Privacy policy

What personal data TatvaRatings holds and why: user accounts, notes and contact form messages. The rating corpus itself contains no personal data.

Legal Last reviewed 6 min read

On this page — 13 sections

How Tatva Fintech Pvt. Ltd. handles personal data in connection with the TatvaRatings website and platform.

Last updated: 22 August 2026.

[TODO: LEGAL REVIEW] — This page describes accurately what we actually collect and do. It has not been reviewed by counsel and has not been mapped clause-by-clause against the Digital Personal Data Protection Act, 2023 and the rules made under it. Every marked section, and the document as a whole, needs a lawyer’s pass before publication.


The short version

The rating corpus contains no personal data. It holds company records — borrowers, lenders, facilities, rating actions — extracted from publicly published credit rating disclosures. Customers do not upload data to the platform. There is no loan book in it and no borrower file.

The personal data we hold is about the people who use TatvaRatings and the people who write to us: a name, a work email address, an organisation, whatever a user types into their own notes, and whatever you put in a message to us.

There are no third-party trackers on this site and no advertising cookies.


Who we are

Tatva Fintech Pvt. Ltd. Office No. 1, Mayfair Towers - II Shivajinagar, Pune Maharashtra 411005, India

CIN: U66190PN2025PTC250051 Email: hello@tatvaratings.com Phone: [TODO: PHONE NUMBER]

For personal data described in this policy, Tatva Fintech Pvt. Ltd. is the entity that determines the purpose and means of processing.

[TODO: LEGAL REVIEW] — confirm the correct DPDP characterisation (Data Fiduciary / Data Processor) for each processing activity, particularly for user accounts and notes created inside a customer organisation’s tenant, where the customer organisation may itself have a role.


What we collect, and why

1. Platform user accounts

What

Name, work email address, organisation, role, and sign-in records (times of sign-in, the fact of a one-time code being issued and used, and session state).

Why

To provision and authenticate access, to apply the correct role, to enforce a single active session per user, and to keep an account security record.

How it arrives

From your organisation’s administrator, or from you when your organisation is provisioned.

2. Watchlists and notes

What
The watchlists a user creates and any free text a user types into a note.
Why
To provide the feature. Notes are stored inside the user’s own organisation tenant.

A caution worth stating plainly: a note is a free text field, so it can contain whatever a user chooses to type — including personal data about a third party. We do not require or ask for that, and users should not put personal data into notes. Content in notes is the responsibility of the organisation whose users created it.

3. Contact form and correspondence

What
Name, email address, organisation, and the content of your message.
Why
To answer you, and to keep a record of the exchange.

We do not use contact form submissions for advertising, and we do not sell or share them.

4. Technical logs

What

Server and application logs generated by ordinary operation — request records, error records, and security-relevant events such as failed sign-in attempts. These may include an IP address.

Why
To run the service, diagnose faults, and detect abuse.

[TODO: LEGAL REVIEW] — confirm the correct lawful basis and the retention period for technical logs containing IP addresses.


What we do not collect

  • No personal data in the rating corpus. The corpus is company records from public disclosures.
  • No customer-uploaded data. There is no upload path for a customer’s loan book, borrower files or any other dataset.
  • No payment card data. The platform does not collect or process card details.
  • No credit bureau data and no supervisory returns. No non-public source of any kind is used.
  • No special or sensitive categories of personal data. We do not seek them and have no purpose that requires them.
  • No data from children. TatvaRatings is a business product provisioned to organisations and is not directed at anyone under 18.

Cookies and tracking

No third-party trackers. No advertising cookies. No cross-site tracking or advertising pixels.

The platform uses cookies or equivalent browser storage only where they are necessary to make sign-in work — principally to hold your authenticated session.

[TODO: LEGAL REVIEW] — confirm before publication that no analytics or third-party script has been added to the built site, and align this section with whatever the shipped site actually loads. If any analytics is introduced later, this section must be updated first.


Where we process personal data on the basis of consent, we ask for it at the point of collection and you may withdraw it. Where processing is necessary to provide a service your organisation has contracted for, or to comply with law, we rely on that instead.

[TODO: LEGAL REVIEW] — the DPDP Act, 2023 requires a specific notice at or before the point of collection and defines the grounds available. The notice text used on the contact form and at user provisioning needs to be drafted and reviewed, and this section aligned to it.


Sharing

We do not sell personal data and we do not share it for advertising.

We share personal data only:

  • with service providers that host and operate the platform and deliver our email, acting on our instructions and only as needed to provide the service;
  • with your organisation’s administrator, in respect of accounts provisioned under that organisation;
  • where required by law, or to establish, exercise or defend a legal claim.

[TODO: LEGAL REVIEW] — a named sub-processor list and the contractual terms with each processor need to be prepared and referenced here.


Where data is held and for how long

[TODO: LEGAL REVIEW] — hosting location, cross-border transfer position under the DPDP Act, and specific retention periods for each category above need to be confirmed and stated here as facts. They are deliberately not stated as approximations, because an approximate retention period in a privacy policy is worse than none.

As a matter of practice: account data is retained while the account is active and for a period after it is closed for security and record-keeping; watchlists and notes are deleted on the organisation’s request; contact correspondence is kept as business correspondence.


Security

Access to the platform is by passwordless one-time code to a work email address, with a single active session per user. Tenant isolation is enforced at the database layer by PostgreSQL Row-Level Security, using a restricted database role, so a customer’s data is not reachable from another customer’s session. Staff and administrative surfaces sit on a separate access path from customer routes.

We do not hold ISO 27001 certification or a SOC 2 report, and we do not claim either. The full position, including what we do not have, is on Security.


Your rights

Subject to the conditions and exceptions in applicable law, you may ask us to:

  • confirm what personal data about you we hold and how it is processed;
  • correct data that is inaccurate, incomplete or out of date;
  • erase data where there is no continuing purpose or legal requirement to keep it;
  • withdraw consent where consent is the basis for the processing;
  • nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act, 2023.

Write to hello@tatvaratings.com. Where your account was provisioned by an employer, we may need to route the request through that organisation’s administrator.

[TODO: LEGAL REVIEW] — appoint and name a grievance officer or Data Protection Officer as required, publish their contact details here, and state the response timeline. Confirm the escalation route to the Data Protection Board of India.


Changes to this policy

We may update this policy. The “last updated” date above changes when we do. Where a change materially affects how we handle personal data about provisioned users, we will notify the customer organisation’s administrator.


Contact

Tatva Fintech Pvt. Ltd. Office No. 1, Mayfair Towers - II, Shivajinagar, Pune, Maharashtra 411005, India hello@tatvaratings.com [TODO: PHONE NUMBER]

Or use the contact form.