📍 Built in India for the world. Your privacy comes first. The E1 CBDC platform is launching soon 🚀

Privacy Policy

Last Modified: September 16, 2026

Introduction

At 1M Global Business Services Private Limited ("E1", "we", "us" or "our"), your privacy is our priority. We are committed to protecting your personal and financial information while delivering secure, transparent and innovative financial services. This Privacy Policy explains how we collect, use, store and safeguard your data when you use our CBDC and eRupi platform, through our web platform or mobile application.

In short: we collect only the essential information needed to provide our services. Data is encrypted in transit and at rest. We never sell or share personal data with third parties for marketing. You can request access to, correction of or deletion of your data at any time, subject to regulatory requirements.

1. Information We Collect

When you use E1, we collect only the information necessary to provide secure, compliant and personalised financial services. This includes:

  • Personal Information: Name, contact details, date of birth and identification documents required for KYC verification under RBI guidelines.
  • Financial Information: Account numbers, deposits, transaction history, investment records and payment instructions.
  • Usage Data: Device details, login activity, browser type, IP address and interaction patterns with our app or web platform.
  • Compliance Data: KYC records, AML checks and regulatory reporting information to meet RBI and Indian financial law requirements.
  • Device Permissions Data: When enabled by you, access to your camera (for QR code scanning or KYC), location (for fraud detection and compliance), contacts (for simplified transfers) and storage (for saving receipts or statements).
  • Cookies and Tracking Data: Session cookies and analytics tools used to improve platform performance, secure login sessions and deliver personalised insights.

All information is encrypted, stored securely and used solely to provide services such as CBDC transactions, eRupi voucher redemption, CPICBDC payments and enterprise automation.

2. What We Never Collect

We do not access or store:

  • personal photos, videos or media unrelated to our financial services;
  • private messages, browsing history or social media content; or
  • sensitive personal files beyond what is required for KYC and compliance.

3. How We Use Your Information

Your data is used strictly to:

  • provide and improve our services;
  • enable CBDC transactions, eRupi voucher redemption, CPICBDC payments and blockchain-based sidechain settlements;
  • process deposits, recurring deposits, investments and cross-border transfers;
  • personalise your experience with rewards, loyalty points and smart financial insights; and
  • comply with RBI regulations and Indian financial laws, and ensure transparency in every transaction.

We do not sell or share your personal data with third parties for marketing purposes.

4. Device Permissions

To deliver a seamless and secure experience, E1 may request certain device permissions when you use our mobile app or web platform. These permissions are strictly limited to enhancing functionality and ensuring compliance with RBI guidelines. We never access or use your device data beyond what is necessary to provide our services.

Permissions We May Request

  • Camera and Gallery Access: For KYC verification, uploading identity documents or scanning QR codes for payments.
  • Location Access: To detect suspicious login activity, enable location-based offers and comply with regulatory requirements for cross-border transactions.
  • Contacts Access: Only when you choose to make payments directly to saved contacts, simplifying transfers.
  • Microphone Access: For secure voice authentication (if enabled by you).
  • Storage Access: To save transaction receipts, account statements or invoices securely on your device.

How We Protect Your Privacy

  • Permissions are requested transparently and only when required.
  • You can manage or revoke permissions at any time through your device settings.
  • We do not collect or store personal files, photos or media unrelated to our services.
  • All data accessed through permissions is encrypted and used solely for the intended purpose.

5. Cookies and Tracking

We use cookies and similar technologies to:

  • improve platform performance;
  • provide secure login sessions; and
  • deliver personalised insights and rewards.

You can manage your cookie preferences through your browser settings.

6. Information Sharing and Disclosure

We value your privacy and share information only when absolutely necessary. Your personal and financial data is never sold or shared for marketing purposes. Information may be disclosed to third parties only in the following circumstances:

  • Regulatory Compliance: With the Reserve Bank of India (RBI), government authorities or law enforcement agencies, when required by law or in response to lawful requests.
  • Trusted Service Providers: With technology partners, payment processors or auditors who support our operations, strictly for operational purposes and under binding confidentiality agreements.
  • Fraud Prevention and Security: With security agencies or partners, to detect and prevent unauthorised transactions.
  • Customer Consent: With third parties only when you explicitly authorise us (for example, when linking accounts, redeeming vouchers or using partner offers).

We ensure that all third parties adhere to strict data protection standards and use your information only for the intended purpose.

7. Data Retention

We retain your information only for as long as necessary to provide our services and comply with legal obligations:

  • KYC and Compliance Records: Retained as mandated by the RBI and Indian financial regulations.
  • Transaction Data: Maintained for audit, dispute resolution and regulatory reporting.
  • User Account Data: Retained while your account is active. If you close your account, data is archived securely and deleted after the legally required retention period.
  • Optional Data (e.g., analytics, personalisation): Retained only with your consent and deleted upon withdrawal of consent.

All retained data is encrypted, stored securely and subject to strict access controls. Once the retention period expires, data is permanently deleted or anonymised.

8. Information Security

We implement industry-leading safeguards to protect your personal and financial data:

  • All information is encrypted in transit and at rest, and all transactions are protected with end-to-end encryption.
  • Multi-factor authentication is required for account access.
  • Transactions processed through our CPICBDC wallet and blockchain sidechains are validated on tamper-proof ledgers, ensuring immutability and transparency.
  • We comply with RBI guidelines and conduct regular audits, vulnerability assessments and continuous fraud monitoring to detect and prevent unauthorised activity.
  • Access to sensitive data is strictly controlled, limited to authorised personnel and governed by RBI compliance standards.

9. Data Privacy Commitments

  • We adhere to Indian data protection laws and RBI directives.
  • Data usage is transparent and consent-based.
  • Strict access controls prevent unauthorised use of your data.

10. Your Rights in Relation to Sensitive Personal Data or Information

As a customer, you have clear rights regarding the sensitive personal data we collect and process:

  • Right to Access: You may request details of the personal and financial information we hold about you.
  • Right to Correction: You may update or correct inaccurate or incomplete information at any time.
  • Right to Deletion: You may request deletion of your data, subject to mandatory retention periods under RBI and Indian financial regulations.
  • Right to Withdraw Consent: For optional data usage (such as analytics or personalisation), you may withdraw consent at any time.
  • Right to Restrict Processing: You may request that we limit the use of your sensitive data to essential services only.
  • Right to Transparency: You will be notified of any significant changes in how your sensitive data is collected, used or shared.

We are committed to honouring these rights while balancing our regulatory obligations, ensuring that your sensitive personal data is always handled with fairness, transparency and respect. You may write to us at dataprivy@E1.com to access, review, modify or correct your personal data or information, or to withdraw your consent to provide personal data or information.

11. Links to Other Sites

  • Our platform may provide links to third-party advertisements, websites or electronic communication services operated by independent third parties.
  • Unless expressly specified, these links are not controlled by, affiliated with or associated with E1.
  • We are not responsible for any transmissions, communications or content you may receive from third-party websites.
  • We make no representations regarding the privacy practices, policies or terms of use of such third parties.
  • We do not control or guarantee the accuracy, integrity or quality of information, data, text, software, music, sound, photographs, graphics, videos or other materials available on third-party websites.
  • The inclusion or exclusion of links does not imply endorsement by E1 of the third-party website, its provider or its content.
  • Any information you provide to third-party websites will be governed by their own privacy policies, and we strongly recommend reviewing those policies before using such websites.

12. Secure Usage Guidelines

At 1M Global Business Services Private Limited, safeguarding your financial assets is our highest priority. We are committed to protecting customers from online scams, fraudulent activities and unauthorised access. This section outlines common threats, preventive measures and best practices for secure usage of our platform.

Common Threats

  • Malware: Malicious software can monitor activity and steal sensitive data. Avoid downloading files from untrusted sources.
  • Phishing and Smishing: Fraudulent emails, SMS or social media messages may impersonate trusted institutions to steal credentials.
  • Spear Phishing: Targeted, personalised attacks disguised as legitimate communications.
  • Spoofing: Fraudsters replicate websites, emails or phone calls using fake logos and URLs.
  • Vishing: Phone calls pretending to be from banks or service providers, asking for OTPs, PINs or personal details.
  • SIM Swap Fraud: Criminals obtain duplicate SIMs to intercept OTPs and alerts.
  • Social Network Frauds: Fake apps, browser extensions or surveys on social media designed to capture personal and financial information.
  • Money Mule Scams: Fraudsters lure victims into sharing bank details for "easy money", using their accounts to launder stolen funds.

Secure Portal Usage Tips

  • Confidentiality: Keep your login credentials private; never share them.
  • Memorise: Do not write down or store passwords insecurely.
  • Safe Access: Avoid logging in from public Wi-Fi or shared computers.
  • Direct Login: Always type our official URL in your browser's address bar.
  • Suspicion: Treat any request for confidential information with caution.
  • Disable Auto-Complete: Prevent browsers from storing sensitive login data.
  • Monitor: Regularly review your transactions and account statements.
  • Log Out: Always log out after use; do not just close the browser.
  • Update Contact Information: Ensure your mobile number and email details are current.
  • Stay Vigilant: Pay attention to SMS alerts and OTPs, and report discrepancies immediately.
  • Delete Suspicious Emails: Do not open attachments or click links from unknown sources.

Additional Security Practices

  • Multi-Factor Authentication (MFA): Always enable MFA for added protection.
  • Device Hygiene: Keep your operating system, browser and apps updated.
  • Strong Passwords: Use complex, unique passwords for your account.
  • Fraud Reporting: Immediately report suspicious activity to our support team.
  • Awareness: Educate employees and family members about online fraud tactics.
  • Links: Do not click any links received from unauthorised, suspicious or unknown sources.

Reporting and Support

If you notice unusual activity on your account, contact us immediately at support@E1.com. We provide 24/7 assistance and a clear escalation matrix to ensure timely resolution.

13. Grievance Redressal

  • We provide 24/7 support via chat, email and phone.
  • Every grievance is tracked with a unique reference ID.
  • Issues are resolved within clear timelines: 48 hours for first response and 7 days for closure.
  • If you have concerns about your data privacy, you can contact our Data Protection Officer (DPO) at privacy@E1.com. We aim to resolve all privacy complaints within 7 business days.
  • Unresolved complaints can be escalated to the RBI Banking Ombudsman.

Grievance Officer

Grievance Officer — contact details will be published here soon. In the meantime, you may reach us at:

14. Acknowledgements

You hereby agree that the application and all documents submitted by you shall, to the extent permitted under applicable law, remain the property of 1M Global Business Services Private Limited. We are not obliged to return these documents upon request. Any unauthorised access to our platform constitutes a breach of these terms and a violation of applicable law. You agree to access the platform only through the official interface provided by 1M Global Business Services Private Limited.

You further acknowledge and agree that this Privacy Policy:

  • is clear, transparent and easily accessible, providing statements of our policies and practices with respect to information security;
  • defines the various types of personal and sensitive personal data we collect;
  • explains the purposes for which such information is collected and used;
  • outlines the circumstances under which information may be disclosed; and
  • establishes the reasonable security practices and procedures we follow to protect your data.

If you have any questions or concerns regarding this Privacy Policy, you may contact our Grievance Officer at the coordinates provided above. We are committed to addressing your queries promptly and transparently.

15. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in regulations, technology or our services. All updates will be published on this page, and significant changes will be communicated to customers directly.

16. Disclaimer

This Privacy Policy is tailored to E1 and is intended to comply with the EU General Data Protection Regulation (GDPR), Indian data protection laws and RBI directives. It does not apply to third-party platforms or services linked externally.