Privacy Policy
Last updated: June 25, 2026
Les Amis Private Limited, trading as “EximPe” (“Company”, “EximPe”, “we”, “us”, or “our”), is committed to protecting your privacy. References to “you” or “your” mean any merchant, marketplace, front-end payment aggregator, individual, or representative of a business who accesses, registers on, or otherwise interacts with the EximPe Platform, Services, or website, including prospective merchants undergoing onboarding and end customers whose transactions are processed through the Services.
We place great importance on how your information is collected, used, shared, and protected. This Privacy Policy (“Policy”) describes our privacy practices in connection with the website at https://eximpe.com/ (“Website”) and EximPe’s payment aggregator – cross border services (“PA-CB Service”), connected banking / AD-1 Trade Account facilitation services, and referral or technology service provider (“TSP”) services (together, the “Services”).
This Policy is incorporated into, and forms part of, EximPe’s Terms of Use, available at https://eximpe.com/terms-and-conditions. In the event of any conflict between the Terms of Use and this Policy with respect to the handling of personal data, this Policy shall prevail.
1. Acceptance of this Policy
By visiting the Website, registering as a merchant, or otherwise availing the Services, you acknowledge that you have read and understood this Policy and agree to be bound by it, as may be amended from time to time. Your continued access to or use of the Website or Services following any update constitutes your acceptance of the revised Policy. If you do not agree with this Policy, please do not access or use the Website or Services.
By using the Website or Services, you consent to providing EximPe with your personal information for the purposes set out in this Policy, and you acknowledge that such collection, storage, and processing is lawful, necessary, and permissible on the basis described herein.
2. Our Services
EximPe operates a cross-border payment aggregation and connected banking facilitation platform. The Services covered by this Policy include:
- Payment Aggregator – Cross Border (PA-CB) Service: EximPe is RBI-licensed to operate as a Payment Aggregator – Cross Border, enabling eligible merchants to receive inward cross-border remittances and settle international transactions from overseas customers.
- Connected Banking / AD-1 Trade Account Facilitation: EximPe acts solely as a Technology Service Provider (TSP), offering a digital interface through which importers and exporters may apply for and access AD-1 Trade Accounts maintained by EximPe’s AD-1 licensed banking partner(s), including digital submission of EDPMS/IDPMS trade documentation and generation of e-FIRA.
- Referral Service: Where a prospective merchant cannot be onboarded under the PA-CB Service, EximPe may, as a TSP and lead-referral intermediary, introduce such merchant to one or more partner service providers, who independently assess and service the merchant under their own terms.
This Policy does not cover, and EximPe is not responsible for:
- personal information collected, used, or processed by merchants who act as independent data controllers in respect of their own end customers, which is governed by the merchant’s own privacy policy;
- personal information handled by AD-1 banking partners or referral partners once your information has been transmitted to them, which is governed by their respective privacy policies;
- personal information and privacy practices of third-party websites or services linked from the Website; and
- personal information relating to job applicants, employees, and other EximPe personnel.
3. Information We Collect
“Personal Information” means information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, to you. It does not include aggregated or de-identified information. Depending on how you interact with us, we may collect:
- Contact and identity information: name, email address, phone number, designation, and business name.
- Business and onboarding information: entity registration details, business category, beneficial ownership information, and bank account details.
- KYC/KYB documentation: PAN, passport, driving licence, voter ID, certificate of incorporation, GST registration, and other officially valid documents (“OVDs”) required for onboarding under RBI guidelines. Where Aadhaar is voluntarily provided as an OVD, we may collect the Aadhaar number, Virtual ID, e-Aadhaar/XML, masked Aadhaar, demographic information, and related authentication details, in accordance with Section 13 below.
- Transaction data: payment instrument details, last four digits of card numbers, transaction amount, currency, transaction ID, customer ID, settlement and reconciliation records.
- Trade and connected banking data: invoices, shipping bills, foreign inward remittance details, EDPMS/IDPMS-related documentation, and indicative FX rate communications, where you apply for an AD-1 Trade Account.
- Financial information: bank account number, IFSC/SWIFT codes, and payment instrument details, encrypted in accordance with PCI DSS standards.
- Technical and usage information: IP address, browser type, operating system, device identifiers, geo-location data, referring/exit URLs, and cookie data.
- Communications: correspondence, support tickets, chat transcripts, and call recordings arising from your interactions with EximPe.
4. How We Use Your Information
We use Personal Information for the following purposes:
- to assess merchant eligibility and conduct onboarding, KYC, and KYB verification under the PA-CB Service;
- to process inward cross-border remittances, authorise and settle transactions, and generate transaction reports and settlement reconciliation statements;
- to facilitate your application for, and access to, AD-1 Trade Accounts, including transmitting your instructions and trade documentation to our AD-1 banking partner(s) and generating e-FIRA upon receipt of funds;
- to refer or introduce you to partner service providers under the Referral Service, where applicable;
- to perform sanctions screening, anti-money laundering checks, fraud detection, and risk assessment in connection with cross-border transactions;
- to communicate with you regarding your account, transactions, onboarding status, and service-related updates, including via email, SMS, push notification, and in-app messaging;
- to comply with applicable law, including RBI directions, FEMA, PMLA, and reporting obligations to regulators, law enforcement, or government authorities;
- to maintain platform security, prevent unauthorised access, and investigate suspected violations of our Terms of Use;
- to improve our products, conduct analytics, and generate aggregated or anonymised reports; and
- to establish, exercise, or defend legal claims, and to respond to audits, investors, and professional advisers as required.
5. Disclosure of Personal Information
EximPe does not sell your Personal Information. We may disclose Personal Information in the following circumstances:
- Banking and payment partners: with acquiring banks, card networks, AD-1 licensed banking partners, and escrow banks, to the extent necessary to process, settle, or reconcile cross-border transactions or facilitate your AD-1 Trade Account application. Once shared with an AD-1 banking partner, your information is also governed by that partner’s own privacy policy and KYC/KYB process, over which EximPe has no control.
- Referral partners: where you are referred under the Referral Service, we share your contact and business information with the identified partner solely to enable their independent eligibility assessment. EximPe does not control, and is not responsible for, that partner’s subsequent use of your information.
- Regulators and law enforcement: with the Reserve Bank of India, financial intelligence and sanctions authorities, courts, or law enforcement agencies, where required by law or regulatory direction.
- Service providers: with vendors who perform services on our behalf, such as cloud hosting, identity verification, sanctions screening, and customer support, under contractual confidentiality and security obligations.
- Corporate transactions: in connection with a merger, acquisition, restructuring, or sale of business assets, subject to the acquiring entity’s adherence to this Policy in respect of Personal Information already collected.
- Affiliates: with Les Amis Private Limited group entities for purposes consistent with this Policy.
- With your consent: for any other purpose disclosed to you at the time of collection.
As cross-border payments inherently involve the transfer of data outside India to overseas acquiring banks, card networks, and correspondent banks, your Personal Information may be processed in jurisdictions other than your own. We take reasonable steps to ensure such transfers comply with applicable law and are subject to appropriate safeguards.
6. Legal Basis and Purposes for Processing
The table below summarises the primary purposes for which we process Personal Information, the categories of data involved, our lawful basis, and the categories of recipients.
| Purpose / Activity | Type of Data | Lawful Basis | Disclosed To |
|---|---|---|---|
| Merchant onboarding and KYC/KYB under the PA-CB Service | Identity, business, financial and KYC documentation (including Aadhaar, where voluntarily provided) | Performance of contract; compliance with RBI/PMLA obligations | RBI, AD-1 banks, acquiring banks, sanctions/AML screening providers |
| Processing inward cross-border remittances and settlement (PA-CB) | Transaction data, payment instrument details, customer identifiers | Performance of contract; legitimate interests | Acquiring banks, card networks, AD-1 banks, escrow banks |
| Facilitating AD-1 Trade Account applications (Connected Banking / TSP) | Contact details, trade documents, EDPMS/IDPMS data, FX instructions | Performance of contract; consent | AD-1 licensed banking partner(s) |
| Referral to partner service providers (Referral / TSP Service) | Contact and business details, eligibility-assessment information | Consent; legitimate interests | Identified referral partner(s) |
| Fraud prevention, sanctions screening and risk management | Device and IP identifiers, geo-location, transaction behaviour, watchlist screening results | Legitimate interests; legal obligation | Regulators, law enforcement, sanctions/AML screening vendors |
| Generating e-FIRA, invoices, statements and reconciliation records | Transaction data, contact information, unique identifiers | Performance of contract; legitimate interests | Not shared with third parties beyond the relevant banking partner |
Note: the lawful basis described above may vary depending on the jurisdiction applicable to a given transaction. Where local law differs, we will process Personal Information in accordance with that law.
7. Cookies and Tracking Technologies
We use cookies and similar technologies on the Website to recognise returning visitors, analyse page flow, measure the effectiveness of communications, and enhance platform security. Most cookies are session-based and are deleted once your session ends. You may disable cookies through your browser settings; doing so may affect certain features of the Website. We do not control cookies placed by third parties whose content may appear on the Website.
8. Your Rights
Subject to applicable law and the jurisdiction in which you are located, you may have the following rights in relation to your Personal Information:
- Right to Information: to be informed about the collection and use of your Personal Information.
- Right of Access: to request a summary of the Personal Information we hold and process about you, and the entities with whom it has been shared.
- Right to Correction and Erasure: to request correction, completion, or deletion of your Personal Information, subject to our regulatory record-keeping obligations.
- Right to Restrict Processing: to request that we restrict processing where data is inaccurate, unlawfully processed, or where you have objected to processing.
- Right to Object or Withdraw Consent: to object to or withdraw consent for certain processing, where consent is the basis of processing.
- Right to Data Portability: to request that data you have provided be transmitted to another service provider, where technically feasible.
- Right to Grievance Redressal: to raise a grievance regarding the processing of your Personal Information, as set out in Section 15.
- Right to Nominate: to nominate an individual who may exercise these rights on your behalf in the event of your death or incapacity.
Please note that where Personal Information has been shared with and is independently held by an AD-1 banking partner or referral partner, requests relating to that information should also be directed to the relevant partner, as EximPe does not control data held in their systems.
To exercise any of these rights, please write to us at [email protected].
9. Retention of Personal Information
We retain Personal Information for as long as necessary to fulfil the purposes described in this Policy, including to comply with RBI record-retention requirements for payment aggregators (currently a minimum retention period as prescribed under applicable RBI directions), to establish or defend legal claims, and to maintain transaction and audit records. Once no legitimate business or legal need to retain Personal Information remains, we will securely delete or anonymise it.
10. Children’s Personal Information
The Website and Services are intended for use by persons who are at least 18 years of age and legally competent to contract. We do not knowingly collect Personal Information from anyone under 18. If we become aware that we have inadvertently collected Personal Information from a minor, we will take steps to delete such information promptly. Parents or guardians who believe a minor has provided us with Personal Information may contact us at [email protected].
11. Third-Party Websites and Partners
The Website may contain links to third-party websites, including those of our AD-1 banking partners and referral partners. This Policy does not apply to, and EximPe is not responsible for, the privacy practices of such third parties. We encourage you to review the privacy policies of any third-party service before sharing your Personal Information with them.
12. Security of Personal Information
We implement reasonable technical and organisational measures, including encryption, access controls, and tokenisation of sensitive payment data, to protect Personal Information from unauthorised access, loss, misuse, alteration, or destruction, consistent with PCI DSS and applicable RBI data security requirements. No method of transmission or storage is completely secure; while we strive to protect your Personal Information, we cannot guarantee absolute security. If you become aware of any actual or suspected breach involving your information, please contact us immediately at [email protected].
13. Aadhaar-Related Consent
Where you are located in India and voluntarily opt to use Aadhaar as an Officially Valid Document for KYC purposes, you acknowledge that such submission is entirely voluntary and that alternative OVDs (such as passport, voter ID, or driving licence) are available to you. Where Aadhaar is submitted:
- we will collect and use your Aadhaar-related information solely for identity verification, KYC and periodic KYC under the PML Act, 2002, e-KYC, or offline verification, as permitted by law;
- where Aadhaar Number is used for offline verification, the first eight digits will be redacted, and only the last four digits will be retained;
- your consent for Aadhaar-based verification will be securely stored for evidentiary and regulatory purposes; and
- Aadhaar-related information will be retained only for as long as necessary to fulfil the purpose for which it was collected, and will thereafter be securely deleted, in accordance with the Aadhaar Act, 2016, and UIDAI guidelines.
14. Updates to this Policy
We may revise this Policy from time to time to reflect changes in our practices, services, or applicable law. Material changes will be notified by posting the revised Policy on the Website, and where appropriate, via email to registered merchants. The “Last updated” date at the top of this Policy indicates when it was last revised. Your continued use of the Website or Services after such posting constitutes acceptance of the revised Policy.
15. Grievance Redressal
If you have any complaints, concerns, or questions regarding the processing of your Personal Information, please contact our Grievance Officer / Data Protection contact at:
Grievance Officer / Privacy Contact
Les Amis Private Limited (trading as EximPe)
WeWork Express Towers, Nariman Point, Marine Drive, Mumbai, Maharashtra, India 400021
Email: [email protected]
Support: [email protected]
Complaints relating to customer transactions and disputes arising from merchant services are additionally addressed under our Grievance Redressal Policy, available at https://eximpe.com/redressal-policy.
16. Contact Us
If you have any questions about this Policy or our data practices, please write to us at [email protected], or at our registered office: WeWork Express Towers, Nariman Point, Marine Drive, Mumbai, Maharashtra, India 400021.