Privacy Policy
We respect your privacy. This policy explains what personal data we collect, why we collect it, how we use it, and your rights over it.
Our commitment: We do not sell, rent, or trade your personal information to any third party. We collect only what is necessary to provide our services, and we protect it with industry-standard security measures.
1 Who We Are
BankingKnowledge.ai ("we", "us", "our") operates the website at https://bankingknowledge.ai and related subdomains. We are an independent banking education platform providing financial knowledge content, tools, and APIs for users primarily in India and globally.
For the purposes of this Privacy Policy, we are the data controller in respect of personal data you provide when using our Platform. Any questions about how we process your data should be directed to us at hello@bankingknowledge.ai.
2 Data We Collect
We collect information in the following categories:
2.1 Information You Provide Directly
2.2 Information Collected Automatically
- Log data: IP address, browser type, pages visited, referring URL, timestamps — collected via server logs
- Device information: Screen resolution, operating system, browser version
- Usage data: Features used, content accessed, session duration
- Cookies and similar technologies: See Section 4
- API request data: Caller IP, IBAN queried (partially masked), response codes, timestamps — for API clients only
2.3 Information We Do Not Collect
We do not collect or store:
- Full IBAN numbers entered into our free validator (only the first 6 characters are logged)
- Payment card details (we do not process payments directly)
- Government-issued identification numbers
- Financial account credentials of any kind
- Location data beyond what is implied by your IP address
3 How We Use Your Data
We process your personal data on the following legal bases and for the following purposes:
We will not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
4 Cookies & Tracking Technologies
We use the following types of cookies on the Platform:
You can control cookies through your browser settings. Note that disabling strictly necessary cookies will impair Platform functionality. To opt out of Google personalised advertising, visit Google Ads Settings.
5 Data Sharing & Third Parties
We may share your data with:
- Hosting and infrastructure providers: Our web hosting provider stores your data on secure servers. They act as data processors under our instructions.
- Google (AdSense / Analytics): Google may collect data through advertising cookies and analytics tools as described in Section 4. Subject to Google's Privacy Policy.
- Email service providers: Used to send transactional emails (account verification, API approval notifications, content email delivery). These providers process email addresses under data processing agreements.
- Law enforcement / legal authorities: We may disclose your data if required by applicable law, court order, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business transfers: If BankingKnowledge.ai is acquired, merged, or its assets are transferred, your data may be transferred as part of that transaction. We will notify you via the Platform or email before such transfer.
All third parties we work with are contractually obligated to process your data only as instructed and to maintain appropriate security measures.
6 Data Retention
After these periods, data is securely deleted or anonymised. We may retain data longer where required by law.
7 Security
We implement industry-standard security measures to protect your personal data:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS
- Password hashing: User passwords are hashed using bcrypt (cost factor 12) — we never store or transmit plain-text passwords
- API credentials: Client secrets are bcrypt-hashed; JWT tokens are signed with HMAC-SHA256
- CSRF protection: All forms are protected with CSRF tokens to prevent cross-site request forgery
- SQL injection prevention: All database queries use parameterised statements (PDO prepared statements)
- Session security: Sessions use httponly cookies with strict mode enabled
- IP whitelisting: API access can be restricted to approved IP addresses
- Access controls: Admin functions are protected by role-based access control
Despite our best efforts, no method of transmission over the Internet is 100% secure. We cannot guarantee the absolute security of your data. If you become aware of any security vulnerability, please report it responsibly to hello@bankingknowledge.ai.
8 Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
Right to Access
Request a copy of the personal data we hold about you.
Right to Rectification
Request correction of inaccurate or incomplete personal data.
Right to Erasure
Request deletion of your personal data ("right to be forgotten") where no legal basis exists for retention.
Right to Restrict
Request that we restrict processing of your data in certain circumstances.
Right to Portability
Receive your personal data in a structured, machine-readable format to transfer to another service.
Right to Object
Object to processing of your data based on legitimate interests, including for direct marketing.
Withdraw Consent
Withdraw consent at any time where processing is based on consent (e.g. newsletter). Withdrawal does not affect prior processing.
Right to Complain
Lodge a complaint with your local data protection authority if you believe we have mishandled your data.
To exercise any of these rights, please contact us at hello@bankingknowledge.ai. We will respond within 30 days. We may need to verify your identity before fulfilling requests.
9 Children's Privacy
Our Platform is not directed at individuals under the age of 18. We do not knowingly collect personal data from children under 18. If you believe we have inadvertently collected data from a minor, please contact us immediately at hello@bankingknowledge.ai and we will delete the data promptly.
10 Third-Party Links
Our Platform may contain links to third-party websites (for example, links to RBI guidelines, NPCI resources, or bank websites). We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policy of every website you visit.
External links on our Platform are provided for informational convenience only and do not constitute an endorsement by BankingKnowledge.ai of any products, services, or content on those sites.
11 Advertising — Google AdSense
BankingKnowledge.ai displays advertisements served by Google AdSense. Google uses cookies and similar technologies to serve ads based on prior visits to our website and other websites on the internet. Google's collection and use of data is subject to Google's Privacy Policy.
You can opt out of personalised advertising by visiting Google Ads Settings or by using the NAI opt-out tool.
BankingKnowledge.ai does not receive or have access to any personally identifiable information from Google's advertising systems.
12 API Client Data
If you have registered as an API client to use the IBAN Validation API, we additionally process:
- API request logs: We log each API call including the caller IP address, a partially masked IBAN (first 6 characters only), the validation result, and response time. Full IBANs are never logged.
- Usage statistics: Monthly request counts per client for rate limiting and plan compliance.
- JWT tokens: A hash of each issued JWT token is stored for revocation support. The token itself is not stored.
- Client credentials: Your
client_secretis stored as a bcrypt hash. The plain-text secret is shown only once at registration and is never recoverable from our systems.
API request log data is retained for 12 months and then deleted. This data may be used to investigate security incidents, resolve disputes, and enforce our API Terms.
13 International Data Transfers
Your data is primarily stored and processed on servers located in India. If any data is transferred internationally (for example, through Google's infrastructure), we ensure appropriate safeguards are in place, including:
- Standard contractual clauses approved by relevant data protection authorities
- Use of service providers certified under recognised privacy frameworks
- Ensuring recipients provide equivalent data protection standards
14 Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make material changes, we will:
- Update the "Last updated" date at the top of this page
- Notify registered users by email for significant changes affecting their rights
- Display a notice on the Platform
We encourage you to review this Policy periodically. Continued use of the Platform after changes are posted constitutes your acceptance of the updated Policy.
15 Contact Us
For any privacy-related questions, data subject requests, or to report a privacy concern, please contact us:
We aim to respond to all privacy-related enquiries within 30 days of receipt.