company may engage third party services providers for maintenance of its website, analyzing data, providing marketing assistance, provision of customer services etc.
Business Transfers: The Company may transfer or otherwise share some or all of its assets, including your Information in connection with a merger, acquisition, reorganization or sale of assets or business or in the event of bankruptcy. Should such a sale or transfer occur, the Company will reasonably ensure that the Information you have provided and which we have collected is stored and used by the transferee in a manner that is consistent with this Privacy Policy. Any third party to which the Company transfers or sells as aforesaid will have the right to continue to use the information that you provide to us or collected by us immediately prior to the transfer.
Government Agency: The Company may share any Information relating to Users (i) with Government agencies mandated under the law to obtain Information relating to users from the Company; (ii) any third party, when the Company is required to disclose the same under an order of a Government or judicial authority under any law for the time being in force, or where such disclosure is necessary for the compliance of a legal obligation.
With User Consent: Without prejudice to the aforesaid, the Company may disclose Personal Information relating to the User with his / her consent. For this purpose, the Company may send a prior notice to the User before sharing Personal Information relating to the User with third parties. In case no objection or intimation is received from the User, the Company would presume that User has granted its consent for sharing of said Information with third parties.
By using or visiting the Platform and agreeing to the terms of this Privacy Policy, the User shall be construed to have consented to and accepted the disclosure of his Information to third parties as provided under this Privacy Policy.
The Company shall retain information of a user collected for registration on the Platform for a period of one hundred and eighty days after any cancellation or withdrawal of his/her registration, as the case may be.
The Company will share your Personal Information internally with those staff members who need it to complete provision of services to you on the Platform.
The Company shall keep sensitive personal data or information for only as long as the purposes for which the information may lawfully be used or is otherwise required under any other law for the time being in force. For those customers who have registered for the mailing list, their personal information is kept until we are notified that they no longer want their information stored.
6. Company’s Commitment to Data Security
The Company will adopt required IT framework and interfaces to ensure secure data flows from the Financial Information providers to its own systems and onwards to the Financial Information users.
The Company will not request or store your credentials (like passwords, PINs, private keys) which may be used for authenticating you to the Financial Information providers.
We shall access your information only based on consent-based authorization.
We shall build adequate safeguards in our IT systems to ensure that they are protected against unauthorized access, alteration, destruction, disclosure or dissemination of records and data.
The Company shall take all reasonable measures to secure its Platform and information contained therein following the reasonable security practices and procedures as prescribed in the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Information) Rules, 2011.
7. Accuracy and Protection of Personal Information
The Company relies on our customers notifying us of any changes in personal information. Should inaccurate information come to our attention, we will investigate and correct the information and, if necessary, appraise you of the change. Only those staff members who need your personal information in order to respond to your requests are given access to it. Employees are provided with training and information regarding the proper handling of personal information. All information stored in our computer system is protected from unauthorized access and information that is stored in document form is kept in secure locations to prevent access by unauthorized people.
8. Data Retention
The Company operates as a Non-Banking Financial Company – Account Aggregator (“NBFC-AA”) under the directions issued by the Reserve Bank of India and adheres strictly to the principles of data minimization and purpose limitation.
No Storage of Financial Information
In accordance with the RBI AA framework, the Company does not store, process, or retain customers’ financial information (including bank statements, transaction data, or investment details). Financial information is retrieved from Financial Information Providers (FIPs) and transmitted to Financial Information Users (FIUs) on a consent-based, encrypted, and real-time basis.
Consent Artefacts and Metadata
The Company maintains records of:
User consent artefacts
Consent logs (including timestamps, purpose, frequency, and data attributes)
Transaction metadata
These are retained strictly as required under applicable RBI directions to ensure auditability, traceability, and grievance redressal.
Retention Period
Consent records and logs are retained for such minimum duration as may be prescribed under the RBI framework and other applicable laws, including for:
Regulatory inspections
Dispute resolution
Fraud monitoring
Revocation and Expiry of Consent
Upon consent expiry or revocation by the customer, no further data flows are enabled. Historical logs remain retained only to the extent mandated for compliance and audit purposes.
Secure Deletion
All retained data is securely deleted or anonymized upon expiry of the applicable retention period, in line with RBI-prescribed security and data lifecycle standards.
9. Security Measures and Disclosures to Third Parties
Security Measures
The Company implements robust security controls in compliance with RBI’s NBFC-AA Master Directions and technical specifications issued under the AA ecosystem.
End-to-End Encryption
All financial information is transmitted using strong, end-to-end encryption, ensuring that the AA acts purely as a secure data “pipe” and cannot access readable financial data.
Data Blind Architecture
The AA follows a “data-blind” architecture, meaning it does not have visibility into the contents of the financial information being transmitted.
Authentication and Consent Validation
All data flows are subject to:
Strong customer authentication
Consent validation through standardized artefacts
Secure APIs prescribed under the AA ecosystem
Access Controls and Monitoring
Role-based access control (RBAC)
Continuous monitoring and logging of system access
Periodic review of access privileges
Infrastructure Security
Secure hosting environments compliant with RBI expectations
Network security controls, firewalls, and intrusion detection systems
Regular vulnerability assessments and penetration testing
Audit and Compliance
The Company undergoes:
Periodic system audits
Information security audits
Compliance reviews as mandated by the RBI
Incident Response
A documented incident response framework is in place to detect, contain, and report security incidents, including reporting to regulators where required. Reporting the incident in the prescribed format of the regulator to be followed.
10. Disclosures to Third Parties
The Company adheres to strict limitations on data sharing as prescribed under the RBI AA framework.
Consent-Based Data Sharing Only
Financial information is shared only with Financial Information Users (FIUs) and strictly pursuant to:
Explicit, informed, granular, and revocable customer consent
Standardized consent artefacts
No Use Beyond Purpose
The Company does not use, store, or analyze financial information for any purpose other than facilitating its transfer as per consent.
Prohibition on Unauthorized Disclosure
The Company does not sell, trade, or otherwise monetize customer data.
Regulatory Disclosures
Information will be disclosed:
To the Reserve Bank of India
To other regulators, courts, or law enforcement agencies strictly in accordance with applicable law.
Outsourcing and Service Providers
Where third-party service providers (e.g., cloud infrastructure providers) are engaged:
They are bound by RBI-compliant outsourcing and confidentiality obligations
They do not have access to decrypted financial information
Adequate due diligence and ongoing monitoring is conducted
Cross-Border Restrictions
Any data handling complies with RBI guidance on data localization and cross-border data flows, where applicable.
11. Employee and Vendor Data
Employee Data
The Company processes personal data of its employees in accordance with applicable Indian laws and internal policies, while maintaining alignment with its obligations as an NBFC-AA.
Confidentiality and Access: Employees are subject to:
Strict confidentiality obligations
Information security training
Role-based access restrictions, especially with respect to AA systems
Restriction on Data Access:
Employees do not have access to customers’ financial information, consistent with the AA’s data-blind design.
Vendor Data
The Company collects and processes personal data of vendors and service providers for legitimate business and compliance purposes.
Vendor Management:
Due diligence is conducted prior to onboarding vendors
Vendors are contractually bound to comply with:
RBI outsourcing guidelines applicable to NBFC-AAs
Data protection and confidentiality obligations
Permitted Use: Vendor data is used only for:
Contract execution
Payment processing
Compliance and audit requirements
Security Requirements: Vendors are required to implement:
Adequate security controls
Access restrictions
Incident reporting mechanisms
Data Retention and Protection
Employee and vendor data is retained only for as long as necessary to meet:
Contractual obligations
Legal and regulatory requirements
Appropriate safeguards, including encryption, access controls, and secure storage, are applied to such data.
12. Customer Grievance
In case you have any grievances or want to address any discrepancy with respect to the processing of any of the information/data you provided to the Company, please contact our Grievance Officer. The name and contact details of the Grievance Officer are available on the Grievance Redressal Policy page of the Company.