Privacy Policy
How Loan Resolution India collects, processes, encrypts, and protects borrower identity, sensitive debt liabilities, and financial dispute records under the Digital Personal Data Protection Act, 2023.
We recognize that individuals seeking debt resolution, loan restructuring, or protection against recovery harassment entrust us with highly confidential personal and financial records. We adhere to the strictest standards of data confidentiality, professional privilege, and non-disclosure under Indian law.
1. Fiduciary Identification & Scope
This Privacy Policy applies to the website, digital portals, mobile interfaces, communication channels, and consultation intake forms operated by Loan Resolution India ("We", "Us", "Our", or "Company"), an independent debt resolution and borrower rights consultancy having its corporate and registered office at:
For the purposes of the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000, Loan Resolution India acts as the Data Fiduciary in respect of the personal data you provide as a Data Principal.
2. Key Legal Definitions
- "Data Principal": The individual borrower or guarantor to whom the personal data relates.
- "Data Fiduciary": Any person or entity that determines the purpose and means of processing personal data (Loan Resolution India).
- "Personal Data": Any data about an individual who is identifiable by or in relation to such data, including name, phone number, email address, and identification numbers.
- "Sensitive Financial Data": Information pertaining to loan accounts, credit card defaults, bank statements, CIBIL/Experian credit records, income tax returns, salary slips, and legal demand notices.
- "Processing": A wholly or partly automated operation or set of operations performed on digital personal data, such as collection, recording, organisation, structuring, storage, adaptation, retrieval, consultation, use, disclosure, or erasure.
3. Categories of Personal & Financial Data Collected
In order to evaluate debt distress, compute One-Time Settlement (OTS) viability, issue legal anti-harassment containment notices, and coordinate with empanelled advocates, we collect the following classes of data:
A. Direct Identification & Contact Information
- Personal Identity: Full legal name, gender, date of birth, marital status, and permanent/current residential address.
- Communication Channels: Primary mobile telephone number, alternate contact number, WhatsApp handle, and personal email address.
- Government Identifiers (KYC): Permanent Account Number (PAN) and masked Aadhaar card (only the last 4 digits are processed, strictly adhering to UIDAI guidelines prohibiting raw biometric retention).
B. Financial Liability & Banking Records
- Loan Portfolio Details: Name of creditor banks, NBFCs, fintech loan applications, loan account numbers, sanctioned principal, current outstanding liability, and date of default / NPA classification.
- Income & Cash Flow Documents: Salary pay-slips, profit and loss statements, Form 16 / ITR records, bank account statements for the preceding 6 to 12 months, and proof of income disruption (e.g., job loss letter, medical emergency bills).
- Credit Bureau Records: Credit Information Reports (CIR) from authorized Credit Information Companies (CIBIL TransUnion, Experian, CRIF High Mark, Equifax) provided voluntarily by you.
C. Legal Notices & Creditor Correspondence
- Statutory notices issued under Section 13(2) and Section 13(4) of the SARFAESI Act, 2002.
- Notices issued under Section 14 of the SARFAESI Act from District Magistrates (DM) or Chief Metropolitan Magistrates (CMM).
- Summons and plaints before the Debt Recovery Tribunal (DRT) or Debt Recovery Appellate Tribunal (DRAT).
- Demand notices and summons under Section 138 of the Negotiable Instruments Act, 1881 (cheque bounce) or Section 25 of the Payment and Settlement Systems Act, 2007 (NACH bounce).
- Arbitration notices, arbitration claims, or interim awards under the Arbitration and Conciliation Act, 1996.
D. Recovery Agent Harassment Evidence
- Call recordings, SMS messages, and WhatsApp transcripts documenting coercive collection tactics, abusive language, or unauthorized third-party contact.
- Photographs, CCTV footage, or visitor logs documenting unannounced visits by recovery agents outside permitted hours (before 08:00 AM or after 07:00 PM).
4. Lawful Purpose & Grounds for Processing
Under Section 6 of the DPDP Act 2023, personal data is processed solely on the basis of your informed, specific, unambiguous, and revocable consent for explicit purposes:
- Debt Restructuring & Assessment: Analyzing liability ratios, income eligibility, and cash flow constraints to formulate sustainable repayment or One-Time Settlement (OTS) proposals.
- Issuing Containment Notices: Drafting and dispatching formal intimation letters to creditor banks, NBFCs, and recovery desks citing RBI Fair Practices Codes to halt harassment and route correspondence through your authorized consultancy desk.
- Facilitating Empanelled Advocate Engagement: Enabling authorized independent advocates to draft replies to statutory demand notices (e.g., representations under Section 13(3A) SARFAESI) or prepare pleadings for DRT/High Court proceedings.
- Membership Program Administration: Enrolling you into our Borrower Protection Membership (₹499 one-time program fee), generating automated receipts, and securing your file desk.
- Regulatory & Legal Inquiries: Answering lawful requisitions issued by statutory regulatory bodies or judicial authorities under Indian law.
5. Third-Party Disclosures & Non-Sale Warranty
Loan Resolution India NEVER sells, rents, commercializes, or trades your personal, contact, or financial information to third-party telemarketing companies, loan lead distributors, credit card promoters, or data brokerage firms.
Your information is shared strictly on a need-to-know basis with authorized entities:
- Empanelled Legal Counsels: Licensed practicing advocates enrolled with State Bar Councils engaged to draft formal legal responses or represent you before judicial forums under separate Vakalatnama.
- Payment Gateway Partners: Razorpay Software Private Limited is our authorized payment processor for fee transactions. All payment processing conforms to PCI-DSS Level 1 compliance; we never store your credit card CVV or net-banking passwords on our servers.
- Lenders & Creditors (Upon Written Authorization): Submitting settlement proposals and financial justification letters directly to your designated bank's Stressed Assets Resolution Branch (SARB) or OTS Committee.
- Statutory Authorities: Where mandated by a valid judicial warrant, court order, or formal summons issued under the Code of Criminal Procedure / Bharatiya Nagarik Suraksha Sanhita.
6. Data Storage & Sovereign Localization
In full compliance with Reserve Bank of India (RBI) directives on the storage of payment system data and the DPDP Act 2023, all electronic borrower records, financial files, and database backups are housed exclusively on secure server infrastructure physically located within the territorial boundaries of India (Mumbai / Pune / Delhi NCR cloud availability zones).
7. Bank-Grade Technical & Organizational Safeguards
We deploy robust electronic, procedural, and administrative safeguards designed to withstand unauthorized penetration and data exfiltration:
- Cryptographic Standards: 256-bit Advanced Encryption Standard (AES-256) for data at rest, and Transport Layer Security (TLS 1.3) with SHA-256 signatures for all data in transit across our digital portals.
- Role-Based Access Control (RBAC): Only senior debt analysts and assigned legal case managers assigned to your file have credentialed access to view your financial attachments.
- Audit Logging & Access Trails: Every viewing, download, or transmission of borrower KYC or bank notices is logged with an immutable timestamp and operator ID.
- Non-Disclosure Agreements: All operational personnel, paralegals, and empanelled advocates execute binding confidentiality covenants prior to accessing client records.
8. Data Retention & Cryptographic Disposal Schedule
We retain personal and financial data only for as long as is necessary to accomplish the stated purpose of debt resolution, or to meet statutory limitation periods under Indian law:
| Data Category | Retention Duration | Statutory Justification & Action |
|---|---|---|
| Active Case Records & Bank Notices | Duration of active resolution engagement + 3 years from No Dues Certificate (NDC) release | Limitation Act, 1963 for defending against post-settlement creditor claims or residual disputes. |
| Financial Invoices & Razorpay Transactions | 7 fiscal years from the date of billing | Mandatory statutory retention under the Companies Act, 2013 and Goods and Services Tax (GST) Act. |
| Unconverted Inquiry Leads | 90 calendar days from initial submission | Purged automatically from active CRM if borrower decides not to proceed with membership. |
| Harassment Call Recordings & Evidence | 1 year post-closure of grievance with Banking Ombudsman or Police | Retained for regulatory and evidentiary proof, then destroyed via secure cryptographic wipe. |
9. Your Rights as a Data Principal under DPDP Act 2023
As a Data Principal residing in India, you enjoy comprehensive, legally enforceable rights under Chapter III of the DPDP Act 2023:
- Right to Access Summary (Section 11): You may request a plain-language summary of all personal data held by us and the identity of any third parties (e.g. empanelled lawyers) with whom it has been shared.
- Right to Correction & Completion (Section 12): You may request correction of inaccurate, outdated, or incomplete financial data in your file.
- Right to Erasure / Deletion (Section 12): You may instruct us to permanently delete your data when the debt resolution mandate has finished, subject to legal and taxation retention mandates.
- Right to Withdraw Consent (Section 6(4)): You may withdraw your consent to data processing at any point by writing to our Grievance Desk. Withdrawal of consent does not affect the lawfulness of processing done prior to the withdrawal, but may require discontinuation of resolution advisory services.
- Right of Grievance Redressal (Section 13): You have an absolute right to have any data protection dispute addressed by our designated Grievance Officer within statutory timelines.
- Right to Nominate (Section 14): You may nominate an individual who shall exercise your data principal rights in the unfortunate event of your death or permanent medical incapacity.
10. Protection of Children & Vulnerable Individuals
Our services and platforms are strictly reserved for individuals aged 18 years and older who possess the legal capacity to enter into binding credit contracts under the Indian Contract Act, 1872. We do not knowingly solicit, collect, or process personal data from minors. Any record inadvertently collected from a minor will be purged immediately upon notification.
11. Personal Data Breach Management
In the event of an identified, credible personal data breach that impacts the security or integrity of your personal information, Loan Resolution India will:
- Notify the Data Protection Board of India in the form and manner prescribed under the DPDP Rules.
- Promptly intimate each affected Data Principal via registered email or SMS, detailing the nature of the breach, potential consequences, and remedial measures deployed.
12. Grievance Redressal Officer & Statutory Inquiries
In compliance with Section 13 of the DPDP Act 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the particulars of our appointed Grievance Officer are:
All data protection inquiries and formal requests will receive an initial acknowledgment within 24 hours and a conclusive resolution within 15 calendar days.