01 Purpose
The purpose of this Policy is to establish a comprehensive framework for obtaining, recording, managing, reviewing, renewing and withdrawing customer consent for processing personal data by Allen's Housing and Finance Limited ("the Company").
The Policy aims to ensure that:
- Customer consent is free, specific, informed, unconditional and unambiguous.
- Personal data is processed only for lawful purposes.
- Customers retain control over their personal information.
The Company complies with:
- Digital Personal Data Protection Act, 2023;
- Applicable DPDP Rules, as notified;
- RBI Master Directions applicable to NBFCs;
- KYC/AML Guidelines;
- Information Technology Act and other applicable laws.
02 Scope
This Policy applies to:
- Existing customers
- Prospective customers
- Guarantors
- Co-borrowers
- Employees (where applicable)
- Vendors processing personal data on behalf of the Company
It covers:
- Physical applications
- Website
- Mobile application
- Digital lending platforms
- Loan Service Providers (LSPs)
- Call Centre
- Branches
- Collection Agencies
- Business Correspondents
03 Objective
The Company shall ensure that personal data is processed:
- fairly;
- transparently;
- lawfully;
- only for specified purposes;
- with valid consent wherever legally required.
04 Definitions
Consent
A freely given, specific, informed, unconditional and unambiguous indication by the customer signifying agreement to processing of personal data.
Data Principal
The individual to whom the personal data relates.
Personal Data
Any data about an identifiable individual.
Processing
Collection, storage, recording, organisation, sharing, use, disclosure, deletion or destruction of personal data.
05 Guiding Principles
The Company shall ensure:
- Transparency
- Purpose Limitation
- Data Minimisation
- Accuracy
- Security
- Accountability
- Customer Control
06 Consent Requirements
Before collecting personal data, the Company shall provide a clear privacy notice including:
- categories of personal data collected;
- purpose of processing;
- legal basis;
- categories of recipients;
- retention period;
- rights available to the customer;
- grievance mechanism;
- contact details of the Grievance Officer/Data Protection Officer (where designated).
Consent shall be:
- obtained before processing;
- recorded electronically or physically;
- capable of being demonstrated during audit;
- linked with date, time and source.
07 Situations Requiring Consent
Consent shall be obtained before:
- loan application processing;
- KYC collection beyond statutory requirements;
- bureau enquiries (where required by law/contract);
- Aadhaar-based authentication wherever legally permissible;
- marketing communications;
- promotional messages;
- cross-selling;
- sharing information with group companies;
- sharing with business partners;
- use of analytics beyond operational necessity;
- biometric processing (where applicable).
08 Consent Not Required
Consent may not be required where processing is necessary:
- under RBI regulations;
- under Income Tax laws;
- under Prevention of Money Laundering Act;
- for fraud prevention;
- pursuant to court or regulatory directions;
- for contractual obligations;
- for any lawful purpose specifically exempted under applicable law.
09 Methods of Obtaining Consent
Consent may be obtained through:
- digital checkbox;
- OTP verification;
- electronic signature;
- Aadhaar e-sign;
- physical signature;
- recorded voice confirmation;
- customer portal;
- mobile application.
Pre-ticked boxes shall not constitute valid consent.
10 Consent Register
The Company shall maintain a centralized Consent Register capturing:
- Customer ID
- Consent ID
- Date and Time
- Purpose
- Collection Channel
- Consent Status
- Version of Privacy Notice
- Withdrawal Date
- Renewal Date (if applicable)
11 Consent Withdrawal
Customers may withdraw consent at any time through:
- branch;
- website;
- mobile application;
- email;
- customer care;
- grievance officer.
Upon withdrawal:
- processing based solely on consent shall cease within a reasonable period, unless otherwise required by law or contract;
- statutory records shall continue to be retained where legally mandated;
- withdrawal shall not affect processing already undertaken lawfully prior to withdrawal.
12 Consent Review
The Company shall periodically review:
- validity of consent;
- continued necessity of processing;
- changes in processing purposes;
- adequacy of notices.
Fresh consent shall be obtained whenever processing purposes materially change.
13 Sharing of Personal Data
Personal data may be shared only with:
- RBI;
- Credit Information Companies;
- Information Utilities;
- UIDAI (where legally permitted);
- regulators;
- auditors;
- recovery agencies;
- Loan Service Providers;
- legal advisors;
- technology vendors;
- statutory authorities.
All third parties shall be contractually obligated to maintain confidentiality and implement appropriate security safeguards.
14 Marketing Consent
Separate consent shall be obtained for:
- SMS
- Tele-calling
- Promotional campaigns
- Cross-selling
Customers shall have an easy opt-out mechanism.
15 Information Security
The Company shall implement:
- encryption;
- access controls;
- audit trails;
- role-based access;
- secure backups;
- incident response procedures;
- periodic vulnerability assessments.
16 Record Retention
Consent records shall be retained:
- during the customer relationship; and
- thereafter for the period prescribed under applicable laws, RBI directions and internal record retention policy.
17 Customer Rights
Customers may:
- access information regarding processing;
- correct inaccurate information;
- withdraw consent;
- seek grievance redressal;
- exercise rights available under applicable law.
18 Grievance Redressal
The Company shall designate a Grievance Officer responsible for:
- consent-related complaints;
- withdrawal requests;
- privacy complaints;
- customer rights requests.
Complaints shall be acknowledged and resolved within timelines prescribed by applicable law.
19 Roles and Responsibilities
| Role | Responsibilities |
|---|---|
| Board of Directors | Approve the Policy. Review implementation annually. |
| Compliance Officer | Monitor compliance. Conduct periodic reviews. |
| Business Heads | Ensure operational implementation. |
| IT Department | Maintain consent management systems. Ensure security controls. |
| Internal Audit | Verify compliance. Conduct annual audits. |
20 Monitoring and Audit
Internal audits shall verify:
- validity of consent;
- maintenance of consent logs;
- consent withdrawal process;
- third-party compliance;
- system controls.
Any non-compliance shall be reported to senior management and the Board.
21 Policy Review
This Policy shall be reviewed:
- annually;
- upon regulatory changes;
- upon introduction of new products or digital channels;
- following material privacy incidents.
22 Exceptions
Any deviation from this Policy shall require approval from the Compliance Officer and, where material, the Board of Directors.
23 Effective Date
This Policy shall come into force upon approval by the Board of Directors and shall remain effective until amended or replaced.