COOKIES POLICY
Last Updated: 05-06-2026
1. INTRODUCTION
This Cookies Policy (“Policy”) explains how Erupaiya, a brand owned and operated by Innoplix IT Private Limited (“Company”, “we”, “our”, or “us”), uses cookies and similar tracking technologies when you access or use our platform, website, applications, APIs, dashboards, or related services (collectively, the “Platform”).
Erupaiya provides business-to-business (B2B) financial and payment facilitation services including:
- Domestic Money Transfer (DMT)
- Aadhaar Enabled Payment System (AEPS)
- Micro ATM (mATM) services
- Mobile Point of Sale (mPOS)
- Bharat Bill Payment System (BBPS) for utility payments
2. WHAT ARE COOKIES
Cookies are small text files placed on your device (computer, mobile device, tablet) when you visit or interact with our Platform. These cookies enable us to recognize your device, store preferences, enhance functionality, and improve user experience.
Cookies may be:
- Session Cookies – deleted when you close your browser
- Persistent Cookies – remain on your device for a defined period
- First-party Cookies – set by us
- Third-party Cookies – set by external service providers
3. LEGAL BASIS UNDER DPDP ACT, 2023
In accordance with the Digital Personal Data Protection Act, 2023, we process personal data collected via cookies based on:
3.1 Consent (Section 6 of DPDP Act)
We obtain free, specific, informed, unconditional and unambiguous consent before placing non-essential cookies on your device.
3.2 Legitimate Uses (Section 7 of DPDP Act)
Certain cookies are deployed without explicit consent where permitted for:
- Compliance with legal obligations
- Prevention of fraud and cyber threats
- Ensuring network and information security
- Provision of services requested by the user
4. TYPES OF COOKIES WE USE
4.1 Strictly Necessary Cookies
These cookies are essential for the functioning of our Platform and cannot be disabled.
Examples: Authentication and login sessions, Secure transaction processing, Fraud detection and prevention, Load balancing.
4.2 Functional Cookies
These cookies enhance usability and remember your preferences.
Examples: Language settings, User interface customization, Saved preferences.
4.3 Performance and Analytics Cookies
These cookies help us understand how users interact with the Platform.
Examples: Page visit tracking, Error logging, Usage statistics.
4.4 Security and Compliance Cookies
Given the fintech nature of our services, these cookies are critical.
Examples: Transaction monitoring, Device fingerprinting, Suspicious activity detection, Regulatory audit logs.
4.5 Third-Party Cookies
We may allow trusted third-party partners (e.g., analytics providers, payment gateways) to place cookies. These entities are contractually bound to comply with applicable Indian laws, data protection standards, and confidentiality obligations.
5. PURPOSE OF COOKIE USAGE
The Company uses cookies and similar tracking technologies for the following lawful and operational purposes, in compliance with applicable laws including the Digital Personal Data Protection Act, 2023 and regulatory frameworks issued by the Reserve Bank of India:
- Secure Enablement of Financial Transactions: To facilitate and ensure the integrity, confidentiality, and successful execution of B2B financial transactions across services such as Domestic Money Transfer (DMT), AEPS, mATM, mPOS, and BBPS, including session continuity, transaction validation, and encryption support mechanisms.
- User Authentication and Access Control: To verify user identity, manage authenticated sessions, enforce access controls, and prevent unauthorized or fraudulent access to the Platform, including multi-factor authentication support and device recognition.
- Regulatory Compliance and Reporting: To comply with applicable statutory, regulatory, and supervisory requirements, including guidelines, circulars, and directions issued by the Reserve Bank of India and other competent authorities, including maintenance of logs, traceability of transactions, and audit readiness.
- Platform Performance and Optimization: To monitor system performance, diagnose technical issues, analyze user interaction patterns, and improve functionality, reliability, and user experience of the Platform.
- Fraud Detection, Risk Mitigation, and Security Monitoring: To identify, prevent, and investigate suspicious activities, unauthorized transactions, cyber threats, or misuse of services, including behavioral analytics, anomaly detection, and risk scoring mechanisms.
- Audit Trails and Legal Compliance: To maintain comprehensive records and audit trails necessary for internal governance, statutory audits, dispute resolution, forensic analysis, and compliance with legal obligations under applicable laws.
6. CONSENT MECHANISM
In compliance with the DPDP Act, we implement:
- Cookie consent banners/pop-ups upon first access
- Granular consent options (accept/reject categories)
- Ability to withdraw consent at any time
7. DATA COLLECTED THROUGH COOKIES
Cookies may collect: IP address, device identifiers, browser type and version, operating system, transaction metadata, session identifiers, and usage behavior. Where such data qualifies as personal data under the DPDP Act, it is processed in accordance with applicable legal obligations.
8. DATA RETENTION
We retain cookie data only for as long as necessary to fulfill the purpose for which it was collected, comply with legal and regulatory obligations, or resolve disputes and enforce agreements. Retention periods vary depending on the type of cookie and applicable laws.
9. YOUR RIGHTS UNDER DPDP ACT
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the right to access information about your personal data, request correction or erasure, withdraw consent at any time, access grievance redressal parameters, or nominate another individual in case of incapacity.
10. THIRD-PARTY DISCLOSURES
We may share cookie-derived data with payment processors, regulatory authorities, technology service providers, and fraud detection agencies. Such disclosures are made under contractual safeguards, in compliance with applicable laws, and on a need-to-know basis.
11. CROSS-BORDER DATA TRANSFERS
Where cookie data is transferred outside India, transfers are made strictly in compliance with DPDP provisions, adequate safeguards are implemented, and transfers are restricted to permitted jurisdictions.
12. SECURITY MEASURES
We implement appropriate technical and organizational measures including encryption protocols, access controls, network security systems, alongside continuous monitoring and auditing infrastructure.
13. CHANGES TO THIS POLICY
We reserve the right to update this Policy periodically. Changes will be posted on this page and notified via the Platform or email where required. Continued use of the Platform constitutes acceptance of the updated Policy.
14. GRIEVANCE REDRESSAL & CONTACT DETAILS
In accordance with the DPDP Act, we have appointed a Grievance Officer.
Contact Details:
- Email: [email protected]
- Address: 2nd, office no2, Mahesh Plaza, Mumbai Bangalore highway, Lodha hospital, Above KTM Showroom, Warje Malwadi, Pune, Maharashtra, 411058.
15. GOVERNING LAW
This Policy shall be governed by and construed in accordance with the laws of India, including but not limited to the provisions of the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and rules and regulations framed thereunder, as may be amended from time to time.
Subject to any dispute resolution mechanism specified in the Company’s Terms of Use, the courts and tribunals having competent jurisdiction at Pune, Maharashtra, India shall have exclusive jurisdiction over all matters arising out of or in connection with this Policy.
16. ACKNOWLEDGEMENT
By accessing, browsing, or using the Platform, you expressly acknowledge that you have read, understood, and agree to be bound by this Cookies Policy and consent to the use of cookies and similar tracking technologies as described herein, in accordance with applicable laws including the Digital Personal Data Protection Act, 2023.
Such acceptance shall constitute a valid and informed consent for the processing of personal data, where applicable, for the purposes specified under this Policy. If you do not agree with the terms of this Policy, you are advised to discontinue use of the Platform and disable cookies through your browser settings, except for those cookies that are strictly necessary for the functioning of the Platform.
Continued use of the Platform following any updates or modifications to this Policy shall be deemed to constitute your irrevocable acceptance of such revised terms.