Privacy Policy
v2 · FastLegal Technologies Private Limited. Borrower data held in the platform is processed on behalf of the NBFC that licenses it; that lender is the Data Fiduciary and we act on its instructions.
See also the Terms of Service.
LENVIQ
PRIVACY POLICY
Fastlegal Technologies Private Limited
Version 2.0 | Effective from: 01 April 2026 | Supersedes the Fastlegal Privacy Policy dated 30 July 2022
We ask for the least information necessary, gather only what we need to do business or to complete the transaction at hand, and tell you plainly what we do with it and what we do not do with it. This policy is written in ordinary language wherever the law permits.
Lenviq is a loan origination and loan management platform used by non-banking financial companies and other lending institutions. Most of the personal data that passes through Lenviq belongs to the borrowers of our customers, not to us. That data belongs to our customer, who decides what happens to it. We hold it only to run the platform for them. Part II of this policy explains that relationship, and it is the part that matters most to a borrower.
1. SCOPE OF THIS POLICY
1.1 This policy applies to the Fastlegal and Lenviq websites that link to it, to the Lenviq platform and its mobile and desktop applications, and to the products and services provided through them. It does not apply to any product or service that has its own separate privacy policy.
1.2 This policy is issued under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and under the Information Technology Act, 2000 and the rules made thereunder. Terms such as "Data Principal", "Data Fiduciary", "Data Processor", "Personal Data" and "Personal Data Breach" carry the meanings given to them in that Act.
1.3 For customers of Lenviq, this policy is to be read with the Lenviq Terms of Service and Master Subscription Agreement, and in particular with Schedule C (Data Processing and Regulatory Addendum), which prevails over this policy in the event of any inconsistency.
2. OUR TWO ROLES, AND WHY THE DISTINCTION MATTERS
We handle personal data in two quite different capacities. Which capacity applies determines who decides what happens to the data, and whom you should approach to exercise your rights.
Capacity
Whose data
Who decides, and whom to approach
Data Fiduciary (Part I)
Visitors to our websites; prospective customers; the administrators and authorised users of our customers; persons who write to us for support, a quotation or a demonstration; persons who attend our events.
Fastlegal decides the purposes and means. Approach our Data Protection Officer named in Clause 24.
Data Processor (Part II)
Applicants, borrowers, co-applicants, guarantors, mortgagors and their related parties whose records are held in a lender's Lenviq tenant, and all other data our customer puts into the platform.
Our customer, the lending institution, is the Data Fiduciary and decides. A borrower should approach that lender. We act only on the lender's instructions.
A borrower should note: if you have taken or applied for a loan from a lender that uses Lenviq, we are not the holder of your data in our own right. Your lender is. Requests to see, correct or erase your loan records, and complaints about how your data has been used in connection with your loan, should be addressed to that lender's grievance redressal officer. We will forward to the lender anything you send to us, and will tell you that we have done so.
3. HOW THIS POLICY IS ARRANGED
– Part I — Information that Fastlegal collects and controls, where we are the Data Fiduciary.
– Part II — Information that Fastlegal processes on behalf of a customer, where we are a Data Processor.
– Part III — General matters relevant to both Parts, including security, breach notification, our designated officers and how we notify changes.
PART I
INFORMATION FASTLEGAL COLLECTS AND CONTROLS
4. WHAT WE COLLECT
We collect information about you only where we need it for a stated purpose. We will hold information about you only if you gave it to us, or we collected it automatically, or we obtained it from a third party. Each of those is described below.
4.1 Information you give us
- (a) Account sign-up. When you or your organisation sign up, we ask for your name, designation, contact number, email address, organisation name and country, and you choose a username and password. You may optionally add a photograph, time zone and language. For a lending institution we additionally ask for the particulars needed to onboard a regulated entity, such as the corporate identity number, permanent account number, goods and services tax identification number, certificate of registration particulars and the addresses of the registered and corporate offices.
- (b) Enquiries, demonstrations and events. Where you request a demonstration or quotation, subscribe to a mailing list, download material, register for an event or webinar, respond to a survey, or submit any other form, we record what you submit.
- (c) Payment. When you pay us, we collect the name, contact and billing particulars of the payer and the tax registration details needed to raise a compliant invoice. We do not store complete payment card numbers. Card and bank particulars are handled by our payment gateway provider under its own terms, and we retain at most the cardholder name, the expiry date and the last four digits.
- (d) Support and other interactions. We may record, analyse and retain our correspondence with you, including email, support tickets, chat and, where you are told at the time, telephone calls, so that we can resolve issues, train our people and improve our service.
- (e) References and testimonials. Where you authorise us to publish a testimonial, we may include your name and designation. You will see and approve it before it is published, and you may ask us to withdraw it at any time.
4.2 Information we collect automatically
- (a) From browsers, devices and servers. When you visit our websites we record what your browser, device and our servers make available, including the internet protocol address, browser type, language preference, time zone, referring address, date and time of access, operating system and device particulars. These sit in our log files.
- (b) From cookies and similar technologies. We use temporary and persistent cookies to keep you signed in, remember your preferences and understand how our websites are used. We use first-party cookies and first-party local storage. We do not use third-party cookies or third-party tracking technologies on our websites for intrusive or non-essential tracking.
- (c) From application and access logs. We record how the platform is used — sign-ins, features accessed, errors raised, performance and response times, storage consumed, configuration and the devices used — so that we can operate, secure, support and improve it, and so that a complete audit trail exists. Our logs are sanitised so that permanent account numbers, Aadhaar numbers and mobile numbers are not written to them.
4.3 Information we receive from others
- (a) Federated sign-in. Where you sign in through a supported identity provider, that provider authenticates you and shares limited particulars such as your name and email address.
- (b) Referrals and partners. Where someone refers you to us, or you express interest through a channel or implementation partner, or you attend an event we sponsor, we may receive your name, organisation, email address and role. If you would rather we did not hold it, write to us and we will remove it.
- (c) Public sources. Where you comment on, review or engage with us publicly, we may collect and retain what is publicly available in order to respond to you and to improve our products.
4.4 What we do not do
We do not sell personal data. We do not rent, trade or share it for consideration. We do not use it to build advertising profiles. We do not use the personal data of a borrower held in a customer's tenant for any purpose of our own, and in particular we do not use it to train or improve any artificial intelligence or machine learning model.
5. WHY WE USE IT, AND ON WHAT BASIS
We process the information described in Part I for the purposes below. Where we rely on your consent, you may withdraw it at any time. Where the law permits us to process without consent for a legitimate use — for example, to comply with a legal obligation, to respond to your own voluntary request, or in the discharge of a duty under law — we say so.
Purpose
What we use
Basis
Creating and administering your account, provisioning users, and providing the platform and support
Sign-up, contact and usage data
Performance of the contract with your organisation; your voluntary request
Billing, invoicing, tax compliance, recovery of dues and maintenance of statutory books
Billing and tax particulars
Legal obligation
Security, access control, fraud and abuse prevention, and maintenance of the audit trail
Log and access data
Legal obligation; legitimate use
Service announcements, security alerts, renewal and administrative notices
Contact data
Performance of the contract
Newsletters, product announcements, offers, events and other marketing
Contact and interest data
Consent, which you may withdraw
Understanding how the product is used, diagnosing problems and improving it
Aggregate and de-identified usage data
Legitimate use; consent where identifiable
Responding to enquiries, demonstrations, surveys and feedback
What you submit
Your voluntary request
Responding to a court, regulator or law enforcement agency
As required
Legal obligation
Withdrawal of consent. Where we rely on consent, you may withdraw it at any time with the same ease with which it was given, by writing to our Data Protection Officer or by using the unsubscribe facility in the relevant communication. Withdrawal does not affect processing already carried out, and it may mean that we can no longer provide part of a service to you. We will tell you if that is the case before acting on the withdrawal.
6. YOUR CHOICES
– Marketing. You may opt out of newsletters and other non-essential messages using the unsubscribe facility in each such message. You will continue to receive essential notices — password changes, renewal reminders, security alerts, privacy notifications and transactional and payment communications — because they are part of the service.
– Cookies. You may disable cookies in your browser before visiting our websites. Some features may then not work correctly.
– Optional fields. You need not fill any field marked optional, and you may edit or delete optional profile information at any time.
7. WHOM WE SHARE IT WITH
We share the information covered by Part I only as described below, and only with parties who are bound by appropriate confidentiality and security obligations.
– Our employees and contractors, on a need-to-know basis, and bound by confidentiality undertakings and our internal policies.
– Service providers we engage — hosting, storage, email delivery, analytics, payment processing and professional advisers — who are authorised to use the information only to provide those services to us.
– Channel and implementation partners, where you were introduced by them or they support your deployment, and solely for that purpose. You may ask us to stop.
– A court, regulator or law enforcement agency, in the circumstances described in Clause 27.
– An acquirer, in the circumstances described in Clause 29.
8. HOW LONG WE KEEP IT
8.1 We keep the information covered by Part I for as long as it is needed for the purpose for which it was collected, and thereafter for as long as we are required or permitted to keep it by law — for instance to maintain our books of account, to defend a claim, to enforce our agreements, or to maintain a suppression list so that we do not contact you again.
8.2 We may terminate an unpaid user account that has been inactive for a continuous period of one hundred and twenty (120) days, and delete the data associated with it. We will give you not less than thirty (30) days' prior notice and an opportunity to export your data. This does not apply to a paid subscription, to which Clause 26 of the Terms of Service applies instead.
8.3 When we no longer have a lawful need to process your information, we delete it from our active systems or render it de-identified, and we isolate it from further processing on backup media until deletion is possible.
9. YOUR RIGHTS AS A DATA PRINCIPAL
In relation to personal data for which we are the Data Fiduciary, you have the following rights under the Digital Personal Data Protection Act, 2023:
Right to information
To obtain a summary of the personal data of yours that we are processing, the processing activities we have undertaken, and the identities of the other Data Fiduciaries and Data Processors with whom we have shared it.
Right to correction and erasure
To have inaccurate or misleading data corrected, incomplete data completed, data updated, and data erased where it is no longer necessary for the purpose for which it was collected, unless retention is necessary for a specified purpose or for compliance with law.
Right of grievance redressal
To have a grievance about our processing, or about our failure to act on a request, heard and disposed of.
Right to nominate
To nominate another individual to exercise your rights in the event of your death or incapacity.
9.1 To exercise a right, write to our Data Protection Officer at the address in Clause 24, from the email address registered with us or with such verification of identity as we reasonably require. Tell us which right you are exercising and give us enough detail to locate your data.
9.2 We will acknowledge your request within seventy-two (72) hours and respond substantively within thirty (30) days, and in any event within the period prescribed by law. If we need longer, we will tell you why and when you can expect a response. We do not charge a fee.
9.3 If you are not satisfied with how we have dealt with your request or grievance, you may complain to the Data Protection Board of India in the manner prescribed under the Digital Personal Data Protection Act, 2023 and the rules made thereunder.
9.4 Where the request relates to data held in a customer's Lenviq tenant, Part II applies and we will route the request to that customer as described in Clause 18.
PART II
INFORMATION FASTLEGAL PROCESSES ON BEHALF OF A CUSTOMER
10. WHAT SERVICE DATA IS
10.1 When our customer uses Lenviq, it entrusts data to us. That data includes information about the customer's applicants, borrowers, co-applicants, guarantors and mortgagors; about the directors, partners, trustees, shareholders and ultimate beneficial owners of its non-individual borrowers; about its own employees and users; and about the agents, advocates, valuers, dealers and appraisers it deals with. It also includes the customer's master data, transaction records, generated documents, ledgers and audit trail. All of this is referred to as "Service Data".
10.2 Service Data also includes anything a customer shares with us while requesting technical support, and anything it asks us to import into the platform.
11. OUR ROLE AND OUR CUSTOMER'S ROLE
11.1 The customer owns Service Data. Ownership does not pass to us at any time.
11.2 In relation to the personal data within Service Data, the customer is the Data Fiduciary and Fastlegal is a Data Processor. The customer decides what personal data is collected, for what purpose, from whom, on what basis, for how long it is kept, and to whom it is disclosed. The customer is responsible for giving notice to and obtaining the consent of the individuals concerned, and for the lawfulness of its own processing.
11.3 We process Service Data only on the documented instructions of the customer. Those instructions are given by the subscription agreement, by the way the customer configures the platform, by the actions its authorised users take within it, and by any written instruction its nodal officer gives us. If we think an instruction breaks the law, we will say so and may decline to act on it.
11.4 We give our customers complete control of their Service Data. They can access it, share it through the integrations they enable, and require us to export or delete it.
12. HOW WE USE SERVICE DATA — AND HOW WE DO NOT
12.1 We use Service Data solely to host, run, secure, support, back up and restore the platform for the customer, and to generate the outputs the customer asks the platform to generate. For example, when a lender creates a loan, the borrower's name and address are used to create the loan account and to generate the loan documents; when the lender assembles a regulatory return, the loan records are read to populate it.
12.2 We do not use Service Data to train artificial intelligence. We do not use Service Data, whether identifiable, pseudonymised, anonymised, aggregated or derived, to train, fine-tune, evaluate or improve any artificial intelligence or machine learning model, nor for product development, benchmarking, analytics, marketing, sale or licensing, without the customer's prior specific written consent. This is a contractual commitment recorded in the subscription agreement and it survives the end of the engagement.
12.3 We may collect operational telemetry about how the platform itself is performing — request volumes, error rates, response times, feature counts and infrastructure metrics — provided it contains no personal data and identifies no customer. We use it only to run, secure and improve the platform.
12.4 Access by our people to Service Data is on a need-to-know basis, for support, incident resolution, migration or restoration only. Such access is authorised, time-bound and logged, and wherever practicable we ask the customer first.
13. WHAT THE PLATFORM DELIBERATELY DOES NOT HOLD
– Full Aadhaar numbers. Only the last four digits are stored, and they are displayed in masked form. A full Aadhaar number is never stored, logged or displayed.
– Biometric information. None is captured or stored.
– Complete payment card numbers. None are stored.
– Permanent account numbers, Aadhaar numbers and mobile numbers in application logs. Our log sanitiser strips them.
These are design controls. They can be defeated if a user types such information into a free-text or remarks field, which the subscription agreement prohibits, and which the customer is responsible for preventing.
14. WHOM WE SHARE SERVICE DATA WITH
14.1 Our employees and contractors. Access is limited to those who need it to identify, analyse and resolve errors, to migrate data at the customer's request, or to restore service. They are bound by confidentiality undertakings that survive their engagement, are trained on data protection and information security, and are subject to background verification.
14.2 Sub-processors. We engage a small number of sub-processors — for cloud infrastructure and hosting, object storage, transactional messaging, and monitoring and error reporting. All of them process data within India. Each is bound by written obligations no less protective than our own, and we remain responsible to the customer for what they do. We give the customer thirty (30) days' notice before engaging a new sub-processor that will process Service Data, and the customer may object. The current list is available on request.
14.3 Third-party services the customer enables. Where the customer configures an integration — identity or document verification, bank account verification, credit information companies, central know-your-customer services, electronic mandates, payment gateways, messaging, electronic signature, video-based identification, vehicle registry or account aggregator services — data is sent to that provider at the customer's instruction and under the customer's own contract with it. Those providers are not our sub-processors. We encourage every customer to review their privacy practices before enabling an integration.
14.4 Nobody else. We do not disclose Service Data to any other person except as required by law in the circumstances described in Clause 27, and we do not sell or share it for consideration.
15. WHERE SERVICE DATA IS KEPT
15.1 All Service Data is stored and processed within India. The primary environment, the disaster recovery environment, object storage, backups and log stores are all located in India.
15.2 We do not transfer Service Data outside India, and we do not make it accessible from outside India, without the customer's prior written consent and compliance with the Digital Personal Data Protection Act, 2023 and any applicable direction of the Reserve Bank of India.
15.3 Our support personnel who access Service Data are located in India.
15.4 Where a customer hosts Lenviq on its own infrastructure, this Clause 15 records an obligation of that customer rather than a control operated by us. The location of the data is determined entirely by where the customer chooses to deploy the platform, and the subscription agreement requires that location to be within India. We hold no copy of that data and exercise no control over where it resides.
16. HOW WE SECURE SERVICE DATA
We maintain technical and organisational measures set out in full in Annexure C-2 to the subscription agreement. In summary, they include row-level isolation of each customer's tenant; role-based access control with server-side enforcement; two-factor authentication for approvers and administrators; session and idle expiry; transport layer security in transit and encryption at rest; AES-256-GCM encryption of integration credentials, which are never displayed or logged; masked storage of identifiers; sanitised logs; an append-only audit log of every change; maker-checker controls; rate limiting and security response headers; encrypted daily backups retained within India; retention of access logs within India for not less than one hundred and eighty days; and independent vulnerability assessment and penetration testing at least once a year.
17. HOW LONG WE KEEP SERVICE DATA, AND HOW WE DELETE IT
17.1 We hold Service Data for as long as the customer uses Lenviq, and thereafter only for the periods needed for an orderly exit.
17.2 On expiry or termination, the customer may take a complete export in a machine-readable, non-proprietary format. We then delete Service Data from our active systems within thirty (30) days, and from backup and archival media within a further ninety (90) days, and give the customer a signed certificate of erasure. The full mechanics are in Clause 26 of the subscription agreement.
17.3 We will also delete or return Service Data at any time on the customer's written instruction, subject only to what we are required by law to retain, which continues to be protected by our confidentiality obligations.
17.4 We do not withhold Service Data because of a commercial dispute.
18. IF YOU ARE A BORROWER AND YOU WRITE TO US
18.1 If you are a borrower, applicant, guarantor or other individual whose records are held in a lender's Lenviq tenant, and you ask us to give you access to your data, to correct or erase it, or to explain how it has been used, we will not answer the substance of that request ourselves, because the data is not ours to deal with.
18.2 We will tell you promptly to approach the lender, we will forward your request to that lender within three (3) business days, and we will confirm to you that we have done so. The lender must respond to you within the timelines that apply to it.
18.3 When the lender instructs us to act on your request, we act on it within seven (7) working days, or sooner where the lender tells us it has a statutory deadline.
18.4 Nothing in this Clause affects your right to complain to the lender's grievance redressal officer, to the Reserve Bank — Integrated Ombudsman Scheme, or to the Data Protection Board of India.
19. WHERE THE CUSTOMER HOSTS LENVIQ ON ITS OWN SERVERS
Some customers deploy Lenviq on their own infrastructure. In that case we hold no Service Data at all. The customer is the sole custodian of everything in the system, and is responsible for its security, backup, availability and retention. We have no standing access. Where the customer grants us time-bound access to help with a support issue, we act as a Data Processor for the duration and to the extent of that access only, and everything in this Part II applies for that period.
20. MOBILE APPLICATIONS AND NOTIFICATIONS
20.1 Where a mobile or desktop application requires access to your device — for instance to the camera to capture a field investigation photograph, or to location to record where a field visit or collection took place — it will ask for that permission, will use it only for the stated purpose within the application, and you may withdraw the permission at any time in your device settings.
20.2 Where you enable notifications, they are delivered through the operating system's push notification service. You may turn them off in the application or device settings.
PART III
GENERAL
21. OUR SECURITY COMMITMENT
We take security seriously, and we have implemented administrative, technical and physical safeguards designed to prevent unauthorised access to, use, modification, disclosure or destruction of the information entrusted to us. No system is perfectly secure, and we do not claim otherwise; what we do claim is that we maintain the measures described in Clause 16 and in Annexure C-2 to the subscription agreement, that we test them, and that we do not quietly reduce them. If you have a concern about the security of your data, or if you believe you have found a vulnerability, please write to our Nodal Officer at the address in Clause 24. We will not pursue a person who reports a vulnerability to us responsibly and in good faith.
22. IF SOMETHING GOES WRONG — BREACH NOTIFICATION
22.1 If we become aware of a Personal Data Breach affecting personal data for which we are the Data Fiduciary, we will inform each affected Data Principal and the Data Protection Board of India in the manner and within the timelines prescribed under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, and will make any report required to the Indian Computer Emergency Response Team.
22.2 If we become aware of a Personal Data Breach affecting Service Data, we will notify the affected customer's nodal officer without undue delay and in any event within twenty-four (24) hours, with the nature and extent of the breach, its cause, the categories and approximate number of individuals and records affected, its likely consequences, what we have done and propose to do about it, and whom to contact for more. That customer, as Data Fiduciary, then makes the intimation to the individuals concerned and to the Data Protection Board.
22.3 We will report a cyber security incident to the affected customer within six (6) hours of becoming aware of it, so that the customer can meet the six-hour reporting timeline that applies to it under the directions of the Indian Computer Emergency Response Team dated 28 April 2022 and, for a regulated entity, under the directions of the Reserve Bank of India.
22.4 We preserve evidence and logs, provide a root cause analysis and remediation plan within fifteen (15) days, and cooperate fully with the customer, with regulators and with any forensic investigator.
22.5 Where a customer hosts Lenviq on its own infrastructure, we do not operate that environment, do not monitor it, and are not able to detect an incident occurring within it. The timelines in Clauses 22.2 and 22.3 apply only to systems we operate, and to Service Data during a period of support access granted to us. Detection, investigation, containment and regulatory reporting of any incident within the customer's own environment are the customer's sole responsibility. Our obligation in respect of a vulnerability in the Lenviq software itself is set out in paragraph B5A of Schedule B to the subscription agreement.
23. AUTOMATION AND ARTIFICIAL INTELLIGENCE
23.1 Parts of the platform use rule-based automation, pattern matching, computation engines and scheduled jobs — for instance to compute a repayment schedule, to accrue interest, to flag a deviation, to compute a provision, or to assemble a return. These are deterministic and are driven entirely by the parameters and data the customer configures. They are tools; they do not make decisions.
23.2 Where a feature uses artificial intelligence or machine learning, we will say so plainly in the product, and the customer will be able to turn it off.
23.3 We do not use Service Data to train, fine-tune or improve any model. Any model we develop is trained on our own organisation's data, on synthetic data, and on freely available or licensed external sources. This is set out in Clause 12.2 and is a contractual commitment.
23.4 No credit decision, asset classification, provisioning decision, pricing decision or borrower communication is made by us or by any automated system of ours. Every such decision is made by the lender, on its own configuration and its own judgement, and is required by the subscription agreement to be reviewed by the lender before it is acted upon.
24. OUR DESIGNATED OFFICERS
Role
Name
Telephone
Data Protection Officer — questions about this policy, and the exercise of Data Principal rights
Mr. Sushil Choudhary
sushil@fastlegal.in
+91 90248 28295
Grievance Officer — under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and Section 13 of the Digital Personal Data Protection Act, 2023
Mr. Manoj Gurjar
manoj@fastlegal.in
+91 96641 46595
Nodal Officer — security incidents, vulnerability reports, audits, and regulatory and law-enforcement requests
Mr. Jitendra Sharma
jeetsharma@fastlegal.in
+91 97829 00038
General and support
Support desk
mail@fastlegal.in / support@fastlegal.in
—
Postal address: Fastlegal Technologies Private Limited (CIN: U74999RJ2018PTC060472), S-226, Time Square, Central Spine, Vidhyadhar Nagar, Jaipur, Rajasthan 302039, India.
A grievance will be acknowledged within twenty-four (24) hours and disposed of within fifteen (15) days of receipt, and in any event within the period prescribed by law. If you remain dissatisfied, you may complain to the Data Protection Board of India.
25. DATA PROCESSING ADDENDUM
Schedule C to the Lenviq Terms of Service and Master Subscription Agreement is our standard data processing addendum, and it takes effect automatically as part of that agreement — a customer does not need to ask for it separately. Where a customer requires a separately executed addendum, or its own form of addendum, it may request one by writing to support@fastlegal.in.
26. COOKIES, TRACKING AND DO NOT TRACK
26.1 Our use of cookies is described in Clause 4.2(b). You may disable them in your browser.
26.2 Some browsers send a "do not track" signal. There is at present no accepted standard governing what a website should do on receiving one, and we do not currently respond to it. We will say so here if that changes.
26.3 Our websites may include social media widgets that let you share a page. Those widgets may set their own cookies and collect your internet protocol address and the pages you view. Your interaction with them is governed by the privacy policies of the companies that provide them.
27. DISCLOSURES REQUIRED BY LAW, AND ENFORCEMENT OF OUR RIGHTS
27.1 We may preserve or disclose personal data and Service Data where required to do so by law, or by a court, tribunal, regulator or law enforcement agency acting within its powers, including to meet national security requirements.
27.2 Where the disclosure concerns Service Data, we will, unless prohibited by law, give the customer prompt prior notice, disclose only the minimum necessary, record the disclosure, and where lawfully possible give the customer an opportunity to seek protective relief.
27.3 We may disclose personal data or Service Data to a third party where we reasonably believe it necessary to prevent fraud, to investigate suspected illegal activity, to enforce our agreements or policies, or to protect the safety of any person.
28. EXTERNAL LINKS
Some pages on our websites link to sites not covered by this policy. If you submit information to those sites, their privacy policies govern it. We suggest you read them before you do.
29. BUSINESS TRANSFERS
We do not intend to sell our business. If we were nevertheless to sell it, or to be acquired or merged, we would ensure that the acquiring entity is legally bound to honour the commitments in this policy, and we would notify you by email or by a prominent notice on our website, together with any choices then available to you. In the case of Service Data, the customer's rights under the subscription agreement, including its right to terminate and to take an export, would continue to apply.
30. COMPLIANCE WITH THIS POLICY
We review our practices periodically to satisfy ourselves that personal data is used in conformity with this policy. If you have a concern about our adherence to it, write to our Data Protection Officer. We will investigate, respond to you, and where necessary coordinate with the appropriate regulatory authority.
31. CHANGES TO THIS POLICY
31.1 We may modify this policy on notice to you, by a service announcement or by email to your primary email address. Where a change materially affects your rights, we will give not less than thirty (30) days' prior notice.
31.2 If you consider that the revised policy affects your rights in relation to your use of our products or services, you may discontinue that use and, where you are a customer, terminate in accordance with the subscription agreement, by writing to us within thirty (30) days. Continued use after the effective date of a change is treated as acceptance of it.
31.3 We do not send email notification of minor changes. If you have not verified your email address, you may miss notices that we send by email. The current version of this policy is always available on our website.
ANNEXURE A — THIS POLICY AT A GLANCE
Question
Answer
Who holds a borrower's data?
The lender does. Fastlegal only processes it on the lender's instructions.
Whom should a borrower approach?
The lender's grievance redressal officer. We forward anything sent to us within three business days.
Is data stored outside India?
No. Primary, disaster recovery, storage, backup and log environments are all in India.
Is data used to train artificial intelligence?
No. Not in any form, without the customer's prior specific written consent.
Is data sold or shared for consideration?
No.
Is a full Aadhaar number stored?
No. Only the last four digits, in masked form. No biometrics. No card numbers.
How quickly is a breach notified?
Cyber security incident within six hours; Personal Data Breach within twenty-four hours, to the customer.
What happens to data on exit?
Full export in machine-readable form; deletion from active systems in thirty days and from backups in a further ninety days; signed certificate of erasure.
Who is responsible in a self-hosted deployment?
The customer, entirely. We hold no data and have no standing access.
ANNEXURE B
ACKNOWLEDGEMENT PAGE
Applicability. This Annexure applies only where a customer requires this Privacy Policy to be acknowledged in physical form or by digital signature, whether on its own or together with Annexure I to the Lenviq Terms of Service and Master Subscription Agreement. Where the Privacy Policy is accepted electronically on the Lenviq platform, this Annexure does not apply, is not generated, and shall be disregarded.
The Customer confirms that it has read and understood the Lenviq Privacy Policy, Version 2.0, comprising Parts I, II and III and Annexure A, and acknowledges in particular that:
– in respect of the personal data of its applicants, borrowers, co-applicants, guarantors and their related parties, the Customer is the Data Fiduciary and Fastlegal Technologies Private Limited is a Data Processor;
– the Customer is responsible for issuing notices to, and obtaining and managing the consent of, those individuals under the Digital Personal Data Protection Act, 2023;
– all such data is stored and processed within India and is not used to train any artificial intelligence or machine learning model; and
– this Privacy Policy is to be read with Schedule C to the Lenviq Terms of Service and Master Subscription Agreement, which prevails in the event of inconsistency.
For FASTLEGAL TECHNOLOGIES PVT. LTD.
Signature: ______________________________
Name: __________________________________
Designation: ____________________________
Date: ___________________________________
Place: __________________________________
Company seal:
For the CUSTOMER
Signature: ______________________________
Name: __________________________________
Designation: ____________________________
Date: ___________________________________
Place: __________________________________
Company seal:
Name of the Customer
Corporate Identity Number
Reserve Bank of India Certificate of Registration number
Nodal Officer of the Customer for data protection matters — name, email and telephone
Grievance Redressal Officer of the Customer — name, email and telephone