DEMO ENVIRONMENT - simulated data. No real money moves and no real lending takes place.

भाषा
साइट देखें

अभी केवल अंग्रेज़ी में. इस पृष्ठ का अनुवाद अभी नहीं हुआ है। यह कॉर्पोरेट फ़ाइनेंस और बैंकिंग टीमों के लिए लिखा गया है, जिन्होंने हमें बताया कि वे अंग्रेज़ी में ही पढ़ना पसंद करेंगे। MSME सप्लायर के लिए ज़रूरी पृष्ठों का पूरा अनुवाद हो चुका है।

Legal

Privacy policy

Written to be read. If any part of this is unclear that is our failure - the plain-language summary and the policy are meant to say the same thing.

This page is not yet finalised. It has not been through legal review and does not yet reflect a live entity, its registration, or its actual data processors.

1. Who we are, and what we are not

BZi Growth is a technology and origination platform for invoice finance. We act as a Lending Service Provider to banks and NBFCs.

We are not a lender and we are not a regulated financial institution. We hold no RBI licence or registration and need none in this role - the lender holds the licence and makes every credit decision. We are not a participant in any TReDS exchange.

For the personal data you give us through this platform we are the Data Fiduciary under the Digital Personal Data Protection Act, 2023. For the lending decision itself the bank or NBFC is the fiduciary, and their policy applies alongside this one.

2. The lawful basis we rely on

Mostly your consent, given when you create an account or submit an invoice. For a narrower set of processing we rely on the Act’s legitimate uses - meeting a legal obligation, and data you have voluntarily provided for a specific purpose.

Consent is asked for in plain language, separately from the terms of use, and is specific to the purposes listed below. We do not treat continued use of the site as consent.

3. What we collect, and why

Each purpose below is the reason we hold that data. We do not collect anything for a purpose that is not on this list.

If you are a supplier

  • Business identity - name, GST number, Udyam registration, PAN, registered address. To verify you exist and are eligible.
  • People who use the account - name, email, mobile, role. To let you sign in, and to tell you what is happening to your invoices.
  • Bank account for payouts, verified by a one-rupee credit. To make sure money reaches you and not someone else.
  • Invoices, purchase orders and delivery evidence. This is the asset being financed.
  • Data fetched from government sources - GST filing status, e-invoice references, e-way bills. To confirm the invoice is genuine.
  • Bank statements provided at onboarding. For the lender’s credit assessment.

If you are a buyer

  • Company name, sector and turnover band
  • The contact who confirms invoices, and their confirmation decisions
  • How promptly you have paid the suppliers financed through us

We do not ask a buyer for bank statements, balances or financial records - you are not borrowing. There is one exception, and it is entirely in your hands: a financier considering a specific invoice may ask you for a specific document, and must say why. You can refuse. Refusing does not affect your account, your suppliers, or anything else on this platform - the lender is simply told you declined and decides on the invoice without it. We never pass on a document you have not chosen to give. What a financier can and cannot see about you is set out in full here.

Everyone

  • Technical logs needed to run and secure the service
  • A record of what happened and who did it, for audit

The public pages, including the calculator, need no account. Using the calculator does not create a record of you, and we do not ask for a phone number in exchange for a number.

4. Who we share it with

  • Lenders - only those holding an approved limit on you, and only for an invoice you have submitted.
  • Your buyer - the invoice details we ask them to confirm, which they already hold.
  • Verification providers - GST Suvidha Providers and CERSAI, to run the checks above.
  • Infrastructure providers - hosting, email and storage, acting as Data Processors under contract and only on our instructions.
  • Meeting scheduling - if you book a meeting from our contact page, Cal.com receives your name, email address and anything you write in the booking, to arrange it.
  • Regulators, auditors and courts - where we are legally required to.

We do not sell your data. We do not share it for anyone else’s marketing, and we do not build a separate credit product out of it.

5. Where it is stored

On servers located in India. If we ever transfer personal data outside India we will do so only to countries not restricted by the Central Government, under contractual safeguards, and we will say so here before it happens.

6. How long we keep it

  • Transaction and KYC records - eight years after the facility closes, which is what tax and anti-money-laundering rules require of our partners.
  • Documents for an invoice that was never financed - twelve months.
  • Technical logs - twelve months.
  • Marketing contact details - until you ask us to stop, then deleted.

When a purpose has been served and no legal obligation requires us to keep the data, we erase it. Closing your account does not shorten the periods above, because they are not ours to waive.

7. Your rights

Under the DPDP Act you may:

  • Ask what we hold about you, and who we have shared it with
  • Have it corrected if it is wrong, incomplete or out of date
  • Have it erased where no legal obligation requires us to keep it
  • Withdraw consent at any time, as easily as you gave it. Withdrawal does not undo processing already carried out, and may mean we can no longer offer you the service
  • Nominate someone to exercise these rights if you die or become incapacitated
  • Complain to us, and then to the Data Protection Board of India

Ask through the grievance officer. We reply within the statutory timeline, and if we refuse a request we will tell you which obligation we are relying on rather than simply declining.

8. Security

Access is scoped on the server, per organisation and per role - a financier without a limit on a supplier cannot load that supplier’s deal at all, rather than merely being shown no link to it. Passwords and one-time sign-in codes are stored hashed, never in readable form. Every state change is written to an append-only audit log recording who did it and when.

If a breach occurs that affects your data, we will notify you and the Data Protection Board of India as the Act requires.

9. Cookies

We use a session cookie to keep you signed in, and nothing else. There is no advertising network, no third-party analytics and no cross-site tracking on this site - which is why you are not being asked to dismiss a consent banner.

10. Children

This is a service for registered businesses. We do not knowingly process the personal data of anyone under 18, and no part of this platform is directed at children.

11. Changes

If we change this policy in a way that affects what we do with data we already hold, we will tell you directly rather than quietly reposting the page.