Privacy Policy

PRIVACY POLICY

ApiBox B2B Marketplace and API Platform
Effective date: 4 September 2026 | Last updated: 4 September 2026

This Privacy Policy explains how Knockus Services Private Limited ("Knockus Services", "Company", "we", "us" or "our"), which owns and operates the ApiBox brand and platform, collects, uses, shares, stores and protects personal data when a person visits https://apibox.co.in/ , registers for or uses the ApiBox website, dashboard, APIs, virtual-account funding facility, communications or related services (collectively, the "Platform").

ApiBox is a B2B marketplace and technology platform. Registered Users may act as a Buyer, a Seller, or both, subject to applicable onboarding and service eligibility. Third-party Sellers/service providers supply the underlying recharge, DTH, utility-bill-payment and other enabled services; the Company facilitates platform access, transaction processing, settlement support and invoicing as described in the Terms and Conditions.

This Policy should be read with the ApiBox Terms and Conditions and other notices presented when particular data is collected. Where a separately signed agreement applies, that agreement may contain additional data-processing terms.

1. SCOPE AND ROLES

This Policy applies to personal data relating to individual proprietors, directors, partners, authorised signatories, employees, agents, beneficial owners, customers, recipients and other natural persons whose data is submitted to or generated through the Platform. It does not govern a third party’s independent processing under its own privacy notice.

Depending on the activity, Knockus Services may act as the entity deciding why and how personal data is processed, or may process data on documented instructions of a business User. Each Buyer or Seller remains responsible for having a lawful basis and giving required notices for personal data that it uploads, transmits or otherwise makes available through the Platform.

2. PERSONAL DATA WE COLLECT

  • Account and identity data: name, business name, username, role, date of birth where required, photograph, signature, authorised-user details and account credentials.
  • Business and KYC data: PAN, GSTIN, Aadhaar or other officially valid document details where legally permitted, incorporation/registration records, beneficial-ownership information, licences and verification results.
  • Contact data: business/registered address, email address, telephone number and communication preferences.
  • Financial and settlement data: bank-account and beneficiary details, virtual-account identifiers, deposits, wallet/ledger balances, payouts, refunds, reversals and reconciliation information. We do not intend to store full card credentials; payment partners may process them under their own terms.
  • Transaction and invoice data: Buyer/Seller role, orders, service category, operator/biller, customer or recipient identifiers needed to fulfil a transaction, amounts, status, commissions/platform charges, tax details, invoices, credit notes and disputes.
  • Technical, device and usage data: IP address, device/browser identifiers, operating system, login and API activity, timestamps, request/response metadata, security events, cookies and diagnostic logs.
  • Communications and support data: emails, calls or chat records, instructions, complaints, grievance records, feedback and documents submitted for investigation or support.
  • Compliance and risk data: sanctions/fraud-screening results, transaction monitoring, audit trails and information obtained from banks, payment/collection partners, Sellers, billers, operators, regulators or law-enforcement agencies.

Please do not submit personal data that is not necessary for the relevant transaction or legal requirement. Where authentication or verification uses biometric-enabled government systems, the relevant authorised provider may process biometric data; ApiBox will process or retain such data only where specifically authorised and legally permitted.

3. HOW WE COLLECT DATA

  • Directly from Users during registration, KYC, account administration, virtual-account funding, orders, invoicing, support and communications.
  • Automatically through the website, dashboard, APIs, cookies, server logs and security tools.
  • From authorised partners such as Sellers/service providers, banks, payment and collection partners, virtual-account providers, BBPS/COU/BBPOU participants, billers, telecom/DTH operators, KYC providers and fraud-prevention vendors.
  • From public records, government or regulatory databases, and competent authorities where lawful.

4. PURPOSES AND LAWFUL GROUNDS

We process personal data for a lawful purpose based on consent, performance of the User relationship, compliance with law, or another ground permitted under applicable law. Purposes include:

  • creating and securing accounts; completing KYC, business and beneficial-owner verification; and determining service eligibility;
  • enabling a User to operate as Buyer, Seller or both and matching/processing marketplace transactions;
  • routing transaction instructions to the relevant Seller, operator, biller, bank or service provider and returning status/callback information;
  • mapping funds deposited by a Buyer into an assigned virtual account linked to the Company’s designated main collection account, maintaining the platform ledger and supporting settlement, refunds, reversals and reconciliation;
  • generating and exchanging invoices, commission/platform-charge documents, tax records and account statements under the applicable P2P or P2A model;
  • providing support, resolving disputes and grievances, preventing duplicate/failed transactions and communicating service or policy updates;
  • detecting fraud, abuse, cyber incidents, sanctions or unlawful activity and enforcing Platform terms;
  • meeting accounting, tax, audit, banking, payment-network, regulatory, court and law-enforcement requirements; and
  • improving performance, reliability and business analytics using aggregated or appropriately de-identified data where practicable.

Promotional communications will be sent only as permitted by law and applicable preferences. Operational, security, transaction and legal notices may still be sent where necessary.

5. SHARING AND DISCLOSURE

We may share only the data reasonably necessary for the relevant purpose with:

  • the counterparty Buyer or Seller and the relevant Seller/service provider for fulfilment, invoicing, settlement, reconciliation, support and disputes;
  • banks and authorised payment, collection and virtual-account partners, including Axis Bank Limited, HDFC Bank Limited and ICICI Bank Limited where engaged for the applicable flow;
  • BBPS participants, billers, telecom/DTH operators, travel or other service providers, KYC/verification providers and technology vendors;
  • affiliates or a successor in a merger, acquisition, restructuring or asset transfer, subject to applicable law; and
  • courts, regulators, tax authorities, law-enforcement agencies or other persons where disclosure is required or permitted by law, or necessary to protect rights, security and users.

Recipients may independently determine how they process data for their own statutory or service-delivery obligations. Their privacy policies may also apply.

6. COOKIES AND ANALYTICS

The Platform may use strictly necessary cookies or similar technologies for login, session continuity, security, load balancing and preferences, and may use analytics technologies to understand performance and usage. Where required, optional cookies will be used only after obtaining consent. Browser settings may block cookies, but some Platform features may then not work correctly.

7. STORAGE, TRANSFERS AND RETENTION

Data may be processed in India and, where lawfully permitted, in other jurisdictions in which approved service providers operate. We apply contractual, technical and organisational safeguards and comply with any transfer restrictions notified under applicable law.

We retain personal data only for as long as necessary for the stated purpose, the User relationship, transaction completion, fraud prevention, dispute resolution, audits and legal/regulatory obligations. Transaction, KYC, tax, invoice, accounting, security and banking records may be retained for the period required by applicable law or partner/network rules. When retention is no longer required, data is deleted, anonymised or securely isolated, subject to backup cycles and lawful holds.

8. SECURITY AND INCIDENT RESPONSE

We use reasonable technical and organisational safeguards appropriate to the nature of the data and risk, which may include access controls, encryption in transit and where appropriate at rest, logging, monitoring, vulnerability management, backups, segregation and vendor controls.No internet-based system can guarantee absolute security; Users must protect credentials, API keys, devices and authorised-user access and promptly report suspected compromise.

If a personal-data breach occurs, we will investigate, mitigate and provide notifications to affected persons and authorities where required by applicable law. Security incidents should be reported to grievances@apibox.co.in or 9355256888.

9. YOUR RIGHTS AND CHOICES

Subject to applicable law and verification of the requester, an individual may request information about processing, access to a summary of personal data and sharing, correction or updating, erasure where retention is not legally required, withdrawal of consent, grievance redressal, and nomination of another individual to exercise rights in the event of death or incapacity. These rights apply in accordance with the commencement and scope of the Digital Personal Data Protection Act, 2023 and other applicable law.

A request may be sent to grievances@apibox.co.in . We may ask for proportionate identity verification.Withdrawal of consent does not affect earlier lawful processing and may prevent future use of a feature, but it will not stop processing required for completed/pending transactions or legal compliance.

Users must keep information accurate, avoid impersonation, refrain from filing false or frivolous grievances and ensure they are authorised to provide another individual’s data.

10. CHILDREN

The Platform is intended for businesses and persons legally competent to contract and is not directed to children. Users must not submit a child’s personal data unless it is necessary, lawful and supported by verifiable parental/guardian consent where required.We do not knowingly undertake tracking, behavioural monitoring or targeted advertising directed at children.

11. THIRD-PARTY LINKS AND SERVICES

The Platform may link or connect to third-party services. We are not responsible for a third party’s independent websites, security practices or privacy notices. Users should review the relevant third-party terms before providing data.

12. CHANGES TO THIS POLICY

We may update this Policy to reflect operational, legal or regulatory changes. The revised version will be posted with an updated date and, where required, notified through email, dashboard or another effective channel. Material changes operate prospectively unless law requires otherwise.

13. GRIEVANCE AND CONTACT DETAILS

Company: Knockus Services Private Limited

Brand/Platform: ApiBox

Website: https://apibox.co.in/

Registered Office: Second Floor, FF-23, Gali No. 2, Mangal Bazar, Laxmi Nagar, New Delhi, East Delhi, Delhi - 110092

Grievance Officer: Mr. Sandeep Kumar Yadav

Email: grievances@apibox.co.in

Phone/WhatsApp: 9355256888

General Contact: hello@apibox.co.in

Support: support@apibox.co.in

We will acknowledge and address grievances within the period required by applicable law. If a grievance remains unresolved, an eligible individual may use the remedy available before the competent authority once and to the extent applicable.

14. LEGAL STATUS AND INTERPRETATION

References to the Digital Personal Data Protection Act, 2023 and its rules apply as and when the relevant provisions come into force. Until then, the Information Technology Act, 2000 and applicable rules continue to apply to the extent in force. If any part of this Policy conflicts with mandatory law, the mandatory law will prevail and the remaining provisions will continue to apply.