CGPEY International Pvt. Ltd. is committed to data sovereignty. All customer data, transaction records, and KYC information are stored and processed within India, in compliance with Indian data protection and regulatory requirements.
Data residency means that all data you share with CGPEY is physically stored and processed on servers located within India, giving you full sovereignty over your financial information.
All customer data, KYC records, and transaction logs are stored on servers physically located inside India.
Our data practices align with RBI guidelines, the Digital Personal Data Protection Act, and Indian IT Act requirements.
Your data remains subject to Indian jurisdiction, ensuring legal clarity and predictable protection for your business.
We take data residency seriously and enforce it through infrastructure, process, and contractual commitments.
All production workloads run in Tier-IV data centres located within India, with no cross-border data replication.
Data is encrypted in transit using TLS 1.3 and at rest using AES-256, with keys managed inside India.
Only authorised India-based personnel can access production systems, with full audit logging and role-based controls.
Our third-party processors operate under strict contracts that require them to store and process data within India.
Encrypted backups are held in geographically separate Indian regions to ensure business continuity without leaving the country.
We provide clear documentation of our data location, retention, and processing practices on request.
This policy applies to all personal data, business data, KYC records, and transaction data collected, stored, or processed by CGPEY through its platform and services.
All production data is stored in Tier-IV data centres within India. Backup copies reside in a second Indian region for disaster recovery. No customer data is replicated outside India.
CGPEY does not transfer customer data outside India. Any future requirement for cross-border transfer would only occur with prior legal review, customer consent where required, and full compliance with applicable laws.
Our data residency framework is designed to align with the RBI's Storage of Payment System Data directive, the Digital Personal Data Protection Act, and applicable rules issued by Indian regulatory authorities.
Data is retained for the period required by law and by our regulatory obligations. Once the retention period ends, data is securely deleted or anonymised.
Customers can request details about where their data is stored, how long it is retained, and how it is protected, by contacting our compliance team.
Our data residency controls are reviewed through internal audits and periodic third-party assessments to ensure continued compliance.
For any data residency related questions, reach out to our compliance team at compliance@cgpey.com.
Our compliance team can walk you through our data locations, controls, and documentation for regulatory reviews.