Objective
This public policy describes how the Company and its authorised service providers store, retain, restrict, archive and securely destroy customer data. The detailed internal retention schedule and legal-hold procedure remain controlled documents.
Core rules
- collect only data necessary for a lawful, disclosed purpose;
- store digital-lending data in India and control any permitted temporary processing outside India in accordance with RBI directions;
- apply role-based access, logging, encryption or equivalent controls, segregation and periodic access review;
- retain records only for an approved business / legal period, subject to legal holds;
- ensure LSPs store only permitted minimum data required for contracted functions;
- do not collect / store biometric data unless expressly permitted by applicable statutory directions;
- delete, anonymise or render data irretrievable when the approved period expires.
Public retention schedule
| Record category | Typical trigger | Retention period | Disposal method |
|---|---|---|---|
| KYC / AML and identity records | End of relationship / transaction | [INSERT PERIOD REQUIRED BY LAW] | Secure deletion / approved archive |
| Loan and repayment records | Closure / write-off / settlement | [INSERT PERIOD] | Secure deletion / anonymisation |
| Unsuccessful applications | Decision / withdrawal | [INSERT PERIOD] | Secure deletion |
| Consent and privacy records | Withdrawal / end of purpose | [INSERT PERIOD] | Audit archive then deletion |
| Call recordings and complaints | Closure of interaction / complaint | [INSERT PERIOD] | Secure deletion |
| Security and access logs | Log creation | [INSERT PERIOD] | Automated deletion |
| Backups | Backup creation | [INSERT CYCLE / PERIOD] | Cryptographic / secure expiry |
LSPs and processors
Contracts will define permitted data, location, access, retention, breach reporting, audit, return / deletion and subcontracting. On termination or completion, the provider will return or delete data except where retention is lawfully required and approved. The Company may verify deletion through certification, audit or technical evidence.
Data-principal request and legal hold
Requests for erasure will be assessed against statutory retention, outstanding obligations, fraud / security needs and legal claims. A legal hold suspends routine deletion for relevant records until released by Legal / Compliance. The requester will receive an appropriate response through [INSERT PRIVACY GRIEVANCE CHANNEL].
Incident response
Suspected loss, unauthorised access, disclosure or alteration must be reported immediately to [INSERT INCIDENT EMAIL / PHONE]. The Company will contain, investigate, document and remediate the incident and make notifications to affected persons and authorities where applicable.
RBI Digital Lending Directions, 2025 data collection / storage / privacy provisions; DPDP Act and applicable rules; RBI KYC record-retention directions; applicable cyber-incident reporting requirements.