Privacy Policy for CreditX Finkart Technology Pvt. Ltd.:
1. Applicability of Privacy Policy
This section ensures compliance with Indian legal frameworks such as the Information Technology Act, 2000 and associated rules. It clarifies that the Privacy Policy governs all interactions between the user and the Platform. Users are informed that accessing or using the Platform implies consent to the terms of the Privacy Policy. This ensures that users are aware of their rights and obligations.
2. Information We Collect
This section outlines the specific categories of data collected:
2.1 Personal Information
Data such as name, address, phone number, email, PAN, Aadhaar, and financial details are collected for identity verification, credit profiling, and service delivery. These details ensure customized services, like pre-approved loan offers or credit analysis.
2.2 Sensitive Personal Data
Sensitive data includes financial SMS, device metadata, location, and call logs. These are used to analyze user creditworthiness and prevent fraud.
2.3 Non-Personal Information
This includes device information, browsing patterns, and session activity. It helps improve user experience and detect anomalies in usage patterns.
2.4 Cookies and Tracking
Cookies and similar technologies collect non-identifiable user behavior, enabling seamless navigation and personalized recommendations.
3. Purpose of Data Collection
Explains why data is collected:
- Verification: To validate user identity.
- Service Delivery: Facilitating loans, credit checks, and other financial services.
- Risk Mitigation: Detecting and preventing fraudulent activities.
- Customization: Personalizing offers and recommendations based on user activity.
This ensures transparency about the purpose of data collection.
4. How We Use Your Information
Data is used to:
- Enhance loan processing and credit profiling.
- Monitor user behavior for personalized recommendations.
- Analyze patterns for risk detection and fraud prevention.
The focus is on improving operational efficiency while adhering to legal standards.
5. Disclosure of Information
Details scenarios where data may be shared:
- Financial Institutions: User data is shared with banks and NBFCs for credit approvals.
- Technology Partners: For analytics and platform performance enhancements.
- Government Authorities: To comply with legal obligations.
- Service Providers: Operational support like payment processing and KYC.
Users are assured that data shared with third parties is secured by confidentiality agreements.
6. Collection of Financial SMS Data
Explains the importance of financial SMS data:
- Used to identify bank accounts and assess cash flow patterns.
- Enables credit risk profiling.
- Ensures accurate credit assessments for loan approvals.
Personal SMS is explicitly excluded to respect user privacy.
7. Collection of Device Information
Details the types of device metadata collected:
- IMEI and SIM Info: For fraud prevention and device identification.
- Location Data: To verify address and reduce credit risks.
- Call Logs: Aggregated data for additional credit analysis.
This ensures robust risk profiling and enhances data security.
8. Collection of Installed Applications Metadata
This includes metadata of apps installed on the user’s device:
- Purpose: Assess creditworthiness and behavioral patterns.
- Use Case: Helps enrich user profiles for pre-approved loans.
This ensures relevant service recommendations based on user habits.
9. Security of Your Information
Explains robust security measures:
- Encryption: Data is encrypted during transmission and storage.
- Access Control: Role-based access ensures that only authorized personnel handle sensitive data.
- Audits: Regular security checks and compliance with ISO 27001 standards to prevent unauthorized access.
These measures ensure that user data is protected from breaches.
10. Retention of Information
Data is retained only as long as necessary for:
- Providing Services.
- Complying with legal requirements.
- Resolving disputes and enforcing agreements.
Users can request data deletion, subject to applicable laws.
11. User Rights
Users are informed about their rights:
- Access and Review: Users can request a copy of their data.
- Correction: Users can correct inaccurate data.
- Deletion: Users can request data deletion, although this may limit the Services.
- Consent Withdrawal: Users can withdraw consent for data processing, though it may restrict platform usage.
This ensures users retain control over their personal data.
12. Consent
By using the Platform, users consent to:
- Data collection, processing, and sharing as described.
- Receiving communications related to Services, including loan offers.
This ensures transparency in obtaining user consent.
13. Third-Party SDKs
Third-party SDKs are used for:
- Credit risk assessments.
- Performance monitoring.
The policy assures users that third-party data processors follow strict security practices.
14. Changes to This Privacy Policy
This section informs users that:
- The Privacy Policy may be updated periodically.
- Updates take effect upon posting on the Platform.
- Users are encouraged to review the policy regularly.
This keeps users informed about changes in data handling practices.
15. Governing Law
These T&C are governed by and construed in accordance with the laws of Maharashtra, India. Any disputes will be subject to the exclusive jurisdiction of the courts in Mumbai.