Indian law that applies
We process personal data in accordance with the laws of India, in particular:
- the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025;
- the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
- the Arbitration and Conciliation Act, 1996, under which the arbitrations are conducted.
Where this page uses terms such as data fiduciary, data principal and consent, they have the meaning given in the DPDP Act, 2023. This page describes our practice. It is not a certification of compliance.
Who this policy covers
This policy explains how personal data is handled on abirnyayasetu.com and in the arbitration administration platform behind it ("the platform"). The platform is operated by the arbitration administrator named below, on behalf of lenders who refer loan-default disputes to arbitration.
Nyaya Setu
It covers three groups: respondents (borrowers, co-borrowers and guarantors who receive a notice), staff and lender users who sign in, and visitors to the public pages.
For the data of respondents, the lender decides why the data is needed (to pursue a claim) and the platform handles it for that purpose. The administrator is responsible for how the platform stores, sends and protects it.
Basis for using the data. For respondents we rely on the lawful uses the DPDP Act, 2023 allows without consent, such as the performance of a function under law, compliance with a judgment or order, and the legitimate uses it lists. Where we rely on your consent instead, for example to send messages on WhatsApp or SMS, we ask for it plainly, you can withdraw it at any time, and withdrawing it is as easy as giving it. A notice about this is given to you when we first contact you.
What we collect
Respondents
- Name, loan number, claim amount and dates, as supplied by the lender in its case upload.
- Mobile number and, where the lender has one, email address and postal address, used to deliver notices.
- Documents the lender files, and documents and replies you upload.
- Your language choice, objections, requests and filings made through the case link.
- Delivery records for each notice: channel, time and status (sent, delivered, read, failed, returned), and a proof of service.
- Records of when you open a document and of any consent or opt-out you give.
Staff and lender users
- Name, email address, role, and sign-in details: a password hash, an optional authenticator-app secret, recovery codes, or a Google account identifier if you sign in with Google.
- Session records: device and browser details, approximate network location and last-seen time.
Visitors
The public pages collect nothing about you beyond the technical request data any web server receives. There is no form on them. See Cookies.
Google sign-in
Staff may sign in with Google. We receive only the basic sign-in details that Google provides for authentication (your account identifier and email address). We do not read your Google mail, files or contacts.
Why we use it
- To deliver legal notices on WhatsApp, email, SMS and post, and to prove that they were delivered. Proper notice is a condition of a valid award.
- To let you open your case, read documents, object, reply and take part in hearings.
- To let staff, lenders and arbitrators carry out the process, with each user seeing only what their role allows.
- To keep an accurate record of what was done, by whom and when, and to protect the platform against misuse.
- To answer rights requests and grievances.
The platform does not sell personal data, does not use it for advertising, and does not take payments. Artificial intelligence may assist staff with drafting and summarising, and a person reviews its output. It does not decide anything about your case.
Where your data is stored: India
Your data is stored in India. The database, the backend services, the backups and the stored documents are all in Microsoft Azure, Central India (Pune).
| What | Where it is stored |
|---|---|
| Case, party and audit records (database), and backups | Microsoft Azure, Central India (Pune) |
| Backend services that run the platform | Microsoft Azure, Central India (Pune) |
| Documents: notices, proofs of service, filings, awards (Azure Blob Storage, with versioning) | Microsoft Azure, Central India (Pune) |
| Email notices and sign-in emails (Azure Communication Services) | Azure, data location India |
| AI features (drafting and summarising help for staff) | CallMissed models hosted in India |
What passes outside India, and what does not stay there
Some data has to travel over networks that are not in India. We separate what is stored from what is carried. Stored data is in India. We do not claim that no data ever crosses a border while in transit, for these paths:
- Website pages. Pages are served through Cloudflare's global edge network, and public pages are cached there. No personal data is stored on that network. The respondent portal and staff screens are not public pages, and their content is not cached for others.
- Live video hearings. Audio and video are relayed through Cloudflare's real-time network, which routes each call to the nearest data centre. Nothing is recorded by default. A hearing is recorded only if the arbitrator starts a recording. A recording is first held by the video provider and is then copied into the platform's document storage in Azure, Central India, which is where we keep it.
- WhatsApp. WhatsApp messages are carried over Meta's WhatsApp network, and are subject to WhatsApp's own terms. We send them through CallMissed. Messages sent to you on WhatsApp are on that network once sent.
- SMS and post. These are delivered by telecom and postal carriers. The number or address needed to deliver a notice is passed to them for that purpose.
Providers process data only to provide their service to the platform. We are a data fiduciary under the Digital Personal Data Protection Act, 2023 and we process personal data in accordance with that Act and the rules made under it, including any restriction on transfers outside India that the Government notifies.
Data is also shared with the parties to a case as the process requires: the lender, the appointed arbitrator and the other side, each limited to the case. We disclose data to a court or authority when the law requires it.
How it is protected
- Phone numbers and email addresses are encrypted at rest. A separate keyed hash lets the system match a number without storing it in readable form.
- Data is separated by firm (tenant) at database level, and every query runs inside that boundary.
- Case links are single-use, and signing in to a case needs a one-time code sent to your registered mobile number plus a check on your loan number. Staff sign-in supports two-step verification.
- An append-only audit log, chained with hashes, records every change to a case. Application accounts cannot edit or delete it.
- One-time codes, tokens and passwords are never written to logs.
No system is perfectly secure. If a personal data breach affects you, we will tell the Data Protection Board of India and each affected person, as the DPDP Act, 2023 and its Rules require.
The audit log and delivery records are kept as electronic records so that they can be produced as evidence in the manner the Bharatiya Sakshya Adhiniyam, 2023 allows.
How long we keep data
Retention periods are set per type of document in the platform's retention policy, on the advice of counsel, and each period runs either from the date the document was created or from the date the case closed. The system enforces a minimum of 30 days. We do not publish fixed periods on this page until counsel has confirmed them; you may ask us for the period that applies to your case at privacy@abirnyayasetu.com.
- A scheduled job runs every night (02:30 India time) and permanently deletes documents whose period has ended.
- A legal hold on a case stops deletion until the hold is lifted.
- When a document is deleted we keep a deletion record: a fingerprint of the content, the date and the policy applied, but not the document.
- Audit log entries are kept as the integrity of the record requires.
Your rights
Under the Digital Personal Data Protection Act, 2023 you may ask us to give you access to your personal data and a summary of how it is processed, correct or complete it, erase it, and have a grievance resolved. You may also nominate another person to exercise these rights for you if you die or become incapable.
The platform records each request with its date and a due date. The default response time is 30 days. Some data cannot be erased while a case is open or under a legal hold, or where the law requires us to keep it. We will tell you the reason if that applies.
To make a request, follow the steps on the grievance and rights page. If you have used our grievance process and are not satisfied, or we have not replied in time, you may complain to the Data Protection Board of India.
Children
The platform is for adults who are party to a loan. It is not directed at children. If you believe a child's data has been entered, write to privacy@abirnyayasetu.com.
Changes and contact
We will update this page when practices change and show the date at the top. Questions about this policy: privacy@abirnyayasetu.com. Rights requests and complaints: grievance@abirnyayasetu.com.
Nyaya Setu