Privacy Policy
How DBDK Technology collects, uses, shares, and protects information across all products and services we offer.
Last updated: 9 September 2026
1. Who we are
This policy is issued by DBDK Technology, Office no 203, Possible Triangle Complex, opp Satva Prime, Mavdi road, Rajkot - 360004, Gujarat, India (“we”, “us”, “our”, “DBDK”).
It applies to our website, apps, APIs, white-label / partner platforms, custom software, and all products and services we currently offer or may offer from time to time, including:
- Utility and bill payments, including Bharat Bill Payment System (BBPS)
- Mobile, DTH, and postpaid recharge
- AePS, DMT, payout, and payment-gateway related technology
- Travel booking (hotel, flight, bus, and train)
- Identity, KYC, and e-governance services (Aadhaar, PAN, online applications, digital signature, government-application links)
- Bank-account opening and insurance modules
- B2B APIs, white-label software, partner portals, and custom fintech development
- Related support, onboarding, billing, and website inquiries
Contact: dbdktechnology@gmail.com
This policy should be read with our Terms & Conditions and Refund Policy.
2. Scope
This policy covers personal and business information of website visitors, end customers, agents, retailers, distributors, and enterprise partners who use any DBDK product or service. Where a product is delivered through a bank, NPCI, biller, telecom operator, travel supplier, UIDAI / PAN agency, insurer, or other authorised partner, that partner may also process data under its own privacy notice. We collect and use only what is needed to provide, secure, bill, and support the relevant service.
3. Information we collect
Depending on the product or service you use, we may collect:
- Identity and contact — name, mobile number, email, address, date of birth, photograph, and organisation details of customers, agents, or partners.
- KYC / onboarding — KYC documents, Aadhaar / PAN / other ID numbers (as permitted by law), business proofs, and onboarding forms required for agents, retailers, or corporate users.
- BBPS and utility payments — biller name, consumer number / account ID, bill amount, payment mode, date, time, and BBPS / biller reference or approval number.
- Recharge — operator, circle, mobile / DTH / account number, plan or amount, and operator confirmation / reference.
- AePS, DMT, payout, and payment gateway — beneficiary name, account / IFSC / UPI details, amount, mode, and bank or gateway references, as required to complete the instruction.
- Travel — traveller names, age or date of birth, contact details, journey or stay dates, PNR / booking references, and payment status shared by the airline, hotel, bus, or train supplier.
- Identity, KYC, and e-governance — application type, document uploads, biometric or OTP authentication status (where enabled), and application / acknowledgement numbers. We do not store Aadhaar OTP, biometric templates, or card / UPI PIN.
- Banking and insurance — information needed to facilitate digital account opening or insurance quotation / issuance with the relevant bank or insurer (for example name, KYC, nominee, and product selection). The bank or insurer is the data controller for underwriting and account records.
- Software, API, and white-label — company name, GST, authorised-signatory details, IP whitelist, API keys (hashed or masked where stored), webhook URLs, usage logs, and commercial / billing data.
- Device and technical data — IP address, browser or app type, device identifiers, and logs needed for security, fraud prevention, and dispute handling.
- Support and website — inquiry forms, emails, call notes, and complaint records you send to us.
We do not ask you to store card PIN, UPI PIN, ATM PIN, or OTP with us. Those are entered only on the bank / UPI / card network / authorised agency page.
4. How we use information
We use information to operate the specific product you requested and to run our business, including:
- To process BBPS bill payments, recharges, payouts, travel bookings, KYC applications, banking / insurance facilitation, and related receipts or status updates.
- To route instructions to NPCI, billers, banks, operators, travel suppliers, UIDAI / PAN agencies, insurers, and payment partners as required to complete the transaction or application.
- To onboard partners, issue API credentials, deliver white-label or custom software, and provide support.
- To prevent fraud, comply with RBI, NPCI, BBPS, UIDAI, IRDAI, tax, and other applicable rules, and to handle complaints, chargebacks, or audits.
- To send transactional alerts (SMS / email / app) related to your order or payment. Marketing messages are sent only where permitted.
- To improve reliability, security, and product quality of our platforms.
5. Sharing of information
We share data only as needed to deliver the product or service and to meet legal duties, including with:
- NPCI and the BBPS ecosystem (billers, COU/BOU, banks, and settlement partners) for bill payments.
- Telecom / DTH operators and recharge aggregators for recharge services.
- Banks, AePS / DMT / payout partners, and payment-gateway providers for banking and fund-transfer rails.
- Airlines, hotels, bus operators, IRCTC / train partners, and travel aggregators for bookings.
- UIDAI, NSDL / UTIITSL or other PAN agencies, DSC providers, and authorised e-governance partners for identity services.
- Banks and insurers for account-opening and insurance modules (they process data under their own policies).
- Hosting, SMS, email, and IT vendors under confidentiality, solely to run the platform.
- Regulators, law-enforcement, or auditors when legally required.
We do not sell personal data.
6. Retention
We retain records for as long as needed to provide the service, resolve disputes, collect dues, and meet applicable RBI, NPCI, BBPS, UIDAI, tax, IRDAI, and contract timelines. Payment, booking, KYC, and ledger records are then deleted or anonymised where feasible. Some transaction data cannot be deleted immediately because of regulatory retention rules.
7. Security
We use access controls, encrypted transmission where applicable, credential protection for APIs, and audit logs. No internet transmission is 100% secure. You and our partners must keep login credentials, API secrets, and OTP confidential.
8. Your rights
Subject to Indian law (including the Digital Personal Data Protection Act, 2023, as applicable), you may request access, correction, or deletion of personal data, or raise a privacy complaint, by writing to dbdktechnology@gmail.com. We may need to verify your identity. Some records must be retained for regulatory, tax, or dispute reasons and cannot be erased on request.
9. Cookies
Our website may use essential cookies for security and session management. You can control cookies in your browser settings.
10. Children
Our products and services are intended for persons who can enter a contract under Indian law, and for businesses. We do not knowingly collect personal data from children for marketing. Travel bookings may include a child’s passenger details only as provided by the adult booker to complete the booking.
11. Changes
We may update this policy when we add products, change processing, or the law changes. The revised version will be posted on this page with an updated date. Continued use of any DBDK website, product, or platform after the update means you accept the revised policy.