SHATABDI LEAPROFIN PRIVATE LIMITED

Consent Management Policy

Document No.: SHB/CMP/01/2026

Version: 1.0

Policy Owner: Compliance Department

Approved By: Board of Directors

Review Frequency: Annual or as required by applicable laws and regulatory directions.

1. Purpose

This Consent Management Policy establishes the governance framework for obtaining, recording, managing, reviewing, storing, sharing, and withdrawing customer consent for the collection, processing, use, disclosure, and retention of personal data by Shatabdi Leaprofin Private Limited.

The policy ensures that personal data is processed lawfully, fairly, transparently, and in compliance with applicable laws while protecting customer privacy and confidentiality.

2. Scope

This policy applies to all personal data processed by the company through physical or digital channels and is binding upon:

  • Directors and Employees
  • Customers and Prospective Customers
  • Co-applicants and Guarantors
  • Lending Service Providers (LSPs)
  • Direct Selling Agents (DSAs)
  • Business Correspondents
  • Collection Agencies
  • Technology Service Providers
  • Vendors and Outsourcing Partners
  • Any entity processing personal data on behalf of the Company

Applicable across:

  • Website
  • Mobile Application
  • Customer Portal
  • Branch Offices
  • Call Centres
  • APIs
  • Other Digital Platforms

3. Regulatory Framework

This policy complies with:

  • Digital Personal Data Protection Act, 2023
  • Information Technology Act, 2000
  • RBI Digital Lending Guidelines
  • RBI KYC Master Direction
  • RBI Fair Practices Code
  • RBI Outsourcing Guidelines
  • Other applicable RBI Circulars and Directions

4. Consent Principles

Customer consent must be:

  • Freely Given
  • Specific
  • Informed
  • Unambiguous
  • Purpose Limited
  • Revocable
  • Auditable

The company shall not rely on implied consent, silence, inactivity, or pre-selected checkboxes.

5. Collection of Consent

Consent shall be obtained before processing personal data for:

  • Customer onboarding
  • Loan application processing
  • KYC verification
  • Credit bureau enquiries
  • Bank account verification
  • Digital agreements
  • Electronic mandates
  • Loan servicing
  • Customer support
  • Fraud prevention
  • Risk management
  • Regulatory reporting
  • Marketing communications (with separate optional consent)

Marketing consent shall always be independent and optional.

6. Customer Information Notice

Before obtaining consent, customers shall be informed about:

  • Company identity
  • Purpose of data collection
  • Categories of personal data collected
  • Data sharing entities
  • Data retention period
  • Customer rights
  • Withdrawal procedure
  • Grievance Officer details

7. Mobile Application Permissions

The company follows the principle of Data Minimisation.

The company shall not access or collect:

  • Contact List
  • SMS Messages
  • Call Logs
  • Photo Gallery
  • Videos
  • Audio Recordings
  • Microphone
  • Location Data
  • Device Storage

unless:

  • Required for legitimate business purposes
  • Permitted under applicable law
  • Clearly disclosed
  • Supported by explicit customer consent

Customer data shall never be used for intimidation, harassment, or unauthorized disclosure.

8. Consent Records

The company shall securely maintain records containing:

  • Customer Identification Number
  • Consent Reference Number
  • Purpose of Consent
  • Date & Time
  • Authentication Method
  • Version of Consent Notice
  • Consent Status (Active/Withdrawn/Expired)

These records shall be retained for audit and regulatory requirements.

9. Withdrawal of Consent

Customers may withdraw optional consent through:

  • Mobile Application
  • Website
  • Customer Support
  • Email
  • Written Request

Withdrawal does not affect:

  • Previous lawful processing
  • Legal obligations
  • Contractual obligations
  • Fraud prevention
  • Loan servicing and recovery activities

10. Data Sharing

Personal data may be shared with:

  • Reserve Bank of India
  • Credit Information Companies
  • Banks
  • Payment System Participants
  • Lending Service Providers
  • Collection Agencies
  • Government Authorities
  • Courts & Tribunals
  • Law Enforcement Agencies
  • Other legally authorized entities

Third parties must maintain confidentiality and implement appropriate security controls.

11. Information Security

The company shall implement:

  • Encryption
  • Role-Based Access Control
  • Multi-Factor Authentication
  • Secure Application Architecture
  • Audit Logging
  • Vulnerability Assessments
  • Penetration Testing
  • Security Incident Response Procedures
  • Backup & Disaster Recovery Mechanisms

12. Roles and Responsibilities

Responsible parties include:

  • Board of Directors
  • Senior Management
  • Compliance Department
  • Information Security Team
  • Business Units
  • Employees

13. Monitoring and Audit

Periodic reviews shall include:

  • Consent Collection Practices
  • Consent Records
  • Audit Trails
  • Third-Party Compliance
  • Data Processing Activities
  • Customer Complaints

Material observations shall be reported to Senior Management and the Board.

14. Non-Compliance

Unauthorized collection, access, disclosure, processing, or misuse of personal data may result in:

  • Disciplinary Action
  • Employment Termination
  • Contractual Remedies
  • Legal Proceedings

15. Policy Review

The policy shall be reviewed:

  • At least annually
  • Whenever there is a material change in:
    • Applicable laws
    • Regulatory requirements
    • Business operations
    • Technology
    • Risk profile

Annexure A – Consent Matrix

Processing ActivityConsent Requirement
Loan Application & ProcessingMandatory
KYC VerificationMandatory
Credit Bureau EnquiryMandatory
Bank Account VerificationMandatory
e-Sign & Digital AgreementMandatory
Loan Servicing CommunicationsMandatory
Collection CommunicationsMandatory
Marketing SMSOptional
Promotional EmailsOptional
WhatsApp Promotional MessagesOptional
Cross-selling of ProductsOptional