1. INTRODUCTION
We, Respo Financial Capital Private Limited (“Respo” or “we” or “us” or “our”), are a private limited company duly incorporated under the provisions of the Companies Act, 2013, bearing CIN U65990MH2021PTC373655, a Non-Banking Financial Company (“NBFC”) duly registered with the Reserve Bank of India (“RBI”) and a corporate insurance agent registered with the Insurance Regulatory and Development Authority (“IRDAI”) having our registered office address at 2nd Floor, Dyna Business Park, Street No. 1, MIDC, Andheri (East), Mumbai, Maharashtra, India 400093.
This privacy policy (“Policy”) discloses the practices and measures adopted by Respo for accessing, collecting, storing, retrieving, disclosing, transferring, using or otherwise processing Personal Data (defined below) and other information it may receive from customers or any other persons (“you” or “your” or “user”) accessing its website https://respo.co.in/ or any other websites, mobile applications, facilities or communication channels owned or operated by us (collectively, “Platform(s)”) necessary for the purposes ( defined under clause 4 below) of providing its Services (defined below). This Policy also defines the terms of disclosure of information with our sponsors, affiliates, group companies and business partners / associates and such other entities (“Third Parties”, defined below) with whom we share information pursuant to our contractual obligations and / or Applicable Laws (defined below).
This Policy also identifies the rights and options available to you with respect to your Personal Data. Capitalised terms used but not otherwise defined in this Policy will have the meaning as set out in Respo’s Terms and Conditions (accessed at https://respo.co.in/terms-conditions/) (“T&C”).
This Policy is published in accordance with Applicable Laws. You are requested to carefully read this Policy and the T&C before using any of the Platforms, sharing Personal Data or any other information with us or our representatives, and availing of any of our Services. You will be informed at least once every year that any violation of our rules, T&C, Policy, or user agreement may lead to immediate termination of access to our platform or removal of non-compliant content, or both, as applicable.
2. DEFINITIONS
- Applicable Laws means and includes the Information Technology Act, 2000 (“IT Act”), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013 (“CERT-In Rules”) and directions and guidelines issued thereunder, the Digital Personal Data Protection Act, 2023 (“DPDP Act”) as and when enforced, the Prevention of Money Laundering Act, 2002 (“PMLA”) and rules notified thereunder, the Credit Information Companies Act, 2005 (“CIC Act”) and the rules made thereunder, the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 (“Aadhaar Act”), the Banking Regulation Act, 1949, the Reserve Bank of India (Digital Lending) Directions, 2025 dated 8 May 2025 (“Digital Lending Directions”), the Reserve Bank of India (Know Your Customer) (KYC)) Directions, 2016 dated 25 February 2016 (KYC Master Directions”), the Insurance Act, 1938, the Insurance Regulatory and Development Authority of India (Registration of Corporate Agents) Regulations, 2015 dated (“IRDAI Registration of Corporate Agents Regulations”), IRDAI Information and Cyber Security Guidelines, 2023 (“Cyber Security Guidelines”), the Insurance Regulatory and Development Authority of India (Protection of Policyholders’ Interests, Operations and Allied Matters of Insurers) Regulations, 2024 (“IRDAI Policyholders’ Interests Regulations”) and the Insurance Regulatory and Development Authority of India (Maintenance of Information by the Regulated Entities and Sharing of Information by the Authority) Regulations, 2025 (“IRDAI Maintenance of Information Regulations”), each as may be amended from time to time, as well as all other laws, rules and regulations for the time being in force in India or as may be notified to be in force in India;
- CERT-In shall mean the Indian Computer Emergency Response Team;
- Collected Data shall have the same meaning as ascribed to it under Clause 3 below;
- Cookie means a small file placed on your device by our Platform(s) or Third Parties authorised by us to do so in accordance with the terms of this Policy;
- Cyber Incident, Cyber Security Incident and Cyber Security Breaches shall have the same meaning as ascribed to them under the IT Rules, 2013 as may be amended from time to time;
- Data shall have the same meaning as ascribed to it under sub-section (h) of Section 2 of the DPDP Act, as may be amended from time to time;
- Digital Lending Applications / Platforms (DLAs) shall have the same meaning as ascribed to it under sub-clause (iv) of paragraph 4 of the Digital Lending Directions, as may be amended from time to time;
- Know-Your-Customer (KYC) shall have the same meaning as ascribed to it under the KYC Master Directions;
- Legitimate Uses shall have the same meaning as ascribed to it under Section 7 of the DPDP Act, as may be amended from time to time;
- Lending Service Provider (LSP) shall have the same meaning as ascribed to it under sub-clause (v) of paragraph 4 of the Digital Lending Directions, as may be amended from time to time;
- Personal Data means any information that belongs to or relates to a natural person which, either directly or indirectly, in combination with other information available or likely to be available with any Third Parties, is capable of identifying such person.
- Personal Data Breach shall have the same meaning as ascribed to it under sub-section (u) of Section 2 of the DPDP Act, as may be amended from time to time;
- Processing shall have the same meaning as ascribed to it under sub-section (x) of Section 2 of the DPDP Act, as may be amended from time to time;
- Representative means the personnel employed or otherwise engaged by Respo for the purpose of carrying out their business;
- Service(s) means any or all services provided by Respo, including provision of loans and credit facilities as well as activities undertaken as insurance corporate agent; and
- Third Parties means and includes our sponsors, affiliates, group companies and business partners, associates, agents, contractors, service providers, vendors, and statutory bodies, to whom we disclose your Collected Data, whom we have engaged or authorised to access your Collected Data, or from whom we receive information, as the case may be, under our contractual obligations and/or Applicable Laws.
3. INFORMATION COLLECTED BY US
We may access, collect, store, use or otherwise process the following Data from you (“Collected Data”) which may include Personal Data for the Purposes specified below and in clause 4 below:
- Personal Data: We may collect Personal Data such as your name, gender, address including pin code, email address, mobile phone number, nationality, marital status and date of birth for the Purposes as explained under clause 4 below.
- KYC Data: KYC information such as government-issued officially valid documents such as PAN card, voter ID, Goods and Services Tax (“GST”) details, and ration card, voter identification card, Aadhaar card, driver’s licence, Udyam information, etc. and any other document prescribed under Applicable Laws from time to time. This data is collected for the purpose of on-boarding / KYC requirements and are only used on a need to use / know basis. Obtaining one-time access to your device’s camera, microphone, location or any other facility may be necessary for the purposes of fulfilling KYC requirements under Applicable Laws;
- Aadhaar data: We may collect your Aadhaar number for verifying, authenticating and / or updating your Aadhaar number in accordance with the Aadhaar Act solely for the purpose of facilitation of our Services. Collection of your Aadhaar details is not a mandatory requirement for availing our Services unless required under any Applicable Laws. We ensure that your Aadhaar number shall be disclosed only with your consent, and in a manner specified under Applicable Laws.
- App, Device and Usage Data: Your access dates of the Platforms, features or pages viewed, cookie data, log data, crashes and other system activity, IP addresses, hardware models, device IP addresses, operating systems and versions, preferred language, marketing/ communication preferences, unique device identifiers, type of browser, and installed applications may collect and processed for the Purposes listed under clause 4 below and as required for compliance with Applicable Laws. However, in no case shall we access mobile phone resources like file and media, contact list, call logs, telephony functions, etc.
- Transaction Data: Your usage of Services, date and time of provision of the Service, payment method thereof, and transaction history with us may be processed for the Purposes listed under clause 4 below and as required for compliance with Applicable Laws.
- Financial Data: Information relating to your economic profile, including your age, income, occupation, employer, employment details (for instance, whether in service or self-employed), bank account details, payment credentials or payment instrument information, financial statements, income tax returns, lending history, repayments, credit history, credit information report, insurance policies, and expenditure trends may be processed for the Purposes listed under clause 4 below and as required for compliance with Applicable Laws, including for the purposes of assessing your eligibility for our Services.
- Insurance Data: Information such as insurance policy details, medical records, claims history, payment details, proposals, quotations, and any other information required for underwriting, servicing, or settling insurance contracts.
- Information from regulated third-parties: With your express consent, we collect information from credit information companies and Central Registry of Securitisation Asset Reconstruction and Security Interest of India (“CERSAI”) for the Purposes listed under clause 4 below and as required for compliance with Applicable Laws.
- Voluntarily shared Data: We will also process Data that may be shared by you voluntarily and / or Data received from your family members / your employers, shared online, by telephone or via written correspondence, as well as Data received from regulatory authorities or government agencies and their databases. This includes Data that you provide us by filling in forms on the Platform for availing the Services. This includes contact information such as name, email address, mailing address, phone number, financial information, if any, unique identifiers such as username, account number, password and preferences information such as favourites lists and transaction history and any Data provided by you at the time of registration / application for the Services offered by us directly or through Third Parties.
- Biometric Data: No biometric data shall be collected by us or Third Parties, in accordance with the Digital Lending Directions.
- Account Aggregator Data: Information received from account aggregators in encrypted form and the subsequent decrypted output generated by us directly or through any of Third Parties. Such data is strictly confidential and the Third Parties, if any, assisting in processing / decrypting such data do not store such data and are data blind, i.e. have no direct visibility on the data received from account aggregators.
- Marketing related Data: We may collect information such as preferences regarding marketing messages from us and Third Parties, as well as your communication preferences. We may use third-party advertising companies to serve advertisements when you visit the Platform(s). These companies may use information about your usage preferences and about your visits to this and other websites in order to provide advertisements about goods and services of interest to you. In the event you chose to interact with their advertisements and are redirected to their websites, you will be complying with their respective terms and conditions. We will not be responsible for product and services of such websites and is also not responsible for their privacy practices, as we do not own, manage or control such websites.
- Information received from Third Parties: We may also receive information from Third Parties under all Applicable Laws, for the Purposes specified in this clause and clause 4 below. We may require you to share additional information, at a later date for providing customised Services, for referrals, marketing, insurance, monitoring, underwriting, collection and other purposes including to confirm the veracity of the information collected from you. We may process further information relating to you pursuant to any additional features added to the Platforms, after making such amendments to the Policy and obtaining your prior and informed consent thereto.
- Other Data processed as part of providing the Services: Information which may be processed as part of underwriting, debt collection, operations, compliance requirements and user grievance redressal.
Additionally, we may process further information relating to you as may be required for certain Legitimate Uses for the purpose of compliance with Applicable Laws. This includes instances where the processing is for the purpose of ascertaining the financial information and assets and liabilities of any person who has defaulted in payments due on account of a loan obtained from us, subject to such processing being in accordance with Applicable Laws.
This Policy shall be notified to you while you apply for any of the Services or when we initiate processing of any of your Personal Data, along with appropriate requisite consent requests for collection of your Personal Data in relation to the Services.
You understand that you have explicitly consented to voluntarily sharing such information with us as specified in this clause. You are required to comply with Applicable Laws while providing us with your Personal Data and other information. We request that any change to your Personal Data be communicated to us at the earliest and within a reasonable time, for provision of Services and to comply with Applicable Laws.
4. PURPOSES OF COLLECTION
We may access, collect, store, retrieve, disclose, transfer, use or otherwise process the Collected Data detailed in clause 3 above as necessary for the performance of our obligations and for the following specified purposes (“Purposes”):
- Onboarding and administration: Creating and updating your user account and profile, onboarding you as a user, verifying and authenticating your identity, verifying and authenticating and authorising your use of our products or Services, facilitating your usage of the Platform(s), administering your account on a continued basis, providing Services which you request or have expressed an interest in, carrying out obligations arising from any contract entered into between you and us, processing and completing your transactions, connecting your with our Third Parties, linking your bank account to your user account for such purposes and otherwise managing our relationship with you;
- Eligibility assessment: Assessing your eligibility for various Services you request, avail or have expressed an interest in, including assessing creditworthiness by way of analysis of the Data provided by you;
- Communications: Informing you about important details regarding the Platforms or any new services or features, change in terms, conditions and policies and/or other relevant information, communicating with you in relation to your use of the Platforms or Third Parties, and addressing your requests, feedback and queries in relation to our Services;
- Advertisements: Advertising of, or relating to, Services offered by us, including providing targeted advertisements to you;
- Personalisation / customisation: Tracking your activities and engagement on our Platforms, personalising and improving your experience in availing our Services, referring Services tailored to you and tailoring any communications made to you in relation to our Services or Platforms;
- Technical functions: Diagnosing technical problems and providing troubleshooting services, performing internal operations and reviews necessary to provide and improve Services and the content and features of our Platform(s) and protecting the integrity of our Platform(s), developing the system or product, carrying out internal risk assessments and analysis, managing cybersecurity risks and improving the performance and user interface/user experience of Platforms;
- Record-keeping and fraud detection: Record-keeping purposes, screening and preventing fraud, illegal activity, harm, financial loss and other legal risks, and to protect our legal rights, security and business continuity; and
- Legitimate Uses: For Legitimate Uses, as may be amended from time to time, including without your prior and informed consent where required to do so to comply with Applicable Laws.
- Assessment of insurance needs and risk evaluation, processing insurance applications and proposals, underwriting and policy issuance, claims processing and settlement.
5. CONSENT
- By having consented to the terms of this Policy, you provide your free, prior, informed and unconditional consent to us, and permit us to utilise the Collected Data for the Purposes as set out in this Policy or with the consent obtained from you. Such consent provided by you will be recorded by us for the purpose of maintaining an audit trail.
- We shall disclose to you the Purpose for which consent is being obtained from you at each stage of interface. You confirm that you have obtained all necessary consent from such third parties for the disclosure and use of their information in accordance with this Privacy Policy.
- We reserve the right to regularly review and amend this Policy to reflect changes to our privacy procedures and practices and Applicable Laws from time to time. While we shall provide express notice to you of any material amendments, we encourage you to periodically review this Policy for the latest information on our privacy procedures and practices. The updated version of this Policy will be effective as soon as they are accessible on our Platform(s) and your continued use and access of our Platform(s) will be considered as your acceptance of this Policy or any updated version thereof.
6. COOKIES AND WEB BEACONS
- We may collect certain Data from your browser / Platforms using small data files using Cookies, deployed by us or by our Third Party partners. We encode our Cookies so that only we can interpret the Data stored in them. You may remove or block this Cookie using your browser settings to disable the feature. We may also collect additional Data in ways not specifically described herein. For example, we may track information related to interactions with you while providing the Services or responses from surveys or other feedback tools. We use this information to continually improve the Services provided to you. This Policy does not cover the use of cookies by Third Parties. We do not have access or control over these cookies.
- Certain web pages of the Platform contain electronic images known as “web beacons” (sometimes called single-pixel gifs) and are used along with Cookies to compile aggregated statistics to analyse how the Platform is used for availing the Services. Web beacons may also be used in some of our emails so as to know which emails and links recipients have opened, allowing it to gauge the effectiveness of its communications and marketing campaigns.
7. DATA SHARING WITH THIRD PARTIES
We do not sell or rent your Personal Data to anyone and will protect and maintain the confidentiality of the same. We may share Collected Data with its group companies in relation to offering of Services to you, or for the Purposes of the engagement subject to Applicable Laws. We shall take your explicit consent before sharing your Personal Data with any Third Party, except for cases where such sharing is required as per statutory or regulatory requirement.
Confidentiality of Collected Data shall be maintained at all times except in the following circumstances:
- We may disclose Collected Data to governmental and other statutory bodies who have appropriate authorisation to access the same for any specific legal purposes.
- We may disclose Collected Data if it is under a duty to do so in order to comply with any legal obligation, or in order to enforce or apply the loan agreement(s) or other documentation(s) agreed by the User as part of availing the Services, or to protect your rights, property or safety of those of other users of the Platform. This includes exchanging information with other companies / agencies that work for fraud prevention and credit reference.
- We may disclose Collected Data with insurance companies to insurers with whom we have valid distribution arrangements for the purpose of risk assessment, policy issuance, and claims processing to reinsurers as part of the insurance process, licensed third-party administrators, claims adjusters and investigators.
- We may disclose Collected Data to our agents under a strict code of confidentiality, where such sharing is required or permitted as per statutory or regulatory requirements.
- We may disclose Collected Data to such third parties to whom it transfers whole or part of its rights and duties under the loan agreement(s) and other documentation(s) entered into with your, such as co-lending partners. In such an event, the said third parties’ use of the information will be subject to such confidentiality obligations as contained in this Policy. You may be subject to the privacy policy of such third party in addition to this Policy if the Services availed by you entails loans sanctioned by us along with the co-lending partner.
- We may disclose Collected Data to any member of its related or group companies including its subsidiaries, its ultimate holding company and its subsidiaries for Data Processing under strict confidentiality measures, as the case may be, subject to Applicable Laws and as required for the purposes of providing the Services.
- In the event that we sell or buy any business or assets, it may disclose the Collected Data to the prospective seller or buyer of such business or assets. User, email and visitor information is generally one of the transferred business assets in these types of transactions. We may also transfer or assign such information in the course of corporate divestitures, mergers or dissolution.
- We may disclose the Collected Data with Third Parties whose details can be accessed https://respo.co.in/others/
- We shall conduct enhanced due diligence of such Third Parties, including LSPs as required under the Digital Lending Directions, regarding their technical capabilities and robustness of their data privacy policies and storage systems, before entering into contracts providing for disclosure of Collected Data. We shall also carry out periodic review of the conduct of such Third Parties on an ongoing basis vis-à-vis the terms of the contract and shall take appropriate action in the event of deviation therefrom.
- You understand that this Policy only addresses the use and disclosure of Collected Information on the Platforms. Other websites / applications that may be accessible through the Platforms may have their own privacy policies and practices. If you access such websites / applications by way of links from any of the Platforms, you are urged to review such websites’ / applications’ privacy policies. We are not responsible for the privacy policies or practices of Third Parties, including those of advertisers who may use cookies, JavaScript, web beacons and other technologies to measure the effectiveness of their advertisements or personalise consent.
- The Collected Data may be transferred to any destination within and / or outside India, to the extent permitted as per Applicable Laws. We will take such steps considered necessary to ensure that the Collected Data is treated securely and in accordance with this Policy.
- Apart from as covered under this Policy, we will not disclose the Collected Data to any Third Party unless required to do so under the Applicable Laws.
- By consenting to this Policy, you explicitly consent to the processing of Collected Data by Third Parties as explained in this clause. You retain the right to withdraw consent for processing of specific information and restrict disclosure to Third Parties including consent previously granted, and to request the erasure of data by our Third Parties. You may exercise such rights by e-mailing us at connect@respo.co.in. You understand that upon withdrawing consent to provide Collected Data necessary to perform any of the Purposes as specified in clause 4 above and otherwise provide you with our Services, you may not be able to access or avail of some or all of our Services or features of our Platforms.
8. RESTRICTIONS ON THE PROCESSING OF YOUR INFORMATION
We will not use Collected Data for any purpose other than as set out in this Policy or as may be required under Applicable Laws.
9. SAFETY, SECURITY AND CONFIDENTIALITY OF COLLECTED DATA
- We value your online privacy and security while you are accessing the Platforms. We make every effort to ensure that the Collected Data relating to you, including information collected during solicitation or subsequently during our activities as a Corporate Insurance Agent, will be maintained with utmost confidentiality, privacy and protection. We shall take all measures to ensure that Collected Data will not be misused or accessed without authorisation.
- All Collected Data will be stored and preserved in a safe and secure manner so as to ensure that there is no tampering, alteration, destruction or anything which endangers the content, utility, authenticity, or accessibility of the Collected Data. We encrypt certain Collected Data using SSL technology to ensure that such Collected Data is safe as it is transmitted to us. We implement appropriate technical and organisational measures and reasonable security safeguards to protect your Collected Data, including your Personal Data, in accordance with Applicable Laws.
- Access to Collected Data is limited to representatives and Third Parties on a need-to-know basis, subject to our instructions and a duty of confidentiality. We will protect your Collected Data against unauthorised use, dissemination or publication in the same manner in which we would protect our confidential information of like nature. We require the Third Parties to whom we disclose your Collected Data, as explained in clause 7 above, to implement similar or higher level of technical and organisational measures and reasonable security safeguards to protect such Collected Data.
- In the event of any unforeseen case of security breach of Collected Data which comes to our knowledge, including Cyber Security Breach and Personal Data Breach, we will take all steps as set out in our internal Information Technology Framework and work expeditiously to recover the data including in cooperation with law enforcement authorities, and will take measures to place preventive controls against potential instances of such breaches. We shall intimate you, concerned regulators and other governmental authorities in accordance with such procedure as provided under Applicable Laws.
- All suspected or reported security breaches will be logged and tracked from initiation of the preliminary analysis to determine whether there was a security breach till completion of necessary actions in relation thereto. As mandated by the IT Act and directions or guidelines stipulated thereunder, we shall report Cyber Incidents to CERT-In within 6 hours of noticing such incidents or being brought to notice about such incidents according to the procedures notified by CERT-In for such reporting. We shall cooperate with CERT-In and all other law enforcement agencies for the purposes of responsive and protective/preventive actions related to Cyber Incidents. We further reserve the right to report incidents to the RBI or IRDAI as may be required under Applicable Laws and regulations.
- Notwithstanding the aforesaid, you understand and accept that no information transmission over the internet can be guaranteed to be completely secure. We cannot absolutely guarantee the security of any information that you transmit to us and you do so at your own risk. We hold no liability or responsibility for security breaches beyond our reasonable control, including unauthorised access to computer data and storage devices, (including access by our personnel and third agents outside the scope of our agreements with them), data pilferage, computer crashes, breach of security and encryption, hacking, poor quality of your internet service, and/or virus attacks.
- We have established and implemented internal policies and procedures to ensure appropriate access controls with respect to Data stored on its servers. It ensures that Data stored is appropriately controlled and restricted.
- We ensure that Third Parties do not store Personal Data of users except some basic minimal data (viz., name, address, contact details of the user, etc.) that may be required to carry out their operations.
- We have implemented clear policy guidelines regarding the storage of user data including the type of data that can be stored, the length of time for which data can be stored, restrictions on the use of data, data destruction protocol, standards for handling security breach, etc. The same has been disclosed to Third Parties and made publicly available on our Platform at all times.
- We ensure that no biometric data, obtained with respect to Services, is stored / collected in the systems associated with our Third Parties, unless allowed under Applicable Laws.
- We use commercially reasonable safeguards to preserve the integrity and security of the users’ Data against loss, theft, unauthorised access, disclosure, reproduction, use or amendment.
- The Data that is collected from the users may be transferred to, and stored at, a destination inside India. By submitting information on the Platform in relation to the Services, the users agree to this transfer, storing and / or processing.
- In using the Platform in relation to the Services, the users accept the inherent security implications of data transmission over the internet. Therefore, the use of the Platform will be at the own risk of the users.
- We will take such steps as is considered reasonably necessary to ensure that the users’ Data is treated securely and in accordance with the Policy.
10. YOUR PRIVACY RIGHTS
The rights available to you, in accordance with Applicable Laws, are as follows:
- Right to access information: The right to access and review Collected Data relating to you, through your login credentials, including the right to seek a summary of such Collected Data, including the activities performed thereto, underlying purposes thereof, and identities of Third Parties to whom such Personal Data has been disclosed;
- Right to correction: The right to correct Collected Data relating to you, including to correct and update inaccurate information and complete incomplete information;
- Right to erasure of Collected Data: The right to seek erasure of Collected Data relating to you, including by way of withdrawing consent, unless the retention of such data is required as outlined in clause 11 below. You may exercise this right by e-mailing us at connect@respo.co.in.
- Right to grievance redressal: The right to communicate grievances pertaining to our processing of Collected Data relating to you to our Grievance Redressal Officer as identified below in clause 13 below;
- Right to file a complaint: The right to file complaints to the relevant regulatory authorities in connection with our processing of Collected Data relating to you as notified on our Platforms; and
- Right to nominate: The right to nominate any other individual who shall, in the event of your death or incapacity, exercise your rights under this Policy in accordance with Applicable Laws.
Each of these rights may be exercised by you by writing to us (or, as may be relevant, the Grievance Redressal Officer or relevant regulatory authorities). We shall endeavour to cooperate with your exercise of these rights within a reasonable period.
You understand that upon withdrawing consent to provide Personal Data that is necessary to perform any of the Purposes as specified in clause 4 above and provide you with our Services, you may not be able to access or avail of some or all of our Services or features of our Platforms.
You understand that withdrawing consent to our usage of cookies or to receive certain marketing materials pertaining exclusively to new services or upcoming events (including by emailing us your updated preferences at connect@respo.co.in or unsubscribing from the mailing list) will not affect your ability to access or avail of our other Services or features of our Platforms, though it may negatively impact user experience.
11. RETENTION OF COLLECTED DATA
Notwithstanding anything contained in this Policy, unless you request the erasure of any or all of your Collected Data as explained in clause 3 above, including by withdrawing consent, we will continue to retain Collected Data in the following instances:
- As long as necessary to fulfil the specified Purposes for the processing of such information, including as long as any outstanding amount(s) in respect of any loans or credit facilities provided by us and availed by you are due and payable to us;
- As long as we have your prior, informed and express consent to the retention of such information;
- As long as necessary to comply with Applicable Laws, including but not limited to the PMLA, Digital Lending Directions and IRDAI Regulations;
- As long as necessary to enforce/exercise our rights under any agreements between you and us, as well as necessary to enable an authorised Third Party to enforce / exercise their rights under any such agreements between you, us and/or the Third Party; or
- As long as necessary to reach a final settlement/outcome of any disputes between you and us or a third party authorised by us to process your information.
Once any of the aforementioned reasons are not satisfied, requiring us to cease processing, we shall endeavour to, and cause Third Parties accessing your Collected Data through us, to erase Collected Data within a reasonable period. Despite our best attempts at erasure, there might be latency in completely erasing the information from our servers, including certain backed-up versions.
12. YOUR REPRESENTATIONS TO US
- You confirm that by consenting to this Policy, you are providing your free, specific, informed, unconditional and unambiguous consent to the terms contained therein.
- You represent to us that you are above the age of 18 and are in contracting capacity to access our Platform and to share your Personal Data with us.
- You confirm that all information submitted by you is authentic, accurate and consistent. Further, you are not impersonating another person.
- You confirm that in providing information to us, you are compliant with all Applicable Laws and not suppressing any material information.
- You undertake to update us on any changes to the same via email at connect@respo.co.in.
- You represent that in circumstances where you share Personal Data relating to other individuals (such as family members, co-applicants or nominees), you have obtained such individuals’ prior and informed consent for our processing of their Personal Data.
- You shall use the Services and the Platforms for lawful purposes and under no circumstances for any activity which violates or is prohibited under Applicable Laws.
13. GRIEVANCE REDRESSAL MECHANISM
For expressing any concerns, grievances or discrepancies with respect to our processing of your Personal Data, you may contact us at connect@respo.co.in, follow the procedure described at https://respo.co.in/grievance-redressal/ or write to us at the following address:
Principal Officer
Name: Swapnil Kinalekar
Respo Financial Capital Private Limited
2nd Floor, Dyna Business Park, Street No. 1, MIDC, Andheri (East) Mumbai-400093.
Email: nodal@respo.co.in
Contact Number: 022-28256467
14. DISPUTE RESOLUTION
The courts of Mumbai, India shall have exclusive jurisdiction to try any dispute, difference or claim arising out of this Policy under the Applicable Laws in force in India.
15. INCORPORATION OF THIS POLICY TO LOAN DOCUMENTS
This Policy is incorporated to the loan documents and other documentation(s) in relation to the Services availed by the Users.