Consent Management Policy

AYAAN FINSERV INDIA PRIVATE LIMITED

Document No.: AFI/CMP/01/2026
Version: 1.0
Policy Owner: Compliance Department
Approved By: Board of Directors
Review Frequency: Annual or as required by applicable laws and regulatory directions.
1. Purpose

This Consent Management Policy establishes the governance framework for obtaining, recording, managing, reviewing, storing, sharing, and withdrawing customer consent for the collection, processing, use, disclosure, and retention of personal data by Ayaan Finserv India Private Limited.

The policy ensures that personal data is processed lawfully, fairly, transparently, and in compliance with applicable laws while protecting customer privacy and confidentiality.

2. Scope

This policy applies to all personal data processed by the company through physical or digital channels and is binding upon:

  • Directors and Employees
  • Customers and Prospective Customers
  • Co-applicants and Guarantors
  • Lending Service Providers (LSPs)
  • Direct Selling Agents (DSAs)
  • Business Correspondents
  • Collection Agencies
  • Technology Service Providers
  • Vendors and Outsourcing Partners
  • Any entity processing personal data on behalf of the Company

Applicable across:

  • Website
  • Mobile Application
  • Customer Portal
  • Branch Offices
  • Call Centres
  • APIs
  • Other Digital Platforms
3. Regulatory Framework

This policy complies with:

  • Digital Personal Data Protection Act, 2023
  • Information Technology Act, 2000
  • RBI Digital Lending Guidelines
  • RBI KYC Master Direction
  • RBI Fair Practices Code
  • RBI Outsourcing Guidelines
  • Other applicable RBI Circulars and Directions
4. Consent Principles

Customer consent must be:

  • Freely Given
  • Specific
  • Informed
  • Unambiguous
  • Purpose Limited
  • Revocable
  • Auditable

The company shall not rely on implied consent, silence, inactivity, or pre-selected checkboxes.

5. Collection of Consent

Consent shall be obtained before processing personal data for:

  • Customer onboarding
  • Loan application processing
  • KYC verification
  • Credit bureau enquiries
  • Bank account verification
  • Digital agreements
  • Electronic mandates
  • Loan servicing
  • Customer support
  • Fraud prevention
  • Risk management
  • Regulatory reporting
  • Marketing communications (with separate optional consent)

Marketing consent shall always be independent and optional.

6. Customer Information Notice

Before obtaining consent, customers shall be informed about:

  • Company identity
  • Purpose of data collection
  • Categories of personal data collected
  • Data sharing entities
  • Data retention period
  • Customer rights
  • Withdrawal procedure
  • Grievance Officer details
7. Mobile Application Permissions

The company follows the principle of Data Minimisation.

The company shall not access or collect:

  • Contact List
  • SMS Messages
  • Call Logs
  • Photo Gallery
  • Videos
  • Audio Recordings
  • Microphone
  • Location Data
  • Device Storage

unless:

  • Required for legitimate business purposes
  • Permitted under applicable law
  • Clearly disclosed
  • Supported by explicit customer consent

Customer data shall never be used for intimidation, harassment, or unauthorized disclosure.

8. Consent Records

The company shall securely maintain records containing:

  • Customer Identification Number
  • Consent Reference Number
  • Purpose of Consent
  • Date & Time
  • Authentication Method
  • Version of Consent Notice
  • Consent Status (Active/Withdrawn/Expired)

These records shall be retained for audit and regulatory requirements.

9. Withdrawal of Consent

Customers may withdraw optional consent through:

  • Mobile Application
  • Website
  • Customer Support
  • Email
  • Written Request

Withdrawal does not affect:

  • Previous lawful processing
  • Legal obligations
  • Contractual obligations
  • Fraud prevention
  • Loan servicing and recovery activities
10. Data Sharing

Personal data may be shared with:

  • Reserve Bank of India
  • Credit Information Companies
  • Banks
  • Payment System Participants
  • Lending Service Providers
  • Collection Agencies
  • Government Authorities
  • Courts & Tribunals
  • Law Enforcement Agencies
  • Other legally authorized entities

Third parties must maintain confidentiality and implement appropriate security controls.

11. Information Security

The company shall implement:

  • Encryption
  • Role-Based Access Control
  • Multi-Factor Authentication
  • Secure Application Architecture
  • Audit Logging
  • Vulnerability Assessments
  • Penetration Testing
  • Security Incident Response Procedures
  • Backup & Disaster Recovery Mechanisms
12. Roles and Responsibilities

Responsible parties include:

  • Board of Directors
  • Senior Management
  • Compliance Department
  • Information Security Team
  • Business Units
  • Employees
13. Monitoring and Audit

Periodic reviews shall include:

  • Consent Collection Practices
  • Consent Records
  • Audit Trails
  • Third-Party Compliance
  • Data Processing Activities
  • Customer Complaints

Material observations shall be reported to Senior Management and the Board.

14. Non-Compliance

Unauthorized collection, access, disclosure, processing, or misuse of personal data may result in:

  • Disciplinary Action
  • Employment Termination
  • Contractual Remedies
  • Legal Proceedings
15. Policy Review

The policy shall be reviewed:

  • At least annually
  • Whenever there is a material change in:
    • Applicable laws
    • Regulatory requirements
    • Business operations
    • Technology
    • Risk profile
Annexure A – Consent Matrix
Processing Activity Consent Requirement
Loan Application & Processing Mandatory
KYC Verification Mandatory
Credit Bureau Enquiry Mandatory
Bank Account Verification Mandatory
e-Sign & Digital Agreement Mandatory
Loan Servicing Communications Mandatory
Collection Communications Mandatory
Marketing SMS Optional
Promotional Emails Optional
WhatsApp Promotional Messages Optional
Cross-selling of Products Optional