DRAFT FOR LEGAL REVIEW

Privacy Policy

How Yugai Solution Private Limited (“YugAI”) collects, uses, stores, protects and manages personal data across its corporate website, digital platforms, portals and services.

Effective Date:To be approved
Draft Updated:22 August 2026
Important Compliance Notice

Important: This is a structured working draft for legal and compliance review. Final publication should use verified operational practices, approved contact details, service-specific data flows and applicable legal requirements.

01

Introduction & Scope

Yugai Solution Private Limited, operating under the enterprise brand YugAI, respects privacy and is committed to responsible handling of personal data. This Privacy Policy is intended to explain how personal data is handled when individuals interact with YugAI’s public website and, where specifically adopted, YugAI digital portals, applications and services.

Where a specific YugAI service, business brand, partner journey, provider workflow or regulated financial service has additional privacy terms, those service-specific terms should be read together with this Policy.

02

Information We Collect

Depending on the service or relationship, YugAI may process categories of information such as:

Identity and contact information.
Profile, customer, farmer, SHG, FPO or business information.
Registration, account and verification information.
KYC documents and verification status where applicable.
Application, service, order, transaction, receipt and invoice information.
Bank or payment-related information where required for a service or transaction.
Device, session, login, security and activity information.
Communication, support, grievance and preference information.

Before publication: confirm the exact categories actually collected by each live YugAI channel and remove any category not in use.

03

How We Collect Information

Information may be collected directly from users through forms, registrations, account activity, KYC or service requests; through transactions and support interactions; through authorized YugAI partners or service providers where the relevant workflow permits; and through technical systems used to operate and secure YugAI digital services.

04

How We Use Information

Subject to the applicable service and legal basis, information may be used to provide and manage registrations, accounts, applications, transactions, orders, customer support, communications, verification, security, fraud/risk controls, reporting, compliance and service improvement.

Before publication: map each stated purpose to the actual system/process owner and remove generic purposes that are not operational.

05

Consent & Lawful Processing

Where consent is the appropriate basis, YugAI should provide clear information about the purpose of processing and record the relevant consent. Privacy consent, terms acceptance, cookie preferences and optional marketing consent should be managed distinctly where applicable.

Unbundled Consent Principle:Optional marketing consent should not be bundled with mandatory service acceptance where separate consent is appropriate.
06

KYC, Financial & Transaction Data

Certain YugAI journeys may require KYC, payment, banking, wallet, order, invoice, receipt or transaction-related information. Such data should be collected and processed only to the extent necessary for the applicable service, verification, settlement, accounting, support, legal or regulatory requirement.

Before publication: confirm which financial/KYC data YugAI stores directly versus which data is processed by banks, NBFCs, insurers, payment gateways or other regulated providers.

07

Sharing with Providers, Partners & Regulated Entities

YugAI may need to share relevant information with authorized service providers, YugAI partners, banks, NBFCs, insurers, payment or technology providers, professional service providers, government/regulatory authorities or other entities where necessary for the requested service, legal obligation, security, dispute handling or authorized business operation.

Information should be shared on a need-to-know and purpose-limited basis, subject to applicable contractual, security and legal controls.

08

Data Retention

Personal data should be retained only for as long as required for the relevant service, business, contractual, accounting, security, dispute, audit, legal or regulatory purpose, after which it should be securely deleted, anonymized or otherwise handled in accordance with approved retention rules.

Before publication: insert approved retention periods or a legally reviewed retention methodology. Do not publish invented timelines.

09

Data Security

YugAI’s security architecture is intended to use layered safeguards such as identity and access controls, secure sessions, authentication controls, role/permission management, login and device monitoring, activity logging and security controls appropriate to the relevant system.

Operational Disclaimer: No digital system can be described as risk-free. Final public wording should reflect the controls actually implemented in production.
10

Cookies & Similar Technologies

The YugAI website may use essential cookies and, where enabled, analytics, preference or similar technologies. Non-essential technologies should be governed by the applicable cookie preference and consent approach.

View Official Cookie Policy & Storage Preferences →
11

International / Cross-Border Data Processing

If YugAI or an approved service provider processes or stores personal data outside India, such processing should occur only where permitted and in accordance with applicable legal, contractual and security requirements.

Before publication: confirm actual hosting, cloud, processor and cross-border arrangements. If no cross-border processing occurs, revise this section accordingly.

12

Your Data Rights

Subject to applicable law and the nature of the processing, individuals may have rights relating to access, correction, updating, erasure, consent withdrawal and grievance redressal. Some rights may be limited where retention or processing is required by law, contract, security or regulatory obligations.

Detailed request procedures should be maintained on the Grievance Redressal & Data Rights page.See Redressal →
13

Children’s Personal Data

Where a YugAI service is intended for or may involve children, the relevant service must apply the specific consent, verification and protection requirements required by applicable law and the service design.

Before publication: confirm whether any YugAI service is directed to children and finalize the eligibility/guardian-consent position.

14

Changes to this Privacy Policy

YugAI may update this Privacy Policy to reflect changes in services, technology, operations or legal requirements. The current version should display its effective date and last-updated date. Material changes should be communicated through an appropriate channel where required.

15

Contact & Grievance

Privacy questions, data-rights requests and grievances should be routed through the approved YugAI grievance mechanism.

Required Before Public Launch

Insert the verified Grievance Officer / privacy contact name or designation, approved email/contact channel, address if legally required, and escalation procedure.

Corporate Address for Legal Inquiries:

Yugai Solution Private Limited
Milkat No.3155/3, Manohar Heights, Ground Floor, Pune–Nashik Highway, Ale, Tal. Junnar, Dist. Pune – 412411, Maharashtra, India

YugAI
Powering India’s Digital Enterprise
© 2026 Yugai Solution Private Limited. All rights reserved.