Privacy Policy

Nistula Reality Solutions Private Limited (“Nistula”), a company registered under the Companies Act of 2013, is located at B-70, Ground Floor, Paryavaran Complex, IGNOU Road, South West Delhi, Delhi 110030, India. This Policy outlines how Nistula collects, stores, utilizes, and processes your Personal Information through our website, application, mobile site, chatbot, notifications, and any other medium through which we offer our services (collectively referred to as the “Platform”). By downloading and using our application, visiting our website, or availing yourself of our products and services, you explicitly consent to this Privacy Policy (“Policy”) as well as the relevant service/product terms and conditions. We value your trust and respect your privacy by upholding the highest standards for secure transactions and safeguarding your personal information.

This Privacy Policy has been created in accordance with Indian laws and regulations, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, under the Information Technology Act, 2000, as well as the Aadhaar Act, 2016 and its amendments, which mandate the publication of a privacy policy regarding the collection, use, storage, transfer, and disclosure of Personal Information.

Personal Information refers to all data that can be linked to an identifiable individual, including Sensitive Personal Information, which entails Personal Information that requires enhanced protection due to its sensitive nature. Both types of information will collectively be referred to as “Personal Information.” If you do not agree with the terms of this Privacy Policy, we kindly ask you not to use or access our Platform.

Information Collection

We may gather specific Personal Information when you engage with our services, use our Platform, or interact with us throughout our relationship. The Personal Information we collect is relevant and essential for delivering the requested services and for continuously enhancing our Platform and applications.

The types of Personal and Sensitive Personal Information we may collect include, but are not limited to:

  • Your name

  • Account password

  • Postal address

  • Phone number

  • Email address

  • Contact preferences

  • Identification documents (such as PAN, Passport, Voter ID, etc.)

  • Bank account, credit card, and debit card details

  • Employment verification

  • Educational background

  • Any other information necessary for identity verification

Additionally, Personal Information may also encompass data that does not directly identify you, including but not limited to:

  • Browser information

  • Data collected through cookies (defined below), pixel tags, and similar technologies

  • Demographic information

  • Device-specific details, such as device identifiers, internet bandwidth, mobile device models, browser plug-ins, and cookies or similar technologies that may identify your browser or application

  • Duration of time spent on the Platform

  • IP address and geographic location

Information may be collected at various points during your use of the Company Platform, including:

  • Visiting the Company Platform

  • Registering as a “user” or engaging in any other relationship governed by the terms and conditions listed on the Company Platform

  • Conducting transactions or attempting to transact on the Company Platform

  • Accessing links, emails, chat conversations, feedback, notifications sent by or related to the Company Platform, and participating in our occasional surveys

  • Interacting with any of the Company’s Affiliates, Entities, Subsidiaries, or Associates

  • Applying for job opportunities with the Company

Purpose and Use of Information

The Company may utilize your Personal Information for the following purposes:

  • To create your account, verify your identity, and establish your access privileges.

  • To grant you access to products and services offered by us, our merchants, affiliates, subsidiaries, associates, or business partners.

  • To carry out the KYC compliance process, which is a mandatory requirement as stipulated by various regulatory bodies, including UIDAI under the Aadhaar Act and its associated regulations.

  • To process payments on your behalf based on your instructions, and to communicate with you regarding your inquiries, transactions, or any other regulatory obligations.

  • To enhance your user experience during various processes, including the submission of applications and availing of product/service offerings, by analyzing aggregated user behavior.

  • To monitor and review products/services periodically; customize offerings to improve your experience; and conduct audits.

  • To permit third parties to contact you regarding products and services you have availed or requested on the Company Platform or through third-party links.

  • To perform credit checks, screenings, or due diligence as required by law; detect and protect against errors and fraud; and enforce our terms and conditions.

  • To inform you about online and offline offers, products, services, and updates; and to personalize and improve your experience through marketing, advertising, and tailored product offers.

  • To resolve disputes, troubleshoot issues, provide technical support, and fix bugs to ensure a safe service environment.

  • To identify security breaches and attacks; investigate, prevent, and take action against illegal activities, including fraud or money laundering; and conduct forensic audits as part of internal or external investigations by the Company or government agencies in India or elsewhere.

  • Your data shared with Nistula will primarily be processed in India and in other jurisdictions where a third party engaged by Nistula may process the data on its behalf. By accepting this policy, you explicitly consent to Nistula processing your Personal Information for the purposes outlined herein. Please note that data protection regulations in India or other mentioned jurisdictions may differ from those in your country of residence.

  • To collect information regarding your Covid-19 vaccination status and certificate if such information is required for any service or if you wish to access your vaccination certificate later for travel or other purposes.

  • To comply with legal obligations.

While we may also process your Personal Information for other legitimate business purposes, we are committed to taking appropriate measures to minimize such processing to the extent possible, ensuring less intrusion into your privacy.

Information Sharing and Disclosures

Your personal information is shared in accordance with applicable laws, after conducting due diligence and in alignment with the purposes outlined in this policy.

Personal information will be shared on a need-to-know basis for the following purposes:

  • To facilitate the provision of products/services you have availed and support interactions between you and the service provider, as requested.

  • For Aadhaar authentication by submitting Aadhaar information to the Central Identities Data Repository (CIDR) and National Securities Depository Limited (NSDL).

  • To comply with legal requirements and fulfill Know Your Customer (KYC) obligations mandated by regulatory bodies, based on the regulated services/products you opt for through our platforms.

  • To complete payment transactions initiated by you.

  • To assist financial institutions in verifying, mitigating, or preventing fraud, managing risks, or recovering funds, in accordance with relevant laws and regulations.

  • For services related to communication, marketing, data storage, transmission, security, analytics, fraud detection, risk assessment, and research.

  • To enforce our Terms or Privacy Policy, respond to claims involving third-party rights violations, or to protect the rights, property, or personal safety of our users or the general public.

  • If legally required, or if we believe in good faith that such disclosure is necessary to comply with subpoenas, court orders, or other legal processes.

  • Upon request by government authorities for governmental initiatives and benefits.

  • For grievance redressal and dispute resolution.

Personal information may also be shared with the internal investigation department or with agencies appointed by the company for investigative purposes, whether within or outside Indian jurisdiction.

In the event of a merger, acquisition, reorganization, or restructuring of our business, personal information may be shared with the other business entity involved.

While information is shared with third parties for the purposes set forth in this policy, the processing of your personal information is governed by their policies. The company ensures that these third parties are bound by privacy protection obligations that are no less stringent, wherever applicable and to the extent possible. However, the company may share personal information with third parties such as legally recognized authorities, regulatory bodies, governmental authorities, and financial institutions as per the purposes outlined in this policy or as per applicable laws. We do not assume responsibility or liability for the use of your personal information by these third parties or for their policies.

Storage and Retention

Where applicable, we store personal information within India and retain it in accordance with relevant laws, ensuring it is kept only for as long as necessary to fulfill the purpose for which it was collected.

However, we may retain personal information for a longer period if we believe it is necessary to prevent fraud or future misuse, or if required by law, such as during ongoing legal or regulatory proceedings, or in response to legal and/or regulatory directives, or for other legitimate purposes.

Once the retention period has expired, the personal information will be deleted in compliance with applicable laws.

Reasonable Security Practices

We are committed to protecting your personal information from unauthorized access, alteration, disclosure, or destruction. To achieve this, we use encryption and secure server software, which is in line with industry standards and among the most reliable solutions available today for secure transactions.

Third-Party Products, Services, or Websites

When you use products and services from service providers on our platform, your personal information may be collected by those service providers, and it will be governed by their privacy policies. You are encouraged to review their privacy policies and terms of service to understand how your personal information will be handled by these providers.

Our services may also contain links to other websites or applications. These external sites are governed by their own privacy policies, which are beyond our control. Once you leave our platform (you can identify this by checking the URL in your browser’s address bar or the m-site you are redirected to), any personal information you provide on these sites or applications will be subject to the privacy policy of the respective operator. This policy may differ from ours, so we advise you to review these policies or obtain them from the domain owner before proceeding. We do not assume any responsibility or liability for the use of your personal information by these third parties or their policies.

Your Consent

We process your personal information based on your consent. By using the company platform or services, and/or by providing your personal information, you agree to the processing of your information by the company in accordance with this privacy policy.

If you provide us with personal information relating to other individuals, you confirm that you have the authority to share that information and permit us to use it in line with this privacy policy.

Choice/Opt-out

We offer all users the option to opt out of receiving any non-essential (promotional or marketing-related) communications from us after setting up an account. If you wish to remove your contact information from our mailing lists and newsletters or discontinue any of our services, simply click the unsubscribe button in the emails you receive from us.

Personal Information Access/Rectification and Consent

You have the right to access and review the personal information you have shared with us by submitting a request. Additionally, you may revoke your consent at any time for the storage of your e-KYC information collected as part of the Aadhaar-based e-KYC process. However, revoking consent may result in the loss of access to services that were provided based on that consent. In some cases, we may still retain your information as outlined in the “Storage and Retention” section of this policy. To submit any of these requests, please contact us using the information provided in the “Contact Us” section of this policy.

If you wish to delete your account or personal information, please reach out to us via the “Contact Us” section on the company platform. However, retention of your personal information will be subject to applicable laws.

For the above requests, we may require specific information from you to confirm your identity and ensure proper authentication. This is a security measure to prevent unauthorized disclosure, modification, or deletion of your personal information.

For additional information specific to the products or services you are using, we encourage you to review the Terms and Conditions related to the product/service, which are easily accessible through the company platform. For further inquiries, you can contact us using the details mentioned in the “Contact Us” section of this policy.

Children Information

We do not knowingly solicit or collect personal information from children under the age of 18. Our platform is available only to individuals who can legally form a binding contract under the Indian Contract Act, 1872. If you are under 18 years of age, you must use the platform or services under the supervision of a parent, legal guardian, or another responsible adult.

Changes to Policy

As our business evolves, so will our policies. We reserve the right, at our sole discretion, to modify, add, or remove portions of this Privacy Policy at any time without prior written notice to you. While we will make reasonable efforts to notify you of significant changes, it is your responsibility to periodically review the Privacy Policy for updates. Your continued use of our services or platform following any posted changes will signify your acceptance of the revised policy. Rest assured, we will never modify our policies in a way that reduces the protection of personal information you have already shared with us.

Contact Us

If you have any questions, concerns, or complaints regarding the processing of your personal information or this Privacy Policy, you can reach out to the company’s Privacy Officer via the following email: contact.us@nistula.life.

We are committed to responding to your inquiries within a reasonable time frame. In the event of any delay, we will proactively inform you, providing the reason for the delay along with the expected resolution timeline.