PRIVACY POLICY

This Privacy Policy ("Privacy Policy") has been prepared by FDPL Finance Private Limited (“FFPL”, “We”, “our”, “us”), a private limited company incorporated in India, having its registered office at Plot 20 Flat-1 Ground Floor, Ajit CHSL Evershine Nagar Link Road, Malad West Dely, Mumbai, Malad West, Maharashtra, India, 400064. FFPL is a Non-Banking Financial Company (“NBFC”) - Investment and Credit Company (ICC) - registered with the Reserve Bank of India ("RBI").

FFPL provides the user (“You”, “Your” or “User”) accessing this website (“Website”) or our digital lending application (“DLA”), operated by our lending service providers (“LSP”) for availing the loan products offered by FFPL (collectively, “Platform”). The purpose of this Privacy Policy is to give You information on how FFPL collects, stores, uses, discloses, transfers and processes Your personal information when You use our Platform in order to avail our lending services (“Services”).

You are advised to read this Privacy Policy along with the Terms and Conditions at https://fdplfinance.com/policies and other information on the Platform (“Terms”). Users please take note that any statements made on FFPL’s Platform shall not be construed as an offer or promises for grant of any financial services or credit facilities to You.

This Privacy Policy has been prepared in compliance with:

(a) Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;

(b) Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;

(c) Guidelines on Digital Lending issued by the RBI, 2022;

(d) other applicable acts, regulations and rules which requires the publishing of a privacy policy for handling of or dealing in personal information including sensitive personal data or information and all applicable laws, regulations, guidelines provided by applicable regulatory authorities including but not limited to the RBI.

1. USE OF OUR PLATFORM OR SERVICES

This Privacy Policy is incorporated into and at all times is subject to and is to be read in conjunction with the Terms.

You hereby expressly consent to provide below mentioned information to Us for the purpose of providing the Services to You. If You disagree with any of the terms mentioned herein, please do not proceed with the usage of the Services.

For the Users consenting to continue accessing the Platform and availing the Services, this Privacy Policy explains our policies and practices regarding the collection, usage, and disclosure of Your information.

2. COLLECTION OF INFORMATION

Information We collect from You:

i. ‘User Personal Information’: The data points We collect from You for providing the Services include, inter alia, Your full name, email id, PAN, address, mobile number, postal code, gender, date of birth.

How We use this information: We use this data for identifying You, preventing unauthorised access and providing the Services to uniquely identify, register and enable You to use the Platform We also use this information for the purpose of underwriting You in order to determine your eligibility as part of our offer of credit facilities and loan products to you.

ii. ‘Economic Profile Information’: In order to provide the Services, We may require certain economic profile information such as age, occupation details, bank details, salary statements, .

How We use this information:We use this information to assess Your creditworthiness and eligibility for the loan products and credit facilities offered to You.

iii. ‘Social Account Information’:We may provide You with the option to register using social accounts (Google or Facebook) to access the Platform shall collect only such registered email id and user public profile information like name, email depending on the account used by You to log-in to the Platform during registration/ sign in process for the Services.

How We use this information:We may collect and store email id and name associated with that account for the purpose of verification and to pre-populate relevant fields in the course of Platform interface.

a) ‘SMS Information’:We do not collect, read or store personal SMSs, account details, OTP etc. from Your Inbox. We may only collect, store and monitor the SMS sent by 6 - digit alphanumeric senders. With Your permission, We collect, transmit and store transactional SMS data from Your phone on our secured server to verify and analyze Your financial position, to determine Your cash flow, credits, income, and spending pattern.

How We use this information: We use this data to provide You with updates or confirmation of any actions taken during the term of Services.

iv. ‘Device Information’:We additionally collect certain device information provided herein for our Services. Information the Platform collects, and its usage, depends on how You manage Your privacy controls on Your device. When You access or install the Platform, We store the information We collect with unique identifiers tied to the device You are using. Additionally, We also collect Your Log information (via the domain server through which the User accesses the App Search queries, IP address, crashes, date etc) for the purpose of improvising the Platform functionality. In addition to the above, We also track and collect the data related to the performance of the Platform and other diagnostic data for identifying and resolving any technical glitches that may be identified from such data and also for improving the overall functionality of the Platform.

How We use the information: We collect information about Your device to provide automatic updates and additional security so that Your account on the Platform is not used in other people’s devices. In addition, the information provides us valuable feedback on Your identity as a device holder as well as Your device behavior, thereby allowing us to improve our products interaction, quality of Services and provide an enhanced customized user experience to You. We further collect other identifiable information such as Your transactions history on the Platform when You set up a free account with Us.

v. ‘Installed Application Data’:We collect and transmit a list of specific installed applications’ metadata information which includes the application name, package name, installed time, updated time, version name and version code of each installed application on Your device. This data may be collected even when the application is closed or not in use.

How We use this information: We use this information to provide You with various customized offers for Services.

vi. ‘Location, Camera, Microphone Access’:We collect Your device location and request camera and microphone access for undertaking know Your customer (KYC) on you as part of providing the Services in accordance with applicable laws.

How We use this information: We collect Your device location information as part of the Know Your Customer (KYC) and onboarding process for the Services as required under applicable laws. We may request camera access to scan and capture the required KYC documents in accordance with applicable laws. We require microphone permissions to enable a two-way communication between our authorised agents and You for the purpose of performing and completing Your video KYC. Your audio shall be recorded for regulatory purposes.

vii. ‘Information We collect about You from third parties’:For making the Services available to You, We may collect credit information in accordance with applicable laws, from certain third parties such as credit bureaus or credit rating companies, account aggregators, financial institutions from time to time during the loan journey. In order to provide credit products to You, We may receive certain information pertaining to document verification, repayment status etc. from certain third parties including UIDAI, Digilocker, NSDL or other PAN databases, credit bureaus, payment gateway providers. We may further collect Your bank account numbers or UPI payment information for collection and repayment of loans.

How We use this information:We shall collect and use this information on a need basis for the provision of Services and for performing due diligence and verification of Your loan application.

viii. ‘Information You give us about you in due course of using our Services’:You are required to submit data to enable our Services. We use this data to create Your profile and provide You with the best available services. We shall collect the following information from You:

(a) Data provided by You by filling in forms on the Platform.

(b) Data provided by corresponding with us (for example, by e-mail or chat)

(c) Data and information You provide when You register to use the Platform, subscribe to any of our Services, search for a Service, and when You report a problem with our Platform, our Services, or any of our Sites.

(d) Data including Your name, address, gender, date of birth, address, e-mail address, phone number, for Your account registration purpose.

(e) PAN, Aadhaar details, financial information such as profession/employer name, monthly salary, bank account no., bank statements, credit information, copies of identification documents for the onboarding of Your application to avail the Services. During the course of collection of Your Aadhar details, Your Aadhar number is duly masked in compliance with the applicable laws.

(f) Data generated by Your usage of our Platform. This data helps us create Your profiles, complete mandatory KYC to offer You the Services, unlock and approve loans and provide You with customized support in case of issues. Wherever possible, We indicate the mandatory and the optional fields. You always have the option to not provide any information by choosing not to use a particular service or feature on the Platform.

ix. ‘Information We collect from our DLA in due course of You availing our Services through DLA’: We collect the following data from You and use it to provide You with the available Services with Your prior and explicit consent.

(a) Personal information: Personal details such as Your name, email address, postal address, phone number, date of birth, details of PAN and Aadhaar, for Know Your Customer (KYC) purposes such as for identifying You, preventing unauthorized access and enable provision of Services to You.

(b) Other files and documents: Depending on the nature of the loan application made by You, We collect additional documents such as bank statements, as may be required for provision of the Services.

(c) Financial information:Certain economic profile or financial information including information such as Your age, occupation details, bank details, salary statements, to assess Your creditworthiness and eligibility for the products offered to You.

(d) Device or other IDs:Your device details, as it provides us valuable feedback on Your identity as a device holder as well as Your device behaviour, thereby allowing us to improve interaction, quality of services and provide an enhanced customized offers for the Services. We may also collect other identifiable information including information such as Your IP address, MAC address, transactions history on the DLA when You set up your account.

(e) LocationYour device location is accessed while providing the Services and to provide serviceability of loan application, reduce risks associated with application and also provide customized offers. We do not access your location data on a continuous basis.

3. STORAGE OF INFORMATION

We store Your information in the servers located within India.

We ensure that no biometric data belonging to You shall be collected by our DLA or stored by our LSP through DLAs. In case, if any of our representatives ask for the same from You, We request You to kindly refrain from doing the same and address this concern to our Grievance Officer (the details of the same have been provided below in Clause 12).

We further ensure that our LSP complies with all mandatory technology standards, requirements on cybersecurity guidelines stipulated by RBI and other regulators /agencies, or as may be specified from time to time, for undertaking digital lending Services.

We retain any data or information provided by You for the period mandated under applicable law. Our data retention policy is restricted to our provision of Services. You can request deletion of Your information from us at any stage. Our data retention and deletion policies are in consonance with applicable laws including relevant guidelines of the RBI.

In the event of a data breach, We act swiftly to contain and investigate the incident. We report incidents to CERT-IN within 6 (six) hours of discovery and notify regulatory bodies, impacted customers, and other relevant parties as required. Corrective actions are taken to strengthen security, and We provide support to affected customers as necessary.

4. USE OF INFORMATION COLLECTED BY FFPL

The information collected from You will be used by FFPL for the following purposes

i. To provide Services You have requested;

ii. To establish identity, conduct KYC and verify the same in compliance with the applicable laws;

iii. To resolve disputes and help investigate violations of our Terms or to defend against legal claims;

iv. To disclose the information under special circumstances such as compliance with the applicable local law, court summons, court orders, requests/order from legal authorities or law enforcement agencies requiring such disclosure;

v. To assess Your creditworthiness for providing the Services;

vi. To get in touch with You (either directly or through our partners, agents, or LSPs) when necessary and contact You by email, SMS, letter, WhatsApp, telephone or in any other way about our products and Services, including for any transaction, promotion activity, marketing and/or commercial communications in relation thereto;

vii. To identify, prevent, detect or tackle fraud, money laundering, terrorism and other crimes;

viii. To identify, develop or improve products, that may be of interest to You;

ix. To perform other administrative and operational purposes including the testing of systems; x. To recover any payments You owe to us or to our partners;

xi. To undertake filing of records with the relevant government / Statutory authorities in compliance with the applicable laws;

xii. Comply with our regulatory and legal obligations;

xiii. To maintain records under applicable law or a may apply to pursuant to agreements executed by FFPL;

xiv. To carry out, monitor and analyse our business, carry out audits, market research, business, and statistical analysis and also direct our efforts for product improvement; and

xv. To design and offer customized products and services. We collect all data and other necessary information under this Privacy Policy or otherwise on a need basis required for the above intended purposes in compliance with applicable laws.

5. DISCLOSURE OF INFORMATION

We will share Your information that We collect (except for any device information) only in such manner as described below and limited to the extent required for providing the Services (including through partners of FFPL):

i. We disclose and share Your information with our LSPs, partner banks, data processors, financial institutions, credit bureaus and other third-party partners (such as Direct Sales Agents (‘DSA’) and Debt Recovery Agents (‘DRAs’)) for facilitation and recoverIy pertaining to loan or facility or line of credit or purchase of a product.

ii. To enable our third-party partners to contact You or to respond to Your queries / comments, for promotional offers or to resolve service issues to serve You better.

iii. We will disclose the data or information provided with other technology partners to track how You interact with the Platform on our behalf.

iv. We and our affiliates may share Your information with other business entity should We (or our assets) merge with, or be acquired by that business entity, or re-organization, amalgamation, restricting of business for continuity of business. Should such transaction occur than any business entity receiving any such information from us shall be bound by this Privacy Policy with respect to Your information.

v. We may share Your personal information upon receipt of notice/communication/ order, as a part of our legal obligations and as per applicable laws with the government /quasi government authorities, judicial / quasi-judicial authorities.

vi. By using our Services, You hereby provide Your consent to disclose Your personal information for the above-mentioned purposes. Any disclosure to third parties is subject to the following:

a) If We are under a duty to disclose or share Your personal data in order to comply with any legal or regulatory obligation or request, We shall not seek Your explicit consent however We shall reasonably endeavor to notify the same to You accordingly as the case may be;

b) We shall take Your express consent in the event We share Your personal data with third parties;

c) We shall share Your information with third-party only on a need basis and only for the purpose stated hereunder, as per the applicable laws.

d) We shall additionally seek express consent through a specific consent for at appropriate stages of data collection, if required under applicable laws.

e) Usage of Your information by such third parties is subject to their privacy policies. We share information to the extent required. We also suggest You go through the privacy policies of such third parties. The list of our lending service providers and digital lending applications of our lending service providers (as amended from time to time) are accessible on our Website https://fdplfinance.com/policies.

5. INFORMATION SECURITY

FFPL intends to protect Your information and to maintain its accuracy as confirmed by You. We implement reasonable physical, administrative and technical safeguards to help us protect Your information from unauthorized access, use and disclosure. For example, We encrypt all information when We transmit the data in digital form. We also require that our registered third-party service providers protect such information from unauthorized access, use and disclosure.

FFPL has adequate security measures in place to protect the loss, misuse and alteration of information under control. We endeavor to safeguard and ensure the security of the information provided by You. We use Secure Sockets Layers (SSL) based encryption, for the transmission of the information, which is currently the required level of encryption in India as per applicable laws.

We blend security at multiple steps within our products with state of the art technology to ensure our systems maintain strong security measures and the overall data and privacy security design allow us to defend our systems ranging from low hanging issue up to sophisticated attacks. We aim to protect from unauthorized access, alteration, disclosure or destruction of information We hold, including:

i. Encryption of data to keep Your data private while in transit;

ii. Security feature like an OTP verification to help You protect Your account;

iii. Review our process of collection, storage, and processing practices, including physical security measures, to prevent unauthorized access to our systems;

iv. Restricted access to personal information to our staff, representatives, contractors, and agents who need that information in order to process it. Anyone with this access is subject to strict contractual confidentiality obligations and suitable disciplinary action taken, in case if they fail to meet these obligations;

v. Compliance & cooperation with regulations and applicable laws;

vi. Periodic review of this Privacy Policy and make sure that We process Your information in ways that comply with it.

vii. Non-disclosure of Aadhaar number in any manner. We comply with legal frameworks relating to the transfer of data as mentioned and required under the Information Technology Act, 2000, rules and the amendments made thereunder.

viii. On receipt of formal/ written complaints, We respond by contacting the person who made the complaint. We work with the appropriate regulatory authorities, including local data protection authorities, to resolve any complaints regarding the transfer of Your data that We cannot resolve with You directly.

7. CHANGES IN PRIVACY POLICY

Our Privacy Policy might change from time to time, and FFPL will provide notice of it on Your email address linked to Your Platform account or can be seen by You in our Platform. We encourage You to periodically review the Platform for the latest information on our privacy practices. Users are bound by any changes to the Privacy Policy hosted / made available on the Platform.

8. COOKIES

The Platform uses temporary cookies to store certain data that is used by us for maintenance of the Platform and its features as well as for research and development. We do not store personal/identity information in the cookies.

The cookies shall not provide access to data in Your device such as email addresses or any other data that can be traced to You personally. The data collected by way of cookies will allow the Platform to provide more enhanced and personal features, enabling delivery of more User-friendly services.

Most devices allow You to configure settings to notify You when a cookie is received or to block cookies altogether. However, disabling cookies may restrict the functionality and features available on the Platform or limit access to certain Services. Additionally, some pages on the Platform may include cookies or similar technologies implemented by third parties. Please note that We do not control the use of cookies by these third parties.

9. THIRD PARTY SDKS AND OTHER SITES

The Platform has a link to registered third party software development kits (“SDKs”), Application Programming Interface (“API”) integrations, redirections which collects data on our behalf and data is stored to a secured server. We ensure that our third-party service providers take extensive security measures in order to protect Your personal information against loss, misuse or alteration of the data as required under the applicable laws.

However, We are not responsible for the privacy practices or the content of those linked websites. With this Privacy Policy, We are only addressing the disclosure and use of data collected by Us. Their data collection practices, and their policies might be different from this Privacy Policy and We do not have control over any of their policies neither do We have any liability in this regard.

Our third-party service providers employ separation of environment and segregation of duties and have strict role-based access control on a documented, authorized, need-to-use / know basis. The stored data is protected and stored by application-level encryption. They enforce key management services to limit access to data.

Furthermore, our registered third-party service providers provide hosting security – they use industry leading anti-virus, anti-malware, intrusion prevention and detection systems, file integrity monitoring, and application control solutions.

We don't allow unauthorized access to Your non-public personal contacts or financial transaction SMS data by any third party in relation to Services other than our authorized partners for the Services.

10. YOUR RIGHTS

Modifying or rectifying Your information: You are responsible for providing us with accurate and complete personal data. In the event of any personal information provided by You is inaccurate, incomplete or outdated then You shall have the right to provide Us with the accurate, complete and up to date data and have us rectify such data at our end immediately.

We urge You to ensure that You always provide us with accurate and correct information/data to ensure Your use of our Services is uninterrupted. In case of modification of personal information, You will be required to furnish supporting documents relating to change in personal information for the purpose of verification by FFPL.

Your Privacy Controls:You have certain choices regarding the information We collect and how it is used:

i. Your device may have controls that determine what information We collect. For example, You can modify permissions on Your android/iOS device or browser to remove any permissions that may have been given. However, FFPL does not provide a guarantee of Services if any such controls are exercised / access is denied.

ii. You can also request to remove content from our servers in accordance with sub-clause below

iii. Withdrawal/Denial of consent: You acknowledge that We have duly collected the information with Your consent and You have the option to not to provide such information, or deny consent for use of specific information, restrict disclosure by us to any third parties, deny retention by us of any of Your information, or revoke the consent already given for any of the above, and if required, make the /our DLAs delete/forget any such information. However, any withdrawal of such personal information will not be permitted in case any Service availed by You is active and such information is necessary to be retained by us or DLA/LSP/third party partners until the continuation of Services, or until such duration as stipulated under any applicable laws, whichever is later. Where consent has been withdrawn by you, We do not guarantee and cannot be liable for providing such Service. For exercising your right to withdraw/deny consent as per this clause, please contact us at [email protected]

You shall have the following rights pertaining to Your information collected by us:

i. Deny Consent: You shall have the right to deny consent for use of specific data, restrict disclosure of your data to third parties, revoke consent already granted to collect personal data, opt for preferences as to data retention, and if required, make the Platform delete/ forget the data. However, any such denial will not prejudice our right to retain any data in relation to the loans or credit facilities availed by You. Further, in case of a denial of consent, the Platform does not provide a guarantee or will not be liable towards the continued facilitation of the Services if any such controls are exercised.

ii. Withdraw Consent:You may withdraw Your consent to contact You, for the continued collection, use or disclosure of Your information, at any time, or request for deletion of Your login account to the Platform by raising a request on the Platform or by mailing us at [----]. However, We do not provide guarantee of continued provision of Services if any such controls are exercised / access is denied. Further, in the event the request for withdrawal is made while any credit facility or loan taken by you is outstanding, We shall have the right to continue processing Your information till such credit facility has been repaid in full, along with any interest and dues payable and/or for such period as may be allowed under applicable law. However, We shall not retain Your data and information if it is no longer required by us and there is no legal requirement to retain the same, and such data will be destroyed/purged in line with our internal policies. Do note that multiple legal bases may exist in parallel, and We may still have to retain certain data and information at any time to comply with applicable laws. Also, the information may still be used for execution of any outstanding or termination activity of any Services.

iii. Report an issue:You have the right to report any security breach / incident to the Grievance Redressal Officer (GRO) of FFPL (details mentioned hereinbelow). You are entitled / shall be entitled to prevent unauthorised usage of Your information by our personnel/staff / representative / agents by informing us immediately / within 10 days of being informed of the proposed use, that You do not wish to disclose such information. You can also exercise the right at any time by contacting us at [email protected].

iv. Information/data deletion may not be implemented for ongoing Services including loan, insurance policy (if any).

v. Marketing and Communication: The consent for this information can be withdrawn by sending an email to [email protected]

11. PROHIBITED ACTIONS

While visiting or using the Platform, You agree not to, by any means (including hacking, cracking or defacing any portion of the Platform) indulge in illegal or unauthorized activities including the following:

i. Restrict or inhibit any authorized user from using the Platform.

ii. Use the Platform for unlawful purposes.

iii. Harvest or collect information about Platform’s users without their express consent.

iv. "Frame" or "mirror" any part of the Platform without our prior authorization. v. Engage in spamming or flooding.

vi. Transmit any software or other materials that contain any virus, time bomb, or other harmful or disruptive component.

vii. Remove any copyright, trademark or other proprietary rights notices contained in the digital platform.

viii. Use any device, application or process to retrieve, index, "data mine" or in any way reproduce or circumvent the navigational structure or presentation of the digital platform.

ix. Permit or help anyone without access to the digital platform to use the digital platform through Your username and password or otherwise.

12. GRIEVANCE REDRESSAL AND FURTHER INFORMATION

In case You have grievance or relating to collecting receiving, possessing, storing, dealing or handling of Your personal information provided, You may contact our Grievance Officer on the following address or write an email:

Name :

Email Address :

Contact No.:

Address :

Ms. Adv. Varsha Manoharan

[email protected]

+91-9076058709

Corporate Address: Office 01, Technopolis Knowledge Park, Mahakali Caves Road, Andheri East, Mumbai-93