Policy Center

Consent Management Policy

Allen's Housing and Finance Limited

Effective Date: 01.04.2026 Approved By: Board of Directors Review: Annual or earlier

01 Purpose

The purpose of this Policy is to establish a comprehensive framework for obtaining, recording, managing, reviewing, renewing and withdrawing customer consent for processing personal data by Allen's Housing and Finance Limited ("the Company").

The Policy aims to ensure that:

  • Customer consent is free, specific, informed, unconditional and unambiguous.
  • Personal data is processed only for lawful purposes.
  • Customers retain control over their personal information.

The Company complies with:

  • Digital Personal Data Protection Act, 2023;
  • Applicable DPDP Rules, as notified;
  • RBI Master Directions applicable to NBFCs;
  • KYC/AML Guidelines;
  • Information Technology Act and other applicable laws.

02 Scope

This Policy applies to:

  • Existing customers
  • Prospective customers
  • Guarantors
  • Co-borrowers
  • Employees (where applicable)
  • Vendors processing personal data on behalf of the Company

It covers:

  • Physical applications
  • Website
  • Mobile application
  • Digital lending platforms
  • Loan Service Providers (LSPs)
  • Call Centre
  • Branches
  • Collection Agencies
  • Business Correspondents

03 Objective

The Company shall ensure that personal data is processed:

  • fairly;
  • transparently;
  • lawfully;
  • only for specified purposes;
  • with valid consent wherever legally required.

04 Definitions

Consent

A freely given, specific, informed, unconditional and unambiguous indication by the customer signifying agreement to processing of personal data.

Data Principal

The individual to whom the personal data relates.

Personal Data

Any data about an identifiable individual.

Processing

Collection, storage, recording, organisation, sharing, use, disclosure, deletion or destruction of personal data.

05 Guiding Principles

The Company shall ensure:

  • Transparency
  • Purpose Limitation
  • Data Minimisation
  • Accuracy
  • Security
  • Accountability
  • Customer Control

13 Sharing of Personal Data

Personal data may be shared only with:

  • RBI;
  • Credit Information Companies;
  • Information Utilities;
  • UIDAI (where legally permitted);
  • regulators;
  • auditors;
  • recovery agencies;
  • Loan Service Providers;
  • legal advisors;
  • technology vendors;
  • statutory authorities.

All third parties shall be contractually obligated to maintain confidentiality and implement appropriate security safeguards.

15 Information Security

The Company shall implement:

  • encryption;
  • access controls;
  • audit trails;
  • role-based access;
  • secure backups;
  • incident response procedures;
  • periodic vulnerability assessments.

16 Record Retention

Consent records shall be retained:

  • during the customer relationship; and
  • thereafter for the period prescribed under applicable laws, RBI directions and internal record retention policy.

17 Customer Rights

Customers may:

  • access information regarding processing;
  • correct inaccurate information;
  • withdraw consent;
  • seek grievance redressal;
  • exercise rights available under applicable law.

18 Grievance Redressal

The Company shall designate a Grievance Officer responsible for:

  • consent-related complaints;
  • withdrawal requests;
  • privacy complaints;
  • customer rights requests.

Complaints shall be acknowledged and resolved within timelines prescribed by applicable law.

19 Roles and Responsibilities

Role Responsibilities
Board of Directors Approve the Policy. Review implementation annually.
Compliance Officer Monitor compliance. Conduct periodic reviews.
Business Heads Ensure operational implementation.
IT Department Maintain consent management systems. Ensure security controls.
Internal Audit Verify compliance. Conduct annual audits.

20 Monitoring and Audit

Internal audits shall verify:

  • validity of consent;
  • maintenance of consent logs;
  • consent withdrawal process;
  • third-party compliance;
  • system controls.

Any non-compliance shall be reported to senior management and the Board.

21 Policy Review

This Policy shall be reviewed:

  • annually;
  • upon regulatory changes;
  • upon introduction of new products or digital channels;
  • following material privacy incidents.

22 Exceptions

Any deviation from this Policy shall require approval from the Compliance Officer and, where material, the Board of Directors.

23 Effective Date

This Policy shall come into force upon approval by the Board of Directors and shall remain effective until amended or replaced.