This Privacy Policy explains how JMP NEXTGENPAY PRIVATE LIMITED (CIN: U66190GJ2025PTC170905) ("NextGenPay", "we") collects, uses, discloses and protects your personal data when you use our website or services. This Policy is compliant with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable RBI/NPCI guidelines.
1. Data fiduciary
For the purposes of the DPDP Act, JMP NEXTGENPAY PRIVATE LIMITED is the "Data Fiduciary" for the personal data collected through our website and services. Our registered office is at 2nd Floor, 201, Devi Arcade, Ashwini Kumar Road, Modi Maholla, Surat, Gujarat – 395008, India.
2. Data we collect
- Identity data: name, date of birth, PAN (where required for KYC).
- Contact data: email address, mobile number, billing address.
- Transaction data: biller name, consumer number, bill amount, payment instrument (last 4 digits only), BBPS TRN, transaction status.
- Technical data: IP address, device information, browser type, cookies (see our Cookie Policy).
- Support data: messages, complaints and information you share with our support team.
We do not store your full card number, CVV, UPI PIN or bank password. Card details are tokenised at the payment gateway.
3. Purposes of processing
We process your personal data only for these lawful purposes:
- Facilitating your bill payment via the BBPS network;
- Complying with KYC, AML, PMLA and BBPS/NPCI obligations;
- Preventing fraud and unauthorised access;
- Providing customer support and grievance redressal;
- Sending service-related communications (transaction receipts, alerts);
- Improving our services, subject to your consent;
- Complying with legal, regulatory and court orders.
4. Legal basis
We rely on (a) your consent, (b) legitimate uses under Section 7 of the DPDP Act, or (c) compliance with law, as the case may be.
5. Sharing your data
We share your data only with:
- NPCI Bharat BillPay Ltd. and the concerned biller — to complete your bill payment;
- Our sponsor bank and payment processors — for payment settlement;
- Regulators, law-enforcement or courts — when required by law;
- Trusted service providers (cloud, analytics, email) under strict confidentiality obligations.
We do not sell your personal data to any third party.
6. Data retention
We retain your personal data only as long as required for the purpose it was collected and as mandated by RBI, NPCI, tax, KYC/AML and other applicable laws — typically up to 10 years for financial records. Once retention is no longer required, data is erased or anonymised.
7. Your rights under the DPDP Act
Subject to the DPDP Act, you have the right to:
- obtain a summary of personal data being processed;
- correction, completion, updation and erasure of your personal data;
- grievance redressal through our Data Protection Officer;
- nominate another individual to exercise your rights in the event of death or incapacity;
- withdraw consent at any time (subject to legal retention requirements).
To exercise any of these rights, write to our Data Protection Officer at dpo@nextgpay.in.
8. Data security
We implement industry-standard technical and organisational measures — TLS 1.3 encryption, AES-256 at rest, tokenisation, role-based access, security-training programs and continuous monitoring. However, no method of transmission over the internet is 100% secure.
9. Children
Our services are not directed at children under 18. We do not knowingly collect personal data from children. If you believe we have inadvertently done so, please contact us for prompt deletion.
10. Cross-border transfers
Personal data is primarily stored in India. Where cross-border transfers are required, we transfer only to countries permitted by the Central Government under the DPDP Act.
11. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through email or an on-site notice.
12. Contact
Data Protection Officer (DPO): dpo@nextgpay.in
General queries: info@nextgpay.in