Terms of Service
v2 · FastLegal Technologies Private Limited. These terms govern use of the Lenviq platform. Where a signed Subscription Agreement exists between us, it takes precedence over anything on this page.
See also the Privacy Policy.
LENVIQ
TERMS OF SERVICE AND MASTER SUBSCRIPTION AGREEMENT
Fastlegal Technologies Private Limited
Version 2.1 | Effective from: 01 April 2026 | Supersedes the Fastlegal Terms of Service last updated on 30 July 2022
THIS IS A LEGALLY BINDING AGREEMENT BETWEEN YOU, OR THE ENTITY THAT YOU REPRESENT (HEREINAFTER "CUSTOMER" OR "YOU"), AND FASTLEGAL TECHNOLOGIES PRIVATE LIMITED, A COMPANY INCORPORATED UNDER THE COMPANIES ACT, 2013, BEARING CORPORATE IDENTITY NUMBER U74999RJ2018PTC060472 AND HAVING ITS REGISTERED OFFICE AT S-226, TIME SQUARE, CENTRAL SPINE, VIDHYADHAR NAGAR, JAIPUR, RAJASTHAN 302039 (HEREINAFTER "FASTLEGAL", "WE" OR "US"), GOVERNING YOUR ACCESS TO AND USE OF LENVIQ, THE LOAN ORIGINATION AND LOAN MANAGEMENT PLATFORM FOR NON-BANKING FINANCIAL COMPANIES AND OTHER LENDING INSTITUTIONS, WHETHER DELIVERED AS A CLOUD SUBSCRIPTION OR DEPLOYED ON INFRASTRUCTURE CONTROLLED BY YOU.
Mode of acceptance. This Agreement may be accepted electronically or executed physically. Where the parties elect to execute it physically or by digital signature, they shall complete Annexure I (Execution Page and Customer Particulars), which shall then form an integral part of this Agreement. Where the Customer accepts this Agreement electronically on the Lenviq platform, Annexure I shall not apply and acceptance shall be recorded electronically in the manner set out in Clause 3.
Read this first. Clause 5 records what Lenviq is and, importantly, what it is not. Clause 9 records the regulatory responsibilities that remain yours alone as a lender. Clause 28 limits our liability. Schedule B applies only if you deploy Lenviq on your own servers. Schedule C is the data processing and regulatory addendum and is intended to satisfy the contractual requirements of the Reserve Bank of India (Outsourcing of Information Technology Services) Directions, 2023 and Section 8(2) of the Digital Personal Data Protection Act, 2023.
1. DEFINITIONS AND INTERPRETATION
1.1 In this Agreement, unless the context otherwise requires:
"Agreement" means these General Terms together with Schedules A, B and C, the Privacy Policy, the Subscription Schedule and Annexure I, as applicable.
"Applicable Law" means all laws, rules, regulations, directions, circulars, notifications and guidelines applicable to a party, including the Companies Act, 2013, the Reserve Bank of India Act, 1934 and the directions issued thereunder, the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, the Information Technology Act, 2000 and the rules and directions thereunder (including the CERT-In Directions dated 28 April 2022), the Credit Information Companies (Regulation) Act, 2005, the Prevention of Money-Laundering Act, 2002, and applicable tax laws.
"Authorised User" means an individual employee, officer, director, retainer, auditor or contractor of the Customer whom the Customer authorises to access the Services under a named login.
"Borrower Data" means Personal Data and other information relating to the Customer's applicants, borrowers, co-applicants, guarantors, mortgagors and their related parties, processed through the Services.
"Cloud Subscription" means delivery of the Services on a multi-tenant basis from infrastructure operated or procured by Fastlegal within India.
"Customer Data" means all data, content, records, documents and files uploaded to, entered into or generated within the Customer's tenant through use of the Services, including Borrower Data, master data, transaction data, generated documents and audit logs. Customer Data does not include the Platform itself or Fastlegal's own operational telemetry.
"Data Fiduciary", "Data Principal", "Data Processor", "Personal Data" and "Personal Data Breach" have the meanings assigned to them under the Digital Personal Data Protection Act, 2023.
"Documentation" means the user manuals, onboarding guides, release notes and technical documentation made available by Fastlegal for the Services.
"Fees" means the subscription, licence, annual maintenance, implementation and other charges specified in the Subscription Schedule.
"Lenviq" or the "Platform" means Fastlegal's loan origination and loan management software platform, together with its modules, interfaces, application programming interfaces, document engine and administrative console, in each case as updated from time to time.
"RE" means a regulated entity of the Reserve Bank of India, and includes a non-banking financial company holding a certificate of registration under Section 45-IA of the Reserve Bank of India Act, 1934.
"Self-Hosted Deployment" means installation and operation of the Platform on infrastructure owned, leased or otherwise controlled by the Customer, on the terms of Schedule B.
"Services" means the provision of access to and use of the Platform, together with the support, maintenance and related services described in this Agreement.
"Sub-processor" means a third party engaged by Fastlegal to process Customer Data in the course of providing the Services.
"Subscription Schedule" means the order form, quotation, proposal or Part 2 of Annexure I recording the commercial particulars of the Customer's subscription.
1.2 Headings are for convenience only. References to a clause or schedule are to a clause or schedule of this Agreement. Words importing the singular include the plural. "Including" means "including without limitation". A reference to a statute includes any amendment or re-enactment of it. "Writing" includes email. "₹" means Indian Rupees. Time periods in business days exclude Sundays and public holidays notified at Jaipur, Rajasthan.
2. STRUCTURE OF THIS AGREEMENT AND ORDER OF PRECEDENCE
2.1 This Agreement comprises: (a) these General Terms; (b) Schedule A (Service Levels and Support); (c) Schedule B (Self-Hosted Deployment Terms), which applies only where the Customer has elected a Self-Hosted Deployment; (d) Schedule C (Data Processing and Regulatory Addendum); (e) the Lenviq Privacy Policy; and (f) the Subscription Schedule and, where executed, Annexure I.
2.2 In the event of conflict, the following order of precedence applies, in descending order: (i) a separately negotiated and executed master services agreement or addendum signed by authorised signatories of both parties; (ii) Annexure I and the Subscription Schedule; (iii) Schedule C; (iv) Schedule B; (v) Schedule A; (vi) these General Terms; and (vii) the Privacy Policy.
2.3 Terms specific to an individual module or service, where published, shall prevail over these General Terms in respect of that module or service only.
3. ACCEPTANCE AND FORMATION
3.1 The individual accepting this Agreement represents that he or she is of legal age and is duly authorised to bind the Customer, and, where the Customer is a company, that such authority flows from a resolution of its board of directors or a duly executed power of attorney. Fastlegal may require a copy of such authorisation.
3.2 The Customer accepts this Agreement by (a) checking the acceptance box or clicking the acceptance button presented during onboarding; (b) executing Annexure I or a separate agreement; or (c) accessing or using the Services. Electronic acceptance is recorded in the audit log with the user identifier, internet protocol address, and date and time stamp, and constitutes valid acceptance under the Information Technology Act, 2000.
3.3 Where the Customer is an RE, the Customer confirms that it has, before accepting this Agreement, (a) carried out due diligence on Fastlegal in accordance with its board-approved information technology outsourcing policy, and (b) assessed whether this arrangement constitutes a material outsourcing arrangement for the purposes of the Reserve Bank of India (Outsourcing of Information Technology Services) Directions, 2023.
4. DESCRIPTION OF THE SERVICES
4.1 Lenviq is an enterprise software platform for lending institutions. Subject to the Customer's subscription, it comprises: (a) a loan origination system covering lead management, party and know-your-customer records, application processing, field investigation and telephonic verification, credit bureau record management, financial assessment, collateral management, credit appraisal, the deviation register, the approval chain, sanction and disbursement; (b) a loan management system covering loan accounts, repayment schedules, repayment posting, collections, penal and bounce charges, delinquency and asset classification tracking, provisioning computation, foreclosure, settlement and closure; (c) an accounting module comprising the chart of accounts, voucher engine, party ledgers, books and financial statements; (d) data assembly for regulatory returns and for credit information and central know-your-customer registry file generation; (e) a document generation engine producing loan and related documents on the Customer's letterhead; (f) management information and portfolio reports; and (g) administration, configuration and audit facilities.
4.2 The Services are provided for the Customer's internal business use in conducting its own lending business, by its own Authorised Users.
4.3 Fastlegal may enhance, modify or reorganise the Platform and its modules from time to time. Where a change materially and adversely reduces the core functionality subscribed to by the Customer, Fastlegal shall give the Customer not less than thirty (30) days' prior notice, and the Customer may terminate the affected module by notice within that period and receive a pro-rata refund of prepaid Fees for the unexpired term of that module.
4.4 Features designated as beta, preview or pilot are provided on an as-is basis, without service levels, warranty or liability, and may be withdrawn at any time.
4.5 Any implementation, data migration, configuration, customisation, integration or training services are provided only where expressly agreed in the Subscription Schedule or a separate statement of work, and are chargeable separately unless stated to be included.
5. NATURE OF THE ARRANGEMENT
5.1 Technology provider only. Fastlegal is a technology service provider. It is not a bank, non-banking financial company, financial institution or credit information company; it holds no registration or licence from the Reserve Bank of India; it does not extend credit, accept deposits, hold customer funds, or assume any credit, market or operational risk of the Customer's lending business.
5.2 Not a lending service provider. Fastlegal does not act as a lending service provider, and does not operate a digital lending application on the Customer's behalf, within the meaning of the Reserve Bank of India (Digital Lending) Directions, 2025. In particular, Fastlegal does not: (a) source, solicit or acquire borrowers; (b) interface or communicate with the Customer's borrowers; (c) make, recommend or influence any credit decision; (d) disburse, collect, hold or route any loan monies; (e) undertake recovery or engage recovery agents; or (f) furnish any default loss guarantee. Where the Customer elects to expose any borrower-facing interface, portal or application built with or connected to the Platform, the Customer alone shall be the regulated entity responsible for compliance with those Directions, including due diligence, disclosure, cooling-off, grievance redressal and the reporting of digital lending applications on the Reserve Bank of India's Centralised Information Management System portal.
5.3 Outsourcing of information technology services. The Customer acknowledges that where it is an RE to which the Reserve Bank of India (Outsourcing of Information Technology Services) Directions, 2023 apply (which, at present, covers non-banking financial companies in the Middle, Upper and Top Layers under the Scale Based Regulation framework), this arrangement may constitute outsourcing of information technology services and may be assessed by the Customer as a material outsourcing arrangement. Part B of Schedule C shall then apply. Outsourcing does not diminish the Customer's obligations to its borrowers or to the Reserve Bank of India, and nothing in this Agreement shall be construed as transferring any regulatory obligation of the Customer to Fastlegal.
5.4 No professional advice. Nothing in the Services, the Documentation, any generated document, computation, classification, template or report constitutes legal, regulatory, tax, accounting, actuarial, valuation or compliance advice, and none of it may be relied upon as such.
6. DEPLOYMENT MODELS
6.1 Cloud Subscription. The Platform is hosted by Fastlegal on infrastructure located in India, with row-level tenant isolation. Schedule A (Service Levels and Support) and Schedule C apply in full.
6.2 Self-Hosted Deployment. Where the Customer elects to deploy the Platform on its own infrastructure, Schedule B applies and prevails. In a Self-Hosted Deployment, Fastlegal does not host, store or have standing access to Customer Data, the availability commitments and service credits in Schedule A do not apply, and Fastlegal's obligations as a Data Processor under Schedule C apply only to the extent and for the period that Fastlegal is granted access to Customer Data for support purposes.
6.3 Migration from one deployment model to the other requires a written variation to the Subscription Schedule and may involve revised Fees, a migration charge, and a re-execution of Annexure I.
7. TRIAL, PILOT AND PROOF OF CONCEPT
7.1 Where Fastlegal makes the Services available on a free trial, pilot or proof-of-concept basis, the Services are provided as-is, without warranty, service level, support commitment or liability of any kind, and may be withdrawn or terminated by Fastlegal at any time in its discretion.
7.2 Data entered during a trial or pilot will be permanently deleted thirty (30) days after the end of the trial period unless the Customer converts to a paid subscription. The Customer is responsible for exporting its data before that date.
7.3 The Customer shall not process live Borrower Data or any other live Personal Data in a trial or pilot environment unless (a) it has issued the notices and obtained the consents required under the Digital Personal Data Protection Act, 2023, and (b) this Agreement, including Schedule C, has been accepted.
8. ACCOUNTS, AUTHORISED USERS AND ADMINISTRATORS
8.1 The Customer shall provide true, accurate, current and complete information at sign-up and shall keep it updated. Fastlegal may suspend or terminate an account where information provided is untrue, inaccurate, outdated or incomplete, or where Fastlegal has reasonable grounds to believe it to be so.
8.2 The individual who completes onboarding will be constituted as the super administrator of the Customer's tenant. The Customer is responsible for (a) appointing competent administrators; (b) provisioning and de-provisioning Authorised Users promptly, including on separation of an employee; (c) configuring roles, data scopes, the approval matrix and maker-checker controls in a manner consistent with its own internal control and segregation-of-duties policies; and (d) enforcing two-factor authentication for approvers and administrators.
8.3 Access is by named user. Login credentials shall not be shared, and a single login shall not be used by more than one individual. The Customer shall keep credentials confidential and shall notify Fastlegal within twenty-four (24) hours of becoming aware of any actual or suspected unauthorised access to or use of its tenant.
8.4 The number of Authorised Users, branches and other usage metrics shall not exceed those specified in the Subscription Schedule. Fastlegal may charge for excess usage at the prevailing rate on thirty (30) days' notice.
8.5 The Customer may lodge with Fastlegal a written administrator-account recovery process. In the absence of such a process, Fastlegal may restore control of an administrator account to an individual furnishing proof of authority satisfactory to Fastlegal, and the Customer shall not hold Fastlegal liable for any action taken in good faith in that regard.
8.6 The Customer is responsible for all acts and omissions of its Authorised Users and administrators, and for all activity occurring within its tenant, as if they were its own.
9. CUSTOMER RESPONSIBILITIES — REGULATORY AND OPERATIONAL
9.1 The Customer is solely responsible for compliance with Applicable Law in the conduct of its lending business. The Services compute, classify, assemble and generate output strictly on the basis of the products, schemes, rates, charges, policies, parameters, master data and transaction data configured or entered by the Customer or its Authorised Users. Fastlegal exercises no credit, accounting, valuation or regulatory judgement.
9.2 Without limiting Clause 9.1, and notwithstanding any assistance rendered by the Services or by Fastlegal, each of the following remains the sole and non-delegable responsibility of the Customer:
- (a)obtaining and maintaining its certificate of registration and complying with the Scale Based Regulation framework and all directions applicable to its layer and category;
- (b)the formulation, board approval, publication and periodic review of all policies required of it, including its fair practices code, interest rate model and policy, penal charges policy, know-your-customer and anti-money-laundering policy, credit and risk policy, outsourcing and information technology policy, information security policy, business continuity policy, recovery policy and grievance redressal policy;
- (c)the correctness and completeness of the configuration of products, facilities, security types, schemes, charges, documents, deviations, approval matrices, gold rates, loan-to-value caps, income and obligation norms, penal and bounce charges, numbering series and general ledger mappings, and of the interest rate methodology applied to each scheme;
- (d)the accuracy, adequacy and timeliness of every borrower disclosure issued through the Services, including the key facts statement, the annual percentage rate, the sanction letter, the loan agreement, the repayment schedule, the statement of account and all charge disclosures;
- (e)income recognition, asset classification, provisioning, upgradation, restructuring, one-time settlement and write-off decisions under the applicable prudential norms, and the independent review of every classification, provision and computation suggested or generated by the Services;
- (f)the preparation, verification, certification and timely submission of all returns, statements and reports to the Reserve Bank of India and any other authority, including returns in the DNBS series, the central repository of information on large credits, priority sector lending statements and annual data extracts; the Services assemble data for the Customer's review only, and do not submit anything to any authority on the Customer's behalf;
- (g)the accuracy, completeness and timeliness of credit information furnished to credit information companies under the Credit Information Companies (Regulation) Act, 2005 and the rules and regulations made thereunder, of records uploaded to the central know-your-customer records registry, and the correction of such information on borrower request;
- (h)customer due diligence, risk categorisation, screening of politically exposed persons, sanctions and adverse-media screening, and reporting obligations under the Prevention of Money-Laundering Act, 2002 and the rules thereunder;
- (i)the appraisal, valuation, insurance, custody, movement, release, auction and disposal of gold, immovable property, vehicles and other collateral, and compliance with the directions of the Reserve Bank of India applicable to lending against such collateral, including notice, tenure and surplus-return requirements;
- (j)mandate registration, presentation and collection through the national automated clearing house, electronic mandates, post-dated cheques and unified payments interface, adherence to the rules of the National Payments Corporation of India, and the conduct of all collection and recovery activity, including the conduct of recovery agents;
- (k)the accuracy of its books of account, accounting policies, tax deduction at source, goods and services tax positions and statutory financial statements, and their audit under Applicable Law; the accounting module is a book-keeping tool and does not substitute the Customer's accountants or auditors;
- (l)the adequacy, stamping, execution, attestation, registration, custody and enforceability of every document generated through the Services, including the payment of stamp duty at the rate applicable in the relevant State;
- (m)issuing notices to, and obtaining, recording and managing the consent of, Data Principals under the Digital Personal Data Protection Act, 2023, including consent to the processing of their Personal Data by technology service providers such as Fastlegal, and responding to requests made by Data Principals;
- (n)borrower grievance redressal, including the appointment, publication and functioning of a grievance redressal officer and nodal officer under the fair practices code and the Reserve Bank — Integrated Ombudsman Scheme; and
- (o)every decision to lend, decline, price, disburse, restructure, compromise, settle, write off, enforce or initiate legal proceedings.
9.3 Verification before use. Every return, statement, key facts statement, sanction letter, agreement, certificate, ledger, financial statement, credit information file, know-your-customer file, computation and report generated by the Services shall be independently reviewed and verified by the Customer before issue, filing, submission, publication or reliance. The Customer shall not treat any system-generated output as final without such review.
9.4 Document templates. The document templates within the Platform are formats intended to reduce drafting effort. They are not legal opinions and have not been settled for the Customer's particular products, State or circumstances. The Customer shall have its templates vetted by its own legal advisers before first use and after any change in law, and shall be responsible for the legal sufficiency of the executed documents.
9.5 The Customer is responsible for the accuracy of master and reference data it uploads or maintains, including gold rates, bureau reports, valuation reports, legal opinions, stock statements, insurance particulars and third-party data.
9.6 The Customer is responsible for its own endpoints, network, electronic mail, browser versions, connectivity and physical security, and for the security awareness of its personnel.
9.7 The Customer shall designate in Annexure I a nodal officer for this Agreement, who shall be Fastlegal's point of contact for incidents, audits, regulatory requests and exit management.
10. RESTRICTIONS ON USE
10.1 The Customer shall not, and shall not permit any Authorised User or third party to:
- (a)transfer, resell, sublicense, rent, lease or otherwise make the Services available to any third party, operate the Services as a service bureau, or use the Services to originate, service or manage the loan portfolio of any person other than the Customer itself, save where expressly permitted in the Subscription Schedule;
- (b)permit access by more than the number of Authorised Users subscribed for, share login credentials, or use generic or shared logins;
- (c)disassemble, decompile, reverse engineer, translate, or otherwise attempt to derive the source code, object code, database schema or underlying structure of the Platform, or create any derivative work, except to the extent such restriction is prohibited by Applicable Law;
- (d)circumvent, disable or interfere with any licence control, authentication mechanism, role-based access control, maker-checker control, audit log, rate limit or other security or integrity feature of the Platform;
- (e)conduct any vulnerability assessment, penetration test, load test or security scan against the Platform without Fastlegal's prior written consent, which shall not be unreasonably withheld where the Customer is an RE conducting such assessment in discharge of its regulatory obligations, subject to Clause 15.4;
- (f)use the Services for competitive analysis or benchmarking, or to build or assist in building a competing product or service;
- (g)enter full Aadhaar numbers, biometric information, complete payment card numbers, passwords or other sensitive identifiers into free-text, remarks, notes or file-name fields, or otherwise defeat the masking and minimisation controls built into the Platform;
- (h)upload, transmit or store material that is unlawful, defamatory, obscene, infringing, or that contains viruses, worms, malicious code or scripts, or use the Services in a manner that damages, disables, overburdens or impairs any server, network or system of Fastlegal or of any other tenant;
- (i)attempt to gain unauthorised access to the Services, to any other tenant, or to any related system, network or data;
- (j)host, display, upload, publish, transmit, store or share information belonging to another person to which the Customer has no right, including Personal Data in respect of which the Customer has not obtained the necessary consent or does not have a lawful basis;
- (k)use the Services in any manner that threatens the unity, integrity, defence, security or sovereignty of India, friendly relations of India with foreign states, or public order, or that causes incitement to the commission of any cognisable offence or prevents the investigation of any offence;
- (l)use the Services to facilitate lending, collection or recovery in contravention of the directions of the Reserve Bank of India, or on behalf of any person not holding the registration or authorisation required for such activity; or
- (m)remove, obscure or alter any proprietary notice, watermark, licence marking or attribution contained in the Platform or in any generated document.
10.2 The Customer shall be solely responsible for the content of all transmissions made through the Services, and shall not use the Services for the transmission of unsolicited bulk communications, phishing or other communications in contravention of Applicable Law or of the regulations of the Telecom Regulatory Authority of India.
11. THIRD-PARTY INTEGRATIONS AND CREDENTIALS
11.1 The Platform supports integration with third-party services, including identity and document verification, bank account verification, electronic mandates, payment gateways, short message service, instant messaging and electronic mail providers, credit information companies, central know-your-customer services, electronic signature, video-based customer identification, vehicle registry and account aggregator services.
11.2 Except where expressly stated in the Subscription Schedule, the Customer shall contract directly with, and procure its own credentials from, each such third-party provider, and shall bear the charges of that provider. Fastlegal is not a party to, and gives no warranty in respect of, the terms, performance, availability, accuracy, pricing or continuity of any third-party service.
11.3 Credentials configured by the Customer are encrypted at rest using AES-256-GCM, are never displayed in full, are excluded from logs and application responses, and are used only through a server-side proxy for calls initiated by the Customer's own users or scheduled jobs.
11.4 The Customer is responsible for obtaining all consents and authorisations required for each integration, including borrower consent for the pull and use of credit information and for verification enquiries, and for compliance with the terms on which such data may be used.
11.5 Credit information obtained through the Platform is obtained by the Customer in its capacity as a specified user under the Credit Information Companies (Regulation) Act, 2005. Fastlegal is not a specified user, claims no right in such information, and processes it solely to render it to the Customer.
11.6 Fastlegal may suspend, restrict or remove an integration where required by the third-party provider, by Applicable Law, or on grounds of security. Where reasonably practicable, Fastlegal shall give thirty (30) days' prior notice.
12. FEES, TAXES AND PAYMENT
12.1 The Customer shall pay the Fees specified in the Subscription Schedule, in advance for each billing cycle unless otherwise stated. Fees are exclusive of taxes.
12.2 Invoices are payable within fifteen (15) days of the invoice date by electronic transfer, or by such other mode as Fastlegal may notify. Fastlegal may charge interest on amounts overdue at the rate of one and a half per cent (1.5%) per month or part thereof, from the due date until payment.
12.3 Goods and services tax and any other tax, levy or cess chargeable on the Fees shall be borne by the Customer in addition to the Fees, and Fastlegal shall issue a tax invoice in the prescribed form to enable the Customer to claim input tax credit where available.
12.4 Where the Customer is required to deduct tax at source, it shall deposit the same within the prescribed time and furnish the certificate of deduction. The Customer shall not deduct or withhold any other amount from the Fees.
12.5 Fastlegal may revise the Fees with effect from the commencement of a renewal term, on not less than thirty (30) days' prior notice. Fees shall not be increased during a subscription term for which the Customer has prepaid.
12.6 Save as expressly provided in Clauses 4.3, 25.3 and 25.5, Fees once paid are not refundable, and no credit is available for partial periods, unused users or reduced usage during a subscription term.
12.7 Disputed amounts shall be notified in writing within fifteen (15) days of the invoice date, with reasons. Undisputed amounts remain payable on the due date.
13. SUSPENSION
13.1 Where an invoice remains unpaid, Fastlegal will issue reminders on the seventh (7th) and fifteenth (15th) day after the due date, a written suspension warning on the twenty-second (22nd) day, and may suspend access to the Services on the twenty-fourth (24th) day after the due date. Notice of suspension shall additionally be given to the nodal officer designated by the Customer under Clause 9.7.
13.2 Regulatory continuity during suspension. Notwithstanding any suspension, Fastlegal shall not delete, alter or render irrecoverable any Customer Data during the period of suspension and for sixty (60) days thereafter, and shall, on the Customer's written request, restore read-only access, or provide a complete data export under Clause 26.3, for the limited purpose of enabling the Customer to discharge its statutory, regulatory, audit, tax, borrower-servicing and record-keeping obligations. This right is not conditional on payment of disputed amounts.
13.3 Fastlegal may also suspend access, in whole or in part and with such notice as is reasonable in the circumstances, where (a) there is a credible threat to the security or integrity of the Platform or of other tenants; (b) there is reasonable ground to believe the Services are being used for an unlawful purpose; (c) suspension is required by a direction of a court, regulator or law enforcement agency; or (d) suspension is necessary for emergency maintenance.
13.4 Access is restored promptly, and in any event within two (2) business days, on the cause of suspension being remedied. Suspension does not extend the subscription term or abate Fees, save where the suspension is attributable to Fastlegal's breach.
14. SERVICE LEVELS, SUPPORT AND MAINTENANCE
14.1 Fastlegal shall provide the Services in accordance with Schedule A. Schedule A does not apply to a Self-Hosted Deployment, to trials and pilots, or to beta features.
14.2 Fastlegal shall maintain the Platform, apply security patches, and make available updates and new releases within the Customer's subscription at no additional charge, save for separately licensed modules.
15. SECURITY
15.1 Fastlegal shall implement and maintain the technical and organisational security measures set out in Annexure C-2, and shall not materially diminish them during the Term.
15.2 Fastlegal shall cause an independent vulnerability assessment and penetration test of the Platform to be conducted at least once every financial year, shall remediate findings within a reasonable period commensurate with their severity, and shall make the summary report available to the Customer on request, subject to Clause 18.
15.3 Fastlegal shall maintain logs of access to and processing of Customer Data, and shall retain such logs within India for a period of not less than one hundred and eighty (180) days, in accordance with the directions issued by the Indian Computer Emergency Response Team dated 28 April 2022, and shall synchronise the clocks of its systems to the network time protocol servers of the National Informatics Centre or the National Physical Laboratory.
15.4 Where the Customer wishes to conduct its own vulnerability assessment or penetration test in discharge of a regulatory obligation, Fastlegal shall permit it once per financial year, on not less than fifteen (15) days' written notice, against a non-production replica environment in the case of a Cloud Subscription, on terms of confidentiality, without disruption to production, and on the basis that the findings are shared with Fastlegal and are not disclosed to any third party other than the Customer's regulator or auditors.
16. CUSTOMER DATA — OWNERSHIP AND PERMITTED USE
16.1 As between the parties, the Customer owns and retains all right, title and interest in Customer Data, including Borrower Data and all documents, ledgers, computations and audit logs generated within its tenant. Nothing in this Agreement transfers any ownership in Customer Data to Fastlegal.
16.2 The Customer grants Fastlegal a limited, non-exclusive, non-transferable licence to host, store, transmit, copy, process, back up, restore and display Customer Data solely to the extent necessary to provide, secure, support, maintain and restore the Services, and for no other purpose.
16.3 No training, no secondary use. Fastlegal shall not use Customer Data, and shall not permit any Sub-processor to use Customer Data, whether in identifiable, pseudonymised, anonymised, aggregated or derived form, to train, fine-tune, evaluate or improve any artificial intelligence or machine learning model, or for product development, benchmarking, analytics, marketing, sale, licensing or any other purpose, without the Customer's prior specific written consent. This clause survives termination.
16.4 Fastlegal may collect and use operational telemetry relating to the functioning of the Platform, such as aggregate request volumes, error rates, response times, feature usage counts and infrastructure metrics, provided that such telemetry contains no Personal Data, no Borrower Data and no information identifying the Customer, and is used only to operate, secure, support and improve the Platform.
16.5 Access by Fastlegal personnel to Customer Data shall be on a need-to-know basis only, for the purpose of support, incident resolution, migration or restoration, shall be authorised, logged and time-bound, and shall, wherever practicable, be sought with the Customer's prior consent through the support channel.
16.6 Fastlegal shall not disclose Customer Data to any third party except as permitted by Schedule C or required under Clause 24.
17. DATA LOCALISATION AND HOSTING
17.1 All Customer Data shall be stored and processed within the territory of India. The primary hosting environment, the disaster recovery environment, object storage, backups and log stores shall all be located in India.
17.2 Fastlegal shall not transfer, replicate or make Customer Data accessible outside India without the Customer's prior written consent, and shall not do so where such transfer is restricted by the Digital Personal Data Protection Act, 2023, by any notification issued thereunder, or by any direction of the Reserve Bank of India.
17.3 Personnel accessing Customer Data for support or administration shall be located in India.
17.4 Where any payment transaction data is processed, it shall be stored only in India in accordance with the directions of the Reserve Bank of India on storage of payment system data.
17.5 Fastlegal shall inform the Customer of the location of the hosting and disaster recovery environments and of any proposed change, not less than thirty (30) days in advance.
18. CONFIDENTIALITY
18.1 "Confidential Information" means all non-public information disclosed by one party to the other, in any form, which is designated as confidential or which a reasonable person would understand to be confidential, including Customer Data, borrower information, business plans, pricing, policies, product roadmaps, security architecture, source code, audit findings and the terms of this Agreement.
18.2 The receiving party shall (a) use Confidential Information solely for the performance of this Agreement; (b) protect it with not less than the degree of care it applies to its own confidential information, and in no case less than reasonable care; and (c) disclose it only to its personnel, professional advisers and Sub-processors who need to know it and who are bound by obligations of confidentiality no less protective than these.
18.3 These obligations do not apply to information which is or becomes public otherwise than by breach, was lawfully known to the receiving party without obligation before disclosure, is lawfully received from a third party without restriction, or is independently developed without use of the Confidential Information.
18.4 Disclosure compelled by law, by a court, or by a regulator is permitted, provided that the receiving party gives, where lawful and practicable, prompt prior notice to the disclosing party and discloses only so much as is required.
18.5 Obligations of confidentiality survive termination for a period of five (5) years, and, in respect of Customer Data, Borrower Data and any Personal Data, indefinitely.
18.6 Each party acknowledges that damages may be an inadequate remedy for breach of this Clause and that the disclosing party shall be entitled to seek injunctive relief.
19. INTELLECTUAL PROPERTY
19.1 Fastlegal and its licensors own all right, title and interest in and to the Platform, its software, architecture, database schema, user interface, document templates, Documentation and all enhancements, and all intellectual property rights therein. No rights are granted to the Customer other than the limited right to use the Services expressly conferred by this Agreement.
19.2 No source code is licensed, delivered, or required to be delivered, under this Agreement. Source code escrow, if desired, shall be the subject of a separate agreement and fee.
19.3 The Customer retains ownership of its name, logos, letterhead and marks, and grants Fastlegal a limited licence to reproduce them solely for rendering them within documents and reports generated for the Customer.
19.4 Where the Customer provides suggestions, feedback or enhancement requests, Fastlegal may use and implement them without restriction or obligation, provided that no Customer Data and no Confidential Information of the Customer is used or disclosed in doing so, and provided that no enhancement developed and paid for by the Customer as bespoke work under a separate statement of work shall be so used where that statement of work provides otherwise.
19.5 Neither party shall use the name, logo or marks of the other in any publicity, case study, customer list or press release without prior written consent, save that Fastlegal may identify the Customer as a user of Lenviq to a regulator or auditor where required.
20. AUDIT, INSPECTION AND REGULATORY ACCESS
20.1 Fastlegal shall, on reasonable prior notice, grant the Customer, its internal auditors, statutory auditors, information systems auditors, concurrent auditors and other persons authorised by it, and the Reserve Bank of India and any other regulator having jurisdiction over the Customer and their authorised officers, the right to: (a) access all documents, records of transactions, systems, reports and other information relating to the Customer that are in the possession, custody or control of Fastlegal; (b) inspect the premises, infrastructure, processes, books and controls of Fastlegal in so far as they relate to the Services provided to the Customer; and (c) take copies of the foregoing.
20.2 Nothing in this Agreement shall impede, restrict or delay the exercise by the Reserve Bank of India of its supervisory powers, including its right to cause an inspection to be made of Fastlegal and of its books and accounts in respect of the services outsourced to it by the Customer, and to obtain any record, document or information from Fastlegal directly.
20.3 The rights in Clause 20.1 may be exercised by the Customer once in each financial year, and additionally (a) at any time on the direction of a regulator; (b) following a material security or service incident; and (c) where reasonably required to investigate a suspected breach of this Agreement. Rights exercised at the instance of a regulator are not subject to any limitation as to frequency, notice or scope.
20.4 Fastlegal shall furnish annually, and on reasonable request, a compliance confirmation covering the matters in Annexure C-2, together with such of the following as are available: audited financial statements, organisation and key personnel details, the summary vulnerability assessment and penetration test report, the business continuity and disaster recovery test summary, insurance particulars, and any independent assurance report.
20.5 Each party shall bear its own costs of an audit, save that the Customer shall bear the fees of any external auditor it appoints. Where an audit reveals a material breach by Fastlegal, Fastlegal shall bear the reasonable cost of the audit and shall remediate the findings at its own cost within a reasonable period.
20.6 Fastlegal shall preserve records relating to the Customer for the period required by Applicable Law, and shall, for a period of five (5) years after termination, furnish to the Customer or its regulator on request such records as remain in its possession, subject to Clause 26.4.
21. BUSINESS CONTINUITY AND DISASTER RECOVERY
21.1 Fastlegal shall maintain a documented business continuity and disaster recovery plan proportionate to the criticality of the Services, shall test it at least once every financial year, and shall furnish a summary of the test results to the Customer on request.
21.2 The recovery time objective and recovery point objective applicable to a Cloud Subscription are stated in Schedule A.
21.3 Fastlegal shall at all times maintain the ability to deliver Customer Data to the Customer in a complete, machine-readable and non-proprietary form, and shall not adopt any architecture or practice that would prevent it from doing so.
21.4 Fastlegal shall notify the Customer promptly, and in any event within seven (7) days, of any event likely to materially affect its ability to provide the Services, including any material adverse change in its financial condition, the commencement of insolvency or winding-up proceedings, any change in control, the loss of a critical Sub-processor, or any adverse regulatory or enforcement action against it.
22. INCIDENT AND BREACH REPORTING
22.1 Cyber security incidents. Fastlegal shall report to the nodal officer designated by the Customer any cyber security incident affecting the Services or Customer Data, immediately upon becoming aware of it and in any event within six (6) hours, so as to enable the Customer to make its own report to the Reserve Bank of India and to the Indian Computer Emergency Response Team within the timelines applicable to it. Fastlegal shall make its own report to the Indian Computer Emergency Response Team where required of it.
22.2 Personal Data Breach. Fastlegal shall notify the Customer of any Personal Data Breach affecting Customer Data without undue delay and in any event within twenty-four (24) hours of becoming aware of it, with the particulars specified in Clause C7 of Schedule C, so as to enable the Customer, as Data Fiduciary, to give intimation to each affected Data Principal and to the Data Protection Board of India within the timelines prescribed under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025.
22.3 Fastlegal shall take immediate steps to contain, investigate and remediate the incident, shall preserve evidence and logs, shall furnish a root cause analysis and remediation plan within fifteen (15) days, and shall cooperate fully with the Customer and with any regulator, auditor or forensic investigator.
22.4 Neither party shall make any public statement or filing that identifies the other in connection with an incident without the other's prior written consent, save where required by Applicable Law or by a regulator, in which case notice shall be given where lawful and practicable.
23. SUB-CONTRACTING
23.1 Fastlegal shall make available to the Customer, on request, the categories of Sub-processors engaged by it and the current list of named Sub-processors. Fastlegal shall give the Customer not less than thirty (30) days' prior written notice before engaging a new Sub-processor that will process Customer Data.
23.2 The Customer may object to a proposed Sub-processor on reasonable grounds relating to security, regulatory compliance, or data protection, by notice within the notice period. If the parties are unable to resolve the objection, the Customer may terminate the affected Services without penalty and receive a pro-rata refund of prepaid Fees for the unexpired term.
23.3 Fastlegal shall impose on each Sub-processor obligations no less protective than those in this Agreement, and shall remain fully liable to the Customer for the acts and omissions of its Sub-processors as if they were its own.
23.4 Fastlegal shall not sub-contract the core provision of the Services as a whole, and shall not permit any Sub-processor to store or process Customer Data outside India.
24. DISCLOSURES REQUIRED BY LAW
24.1 Fastlegal may preserve or disclose Customer Data where required to do so by Applicable Law, by a court or tribunal, or by a lawful direction of a regulator or law enforcement agency.
24.2 Fastlegal shall, unless prohibited by law, give the Customer prompt prior notice of any such requirement, shall furnish only the minimum necessary, shall record the disclosure, and shall, where lawfully permissible, afford the Customer an opportunity to seek protective relief.
24.3 Where Fastlegal receives a complaint from any person relating to the Customer's use of the Services, Fastlegal will forward it to the primary email address on the Customer's account. The Customer shall respond to the complainant within ten (10) days, marking a copy to Fastlegal.
25. TERM AND TERMINATION
25.1 This Agreement commences on the Effective Date and continues for the initial term stated in the Subscription Schedule, and shall renew automatically for successive terms of like duration unless either party gives written notice of non-renewal not less than thirty (30) days before the end of the then-current term.
25.2 The Customer may terminate for convenience on sixty (60) days' written notice. Prepaid Fees for the unexpired period are not refundable on a termination under this Clause.
25.3 Either party may terminate for material breach by the other, by written notice, if the breach is not cured within thirty (30) days of notice specifying it. Where the Customer terminates under this Clause, it shall be entitled to a pro-rata refund of prepaid Fees for the unexpired term.
25.4 Either party may terminate with immediate effect if the other (a) becomes insolvent, is unable to pay its debts, or has an insolvency, liquidation or winding-up proceeding admitted against it; (b) ceases or threatens to cease to carry on business; (c) suffers revocation or suspension of a licence or registration essential to its performance; or (d) is convicted of, or has proceedings initiated against it for, an offence involving fraud, dishonesty or moral turpitude.
25.5 Regulatory termination. The Customer may terminate this Agreement, in whole or in part, with immediate effect and without penalty, where directed to do so by the Reserve Bank of India or any other regulator, or where the continuation of the arrangement would place the Customer in breach of Applicable Law. In such event the Customer shall be entitled to a pro-rata refund of prepaid Fees for the unexpired term.
25.6 On expiry or termination, the Customer's and its Authorised Users' right to access the Services ceases, save as provided in Clause 26; all Fees accrued to the date of termination become immediately payable; and each party shall return or destroy the Confidential Information of the other, subject to Clause 26 and to retention required by Applicable Law.
25.7 Clauses 1, 5, 9.2, 16, 18, 19, 20.6, 24, 26, 27.4, 28, 29, 32, 33 and 36, and Schedule C to the extent it relates to erasure, confidentiality and audit, survive termination.
26. EXIT MANAGEMENT, DATA RETURN AND ERASURE
26.1 Fastlegal shall maintain, and shall furnish to the Customer on request, a documented exit plan describing the steps, formats, timelines and responsibilities for an orderly transition of the Services to the Customer or to a successor provider.
26.2 Transition Period. On the Customer's written request made before or within thirty (30) days after expiry or termination (other than termination by Fastlegal under Clause 25.4), Fastlegal shall continue to provide the Services on the same terms for a period of up to sixty (60) days, or such longer period as the parties may agree, at the then-current Fees, to enable an orderly transition, migration and regulatory close-out.
26.3 Data export. Fastlegal shall, within fifteen (15) working days of a written request made at any time during the Term or the Transition Period, furnish a complete export of Customer Data in a machine-readable, non-proprietary format, comprising structured data in comma-separated values or JavaScript object notation format together with a documented schema, generated documents in portable document format, and the audit trail. One such export in each subscription year is provided at no additional charge; further or bespoke extractions are chargeable at rates agreed in advance.
26.4 Erasure. On the later of the expiry of the Transition Period and thirty (30) days after the final export, Fastlegal shall delete Customer Data from its active systems within thirty (30) days, and from its backup and archival media within a further ninety (90) days, and shall thereupon furnish a certificate of erasure signed by an authorised signatory. Fastlegal may retain such records as it is required to retain by Applicable Law, which shall continue to be protected by Clause 18.
26.5 No withholding of data. Fastlegal shall not withhold, encumber or refuse to deliver Customer Data by reason of any dispute between the parties, provided that undisputed Fees for the period during which the Services were actually rendered have been paid.
26.6 The Customer is responsible for its own record-retention obligations under Applicable Law, including under the Prevention of Money-Laundering Act, 2002, the Companies Act, 2013, the Income-tax Act, 1961 and the directions of the Reserve Bank of India, and shall ensure that it has taken and preserved a complete export before erasure under Clause 26.4.
26.7 In a Self-Hosted Deployment, Clause B13 of Schedule B applies in place of Clauses 26.3 and 26.4.
27. REPRESENTATIONS AND WARRANTIES
27.1 Each party represents and warrants that it is duly incorporated and validly existing, has full power and authority to enter into and perform this Agreement, that the person accepting or executing it is duly authorised, and that its performance will not breach any other agreement or Applicable Law, including any law relating to the prevention of bribery and corruption.
27.2 Fastlegal represents and warrants that (a) the Services will be performed with reasonable skill and care by suitably qualified and trained personnel; (b) the Platform will conform in all material respects to the Documentation; (c) it will not knowingly introduce any virus, worm, trojan, ransomware, back door or other malicious code into the Platform or the Customer's environment; (d) it has and will retain all rights necessary to grant the rights conferred by this Agreement; (e) it will maintain the security measures set out in Annexure C-2; and (f) it will comply with Applicable Law in its performance as a service provider.
27.3 The Customer represents and warrants that (a) it holds and will maintain all registrations, licences and approvals required for its business; (b) it has the authority and the lawful basis, including all consents required under the Digital Personal Data Protection Act, 2023, to upload and have processed the data it puts into the Services; and (c) it will use the Services only for its own lending business and in compliance with Applicable Law.
27.4 Disclaimer. SAVE AS EXPRESSLY SET OUT IN CLAUSE 27.2 AND SCHEDULE A, THE SERVICES ARE PROVIDED ON AN AS-IS AND AS-AVAILABLE BASIS. FASTLEGAL DISCLAIMS ALL OTHER WARRANTIES, WHETHER EXPRESS, IMPLIED OR STATUTORY, INCLUDING ANY IMPLIED WARRANTY OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. FASTLEGAL DOES NOT WARRANT THAT THE SERVICES WILL BE UNINTERRUPTED OR ERROR-FREE, THAT ALL DEFECTS WILL BE CORRECTED, OR THAT ANY OUTPUT, COMPUTATION, CLASSIFICATION, RETURN, TEMPLATE OR DOCUMENT GENERATED BY THE SERVICES WILL BE ACCEPTED BY, OR WILL SATISFY THE REQUIREMENTS OF, ANY REGULATOR, AUTHORITY, AUDITOR OR COURT.
28. LIMITATION OF LIABILITY
28.1N EITHER PARTY SHALL BE LIABLE TO THE OTHER FOR ANY INDIRECT, INCIDENTAL, SPECIAL, PUNITIVE OR CONSEQUENTIAL LOSS, OR FOR LOSS OF PROFIT, REVENUE, BUSINESS, ANTICIPATED SAVINGS, GOODWILL OR REPUTATION, HOWEVER ARISING, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH LOSS.
28.2 General cap. Subject to Clauses 28.3, 28.4 and 28.4A, the aggregate liability of either party arising out of or in connection with this Agreement, whether in contract, tort, under statute or otherwise, shall not exceed the higher of (a) INR 1,00,000 (Rupees One Lakh) and (b) the Fees paid and payable by the Customer under this Agreement in the twelve (12) months immediately preceding the first event giving rise to the claim.
28.3 Enhanced cap. In respect of claims arising from a breach by Fastlegal of Clause 16.3, Clause 17, Clause 18 or Schedule C, the aggregate liability of Fastlegal shall not exceed two hundred per cent (200%) of the Fees paid and payable by the Customer in the twelve (12) months immediately preceding the first event giving rise to the claim.
28.4 Matters not limited. Nothing in this Agreement limits or excludes liability for (a) fraud, fraudulent misrepresentation or wilful misconduct; (b) the Customer's indemnity at Clause 29.2; (c) the Customer's obligation to pay Fees; or (d) any liability which cannot lawfully be limited or excluded.
28.4A Matters subject to the enhanced cap. Liability arising from gross negligence, and Fastlegal's indemnity at Clause 29.1, shall be subject to the enhanced cap in Clause 28.3 and not to the general cap in Clause 28.2.
28.4B Statutory remedies for fraud preserved. For the avoidance of doubt, nothing in this Agreement shall restrict, exclude or otherwise affect any right, remedy, claim or proceeding available to either party under Applicable Law in respect of fraud or fraudulent misrepresentation, including under Sections 17 and 19 of the Indian Contract Act, 1872 and Section 447 of the Companies Act, 2013, and every such right and remedy shall be in addition to, and not in derogation of, the rights of the parties under this Agreement.
28.5 Regulatory penalties. Neither party shall be liable for any penalty, fine, censure or compounding cost imposed on the other by a regulator, save where it is directly and solely caused by that party's breach of this Agreement, and in that event subject to the caps in Clauses 28.2 and 28.3. Without limiting the foregoing, the Customer shall bear all penalties and consequences arising from its own configuration, data entry, credit decisions, disclosures, classifications and filings.
28.6 Each party shall take reasonable steps to mitigate its loss. No claim may be brought more than twelve (12) months after the claiming party became aware, or ought reasonably to have become aware, of the circumstances giving rise to it.
28.7 The service credits in Schedule A are the Customer's sole and exclusive financial remedy for failure to meet the availability commitment.
29. INDEMNITY
29.1 Fastlegal shall defend and indemnify the Customer against any third-party claim that the Platform, as supplied by Fastlegal and used in accordance with this Agreement and the Documentation, infringes any patent, copyright, trade mark or trade secret subsisting in India, and shall pay damages and costs finally awarded or agreed in settlement. This indemnity does not apply to a claim arising from (a) Customer Data or Customer-supplied content, templates or specifications; (b) modification of the Platform by any person other than Fastlegal; (c) use of the Platform in combination with software, hardware or data not supplied or approved by Fastlegal; (d) use contrary to this Agreement or the Documentation; or (e) continued use of a version of the Platform after Fastlegal has supplied a non-infringing update. Where a claim arises or is likely, Fastlegal may, at its option, procure the right to continue use, replace or modify the Platform, or terminate the affected Services and refund prepaid Fees for the unexpired term.
29.2 The Customer shall defend and indemnify Fastlegal against any claim, penalty, loss or expense arising from (a) Customer Data or the Customer's use of the Services in violation of Applicable Law or of this Agreement; (b) any claim by a borrower, guarantor, third party or authority relating to the Customer's lending decisions, pricing, disclosures, classification, collection, recovery or enforcement; (c) breach of Clause 10; or (d) any claim by a Data Principal or the Data Protection Board of India arising from the Customer's failure to give notice, obtain consent, or otherwise discharge its obligations as Data Fiduciary.
29.3 The indemnified party shall give prompt written notice of the claim, shall not admit liability or settle without the indemnifying party's consent, shall permit the indemnifying party to control the defence and settlement, and shall provide reasonable cooperation at the indemnifying party's cost.
30. FORCE MAJEURE
30.1 Neither party shall be liable for any failure or delay in performance (other than an obligation to pay money) caused by an event beyond its reasonable control, including act of God, flood, fire, earthquake, epidemic or pandemic, war, terrorism, civil disturbance, strike affecting third parties, failure of the public internet, telecommunications or power grid, cyber-attack on national infrastructure, or an act, order or restraint of government or a regulator.
30.2 The affected party shall notify the other promptly, shall use reasonable endeavours to mitigate and resume performance, and shall invoke its business continuity plan. If a force majeure event continues for more than thirty (30) consecutive days, either party may terminate the affected Services on written notice, and the Customer shall be entitled to a pro-rata refund of prepaid Fees for the unexpired term.
31. ASSIGNMENT AND CHANGE OF CONTROL
31.1 Neither party may assign or novate this Agreement without the prior written consent of the other, which shall not be unreasonably withheld, save that either party may assign to an affiliate or to a successor in a merger, amalgamation or sale of substantially all of its assets, on written notice.
31.2 Fastlegal shall notify the Customer within seven (7) days of any change in the control or beneficial ownership of Fastlegal. Where the Customer is an RE and reasonably determines that such change gives rise to a regulatory, competitive or security concern, it may terminate this Agreement on thirty (30) days' notice, with a pro-rata refund of prepaid Fees for the unexpired term.
32. NOTICES
32.1 Notices under this Agreement shall be in writing and shall be delivered by hand, by registered post or courier, or by electronic mail to the addresses stated in Annexure I or, in the absence of Annexure I, to the addresses on the account and, in the case of Fastlegal, to mail@fastlegal.in with a copy to the officers named in Clause 34.
32.2 Notices of breach, suspension, termination, incident and regulatory direction shall additionally be sent by electronic mail to the nodal officer of each party and shall be deemed given on the date of transmission, provided no delivery failure is received.
32.3 Each party shall notify the other of a change in its notice particulars within seven (7) days.
33. GOVERNING LAW AND DISPUTE RESOLUTION
33.1 This Agreement is governed by and shall be construed in accordance with the laws of India, without regard to conflict of law principles.
33.2 The parties shall first attempt to resolve any dispute amicably. Either party may refer the dispute in writing to the senior management of both parties, who shall meet within fifteen (15) days and endeavour to resolve it within thirty (30) days of the reference.
33.3A dispute not resolved under Clause 33.2 shall be referred to and finally resolved by arbitration under the Arbitration and Conciliation Act, 1996, by a sole arbitrator appointed by agreement of the parties, failing which as provided in that Act. The seat and venue of arbitration shall be Jaipur, Rajasthan, and the language shall be English. The award shall be final and binding.
33.4 Nothing in Clause 33.3 prevents either party from seeking urgent interim or injunctive relief from the courts at Jaipur, Rajasthan, which shall have exclusive jurisdiction for that purpose, nor affects the jurisdiction of any regulator or of the Reserve Bank — Integrated Ombudsman Scheme in respect of a borrower complaint.
33.5 Each party shall continue to perform its obligations during the pendency of a dispute, and Fastlegal shall not suspend the Services or withhold Customer Data by reason of a dispute, save as permitted by Clause 13.
34. GRIEVANCE REDRESSAL AND DESIGNATED OFFICERS
34.1 Fastlegal has designated the following officers. A grievance may be lodged with the Grievance Officer, who shall acknowledge it within twenty-four (24) hours and shall dispose of it within fifteen (15) days of receipt.
Role
Name
Telephone
Grievance Officer — under the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021
Mr. Manoj Gurjar
manoj@fastlegal.in
+91 96641 46595
Data Protection Officer — contact for the purposes of the Digital Personal Data Protection Act, 2023
Mr. Sushil Choudhary
sushil@fastlegal.in
+91 90248 28295
Nodal Officer — incidents, audits, regulatory and law-enforcement requests, exit management
Mr. Jitendra Sharma
jeetsharma@fastlegal.in
+91 97829 00038
General and support
Support desk
mail@fastlegal.in / support@fastlegal.in
—
34.2A Data Principal who is not satisfied with the disposal of a grievance may approach the Data Protection Board of India in accordance with the Digital Personal Data Protection Act, 2023 and the rules made thereunder. A borrower of the Customer shall address grievances relating to a loan to the Customer's own grievance redressal officer.
35. MODIFICATION OF THIS AGREEMENT
35.1 Where this Agreement has been accepted electronically and not executed under Annexure I, Fastlegal may modify it on notice by service announcement or by electronic mail to the Customer's primary email address. Where a modification materially affects the Customer's rights, not less than thirty (30) days' prior notice shall be given, and the Customer may terminate within that period with a pro-rata refund of prepaid Fees for the unexpired term. Continued use after the effective date of a modification constitutes acceptance.
35.2 Where this Agreement has been executed under Annexure I or under a separately negotiated agreement, no amendment or variation shall be effective unless made in writing and signed by an authorised signatory of each party. Fastlegal may, however, update the list of Sub-processors and Schedule A in the manner provided in Clauses 23.1 and A9 respectively.
36. MISCELLANEOUS
36.1 Entire agreement. This Agreement constitutes the entire agreement between the parties in relation to its subject matter and supersedes all prior proposals, representations and understandings, save for fraud.
36.2 Severability. If any provision is held invalid or unenforceable, it shall be severed and the remainder shall continue in full force.
36.3 Waiver. No failure or delay in exercising a right operates as a waiver, and no single or partial exercise precludes further exercise.
36.4 Relationship. The parties are independent contractors. Nothing creates a partnership, joint venture, agency or employment relationship, and neither party may bind the other.
36.5 No exclusivity. Nothing in this Agreement restricts the Customer from engaging any other service provider, or from developing its own capability, for any part of the services covered by this Agreement.
36.6 Counterparts and electronic execution. This Agreement may be executed in counterparts, and by electronic signature or digital signature affixed in accordance with the Information Technology Act, 2000, each of which shall be an original and all of which together shall constitute one instrument.
36.7 Stamp duty. Where this Agreement is executed physically, it shall be stamped in accordance with the Rajasthan Stamp Act, 1998 or the stamp law of the State in which it is executed, whichever is applicable, and the stamp duty shall be borne by the Customer unless otherwise agreed.
36.8 Third-party rights. No person other than a party to this Agreement has any right to enforce any of its terms.
SCHEDULE A
SERVICE LEVELS AND SUPPORT
This Schedule applies to a Cloud Subscription only. It does not apply to a Self-Hosted Deployment, to trials, pilots or proof-of-concept environments, or to features designated beta or preview.
A1. Availability
A1.1Fastlegal shall use commercially reasonable endeavours to make the production environment available for not less than 99.5% of the minutes in each calendar month, measured at the application health endpoint.
A1.2The following are excluded from the availability computation: scheduled maintenance notified under A2; emergency maintenance; suspension under Clause 13; force majeure; failure of a third-party integration, network or provider not procured by Fastlegal; failure of the Customer's own connectivity, endpoints or configuration; and unavailability caused by the Customer's breach or by use contrary to the Documentation.
A2. Scheduled maintenance
A2.1Scheduled maintenance shall be notified not less than forty-eight (48) hours in advance, shall ordinarily be carried out between 22:00 and 06:00 Indian Standard Time on Sundays, and shall not exceed eight (8) hours in a calendar month. Fastlegal shall endeavour to avoid maintenance during month-end, quarter-end and regulatory return submission windows notified by the Customer.
A2.2Emergency maintenance and security patching may be carried out without prior notice, with notice given as soon as practicable.
A3. Support
A3.1Support is available Monday to Saturday from 09:30 to 18:30 Indian Standard Time, excluding public holidays notified at Jaipur, Rajasthan. Severity 1 incidents are attended to outside these hours.
A3.2Support is provided through the in-application support channel and by electronic mail to support@fastlegal.in. Tickets are raised only by the Customer's designated administrators or nominated contacts.
A4. Severity levels, response and resolution
Severity
Definition
Response time
Target resolution or workaround
P1 — Critical
Production unavailable; disbursement, repayment posting, day-end or interest accrual processing halted; loss of data integrity; confirmed security or data breach.
1 hour
8 business hours
P2 — High
A major function is unavailable or materially impaired with no reasonable workaround; generation of a regulatory return, credit information file or statutory document is blocked and the due date falls within seven days.
4 business hours
2 business days
P3 — Medium
A non-critical function is impaired, or a function is impaired but a workaround exists.
1 business day
10 business days
P4 — Low
Cosmetic defect, documentation query, configuration assistance or enhancement request.
2 business days
Next scheduled release
A4.1Severity is assigned by Fastlegal in consultation with the Customer, acting reasonably. A severity classification may be escalated by the Customer's nodal officer with reasons.
A5. Service credits
Where monthly availability falls below the committed level, the Customer may claim a service credit against the next invoice, computed on the monthly subscription Fee for the affected environment:
Monthly availability achieved
Service credit
Below 99.5% but at or above 99.0%
5% of the monthly Fee
Below 99.0% but at or above 95.0%
10% of the monthly Fee
Below 95.0%
25% of the monthly Fee
A5.1Claims shall be made in writing within thirty (30) days of the end of the affected month. Credits in any month shall not exceed twenty-five per cent (25%) of the monthly Fee, are not payable in cash, and are the sole financial remedy for unavailability, without prejudice to the Customer's right to terminate under Clause 25.3.
A6. Backup and recovery
A6.1Fastlegal shall take daily backups of the production database and object storage, shall retain them for not less than thirty (30) days, and shall store them within India in encrypted form.
A6.2The recovery point objective is twenty-four (24) hours and the recovery time objective is eight (8) hours. Restoration shall be tested at least once every quarter and a summary of results made available on request.
A7. Environments
A7.1Fastlegal shall provide a production environment and a user acceptance testing environment. The user acceptance testing environment carries no availability commitment and shall not be used to process live Borrower Data except with masked or synthetic data.
A8. Releases
A8.1Minor releases shall be notified not less than three (3) business days in advance and major releases not less than fifteen (15) days in advance, in each case with release notes. Security patches may be applied at any time. Fastlegal shall not, without notice, remove functionality on which the Customer's configured processes depend.
A9. Variation of this Schedule
A9.1Fastlegal may improve the service levels in this Schedule at any time. Any change that reduces a service level requires thirty (30) days' prior notice, and, where the Customer objects, the Customer may terminate the affected Services under Clause 4.3.
SCHEDULE B
SELF-HOSTED (ON-PREMISE) DEPLOYMENT TERMS
This Schedule applies only where the Subscription Schedule records the deployment model as Self-Hosted. Where it applies, it prevails over the General Terms and over Schedule A to the extent of any inconsistency.
B1. Licence grant
Fastlegal grants the Customer, for the subscription term and subject to payment of the Fees, a non-exclusive, non-transferable, non-sublicensable, revocable licence to install, configure and operate the Platform on infrastructure owned, leased or otherwise controlled by the Customer and located within India, for one (1) production instance and one (1) non-production instance, for use by up to the number of Authorised Users stated in the Subscription Schedule, solely for the Customer's own lending business.
B2. Delivery
Fastlegal shall deliver the Platform in the form of deployable container images or build artefacts, together with the Documentation, deployment guide and configuration templates. No source code is delivered or licensed. Source code escrow, if required, shall be the subject of a separate tripartite escrow agreement and a separate fee.
B3. Environment and minimum specification
The Customer shall procure, provision and maintain, at its own cost, the infrastructure required to operate the Platform, being not less than the minimum specification stated in the Documentation, which as at the date of this Agreement comprises a server with four (4) virtual central processing units and eight (8) gigabytes of memory, PostgreSQL version 15 or later, Redis version 7 or later, storage compatible with the simple storage service application programming interface, a valid transport layer security certificate, and a supported operating system. Fastlegal shall notify any change to the minimum specification not less than sixty (60) days in advance.
B4. Customer responsibilities
In a Self-Hosted Deployment the Customer is solely responsible for: (a) the procurement, security, capacity, patching and hardening of the infrastructure, operating system, database, cache, storage and network; (b) firewalls, network segmentation, intrusion detection, endpoint protection and physical security; (c) database administration, tuning, indexing and archival; (d) backups, their encryption, their off-site storage and the periodic testing of restoration; (e) business continuity and disaster recovery, including the maintenance of a recovery site; (f) availability and uptime; (g) key management, secret storage and certificate renewal; (h) monitoring, alerting, log retention and log protection; (i) the application of updates and security patches supplied by Fastlegal; and (j) all compliance obligations arising from its custody of the data.
B5. Fastlegal responsibilities
Fastlegal shall, for so long as the annual maintenance charge is paid: (a) supply updates, new releases and security patches within the licensed scope; (b) supply release notes and updated Documentation; (c) provide remote support during the hours stated in paragraph A3.1 for defects in the Platform itself; and (d) provide reasonable assistance with upgrades. Fastlegal is not responsible for the Customer's environment, or for any defect arising from it.
B5A. Security advisories and vulnerabilities
Where Fastlegal becomes aware of a vulnerability in the Platform which it classifies as critical or high severity and which affects a version in use by the Customer, Fastlegal shall notify the Customer's nodal officer within seven (7) days of becoming aware of it, and shall supply a patch, an updated release or a documented workaround within a period commensurate with the severity. The notification shall state the affected versions, the nature and severity of the vulnerability, its potential impact, and the mitigating steps available pending remediation. The Customer shall apply the patch or workaround within the period stated in paragraph B9. Fastlegal does not operate or monitor the Customer's environment and is not able to detect a security incident occurring within it; the detection, investigation, containment and regulatory reporting of any such incident, including any report required to the Reserve Bank of India or the Indian Computer Emergency Response Team, are the sole responsibility of the Customer.
B6. No availability commitment
Schedule A does not apply. Fastlegal gives no availability, uptime, recovery time or recovery point commitment, and no service credits are payable, in respect of a Self-Hosted Deployment. Fastlegal shall have no liability for any downtime, data loss, corruption or breach arising from the Customer's environment, configuration, infrastructure, backups or operational practices.
B7. Licence key and telemetry
The Platform may require periodic activation or validation against a licence key. Validation transmits only the licence identifier, the instance identifier, the software version and the count of provisioned users. No Customer Data, Borrower Data or Personal Data is transmitted. The Customer shall not disable, block or tamper with the licence validation mechanism. Where the Customer's network policy prevents outbound validation, Fastlegal shall provide an offline activation mechanism.
B8. Access for support
Fastlegal shall have no standing access to the Customer's environment or to Customer Data. Where support requires access, the Customer shall grant time-bound, named, logged and supervised access, or shall furnish sanitised logs and reproduction data. Where the Customer declines to grant access or to furnish the information reasonably required, Fastlegal's support obligation in respect of that issue is suspended. Fastlegal acts as a Data Processor only for the duration and to the extent of such access, and Schedule C applies accordingly.
B9. Versions, updates and supported releases
The Customer shall apply security patches within thirty (30) days of supply and shall not operate a version older than the current release less two (2) minor versions. Fastlegal supports only the current release and the two immediately preceding minor releases. Support, warranties at Clause 27.2 and the indemnity at Clause 29.1 do not apply to an unsupported, modified or unpatched version.
B10. Restrictions
In addition to Clause 10, the Customer shall not: (a) install or operate more instances than licensed; (b) modify, patch, recompile or create derivative works of the Platform; (c) permit any third party to access the Platform, whether as a service bureau, managed service or otherwise; (d) use the Platform to service the loan portfolio of any other person; (e) copy the Platform except for one archival copy; or (f) remove or alter any licence marking, watermark or attribution.
B11. Verification of usage
Fastlegal may, once in each financial year and on not less than fifteen (15) days' notice, request a self-certification of the number of instances, Authorised Users and branches in use, supported by a system-generated report. Where a shortfall in Fees is established, the Customer shall pay the difference within thirty (30) days.
B12. Data protection in a Self-Hosted Deployment
The Customer is the sole custodian and Data Fiduciary in respect of all data held in a Self-Hosted Deployment. Fastlegal neither holds nor has access to such data. Clauses 15.1 to 15.3, 17, 21.1 to 21.3 and 26.3 to 26.4, and Schedule C Part A, apply only to the extent and for the periods that Fastlegal is granted access under paragraph B8. The security measures in Annexure C-2 describe controls built into the Platform; their effective operation depends on the Customer's configuration and environment.
B13. Termination
On expiry or termination, the Customer shall immediately cease all use of the Platform, uninstall and permanently delete all instances, images, artefacts and copies, and shall furnish within thirty (30) days a certificate signed by an authorised signatory confirming that it has done so. The Customer's own data remains with the Customer, and Fastlegal has no obligation to export, return, retain or erase it. Fastlegal shall deactivate the licence key. The Customer shall be entitled to retain read-only access to its own database for its statutory record-retention purposes, but shall not operate the Platform.
B14. Fees
A Self-Hosted Deployment is charged as a licence fee together with an annual maintenance charge as stated in the Subscription Schedule. Where the annual maintenance charge is not paid, the licence to use the version then installed continues for the balance of the subscription term, but entitlement to updates, patches and support ceases, and Fastlegal shall have no liability in respect of the unsupported version. Implementation, migration, integration and training are chargeable separately.
B15. Third-party and open-source components
The Platform incorporates third-party and open-source components, a list of which and of their licences shall be supplied with the delivery. The Customer shall comply with those licences. Fastlegal gives no warranty in respect of such components beyond passing through, to the extent permitted, any warranty it receives.
B16. Liability in a Self-Hosted Deployment
For the purposes of Clauses 28.2 and 28.3, "Fees" means the licence fee and annual maintenance charge paid and payable in the preceding twelve (12) months. Fastlegal shall have no liability whatsoever for loss, corruption, unavailability or unauthorised disclosure of data arising from the Customer's infrastructure, configuration, access management, backups or operational practices.
SCHEDULE C
DATA PROCESSING AND REGULATORY ADDENDUM
This Schedule forms part of the Agreement. Part A gives effect to Section 8(2) of the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025. Part B gives effect to the contractual requirements of the Reserve Bank of India (Outsourcing of Information Technology Services) Directions, 2023 and applies where the Customer is an RE to which those Directions apply.
PART A — DATA PROTECTION
C1. Roles of the parties
In respect of Borrower Data and all other Personal Data contained in Customer Data, the Customer is the Data Fiduciary and Fastlegal is a Data Processor processing such Personal Data on behalf of, and under the authority of, the Customer. In respect of the Personal Data of the Customer's own administrators and Authorised Users collected by Fastlegal for account administration, billing, support and security, and in respect of website visitors and prospects, Fastlegal is itself a Data Fiduciary and the Lenviq Privacy Policy applies.
C2. Processing on instructions
Fastlegal shall process Personal Data only for the purpose of providing, securing, supporting, maintaining and restoring the Services, and only on the documented instructions of the Customer, which instructions are constituted by this Agreement, the configuration of the Platform by the Customer, the actions of the Customer's Authorised Users, and any further written instruction given by the Customer's nodal officer. Where Fastlegal considers that an instruction contravenes Applicable Law, it shall inform the Customer without delay and may suspend compliance with that instruction.
C3. Purpose limitation
Fastlegal shall not process Personal Data for any purpose of its own, shall not sell, licence, trade or share it, and shall not use it for training or improving any artificial intelligence or machine learning model, in accordance with Clause 16.3.
C4. Security safeguards
Fastlegal shall implement and maintain the reasonable security safeguards set out in Annexure C-2 to prevent Personal Data Breach, and shall review them periodically and after any material incident or material change to the Platform.
C5. Personnel
Fastlegal shall ensure that persons authorised to process Personal Data are subject to binding obligations of confidentiality that survive the end of their engagement, receive periodic training on data protection and information security, are granted access on a need-to-know and least-privilege basis, and have their access revoked promptly on change of role or separation. Fastlegal shall carry out reasonable background verification of personnel having access to Customer Data.
C6. Sub-processors
Fastlegal may engage Sub-processors only in accordance with Clause 23 and only from the categories notified to the Customer under that Clause. Each Sub-processor shall be bound by written obligations no less protective than those in this Schedule, and Fastlegal remains liable for their acts and omissions.
C7. Personal Data Breach
On becoming aware of a Personal Data Breach affecting Customer Data, Fastlegal shall notify the Customer's nodal officer without undue delay and in any event within twenty-four (24) hours, and shall furnish, to the extent then known and thereafter as it becomes known: (a) the nature and brief description of the breach, including the categories and approximate number of Data Principals and records affected; (b) the circumstances and cause, including the time and duration of the breach and the time and manner of its detection; (c) the likely consequences relevant to the affected Data Principals; (d) the measures implemented or proposed to mitigate risk and to prevent recurrence; and (e) the contact details of the person from whom further information may be obtained. Fastlegal shall provide all cooperation reasonably necessary to enable the Customer to give intimation to each affected Data Principal and to the Data Protection Board of India within the timelines prescribed, and to make any report required to the Reserve Bank of India and the Indian Computer Emergency Response Team.
C8. Assistance with the rights of Data Principals
Fastlegal shall, taking into account the nature of the processing, assist the Customer by appropriate technical and organisational measures in fulfilling the Customer's obligations to respond to a Data Principal exercising the right to access information, the right to correction, completion, updating and erasure, the right of grievance redressal and the right to nominate. Where Fastlegal receives a request directly from a Data Principal in relation to Customer Data, it shall not respond to it substantively, shall inform the Data Principal to approach the Customer, and shall forward the request to the Customer within three (3) business days. Fastlegal shall action a written instruction of the Customer arising from such a request within seven (7) working days, or such shorter period as may be necessary to enable the Customer to meet a statutory timeline of which it has given notice.
C9. Localisation
Fastlegal shall process and store Personal Data only within India, in accordance with Clause 17.
C10. Retention and erasure
Fastlegal shall retain Personal Data only for so long as is necessary to provide the Services, and shall erase it in accordance with Clause 26.4 on the expiry or termination of this Agreement or on the Customer's written instruction, except where retention is required by Applicable Law, in which case the retained data shall continue to be protected under this Schedule and Clause 18.
C11. Records and audit
Fastlegal shall maintain records of its processing of Personal Data sufficient to demonstrate compliance with this Schedule, and shall make them available to the Customer, its auditors and any regulator in accordance with Clause 20.
C12. Children and persons with disability
The Services are not designed for or directed at children. Where a Data Principal is a child or a person with a disability having a lawful guardian, the Customer shall obtain verifiable consent of the parent or lawful guardian as required by the Digital Personal Data Protection Act, 2023 before processing, and shall not permit tracking, behavioural monitoring or targeted advertising directed at a child through the Services.
C13. Identifiers and minimisation
The Platform stores only the last four digits of an Aadhaar number and does not store, log or display a full Aadhaar number. No biometric information is collected or stored. Application logs are sanitised so as to exclude permanent account numbers, Aadhaar numbers and mobile numbers. The Customer shall not defeat these controls, including by entering such identifiers into free-text fields, and shall comply with Section 29 of the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and the regulations made thereunder.
C14. Credit information
Credit information obtained from a credit information company is received and used by the Customer as a specified user under the Credit Information Companies (Regulation) Act, 2005. Fastlegal shall hold it in confidence, shall use it only to render it to the Customer within the Services, and shall not disclose or use it for any other purpose.
C15. Contact
Requests, instructions and communications under this Part A shall be addressed to the Data Protection Officer named in Clause 34.1.
PART B — REGULATORY TERMS FOR OUTSOURCING OF INFORMATION TECHNOLOGY SERVICES
This Part applies where the Customer is a regulated entity to which the Reserve Bank of India (Outsourcing of Information Technology Services) Directions, 2023 apply. Both parties acknowledge that outsourcing does not diminish the obligations of the Customer or of its board and senior management, and that the Customer remains responsible for the acts and omissions of Fastlegal in relation to the outsourced service as if performed by the Customer itself.
C16. Scope and materiality
The nature and scope of the outsourced activity is the provision of the Platform and related support as described in Clause 4. The Customer shall determine whether the arrangement is a material outsourcing arrangement under its board-approved information technology outsourcing policy, and shall inform Fastlegal of that determination. Fastlegal shall comply with such of the Customer's board-approved outsourcing and information security policies as are communicated to it in writing and are consistent with this Agreement.
C17. Confidentiality and security of the Customer's information
Fastlegal shall preserve the confidentiality, integrity and availability of the Customer's information and of information relating to the Customer's borrowers, shall segregate it logically from that of any other client, and shall isolate and clearly identify the Customer's information at all times. Clause 18 and Annexure C-2 apply.
C18. Access to records and right to audit
Clause 20 applies. Fastlegal specifically acknowledges the right of the Customer, its auditors and the Reserve Bank of India to access, inspect, audit and take copies of documents, records of transactions, systems, premises and information relating to the Customer, and that no provision of this Agreement shall impede or delay the exercise of that right.
C19. Monitoring and control
Fastlegal shall furnish to the Customer such periodic management information as the Customer reasonably requires to monitor performance, service levels, incidents, capacity and risk, and shall participate in periodic service review meetings at a frequency agreed between the parties and not less than annually.
C20. Business continuity and disaster recovery
Clause 21 applies. Fastlegal shall maintain and periodically test a documented plan, shall support the Customer's own continuity testing, and shall ensure that the Customer is able to obtain its data and continue its operations in the event of Fastlegal's failure.
C21. Incident reporting
Clause 22 applies. Fastlegal shall report cyber security incidents within six (6) hours so that the Customer can meet the reporting timelines applicable to it.
C22. Sub-contracting and concentration
Clause 23 applies. Fastlegal shall not sub-contract material parts of the Services without the Customer's prior written consent, shall remain responsible for its sub-contractors, and shall not permit any chaining of sub-contracts outside India.
C23. Termination and exit
Clauses 25 and 26 apply. The Customer may terminate on the direction of the Reserve Bank of India, and Fastlegal shall support an orderly exit, including the transfer of data to the Customer or to a successor provider, without disruption to the Customer's business or to service to its borrowers.
C24. Ownership and location of data
The Customer owns all data relating to it and to its borrowers. All such data shall be stored and processed only in India, in accordance with Clause 17.
C25. Adverse events and change of control
Fastlegal shall notify the Customer of any event that may materially affect its ability to perform, and of any change of control, in accordance with Clauses 21.4 and 31.2.
C26. No impediment to supervision
Nothing in this Agreement shall be interpreted as restricting or impeding the Reserve Bank of India or any other regulator in the exercise of its powers of supervision, inspection, examination or direction over the Customer or over the outsourced service.
ANNEXURE C-1 — PARTICULARS OF PROCESSING
Subject matter
Provision of the Lenviq loan origination and loan management platform and related support services to the Customer.
Duration
The Term, together with the Transition Period and the erasure periods stated in Clause 26.4.
Nature and purpose
Hosting, storage, structuring, computation, retrieval, generation of documents and reports, transmission to third-party services configured by the Customer, backup, restoration, and support and incident resolution — in each case solely to provide the Services.
Categories of Data Principals
Applicants, borrowers, co-applicants, guarantors, mortgagors; directors, partners, karta, trustees, shareholders and ultimate beneficial owners of non-individual borrowers; references and contact persons; the Customer's employees and Authorised Users; direct selling agents, field agents and empanelled advocates, valuers, dealers, appraisers and auctioneers.
Categories of Personal Data
Name, date of birth, gender, photograph, signature and salutation; contact and address details; identity document particulars, including permanent account number, voter identity, passport, driving licence and the last four digits of an Aadhaar number; occupation, employment and income particulars; bank account and mandate particulars; obligations and credit information reports; collateral, valuation and insurance particulars; loan, repayment, delinquency and recovery records; audit trail and access logs.
Data not collected
Full Aadhaar numbers, biometric information and complete payment card numbers are not stored by the Platform.
Location of processing
India only.
ANNEXURE C-2 — TECHNICAL AND ORGANISATIONAL SECURITY MEASURES
Fastlegal implements and maintains the following measures. Measures may be replaced by others providing an equivalent or higher level of protection.
Control area
Measures
Tenant isolation
Row-level multi-tenancy with a tenant identifier and foreign key on every table; server-side enforcement of tenant scope on every request; global reference masters segregated from tenant data.
Access control
Role-based access control with defined roles, four data scopes and a permissions catalogue; least privilege; server-side authorisation on every action; separate platform administration plane; maker-checker on masters and on disbursement, with the maker prevented from approving own submission.
Authentication
Session-based authentication; time-based one-time password second factor enforced for approvers and administrators; session expiry of eight hours and idle expiry of thirty minutes; immediate session invalidation on suspension or de-provisioning; rate limiting on authentication endpoints.
Encryption
Transport layer security for data in transit; encryption at rest for the database, object storage and backups; integration credentials and secrets encrypted with AES-256-GCM, never returned in application responses and never written to logs; server-side proxying of all third-party calls.
Data minimisation
Aadhaar stored as last four digits only; no biometric capture; log sanitisation of permanent account numbers, Aadhaar numbers and mobile numbers; masking of secrets in the user interface.
Integrity and audit
Append-only audit log of every mutation, capturing user, timestamp and before-and-after state; sanction, disbursement and write-off recorded as immutable events with correction only by reversal entry; balanced-voucher enforcement in the accounting module.
Application security
Security response headers including content security policy, frame options and content type options; input validation; file upload size and media type validation; rate limiting on reporting and standard endpoints; dependency and vulnerability monitoring.
Logging and monitoring
Access and application logs retained within India for not less than one hundred and eighty days; system clocks synchronised to national time servers; alerting on anomalous access and error conditions; health endpoints.
Backup and recovery
Encrypted daily backups retained for thirty days within India; documented restoration procedure tested quarterly; documented business continuity and disaster recovery plan tested annually.
Personnel
Confidentiality undertakings; background verification for personnel with data access; periodic security and data protection training; prompt revocation of access on role change or separation; access to production granted on a need-to-know, time-bound and logged basis.
Assurance
Independent vulnerability assessment and penetration testing at least annually with time-bound remediation; internal change control and release management; annual review of these measures.
ANNEXURE C-3 — MAPPING TO THE RESERVE BANK OF INDIA (OUTSOURCING OF INFORMATION TECHNOLOGY SERVICES) DIRECTIONS, 2023
This table is provided for the convenience of the Customer's compliance function and does not vary the Agreement.
Requirement of the Directions
Where addressed
Nature and scope of the outsourced activity, and roles and responsibilities of the parties
Clauses 4, 5, 9 and C16
Confidentiality, integrity, availability and security of the regulated entity's information
Clauses 15, 16, 18, C17 and Annexure C-2
Right of the regulated entity and its auditors to audit and inspect
Clauses 20.1, 20.3 to 20.5 and C18
Access by the Reserve Bank of India to documents, records and premises; no impediment to supervision
Clauses 20.1, 20.2 and C26
Preservation of documents and records
Clauses 20.6, 15.3 and 26
Continuous monitoring and control, and periodic reporting
Clauses 20.4, C19 and Schedule A
Business continuity and disaster recovery, and testing
Clauses 21, A6 and C20
Reporting of security incidents and breaches
Clauses 22, C7 and C21
Controls on sub-contracting and chaining
Clauses 23 and C22
Termination rights, including on regulatory direction, and exit strategy
Clauses 25.5, 26 and C23
Ownership of data and storage within India
Clauses 16.1, 17 and C24
Notification of adverse events and change of control
Clauses 21.4, 31.2 and C25
Concentration risk and freedom to engage alternate providers
Clause 36.5
Liability of the service provider and indemnity
Clauses 28 and 29
Governing law and dispute resolution
Clause 33
ANNEXURE I
EXECUTION PAGE AND CUSTOMER PARTICULARS
Applicability. This Annexure applies only where the parties elect to execute this Agreement in physical form or by digital signature. Where the Customer accepts the Terms of Service electronically on the Lenviq platform, this Annexure does not apply, is not generated, and shall be disregarded.
Part 1 — Particulars of the Customer
Legal name of the Customer
Constitution
Public limited company / Private limited company / Other: ______________
Corporate Identity Number
Permanent Account Number
Goods and Services Tax Identification Number
Reserve Bank of India Certificate of Registration number and date
Classification and layer under the Scale Based Regulation framework
Registered office address
Corporate office address (if different)
Website
Authorised signatory — name and designation
Director Identification Number (if a director)
Authority — board resolution / power of attorney dated
Compliance Officer — name, email and telephone
Nodal Officer for this Agreement (Clause 9.7) — name, email and telephone
Grievance Redressal Officer of the Customer — name, email and telephone
Principal Officer under the Prevention of Money-Laundering Act, 2002
Billing contact — name, email and telephone
Technical / administrator contact — name, email and telephone
Address for notices under Clause 32
Part 2 — Subscription particulars
Deployment model
Cloud Subscription ☐ Self-Hosted Deployment ☐ (if Self-Hosted, Schedule B applies)
Subscription plan
Starter ☐ Growth ☐ Enterprise ☐ Custom ☐
Modules subscribed
Loan Origination ☐ Loan Management ☐ Accounting ☐ Regulatory Returns ☐ Credit Information Reporting ☐ Document Engine ☐
Number of Authorised Users
Number of branches
Effective Date
Initial term
Renewal
Automatic renewal for successive terms of like duration under Clause 25.1, unless notice of non-renewal is given
Subscription fee (₹, exclusive of tax)
Billing cycle
Monthly ☐ Quarterly ☐ Annual ☐
Payment terms
Within fifteen (15) days of invoice date, unless stated otherwise here: ______________
One-time implementation / onboarding fee (₹)
Data migration
In scope ☐ Not in scope ☐ Fee (₹): ______________
Training
Number of sessions: ________ Mode: ______________
Annual maintenance charge (Self-Hosted only) (₹)
Special terms, if any
Part 3 — Documents forming this Agreement
The parties confirm that the following documents, each of which has been read and understood by the Customer, together constitute the Agreement:
–General Terms of the Lenviq Terms of Service and Master Subscription Agreement, Version 2.1
–Schedule A — Service Levels and Support
–Schedule B — Self-Hosted Deployment Terms (applicable only where elected in Part 2)
–Schedule C — Data Processing and Regulatory Addendum, with Annexures C-1 to C-3
–The Lenviq Privacy Policy, Version 2.0
–This Annexure I
Part 4 — Execution
IN WITNESS WHEREOF the parties have executed this Agreement on the date and at the place stated below.
For FASTLEGAL TECHNOLOGIES PVT. LTD.
Signature: ______________________________
Name: __________________________________
Designation: ____________________________
Date: ___________________________________
Place: __________________________________
Company seal:
For the CUSTOMER
Signature: ______________________________
Name: __________________________________
Designation: ____________________________
Date: ___________________________________
Place: __________________________________
Company seal:
Witnesses
Witness 1
Name: __________________________________
Address: ________________________________
_________________________________________
Signature: ______________________________
Witness 2
Name: __________________________________
Address: ________________________________
_________________________________________
Signature: ______________________________
Note on stamping: This Agreement is to be stamped in accordance with the stamp law of the State in which it is executed, before or at the time of execution. An unstamped or insufficiently stamped instrument may be inadmissible in evidence until the duty and penalty are paid.