Privacy Policy
Treasatech Global Private Limited
Effective Date: 17 September 2026 · Last Updated: 17 September 2026 · Version: 1.0
1. Introduction
Treasatech Global Private Limited (“Treasatech Global”, “Treasatech”, “we”, “us”, or “our”) respects the privacy of individuals who visit our website, communicate with us, request information about our products or services, participate in product demonstrations, or otherwise interact with us through our digital channels.
This Privacy Policy explains how Treasatech Global collects, receives, uses, discloses, stores, retains, protects, and otherwise processes personal data in connection with the Treasatech Global website and related website interactions.
This Privacy Policy should be read together with our Terms of Use and Security Disclosure.
By accessing or using our website, or by voluntarily providing personal data to us, you acknowledge that you have read and understood this Privacy Policy. Where applicable law requires consent for a particular processing activity, Treasatech Global will obtain such consent through an appropriate mechanism.
2. About Treasatech Global
Treasatech Global Private Limited is an enterprise technology company focused on treasury, correspondent banking, financial operations, and related enterprise technology.
Our technology ecosystem includes TreasuryFlow OS, the underlying enterprise platform layer, and commercial applications including TreasuryFlow 360 (TF360) and TreasuryFlow GlobNos (TFGlobNos).
TreasuryFlow OS provides the underlying enterprise operating environment through which authorised applications and platform capabilities may be accessed.
The Treasatech Global website is primarily intended to provide information about Treasatech Global, its technology, products, capabilities, enterprise solutions, and business activities, and to facilitate communications with prospective customers, partners, investors, suppliers, employees, applicants, and other interested parties.
Unless expressly stated otherwise, the public website does not itself constitute a banking service, payment service, investment service, financial advisory service, or regulated financial product.
3. Scope of this Privacy Policy
This Privacy Policy applies to personal data processed by Treasatech Global in connection with:
- The Treasatech Global website;
- Product and solution pages;
- Contact forms;
- Product demonstration requests;
- Business enquiries;
- Communications with Treasatech Global;
- Newsletters or other communications, where offered;
- Recruitment or career-related submissions, where applicable;
- Events, webinars, seminars, or other business interactions;
- Website security and technical operations; and
- Other online interactions that expressly link to this Privacy Policy.
This Privacy Policy does not automatically apply to information processed by a customer through its own implementation or use of Treasatech products where Treasatech Global is acting solely as a technology provider, service provider, or Data Processor.
Where a customer independently determines the purposes and means of processing personal data through its own systems or implementation of Treasatech products, that customer may have its own privacy policy and legal obligations.
4. Applicable Law
Treasatech Global intends to process personal data in accordance with applicable Indian law, including, as applicable:
- The Constitution of India, including the constitutional protection of privacy recognised by the Supreme Court of India;
- The Digital Personal Data Protection Act, 2023;
- The Digital Personal Data Protection Rules, 2025, as applicable and as they come into force;
- The Information Technology Act, 2000;
- Applicable rules, regulations, directions, notifications, and governmental requirements issued under applicable law;
- Applicable cybersecurity directions issued by the Indian Computer Emergency Response Team (CERT-In); and
- Other applicable laws, regulatory requirements, and lawful governmental directions.
The applicable legal and regulatory framework may change from time to time. Treasatech Global may therefore update its privacy practices and this Privacy Policy to reflect changes in applicable law or regulatory requirements.
5. Definitions
For purposes of this Privacy Policy:
“Personal Data” means any data about an individual who is identifiable by or in relation to such data, to the extent defined under applicable law.
“Data Principal” has the meaning assigned under applicable Indian data protection law and generally refers to the individual to whom personal data relates.
“Data Fiduciary” has the meaning assigned under the Digital Personal Data Protection Act, 2023 and generally refers to a person who, alone or in conjunction with others, determines the purpose and means of processing personal data.
“Data Processor” has the meaning assigned under applicable law and generally refers to an entity that processes personal data on behalf of a Data Fiduciary.
“Processing” includes operations performed on personal data, including collection, recording, organisation, storage, use, disclosure, transmission, retrieval, alteration, combination, restriction, erasure, or destruction, as applicable under law.
6. Personal Data We May Collect
The categories of personal data collected by Treasatech Global depend on how you interact with us. We seek to collect personal data that is reasonably necessary for the relevant purpose.
6.1 Information provided directly by you
When you contact us, request information, request a product demonstration, submit an enquiry, communicate with our representatives, submit an employment application, or otherwise provide information to us, we may collect:
- Name;
- Business email address;
- Telephone or mobile number;
- Job title or designation;
- Organisation or company name;
- Country or general business location;
- Business requirements;
- Information contained in your enquiry or communication;
- Information voluntarily provided regarding your organisation, project, or requirements;
- Professional information where relevant to a business or recruitment interaction; and
- Other information voluntarily submitted by you.
We do not intentionally request personal data that is not reasonably necessary for the relevant purpose.
6.2 Technical information
When you access our website, certain technical information may be collected automatically by our website infrastructure, hosting providers, security systems, analytics services, or similar technologies.
Depending on the website configuration, this information may include:
- IP address;
- Browser type and version;
- Operating system;
- Device type;
- Approximate geographic region derived from technical information;
- Referring website or page;
- Pages visited;
- Date and time of access;
- Session information;
- Website interaction information;
- Diagnostic information;
- Security and fraud-prevention information; and
- Technical logs necessary to maintain website security and operation.
We use such information primarily to operate, maintain, secure, troubleshoot, and improve our website.
7. Cookies and Similar Technologies
Our website may use cookies and similar technologies. Cookies may be used for purposes including:
- Enabling essential website functionality;
- Maintaining session or security functionality;
- Remembering preferences;
- Understanding website usage;
- Improving website performance;
- Measuring engagement; and
- Supporting analytics or communications, where applicable.
Where applicable law requires consent for non-essential cookies or similar technologies, Treasatech Global will provide an appropriate mechanism for obtaining and managing such consent.
You may also control cookies through your browser settings. Disabling certain cookies may affect the availability or functionality of portions of the website.
The cookies and similar technologies used by our website may change as the website evolves.
8. Purposes for Which We Process Personal Data
Treasatech Global may process personal data for the following purposes, as applicable:
8.1 Responding to enquiries
To respond to enquiries, requests for information, product questions, demonstration requests, partnership enquiries, investment enquiries, and other communications.
8.2 Business development
To communicate with prospective customers, business partners, suppliers, investors, and other professional contacts regarding Treasatech Global and its products, services, and enterprise solutions.
8.3 Product demonstrations
To arrange, administer, and follow up on product demonstrations, meetings, presentations, proof-of-concept discussions, and related business interactions.
8.4 Website operation
To operate, maintain, troubleshoot, secure, analyse, and improve the website and related digital services.
8.5 Security
To detect, prevent, investigate, and respond to:
- Unauthorised access;
- Misuse;
- Fraud;
- Cybersecurity threats;
- Security incidents;
- Malicious activity; and
- Other activities that may compromise the security or integrity of our systems.
8.6 Legal and regulatory compliance
To comply with applicable laws, regulations, court orders, governmental requirements, regulatory requirements, and lawful requests.
8.7 Corporate administration
To maintain appropriate business records, manage internal operations, communicate with stakeholders, and administer our business.
8.8 Recruitment
Where applicable, to process employment applications, evaluate candidates, communicate with applicants, and administer recruitment activities.
8.9 Business communications and marketing
Where permitted by law and, where required, with appropriate consent, to send:
- Business communications;
- Product information;
- Event invitations;
- Newsletters;
- Company updates; or
- Other communications relevant to your relationship with Treasatech Global.
You may opt out of non-essential marketing communications at any time.
9. Notice and Consent
Where consent is required under applicable law, Treasatech Global will seek consent through an appropriate notice and consent mechanism.
Consent, where required under applicable law, will be obtained in accordance with the applicable statutory requirements.
Where consent is the basis for processing, you may withdraw your consent at any time through the mechanism made available by Treasatech Global.
Withdrawal of consent does not affect the lawfulness of processing that occurred before withdrawal.
Following withdrawal, Treasatech Global will cease or cause the relevant Data Processor to cease processing based on that consent where required by applicable law, unless continued processing is otherwise permitted or required by law.
10. Processing Without Consent
There may be circumstances in which applicable law permits or requires personal data to be processed without obtaining consent.
These circumstances may include processing necessary for purposes recognised under applicable law, including:
- Compliance with legal obligations;
- Compliance with judicial, regulatory, or governmental requirements;
- Prevention, detection, investigation, or prosecution of offences;
- Cybersecurity and security purposes;
- Emergency situations;
- Certain employment-related purposes;
- Protection of rights and interests where legally permitted; and
- Other circumstances specifically recognised under applicable law.
Treasatech Global will rely on such grounds only where applicable.
11. Data Minimisation
Treasatech Global seeks to collect and process personal data that is reasonably necessary for the purpose for which it is collected.
We do not intentionally collect personal data merely because it may be useful in the future.
Where information is optional, we may distinguish optional information from information that is reasonably necessary to respond to an enquiry or provide a requested service.
12. Accuracy of Personal Data
Treasatech Global seeks to maintain personal data that is reasonably accurate, complete, and current for the purposes for which it is processed.
If you believe that personal data held by us about you is inaccurate, incomplete, or outdated, you may request correction through the contact mechanism described in this Privacy Policy.
13. How We Share Personal Data
Treasatech Global may disclose or make personal data available to third parties where reasonably necessary for the purposes described in this Privacy Policy and as permitted or required by applicable law. Such parties may include:
13.1 Service providers and data processors
Technology and service providers supporting:
- Website hosting;
- Cloud infrastructure;
- Email and communications;
- Analytics;
- Cybersecurity;
- Customer relationship management;
- Professional services;
- Business administration; and
- Other operational requirements.
Such parties will receive only information reasonably required for the relevant service, subject to applicable contractual and legal requirements.
13.2 Professional advisers
We may disclose information to legal, accounting, auditing, consulting, insurance, or other professional advisers where reasonably necessary.
13.3 Government and regulatory authorities
We may disclose information where required or authorised by applicable law, regulation, court order, governmental direction, regulatory requirement, or lawful request.
13.4 Corporate transactions
Personal data may be disclosed where reasonably necessary in connection with a proposed or completed:
- Merger;
- Acquisition;
- Investment;
- Restructuring;
- Financing;
- Sale or transfer of assets;
- Transfer of business; or
- Similar corporate transaction.
Any such processing will remain subject to applicable legal requirements.
14. Data Processors
Where Treasatech Global engages Data Processors to process personal data on our behalf, we intend to implement appropriate contractual and organisational safeguards consistent with applicable law.
Data Processors may process personal data only for authorised purposes and in accordance with applicable contractual arrangements and legal requirements.
Where required by law, Treasatech Global will take reasonable steps to ensure that relevant Data Processors maintain appropriate security safeguards.
15. International Data Transfers
Treasatech Global may use service providers, infrastructure, technology platforms, or business partners located outside India where permitted and appropriate.
Where personal data is transferred outside India, Treasatech Global will undertake such transfers in accordance with applicable Indian law, including any restrictions, conditions, or requirements prescribed by the Central Government or another competent authority.
Where appropriate and required, we may implement contractual, organisational, or technical safeguards relating to international transfers.
16. Data Retention
Treasatech Global retains personal data only for as long as reasonably necessary for the purpose for which it was collected or otherwise processed, unless a longer retention period is:
- Required by applicable law;
- Required for legal claims or proceedings;
- Necessary for regulatory or compliance purposes;
- Necessary for legitimate business recordkeeping permitted by law;
- Necessary to investigate or respond to a security incident; or
- Otherwise permitted or required under applicable law.
When personal data is no longer required, we will seek to securely delete, anonymise, or otherwise dispose of it in accordance with applicable requirements.
Retention periods may vary depending on:
- The type of information;
- The purpose of processing;
- The nature of the relationship;
- Legal requirements;
- Contractual requirements;
- Security requirements; and
- Dispute, investigation, or enforcement requirements.
Treasatech Global does not apply a single universal retention period to all categories of personal data.
17. Security of Personal Data
Treasatech Global takes reasonable technical and organisational measures appropriate to the nature of personal data and the risks associated with its processing.
Depending on the relevant system and processing activity, safeguards may include:
- Access controls;
- Authentication and authorisation mechanisms;
- Role-based access controls;
- Secure development practices;
- Monitoring and logging;
- Vulnerability management;
- Security testing;
- Backup and recovery measures;
- Incident response procedures;
- Personnel security controls;
- Contractual controls for service providers; and
- Other appropriate technical and organisational safeguards.
We continuously seek to improve security practices as technology, threats, legal requirements, and business operations evolve.
No method of transmission, storage, or electronic security can be guaranteed to be completely secure. Accordingly, while we take reasonable measures to protect personal data, we cannot guarantee absolute security.
18. Cybersecurity and Logging
Where applicable, Treasatech Global will comply with cybersecurity obligations imposed under Indian law and applicable directions issued by competent authorities.
Where legally applicable, cybersecurity logs and related technical information may be retained for periods required by law or applicable regulatory directions.
Such information may be used for security monitoring, incident detection, investigation, regulatory compliance, system protection, and related legitimate purposes.
19. Personal Data Breaches
If Treasatech Global becomes aware of a personal data breach affecting personal data for which we are responsible, we will assess and respond to the incident in accordance with applicable law.
Where notification is legally required, we will notify affected individuals and/or the applicable regulatory authority in the manner and within the timeframe required by applicable law.
We may also take appropriate containment, remediation, investigation, and preventive measures.
20. Your Rights as a Data Principal
Subject to applicable law and any applicable conditions or limitations, you may have rights including:
20.1 Right to access information
You may have the right to obtain information concerning personal data processed about you and other information relating to its processing, subject to applicable law.
20.2 Right to correction
You may request correction of inaccurate or incomplete personal data.
20.3 Right to erasure
You may request erasure of personal data where applicable. Erasure may be subject to circumstances in which retention or continued processing is required or permitted by law.
20.4 Right to withdraw consent
Where processing is based on consent, you may withdraw your consent. Withdrawal will not affect processing lawfully undertaken before withdrawal.
20.5 Right to grievance redressal
You may raise a grievance concerning our processing of your personal data.
20.6 Right to nominate
Where applicable under the Digital Personal Data Protection Act, 2023 and applicable Rules, you may nominate another individual to exercise your rights in accordance with the applicable legal framework.
21. How to Exercise Your Rights
To submit a privacy request, correction request, erasure request, consent withdrawal, or privacy grievance, please contact:
Treasatech Global Private Limited
Privacy / Data Protection Contact: Privacy Team
Email: info@treasatechglobal.com
Registered Office: Plot No. 9, 4 Bay, Sector 32, Gurugram, Industrial Area Faridabad, Faridabad, Faridabad– 121001, Haryana
When submitting a request, please provide sufficient information for us to:
- Understand the nature of your request;
- Identify the relevant personal data or processing activity;
- Verify your identity where reasonably necessary; and
- Respond appropriately.
We may request reasonable information to verify that a request genuinely relates to you.
We will not intentionally request unnecessary information solely for the purpose of verifying a privacy request.
22. Grievance Redressal
Treasatech Global takes privacy-related grievances seriously.
If you believe that your personal data has been processed contrary to applicable law or this Privacy Policy, you may contact us using the details provided above.
We will review the grievance and respond in accordance with applicable law and our internal grievance process.
Where applicable law provides for escalation to the Data Protection Board of India or another competent authority, you retain any statutory rights available to you.
23. Marketing Communications
Where Treasatech Global sends marketing or promotional communications, we will do so in accordance with applicable law.
You may opt out of non-essential marketing communications by:
- Using the unsubscribe mechanism included in the communication;
- Contacting us; or
- Using another opt-out mechanism made available by Treasatech Global.
Even if you opt out of marketing communications, we may continue to send non-promotional communications that are necessary for an existing business relationship, legal compliance, security, or other permitted purposes.
24. Business Communications
If you contact Treasatech Global in a professional capacity, we may use your business contact information to:
- Respond to your enquiry;
- Arrange meetings;
- Provide requested information;
- Communicate regarding product demonstrations;
- Manage business relationships; or
- Conduct related business activities.
Such processing will be undertaken in accordance with applicable law.
25. Children’s Personal Data
Our website and enterprise services are not directed toward children.
We do not knowingly seek to collect personal data from children except where permitted or required by applicable law and with appropriate safeguards.
Where applicable law requires verifiable parental or lawful guardian consent for processing children’s personal data, Treasatech Global will implement the measures required by applicable law.
If you believe that a child has provided personal data to Treasatech Global improperly, please contact us so that we can assess the circumstances and take appropriate action.
26. Third-Party Websites and Services
Our website may contain links to third-party websites, applications, platforms, or services.
Such third parties operate independently from Treasatech Global and may have their own privacy policies and terms of use.
Treasatech Global is not responsible for the privacy practices, security, content, or policies of third-party websites or services.
We recommend reviewing the privacy policy and terms of any third-party website before providing personal data.
27. Social Media
Treasatech Global may maintain profiles or pages on third-party social media platforms.
Interactions with Treasatech Global through such platforms may be subject to:
- This Privacy Policy; and
- The privacy policies and terms of the relevant third-party platform.
Treasatech Global does not control how third-party platforms independently process personal data.
28. Enterprise Customer Data
Treasatech Global provides enterprise technology products intended for institutional customers.
Where a customer uses TreasuryFlow products to process personal data within its own environment, the applicable allocation of responsibilities will depend on:
- The deployment model;
- The contractual relationship;
- Customer instructions;
- Applicable law;
- The nature of the processing activity; and
- Whether Treasatech Global acts as a Data Fiduciary, Data Processor, or another legally recognised role.
Customer-specific data processing terms may be established through appropriate contractual documentation, including a Data Processing Agreement where required.
Nothing in this Privacy Policy overrides an applicable customer agreement.
29. Product Demonstration Environments
Treasatech Global may provide demonstrations of TreasuryFlow OS, TreasuryFlow 360, TreasuryFlow GlobNos, or other products.
Demonstration environments may contain simulated, synthetic, fictional, or demonstration data. Such data should not be interpreted as:
- Live banking data;
- Actual customer data;
- Actual customer transaction information;
- Actual financial positions;
- Actual payment instructions; or
- Evidence of a specific customer’s use of the product.
Customer-specific environments may be governed by separate contractual, privacy, and security arrangements.
30. Investor, Partner, and Business Contact Information
If you contact Treasatech Global as an investor, potential investor, partner, supplier, adviser, or other business stakeholder, we may process your business contact information and related correspondence for:
- Responding to your communication;
- Evaluating business opportunities;
- Managing business relationships;
- Conducting due diligence;
- Arranging meetings;
- Maintaining corporate records; and
- Complying with applicable legal obligations.
31. Recruitment Information
Where our website permits job applications or recruitment enquiries, information voluntarily submitted by applicants may include:
- Name;
- Contact details;
- Professional history;
- Qualifications;
- Resume or CV information;
- Employment preferences;
- Interview information; and
- Other information voluntarily submitted by the applicant.
Recruitment information will be used for recruitment and related employment purposes and retained in accordance with applicable law and Treasatech Global’s internal retention practices.
Applicants should not submit unnecessary sensitive personal information unless specifically requested and legally appropriate.
32. Legal Disclosures
Treasatech Global may process or disclose personal data where necessary to:
- Comply with applicable law;
- Comply with court orders;
- Comply with regulatory requirements;
- Respond to lawful government requests;
- Establish, exercise, or defend legal rights;
- Investigate fraud or unlawful activity;
- Protect the rights, property, security, or safety of Treasatech Global, its customers, employees, or other persons; or
- Prevent or respond to cybersecurity incidents.
Such processing will be limited to what is reasonably necessary for the applicable purpose and permitted by law.
33. Data Related to Security Incidents
Where necessary for cybersecurity, fraud prevention, incident response, or system protection, Treasatech Global may process technical information including:
- IP addresses;
- Device information;
- Access logs;
- Authentication events;
- Timestamps;
- Security alerts;
- System activity;
- Suspicious activity indicators; and
- Other information reasonably necessary to investigate or respond to an incident.
Such processing may occur without consent where authorised or required by applicable law.
34. Automated Decision-Making and Artificial Intelligence
Treasatech Global may develop or use artificial intelligence and automated technologies as part of its technology ecosystem.
Where personal data is processed through such technologies, processing will be subject to applicable law, contractual requirements, and relevant governance controls.
We do not use the public website to make decisions about individuals solely through automated means unless such processing is legally permitted and appropriate safeguards are in place.
Where applicable law requires additional information, notice, consent, or safeguards concerning automated processing, Treasatech Global will comply with those requirements.
35. Data Security Responsibilities of Users
You are responsible for taking reasonable steps to protect information that you submit to Treasatech Global.
You should not submit through a general website form:
- Passwords;
- Banking credentials;
- Payment authentication credentials;
- Private cryptographic keys;
- Confidential customer transaction files unless specifically authorised;
- Unnecessary personal data; or
- Other highly confidential information.
If you believe that confidential information has been submitted to Treasatech Global accidentally, please contact us promptly.
36. Confidential Information
This Privacy Policy does not itself create a contractual confidentiality obligation for information submitted through the website.
If you need to provide confidential business, technical, commercial, or other sensitive information, Treasatech Global may require the parties to enter into an appropriate confidentiality agreement or other contractual arrangement.
Please do not submit highly confidential information through a general website contact form unless specifically requested.
37. Privacy by Design
Treasatech Global seeks to incorporate privacy considerations into the design and operation of its systems and services.
Our approach may include principles such as:
- Data minimisation;
- Purpose limitation;
- Access control;
- Appropriate retention;
- Security safeguards;
- Accountability;
- Controlled access to personal data; and
- Consideration of privacy risks during system and process design.
The specific controls applicable to an enterprise deployment may depend on the deployment architecture, customer requirements, contractual commitments, and applicable law.
38. Governance and Accountability
Where Treasatech Global acts as a Data Fiduciary, we will maintain appropriate governance mechanisms for applicable personal data processing.
These may include:
- Privacy policies and procedures;
- Access controls;
- Data processing records;
- Vendor and Data Processor controls;
- Incident response procedures;
- Grievance handling;
- Retention practices;
- Security controls; and
- Periodic review of privacy and security practices.
Where Treasatech Global is designated as a Significant Data Fiduciary under applicable law, we will comply with the additional obligations applicable to that designation.
39. Changes to this Privacy Policy
Treasatech Global may update this Privacy Policy from time to time to reflect:
- Changes in our services;
- Changes in our website;
- Changes in our data-processing practices;
- Changes in applicable law;
- Regulatory guidance;
- Security requirements; or
- Other operational requirements.
Where material changes are made, Treasatech Global may provide appropriate notice through the website or other reasonable means.
The updated Privacy Policy will become effective on the date stated at the beginning of the updated policy unless otherwise specified.
40. Governing Law
This Privacy Policy shall be governed by and interpreted in accordance with the laws of India, subject to applicable mandatory provisions of law.
Nothing in this Privacy Policy is intended to exclude or restrict any statutory right or remedy that cannot lawfully be excluded or restricted.
41. Severability
If any provision of this Privacy Policy is determined by a competent authority to be invalid, unlawful, or unenforceable, the remaining provisions shall continue to operate to the extent permitted by applicable law.
42. No Waiver
Failure by Treasatech Global to enforce any provision of this Privacy Policy shall not constitute a waiver of that provision or of any other rights.
43. Contact Us
For privacy-related questions, requests, or grievances, please contact:
Treasatech Global Private Limited
Privacy / Data Protection Contact: Privacy Team
Email: info@treasatechglobal.com
Registered Office: Plot No. 9, 4 Bay, Sector 32, Gurugram, Industrial Area Faridabad, Faridabad, Faridabad– 121001, Haryana
Website: treasatechglobal.com
For cybersecurity vulnerabilities, please use the dedicated security reporting channel specified in our Security Disclosure rather than submitting vulnerability details through a general contact form.
44. Customer Contracts
This Privacy Policy describes the general privacy practices applicable to the Treasatech Global website and related interactions.
It does not replace or override:
- A Master Services Agreement;
- Data Processing Agreement;
- Security Agreement;
- Enterprise Subscription Agreement;
- Implementation Agreement;
- Confidentiality Agreement;
- Deployment-specific documentation; or
- Other contractual terms agreed between Treasatech Global and an enterprise customer.
Where an applicable customer agreement contains specific provisions concerning personal data processing, those contractual provisions will govern to the extent legally permissible.
45. Effective Date and Version
Effective Date: 17 September 2026
Last Updated: 17 September 2026
Version: 1.0
End of Privacy Policy