How Tatva Fintech Pvt. Ltd. handles personal data in connection with the TatvaRatings website and platform.
Last updated: 22 August 2026.
[TODO: LEGAL REVIEW] — This page describes accurately what we actually collect and do. It has not been reviewed by counsel and has not been mapped clause-by-clause against the Digital Personal Data Protection Act, 2023 and the rules made under it. Every marked section, and the document as a whole, needs a lawyer’s pass before publication.
The short version
The rating corpus contains no personal data. It holds company records — borrowers, lenders, facilities, rating actions — extracted from publicly published credit rating disclosures. Customers do not upload data to the platform. There is no loan book in it and no borrower file.
The personal data we hold is about the people who use TatvaRatings and the people who write to us: a name, a work email address, an organisation, whatever a user types into their own notes, and whatever you put in a message to us.
There are no third-party trackers on this site and no advertising cookies.
Who we are
Tatva Fintech Pvt. Ltd. Office No. 1, Mayfair Towers - II Shivajinagar, Pune Maharashtra 411005, India
CIN: U66190PN2025PTC250051 Email: hello@tatvaratings.com Phone: [TODO: PHONE NUMBER]
For personal data described in this policy, Tatva Fintech Pvt. Ltd. is the entity that determines the purpose and means of processing.
[TODO: LEGAL REVIEW] — confirm the correct DPDP characterisation (Data Fiduciary / Data Processor) for each processing activity, particularly for user accounts and notes created inside a customer organisation’s tenant, where the customer organisation may itself have a role.
What we collect, and why
1. Platform user accounts
- What
Name, work email address, organisation, role, and sign-in records (times of sign-in, the fact of a one-time code being issued and used, and session state).
- Why
To provision and authenticate access, to apply the correct role, to enforce a single active session per user, and to keep an account security record.
- How it arrives
From your organisation’s administrator, or from you when your organisation is provisioned.
2. Watchlists and notes
- What
- The watchlists a user creates and any free text a user types into a note.
- Why
- To provide the feature. Notes are stored inside the user’s own organisation tenant.
A caution worth stating plainly: a note is a free text field, so it can contain whatever a user chooses to type — including personal data about a third party. We do not require or ask for that, and users should not put personal data into notes. Content in notes is the responsibility of the organisation whose users created it.
3. Contact form and correspondence
- What
- Name, email address, organisation, and the content of your message.
- Why
- To answer you, and to keep a record of the exchange.
We do not use contact form submissions for advertising, and we do not sell or share them.
4. Technical logs
- What
Server and application logs generated by ordinary operation — request records, error records, and security-relevant events such as failed sign-in attempts. These may include an IP address.
- Why
- To run the service, diagnose faults, and detect abuse.
[TODO: LEGAL REVIEW] — confirm the correct lawful basis and the retention period for technical logs containing IP addresses.
What we do not collect
- No personal data in the rating corpus. The corpus is company records from public disclosures.
- No customer-uploaded data. There is no upload path for a customer’s loan book, borrower files or any other dataset.
- No payment card data. The platform does not collect or process card details.
- No credit bureau data and no supervisory returns. No non-public source of any kind is used.
- No special or sensitive categories of personal data. We do not seek them and have no purpose that requires them.
- No data from children. TatvaRatings is a business product provisioned to organisations and is not directed at anyone under 18.
Cookies and tracking
No third-party trackers. No advertising cookies. No cross-site tracking or advertising pixels.
The platform uses cookies or equivalent browser storage only where they are necessary to make sign-in work — principally to hold your authenticated session.
[TODO: LEGAL REVIEW] — confirm before publication that no analytics or third-party script has been added to the built site, and align this section with whatever the shipped site actually loads. If any analytics is introduced later, this section must be updated first.
Legal basis and consent
Where we process personal data on the basis of consent, we ask for it at the point of collection and you may withdraw it. Where processing is necessary to provide a service your organisation has contracted for, or to comply with law, we rely on that instead.
[TODO: LEGAL REVIEW] — the DPDP Act, 2023 requires a specific notice at or before the point of collection and defines the grounds available. The notice text used on the contact form and at user provisioning needs to be drafted and reviewed, and this section aligned to it.
Sharing
We do not sell personal data and we do not share it for advertising.
We share personal data only:
- with service providers that host and operate the platform and deliver our email, acting on our instructions and only as needed to provide the service;
- with your organisation’s administrator, in respect of accounts provisioned under that organisation;
- where required by law, or to establish, exercise or defend a legal claim.
[TODO: LEGAL REVIEW] — a named sub-processor list and the contractual terms with each processor need to be prepared and referenced here.
Where data is held and for how long
[TODO: LEGAL REVIEW] — hosting location, cross-border transfer position under the DPDP Act, and specific retention periods for each category above need to be confirmed and stated here as facts. They are deliberately not stated as approximations, because an approximate retention period in a privacy policy is worse than none.
As a matter of practice: account data is retained while the account is active and for a period after it is closed for security and record-keeping; watchlists and notes are deleted on the organisation’s request; contact correspondence is kept as business correspondence.
Security
Access to the platform is by passwordless one-time code to a work email address, with a single active session per user. Tenant isolation is enforced at the database layer by PostgreSQL Row-Level Security, using a restricted database role, so a customer’s data is not reachable from another customer’s session. Staff and administrative surfaces sit on a separate access path from customer routes.
We do not hold ISO 27001 certification or a SOC 2 report, and we do not claim either. The full position, including what we do not have, is on Security.
Your rights
Subject to the conditions and exceptions in applicable law, you may ask us to:
- confirm what personal data about you we hold and how it is processed;
- correct data that is inaccurate, incomplete or out of date;
- erase data where there is no continuing purpose or legal requirement to keep it;
- withdraw consent where consent is the basis for the processing;
- nominate another individual to exercise your rights in the event of death or incapacity, as provided under the DPDP Act, 2023.
Write to hello@tatvaratings.com. Where your account was provisioned by an employer, we may need to route the request through that organisation’s administrator.
[TODO: LEGAL REVIEW] — appoint and name a grievance officer or Data Protection Officer as required, publish their contact details here, and state the response timeline. Confirm the escalation route to the Data Protection Board of India.
Changes to this policy
We may update this policy. The “last updated” date above changes when we do. Where a change materially affects how we handle personal data about provisioned users, we will notify the customer organisation’s administrator.
Contact
Tatva Fintech Pvt. Ltd. Office No. 1, Mayfair Towers - II, Shivajinagar, Pune, Maharashtra 411005, India hello@tatvaratings.com [TODO: PHONE NUMBER]
Or use the contact form.
Related
- Terms of use
- Security
- Sources — where the rating corpus comes from
- Data limits — what the dataset does not cover