WhatsApp chat
Skip to main content

Privacy Policy

Effective date: 29-Sep-2026

1 Who we are and what this Policy covers

LEI International Private Limited, trading as TNV-LEI, is a Local Operating Unit accredited by the Global Legal Entity Identifier Foundation (GLEIF) with LOU prefix 9269. Our registered office is TNV House, B-1/19/69, Sector-K, Aliganj, Lucknow 226024, Uttar Pradesh, India.

This Privacy Policy explains how we collect, use, share, protect and retain personal data when we issue, renew, update and transfer Legal Entity Identifiers (LEIs), handle data challenges, run our website and customer portal, and deal with enquiries. It applies to applicants, authorized representatives, account users, challengers, visitors to www.tnvlei.com and users of our portal at app.tnvlei.com.

This Policy is the privacy notice referred to in Section 11.7 of our General Terms and Conditions for LEI Services published at www.tnvlei.com/terms. For customers of TNV-LEI, if this Policy and the General Terms and Conditions differ, the General Terms and Conditions prevail. Nothing in either reduces your rights under applicable law.

2 Laws we follow

We process personal data under applicable data-protection law, including the Digital Personal Data Protection Act, 2023 (India) and its rules to the extent in force, and the EU General Data Protection Regulation (GDPR), the UK GDPR and Data Protection Act 2018, and the Swiss Federal Act on Data Protection where they apply. We also follow the data-protection safeguards in Chapter XV and Appendix 11 of our Master Agreement with GLEIF. Those safeguards do not replace mandatory law.

3 Our role

We decide why and how personal data is processed for our LEI services, website and portal, and are responsible for that processing as data fiduciary or controller. GLEIF, other LOUs and competent authorities that receive data from us are responsible for their own processing. Some of our service providers, such as hosting and email providers, process data only on our instructions. Others, such as payment gateways and banks, are responsible in their own right for the processing they carry out to provide their service, under their own privacy notices and the rules that apply to them.

4 Definitions

  • Personal data: information about an identified or identifiable individual, such as a name, email address or mobile number.
  • Data principal or data subject: the individual the personal data is about.
  • LE-RD: Legal Entity Reference Data, the reference data linked to an LEI under the GLEIF Common Data File formats, including entity, registration and relationship data.
  • Processing: any operation on personal data, including collection, storage, use, disclosure and deletion.

5 Data we collect

We collect the data needed for the service requested:

  • Legal entity data: legal name, registration authority and number, legal and headquarters addresses, legal form, incorporation details and statutory identifiers such as CIN or PAN where relevant.
  • Relationship data: direct and ultimate parent information, or the reason it is not reported.
  • Supporting documents: certificates of incorporation, registry extracts, board resolutions, authorization letters and powers of attorney.
  • Contact and account data of individuals acting for the legal entity: name, designation, email address, mobile number, login details and records of acceptances and authorizations.
  • Payment data: amount, invoice details, gateway reference and transaction status, and, where a refund cannot go back to the original payment method, the bank account details you give us to receive it.

Card and bank credentials used to pay are entered on the payment gateway's pages and are not stored by us.

  • Challenge data: the challenger's name, email address, the data challenged and the evidence supplied.
  • Communications: emails, support requests and our replies.
  • Technical data: IP address, browser and device information, and log records of access to our website and portal.

6 How we collect data

We collect data through application forms on www.tnvlei.com, document uploads in the customer portal, email and support requests, and data challenges. We also verify legal entity data against public registration authorities and other official sources, and receive data from GLEIF and other LOUs when an LEI is transferred to or from us.

7 Why we use data

We use data only for:

  • issuing, renewing, updating and transferring LEIs, and verifying the data and the authority of the person applying;
  • publishing LEIs and the required LE-RD in the Global LEI System;
  • handling data challenges and meeting GLEIF quality and reporting requirements;
  • billing, invoicing, accounting and audit;
  • customer communication and support, including answering enquiries from prospective customers;
  • running, securing and improving our website and portal, including analytics as described in our Cookies Policy;
  • keeping our systems secure and preventing fraud or misuse; and
  • meeting our legal obligations and our obligations under the GLEIF Master Agreement.

We do not sell personal data or use it for unsolicited marketing.

8 Legal basis

We rely on the basis that fits each purpose, the person concerned and the law that applies:

  • performance of a contract, where you are yourself the contracting party, for example a sole proprietor applying for an LEI in your own name, and steps taken at your request before the contract;
  • our legitimate interests, where the GDPR or UK GDPR applies, in entering into and performing our contract with the legal entity you represent, verifying that you are authorized to act for it, keeping the records our GLEIF Master Agreement requires, preventing fraud and protecting our systems. A contract with a legal entity is not itself the basis for processing the personal data of its representatives, signatories and contacts; for that data we rely on these interests, balanced against your rights;
  • the legitimate uses recognized by the Digital Personal Data Protection Act, 2023, where it applies, such as data you voluntarily provide for the purpose of an application or a challenge, and compliance with law;
  • compliance with legal obligations, such as tax, accounting and lawful requests from authorities; and
  • consent, where the law requires it. Consent is asked for separately and for a specific purpose.

Accepting our terms or acknowledging this Policy is not consent to all processing.

For applicants and their representatives, providing the legal entity, relationship, supporting-document and contact data listed in Section 5 is a contractual and GLEIF requirement; without it we cannot issue or maintain an LEI. Challengers must give an email address so that we can handle the challenge. We do not make decisions based solely on automated processing that produce legal effects for you.

9 Publication of LEI data

LEIs and the required LE-RD are published in the Global LEI System and made freely available for reuse by anyone under the CC0 1.0 licence, through GLEIF and our website. Supporting documents, private contact details and payment records are not published. Where a required public data field contains personal data, for example the name of a sole proprietor, we publish it only as the LEI rules require and handle it under applicable law.

10 Who we share data with

We share data only where needed:

  • GLEIF, which receives LEI data and records we must make available under the Master Agreement;
  • other LOUs, when an LEI is transferred to or from us or for continuity arrangements approved by GLEIF;
  • auditors authorized by GLEIF or by law;
  • the legal entity concerned by a data challenge, as described in our Challenge Policy (the challenger's name and contact details are not passed on unless the challenger agrees);
  • payment gateways, to process payments;
  • IT, hosting, email and other service providers bound by confidentiality, security and data-protection terms; and
  • courts, regulators and other authorities where the law requires.

11 International transfers

Recipients such as GLEIF, other LOUs and some service providers may be outside your country. Before transferring personal data across borders, we identify the lawful transfer mechanism and safeguards required for that data and destination, such as adequacy decisions or standard contractual clauses, and apply them.

12 Security

We protect data with technical and organizational measures that fit the risk, including encryption in transit (TLS), role-based access control and authentication, backups, audit trails and system logs, and oversight of our service providers. If a personal data breach occurs, we notify the affected individuals and the competent authorities as applicable law requires.

13 How long we keep data

LOU-Records, the LEI records, supporting evidence, history and related correspondence we must keep under Chapter IV.B of our GLEIF Master Agreement, are kept for the period in Section 11.5 of the General Terms and Conditions, applied to each record: at least ten years after the most recent update to that record, throughout the term of our Master Agreement with GLEIF and for five years after it ends, whichever is longer. Where the law requires longer, we keep them longer.

Correspondence that forms part of an LOU-Record, for example support or challenge correspondence about an application, a data update, a transfer or a challenge, follows the same rule. Other personal data, such as general enquiries and website logs, is kept only for as long as its purpose requires and any applicable legal retention period. After that, it is securely deleted or anonymized.

14 Your rights

Subject to applicable law, you may ask us to:

  • give you access to your personal data and information about how it is processed;
  • correct or complete inaccurate personal data;
  • delete personal data;
  • restrict or object to processing;
  • provide your data in a portable format; and
  • nominate another person to exercise your rights if you die or become unable to do so, where the law provides for this.

Where processing relies on consent, you may withdraw it at any time. Withdrawal does not affect processing already carried out lawfully. After withdrawal we continue to process the data only where another lawful basis applies to it, as described in Section 8.

We assess every request under the law that applies to you and to the record concerned. Published LEIs and LE-RD, and the records we must keep under the GLEIF Master Agreement and the law, are generally maintained on those bases rather than on consent, so a withdrawal of consent or a deletion request does not by itself remove them. Where a request cannot be met in full, we explain the lawful restriction and how you can escalate. To correct published LEI data, the legal entity can request an update, or anyone can raise a data challenge under our Challenge Policy at www.tnvlei.com/en/challenge-policy.

15 How to make a request or complaint

Send privacy requests and complaints to our Grievance Officer at grievance@tnvlei.com. You may also write to support@tnvlei.com and we will route your request.

We acknowledge requests within 3 business days (Monday to Friday, excluding public holidays observed by TNV-LEI in Uttar Pradesh, India). We respond within the period the applicable law sets and aim to do so within 30 calendar days of receiving the request. We may ask you to verify your identity first. If we need an extension the law allows, or cannot meet a request, we tell you why within those 30 days.

If you are not satisfied with our response, you may complain to the Data Protection Board of India where the Digital Personal Data Protection Act applies, or, where the GDPR or UK GDPR applies, to your local supervisory authority (in the UK, the Information Commissioner's Office), or, where Swiss law applies, to the Federal Data Protection and Information Commissioner.

Grievance Officer, LEI International Private Limited, TNV House, B-1/19/69, Sector-K, Aliganj, Lucknow 226024, Uttar Pradesh, India. Email: grievance@tnvlei.com

16 Cookies

Our website uses cookies and similar technologies. How we use them and how you can control them is explained in our Cookies Policy at www.tnvlei.com/cookie-policy.

17 Changes to this Policy

We review this Policy at least once a year and when the law or GLEIF requirements change. Changes are published on this page with a new version number and effective date. Where a change materially affects how we use personal data, we also inform customers by email.

Version 2.00 | Publication date: 29-Sep-2026