How we handle your data when you become a customer
The page a bank's vendor questionnaire is looking for. This is a summary of our position, not the executed addendum.
Last reviewed 4 August 2026.
Pending legal review. The facts on this page are correct, but the wording has not yet been approved by counsel. Treat it as our stated position rather than as a settled contract.
Why this page exists separately
The privacy notice covers this website: the demo form and analytics. It does not cover what happens once GoDravix is running your loan book, because at that point the relationship inverts. You are the Data Fiduciary and Controller of your borrowers' data. We are the Data Processor, acting only on your instructions.
That distinction is the first thing a procurement reviewer checks, and getting it the wrong way round in a policy document is a common way for a vendor to fail a security review before anyone reads the technical answers.
Our position as processor
- 01We process only on your written instruction
The scope is set in the engagement agreement. We do not use borrower data for any purpose of our own, and we do not use it to train models.
- 02Deployment is single-tenant
Your data sits in its own database instance. Where it sits, managed cloud, your private cloud, on-premise or a government cloud, is agreed per engagement, which is how data residency requirements in India and the GCC get met.
- 03Access is least-privilege and logged
Support access to a production deployment is granted for a named person and a stated reason. The product's own audit trail is append-only, so administrative action inside the application is recorded and cannot be edited away.
- 04Sub-processors are named before they are used
We will not introduce a new sub-processor into a live deployment without telling you first.
- 05Breach notification
We notify you without undue delay so that you can meet your own 72-hour obligations. The exact window is set in the agreement.
- 06Deletion or return at the end
On termination, data is returned in an agreed format or destroyed, at your choice, and we confirm it in writing.
What we do not have
Consistent with the security page: we do not hold SOC 2, and DPDP alignment has not been formally assessed by an external auditor. DigiWagon Technologies Pvt. Ltd. holds ISO 9001 and ISO 27001, and we send both certificates with their scope statements on request.
We would rather you learn that here than three weeks into a procurement cycle.
Getting the executed document
This page is a summary. For a signable Data Processing Addendum, a completed vendor security questionnaire, or our sub-processor list, email hello@godravix.com and tell us which framework you are assessing against.