Consent Management Policy
AYAAN FINSERV INDIA PRIVATE LIMITED
Document No.: AFI/CMP/01/2026
Version: 1.0
Policy Owner: Compliance Department
Approved By: Board of Directors
Review Frequency: Annual or as required by applicable laws and regulatory directions.
1. Purpose
This Consent Management Policy establishes the governance framework for obtaining, recording,
managing, reviewing, storing, sharing, and withdrawing customer consent for the collection,
processing, use, disclosure, and retention of personal data by Ayaan Finserv India Private Limited.
The policy ensures that personal data is processed lawfully, fairly, transparently, and in
compliance with applicable laws while protecting customer privacy and confidentiality.
2. Scope
This policy applies to all personal data processed by the company through physical or digital
channels and is binding upon:
- Directors and Employees
- Customers and Prospective Customers
- Co-applicants and Guarantors
- Lending Service Providers (LSPs)
- Direct Selling Agents (DSAs)
- Business Correspondents
- Collection Agencies
- Technology Service Providers
- Vendors and Outsourcing Partners
- Any entity processing personal data on behalf of the Company
Applicable across:
- Website
- Mobile Application
- Customer Portal
- Branch Offices
- Call Centres
- APIs
- Other Digital Platforms
3. Regulatory Framework
This policy complies with:
- Digital Personal Data Protection Act, 2023
- Information Technology Act, 2000
- RBI Digital Lending Guidelines
- RBI KYC Master Direction
- RBI Fair Practices Code
- RBI Outsourcing Guidelines
- Other applicable RBI Circulars and Directions
4. Consent Principles
Customer consent must be:
- Freely Given
- Specific
- Informed
- Unambiguous
- Purpose Limited
- Revocable
- Auditable
The company shall not rely on implied consent, silence, inactivity, or pre-selected checkboxes.
5. Collection of Consent
Consent shall be obtained before processing personal data for:
- Customer onboarding
- Loan application processing
- KYC verification
- Credit bureau enquiries
- Bank account verification
- Digital agreements
- Electronic mandates
- Loan servicing
- Customer support
- Fraud prevention
- Risk management
- Regulatory reporting
- Marketing communications (with separate optional consent)
Marketing consent shall always be independent and optional.
6. Customer Information Notice
Before obtaining consent, customers shall be informed about:
- Company identity
- Purpose of data collection
- Categories of personal data collected
- Data sharing entities
- Data retention period
- Customer rights
- Withdrawal procedure
- Grievance Officer details
7. Mobile Application Permissions
The company follows the principle of Data Minimisation.
The company shall not access or collect:
- Contact List
- SMS Messages
- Call Logs
- Photo Gallery
- Videos
- Audio Recordings
- Microphone
- Location Data
- Device Storage
unless:
- Required for legitimate business purposes
- Permitted under applicable law
- Clearly disclosed
- Supported by explicit customer consent
Customer data shall never be used for intimidation, harassment, or
unauthorized disclosure.
8. Consent Records
The company shall securely maintain records containing:
- Customer Identification Number
- Consent Reference Number
- Purpose of Consent
- Date & Time
- Authentication Method
- Version of Consent Notice
- Consent Status (Active/Withdrawn/Expired)
These records shall be retained for audit and regulatory requirements.
9. Withdrawal of Consent
Customers may withdraw optional consent through:
- Mobile Application
- Website
- Customer Support
- Email
- Written Request
Withdrawal does not affect:
- Previous lawful processing
- Legal obligations
- Contractual obligations
- Fraud prevention
- Loan servicing and recovery activities
10. Data Sharing
Personal data may be shared with:
- Reserve Bank of India
- Credit Information Companies
- Banks
- Payment System Participants
- Lending Service Providers
- Collection Agencies
- Government Authorities
- Courts & Tribunals
- Law Enforcement Agencies
- Other legally authorized entities
Third parties must maintain confidentiality and implement appropriate security
controls.
11. Information Security
The company shall implement:
- Encryption
- Role-Based Access Control
- Multi-Factor Authentication
- Secure Application Architecture
- Audit Logging
- Vulnerability Assessments
- Penetration Testing
- Security Incident Response Procedures
- Backup & Disaster Recovery Mechanisms
12. Roles and Responsibilities
Responsible parties include:
- Board of Directors
- Senior Management
- Compliance Department
- Information Security Team
- Business Units
- Employees
13. Monitoring and Audit
Periodic reviews shall include:
- Consent Collection Practices
- Consent Records
- Audit Trails
- Third-Party Compliance
- Data Processing Activities
- Customer Complaints
Material observations shall be reported to Senior Management and the Board.
14. Non-Compliance
Unauthorized collection, access, disclosure, processing, or misuse of personal
data may result in:
- Disciplinary Action
- Employment Termination
- Contractual Remedies
- Legal Proceedings
15. Policy Review
The policy shall be reviewed:
- At least annually
- Whenever there is a material change in:
- Applicable laws
- Regulatory requirements
- Business operations
- Technology
- Risk profile
Annexure A – Consent Matrix
| Processing Activity |
Consent Requirement |
| Loan Application & Processing |
Mandatory |
| KYC Verification |
Mandatory |
| Credit Bureau Enquiry |
Mandatory |
| Bank Account Verification |
Mandatory |
| e-Sign & Digital Agreement |
Mandatory |
| Loan Servicing Communications |
Mandatory |
| Collection Communications |
Mandatory |
| Marketing SMS |
Optional |
| Promotional Emails |
Optional |
| WhatsApp Promotional Messages |
Optional |
| Cross-selling of Products |
Optional |