CredOnTime

Privacy Policy

PREAMBLE

Chand Capital Services Ltd ("the Company"), recognising the critical role of digital platforms, Loan Service Providers (LSPs), Digital Lending Applications (DLAs), and technology infrastructure in contemporary financial intermediation, adopts this Credit Policy covering digital lending requirements in alignment with the Reserve Bank of India (Non-Banking Financial Companies – Credit Facilities) Directions, 2025, RBI/DOR/2025-26/347DOR.CRE.REC.266/07-01-008/2025-26 dated November 28, 2025 or any successions thereof. The Company acknowledges that digital lending must be conducted responsibly, transparently, securely and with full respect for the rights, dignity and privacy of customers.

This Policy sets out the governance structure, operating framework, technological safeguards, data governance system, cyber-hygiene standards, consent architecture and compliance responsibilities applicable to all digital lending activities undertaken directly by the Company or through LSPs or DLAs acting on its behalf.

PURPOSE AND SCOPE

The purpose of this Policy is to govern the entire digital lending lifecycle of the Company, covering every digital interface, platform, technology, workflow, outsourced service, data flow and process that facilitates or supports lending activities. The Policy applies to digital onboarding of customers, KYC verification, loan application processing, credit assessment, disbursement, servicing, collections, grievance redressal, and closure.

It covers all relationships with LSPs and DLAs, whether customer-facing or backend-focused, and extends to all digital systems owned, rented or accessed by the Company. Every employee, officer, authorised representative, outsourced agent, service provider, or partner utilising digital systems in connection with the Company's lending operations shall adhere strictly to this Policy.

GOVERNANCE FRAMEWORK AND RBI-COMPLIANT STRUCTURE

The Company adopts a governance structure ensuring that digital lending operations remain fully compliant with RBI's aforesaid Master Direction. All digital processes shall remain under the control, supervision and monitoring of the Company, and no digital activity shall dilute or transfer the Company's regulatory obligations.

The Risk Management function shall conduct periodic reviews of digital processes, security systems, partner integrations, and data-handling practices to ensure continuous compliance.

The Board shall receive periodic reports describing the performance of digital lending channels, technology risks, customer grievances, digital fraud patterns, and compliance indicators.

DISCLOSURES TO BORROWERS

The Company shall ensure that digitally signed documents (on the letter head of the NBFC) viz., KFS, summary of loan product, sanction letter, terms and conditions, account statements, privacy policies of the NBFC / LSP with respect to storage and usage of borrowers' data, etc. shall automatically flow to the borrower on the registered and verified email / SMS upon execution of the loan contract / transactions.

In case of a loan default, when a recovery agent is assigned for recovery or there is a change in the recovery agent already assigned, the particulars of such recovery agent authorised to approach the borrower for recovery shall be communicated to the borrower through email / SMS before the recovery agent contacts the borrower for recovery.

LOAN DISBURSAL, SERVICING AND REPAYMENT

The Company shall ensure that digitally signed documents (on the letter head of the NBFC) viz., KFS, summary of loan product, sanction letter, terms and conditions, account statements, privacy policies of the NBFC / LSP with respect to storage and usage of borrowers' data, etc. shall automatically flow to the borrower on the registered and verified email / SMS upon execution of the loan contract / transactions.

In case of a loan default, when a recovery agent is assigned for recovery or there is a change in the recovery agent already assigned, the particulars of such recovery agent authorised to approach the borrower for recovery shall be communicated to the borrower through email / SMS before the recovery agent contacts the borrower for recovery.

COOLING-OFF PERIOD

The borrower shall be given an explicit option to exit a digital loan by paying the principal and the proportionate APR without any penalty during an initial "cooling-off period". The cooling off period shall be 3 days. For borrower continuing with the loan even after cooling-off period, pre-payment shall continue to be allowed as per Reserve Bank of India (Non-Banking Financial Companies - Responsible Business Conduct) Directions, 2025.

The Company may retain a reasonable one-time processing fee, if the customer exits the loan during the cooling-off period. This, if applicable, shall be disclosed to the customer upfront in KFS.

DATA PRIVACY, SECURITY AND STORAGE

All matters relating to the collection, use, processing, security, and storage of data shall be governed by the Company's Privacy Policy, as amended from time to time. The Company shall implement appropriate technical and organizational measures to safeguard data against unauthorized access, disclosure, alteration, or loss. Such data handling practices shall at all times be carried out in compliance with applicable laws, regulations, and regulatory directions in force, and in accordance with the provisions and standards prescribed under the Company's Privacy Policy.

OVERSIGHT OF LSPS, DLAS AND OUTSOURCED TECHNOLOGY PARTNERS

The Company shall enter into comprehensive service-level agreements with every LSP, DLA or outsourced partner. The agreements shall contain detailed provisions on confidentiality, data use, cybersecurity controls, liability, audit rights, customer conduct, and termination rights.

The Company shall periodically audit the functioning of LSPs and DLAs, review data access logs, inspect cybersecurity safeguards, and examine their adherence to customer-protection obligations.

The Company shall periodically audit the functioning of LSPs for the loan portfolios originated with the support of them.

No DLA or LSP shall use the Company's name, branding or license without written authorisation.

GRIEVANCE REDRESSAL

If any complaint lodged by the borrower against the Company or the LSP engaged by the Company is rejected wholly or partly by the Company, or the borrower is not satisfied with the reply; or the borrower has not received any reply within 30 days of receipt of complaint by the Company, the said borrower can send a physical complaint to "Centralised Receipt and Processing Centre, 4th Floor, Reserve Bank of India, Sector -17, Central Vista, Chandigarh - 160017" as per the grievance redressal mechanism prescribed by the Reserve Bank.

REVIEW, AMENDMENTS AND ONGOING COMPLIANCE

This Policy shall be reviewed annually or sooner in response to changes in RBI provisions, cybersecurity notifications, technology evolution or operational updates. Any revision shall require approval of the Board of Directors and shall thereafter be communicated across all operational and digital channels.

Introduction

CredOnTime is a digital lending brand of Chand Capital Services Ltd (CIN: U74899DL1995PLC072509), a Non-Banking Financial Company registered with the Reserve Bank of India (Certificate of Registration No. 14.01556), having its registered office at [[LEGAL-TBD]]. All loans offered on the CredOnTime platform (credontime.com) are sanctioned and disbursed by Chand Capital Services Ltd. In this Policy, “the Company”, “we” or “us” refers to Chand Capital Services Ltd operating the CredOnTime platform.

This Privacy Policy outlines practices in relation to storage, use, processing, and disclosure of personal data accessed via our website (“Platform”). We are committed to protecting your personal data. By providing consent, you acknowledge we will collect, store, use, and disclose personal data in accordance with this Policy.

The Data We Collect About You

We collect personal data including:

  • Identity Data – name, DOB, marital status, gender, educational qualifications, employment status, ID documents, photographs
  • Profile Data – username, password, purchases, preferences
  • Contact Data – phone, email, address
  • Financial Data – bank account details, statements, tax details, income
  • Financial Information – as defined under RBI Account Aggregator Directions
  • Transaction Data – details of transactions through Platform
  • Credit Data – credit information and scores from credit information companies
  • Marketing and Communications Data
  • Technical Data – IP address, browser type, device info
  • Usage Data – how you use the Services
  • Health Data – health parameters from scans
  • SMS Data – sender names, body, received time

We do not access mobile phone resources except as disclosed. We may access camera, microphone, location solely for onboarding/KYC after explicit consent.

How We Collect Data

  • Information you provide us – Identity, Profile, Contact, Financial Data when using Services
  • Information we collect automatically using cookies
  • Information from third parties – account aggregators, credit information companies, analytics providers, advertising networks

How We Use Your Personal Data

We use your personal data to:

  • Register you as user and create account
  • Verify identity
  • Provide Services
  • Manage our relationship
  • Conduct KYC compliance
  • Authenticate transactions
  • Administer and protect our business
  • Deliver content
  • Send communications via SMS/phone/WhatsApp
  • Monitor trends and improve our business
  • Perform obligations and enforce Terms
  • Undertake marketing and advertise products
  • Carry credit checks and screening
  • Detect fraud and money laundering
  • Investigate illegal activities
  • Address grievances
  • Detect and recover from cybersecurity incidents
  • Ensure compliance with applicable laws

We may share your information with lending partners as we act as a Loan Service Provider (LSP). We share Credit Data with third parties only with your authorization.

How We Share Your Personal Data

Information may be shared with group companies or third parties including financial institutions, vendors, service providers, business partners. We may share where required by law, court, government agency, or authority.

Data Security

We implement appropriate security measures to protect personal data from unauthorised access, following technology standards prescribed by applicable laws.

Data Retention and Destruction

Personal data will continue to be stored as required or permitted by applicable laws. Upon completion of retention period, we shall delete or destroy or anonymise the data.

Your Legal Rights

You may have rights to review and correct personal data, revoke or deny consent, or request erasure. Write to the Grievance Officer to exercise these rights.

Transfer of Personal Data

All personal data is only stored on systems located within India. We do not transfer personal data to any third country.

Links to Third Party Websites

Our Services may contain links to third party websites. We do not accept responsibility for their privacy policies.

Cookies

We use cookies and tracking technologies to distinguish you from other users and remember preferences. Most devices can prevent cookies from being sent.

Business Transitions

In event of merger, acquisition, or sale of assets, your personal data may be among assets transferred.

Change in Privacy Policy

We may amend this Policy from time to time at our sole discretion. Changes will be posted on this page.

Grievance Officer

Name: [[LEGAL-TBD]]

Address: [[LEGAL-TBD]]

Email: [[LEGAL-TBD]]

Tel No: [[LEGAL-TBD]]

Customer Care: [[LEGAL-TBD]]  |  Complaint Helpline: [[LEGAL-TBD]]

Chand Capital Services Ltd