PLEASE READ THIS POLICY CAREFULLY BEFORE USING THE APP

The MudraSure App is made available by D R Khanna Financial Services Pvt Ltd (“our”, “us”, “we”, “Company”), having its registered office at Daryaganj Delhi, India. In order to provide you with the Services, process your loan requests, and to ultimately provide a loan to you (and co-applicants, if any) with the Services, process your loan requests, and to ultimately provide a loan to you, D R Khanna Financial Services Pvt Ltd (i.e., the company) need to collect various data and information from you. The manner in which this data and information is collected, retained, shared, stored, and processed by us (i.e., the Company) is addressed in this MudraSure Privacy Policy (“Policy”). We may revise this Policy as well as update the services and the app from time to time, so please keep visiting this page regularly to take notice of any changes we make. If you do not agree with any part of this Policy, please stop using our Services immediately. This Policy, incorporates, and includes our Terms and the Agreement(s) executed by you (and co-applicants, if any) for availing the lending products made available (“User Loan Agreement”). Words and phrases not defined in this policy shall mean the same as provided in the Terms. All references to you (as a user / visitor) shall include references to all co-applicants, if any.

1. CONTACT INFORMATION

Summary: You may reach out to the data grievance officer, Manisha Patil (support@drkfpl.com) confidentially to enquire about the treatment of your data.  We have appointed a data grievance officer. Our data grievance officer is: Manisha Patil, accessible via email at support@drkfpl.com. You can contact the officer confidentially by email to enquire about the treatment of your data by us.

2. WHAT DATA IS COLLECTED?

Summary: We collect certain information provided by you, some of which is sensitive personal information. We have detailed the manner in which this data is collected.  By using the App, you consent to providing us, data in the ways listed below. We collect the data you provide to ensure that we can provide you services in the best manner possible. We use this data to underwrite (i.e., assess the risk it will be taking) any loan it might offer you and to determine the rates and tenure for such loans. The data being asked from you helps us to provide services to you in a robust and user-friendly manner.
 Data you input in the course of signing up and using our Services:-  MudraSure Account Data: We collect the data you provide when you create or update your MudraSure Mobile App account. This includes your name, phone number, email ID, PAN, date of birth, pin code, nature of employment, official employment, email address, name of employer, monthly income, marital status and relationship with the co-applicant (in case the loan is being sought by more than a single applicant). We may require you to share further information on a later date to confirm the veracity of your information or pursuant to any additional features added to the App.  
How we use this data: See, for enabling the App and its services; For loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.  
Financial and KYC Information: We collect the data you provide when you accept the terms of the loan. This includes your photograph, Aadhaar Number, PAN, parents’ names, bank account number, IFSC, proof of address (which can be your electricity bill, rental/lease agreement, gas bill, passport or driver’s license, or voter’s identity card or any other document our App may be able to record).  
Other Data Solicited: You may be required to provide further information for the purposes of processing your loan application. Such additional information may include (without limitation) bank statements, goods and services tax returns, salary and income statements and title documents for the property being financed. You may also be required to provide this information to us via physical documents, e-mail or other digital and offline methods  
How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For assessing the quantum and interest rate of loan to be extended; For Legal Compliance and Requirements.  
Feedback Data and Other Data: This includes the following: If you call our call centres, we may record information provided by you to service you or record the calls for quality and training purposes. Data you input when you participate in our referral programs or use any discount codes offered by us. If you provide any feedback or comments to us on the App. How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For assessing the quantum and interest rate of loan to be extended; For Legal Compliance and Requirements.
Data we collect from your usage of our Services :-  
How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.  

User Personal Information: Our app collects user account data which includes email address, name to log in to the app. This information is required as part of the registration process to access our service and it is also used to auto populate relevant fields in the course of the interface of our app. Our app also collects mobile numbers for verification to check the active SIM status on the device, uniquely identify you and prevent fraud and unauthorized access.  
Phone Book Contacts: When you grant us access to the address book on your mobile device, then we access and store the names and contact information from your address book to facilitate invitations, assess your phone usage and habits, and to facilitate recovery of delayed EMI payments. You will not be able to use the App if you disable this access. As part of the loan journey, we collect all of your phonebook contacts which includes their contact names, phone numbers, account types, favourites (starred) and contact labels to enrich your financial profile. We use this data to determine your social network from your phonebook contacts and identify fraudulent contacts in your network and for enabling recovery of delayed EMI payments. This helps us in detecting fraud loan applications and reducing credit risk.  
How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication. Financial SMS Data: When you grant us access to the SMSs on your mobile device, then we and our collect SMS data stored on your mobile device. You will not be able to use the App if you disable this access. How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication  
App Data: We collect the data about your installed applications, including the applications that you have installed on and from the date you create your MudraSure Account and the manner in which you use them. This also includes having access and permission to send you messages and notifications via your social media and instant messaging applications. You will not be able to use the App if you disable this access.  
How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach.  
Usage data: We collect data about how you interact with our Services. This includes data such as access dates and times, App features or pages viewed, App crashes and other system activity, type of browser, and third-party sites or services used before or in the course of interacting with our Services. How we use this data: See, For Enabling the App and its Services; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.  
Transaction information: We collect transaction information related to the use of our services, including the type of services requested, date and time the service was provided, loan availed, interest payable, EMI selected, and payment method. Additionally, if someone uses your promotion code, we may associate your name with that person and their usage of the App.  
How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For Enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.  
Device data: We collect data about the devices used to access our Services, including the hardware models, device IP address, operating systems and versions, software, preferred languages, unique device identifiers, advertising identifiers, serial numbers, device motion data, and mobile network data. How we use this data: See, For Enabling the App and its Services; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach.  
Storage: This permission is required so that users' documents can be securely downloaded and saved on users' phones and upload the right documents for a faster approval and disbursal of the loan. This helps provide a very smooth and seamless experience while using the app.  
Information we receive from other sources :-   We may also be working closely with third parties (including, for example, credit information bureaus, business partners, technical sub-contractors, analytics providers, search information providers, title deeds, property verification service providers and valuers) and may lawfully receive information about you and your co-applicant from such sources. Such data may be shared internally and combined with data collected on the App.   How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.

3. HOW AND WHY IS THE COLLECTED DATA USED?

Summary: The company collect and use data collected from you to ensure that the Services are as up to date as possible and provided in the most optimal manner to you.

For Enabling the App and its Services:-

We use the data collected to personalize, maintain and improve our Services. This includes using the data to: Create and update the MudraSure Account. Analyse your loan eligibility and estimate your loan terms. Track the disbursement and repayment of the loan. Enable features that allow you to add and remove bank accounts for your loan repayment and disbursements from time to time. Enable features that help you check your loan history, credit scores (as provide on government databases), and other such App features as may be added from time to time. Perform internal operations necessary to provide our Services, including to troubleshoot software bugs and operational problems; to conduct data analysis, testing, and research; and to monitor and analyse usage and activity trends.

For Loan Processing and KYC Authentication:-

We use the data to analyse your creditworthiness, loan eligibility, KYC documents, current employment verification and the terms of your loans. Failing to process such data means that you cannot be provided any loans. You hereby grant us explicit consent to fetch your KYC (Know Your Customer) details from the Central KYC Records Registry using the details provided by you.

For Enabling Customer Support:-

We use the information to provide customer support, including to resolve your concerns from the use of the Services, and train our customer service executives.

For Research and Development -:

We may use the data so collected for research, analysis, and product development to improve the UI/UX experience – all of which will ultimately improve how you experience the App. This also helps us develop automated actions to be triggered in certain events, such as when we need to identify if photographs uploaded are not clear, fraud takes place, IFSC is incorrect etc.

For Enabling Communications Between You and Us

We may add features that allow you to call us (through the App or otherwise), similarly, we may also need to contact you (through the App or any other channels that you give us access to, such as WhatsApp or Facebook).

For Marketing and Outreach

We may use the data we collect to market the App and our Services. This includes sharing your feedback, ratings and screen names for purely promotion and marketing purposes. Such promotion and marketing may be done via hoardings, banners, pamphlets etc.

For Automated Decisions

The App may provide automated features for customer responses, reimbursement tracking, etc. As our App grows, we will keep adding more automated features to the App.

For Legal Compliance and Requirements

We may use the data we collect to investigate or address claims or disputes relating to use of our Services, or as otherwise allowed by applicable law, or as requested by regulators, government entities, and official inquiries.

For Product Innovation

We may use the data we collect to offer new products and services for your use.

4. HOW DO WE SHARE THE COLLECTED INFORMATION?

Summary: Please note that while none of your data is sold, it is shared with third parties like credit bureau, other scoring partners, technical third-party engagements teams etc. This data is shared for processing of information and ensuring that you receive the services.

We are very protective about your data. We may enter into data-sharing agreements or disclose the collected data in order to provide the services and new product offerings to you. We have detailed the manner in which we share the collected data below:

Sharing with third parties:-

salary and income statements, income tax returns, basis which your loan offer is generated.

Service Providers: We work with third party service providers to execute various functionalities of the App and we may share your information with such service providers to help us provide the App. Some of these functionalities may include: Analysing transaction behaviour and cashflows via your SMSs, bank statements, goods and services tax returns, Validating and authenticating the official verification documents provided by you. Validating your preferred bank account, as well as transferring the loan amounts to you. E-signing of the User Loan Agreement or Sanction Letter, populating the User Loan Agreement or the Sanction Letter. The information shared with these service providers is retained for auditing of the agreements. eNACH/ NACH set-up to enable autopay. Analysing customer behaviour and to automate our marketing and outreach efforts. Detection and flagging of fraud. Cloud services. Gathering of additional information regarding your bank account and statement details, in case adequate information has not been provided by you or through the other service providers we work with. For manually collecting any sums owed by you to ours. Validating and authenticating your employment status, employment information and employment duration.

Third Party Services: The App may allow you to connect with other websites, products, or services that we don’t have control over (for example, if we allow you to pay through an external wallet facility then we will have to share your usage information with the facility provider). However, usage of such third-party services is subject to their privacy policies and not within our control. We recommend that you have a look at their privacy policies before agreeing to use their services.

Affiliates and Group Companies: Subject to applicable law, we may share any data we have collected or collect from you with our affiliates and group companies for product research and development, advertising relevant products to you, and to tailor the products for your benefit.

LINK TO THIRD-PARTY SDK

Our application has a link to a registered third-party SDK which collects data on our behalf and data is stored to a secured server to perform a credit risk assessment. We ensure that our third-party service provider(s) take security measures in order to protect your personal information against loss, misuse or alteration of the data. Our third-party service provider(s) employ separation of environments and segregation of duties and has strict role-based access control on a documented, authorized, need-to-use basis. The stored data is protected and stored by application-level encryption. They enforce key management services to limit access to data.

Furthermore, our registered third-party service provider(s) provide hosting security – they use industry-leading anti-virus, anti-malware, intrusion prevention systems, intrusion detection systems, file integrity monitoring, and application control solutions.

Change in Control:

While negotiating or in relation to a change of corporate control such as a restructuring, merger or sale of our assets, we may have to disclose our databases and information we have stored in the course of our operations.

Sharing with law enforcement when needed :-

If any governmental authority or law enforcement officers request or require any information and we think disclosure is required or appropriate in order to comply with laws,regulations,or a legal process.

5. WHAT ARE YOUR RIGHTS REGARDING THE DATA?

It is important for us that you remain in control of your data. Please write to us at support@drkfpl.com if you wish to exercise any of your rights under the Policy. You shall have the following rights:

Right to rectification:-

You have the right to withdraw your consent to this policy by uninstalling the App. However, if you have availed any loans from our, we shall have the right continue processing your information till such loan has been repaid in full, along with any interest and dues payable.

However, we shall not retain your data and information if it is no longer required by us and there is no legal requirement to retain the same. Do note that multiple legal bases may exist in parallel and we may still have to retain certain data and information at any time.

Right to opt-out:-

Marketing opt-outs:We may email and notify you from time to time about our latest offerings and updates. You may opt out of receiving such promotional emails from us by writing to us. You may also opt out of receiving emails and other messages from us by following the unsubscribe instructions in those messages. However, even if you have opted out of receiving information from us, we will still send non-promotional communications, such as receipts for amount remittance etc.

Push Notifications:You can opt out of receiving push notifications through your device settings. Please note that opting out of receiving push notifications may impact your use of the App.

6. WHAT IS OUR DATA SECURITY PRACTICE?

By setting up a MudraSure Account, you agree to our processing, storage, usage, and sharing of the data provided by you pursuant to this Policy. If you do not agree with any of the terms of this Policy or the Terms or wish to revoke any consent you have provided to us, please write to us at support@drkfpl.com However, please note that if you revoke any mandatory permissions or revoke the consent to process and store information such as your MudraSure Account data, Financial and KYC Information and/or any other information needed to facilitate your loan amounts, then we may have to cease the provision of Services to you. You cannot withdraw your consent once you have availed a loan using the App till you have repaid the loan amount and all related charges in its entirety.

7. CONSENT MECHANISM

Summary:By applying for a loan, you have consented to all our data privacy practices. You can write to support@drkfpl.com if you wish to revoke any consent.

By setting up a MudraSure Account, you agree to our processing, storage, usage, and sharing of the data provided by you pursuant to this Policy. If you do not agree with any of the terms of this Policy or the Terms or wish to revoke any consent you have provided to us and/or the, please write to us at support@drkfpl.com. However, please note that if you revoke any mandatory permissions or revoke the consent to process and store information such as your MudraSure Account data, Financial and KYC Information and/or any other information needed to facilitate your loan amounts, then we may have to cease the provision of Services to you. You cannot withdraw your consent once you have availed a loan using the App till you have repaid the loan amount and all related charges in its entirety.

8. DATA RETENTION

We shall retain the information you provide to facilitate your smooth and uninterrupted use of the App, and (i) to provide, improve and personalize our Services; (ii) to contact you about your account and give customer service; (iii) to personalize our advertising and marketing communications; and (iv) to prevent, detect, mitigate, and investigate fraudulent or illegal activities. We do not retain your personal data for longer than required for the purpose for which the information may be lawfully used. For any other information, we may entertain your request for deletion, however, you may not be able to use our Services at all after such deletion.

9. CHILDREN’S PRIVACY

Our Services are not directed to children, and we do not knowingly solicit or collect personal information from persons under the age of 18 (eighteen). If we find out that a child has given us personal information, we will take steps to delete that information and terminate the relevant MudraSure Account.

10. COMMUNICATIONS FROM US

We may from time to time contact you via calls, SMS, emails, WhatsApp and other communication channels to provide you with information pertaining to our Services, notifications on updates vis-à-vis our Services (when we consider it necessary to do so), educational information and promotions. We may also notify you if we need to temporarily suspend the App for maintenance, and keep you informed on security, privacy, or administrative-related communications. By setting up an account on MudraSure, you consent to us contacting you via call, SMS, WhatsApp, push notifications, or through any other communication channel, as we may deem fit.

11. UPDATES TO THIS NOTICE

We may occasionally update this Policy. Use of our Services after an update constitutes consent to the updated notice to the extent permitted by law. Please take the time to periodically review this Policy for the latest information on our privacy practices.