Privacy Policy

Finova Capital Private Limited
DATA Privacy POLICY

Privacy Commitment:

Finova Capital Private Limited(the company) recognizes the expectations of its customers with regard to Privacy confidentiality and security of their personal information that resides with the Company. It is the policy of the Company to keep the personal information of customers secure and use the same solely for the activities related to the Company. The Company has adopted the privacy policy aimed at protecting the personal information provided by / disclosed by the customers (the Policy). This Policy governs the way in which the Company collects, uses, discloses, stores, secures and disposes of personal information and sensitive personal data or information.

Definitions:

“Personal information” (PI) means any information that relates to a natural person, which either directly or indirectly, in combination with other information available or likely to be available with the Company, is capable of identifying such person.

“Sensitive personal data or information” (SPDI) of a person means such personal information which consists of information relating to:

password;
financial information such as Bank account or credit card or debit card or other payment instrument details;
physical, physiological and mental health condition;
sexual orientation;
medical records & history;
biometric information;
any detail relating to the above clauses as provided to body corporate for providing ser- vice;
any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise.
Provided that, any information that is freely available or accessible in public domain or furnished under any law for the time being in force shall not be regarded as sensitive personal data or information for the purposes of this policy.

Applicability of the Policy:
This Policy is applicable to the personal information and sensitive personal data or information collected by the company or its affiliates directly from the customer or thro>ugh the Company’s online portals, mobile apps and electronic communications as also any information collected by the Company’s server from the customer’s browser.

Purpose of Collection and Use of Personal Information / Sensitive Personal Data or Information:
The Company collects the PI and SPDI from its customers and uses the same for specific business purposes or for other related purposes designated by the Company or for a lawful purpose to comply with the applicable laws and regulations. The Company shall not divulge any personal information collected from the customer, for cross selling or any other purposes, without the written consent of the customer.

The authenticity of the personal information provided by the customer shall not be the responsibility of the Company.

The Company shall not be responsible for any information that is freely available or accessible in public domain or furnished as per law for the time being in force.

Disclosure of Personal Information

The personal information collected by the Company shall not be disclosed to any other organization except:

where the disclosure has been agreed in a written contract or otherwise between the Company and the customer
where the Company is required to disclose the personal information to an affiliate / third party / service provider on a need-to-know basis, for providing services / related activities, provided that in such case the Company shall inform such affiliate / third party / service provider of the confidential nature of the personal information and shall keep the same standards of infor- mation/ data security as that of the Company.
To statutory and regulatory authorities on their specific request as per rules in force.

Reasonable Security Practices and Procedures

The security of personal information is a priority and is protected by maintaining physical, electronic and procedural safeguards that meet applicable laws. The Company shall take reasonable steps and measures to protect the security of the customer’s personal information from misuse and loss, un- authorized access, modification or disclosure. The Company maintains its security systems to ensure that the personal information of the customer is appropriately protected and follows the extant standard encryption norms followed for the transmission of information. The Company ensures that its employees and affiliates respect the confidentiality of any personal information held by the Company.

Notice of change

The Company may, from time to time, change this Policy.

Cookie policy

The Company’s digital platforms may use various third party analytical tools. These tools may use cookies which are downloaded to the customer’s device when the customer visits a website in order to provide a personalized browsing experience. Cookies are used for other purposes like remembering the customer’s preferences & settings, provide personalized browsing experience and analyze site operations. These cookies collect information about how users use a website. All information collected by third party cookies is aggregated and anonymous. By using the Company’s website, the user agrees that these types of cookies can be placed on his/her device. User is free to disable/delete these cookies by changing his/her device / browser settings. The Company is not responsible for cookies placed in the device of user/s by any other website and information collected thereto.

Use of Data and permissions

COLLECTION OF FINANCIAL SMS INFORMATION

ISFC doesn’t collect, read or store your personal SMS from your inbox. We collect and monitor only financial SMS sent by 6-digit alphanumeric senders from your inbox which helps us in identifying transactions undertaken by you as a user to help us perform a credit risk assessment. This process will enable you to take financial facilities from the regulated financial entities available onthe Platform. This Financial SMS data also includes your historical data.

COLLECTION OF DEVICE LOCATION AND DEVICE INFORMATION

We collect and monitor the information about the location of your device to provide serviceability of your loan application and to reduce risk associated with your loan application. Information the App collects, and its usage, depends on how you manage your privacy controls on your device. We collect information from the device when you download and install the App and explicitly seek permissions from You to get the required information from the device. The information we collect from your device includes the hardware model, build model, storage; unique device identifiers like IMEI, serial number, SSAID; SIM information, MAC address etc. to uniquelyidentify the devices and ensure that no unauthorized device acts on your behalf toprevent frauds.

STORAGE

We require storage permission so that you can then easily upload the correct KYC related documents for faster loan application. CAMERA We require the camera information permission to enable you to click photos of your KYC documents and upload the same on the App during your loan application journey.

COLLECTION OF OTHER NON-PERSONAL INFORMATION

We automatically track certain information about you based upon your behaviour on our Platform. We use this information to improve our services and user experience. We may collect your Internet Protocol (IP) address and etc. We retain this information asnecessary to resolve disputes, provide customer support and troubleshoot problemsas permitted by law.

LINK TO THIRD-PARTY SDK

The App has a link to a registered third-party SDK which collects data on our behalf and data is stored to a secured server to perform a credit risk assessment. We ensure that our third-party service provider takes extensive security measures in order to protect your personal information against loss, misuse or alteration of the data. Our third-party service provider employs separation of environments and segregation of duties and have strict role-based access control on a documented, authorized, need to- use basis. The stored data is protected and stored by application-level encryption. They enforce key management services to limit access to data. Furthermore, our registered third party service provider provides hosting security – they use industry leading anti-virus, anti-malware, intrusion prevention systems, intrusion detection systems, file integrity monitoring, and application control solutions.