Privacy Policy
Privacy Policy
Please read this Privacy Policy carefully before using our Services.
Welcome to Collexo, a suite of digital payment, fee facilitation, and financial enablement solutions offered by NoPaperForms Solutions Limited (“NoPaperForms”, “we”, “us”, “our”).
This Privacy Policy describes how we collect, receive, use, store, share, retain, and otherwise process personal data when you access or use our websites, mobile applications (including the Collexo Pixi application), APIs, dashboards, payment interfaces, or any other digital platforms, tools, features, or services operated under the Collexo brand (collectively, the “Services”).
This Privacy Policy applies to all current and future Collexo offerings and related services, whether accessed directly by end users, through institutional partners, or via integrated platforms.
This Privacy Policy explains
- the categories of personal data we collect and process.
- the purposes and legal bases for such processing.
- circumstances in which we act as a Data Controller, Data Processor, or Program Manager, depending on the service, user role, and applicable regulatory framework.
- how long personal data is retained.
- how personal data may be shared or disclosed; and
- the rights available to you under applicable data protection laws and how to exercise them.
Minors
If you are considered a minor under applicable laws, you may access or use the Services only with the involvement and valid consent of a parent or legal guardian. By permitting such access, the parent or legal guardian confirms that they have reviewed and consented to this Privacy Policy and the applicable Terms of Service on the minor’s behalf. If such consent is not provided, the Services must not be used.
Consent and Legal Basis
By accessing or using the Services, submitting information to us, or otherwise interacting with Collexo, you acknowledge that you have read and understood this Privacy Policy. Where required under the India Digital Personal Data Protection Act, 2023 (DPDP) , the EU General Data Protection Regulation (GDPR), the UAE Personal Data Protection Law (PDPL), or other applicable laws, processing of personal data is carried out based on your consent or other lawful grounds permitted under applicable law.
If you do not agree with this Privacy Policy, you must discontinue use of the Services.
Updates to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, regulatory obligations, or business operations. When updated, the “Last Updated” date will be revised at the top. Continued use of the Services after such updates constitutes acceptance of the revised terms.
Definitions
For clarity and legal precision, the following definitions apply throughout this Privacy Policy:
- Personal Data: Means any information relating to an identified or identifiable natural person, including but not limited to name, contact details, identity numbers, device identifiers, online identifiers, financial data, or any attribute that can uniquely identify an individual.
- Processing: Includes any operation or set of operations performed on Personal Data, whether automated or manual, such as collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, transmission, disclosure, alignment, restriction, erasure, or destruction.
- Data Controller: GDPR / PDPL or “Data Fiduciary” (DPDP Act, India) refers to an entity that independently determines the purposes and means of processing Personal Data.
- Data Processor: refers to an entity processing Personal Data on behalf of a Data Controller or Data Fiduciary.
- Customer: Means an educational institution, enterprise, business, or organization using Collexo Services.
- User: Means any employee, representative, agent, or system user designated by a Customer to access Collexo Services.
- Cardholder: Means an individual using a Collexo Pixi Prepaid Card issued by PPI Issuer(s).
- Pixi PPI Issuer: Refers to PPI Issuer(s), a licensed Prepaid Payment Instrument issuer regulated by the Reserve Bank of India (RBI).
- KYC Data: includes PAN details, Aadhaar XML/masked Aadhaar, CKYC information, identity proof, address proof, photographs, liveness/selfie video, and other RBI-mandated identity information.
- Cookies: Are small text files placed on your device to support functionality, session management, preferences, analytics, or advertising (where permitted under law).
- Device Data: includes IP address, device identifiers, browser type, operating system, application version, network indicators, and related metadata.
- Data Protection Officer (DPO): Is the designated individual responsible for overseeing privacy and data protection compliance. Currently the privacy officer holds this position.
1. Who We Are
Collexo is owned and operated by:
NoPaperForms Solutions LimitedUnit No. 4, First Floor, Plot No. 242 & 243,
AIHP Palms, Udyog Vihar Phase-IV,
Gurgaon – 122015, Haryana, India
Depending on how you interact with Collexo Services and the specific product in use, we may act as:
- a Data Processor (for most Collexo payment workflows)
- a Program Manager and Data Processor (for Pixi card onboarding and KYC), or
- a Data Controller/Data Fiduciary (for limited device analytics and app diagnostics).
When We Act as a Data Processor
We act as a Data Processor when processing Personal Data strictly on behalf of our Customers and exclusively under their documented instructions. This applies to:
- Collexo Collect (fee collection workflows)
- Collexo EMI (installment management)
- Collexo AutoDebit (e-mandate initialization and reminders)
- Collexo Central Pay (institution-driven payment portals)
In these scenarios:
- The Customer is the Data Controller/Data Fiduciary .
- The Customer determines what Personal Data is collected, why it is collected, and how it should be processed.
- We process such data solely for delivering contractual Services.
- We do not determine retention periods or purposes of processing.
- We do not use Customer-controlled data for analytics, product development, AI training, advertising, profiling, or behavior tracking.
- We retain, delete, or return data strictly in accordance with Customer instructions.
When We Act as Program Manager & Data Processor for Pixi (PPI Cards)
Collexo operates the Pixi prepaid card onboarding and activation flow in collaboration with
PPI Issuer(s), a licensed PPI issuer under the RBI’s regulatory framework.
In the Pixi ecosystem:
- PPI Issuer(s) is the Data Controller/Data Fiduciary for all KYC, card activation, transaction processing, AML/CFT checks, fraud monitoring, and regulatory retention.
- Collexo acts strictly as a Program Manager and Data Processor on behalf of PPI Issuer(s).
- NPCI (National Payments Corporation of India) acts as an Independent Data Controller for switching, tokenization, transaction settlement, and authentication.
Collexo’s Processor responsibilities for Pixi include:
- Facilitating the KYC submission process within the Collexo mobile app.
- collecting KYC Data solely to transmit it securely to PPI Issuer(s).
- Performing preliminary completeness checks (e.g., image clarity, file validity).
- Enabling card activation status updates.
- Displaying transaction summaries provided by PPI Issuer(s).
- Supporting user onboarding flows under PPI Issuer(s)’s guidelines.
Collexo does not determine:
- whether KYC is required.
- which documents are acceptable.
- retention periods.
- AML/CFT rules.
- card usage terms and conditions.
- onboarding criteria.
These are exclusively determined by PPI Issuer(s).
Important Note About Customer Data
Customer Data:
Name, Email, Contact Information, Address etc.
This is stored and retained with Collexo as long as the Customer Account is active with us.
When We Act as a Data Controller/Data Fiduciary
We act as an independent Controller/Fiduciary only for limited operational and app-level data, such as:
- device metadata.
- performance logs.
- crash diagnostics.
- application usage metrics.
- security and anomaly detection.
- service analytics.
This processing is required to:
- secure the application.
- detect and prevent fraud.
- ensure service reliability.
- troubleshoot issues.
- improve app performance.
Use of Sub-Processors and Service Providers
To deliver our Services, we engage authorized Sub-Processors who support:
- cloud hosting.
- payment gateway integrations.
- SMS/email communication.
- document verification.
- identity verification.
- fraud detection.
- customer support.
- notification and messaging workflows.
Where we act as Processor, these third parties act as Sub-Processors.
where we act as Controllers, they act as Processors.
We require all Sub-Processors to:
- implement strict security measures.
- maintain confidentiality.
- process data only under contractually defined purposes
- adhere to international transfer standards where applicable.
2. Scope of This Privacy Policy
This Privacy Policy applies to Personal Data that we collect, receive, or process when you:
- visit or interact with our website, mobile applications, or digital interfaces;
- communicate with us through email, chat, phone, or support channels;
- activate, onboard, or use a Collexo Pixi prepaid card;
- pay fees or dues via Collexo-powered portals;
- engage with our systems through integrations, APIs, or embedded components;
- participate in webinars, events, or marketing campaigns;
- otherwise provide Personal Data to us or through our Services.
This Policy explains:
- what Personal Data we collect.
- how and why we use Personal Data.
- when we act as Processor, Program Manager, or Controller.
- when we share Personal Data with institutions, PPI Issuer(s), NPCI, or Sub-Processors.
- how long we retain Personal Data and why.
- your rights and how to exercise them.
- security measures we use.
- how we support compliance under DPDP, GDPR, PDPL, and RBI rules.
Where This Privacy Policy Does Not Apply
1. Customer-Controlled Data
If your information was collected by an institution (e.g., a school, college, university, or enterprise), including:
- application forms.
- admission forms.
- fee or payment forms.
- fee or payment forms.
- data uploaded to institutional portals.
Then:
- the institution is the Data Controller/Data Fiduciary.
- their privacy policy applies.
- collexo processes data strictly under their instructions.
- collexo cannot act on your deletion or correction requests directly.
- institutions determine the purpose and legal basis for such data.
2. Third-Party Tools Used by Customers
Institutions may embed or deploy third-party scripts such as:
- analytics tags
- facebook/Google pixels.
- marketing automation tools.
- chatbot integrations.
- forms or survey platforms.
These tools shall solely be governed by the Customer’s and the third party’s privacy policies:
3. External Websites or Services
Our Services may contain links to third-party websites or external services that are not operated by Collexo.
We are not responsible for their:
- privacy practices.
- data handling.
- security measures.
- terms of use.
You should review their privacy policies before engaging with them.
3. Summary
Although we encourage you to read this Policy in full, this summary provides a quick overview:
- Collexo is a product of NoPaperForms Solutions Limited.
- We act as a Data Processor for most Services.
- For Pixi, PPI Issuer(s) is the Data Controller and Collexo acts solely as Program Manager & Processor.
- Collexo does not retain KYC data collected for Pixi.
- Users include visitors, institutions, staff, students, cardholders, and payers.
- We collect only the minimum data required for operational, regulatory, or contractual purposes.
- You have rights under GDPR, PDPL, and DPDP.
- We maintain strong security and compliance measures.
- This Policy is part of and must be read with our Terms of Service.
If you do not agree with any part of this Policy, discontinue use of the Services.
4. Information We May Collect & How We Use It
We collect different categories of Personal Data depending on whether you are:
- a visitor.
- a Customer.
- a Customer’s user.
- a student.
- a parent/guardian.
- a payer.
- a Pixi cardholder.
- or whether you interact with us directly.
All Personal Data is collected and processed based on lawful bases such as consent, performance of a contract, legitimate interests, compliance with legal obligations, or strictly on behalf of a Data Controller/Fiduciary.
4.1 Visitors (Website Browsers)
Personal Data We May Collect:
When you browse our website or mobile applications, we may collect Personal Data including:
- Your name, phone number, email address, organization name (when you voluntarily submit forms or request callbacks).
- Technical information such as IP address, device type, browser type, operating system, network identifiers, screen resolution, and unique device identifiers.
- Behavioral and usage information including pages viewed, time spent, clickstream data, scroll behavior, session duration, referring URLs, and navigation patterns.
- Cookie and tracking information such as device identifiers, web beacons, pixels, tags, logs, and marketing identifiers.
- Information from third-party sources, where permitted under applicable laws, such as data aggregators or advertising partners.
Why We Collect This Data:
We collect visitor data for purposes including:
- understanding how visitors interact with our website.
- improving website functionality, navigation, user experience, and content relevance.
- responding to requests such as demo requests, support queries, or call-back submissions.
- connecting you to relevant resources or product specialists.
- delivering marketing or promotional content (with appropriate consent).
- performing remarketing through third-party advertising platforms (Google/Meta), where allowed.
- analyzing engagement data to improve campaigns, optimize performance, and understand interest levels.
- maintaining security, identifying misuse, and preventing fraudulent activity
We only use cookies or identifiers for marketing or remarketing where legally required consent has been obtained.
4.2 Customers (Organizations Using Collexo)
Personal Data We May Collect:
When an organization becomes a Customer, we may collect:
- the identity and contact details of authorized representatives
- official email addresses and phone numbers.
- organization name, address, authentication details, GST information (if applicable).
- billing and invoicing information.
- support ticket metadata.
- system log entries associated with administrative actions.
- audit trail data to ensure compliance with security standards.
When an organization becomes a Customer, we may collect:
Why We Collect This Data:
We collect and process Customer-level data to:
- create, administer, and maintain Customer accounts.
- provide platform access to authorized personnel.
- support onboarding, configuration, training, and support delivery.
- manage subscriptions, billing, invoicing, and contractual obligations.
- ensure compliance with audit, security, and regulatory standards.
- provide essential notifications such as updates, outages, or changes in service.
- monitor for fraud, unauthorized access, or operational anomalies.
4.3 Users (Employees/Representatives of Customer Organizations)
Personal Data We May Collect:
For Users who log into Collexo platforms on behalf of Customers, we may collect:
Identity & Contact Information:
- name, email address, official phone number, and organization details.
Authentication & System Data:
- login timestamps, logout timestamps.
- device names, browser versions, OS details.
- IP address and approximate geolocation.
- multi-factor authentication records.
Behavior & Usage Data:
- tasks performed on the platform.
- modules accessed.
- records viewed or actions taken.
- workflow triggers activated.
- performance metrics.
Optional Permissions (Only With Explicit Opt-In):
- SMS metadata and call logs metadata (sender/recipient, timestamps—NOT message/call content).
We never collect:
- call recordings.
- content of SMS messages.
- contact lists from devices.
- personal email content.
- photos, media, or files unless voluntarily uploaded.
- biometric data unless strictly mandated by a Controller (e.g., liveness for Pixi KYC).
Why We Collect This Data:
We collect User data to:
- enable secure platform access;
- provide payment, and workflow capabilities;
- enhance User productivity through reminders, follow-ups, and automation;
- ensure auditability and compliance with institutional requirements;
- troubleshoot system issues and improve platform reliability;
- maintain logs for fraud detection, misuse prevention, and policy enforcement;
- adhere to Customer contractual obligations.
Optional features rely exclusively on consent and may be revoked anytime via app or device settings.:
4.4 Students, Payers & Cardholders — Pixi Program
The Pixi prepaid card program involves enhanced data processing due to regulatory obligations under RBI, NPCI and other applicable laws.
Collexo acts only as Program Manager and Data Processor , while PPI Issuer(s) acts as Controller.
Pixi involves three data streams:
A. Personal Data Shared by Institutions (Processor Role)
Institutions may share student or user lists including but not limited to:
Identity & Contact Information:
- name.
- gender.
- phone number.
- email address.
- roll number/student ID.
- academic program.
- eligibility or entitlement information.
- institution-specific attributes.
Role:
Institution= Controller
Collexo= Processor
Collexo does not determine the purpose of this data; we process it solely to facilitate onboarding.
B. Pixi KYC Data (Processor for PPI Issuer(s); NO RETENTION)
Inside the Collexo app, Pixi card applicants may be required to submit:
Other Verification Documents for Minimum KYC
- Aadhaar.
- PAN details.
For Full KYC
- photograph or selfie.
- liveness video.
- government-issued identity documents.
Any other identity data mandated by RBI Master Directives.
Purpose:
To comply with RBI KYC obligations for PPI issuance.
C. Important Note About KYC Data (No Retention)
Collexo (in collaboration with PPI Issuer(s)) enables Customers to do their KYC as determined in the Master Direction of RBI.
Minimum KYC: Minimum details shall necessarily include a mobile number verified with OTP and a self-declaration of name and unique identity / identification number of any ‘mandatory document’ or OVD or any such document with any name listed for this purpose in the Master Direction on KYC, as amended from time to time.
Full KYC (Video KYC): Video-based Customer Identification Process (V-CIP) can be used to open full-KYC PPIs as well as to convert Small PPIs into full-KYC PPIs.
Collexo and PPI Issuer(s) use authorised third party service providers for this.
Collexo’s role is limited to secure transmission of your KYC data to these service providers.
We do not retain any KYC Data after transmission.
This means:
- Collexo does not store Aadhaar XML, PAN images, CKYC, photographs, address proofs, or liveness videos.
- No copies are stored in logs, databases, backups, caches, or analytics systems.
- The Third-party service provider may retain, store, and process KYC data in accordance with its own privacy policy and terms of service, provided that such retention and processing is undertaken with
- The consent of the user and in compliance with applicable laws.
This zero-retention policy is maintained in accordance with:
- RBI PPI Master Directions.
- UIDAI/Aadhaar Storage Restrictions.
- DPDP Act–Data Minimisation Principle.
- GDPR Article 5(1)(e).
- NPCI guidelines.
Role:
PPI Issuer(s)= Controller
Collexo= Processor
NPCI= Independent Controller
This is the single most important privacy safeguard for Pixi compliance.
D. Cardholder Data
We do not store or have access to Card Number, PIN, CVV, Expiry Date.
E. Transaction Data (Controlled by Third Party SP)
Third Party SP may share limited data with Collexo, including:
- transaction amounts;
- merchant category codes;
- timestamps
- UPI token references;
- status codes;
- chargeback notifications.
Collexo does not determine storage duration, purpose, or regulatory compliance for these data points.
Purpose: Collexo processes this information for the Pixi Rewards program and to provide service to the cardholders.
4.5 App-Level Analytics & Diagnostics (Controller Role)
We collect app-level analytics required to:
- detect crashes.
- maintain security.
- monitor performance.
- debug issues.
- ensure device compatibility.
- identify reliability bottlenecks.
This includes:
- app version.
- OS version.
- device model.
- diagnostic logs.
- euser interface performance metrics.
This does not include Customer-controlled, PPI Issuer(s)-controlled, or institution-controlled student data.
4.6 Lawful Bases for Processing
Depending on your jurisdiction and the nature of the processing, we rely on
- Consent (such as marketing emails, optional features, cookies);
- Performance of Contract (such as providing Services to Customers);
- Legitimate Interests (such as security, fraud detection, diagnostics);
- Compliance with Legal Obligations (such as Pixi KYC under RBI rules);
- Processing on behalf of Controllers (such as institutions or Third Party SP).
We adhere to DPDP, GDPR, and PDPL requirements for lawful, fair, transparent, and proportionate processing.
5. Cookies, Tracking Technologies & Optional Features
We use:
Essential Cookies
Required for authentication, session stability, and application operation.
Performance Cookies
Help us measure performance, load times, usage patterns, and errors.
Analytics Cookies
Used only after valid consent.
Used for aggregated analysis.
Marketing Cookies
Used only with consent in jurisdictions that require it.
Web Beacons & Pixels
Used to measure engagement with emails and website pages.
Optional App Permissions
Enabled only with explicit opt-in:
- Camera and/or microphone (for KYC video capture).
- photos/media (for identity uploads).
- notifications.
- contacts or SMS metadata (never content).
You may revoke permissions anytime through device settings or the app.
6. Children’s Data & Parental Consent Requirements
Our Services are generally used by educational institutions and may involve processing Personal Data of students, including minors.
- under the instructions of institutions (Controller).
- under PPI Issuer(s)’s KYC responsibilities (Controller).
- in compliance with DPDP, GDPR, PDPL, and RBI rules.
We do not:
- market to children.
- profile children.
- collect unnecessary data from children.
Institutions and PPI Issuer(s) are responsible for obtaining parental consent where required.
7. Retention of Personal Information
Retention periods depend on role and legal requirements.
Institution-Controlled Data
Retained per Customer instructions.
Pixi KYC Data
Collexo does NOT retain any KYC data after transmission.
All KYC retention is the responsibility of PPI Issuer(s), as required under RBI AML, PPI rules and other applicable laws.
Pixi Transaction Data
PPI Issuer retains as per their policies.
App Analytics Data
Retained 1 year and 2 months depending on diagnostics.
Logging
Minimal logs related to system integrity may be retained for security and auditing.
When deletion is required, data is removed from active systems and deleted during backup cycles.
8. Transfer of Information to Third Parties, International Transfers &
Third-Party Tools
To deliver our Services, we may transfer data to:
- Sub-Processors.
- payment gateways.
- cloud hosting providers.
- PPI Issuer(s) (KYC, AML).
- SMS/email/WhatsApp providers.
- identity verification vendors.
- financial institutions and partners.
- law enforcement (when required).
International Transfers
Data may be transferred internationally subject to:
- Standard Contractual Clauses (GDPR).
- DPDP cross-border transfer requirements.
- PDPL-compliant export mechanisms.
- Encryption and security controls.
We conduct due diligence before engaging any third party.
9. Third-Party Links
Our website or platform may link to third-party services. We do not control and are not responsible for:
- content.
- data handling.
- privacy practices.
- security controls.
You should review third-party privacy policies independently.
10. Compelled Disclosure
We may disclose Personal Data where:
- required by courts.
- mandated by RBI, NPCI, or regulators.
- mandated under AML/CFT obligations.
- required for fraud detection or law enforcement investigations.
- necessary to protect rights, safety, or property.
When we act as Processor, such requests are referred to the Controller unless legally prohibited.
11. Security of Your Personal Information
We implement a comprehensive set of administrative, organizational, and technical safeguards, including:
- encryption in transit (TLS 1.2+).
- AES-256 encryption at rest (where applicable).
- firewalls and network segmentation;
- role-based access controls.
- password hashing and strict authentication.
- secure development lifecycle practices.
- periodic VAPT assessments.
- audit logging and monitoring.
- incident response planning.
Users must maintain the confidentiality of login credentials.
12. Your Privacy Rights
Depending on the region, you may have rights including:
- right to access.
- right to correction.
- right to deletion.
- right to restrict processing.
- right to objection.
- right to portability.
- right to withdraw consent.
- right to grievance redressal.
- right against automated decision-making.
Where to Raise Requests
Institution-controlled data:
Contact your institution.
Pixi KYC, card, transaction data:
Contact PPI Issuer(s) as printed on your Card..
App analytics:
Contact Collexo as mentioned in “How to Contact Us”.
13. Your Privacy Choices
You may:
- opt out of marketing communications;
- withdraw consent;
- disable optional cookies;
- revoke app permissions;
- exercise rights under applicable laws;
- request deletion of app analytics (where applicable).
- Use our GDPR Representative portal: https://app.prighter.com/portal/18828570800
- Use our Data Rights Portal: https://trustcenter.nopaperforms.com/your-data
14. Changes to This Privacy Policy
We update this Policy periodically along with the Date of update.
Continued use constitutes acceptance of updates.
15. How to Contact Us
If you have questions, want to exercise your rights, or wish to raise concerns, you can contact us as follows:
General Privacy Enquiries
Email: data@collexo.com
Registered Address
NoPaperForms Solutions LimitedUnit No. 4, 1st Floor, Plot No. 242 & 243,
AIHP Palms, Udyog Vihar Phase-IV,
Palam Road, Gurgaon, Haryana-122015, India
Data Protection Officer (DPO)
Email: data@collexo.com
Grievance Officer (India – DPDP)
Email: grievance@collexo.com
EU/EEA Representative (GDPR)
Prighter Group: https://app.prighter.com/portal/18828570800