Abbreviations
|
LSP
|
Lending Service Provider
|
|
DLA
|
Digital Lending Application
|
|
KYC
|
Know Your Customer
|
|
PCI DSS
|
Payment Card Industry Data Security Standard
|
|
UIDAI
|
Unique Identification Authority of India
|
|
RBI
|
Reserve Bank of India
|
|
MEITY
|
Ministry of Electronics and Information Technology of India
|
|
IRDAI
|
Insurance Regulatory and Development Authority of India
|
Background & Coverage
This policy is prepared on the back of all prevailing laws and regulations, viz. as entailed in RBI’s Digital Lending Guidelines of 2025, Digital Personal Data Protection Act 2023 and MEITY’s enacted Rules of 2025, Information Technology Act 2000 and the rules thereunder, the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act 2016, IRDAI’s Information and Cyber Security Guidelines, Ver 2.0 of 2026 and the Model Policy of UIDAI for Protecting Personal Data of Aadhaar Number Holders.
At SMFG India Credit Company Limited (hereinafter referred to as "SMFG India Credit" / "we"/ "our" / “us”, which term shall include its successors), we are strongly committed to protect the personal and financial information of providers of information, including but not restricted to sensitive information, Personal Information and financial information that provider of information submits and would endeavour to protect it from unauthorized use.
All persons (“Covered Person”), whose Personal Information is either collected / received / possessed / stored / dealt in / handled by SMFG India Credit, who visit SMFG India Credit’s website https://www.smfgindiacredit.com or SMFG India Credit’s mobile application(s) or digital platforms, and/or whose information is provided to SMFG India Credit via offline or online modes, are covered under this Policy.
This Privacy Policy describes the type of information of Covered Persons collected by SMFG India Credit, use of such information and purposes for processing of the information.
SMFG India Credit is committed to collect and process the Personal Information of the Covered Persons in adherence of this policy while complying with the requirements of applicable laws, rules and regulations governing data protection and privacy.
SMFG India Credit urges all Covered Person to read and understand this Privacy Policy and keep itself updated of any changes that SMFG India Credit makes to this Privacy Policy.
Personal Information
Any information that relates to a Covered Person, which, either directly or indirectly, in combination with other information available or likely to be available with SMFG India Credit, is capable of identifying such person (such as, but not limited to, name, address, email address, PAN number, user name, precise location, employment details, telephone number, age, date of birth, sensitive information such as information relation to health of a person). Such Covered Person will be the data principal under relevant applicable laws
Consent
By accessing or using SMFG India Credit’s website/mobile application/digital platforms or by availing any product or service from SMFG India Credit or providing its information to SMFG India Credit, Covered Person will agree and consent to the terms of this Privacy Policy, and collection, storage, disclosure and processing of Covered Person’s information or data for the purposes of:-
- availing loans or third-party products facilitated by SMFG India Credit,
- verification, due diligence, fraud prevention, risk assessment,
- purpose associated with Covered Person’s employment, engagement or association with SMFG India Credit (as applicable),
- storage of information or data as per SMFG India Credit’s policy in addition to any legal or regulatory requirements, reporting to law enforcement agencies/courts, and
- communications relating to marketing and business promotion. SMFG India Credit may also process the Covered Person’s Personal Information for any other purpose for which consent is separately and specifically sought from the Covered Person at the relevant time, or as otherwise permitted under applicable law.
Collection of Information
In the course of using the website/mobile application/digital platforms of SMFG India Credit or availing the products and services vide the online application forms and questionnaires, SMFG India Credit may become privy to the Personal Information of Covered Person, including information that is confidential in nature.
Such information may include, but not be limited to: Name, date of birth, demographic details, Aadhaar Number, financial details, family details, banking relationships etc.
SMFG India Credit through its digital lending application or through lending service providers (LSPs) and its digital lending applications (DLAs) shall collect only such data as is necessary for the specific purpose for which consent has been obtained.
The DLAs shall not access mobile phone resources such as contact lists, files and media, call logs, or telephony functions. Access to camera, microphone, and location shall be permitted only on a need basis with applicable Covered Person’s explicit consent and specifically in case of digital lending such accesses will be as per RBI’s digital lending guidelines.
The related data retention and erasure policies of our LSPs will also be made available to the applicable Covered Person for ready reference to ensure proper transparency in SMFG India Credit’s service mechanism.
SMFG India Credit may also collect information in hardcopy through loan applications and supporting documents.
The supporting documents will be collected as per Know Your Customer (KYC) guidelines issued by Reserve Bank of India and may include other documents like statement of accounts, financial statements etc. for the underwriting purpose. Some of these documents and the information extracted from the documents may be stored electronically within the ambit of prevailing regulations.
SMFG India Credit, in conformity with the applicable laws and regulations, will maintain requisite due diligence, oversight and accountability in respect of the technical capabilities, robustness of data privacy policies and storage systems, fairness of conduct and past records of its service providers, including LSPs and DLAs, providing services in relation to acquisition, underwriting, pricing, loan servicing, loan recovery, portfolio performance monitoring and/or any other suite of functions associated with the products or services offered by SMFG India Credit.
SMFG India Credit shall adopt and practice data minimisation approach to enable that only necessary Personal Information of the Covered Person is collected, stored and retained within the ambit of prevailing regulatory guidelines.
SMFG India Credit shall use small bits of data called "cookies" stored on user’s computers to enable a continuous connection experience for the users. Cookies enable to store information about user’s preferences, IP address, and specific access information which allow said user to access and move to different pages of its secure website without having to re-enter password information.
Any information collected is stored in secured databases protected by a variety of access controls and is treated as confidential information by SMFG India Credit.
Covered Person should be careful with usage of the username and password by maintaining confidentiality and ensure that Covered Person do not knowingly or accidentally share, provide and facilitate unauthorized use of it.
All Personal Information so provided will be on an ‘as is’ basis and SMFG India Credit shall not be responsible for the accuracy of the Personal Information provided by the Covered Person.
Use & Disclosure of Personal & Financial Information
SMFG India Credit will use Covered Person’s Personal Information / data in the following circumstances (non-exhaustive):-
- To perform its contractual obligations, which is about to enter into or have entered into with Covered Person or to enforce its rights under such contract.
- It is necessary for the legitimate interest of SMFG India Credit, and/or in the interest of Covered Person, or to comply with legal, statutory, judicial, governmental or regulatory obligations and requirements.
- Compliance with any judgment or order of any court, tribunal or authority, or for responding to a medical emergency involving a threat to the life or health of Covered Person or any other individual.
- For fraud screening and prevention purposes and to protect SMFG India Credit’s legal rights and comply with SMFG India Credit’s legal obligations.
- For record keeping purposes, to comply with laws and regulations, and to comply with other legal processes and law enforcement requirements.
- To track Covered Person’s activity on our digital platforms and thereby to personalize and improve Covered Person’s experience on digital platforms.
- For profiling purposes to enable SMFG India Credit to personalize and/or tailor any marketing communications that Covered Person may consent to receive.
- To perform activities such as data analysis, audits, usage trends to determine the effectiveness of SMFG India Credit’s campaigns and as input into improving products and services.
SMFG India Credit may use and share within the ambit of regulations the Personal Information collected from the Covered Person to improve its services to Covered Person and to keep the Covered Person updated about its new product offerings or any other information that may be of interest to the Covered Person. SMFG India Credit may also invite Covered Person to participate in market research and surveys and other similar activities.
Generally, SMFG India Credit relies on consent as a legal basis for processing Covered Person’s Personal Information / data, by itself or through its third-party service providers, partners, agencies or associates, including in relation to sending third party direct marketing communications.
SMFG India Credit will comply with applicable laws in respect of storage and transfer of Covered Person’s Personal Information / data including any cross-border data transfer requirements i.e. wherein as part of Covered Person’s use of our services, Covered Person’s Personal Information / data provided to us may be transferred outside India for the purpose of processing and/or storage. Notwithstanding the foregoing, in case of digital lending services,
SMFG India Credit will ensure that Covered Person’s data is stored only in servers located inside international borders of India and in case the data is processed outside India, the same will be deleted from such servers outside India and brought back to India within 24 hours of processing.
Covered Person will have the right to withdraw the consent provided for marketing purposes at any time by contacting SMFG India Credit at [email protected]
However, SMFG India Credit may not be required to obtain Covered Person’s consent for use of Covered Person’s Personal Information / data to comply with its legitimate legal, statutory or regulatory obligations. SMFG India Credit will only use Covered Person’s Personal Information / data for the purposes for which it was collected, unless SMFG India Credit reasonably consider that it needs to use it for compliance of its legal obligations.
The Covered Person may contact SMFG India Credit if any explanation required in this regard:-
Anand Kumar Kasturi, Data Protection Officer
SMFG India Credit Co. Ltd., Tower C, 11th Floor, Embassy 247, Gandhi Nagar, LBS Marg, Vikhroli West, Mumbai – 400083
[email protected]
Use of Service Providers
SMFG India Credit may use third party services providers to provide services on SMFG India Credit’s behalf or to facilitate SMFG India Credit’s products / services or perform any ancillary services in relation to the SMFG India Credit’s products / services or to assist SMFG India Credit to analyse the usage of the product/services and evaluation of service standards.
Transfer of Information
SMFG India Credit may share the information with other persons in the course of normal business operations, such as for providing services Covered Person has subscribed for, and any activity related to these services such as collection of fees, basis consent obtained from such Covered Persons. It may become necessary for SMFG India Credit to disclose Covered Person’s Personal Information to its agents and contractors in the course of normal business operations for the above referred purpose.
However, these parties will be required to use the information obtained from SMFG India Credit for such purposes exclusively and within the ambit of consent taken from the Covered Person. SMFG India Credit will ensure that the third parties receiving any Personal Information, sensitive personal data or information from SMFG India Credit or from any person on behalf of SMFG India Credit also do not disclose it further. SMFG India Credit will also endeavour that these third parties maintain the same level of data protection that is adhered to by SMFG India Credit.
SMFG India Credit will endeavour to take all reasonable steps to ensure that the confidentiality of Covered Person’s information is maintained by imposing strict confidentiality standards on all the third parties to whom it discloses such information. SMFG India Credit will build-in the necessary covenants for the outsourcing arrangements that are material in nature.
SMFG India Credit will transfer or disclose Covered Person’s information to a third party only if it is necessary for the performance of a lawful contract between SMFG India Credit and the Covered Person as consented by the Covered Person for data transfer or if required to comply with SMFG India Credit’s obligations under applicable laws.
The Covered Person authorizes SMFG India Credit to exchange, share, part with all information related to the details and transaction history of the Covered Person to its affiliates / subsidiaries / banks / financial institutions / credit bureaus / agencies / participation in any telecommunication or electronic clearing network as may be required by law, customary practice, credit reporting, statistical analysis, credit scoring, verification or risk management and shall not hold SMFG India Credit liable for use or disclosure of this information.
SMFG India Credit may collect card payments, in compliance with applicable regulations, through a Payment Card Industry Data Security Standard (PCI DSS) compliant partner(s) and the Covered Persons may contact SMFG India Credit if an email/SMS confirmation was not received within 48 hours for any payment made through a card swipe.
Data Security
SMFG India Credit is strongly committed to protecting the privacy of the Covered Person’s Personal Information / data by taking all necessary and reasonable security measures and safeguards as per applicable laws and regulations to protect the confidentiality of the information and its transmission through the world wide web, including implementation of administrative, management and technical safeguards like encryption of data in rest and transit, access control including multi-factor authentication for any privileged access, maintenance of audit trail, fraud detection modules, device and network security checks, periodic system audits, updated and robust information technology infrastructure and physical security and surveillance of facilities and equipment where the information is processed. SMFG India Credit’s systems continuously monitor for cyber security threats and unusual activities.
As part of ongoing control, SMFG India Credit will ensure periodic vulnerability assessments and penetration tests, together with implementation of secured development and change management process.
SMFG India Credit will limit access to Covered Person’s Personal Information to the employees, agents, contractors and other third parties who have a business with SMFG India Credit, strictly on a need-to-know basis.
SMFG India Credit is committed to upholding data privacy and compliance of data governance requirements to help us deliver quality services to our customers per SMFG India Credit’s Board approved Information Security framework.
SMFG India Credit employees and contractors will be required to follow confidentiality obligations and handle Covered Person’s information ethically and securely. SMFG India Credit employees undergo training on data privacy, security policies, and best practices to ensure they understand their responsibilities in protecting Personal Information.
SMFG India Credit has implemented industry standard security measures for data protection and privacy. Further, SMFG India Credit has a robust incident management system and protocols along with a proactive incident response posture. In the event of data breach, SMFG India Credit is committed to promptly notifying the affected Covered Persons and the authorities as required under applicable laws and regulations via email and/or other applicable communications methods as well as undertaking necessary remedial actions in compliance to regulatory guidelines.
Fraud prevention and service integrity will be ensured through controls which help detect and prevent fraud, account misuse and/or service abuse and may include, but not limited to, device and network security checks, rate-limiting and anomaly detections. SMFG India Credit is committed to maintenance of robust business continuity and disaster recovery mechanisms.
SMFG India Credit shall not be held liable for disclosure of the Covered Person’s confidential information including Personal Information when such disclosure is required for compliance of applicable laws, rules or regulations, or, in accordance with this Privacy Policy, or, in terms of the agreements/terms agreed, if any, with the Covered Person.
Data Retention and Erasure/de-identification of data
SMFG India Credit shall retain Personal Information for such period as is necessary to fulfil the purpose for which it was collected, or for such longer period as may be required under applicable law (including but not limited to RBI’s directions on record retention).
Upon the expiry of the retention period, or upon withdrawal of consent by the Covered Person (whichever is earlier), SMFG India Credit shall erase and/or de-identify/permanently redact the Personal Information to ensure the information cannot be linked to Covered Person (as per applicable law), within the timelines prescribed under applicable law unless continued retention is mandated by law.
SMFG India Credit may retain Covered Person’s Personal Information / data for extended periods where such information is required for legal, statutory, regulatory, accounting or other legitimate purposes including but not limited to any requirement of any investigation agencies or regulatory or governmental bodies, or arising out of any requirements before judicial/quasi-judicial bodies, or to file/address any customer complaints or legal claims.
SMFG India Credit has appropriate policy underlying storage / retention of data, including the length of time for which data can be stored and the restrictions around access or use of data depending on its sensitivity, the data disposal or destruction protocol, the standards of handling data breach, etc. as per regulatory guidelines.
Data Protection Officer / Grievance Redressal Officer
SMFG India Credit has designated Data Protection Officer whose details are as follows:-
Anand Kumar Kasturi, Data Protection Officer
SMFG India Credit Co. Ltd., Tower C, 11th Floor, Embassy 247, Gandhi Nagar, LBS Marg, Vikhroli West, Mumbai – 400083
[email protected]
The Data Protection Officer shall address any grievances or concerns of the Covered Person, including requests for withdrawal of consent by Covered Person and/or exercise of any legitimate rights of Covered Person, expeditiously within reasonable time from the date of receipt of the grievance.
For grievances related to digital lending, the Covered Person may also contact the Nodal Grievance Redressal Officer designated under the RBI Guidelines on Digital Lending whose details are as follows:
Ancy Dmello, Grievance Redressal Officer
SMFG India Credit Co. Ltd., Tower C, Ground Floor, Embassy 247, Gandhi Nagar, LBS Marg, Vikhroli West, Mumbai – 400083
[email protected]
Important to Note
- Exclusions: Third-party / external websites / mobile applications / digital platforms (“External Platforms”) that Covered Person may access via SMFG India Credit’s website/mobile application/digital platforms may have different privacy policies and access to such External Platforms will not be subject to this privacy policy. Such External Platforms are not operated by SMFG India Credit and are beyond SMFG India Credit’s control. SMFG India Credit recommends to the Covered Person to read the privacy statement / privacy policy / privacy commitment of each such External Platforms to find out how they protect Covered Person’s Personal Information / data. SMFG India Credit does not accept any responsibility or liability for the policies of, or for any Covered Person’s Personal Information / data that may be collected through, or disclosures made by the Covered Person in any External Platforms. Covered Person’s relationship with these third parties and their services and tools is independent of Covered Person’s relationship with SMFG India Credit.
- Amendments: Due to changes in legislation or enhancements to functionality and content on the website / mobile application / digital platforms, SMFG India Credit may make changes to its Privacy Policy (without being obliged to do so) and would reflect those changes in this Privacy Policy. Hence Covered Person is obligated to go through this Privacy Policy on a regular basis.
- Prohibited Actions: While using the website / mobile application / digital platforms of SMFG India Credit, Covered Person agrees not to, by any means (including hacking, cracking or defacing any portion of the website/mobile application/digital platforms), indulge in illegal or unauthorized activities including the following:
- Restrict or inhibit any authorized user from using the website / mobile application / digital platforms;
- Use the website/mobile application/digital platforms for unlawful purposes;
- Harvest or collect information about website/mobile application/digital platforms users without their express consent;
- “Frame” or “mirror” any part of the website/mobile application/digital platforms without our prior authorization;
- Engage in spamming or flooding;
- Transmit any software or other materials that contain any virus, time bomb, or other harmful or disruptive component;
- Remove any copyright, trademark or other proprietary rights notices contained in the website /mobile application / digital platforms;
- Use any device, application or process to retrieve, index, “data mine” or in any way reproduce or circumvent the navigational structure or presentation of the website / mobile application / digital platforms;
- Permit or help anyone without access to the website / mobile application / digital platforms to use the website/mobile application/digital platforms through its username and password or otherwise;
- Impersonate another person while providing his/her Personal Information for the purpose of accessing the website / mobile application / digital platforms or SMFG India Credit’s services
- Aggregate/Anonymized Information: This Privacy Policy applies only to Personal Information of the Covered Person and does not extend to aggregate, anonymized, de-identified, redacted information, statistical information or data collected and compiled, derived or generated by SMFG India Credit during the course of its business operations (provided that such data/information does not whether on its own or in combination with other information identify or enable identification of any Covered Person), which shall continue to constitute SMFG India Credit’s proprietary information, sole and exclusive property of SMFG India Credit and shall not be subject to any deletion, purging or other obligations applicable under this Privacy Policy.
- In case the Covered Person avails or uses any facilities / products / services or uses nor accesses SMFG India Credit website / mobile application / digital platforms, additional terms and conditions governing such facilities/products/services or the manner of usage of application including collection and disclosure of Personal Information shall be applicable and to be read along with this Privacy Policy.
- SMFG India Credit will comply with all guidelines of Personal Information collection, processing, sharing, storage, usage, access and disposal as well as system / device configuration, data encryption and handling of grievances / queries in exercise of data subject rights entailed in the Aadhaar Act 2016 as mandated by UIDAI for the purpose of eKYC authentication by Aadhaar Number / Virtual ID of Aadhaar Number Holders.
The Covered Person has the right to review the Personal Information provided and correct or amend any Personal Information or sensitive personal and financial information if found inaccurate by contacting SMFG India Credit at [email protected]