Privacy Policy
This Privacy Policy explains how Better Finansh Solutions Private Limited, operating under the brand Finansh, collects, uses, shares, protects, retains and deletes personal data when you visit our Website, contact us or use our borrowing-advisory and application-support Services.
This Policy is a privacy notice, not a request for blanket consent. Merely visiting the Website or accepting our general Terms does not authorise Finansh to collect a loan file, obtain protected financial data, record a call, submit information to a Lender or send promotional communications. Where consent or specific authority is required, we ask for it separately at the relevant stage.
Please read this Policy together with our Website and General Service Terms, Copyright & Intellectual Property Notice and How Finansh Works disclosure.
Index
- Who we are
- Scope
- Applicable law and DPDP transition
- Personal data we may collect
- Where information comes from
- Why we use personal data
- Lawful processing and your choices
- Stage-specific notices and permissions
- Our in-house and no-agent model
- No sale, rental or partner marketing
- Who may receive personal data
- Lenders are independent decision-makers
- Website cookies, analytics and external services
- Internal decision-support, artificial intelligence and public answer engines
- Storage location and overseas processing
- How long we keep information
- Security
- Security incidents and personal data breaches
- Your privacy rights and service choices
- How to make a privacy request
- Children
- Accuracy and your responsibilities
- External links and embedded services
- Changes to this Policy
- Privacy questions and grievances
- Contact
Important privacy facts
- You deal directly with Finansh. Our customer-facing acquisition, advisory, preliminary assessment, structuring, documentation coordination and Lender coordination are performed by Finansh directors and employees.
- We do not use downstream customer-facing agents. We do not appoint downstream marketing or channel partners, referral agents, sub-DSAs, lead generators or outsourced loan-fulfilment providers to act for Finansh. Finansh may itself have direct sourcing or channel arrangements with named Lenders.
- We do not sell or rent personal data. We do not disclose customer information to another person for that person’s marketing, referral or lead-generation activity.
- A Lender is named before submission. A general enquiry is not permission to circulate your information. We obtain or record authority for each named Lender and stated purpose before sharing an application or material personal or financial information.
- Necessary service providers have limited roles. Technology and professional service providers may support defined functions under appropriate instructions and safeguards. A selected Lender and its appointed KYC, verification, legal, technical or valuation providers operate within the Lender’s process.
- Our internal decision-support system does not make credit decisions. Any material case-specific output used in advice is reviewed by a Finansh team member. The Lender alone decides whether to lend.
- We do not train public or shared AI models on identifiable customer data. We do not use identifiable customer data or confidential customer documents to train or fine-tune a public, shared or general-purpose model, or permit a provider to do so for its own purposes.
- You have practical choices. You may ask questions, correct information, withdraw consent for future processing, stop optional communications or request deletion where continued retention is not required.
This summary helps you navigate the Policy. The complete provisions below describe the details.
1. Who we are
Better Finansh Solutions Private Limited
Corporate Identity Number: U70200PN2023PTC220377
Registered office: Office No. 807, 8th Floor, Solitaire Business Hub, Balewadi High Street, Baner, Pune - 411045, Maharashtra, India
Privacy email: [email protected]
General support email: [email protected]
Telephone: +91 87674 11297
In this Policy:
- “Finansh”, “Company”, “we”, “us” and “our” mean Better Finansh Solutions Private Limited;
- “you” and “your” mean the individual to whom personal data relates;
- “personal data” means information about an identifiable individual, including digital personal data and, where applicable, sensitive personal data or information under Indian law;
- “processing” includes collecting, recording, organising, storing, using, sharing, analysing, correcting, retrieving, deleting or otherwise handling personal data;
-
“Website” means
finansh.inand any page, form, calculator or feature that links to this Policy; and - “Lender” means a bank, non-banking financial company, housing finance company or other lawful credit provider.
For personal data that we decide to process for our own Website, advisory, administration, security and legal purposes, Finansh acts as the organisation responsible for that processing, including as a data fiduciary or body corporate where the applicable Indian law uses those terms.
Finansh is a borrowing adviser and may have direct written sourcing or service arrangements with selected Lenders. We are not a bank, non-banking financial company, housing finance company, credit information company or Lender. A Lender independently controls its credit decision and the processing it undertakes for its own lending, KYC, underwriting, fraud-prevention, regulatory and record-keeping purposes.
2. Scope
This Policy applies when personal data is processed through or in connection with:
- the Finansh website and a page, form, calculator or feature that links to this Policy;
- an enquiry, advisory call, meeting, email, SMS or WhatsApp conversation with Finansh;
- an accepted borrowing-advisory, structuring, lender-selection, application-support or execution service;
- Finansh’s internal credit-intelligence and decision-support system within our advisory process;
- a complaint, rights request, fraud report, permission request or other legal communication;
- relevant targeted business-to-business contact undertaken directly by Finansh; and
- information provided by an authorised representative for an individual, business, co-borrower, guarantor, director, promoter or other affected person.
This Policy does not govern a Lender’s independent processing, a government portal, a credit information company or an external website or service that you choose to use. Those organisations should give you their own privacy information.
Our Services are intended for adults. They are not directed to persons under 18.
3. Applicable law and DPDP transition
This Policy is designed around the Indian privacy and security requirements relevant to Finansh, including:
- the Information Technology Act, 2000 and applicable rules;
- the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, while applicable;
- applicable consumer-protection and electronic-commerce requirements;
- applicable CERT-In directions; and
- the Reserve Bank of India (Digital Lending) Directions, 2025 where a specific Lender arrangement and function bring Finansh within those Directions.
The Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 commence in phases. The Consent Manager-related tranche commences on 13 November 2026. The core private-sector notice, consent, security, breach, retention and Data Principal rights provisions relevant to this Policy are scheduled to commence on 13 May 2027.
Until a provision is legally in force, this Policy does not imply that a statutory remedy or Data Protection Board route is already available. We nevertheless use the privacy choices described here as service commitments where reasonably practicable.
When section 5(2) of the Digital Personal Data Protection Act becomes operative, we will provide the required transition notice for personal data processed on the basis of consent given before commencement, as soon as reasonably practicable.
The Act does not require blanket re-consent solely because processing began before commencement. However:
- we will not treat an unclear, invalid or unrelated historic permission as authority for a new purpose;
- we will request fresh consent or authority where the existing permission does not fairly cover the proposed processing or where law requires it; and
- you may withdraw a consent-based permission for future processing.
Where applicable, you may request a stage-specific notice in English or a language recognised in the Eighth Schedule to the Constitution through the contact route in section 20.
If another applicable law or binding Lender requirement gives you greater protection, that requirement prevails.
4. Personal data we may collect
We collect only information reasonably connected with a stated purpose. The categories depend on what you ask us to do.
4.1 Contact and profile information
This may include your name, mobile number, email address, correspondence address, preferred language and communication channel, date of birth, age confirmation, gender where relevant to a Lender product, occupation, employer, professional role and relationship to an applicant or business.
4.2 Identity and KYC information
Where needed for an authorised process, this may include PAN, proof of identity or address, photograph, signature, nationality or residency status, tax residency, incorporation or registration details, and KYC-related declarations.
We do not ask you to disclose a banking password, card PIN, CVV, UPI PIN or one-time password.
Finansh does not independently undertake Aadhaar authentication. Where a Lender’s lawful process requires identity information, we prefer a masked Aadhaar copy or another appropriate document where the process permits.
We do not collect or store biometric templates. Where a Lender or authorised KYC service requires a lawful identity-verification step, that process must be separately explained and handled through an approved channel.
4.3 Financial, credit and borrowing information
This may include income, salary, business turnover, cash flow, assets, liabilities, repayment obligations, loan statements, bank statements, tax returns, financial statements, credit history or credit-bureau information lawfully provided to us, requested facility, proposed amount, tenure, end use, preferred repayment level, existing Lender relationship, sanctions, offers and repayment information.
Accepting this Policy or our Terms does not authorise access to a credit-bureau report, Account Aggregator data, CKYC record, DigiLocker document, CERSAI-linked data, bank-account feed or another protected source. Any access occurs only through a named Lender’s lawful process, or through another role expressly permitted by law, after the required source-specific notice and recorded authority. If Finansh is not legally eligible to access a source directly, the information must be obtained by the eligible Lender or provided by you through an approved route.
4.4 Business, property and transaction information
For a business or secured facility, this may include business ownership, directors or partners, group structure, customers and suppliers, contracts, projections, project details, licences, security or collateral details, title and property documents, valuation-related information, lease information, transaction counterparties and supporting records.
4.5 Information about other people
A file may include information about a co-borrower, spouse, family member, guarantor, director, shareholder, beneficial owner, employee, tenant, seller or another person. The person providing it must have lawful authority to do so and must help us give any notice or obtain any authority required for that person.
4.6 Communications, instructions and service records
This may include emails, messages, meeting notes, call details, documents you provide, instructions, Lender selections, application status, advice and comparison records, consent and authority records, complaints, feedback and acknowledgements.
A call or meeting is recorded only after an appropriate notice and any permission required for the stated purpose. Where reasonably practicable, we offer a non-recorded way to communicate.
4.7 Website and technical information
When you use the Website, our systems and approved providers may process IP address, device and browser type, operating system, referring page, pages or links used, date and time, general location inferred from IP, cookie or similar identifier, consent choice, security event and diagnostic log.
We do not use a Finansh digital interface to access your phone contacts, call logs, telephony functions or general files and media. One-time access to a camera, microphone or location may be requested only if a specific onboarding or KYC step lawfully requires it, with an explanation and explicit permission.
4.8 Payment, accounting and compliance records
Where a customer-paid business engagement applies, we may process invoice details, GST information, payment status, official bank transaction reference and refund records. We do not need or store your UPI PIN, card PIN, CVV or online-banking password.
We may also create audit, conflict, anti-fraud, access, security, incident, legal-hold and regulatory-compliance records.
5. Where information comes from
We may receive personal data:
- directly from you;
- from a person you have validly authorised, such as a co-applicant, director, employee, accountant, advocate or other representative;
- from a named Lender or a Lender-appointed provider in relation to an authorised application;
- from a protected financial source only through a lawful, specifically authorised process;
- from public records, company filings, professional directories, government portals, Lender publications or other lawfully available sources relevant to the request;
- from a responsible business-information service provider for limited and lawful business-to-business prospecting; and
- automatically from the Website, security systems and communication infrastructure.
We do not purchase consumer loan leads or borrower files from lead generators, referral agents, sub-DSAs, loan aggregators or outsourced loan-fulfilment providers.
If we receive personal data from someone other than you, we assess the source, purpose and authority and provide notice where required and reasonably practicable.
6. Why we use personal data
We use personal data only for a stated and lawful purpose, including to:
- operate, secure, troubleshoot and improve the Website;
- respond to your enquiry and understand your borrowing requirement;
- verify identity, authority and the completeness or consistency of information;
- assess cash flow, affordability, lender fit, structure, likely policy objections and execution feasibility;
- prepare advice, comparisons, document checklists, applications, proposals and supporting analysis;
- provide internally assisted organisation and analysis subject to the safeguards in section 14;
- communicate with you about the requested Service, status, security, complaints and legal or operational notices;
- submit specified information to each named Lender that you authorise and coordinate that Lender’s process;
- interact, where necessary, with the authorised Lender and its appointed KYC, verification, legal, technical or valuation providers;
- administer a customer-paid engagement, invoice, payment, cancellation or refund;
- conduct limited and relevant Finansh business-to-business outreach;
- prevent and investigate fraud, impersonation, misuse, cybersecurity threats, unethical conduct and disputes;
- maintain evidence of notices, consent, authority, instructions, advice, compensation basis and compliance;
- comply with law, court orders, regulatory requirements, tax, audit and professional obligations;
- establish, exercise or defend a legal claim; and
- produce statistics or improve internal workflows using aggregated or irreversibly de-identified information that is not reasonably used to identify a person.
We do not use a general service enquiry as permission for unrelated advertising. We do not profile customers for sale to advertisers or disclose customer data for another person’s marketing.
7. Lawful processing and your choices
Until the relevant DPDP provisions commence, and while the SPDI Rules apply, we obtain written or electronic consent before collecting sensitive personal data or information where those Rules require it, and handle its disclosure and transfer in accordance with those Rules. A voluntary-provision ground is relied on only where it is legally available for the particular processing.
Depending on the activity and the law in force, we process personal data:
- with your free, specific, informed, unconditional, unambiguous and affirmative consent where consent is required;
- when you voluntarily provide information for a clear purpose that you have asked us to perform and have not indicated that you do not agree to that use;
- to comply with a legal, court, regulatory, fraud-prevention, security or emergency requirement; or
- on another ground expressly permitted by applicable Indian law.
We do not rely on a vague or unlimited “legitimate interests” label. We do not use pre-ticked boxes or bundle a Lender submission, call recording, optional update or protected-data access into general Website acceptance.
You may refuse information that is optional. If information is necessary for a requested assessment, KYC step, Lender application, legal requirement or security check, we explain the consequence of not providing it. We do not deny an unrelated Service merely because you refuse an optional use.
Where we rely on consent, you may withdraw it for future processing through the same interface where available or by contacting [email protected] or [email protected]. Withdrawal does not invalidate processing already lawfully completed. It may prevent us from continuing a Service that cannot reasonably be performed without the information.
8. Stage-specific notices and permissions
The full Policy does not replace a short notice at the point of collection. Depending on the journey, we use separate, recorded steps for:
- a Website enquiry and the information needed to respond;
- substantive collection of a borrowing or financial profile;
- call or meeting recording;
- each protected-data source, such as a credit bureau or Account Aggregator;
- each named-Lender submission and the relevant information or document categories;
- an optional first-party Finansh update, if offered; and
- non-essential analytics or similar cookies where consent is required.
Authority for one Lender is not authority for another. If you approve several Lenders together, the record must identify each Lender and the stated facility or purpose.
9. Our in-house and no-agent model
Finansh’s customer acquisition, borrower-facing advisory, preliminary assessment, structuring support, documentation coordination and Lender coordination are performed by Finansh’s directors and employees.
No downstream customer-facing marketing or channel partner, referral agent, sub-DSA, lead generator or outsourced loan-fulfilment provider is authorised to solicit you, advise you, collect your documents or fees, or make a representation or commitment for Finansh.
Finansh may itself have direct sourcing or channel arrangements with selected Lenders. Those arrangements do not authorise a downstream person to act for Finansh.
Necessary technology processors may support a defined system function under Finansh’s instructions. A selected Lender and its employees or appointed providers participate in the Lender’s process. These limited roles do not make them Finansh’s external sales or fulfilment team.
Treat anyone claiming to be an external Finansh customer-facing sales, advisory or loan-fulfilment agent as a possible impersonator. Verify the claim through [email protected] or +91 87674 11297 before sharing personal data, documents or money.
10. No sale, rental or partner marketing
10.1 Customer and applicant information
Finansh does not sell, rent or trade personal data.
We do not disclose customer or applicant information to a downstream marketing, channel, referral or lead-generation partner, and we do not permit a technology processor to use customer information for that provider’s own advertising.
This does not prevent:
- an authorised submission to a named Lender;
- restricted processing by a necessary service provider;
- confidential professional advice;
- a lawful disclosure; or
- processing by a Lender’s own appointed provider.
10.2 Finansh communications and business outreach
A service enquiry does not automatically enrol you in a promotional list.
Where we offer optional Finansh updates, the choice is separate and revocable. Declining or withdrawing it does not affect advisory or application support.
Finansh may directly contact a promoter or authorised business representative at professional contact details lawfully obtained from public company information, professional sources or a responsible business-information service provider, where the proposed communication is reasonably relevant to that person’s business role and lawful.
For such outreach:
- Finansh identifies itself;
- the communication is undertaken by Finansh, not an external marketing agent;
- we do not use consumer loan files, credit reports, protected financial data or private customer information for prospecting;
- we provide a practical opt-out;
- we maintain the minimum suppression record necessary to respect an opt-out; and
- we obtain consent first wherever applicable law requires it.
The availability of professional contact details does not by itself override an applicable DND preference or authorise a channel that requires registered consent. Promotional calls or messages using telecom resources are made only through routes permitted by applicable telecom commercial-communications requirements.
Service, security, grievance and legal communications may continue where reasonably necessary and permitted.
11. Who may receive personal data
We disclose the minimum information reasonably needed for the stated purpose to the following categories.
11.1 Finansh directors and employees
Access is limited according to role and need. Employees and directors are subject to confidentiality, security and acceptable-use obligations.
11.2 Technology and operational processors
Carefully selected providers may support hosting, cloud storage, CRM, email, communications, scheduling, analytics, document management, e-signature, security, backup, customer support, accounting or approved enterprise AI functions. They must act only for a defined purpose under appropriate contractual, access, confidentiality, security, retention and deletion controls.
An email, analytics, hosting or communications provider is not authorised to advise a borrower, choose a Lender, collect a Finansh fee or fulfil a loan for Finansh.
We do not permit an undisclosed third party to collect a loan application, KYC file or protected financial dataset through a Finansh-branded digital interface. If a third party directly collects such information through a future Finansh interface, we will identify it and its purpose at that interface and update this Policy before collection.
11.3 Named Lenders
We share an application or material personal or financial information only with each Lender you have authorised for the stated facility or purpose, unless disclosure is required by law. The Lender then processes the information under its legal duties, regulatory requirements and privacy terms.
11.4 Lender-appointed providers
A Lender may appoint KYC, verification, legal, technical, valuation, document, security or other providers for its process. We may coordinate with them where necessary after the Lender submission. They act within the Lender’s process and are not Finansh marketing or fulfilment agents.
11.5 Professional advisers
Advocates, chartered accountants, auditors, company secretaries, insurers, cybersecurity specialists and other professional advisers may receive restricted information where reasonably necessary for confidential advice, audit, security, insurance, a complaint or a legal claim.
11.6 Authorities and legal recipients
We may disclose information where reasonably necessary to comply with applicable law, a court or tribunal order, a regulator, law-enforcement request, tax or audit requirement, or to prevent, investigate or report fraud, cybercrime, threats or unlawful conduct. We assess the validity and scope of a request where permitted.
11.7 Corporate change
If Finansh undergoes a genuine merger, reconstruction, investment, acquisition or transfer of business, restricted information may be reviewed under confidentiality and security controls. Any transfer of responsibility for personal data will be subject to applicable notice, consent and legal requirements. A corporate change is not a sale of customer data for advertising.
12. Lenders are independent decision-makers
A Lender decides whether to accept an application, what additional information to request, whether to obtain a credit report or verification, the price and conditions, and how long it must keep regulated records. Finansh cannot direct the Lender to erase a record that the Lender must retain.
Withdrawing authority from Finansh stops future Finansh sharing to the extent possible. It does not reverse a lawful submission already made or automatically withdraw the application from the Lender. We will help identify the Lender’s contact route where reasonably possible.
13. Website cookies, analytics and external services
13.1 Technologies we use
The Website may use:
- strictly necessary cookies or storage for security, load balancing, session continuity, consent choices and essential functions;
- limited analytics technologies to understand Website use, page performance and technical problems; and
- anti-spam, diagnostics and security technologies.
Google Tag Manager may be used to manage Website tags. The cookie-preference panel identifies every non-essential analytics or similar tool active in the live Website configuration and is the most current operational disclosure.
Our configuration is designed not to send names, contact details, PAN, financial statements, loan documents or substantive form contents to these analytics tools. Sensitive input fields must be masked or excluded. Session-replay-style analytics must not be deployed on a customer document-upload area, non-public case workspace or substantive case-analysis interface.
13.2 Your analytics choice
Non-essential analytics remain disabled until you make an affirmative choice.
Refusing non-essential analytics must not prevent access to core public Website content. You may change your preference using the Website’s cookie-preference control. Browser settings may also block or delete cookies, although blocking strictly necessary storage may affect a requested function.
If a non-essential tag appears to operate contrary to your recorded choice, contact [email protected] and we will investigate.
13.3 External interactions
Scheduling, mapping, video, WhatsApp or other links may take you to an external provider. When you choose that service, it may independently receive information such as your IP address, device information, account or contact details and information you choose to submit. Review that provider’s privacy information before sending sensitive documents.
A link does not authorise the external provider to market, advise or fulfil a loan for Finansh.
13.4 No behavioural advertising using loan files
We do not use customer loan files for behavioural advertising. We do not place third-party advertising or remarketing trackers on a borrowing application unless we first update this Policy, implement the required choice and ensure that the activity is lawful.
14. Internal decision-support, artificial intelligence and public answer engines
14.1 Our internal system’s current role
Finansh’s internal credit-intelligence and decision-support system presently supports internal or adviser-assisted organisation, analysis, policy matching, comparison and review. It does not lend, underwrite, approve, sanction or reject a loan. A member of the Finansh team reviews a material case-specific recommendation before asking a customer to rely on it. The Lender remains the sole credit decision-maker.
14.2 AI safeguards
We apply the following controls:
- collect and use only information reasonably needed for the stated advisory purpose;
- restrict access to authorised personnel and approved providers;
- avoid placing confidential data in an unapproved public chatbot;
- require an approved enterprise provider to process data only under our instructions and contractual safeguards;
- do not use customer personal data or confidential financial documents to train a publicly available or shared general-purpose AI model;
- do not permit an AI provider to use that information to train its own public or shared model;
- retain internal decision-support inputs and outputs only within the applicable case or security record schedule; and
- use human review because AI and rules-based outputs may be incomplete, probabilistic or outdated.
We may use aggregated or irreversibly de-identified information to measure quality or improve internal rules and workflows where the information is not reasonably used to identify a person. We will not use identifiable customer data to develop a new model for an unrelated purpose without an appropriate notice, lawful basis and safeguards.
14.3 Public Website retrieval
Search engines and AI-assisted answer systems may retrieve publicly accessible Finansh Website pages to help a user locate, cite, summarise or understand public information, subject to our Website controls and Copyright & Intellectual Property Notice.
This limited public-content retrieval does not extend to customer files, non-public case information, restricted systems, personal data submitted through forms, confidential documents or permission to train a model on customer data.
15. Storage location and overseas processing
We select storage and processing locations according to applicable law and the relevant Lender arrangement.
Where a specific Finansh function is classified as a Lending Service Provider function under the RBI Digital Lending Directions:
- processing must follow the relevant regulated entity-Lending Service Provider agreement;
- Finansh will retain only the minimum borrower information permitted and required for that function;
- borrower data subject to the localisation rule must be stored on servers located in India; and
- if permitted processing occurs outside India, the data must be deleted from the overseas server and brought back to India within 24 hours of processing as required by those Directions.
A separate Finansh advisory file is processed only for its separately explained advisory purpose and authority. It is not treated as unrestricted authority to retain data received in a Lender-specific role.
For a function outside an applicable digital-lending arrangement, a provider may process limited information outside India only where permitted by applicable law. While the SPDI Rules apply, sensitive personal data or information is transferred only to a recipient that ensures the same level of data protection required under those Rules and where the transfer is necessary for a lawful contract or the person has consented. When the relevant DPDP provisions commence, transfers will also remain subject to any restriction or requirement notified by the Central Government. Any stricter RBI or other localisation rule prevails.
16. How long we keep information
We retain personal data only for the relevant purpose and applicable legal, contractual, security, tax, audit, grievance and claim requirements.
The periods below are default retention or review points. They are not authority to retain information indefinitely. Deletion may occur through a documented periodic review or a provider’s secure system cycle rather than at an exact minute on the final day.
We may delete information earlier where the purpose has ended and law permits. We may retain specific information longer where required by law, a Lender arrangement, a complaint, investigation, legal hold, fraud concern or legal claim.
16.1 Default schedule
- Website and ICT-system logs: logs required for cybersecurity purposes are retained securely within India for at least 180 days, or longer where another applicable requirement applies. When the corresponding DPDP requirements commence, relevant security and processing records will be retained for the required one-year period unless another law requires longer.
- Cookie-preference and consent records: retained for the life of the preference and for a reasonable audit period, generally up to 12 months after replacement or expiry.
- Enquiry that does not become an active case: reviewed after approximately 12 months without a meaningful interaction and then deleted, reduced or de-identified unless continued retention is reasonably necessary.
- Unsubmitted working case: retained while active and reviewed after approximately 24 months of inactivity, withdrawal or closure.
- Lender-submitted case, advice, authority and instruction records: normally retained for up to five years after closure of Finansh’s work or the last material activity, subject to a longer legal, Lender, complaint or claim requirement.
- Call or meeting recording: reviewed for deletion after approximately 180 days unless it remains necessary for an active case, consent evidence, complaint, investigation, quality review or legal claim.
- Customer-paid engagement, invoice, GST, payment and refund records: retained for the period required by applicable company, tax and accounting law, which may extend to eight financial years or longer where proceedings remain open.
- Complaint, fraud, conflict, incident and legal records: retained through final resolution and for the applicable limitation, regulatory or evidence period.
- Optional communication preference: retained until withdrawal. We may retain a minimal suppression record to prevent future unwanted contact.
- Business-outreach contact records: reviewed after approximately 12 months without a meaningful interaction and then deleted or reduced, while a minimal suppression record may be retained to honour an opt-out.
- Website analytics data: user-level event, interaction and session-replay data is retained only for the shortest practical period configured in the relevant tool; the active tools and current retention periods are disclosed in the cookie-preference panel.
- Internal decision-support case inputs and outputs: follow the applicable enquiry, working-case or submitted-case schedule.
- Backups: deleted information may remain temporarily in encrypted or access-restricted backups until the ordinary documented rotation cycle overwrites it. Backups are not used to restore a deleted record into ordinary business use unless required for disaster recovery or law.
16.2 Deletion and de-identification
At the end of the applicable period, we securely delete, destroy, restrict or irreversibly de-identify the information, taking account of the system and storage medium.
We require processors to follow corresponding instructions, subject to protected backup cycles and lawful retention.
When the DPDP one-year processing-record requirement becomes operative, we will retain the personal data, traffic data and processing logs required for that prescribed period even where an earlier deletion request has been made, and then delete them unless another law requires continued retention.
17. Security
We maintain reasonable technical and organisational safeguards appropriate to the nature and risk of the data. These include, as applicable:
- data minimisation and purpose-based access;
- role-based access controls and authentication;
- encryption in transit and appropriate encryption, masking, obfuscation or tokenisation at rest or in use;
- access, security and incident logs with monitoring and review;
- backups, recovery and business-continuity measures;
- secure transfer and document-sharing methods;
- confidentiality duties and staff training;
- vendor due diligence and processor contract safeguards;
- vulnerability, malware, patching and access-revocation processes;
- retention, deletion and legal-hold controls; and
- incident response, escalation and regulatory reporting procedures.
No online system is completely secure. This statement is not a waiver of our duty to use reasonable safeguards. Please report suspected impersonation, unauthorised access, misdirected documents or another security concern immediately to [email protected] or [email protected] and avoid sending a password, PIN, CVV, UPI PIN or OTP.
18. Security incidents and personal data breaches
We investigate a suspected incident, take reasonable containment and remediation steps, preserve necessary evidence and notify authorities and affected people when required.
Where the substantive DPDP breach provisions apply, we will notify affected individuals in a clear manner without delay, notify the Data Protection Board without delay as prescribed, and provide the Board’s required detailed update within 72 hours unless the Board lawfully allows more time.
Independently, specified cyber incidents must be reported to CERT-In within the applicable period, currently six hours after noticing the incident. Our provider contracts must require rapid escalation so that an external provider does not delay our own response.
An incident notice may explain what happened, relevant consequences, measures taken, protective steps you can take and how to contact us.
19. Your privacy rights and service choices
Subject to the law in force, identity verification and lawful exceptions, you may ask us to:
- confirm whether we process your personal data and provide an understandable summary;
- when the relevant DPDP right applies, provide the identities of the other Data Fiduciaries and Data Processors with whom the personal data was shared, together with a description of the data shared, subject to statutory exceptions;
- correct inaccurate or misleading information;
- complete or update incomplete or outdated information;
- erase personal data that no longer has a lawful retention purpose;
- withdraw consent for future processing where consent is the basis;
- stop optional first-party updates;
- review a decision about your privacy request;
- address a grievance; and
- record a nominee to exercise applicable rights in the event of death or incapacity once that right applies.
The DPDP Act does not create a general data-portability right. We may nevertheless provide a practical copy of customer-provided documents or available data where reasonable, secure and lawful.
We may limit or refuse a request to the extent necessary to protect another person, preserve legal privilege, prevent fraud, comply with law or a binding Lender obligation, retain security or transaction evidence, establish or defend a claim, or where the request is not reasonably verifiable. We explain the reason unless law prevents us.
20. How to make a privacy request
Email [email protected]. You may also send the request to [email protected]; a request received there remains valid and will be routed internally.
Using the subject “Privacy Request” helps us route it quickly but is not a condition for handling it. Please provide:
- your name and contact detail used with Finansh;
- the type of request;
- enough information to identify the relevant interaction or case; and
- authority evidence if you act for another person.
Do not email a new identity document, password, PIN, CVV, UPI PIN or OTP unless we specifically provide a secure and proportionate verification route. We may ask for limited identity verification and will avoid collecting more verification information than reasonably needed.
We will:
- acknowledge the request within 48 hours;
- provide a substantive response or status update as soon as reasonably practicable; and
- complete the request or issue a reasoned final response within 30 calendar days.
Where a shorter binding period applies, we follow the shorter period. A final response may explain a lawful restriction, information still required from you or a part of the request that cannot be completed. It will not leave the request open-ended without an explanation.
21. Children
The Website and Services are for persons aged 18 or older, and we do not accept borrowing applications from minors. We may process limited personal data relating to a child only where it is necessary for a lawful property, family, guardianship or related process and after obtaining verifiable parental or lawful-guardian consent, or relying on another ground expressly permitted by law, where required. We do not undertake tracking, behavioural monitoring or targeted advertising directed at children.
If we learn that a minor submitted personal data outside such a lawful purpose, we will stop the relevant processing and delete it unless retention or action is required to protect the minor, respond to a security or legal concern, or comply with law. A parent or lawful guardian may contact [email protected].
22. Accuracy and your responsibilities
Please provide accurate, current and complete information and promptly correct a material change. Do not provide another person’s data unless you have lawful authority.
Accuracy is particularly important for a credit application. A correction made in Finansh’s records does not automatically amend information already submitted to a Lender. We will help communicate a material correction to the relevant Lender where reasonably possible and authorised.
23. External links and embedded services
The Website may link to or embed content from a Lender, regulator, government portal, mapping, scheduling, messaging, video or other service. Opening or using that service may allow it to collect information independently. Review its privacy information before submitting data.
A link does not mean that Finansh controls the service or that the provider is authorised to market, sell or fulfil a loan for Finansh.
24. Changes to this Policy
The Policy published at this URL is the current public version.
A material change applies prospectively. Where reasonably required, we notify active customers through the Website or recorded contact details. We do not use a policy update to retrospectively validate an incompatible purpose. If fresh consent or authority is required, we ask for it before the new processing.
We keep an archive of prior public versions and review this Policy after a material operational or legal change, with an internal governance target of at least one review each year.
25. Privacy questions and grievances
Privacy and Grievance Contact: Aman Agarwal, Head - Business Operations
Privacy email: [email protected]
Grievance email: [email protected]
Fallback email: [email protected]
Telephone: +91 87674 11297
Postal address: Better Finansh Solutions Private Limited, Office No. 807, 8th Floor, Solitaire Business Hub, Balewadi High Street, Baner, Pune - 411045, Maharashtra, India
A privacy grievance sent to any of the three published email addresses will be handled. Using the subject “Privacy Grievance” helps routing but is not mandatory. Please include the facts, relevant dates, interaction or Lender, requested outcome and supporting information.
We will:
- acknowledge the grievance within 48 hours;
- provide an initial substantive response or status update as soon as reasonably practicable; and
- resolve it or issue a reasoned final response within 30 calendar days.
Where a shorter binding period applies, we follow the shorter period.
Where a complaint concerns a regulated Lender’s product, decision, charge or processing, you may also use that Lender’s grievance channel. If eligible after the applicable Lender process, you may use the RBI Complaint Management System. We do not imply that Finansh itself is an RBI-licensed Lender or that every complaint about Finansh falls within the RBI Ombudsman scheme.
Once the relevant DPDP complaint provisions are in force, an eligible person may escalate a complaint to the Data Protection Board after first using Finansh’s grievance process, in the manner prescribed by law. This sentence does not represent that the Board route is generally available before those provisions commence.
26. Contact
Questions about this Policy may be sent to:
Better Finansh Solutions Private Limited
Office No. 807, 8th Floor, Solitaire Business Hub
Balewadi High Street, Baner
Pune - 411045, Maharashtra, India
Privacy: [email protected]
General support: [email protected]
Telephone: +91 87674 11297