NAVI PRIVACY POLICY

Last updated: December 21, 2020

PLEASE READ THIS POLICY CAREFULLY BEFORE USING THE APP

The Navi App is made available by Navi Technologies Private Limited (“our”, “us”, “we”, “Company”), having its registered office at 3rd Floor, Salarpuria Business Center, 93, 5th A Block, Koramangala Ind Layout, Bengaluru – 560 095, Karnataka, India. In order to provide you with the Services, process your loan requests, and to ultimately provide a loan to you (and co-applicants, if any) with the Services, process your loan requests, and to ultimately provide a loan to you, we (i.e., the Company) and Navi Finserv Private Limited (formerly known as Chaitanya Rural Intermediation Development Services Private Limited) (the "Lending Partner") need to collect various data and information from you. The manner in which this data and information is collected, retained, shared, stored, and processed by us (i.e., the Company) and our Lending Partner is addressed in this Navi Privacy Policy (“Policy”). We may revise this Policy as well as update the Services and the App from time to time, so please keep visiting this page regularly to take notice of any changes we make. If you do not agree with any part of this Policy, please stop using our Services immediately.

This Policy, incorporates, and includes our Terms and the Agreement(s) executed by you (and co-applicants, if any) for availing the lending products made available by the Lending Partner (“User Loan Agreement”). Words and phrases not defined in this Policy shall mean the same as provided in the Terms. All references to you (as a user / visitor) shall include references to all co-applicants, if any.

1. Contact Information

Summary: You may reach out to the data grievance officer, Shikha Gupta at: help@navi.com confidentially to enquire about the treatment of your data.

We and our Lending Partner have appointed a data grievance officer. Our data grievance officer is: Shikha Gupta, accessible via email at: help@navi.com. You can contact the officer confidentially by email to enquire about the treatment of your data by us or our Lending Partner.

2. WHAT DATA IS COLLECTED?

Summary: We and the Lending Partner collect certain information provided by you, some of which is sensitive personal information. We have detailed the manner in which this data is collected.

By using the App, you consent to providing us and our Lending Partner, data in the ways listed below. We collect the data you provide to ensure that we can provide you Services in the best manner possible. Our Lending Partner uses this data to underwrite (i.e. assess the risk it will be taking) any loan it might offer you and to determine the rates and tenure for such loans. The data being asked from you helps us and our Lending Partner to provide services to you in a robust and user-friendly manner. We have detailed the manner in which we and our Lending Partner collect data below:

S. No. Means of Gathering Data Data Collected
1 Data you input in the course of signing up and using our Services

Navi Account Data: We and our Lending Partner collect the data you provide when you create or update your Navi Account. This includes your name, phone number, email ID, PAN, date of birth, pin code, nature of employment and name of employer, monthly income, marital status and relationship with the co-applicant (in case the loan is being sought by more than a single applicant). We or our Lending Partner may require you to share further information on a later date to confirm the veracity of your information or pursuant to any additional features added to the App.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.

Financial and KYC Information: We and our Lending Partner collect the data you provide when you accept the tentative terms of the loans. This includes your photograph, Aadhaar Number, PAN, parents’ names, bank account number, IFSC, proof of address (which can be your electricity bill, rental/lease agreement, gas bill, passport or driver’s license, or voter’s identity card or any other document our App may be able to record).

Other Data Solicited: You may be required to provide further information to the Lending Partner for the purposes of processing your loan application. Such additional information may include (without limitation) bank statements, goods and services tax returns, salary and income statements and title documents for the property being financed. This data shall be supplied to the Lending Partner through us. You may also be required to provide this information to us and the Lending Partner via physical documents, e-mail or other digital and offline methods.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For assessing the quantum and interest rate of loan to be extended; For Legal Compliance and Requirements.

Feedback Data and Other Data: This includes the following:

  • If you call our call centers, we may record information provided by you to service you or record the calls for quality and training purposes.
  • Data you input when you participate in our referral programs or use any discount codes offered by us.
  • If you provide any feedback or comments to us on the App.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For assessing the quantum and interest rate of loan to be extended; For Legal Compliance and Requirements.

2 Data we collect from your usage of our Services

Geolocation data: We and our Lending Partner collect the location data from you in two ways: (i) when you add the pin code as part of your Navi Account data; and (ii) from your mobile device when enabled by you to do so. We collect this data when our App is running in the background of your mobile device. You will not be able to use the App if you disable the location services.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.

User Personal Information: Our app collects user account data which includes email address, name to log in to the app. This information is required as part of the registration process to access our service and it is also used to auto populate relevant fields in the course of the interface of our app. Our app also collects mobile numbers for verification to check the active SIM status on the device, uniquely identify you and prevent fraud and unauthorized access.

Phone Book Contacts: When you grant us access to the address book on your mobile device, then we and our Lending Partner access and store the names and contact information from your address book to facilitate invitations, assess your phone usage and habits. You will not be able to use the App if you disable this access. As part of the loan journey, we collect all of your phonebook contacts which includes their contact names, phone numbers, account types, favorites (starred) and contact labels to enrich your financial profile. We use this data to determine your social network from your phonebook contacts and identify fraudulent contacts in your network. This helps us in detecting fraud loan applications and reducing credit risk.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication.

Financial SMS Data: When you grant us access to the SMSs on your mobile device, then we and our Lending Partner collect SMS data stored on your mobile device. You will not be able to use the App if you disable this access.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication

App Data: We and our Lending Partner collect the data about your installed applications, including the applications that you have installed on and from the date you create your Navi Account and the manner in which you use them. This also includes having access and permission to send you messages and notifications via your social media and instant messaging applications. You will not be able to use the App if you disable this access.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach.

Usage data: We collect data about how you interact with our Services. This includes data such as access dates and times, App features or pages viewed, App crashes and other system activity, type of browser, and third-party sites or services used before or in the course of interacting with our Services.

How we use this data: See, For Enabling the App and its Services; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.

Transaction information: We collect transaction information related to the use of our Services, including the type of Services requested, date and time the Service was provided, loan availed, interest payable, EMI selected, and payment method. Additionally, if someone uses your promotion code, we may associate your name with that person and their usage of the App.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For Enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.

Device data: We collect data about the devices used to access our Services, including the hardware models, device IP address, operating systems and versions, software, preferred languages, unique device identifiers, advertising identifiers, serial numbers, device motion data, and mobile network data.

How we use this data: See, For Enabling the App and its Services; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach.

Storage: This permission is required so that users' documents can be securely downloaded and saved on users' phones and upload the right documents for a faster approval and disbursal of the loan. This helps provide a very smooth and seamless experience while using the app.

3 Information we receive from other sources

We may also be working closely with third parties (including, for example, credit information bureaus, business partners, technical sub-contractors, analytics providers, search information providers, title deeds, property verification service providers and valuers) and may lawfully receive information about you and your co-applicant from such sources. Such data may be shared internally and combined with data collected on the App.

How we use this data: See, For Enabling the App and its Services; For Loan Processing and KYC Authentication; For Enabling Customer Support; For Research and Development; For Enabling Communications Between You and Us; For enabling Marketing and Outreach; For Automated Decisions; For Legal Compliance and Requirements.

3. How and Why Is the Collected Data Used?

Summary: The Company and the Lending Partner collect and use data collected from you to ensure that the Services are as up to date as possible and provided in the most optimal manner to you.

The data that is collected in accordance with Section 2 above will be used in the manner detailed below:

S. No. Reason of Use Manner of Use
1 For Enabling the App and its Services

We use the data collected to personalize, maintain and improve our Services. This includes using the data to:

  • Create and update the Navi Account.
  • Analyze your loan eligibility and estimate your loan terms.
  • Track the disbursement and repayment of the loan.
  • Enable features that allow you to add and remove bank accounts for your loan repayment and disbursements from time to time.
  • Enable features that help you check your loan history, credit scores (as provide on government databases), and other such App features as may be added from time to time.
  • Perform internal operations necessary to provide our Services, including to troubleshoot software bugs and operational problems; to conduct data analysis, testing, and research; and to monitor and analyze usage and activity trends.
2 For Loan Processing and KYC Authentication

Our Lending Partner uses the data to analyze your creditworthiness, loan eligibility, KYC documents, and the terms of your loans. While we collect the Financial and KYC Information, the Lending Partner is required to individually process the loan requests and verify the KYC documentation received. Failing to process such data means that you cannot be provided any loans.

3 For Enabling Customer Support

We use the information to provide customer support, including to resolve your concerns from the use of the Services, and train our customer service executives.

4 For Research and Development

We may use the data so collected for research, analysis, and product development to improve the UI/UX experience – all of which will ultimately improve how you experience the App. This also helps us develop automated actions to be triggered in certain events, such as when we need to identify if photographs uploaded are not clear, fraud takes place, IFSC is incorrect etc.

5 For Enabling Communications Between You and Us

We may add features that allow you to call us (through the App or otherwise), similarly, we may also need to contact you (through the App or any other channels that you give us access to, such as WhatsApp or Facebook).

6 For Marketing and Outreach

We may use the data we collect to market the App and our Services. This includes sharing your feedback, ratings and screen names for purely promotion and marketing purposes. Such promotion and marketing may be done via hoardings, banners, pamphlets etc.

7 For Automated Decisions

The App may provide automated features for customer responses, reimbursement tracking, etc. As our App grows, we will keep adding more automated features to the App.

8 For Legal Compliance and Requirements

We may use the data we collect to investigate or address claims or disputes relating to use of our Services, or as otherwise allowed by applicable law, or as requested by regulators, government entities, and official inquiries.

9 For Product Innovation

We may use the data we collect to offer new products and services for your use.

4. How Do We Share The Collected Information?

Summary: Please note that while none of your data is sold, it is shared with third parties on a contractual basis. This data is shared for processing of information and ensuring that you receive the Services.

We are very protective about your data. We may enter into data-sharing agreements or disclose the collected data in order to provide the Services and new product offerings to you. We have detailed the manner in which we and the Lending Partner share the collected data below:

S. No. Person Shared With Purpose for Sharing
1 Sharing with third parties

Service Providers: We work with third party service providers to execute various functionalities of the App and we may share your information with such service providers to help us provide the App. Some of these functionalities may include:

  • Analyzing transaction behavior and cashflows via your SMSs, bank statements, goods and services tax returns, salary and income statements, income tax returns, basis which your loan offer is generated.
  • Validating and authenticating the official verification documents provided by you.
  • Validating your preferred bank account, as well as transferring the loan amounts to you.
  • E-signing of the User Loan Agreement or Sanction Letter, populating the User Loan Agreement or the Sanction Letter. The information shared with these service providers is retained for auditing of the agreements.
  • eNACH/ NACH set-up to enable autopay.
  • Analyzing customer behaviour and to automate our marketing and outreach efforts.
  • Detection and flagging of fraud.
  • Cloud services.
  • Gathering of additional information regarding your bank account and statement details, in case adequate information has not been provided by you or through the other service providers we work with.
  • For manually collecting any sums owed by you to our Lending Partner.

Third Party Services: The App may allow you to connect with other websites, products, or services that we don’t have control over (for example, if we allow you to pay through an external wallet facility then we will have to share your usage information with the facility provider). However, usage of such third-party services is subject to their privacy policies and not within our control. We recommend that you have a look at their privacy policies before agreeing to use their services.

Affiliates and Group Companies: Subject to applicable law, we may share any data we have collected or collect from you with our affiliates and group companies for product research and development, advertising relevant products to you, and to tailor the products for your benefit.

LINK TO THIRD-PARTY SDK

Our application has a link to a registered third party SDK which collects data on our behalf and data is stored to a secured server to perform a credit risk assessment. We ensure that our third party service provider(s) take security measures in order to protect your personal information against loss, misuse or alteration of the data.

Our third-party service provider(s) employ separation of environments and segregation of duties and has strict role-based access control on a documented, authorized, need-to-use basis. The stored data is protected and stored by application-level encryption. They enforce key management services to limit access to data.

Furthermore, our registered third party service provider(s) provide hosting security – they use industry-leading anti-virus, anti-malware, intrusion prevention systems, intrusion detection systems, file integrity monitoring, and application control solutions.

Change in Control: While negotiating or in relation to a change of corporate control such as a restructuring, merger or sale of our assets, we may have to disclose our databases and information we have stored in the course of our operations.

2 Sharing with law enforcement when needed

If any governmental authority or law enforcement officers request or require any information and we think disclosure is required or appropriate in order to comply with laws, regulations, or a legal process.

5. What are Your Rights Regarding The Data?

Summary: We have identified your rights in the table above and the manner in which you may exercise these rights.

It is important for us that you remain in control of your data. Please write to us at help@navi.com if you wish to exercise any of your rights under the Policy. You shall have the following rights:

S. No. Person Shared With Purpose for Sharing
1 Right to rectification

In the event that any personal data provided by you is inaccurate, incomplete or outdated then you shall have the right to provide us with the accurate, complete and up to date data and have us rectify such data at our end immediately. We urge you to ensure that you always provide us with accurate and correct information/data to ensure your use of our Services is uninterrupted.

2 Right to withdraw consent

You have the right to withdraw your consent to this policy by uninstalling the App. However, if you have availed any loans from our Lending Partner, we shall have the right continue processing your information till such loan has been repaid in full, along with any interest and dues payable.

However, we shall not retain your data and information if it is no longer required by us and there is no legal requirement to retain the same. Do note that multiple legal bases may exist in parallel and we may still have to retain certain data and information at any time.

3 Right to opt-out

Marketing opt-outs: We may email and notify you from time to time about our latest offerings and updates. You may opt out of receiving such promotional emails from us by writing to us. You may also opt out of receiving emails and other messages from us by following the unsubscribe instructions in those messages. However, even if you have opted out of receiving information from us, we will still send non-promotional communications, such as receipts for amount remittance etc.

Push Notifications: You can opt out of receiving push notifications through your device settings. Please note that opting out of receiving push notifications may impact your use of the App.

6. What Is Our Data Security Practice?

Summary: We aspire to keep your data and information as secure as possible and to that effect we have used state of the art software.

By setting up a Navi Account, you agree to our and the Lending Partner’s processing, storage, usage, and sharing of the data provided by you pursuant to this Policy. If you do not agree with any of the terms of this Policy or the Terms or wish to revoke any consent you have provided to us and/or the Lending Partner, please write to us at help@navi.com. However, please note that if you revoke any mandatory permissions or revoke the consent to process and store information such as your Navi Account data, Financial and KYC Information and/or any other information needed to facilitate your loan amounts, then we may have to cease the provision of Services to you. You cannot withdraw your consent once you have availed a loan using the App till you have repaid the loan amount and all related charges in its entirety.

7. Consent Mechanism

Summary: By applying for a loan, you have consented to all our data privacy practices. You can write to help@navi.com if you wish to revoke any consent.

By setting up a Navi Account, you agree to our and the Lending Partner’s processing, storage, usage, and sharing of the data provided by you pursuant to this Policy. If you do not agree with any of the terms of this Policy or the Terms or wish to revoke any consent you have provided to us and/or the Lending Partner, please write to us at help@navi.com. However, please note that if you revoke any mandatory permissions or revoke the consent to process and store information such as your Navi Account data, Financial and KYC Information and/or any other information needed to facilitate your loan amounts, then we may have to cease the provision of Services to you. You cannot withdraw your consent once you have availed a loan using the App till you have repaid the loan amount and all related charges in its entirety.

8. Data Retention

Summary: We retain your personal data to the extent we need to. Once the legal basis for the retention expires, we will not hold onto it.

We shall retain the information you provide to facilitate your smooth and uninterrupted use of the App, and (i) to provide, improve and personalize our Services; (ii) to contact you about your account and give customer service; (iii) to personalize our advertising and marketing communications; and (iv) to prevent, detect, mitigate, and investigate fraudulent or illegal activities. We do not retain your personal data for longer than required for the purpose for which the information may be lawfully used. For any other information, we may entertain your request for deletion, however, you may not be able to use our Services at all after such deletion.

9. Children’s Privacy

Our Services are not directed to children, and we do not knowingly solicit or collect personal information from persons under the age of 18 (eighteen). If we find out that a child has given us personal information, we will take steps to delete that information and terminate the relevant Navi Account.

10. Communications From Us

We may from time to time send you Service-related announcements when we consider it necessary to do so (such as when we temporarily suspend the App for maintenance, or security, privacy, or administrative-related communications). We send these to you via SMS/push notifications/email/instant messaging, as we deem fit.

11. Updates To This Notice

We may occasionally update this Policy. Use of our Services after an update constitutes consent to the updated notice to the extent permitted by law. Please take the time to periodically review this Policy for the latest information on our privacy practices.