Digital Lending – Customer Data Policy

1. Introduction

The Reserve Bank of India (RBI) vide its Reserve Bank of India (Non-Banking Financial Companies – Credit Facilities) Directions, 2025 dated November 28, 2025, as updated from time to time, read with the Digital Personal Data Protection Act, 2023 and rules thereunder, requires non-banking financial companies to adopt guidelines regarding the storage of customer data, including the type of data that can be stored, the length of time for which data can be stored, restrictions on the use of data, data destruction protocol and standards for handling security breaches. Respo Financial Capital Private Limited (Company) is a non-banking financial company that offers unsecured personal loans to its customers/borrowers.

The Board of Directors of the Company (Board) has formulated and approved this policy regarding the handling and storage of customer data.

2. Key Objective

This Digital Lending – Customer Data Policy (Policy) discloses the practices adopted by the Company for storing information it may receive through its mobile applications (collectively referred to as Digital Lending Platforms) or from the lending service provider(s) (LSP(s)) for the purpose of providing loans/credit facilities to customers/borrowers (Services).

3. Information Stored by the Company

The borrowers/customers are required to provide certain information to the LSPs/Digital Lending Platforms, including but not limited to:

• Name, user IDs, signature, email addresses, phone numbers, addresses, Know Your Customer (KYC) / identity documents, and communications.
• Bank account details, financial information, payment credentials, loan details such as loan amount, lending history, repayments, credit history, and income details.
• Any other information as may be required by the Company (collectively referred to as Customer Data) in connection with the Services.

• The Digital Lending Platform/LSP will collect, process, view, and store Customer Data only on a need basis and will retain only the minimum data required for providing the Services and fulfilling its obligations.
• The Company will ensure that Customer Data is stored on a secure server located in India.
• The Company will retain Customer Data for a minimum period of five (5) years from the date of closure of the account or termination of the lending relationship, as required under the Prevention of Money Laundering Act, 2002, RBI KYC Directions, 2025, and other applicable laws. Subject to these mandatory retention requirements, customers or borrowers may request deletion of their personal data in accordance with their rights under the Digital Personal Data Protection Act, 2023.
• The Company will ensure that any collection of data by LSPs, Digital Lending Platforms, or Digital Lending Platforms of LSPs is need-based, supported by the prior and explicit consent of the borrower, and maintains an appropriate audit trail.
• The Company will ensure that no biometric data is collected or stored by the Company or its LSPs unless expressly permitted under applicable statutory guidelines.
• The Company and its LSPs shall maintain a comprehensive Privacy Policy compliant with applicable laws, regulations, and RBI guidelines, which shall be publicly available on their respective websites.
• The Company and its LSPs shall comply with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, as amended from time to time.

4. Restrictions on Use of Customer Data

The Company will not use Customer Data for any purpose other than those set out in the Company’s Privacy Policy https://respo.co.in/privacy-policy/ or for providing the Services.

5. Security

The Company endeavours to safeguard Customer Data by implementing appropriate security measures to protect it against unauthorised access and by following standards prescribed under applicable laws. The Company uses appropriate encryption mechanisms for the transmission of Customer Data.

All Customer Data will be protected and stored in secure conditions to ensure there is no tampering, alteration, destruction, or any activity that may endanger the authenticity, integrity, utility, or accessibility of the data.

If any security breach comes to the Company’s knowledge, it will take all necessary actions in accordance with its Information Technology Framework and applicable laws to prevent misuse of such information. All suspected or reported security breaches or violations will be logged and tracked from preliminary analysis until the completion of corrective actions.

The Company shall not be responsible for any breach of security arising from events beyond its reasonable control, including but not limited to computer hacking, unauthorised access to computer systems or data storage devices, computer crashes, encryption failures, poor internet connectivity, or telephone service interruptions experienced by the user.

6. Policy Review

This Policy shall be reviewed at least annually by the Board and may be amended, modified, or revised from time to time in accordance with applicable laws, regulatory requirements, and business needs. Any amendment, clarification, circular, or direction issued by the RBI or any other applicable regulatory authority shall automatically apply to this Policy and prevail in case of any inconsistency until the Policy is updated accordingly.

Inactive

WHAT WE'RE THINKING
Insights
Valuable insights that empower your decision-making,
Case Studies
Inspiring examples of financial tailored solutions.
Media Mentions
Recognizing our expertise and client success.
Stay ahead in a rapidly changing world

Our monthly insights for strategic business perspectives.

Inactive

FINANCIAL
Investment planning
Tailored investment strategies to help clients grow their wealth.
Retirement planning
Comprehensive plans designed to secure a comfortable future.
Education planning
Guidance on saving and investing for educational expenses.
WEALTH
Portfolio management
Active management to optimize returns while managing risk.
Asset allocation
Maximize growth potential via asset diversification.
Risk management
Managing financial risks with insurance and other measures.
TAX
Tax planning
Optimize tax through services like deductions and strategies.
Estate planning
Effective estate planning for taxes and wealth transfer.
Wealth preservation
Preserve wealth for future while reducing taxes.
FEATURED
Adapting to
the digital era

Inactive

Search