Agrim Fincap Private Limited
Privacy Policy
INTRODUCTION:
Agrim Fincap Private Limited (“Agrim”, “AFPL”, “Company”, “we”, “us” or “our”) is a company incorporated under the Companies Act bearing CIN U74899DL1995PTC067419, having its registered office at 276, First Floor, Gagan Vihar, Shahdara, Delhi – 110051 and corporate office at F-40, Ground Floor, Sector-6, Noida, Gautam Buddha Nagar, Uttar Pradesh – 201301.
The Company is registered with the Reserve Bank of India (“RBI”) as a Non-Banking Financial Company – Investment and Credit Company (“NBFC-ICC”), categorised under the Base Layer as a Non-Deposit Taking, Non-Systemically Important NBFC, bearing RBI Registration No. B-14.02333.
This Privacy Policy (“Policy”) describes the manner in which the Company collects, receives, stores, uses, processes, shares, transfers, retains and protects personal data of customers, prospective customers, users and other persons (“you” or “your”) accessing or using the Company's website, mobile application, Digital Lending Application (“DLA”), digital interfaces and/or services offered by the Company (collectively, the “Platform”).
This Policy shall be read together with the applicable terms and conditions, loan documents, Key Fact Statement, consent artefacts and other notices made available to you.
The Company is committed to protecting your personal data and processing it in accordance with applicable laws, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”), rules made thereunder as brought into force from time to time, applicable RBI directions and other applicable laws. The DPDP Rules, 2025 were notified in November 2025 with an implementation timeline for relevant provisions.
DEFINITIONS AND ROLE OF THE COMPANY:
For purposes of this Policy, expressions such as “Data Principal”, “Data Fiduciary”, “personal data”, “processing”, “Consent Manager” and other expressions relating to personal data shall have the meanings assigned under applicable data protection laws.
To the extent the Company determines the purpose and means of processing your personal data, the Company shall act as the Data Fiduciary, and you shall be the Data Principal, subject to applicable law.
PERSONAL DATA WE COLLECT
We collect and process only such personal data as is reasonably necessary for providing the Services, evaluating and servicing credit facilities, complying with regulatory requirements, preventing fraud and undertaking other purposes disclosed under this Policy.
Such information may include:
We do not access your mobile phone resources such as file and media (except as disclosed above in order to enable you to upload documents), call logs and telephony functions in relation to lending services. However, we may access your camera, microphone, location or any other facility solely for the purpose of onboarding or KYC checks in relation to lending and other services, after obtaining your explicit consent. We may also access your location details to verify your location, and current address, to ensure serviceability, and to identify unusual activity to prevent against any fraud.
We are required to collect your personal data to provide you with access to the Platform and Services. In certain cases, we are required to collect personal data as required by law, or under the Terms. If you fail to provide us that data as and when requested by us, we may not be able to perform our obligations under the arrangement we have with you or are trying to enter into with you. In this case, we may have to cancel or limit your access to or use of the Services (or part thereof).
We also collect, use, and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data under applicable laws.
DEVICE PERMISSIONS AND RESTRICTED DATA
The Company shall collect information through the Platform on a need-based basis and, wherever required, only after obtaining your prior and explicit consent with an appropriate audit trail.
The Company and its authorised DLAs/LSPs shall not access or collect your contact list, call logs, telephony functions, personal files or media, except limited access to files/media voluntarily selected by you for uploading documents through the Platform.
The Company shall not collect or store biometric data through the DLA except where specifically permitted under applicable statutory or regulatory requirements.
One-time access to your camera, microphone, location or other device facility may be requested where necessary for onboarding, KYC, identity verification, fraud prevention or another disclosed purpose. Such access shall be subject to your explicit consent wherever required.
Where required under applicable law or RBI directions, you shall be provided with the ability to give or deny consent for specific data, restrict disclosure to third parties, withdraw consent previously granted and exercise applicable rights relating to retention/deletion.
This formulation is important because RBI expressly requires need-based collection with prior explicit consent and restricts access to phone resources and biometric information.
HOW WE COLLECT DATA ABOUT YOU
We use different methods, as permitted under applicable laws, to collect and process personal data about you. This includes:
(a) Information you provide us: This is the information (including Identity Data, Profile Data, Contact Data, and Financial Data) you consent to give us when you use our Services or when you correspond with us. It includes information you provide when you register to
use the Services, use a Platform feature, share data through the Platform, or any other platform, service, website or interface owned or operated by us, or when you report a problem with the Platform and our Services. If you contact us, we will keep a record of the information shared during the correspondence.
(b) Information we collect about you and your device: Each time you visit the Platform or use the Services, we may automatically collect Technical Data, Usage Data, device information, security information and information through cookies or similar technologies, subject to applicable law and the choices or consent made available to you.
(c) Information we receive from other sources including third parties and publicly available sources: We may receive personal data, including sensitive personal data and information, about you from various third parties such as account aggregators, credit information companies, analytics providers, advertising networks, search information providers, Employee Provident Fund Organization, providers of technical, payment and delivery services, and other publicly available sources. We may also collect Credit Data about you from third parties with your authorisation.
PURPOSE AND BASIS OF PROCESSING
We shall process personal data only for lawful purposes and in accordance with applicable law.
Depending upon the processing activity, personal data may be processed pursuant to your consent, for legitimate uses permitted under applicable law, for providing Services requested by you and/or for compliance with statutory or regulatory obligations.
We may process your personal data for, inter alia:
KYC, CKYCR AND REGULATORY VERIFICATION
For compliance with applicable KYC requirements, the Company may collect, verify, maintain and process your KYC information in accordance with the Prevention of Money Laundering Act, 2002, rules thereunder and applicable RBI KYC directions.
The Company may upload KYC records and related information to the Central KYC Records Registry (“CKYCR”) and may retrieve or obtain KYC records or updates from CKYCR as permitted or required under applicable law.
Where applicable, your KYC Identifier may be used for retrieving KYC records and avoiding unnecessary repetition of KYC documentation.
INSTALLED APPLICATIONS INFORMATION
Subject to applicable law and only after obtaining your prior and explicit consent, the Company and/or its authorised Digital Lending Application (“DLA”) may collect limited information relating to applications installed on your device, to the extent such collection is technically available and legally permissible.
Where such information is collected, the Company may collect limited application-related identifiers, such as the package name or application identifier of installed applications. The Company does not access the content, login credentials, passwords, messages, files, photographs, documents, usage content or other personal information contained within such installed applications.
Such information may be processed only for disclosed and legitimate purposes, including fraud prevention, device-integrity assessment, risk assessment and/or creditworthiness assessment, where such processing is permitted under applicable law and forms part of the Company's approved credit-risk framework.
The Company shall collect such information on a need-based basis and only after providing appropriate notice regarding the purpose of collection and obtaining your explicit consent, wherever required. You shall be provided with appropriate options to provide, deny or withdraw such consent in accordance with applicable law and RBI directions.
Information collected under this section shall be transmitted using appropriate security safeguards and stored and processed in accordance with the Company's information-security, data-retention and data-localisation requirements. Access shall be restricted to authorised personnel and service providers on a need-to-know basis, and such information shall not be retained for longer than necessary or as otherwise required or permitted under applicable law.
SMS INFORMATION
Subject to applicable law and only after obtaining your prior and explicit consent, the Company and/or its authorised DLA may collect and process limited transactional or financial SMS information, where such access is technically available, legally permissible and necessary for providing the Services.
Where such information is collected, it shall be limited to relevant transactional or financial information required for the disclosed purpose, such as information relating to credits, debits, income, expenditure, repayment patterns and other financial transactions, for the purposes of assessing financial position, cash flows, repayment capacity, fraud risk and/or creditworthiness.
The Company does not access, collect, read or store personal or private SMS messages, personal conversations, OTPs, authentication codes, passwords or other unrelated message content for credit assessment, profiling or marketing purposes.
Where SMS functionality is required solely for device or mobile-number verification, the Company may, after obtaining the required permission, use such functionality only for the disclosed verification purpose and in accordance with applicable law.
Any SMS-derived information lawfully collected shall be transmitted using appropriate security safeguards and processed and stored in accordance with the Company's information-security, data-retention and data-localisation requirements. Access to such information shall be restricted to authorised personnel and service providers on a need-to-know basis.
The Company shall retain such information only for so long as necessary for the purpose for which it was collected or for such period as may otherwise be required or permitted under applicable law. Upon expiry of the applicable retention period, the information shall be securely deleted, destroyed or anonymised in accordance with the Company's data-retention and destruction practices.
Where processing is based on consent, you shall be provided with appropriate mechanisms to provide, deny or withdraw such consent, subject to statutory and regulatory requirements.
CREDIT INFORMATION COMPANIES
The Company may obtain your credit information report, credit score, credit history and related information from CICs in accordance with applicable law. The Company may also furnish, report, update and periodically submit information concerning your loan application, credit facility, outstanding amounts, repayment behaviour, defaults and other relevant credit information to CICs registered under the Credit Information Companies (Regulation) Act, 2005.
Digital lending undertaken through a regulated entity's DLA/LSP framework is subject to CIC reporting requirements irrespective of the nature or tenor of the loan.
AML, CFT AND FRAUD PREVENTION
The Company may undertake customer due diligence, enhanced due diligence where applicable, transaction monitoring, risk categorisation, sanctions screening, fraud detection and other verification measures for compliance with applicable AML/CFT and financial-crime prevention requirements.
Where required or permitted by law, information may be disclosed to FIU-IND, RBI, law-enforcement authorities, courts or other competent statutory/regulatory authorities without requiring separate consent.
ACCOUNT AGGREGATOR INFORMATION
Where you choose to share Financial Information through an RBI-regulated Account Aggregator (“AA”), such information shall be obtained and processed in accordance with the consent artefact approved by you and applicable RBI requirements.
The Company shall use such Financial Information only for the purpose specified in the applicable consent artefact and/or otherwise permitted under applicable law.
HOW WE USE YOUR PERSONAL DATA AND FOR WHAT PURPOSES
We will only use your personal data in accordance with applicable laws. Most commonly, we will use your personal data to provide you with the Services, or where we need to comply with a legal obligation.
You agree and acknowledge that by using our Services and creating an account on the Platform, you authorize us, our associate partners, and our affiliates to contact you via email, phone, or otherwise. This is to ensure that you are aware of all the features of the Services.
In general, we use your personal data for the following purposes and activities undertaken without direct human supervision or control:
The Company may provide lending Services directly through its Platform and/or engage authorised Lending Service Providers (“LSPs”), Digital Lending Applications (“DLAs”) and other service providers for permitted activities including customer acquisition, onboarding, underwriting support, servicing, monitoring, collection/recovery and other functions permitted under applicable RBI directions.
Engagement of any LSP or service provider shall not diminish the regulatory obligations of the Company towards its borrowers.
LSPs/DLAs shall be permitted to collect or process only such customer information as is necessary for performing the authorised function and subject to applicable contractual, security, confidentiality and regulatory requirements.
HOW WE SHARE YOUR PERSONAL DATA
Subject to applicable law and consent requirements, the Company may share personal data on a need-to-know and purpose-specific basis with authorised recipients including:
LSPs and DLAs engaged by the Company; CICs; Account Aggregators; CKYCR/KYC agencies; banks and payment service providers; technology/cloud/IT service providers; identity and fraud verification providers; collection/recovery service providers; auditors, advocates and professional advisers; statutory/regulatory authorities; law-enforcement authorities; and other persons authorised under applicable law.
Where third parties process personal data on behalf of the Company, appropriate contractual, confidentiality, security and data-protection obligations shall be imposed, as applicable.
Personal data shall not be shared with third parties for unrelated purposes without valid consent unless such disclosure is otherwise permitted or required by applicable law.
RBI specifically requires the privacy policy to disclose third parties permitted to collect personal information through a DLA and requires explicit consent before third-party sharing except where disclosure is statutorily/regulatorily required.
SECURITY & TRANSACTION META DATA
We collect security and transaction-related metadata, including transaction identifiers, timestamps, payment status, device information, IP address, session logs, and technical records generated while you use our Platform. This information is used solely for processing transactions, verifying your identity, fraud prevention, risk management, maintaining platform security, and complying with applicable laws and regulatory requirements. Such data is retained only for as long as necessary to provide the Services or comply with legal and regulatory obligations. We do not sell or share this information with unauthorized third parties. It may be shared only with authorized service providers, RBI-regulated lending partners, or government authorities where required by law.
ANTI-FRAUD DEVICE INTEGRITY DATA
We collect limited device and security-related information, including device identifiers, operating system details, application version, network information, IP address, location data (where consented), and other technical indicators necessary to assess device integrity and detect fraudulent or suspicious activities. This information is used solely for fraud prevention, identity verification, credit risk assessment, cybersecurity, and regulatory compliance. It is retained only for as long as required to fulfil these purposes and applicable legal obligations. We do not sell or disclose this information to unauthorized third parties and share it only with authorized service providers, RBI-regulated lending partners, or competent authorities where required by law.
HOW WE SHARE YOUR PERSONAL DATA
You hereby agree and acknowledge that any and all information pertaining to you, may be shared by us with our group companies or third parties – including financial institutions, vendors, service providers, and business partners, for the purposes detailed in this Policy, in accordance with your consent where required under applicable laws.
You agree and acknowledge that by using our Services and creating an account on the Platform, you authorize us, our associate partners, and affiliates to contact you via email, phone, or otherwise. This is to ensure that you are aware of all the features of the Services.
You agree and acknowledge that we may share data where we are required by law, any court, government agency, or authority to disclose such information. Such disclosures are made in good faith and belief that it is reasonably necessary to do so for enforcing this Policy or the Terms, or in order to comply with any applicable laws and regulations.
DATA SECURITY
The Company shall implement reasonable and appropriate technical, organisational and physical security safeguards to protect personal data against unauthorised access, disclosure, alteration, loss, misuse or destruction.
Such safeguards may include encryption, access controls, authentication mechanisms, firewalls, secure transmission protocols, logging and monitoring, vulnerability management, backup and recovery controls and other security measures appropriate to the nature and sensitivity of the information.
Access to personal data shall be restricted to authorised employees, personnel and service providers having a legitimate need to access such information.
The Company shall maintain appropriate incident-management processes for detecting, assessing, containing, responding to and recovering from personal-data/security breaches.
Where a personal-data breach occurs, the Company shall take appropriate mitigation and notification measures in accordance with applicable law and regulatory requirements.
DATA STORAGE , LOCALISATION
Personal data collected and processed in connection with digital lending activities shall be stored on servers located in India in accordance with applicable RBI directions and other regulatory requirements.
Any processing, access or transfer of personal data involving a location outside India, where legally and regulatorily permissible, shall be undertaken only in accordance with applicable data protection laws and subject to such restrictions, safeguards and conditions as may be prescribed by the Government of India, RBI or any other competent authority from time to time.
Nothing contained in this Policy shall be construed as permitting the Company, its LSPs, DLAs or service providers to store or transfer personal data in a manner contrary to any applicable data-localisation requirement.
DATA RETENTION AND DESTRUCTION
The Company shall retain personal data only for such period as is necessary for the purpose for which it was collected or processed and/or for such period as may be prescribed under applicable laws and regulatory requirements, including applicable RBI directions, the Prevention of Money Laundering Act, 2002 and rules made thereunder, applicable KYC requirements, the Credit Information Companies (Regulation) Act, 2005, the Companies Act, 2013, applicable tax laws and other statutory or regulatory requirements.
Where different retention periods apply to different categories of personal data or records, the applicable statutory or regulatory retention period shall prevail.
Personal data may also be retained for such additional period as may be reasonably necessary for fraud prevention, regulatory audits or inspections, investigation of complaints, enforcement of contractual rights, recovery of outstanding dues and establishment, exercise or defence of legal claims.
Upon expiry of the applicable retention period and where no legal or regulatory requirement requires further retention, the Company shall securely delete, destroy or anonymise the personal data in accordance with applicable law and its internal data-retention and destruction procedures.
Any request for deletion or erasure shall remain subject to statutory and regulatory retention obligations applicable to the Company.
YOUR LEGAL RIGHTS AND WITHDRAWAL OF CONSENT
Subject to applicable law, you may have the right to:
Withdrawal of consent shall not affect processing lawfully undertaken prior to withdrawal.
The Company may continue processing or retaining information after withdrawal/deletion requests where necessary to comply with legal/regulatory obligations, prevent fraud, service an existing loan or establish/exercise/defend legal claims.
The Company currently expressly addresses erasure, denial of consent, withdrawal of consent and rectification; Agrim's present wording is materially shorter.
TRANSFER OF PERSONAL DATA
Please note that all your personal data is only stored on systems located within India. We do not transfer your personal data to any third country.
PERSONAL DATA BREACH
In the event of a personal data breach, the Company shall take reasonable and appropriate measures to contain, mitigate and remediate the breach and prevent its recurrence.
The Company shall notify affected Data Principals, the Data Protection Board of India and/or any other regulatory or governmental authority, as applicable, in the manner and within the timelines prescribed under applicable law.
The Company shall maintain appropriate records of personal data breaches and remedial measures undertaken in relation thereto, as required under applicable law and internal information-security procedures.
LINKS TO THIRD PARTY WEBSITES
Our Services may, from time to time, contain services provided by or links to and from the websites of our partner networks, service providers, financial institutions, advertisers, and affiliates (“Third Party Services”). Please note that the Third-Party Services that may be accessible through our Services are governed by their own privacy policies. We do not accept any responsibility or liability for the policies or for any personal data that may be collected through such Third-party Services. Please check their policies before you submit any personal data to such websites or use their services.
COOKIES AND TRACKING TEACHNOLOGIES
The Company may use cookies and similar technologies for Platform functionality, security, authentication, analytics, remembering preferences and improving user experience.
Cookies may include essential cookies, functionality/preference cookies and analytics/performance cookies, and where applicable, marketing cookies subject to applicable consent requirements.
You may control certain cookies through your browser/device or available Platform settings. Disabling certain cookies may affect the functionality of the Platform.
BUSINESS TRANSITIONS
You agree and acknowledge that in the event we go through a business transition, such as a merger, acquisition by another organization, or sale of all or a portion of our assets, your personal data may be among the assets transferred.
CHANGE IN PRIVACY POLICY
We keep our Policy under regular review and may amend it from time to time, at our sole discretion.
The terms of this Policy may change and if they do, these changes will be posted on this page and, where required by applicable laws, notified to you.
GRIEVANCE OFFICER
You may contact our Grievance Officer with any inquiry relating to loans.
Name: Mr. Vikas Mandav
Address: F-40, Ground Floor, Sector-6, Noida, Gautam Buddha Nagar, Uttar Pradesh- 201301
Email: gro@agrimfincap.com
Tel No: 0120-4643707
GOVERNING LAW
This Policy shall be governed by and construed in accordance with the laws of India. Any dispute relating to this Policy shall be dealt with in accordance with applicable law and the dispute-resolution provisions contained in the applicable terms, loan documents or agreements, as the case may be.