Policy 05

Data Storage and Retention Policy

How customer data is stored in India, retained for approved periods and securely destroyed.

Policy ownerInformation Security / Data Privacy
Version[INSERT VERSION]
Effective date[INSERT DATE]
Next review[INSERT DATE]
1

Objective

This public policy describes how the Company and its authorised service providers store, retain, restrict, archive and securely destroy customer data. The detailed internal retention schedule and legal-hold procedure remain controlled documents.

2

Core rules

  • collect only data necessary for a lawful, disclosed purpose;
  • store digital-lending data in India and control any permitted temporary processing outside India in accordance with RBI directions;
  • apply role-based access, logging, encryption or equivalent controls, segregation and periodic access review;
  • retain records only for an approved business / legal period, subject to legal holds;
  • ensure LSPs store only permitted minimum data required for contracted functions;
  • do not collect / store biometric data unless expressly permitted by applicable statutory directions;
  • delete, anonymise or render data irretrievable when the approved period expires.
3

Public retention schedule

Record categoryTypical triggerRetention periodDisposal method
KYC / AML and identity recordsEnd of relationship / transaction[INSERT PERIOD REQUIRED BY LAW]Secure deletion / approved archive
Loan and repayment recordsClosure / write-off / settlement[INSERT PERIOD]Secure deletion / anonymisation
Unsuccessful applicationsDecision / withdrawal[INSERT PERIOD]Secure deletion
Consent and privacy recordsWithdrawal / end of purpose[INSERT PERIOD]Audit archive then deletion
Call recordings and complaintsClosure of interaction / complaint[INSERT PERIOD]Secure deletion
Security and access logsLog creation[INSERT PERIOD]Automated deletion
BackupsBackup creation[INSERT CYCLE / PERIOD]Cryptographic / secure expiry
4

LSPs and processors

Contracts will define permitted data, location, access, retention, breach reporting, audit, return / deletion and subcontracting. On termination or completion, the provider will return or delete data except where retention is lawfully required and approved. The Company may verify deletion through certification, audit or technical evidence.

5

Data-principal request and legal hold

Requests for erasure will be assessed against statutory retention, outstanding obligations, fraud / security needs and legal claims. A legal hold suspends routine deletion for relevant records until released by Legal / Compliance. The requester will receive an appropriate response through [INSERT PRIVACY GRIEVANCE CHANNEL].

6

Incident response

Suspected loss, unauthorised access, disclosure or alteration must be reported immediately to [INSERT INCIDENT EMAIL / PHONE]. The Company will contain, investigate, document and remediate the incident and make notifications to affected persons and authorities where applicable.

Regulatory basis

RBI Digital Lending Directions, 2025 data collection / storage / privacy provisions; DPDP Act and applicable rules; RBI KYC record-retention directions; applicable cyber-incident reporting requirements.

Explore other policies

Part of the Transwarranty Finance Limited policy and disclosure framework.