Golu Leasing & Finance Co. Private Limited respects the privacy of its customers, applicants and visitors. This Policy explains how personal information is collected, used, processed, stored, disclosed and protected.
Company
Golu Leasing & Finance Co. Private Limited
RBI NBFC Registration
B-14.01773
Effective Date
16/04/2022
Last Update
(Date)
Golu Leasing & Finance Co. Private Limited ("Golu Leasing", "Company", "we", "us" or "our") respects the privacy of its customers, applicants and visitors. This Privacy & Security Policy ("Policy") explains how we collect, use, process, store, disclose and protect personal information received through our website, online loan application facilities and related services.
This Policy applies to visitors to our website, prospective customers, loan applicants, borrowers and other persons whose personal information is processed by the Company in connection with its services.
By accessing our website or submitting information through our online application facility, you acknowledge that you have read and understood this Policy. Where consent is required by applicable law, such consent will be obtained in the manner prescribed by law.
1. APPLICABILITY
This Policy applies to information collected through the Company's website, online loan application forms, customer service channels and other authorised digital or physical channels used for providing or administering the Company's financial services.
The Company may offer the following loan products:
- Short-Term Personal Loan / Early Salary – tenure of 1 month.
- Personal Loan – tenure of 2 to 12 months.
This Policy applies to information collected for application processing, KYC, verification, loan servicing, repayment, customer support, fraud prevention, regulatory compliance and other legitimate purposes connected with the Company's business.
2. REGULATORY FRAMEWORK
The Company processes personal information in accordance with applicable laws, rules, regulations and directions applicable to it from time to time, including applicable requirements relating to:
- Information Technology Act, 2000 and applicable rules;
- Digital Personal Data Protection Act, 2023 and applicable rules;
- Reserve Bank of India directions and regulatory requirements applicable to NBFCs and digital lending, where applicable; and
- Other applicable laws, regulations and regulatory directions concerning privacy, data protection, information security, KYC and financial services.
Where any applicable law or regulatory direction provides a higher or different standard, the applicable legal or regulatory requirement shall prevail.
3. INFORMATION WE COLLECT
Depending on the service requested and applicable legal requirements, the Company may collect information such as:
- Name and date of birth;
- Mobile number and email address;
- Residential and communication address;
- PAN and other KYC information;
- Officially valid documents;
- Employment, occupation and income information;
- Bank account and payment information;
- Loan application and transaction information;
- Information relating to repayment and servicing of the loan;
- Customer communications and service requests;
- Device and technical information when using digital services;
- IP address, browser information, operating system and related log information;
- Information collected through cookies and similar technologies; and
- Other information reasonably necessary to provide, administer, secure or comply with legal requirements relating to our services.
We seek to collect only information that is reasonably necessary for the relevant purpose and, where required, provide appropriate choices regarding optional information.
4. INFORMATION PROVIDED BY THE CUSTOMER
The Customer is responsible for ensuring that information submitted to the Company is accurate, complete, current and not misleading.
The Customer should promptly inform the Company if any material information changes or if previously provided information is found to be inaccurate.
The Company may request additional information or documents where reasonably necessary for KYC, verification, loan processing, fraud prevention, servicing, compliance or other lawful purposes.
5. PURPOSE OF COLLECTION AND USE
The Company may collect and use personal information for purposes including:
- Establishing and verifying the Customer's identity;
- Completing KYC and customer onboarding requirements;
- Processing and assessing loan applications;
- Administering and servicing loans;
- Communicating loan-related information and notices;
- Processing repayments and payment instructions;
- Preventing, detecting and investigating fraud and misuse;
- Maintaining records and audit trails;
- Complying with applicable laws, regulations and regulatory directions;
- Responding to customer queries and grievances;
- Improving website functionality, security and customer experience;
- Conducting internal analytics and operational reporting where permitted;
- Managing recovery and collection of amounts lawfully due;
- Protecting the Company's rights, property and systems; and
- Other purposes specifically disclosed to the Customer or permitted by applicable law.
6. LAWFUL BASIS AND CONSENT
Where required by applicable law, the Company will obtain consent for processing personal information for specified purposes.
Consent will be sought in a clear and appropriate manner. Where applicable, the Customer may withdraw consent, subject to legal, contractual and regulatory limitations.
Withdrawal of consent may affect the Company's ability to provide certain services where the relevant information is necessary for providing those services or complying with legal requirements.
7. KYC AND VERIFICATION
The Company may collect and verify KYC and identity information through authorised processes and service providers, as permitted by law.
Where Aadhaar-based authentication or e-KYC is used, such processing shall be undertaken in accordance with applicable Aadhaar/UIDAI requirements and applicable law.
The Company may also use authorised verification services for validating information and documents submitted by the Customer.
8. CREDIT SCORE / CIBIL
The Company may obtain, access or verify the Customer's credit information from Credit Information Companies and other legally permissible sources for the purposes of credit assessment, underwriting, risk management, monitoring and regulatory compliance.
The Company may undertake lawful underwriting, due diligence, KYC, identity verification, income verification, banking verification, fraud prevention and other assessment required under applicable law and the Company's internal policies.
9. DEVICE, TECHNICAL AND WEBSITE INFORMATION
When you use our website or authorised digital services, we may collect limited technical information such as IP address, browser type, operating system, device information, pages visited, date and time of access and related log information.
This information may be used for website administration, security, troubleshooting, analytics, fraud prevention and improving the performance and functionality of our services.
The Company will not access information from a customer's device beyond what is necessary and lawfully permitted for the relevant service and purpose.
10. CAMERA, LOCATION AND OTHER DEVICE PERMISSIONS
Where a digital onboarding process requires access to a camera, location or other device functionality, the relevant permission will be requested in accordance with applicable law and the purpose for which the information is required.
Camera access may be used for purposes such as capturing a selfie or required KYC documents where necessary.
Location information, where collected, shall be used only for a lawful and disclosed purpose connected with onboarding, verification, fraud prevention, regulatory compliance or provision of the relevant service.
The Company shall not access a customer's contact list, call logs or other unrelated device resources unless specifically permitted by applicable law and necessary for a disclosed service purpose.
11. COOKIES
The Company's website may use cookies and similar technologies to improve functionality, remember preferences, understand website usage and maintain security.
Cookies may collect information such as browser type, pages visited, session information and other technical information.
Customers may manage cookie settings through their browser. Disabling certain cookies may affect the functionality of some website features.
12. INFORMATION SHARING AND DISCLOSURE
The Company may disclose or share personal information only for lawful and legitimate purposes and as permitted or required by applicable law.
Information may be shared, where appropriate, with:
- Authorised technology and service providers;
- KYC and verification service providers;
- Payment and banking service providers;
- Document and e-sign service providers;
- Collection/recovery service providers;
- Professional advisers, auditors and consultants;
- Government, regulatory, judicial or law-enforcement authorities where legally required;
- Other entities where disclosure is necessary to provide the requested service or is otherwise permitted by law.
Where third-party service providers process information on behalf of the Company, the Company will take appropriate contractual and security measures as required.
13. THIRD-PARTY SERVICE PROVIDERS
The Company may engage third-party service providers to perform specific operational functions, including KYC verification, document processing, payment processing, communication, technology hosting, customer support, fraud prevention and recovery services.
Such providers will receive only information reasonably necessary for the services they perform and will be expected to maintain appropriate confidentiality and security safeguards, subject to applicable law and contractual requirements.
Where a Lending Service Provider (LSP) is engaged by the Company in connection with digital lending activities, the LSP shall process Customer information only for the purposes and activities authorised by the Company and applicable law. The Company shall remain responsible for compliance with applicable RBI requirements in relation to such processing.
14. MARKETING COMMUNICATIONS
Where required, the Company will obtain appropriate consent before sending promotional or marketing communications.
Customers may opt out of promotional communications by using the unsubscribe mechanism provided in the communication or by contacting the Company through its designated channels.
Opting out of promotional communications will not prevent the Company from sending essential service-related communications such as loan approvals, repayment reminders, statements, security alerts, regulatory notices or other necessary communications.
15. DATA RETENTION
The Company will retain personal information only for as long as reasonably necessary for the purposes for which it was collected and as required under applicable laws, regulatory requirements, accounting, tax, audit, dispute-resolution, fraud-prevention and other legal obligations.
After the applicable retention period, information will be securely deleted, anonymised or otherwise disposed of in accordance with the Company's applicable policies and legal requirements.
Where information must be retained despite withdrawal of consent because of a legal or regulatory requirement, the Company may continue to retain such information for the required period.
16. DATA DELETION AND WITHDRAWAL OF CONSENT
Subject to applicable law and mandatory retention requirements, customers may request correction or deletion of personal information or withdrawal of consent by contacting the Company through the designated privacy/grievance channel.
A request for deletion or withdrawal of consent may not be accepted where retention or processing is required by law, regulation, court order, regulatory direction, fraud prevention requirements or for the establishment, exercise or defence of legal claims.
The Company may also retain limited information necessary to maintain records of transactions, consents, complaints and regulatory obligations.
17. CUSTOMER DATA RIGHTS
Subject to applicable law, customers may have rights including:
- Right to access information processed about them;
- Right to request correction or updating of inaccurate information;
- Right to request erasure where legally permissible;
- Right to withdraw consent where processing is based on consent;
- Right to raise a grievance regarding processing of personal information; and
- Other rights available under applicable data protection law.
Requests may be subject to reasonable verification of identity and applicable legal limitations.
18. DATA SECURITY
The Company implements reasonable technical, administrative and organisational safeguards designed to protect personal information against unauthorised access, alteration, disclosure, misuse, loss or destruction.
Security measures may include:
- Access controls;
- Authentication mechanisms;
- Encryption and secure transmission where appropriate;
- Monitoring and logging;
- Secure hosting and infrastructure controls;
- Internal confidentiality requirements;
- Periodic review of security practices; and
- Incident management procedures.
No electronic transmission or storage system can be guaranteed to be completely secure. The Company will nevertheless take reasonable measures to protect information in accordance with applicable requirements.
19. INFORMATION SECURITY INCIDENTS
In the event of a data or information-security incident, the Company will take appropriate steps to contain, investigate, remediate and document the incident and make notifications to regulators, authorities or affected persons where required by applicable law.
The Company will maintain appropriate incident-response procedures consistent with applicable legal and regulatory requirements.
20. LOGIN, OTP AND ACCOUNT SECURITY
Customers are responsible for keeping their login credentials, passwords, OTPs and other authentication information confidential.
Customers should never share OTPs, passwords or authentication credentials with unknown persons.
If a Customer suspects unauthorised access, fraud or misuse of an account, the Customer should immediately contact the Company through its official customer-support or grievance channels.
The Company will not request a Customer's password or OTP for purposes unrelated to an authorised transaction or verification process.
21. FRAUD PREVENTION
The Company may process information to prevent, detect and investigate fraud, identity theft, suspicious activity, unauthorised transactions and misuse of its services.
Where required or permitted by law, information may be shared with competent authorities, regulators, service providers or other relevant entities for fraud prevention and investigation.
22. DATA STORAGE
The Company shall store and process personal information in accordance with applicable RBI directions and other applicable laws. Where RBI directions prescribe specific requirements relating to storage of data relating to customers and/or digital lending operations, the Company shall comply with such requirements.
23. CHILDREN AND MINORS
The Company's loan services are intended for persons who are legally eligible to obtain financial services.
The Company does not knowingly solicit loan applications from minors. If information relating to a minor is inadvertently provided, the Company may take appropriate steps in accordance with applicable law.
24. LINKS TO OTHER WEBSITES
The Company's website may contain links to third-party websites or services. Such third-party websites are governed by their own privacy policies and terms.
The Company is not responsible for the privacy practices, content or security of third-party websites that are outside the Company's control.
Customers are advised to review the privacy policies of third-party websites before providing personal information.
25. GRIEVANCE REDRESSAL
Customers may contact the Company for complaints or concerns relating to privacy, data protection, loan services, website usage or other matters.
Grievance Officer: Vikram Gupta
Email: COMPLIANCE@GOLUFIN.COM
Address: BM-5, East Shalimar Bagh, New Delhi – 110088
The Company shall endeavour to resolve grievances within the applicable regulatory timeframe. If a complaint is not resolved within the prescribed period or the Customer is dissatisfied with the response, the Customer may approach the appropriate RBI grievance redressal mechanism, subject to applicable requirements.
26. CONTACT INFORMATION
For privacy, data-protection or other concerns, customers may contact:
Golu Leasing & Finance Co. Private Limited
RBI NBFC Registration No.: B-14.01773
BM-5, East Shalimar Bagh,
New Delhi – 110088
Grievance Officer: Rajat Agarwal
Email: COMPLIANCE@GOLUFIN.COM
27. CHANGES TO THIS POLICY
The Company may update this Privacy & Security Policy from time to time to reflect changes in its services, technology, applicable law or regulatory requirements.
The updated version will be published on the Company's website. Customers are encouraged to review the Policy periodically.
The "Last Updated" date at the beginning of this Policy indicates the date of the latest revision.
28. GOVERNING REQUIREMENTS
This Policy shall be interpreted in accordance with applicable laws, regulations and regulatory directions in force from time to time.
In the event of a conflict between this Policy and a mandatory legal or regulatory requirement, the applicable legal or regulatory requirement shall prevail.
Customer Acknowledgement
By submitting information through the Company's website or loan application facility, the Customer acknowledges that:
- The Customer has read and understood this Privacy & Security Policy.
- The Customer understands the purposes for which personal information may be collected and processed.
- The Customer understands that required information may be necessary to process and service a loan application.
- The Customer will provide accurate and current information.
- The Customer understands that applicable rights relating to personal information are subject to applicable law and mandatory retention requirements.
Golu Leasing & Finance Co. Private Limited
RBI NBFC Registration No.: B-14.01773