Privacy Policy
Privacy Policy of Rezolv AI Technology Solutions Pvt. Ltd.
PRIVACY POLICY
Table of Contents
1. Introduction
Rezolv AI TechnologySolutions Pvt. Ltd. or referred herein as “Rezolv” ("Company","we", "our", or "us"), a technology serviceprovider that offers a software platform to regulated entities such as banksand non-banking financial companies (NBFCs) to support their debt collectionoperations. Rezolv does not act as a debt collection or recovery agency anddoes not itself pursue debts; the regulated entities that engage Rezolvdetermine the purpose, means, and strategy of any debt collection activitycarried out using the Platform, is committed to protecting the privacy ofindividuals ("you", "your", or "users") who visitour website and/or use our mobile application (collectively, the"Platform"). This Privacy Policy outlines how we collect, use,disclose, and safeguard your personal information when you interact with ourPlatform.
By accessing or using ourPlatform, you agree to the collection and use of information in accordance withthis Privacy Policy. This policy has been developed in compliance withapplicable data protection laws in India, including but not limited to the InformationTechnology Act, 2000, and the associated Information Technology (ReasonableSecurity Practices and Procedures and Sensitive Personal Data or Information)Rules, 2011.
The purpose of this PrivacyPolicy is to inform you about the types of personal data we collect, how weprocess it, your rights concerning your personal data, and the steps we take toprotect it. If you do not agree with the terms of this policy, you are advisednot to use our Platform.
2. Definitions
For the purposes of thisPrivacy Policy, the following terms shall have the meanings ascribed to themunless the context requires otherwise:
● "Personal Data" refers to anyinformation that relates to an identified or identifiable individual, such asname, contact details, identification number, location data, financialinformation, or any other data that, either directly or indirectly, can be usedto identify a person.
● "Processing" means any operation orset of operations performed on Personal Data, whether by automated means orotherwise, including but not limited to collection, recording, organization,structuring, storage, adaptation, alteration, retrieval, consultation, use,disclosure, dissemination, alignment, combination, restriction, erasure, ordestruction of such data.
● "Third Parties" refers to anyexternal entities, including service providers, partners, or affiliates, thatmay access or process Personal Data in connection with the services provided byRezolv.
● "Cookies" refers to small data filesstored on your device when you visit a website, which may be used to rememberyour preferences, collect analytics, and improve your experience on thePlatform.
● "Data Principal" refers to theindividual to whom the Personal Data relates. In this Privacy Policy, the DataPrincipal is referred to as "you" or "your."
● "Data Fiduciary" means any person,including the State, a company, or any entity, who determines the purpose andmeans of processing Personal Data. For the purposes of this Privacy Policy, theregulated entities (such as banks and NBFCs) that engage Rezolv’s services arethe Data Fiduciaries in respect of customer data shared with Rezolv, as theydetermine the purpose, means, and strategy of processing such data, includingany debt collection activity. Rezolv acts as a Data Processor on their behalf.Rezolv may also act as a Data Fiduciary only in respect of limited categoriesof data it independently collects, such as data of visitors to its website orits own personnel and authorised platform users.
● "Data Processor" refers to anyperson or entity that processes Personal Data on behalf of the Data Fiduciary.
● "Sensitive Personal Data or Information" (SPDI) refers to specific categories of personal data that are given a higherlevel of protection under Indian law. This includes but is not limited topasswords, financial information (such as bank account or payment instrumentdetails), health information, biometric data, sexual orientation, and any otherinformation as prescribed under applicable laws.
● "Anonymization" refers to theirreversible process of transforming personal data in such a manner thatindividuals can no longer be identified, either directly or indirectly, fromthe data, thereby making it impossible to trace the data back to a specificindividual.
● "Pseudonymization" refers to theprocessing of Personal Data in such a manner that it can no longer beattributed to a specific Data Principal without the use of additionalinformation, provided that such additional information is kept separately andis subject to technical and organizational measures to ensure that the PersonalData is not attributed to an identified or identifiable person.
● "Data Breach" refers to any unlawfulor unauthorized access, acquisition, disclosure, alteration, loss, ordestruction of Personal Data, which compromises the security, confidentiality,or integrity of such data.
● "Grievance Officer" refers to theindividual designated by the Company, in compliance with Indian laws, who isresponsible for addressing any concerns or complaints regarding the processingof Personal Data.
● "Third-Party Service Providers"refers to external entities that assist the Company in providing services,including but not limited to IT service providers, cloud service providers,payment processors, or marketing platforms, who may have access to PersonalData for the purpose of performing their services.
● "User Account" refers to the accountcreated by a user on the Platform to access services, wherein certain personalinformation may be collected and stored for providing tailored services.
● "Withdrawal of Consent" refers tothe right of a Data Principal to revoke their consent to the processing oftheir Personal Data at any time, without affecting the legality of processingbased on consent prior to its withdrawal.
3. Types of Information Collected
Rezolv may collect the followingtypes of information when you use our website and/or mobile application("Platform"):
3.1Personal Information
Personal Information refers toany data that can identify you as an individual. The types of PersonalInformation we collect may include, but are not limited to:
● Contact Information: Name, email address, phone number, postal address, and other similarcontact details.
● Identity Information: Date of birth, government-issued identification numbers (such as PAN,Aadhaar, or passport numbers), and any other information required for identityverification.
● Financial Information: Bank account details, credit or debit card information, loan or debtinformation, credit history, and other financial data shared with Rezolv by itsregulated entity clients (such as banks and NBFCs) to enable the operation ofthe Platform that supports their debt collection workflows. Such data isprocessed by Rezolv strictly on the instructions of, and on behalf of, therelevant regulated entity.
● Communication Data: Information collected through your correspondence with us, includingdetails of inquiries, complaints, or feedback submitted to us via the Platformor other communication channels.
● Account Information: Usernames, passwords, and any other information you provide whencreating an account on the Platform.
● Transaction Data: Details of payments, recoveries, or any other transactions youperform using the Platform.
3.2Non-Personal Information
Non-PersonalInformation refers to any data that cannot be used to identify you as anindividual and may include:
● Device Information: Details about the device used to access the Platform,such as hardware model, operating system, unique device identifiers, and mobilenetwork information.
● Browser and Usage Information: Type of browser, IP address, Internet Service Provider (ISP),browsing patterns, time zone settings, and Platform usage details (e.g., timespent on the Platform, pages viewed, and navigation paths).
● Log Data: Information collected automatically each time you interact with ourPlatform, including server logs, error reports, and timestamps.
● Cookies and SimilarTechnologies: Data collected through cookies, pixels,web beacons, or other tracking technologies that enhance your browsingexperience and help us analyze user behavior.
3.3Sensitive Personal Data orInformation (SPDI)
In compliance with Indian laws,we may also collect Sensitive Personal Data or Information (SPDI), includingbut not limited to:
● Financial Information: Bank account details, payment instrument details, or any otherpayment-related data.
● Authentication Data: Passwords, security questions, and other authentication credentials.
● Biometric Data: If required by law or with your explicit consent, we may collectbiometric data such as face and fingerprints or facial recognition data foridentity verification purposes. Such biometric data is collected strictly on anexpress, opt-in basis and is processed subject to the safeguards, consent andretention limits described under "Biometric/Face Data Collection andRetention" in the Data Retention Policy below. [RL1] [ss2]
The collection of SensitivePersonal Data or Information is subject to specific legal and securitysafeguards, and we will only process such data with your consent or as requiredby applicable laws.
By using ourPlatform, you consent to the collection of the aforementioned information,which is essential for providing our services effectively and in compliancewith legal obligations. [RL3] [ss4]
4. Method of Data Collection
Rezolv collects PersonalInformation and Non-Personal Information through various methods to ensureefficient and effective use of our Platform and the services we provide. Thesemethods include:
4.1Data Received from RegulatedEntity Clients and Authorised Platform Users
Rezolv does not directly collectpersonal data of customers (borrowers) of regulated entities. Customer data isprovided to Rezolv by its regulated entity clients (such as banks and NBFCs),who act as the Data Fiduciaries and decide the scope, manner, and purpose ofsuch collection and processing for their debt collection operations. Data thatRezolv may directly receive from authorised platform users (such as thepersonnel and field agents of regulated entities who use the Platform) and fromwebsite visitors who voluntarily provide it includes, but is not limited to:
Account Registration: Information you provide when creating an account on our Platform,such as your name, contact details, and other identity-related data.
● Communication andCorrespondence: Information you provide whencommunicating with us through customer service, submitting inquiries,participating in surveys, or providing feedback.
● Transaction Data: Information you provide when making payments, updating accountinformation, or engaging with the Platform in connection with the debtcollection workflows operated by our regulated entity clients.
● Forms and Applications: Information you provide through forms or applications available onour Platform, including those related to identity verification or debtsettlement processes.
4.2Automated Collection
We automatically collect certaininformation through technology when you interact with our Platform, including:
● Cookies: We use cookies and similar tracking technologies to collect dataabout your browsing behavior, device settings, preferences, and Platform usagepatterns. This information helps us enhance user experience, personalizecontent, and improve the functionality of our services. You can manage yourcookie preferences via browser settings or opt out where applicable.
● Web Analytics: We use analytics tools such as Google Analytics to automaticallycollect and analyze information about your interactions with our Platform. Thismay include your IP address, browser type, referral pages, time spent on pages,and other usage data. This data is anonymized and aggregated for statisticalpurposes.
● Log Files: Our servers automatically collect log files containing informationsuch as your IP address, browser type, access times, pages viewed, and otherdiagnostic information that helps us monitor and improve the performance of ourPlatform.
● Device Information: We collect information about the device you use to access ourPlatform, including the hardware model, operating system version, and uniquedevice identifiers. This data is used to optimize compatibility and improveservice delivery.
4.3Third-Party Sources
We may also collect informationfrom third-party sources, including but not limited to:
● Service Providers: Information provided by third-party service providers (such as creditbureaus or payment processors) to assist in providing our services or verifyingthe accuracy of data shared with us by our regulated entity clients.
Social media and PubliclyAvailable Information: If you interact with ourPlatform through third-party social media platforms, we may collect data thatyou make available via such platforms, subject to their privacy settings andpolicies.
● Partners and Affiliates: We may collect information from our business partners, affiliates, orother trusted entities that share data with us to help us deliver ourtechnology platform to our regulated entity clients and comply with legalrequirements.
By using ourPlatform, you acknowledge and agree to the collection of data through thesemethods as outlined in this Privacy Policy. Where applicable, we will obtainyour explicit consent before collecting certain types of data. [RL5] [ss6]
5. Purpose of Data Collection
Rezolv collects and processesPersonal and Non-Personal Information for specific, legitimate purposes inconnection with the services we offer through our Platform. The purposes forwhich we collect your data include, but are not limited to, the following:
5.1For Providing the TechnologyPlatform Supporting Debt Collection by Regulated Entities
We process Personal Data sharedwith us by our regulated entity clients (such as banks and NBFCs), strictly ontheir instructions and on their behalf, to operate and maintain the technologyplatform that supports their debt collection activities. The regulated entitiesdetermine the purpose, means, and strategy of any debt collection; Rezolv doesnot itself decide whom to contact, when to contact them, or what collectionapproach to adopt. The processing supported by Rezolv may include:
● Verification of Identity: Ensuring that the data shared with us by our regulated entity clientsis accurate and up-todate, and verifying the identity of authorised platformusers for the purposes of supporting the regulated entity’s debt collectionprocess on the Platform.
● Debt Collection Activities: Providing the Platform that enables our regulated entity clients tocarry out their own debt collection activities. The communications,negotiations, and transactional decisions are determined and executed by theregulated entity or its authorised personnel using the Platform; Rezolv doesnot itself initiate contact with borrowers, negotiate debts, or pursuerecoveries. Rezolv’s role is limited to operating the technology, processingdata on the regulated entity’s instructions, and maintaining records of activitiesconducted on the Platform for the regulated entity.
● Reporting and Record-Keeping: Maintaining records of interactions, transactions, and recoveries forfuture reference, audits, or legal requirements.
5.2Compliance with Legal Obligations
We may collect and process yourdata to ensure compliance with applicable laws, regulations, and legalprocesses, including but not limited to:
● Regulatory Compliance: Ensuring that the technology services we provide to our regulatedentity clients adhere to relevant legal and regulatory requirements, such asthe Information Technology Act, 2000, and any rules or guidelines issued byregulatory authorities.
Responding to Legal Requests: Disclosing or providing access to your data as required by law, courtorders, or government authorities, including in connection with law enforcementinvestigations, regulatory audits, or legal proceedings.
● Fraud Prevention and RiskManagement: Detecting and preventing fraud,unauthorized transactions, and other illegal activities that may compromise theintegrity of our services or data.
5.3Customer Support
We collect and use your data toprovide effective customer support services, including:
● Responding to Inquiries andComplaints: Addressing any questions, concerns, orcomplaints you may have regarding our services, and providing timely responsesto resolve issues.
● User Account Management: Assisting with the creation, updating, and management of your useraccount, including password resets, account settings, and other relatedfunctions.
● Assisting with Transactions: Helping you with payments, refunds, and any other transaction-relatedsupport you may require during your use of the Platform.
5.4Improvement of Services andWebsite/Application
We process Non-PersonalInformation and analytics data to continuously improve our services, including:
● Enhancing User Experience: Using your feedback and behavioural data to optimize the performance,design, and functionality of our Platform, ensuring a better user experience.
● Platform Maintenance andDevelopment: Monitoring usage patterns, diagnosingtechnical issues, and implementing upgrades to improve the stability, security,and performance of our Platform.
● Research and Analytics: Analyzing trends, usage data, and feedback to gain insights into userneeds, preferences, and satisfaction levels, which helps us improve ourservices and identify new offerings. [RL7] [ss8]
Automated Processing and Artificial Intelligence (AI)
The Platform incorporatesautomated processing and artificial-intelligence and machine-learning (AI/ML)models. In particular, the Platform uses facial-recognition technology toverify the identity of authorised platform users (such as the field agents ofour regulated entity clients) before they access sensitive workflows, and mayuse automated techniques to support fraud detection, anomaly detection andoperational security.
Any AI/ML inferenceperformed on Personal Data or biometric data is carried out on cloudinfrastructure located in India, and, in respect of customer data, on thedocumented instructions of and for the purposes determined by the relevantregulated entity Data Fiduciary. Biometric templates and other Personal Dataare not used to train third-party or general-purpose AI models, and are notdisclosed to any AI-model provider for any purpose other than performing thespecific verification or processing instructed.
Rezolv does not use AI orautomated processing to make solely automated decisions that produce legal orsimilarly significant effects on borrowers. All decisions relating to debtcollection - including whom to contact and what action to take - are made bythe regulated entity or its authorised personnel, and not by Rezolv or itssystems.
Your data is collected andprocessed for these purposes in compliance with Indian data protection laws,and we will not use your information for any purposes other than those outlinedin this Privacy Policy without obtaining your prior consent where required.
6. Legal Basis for Processing Personal Data
Rezolv processes Personal Datain accordance with applicable laws and only when we have a lawful basis fordoing so. The legal bases for processing your Personal Data include, but arenot limited to, the following:
6.1Consent of the Data Principal
We process your Personal Databased on your explicit and informed consent in the following circumstances:
● Marketing and PromotionalActivities: When you agree to receive marketingcommunications, newsletters, or other promotional content, we process your databased on your consent.
● Optional Data Processing: When we collect data that is not strictly necessary for the provisionof our services (such as certain types of cookies or analytics data), we seekyour consent to process such information.
You may withdraw your consent atany time by contacting us or following the opt-out mechanisms provided in thecommunication, without affecting the legality of processing based on consentbefore its withdrawal.
6.2Performance of a Contract
We process your Personal Datawhen it is necessary to fulfill our contractual obligations with you. Thisincludes:
● Provision of the DebtCollection Technology Platform: Processing PersonalData on behalf of, and under contract with, our regulated entity clients (suchas banks and NBFCs) to deliver the technology platform that supports their debtcollection operations. Rezolv processes such data strictly as a Data Processor;the regulated entity remains the Data Fiduciary and determines the lawful basisfor processing in relation to its customers.
● User Account Management: Collecting and processing data for the creation, management, andmaintenance of your user account, including authentication and securitymeasures.
● Transaction Processing: Using your financial information to process payments, refunds, andrelated transactions associated with the services we provide.
If you do not provide thenecessary data for the performance of a contract, we may be unable to fulfillour contractual obligations.
6.3Compliance with Legal Obligations
Rezolv may process your PersonalData when it is necessary to comply with our legal obligations under applicablelaws and regulations. This includes:
● Regulatory Compliance: Ensuring compliance with Indian data protection laws, tax laws,anti-money laundering regulations, and other legal requirements that govern thetechnology services Rezolv provides to regulated entities in connection withdebt collection.
● Legal Disclosures: Disclosing data to regulatory authorities, law enforcement agencies,courts, or other governmental entities when required by law, such as inresponse to subpoenas, court orders, or government investigations.
● Record Retention: Retaining data as required by law for auditing, reporting, or othercompliance purposes.
6.4Legitimate Uses and BusinessOperations
We may process your Personal Data for thefollowing legitimate business purposes recognised under applicable Indian law.These purposes relate to the limited categories of data for which Rezolv actsas a Data Fiduciary, based on the documented instructions of the regulatedentity that is the Data Fiduciary:
● Fraud Prevention and Security: Processing data to detect and prevent fraud, unauthorized activities,or security breaches that may compromise our services, data, or users.
● Legal Defence and RiskManagement: Processing data in connection withpotential legal claims, compliance audits, or risk assessments to protect ourinterests, as well as those of our clients and partners.
● Business Operations: Using data for general business operations, including conductingresearch and analysis to better understand user needs, developing new products,and growing our business. [RL11] [ss12]
In all instances, we will ensurethat the processing of Personal Data is carried out in a fair, transparent, andlawful manner, in compliance with applicable Indian data protectionregulations. If you have any questions about the legal basis for processingyour Personal Data, you can contact us for further clarification.
7. Use of Cookies and Tracking Technologies
Rezolv uses cookies and similartracking technologies to enhance your experience on our website and/or mobileapplication ("Platform"). This section explains the types of cookieswe use, how we use them, and your choices regarding their use.
7.1Types of Cookies Used
Cookies are small data filesthat are stored on your device when you visit a website. We use the followingtypes of cookies on our Platform:
● Functional Cookies: These cookies are essential for the proper functioning of thePlatform. They enable core features such as secure logins, session management,and user preferences. Without these cookies, certain features of the Platformmay not work correctly.
● Analytics Cookies: These cookies help us understand how users interact with the Platformby collecting information about usage patterns, such as pages visited, timespent on the Platform, and any errors encountered. This information isanonymized and used to improve the functionality and performance of ourservices. For example, we may use Google Analytics to gather and analyze usagedata.
● Performance Cookies: These cookies collect information about how the Platform performs,including the speed of page loading and any performance issues. The datacollected is used to monitor and improve the Platform’s efficiency and userexperience.
● Third-Party Cookies: In some cases, third-party service providers (such as social mediaplatforms or advertising networks) may place cookies on your device when youinteract with certain features of our Platform. These cookies are subject tothe privacy policies of the respective third parties.
7.2How We Use Cookies
We use cookies and trackingtechnologies for the following purposes:
● To remember your preferences andsettings (e.g., language, region) during your visits to the Platform.
● To authenticate users and preventunauthorized access to secure areas of the Platform.
● To track and analyse usage data,helping us understand how users navigate through the Platform and identifyareas for improvement.
● To deliver personalized contentand advertisements based on your interests and online behavior.
● To manage and improve the securityand performance of our Platform.
8. Data Sharing and Disclosure
Rezolv is committed tosafeguarding your Personal Data and ensuring that it is shared only underappropriate circumstances. This section outlines the situations in which we mayshare or disclose your data, and the safeguards we employ to protect your privacy.
8.1With Third-Party Service Providers
We may share your Personal Datawith trusted third-party service providers who assist us in delivering ourservices. These third parties include, but are not limited to:
● Payment Processors: Entities that handle payment processing, including financialinstitutions and payment gateways.
● Technology Providers: Providers of IT infrastructure, cloud storage, data analytics, andtechnical support that help us maintain and improve our Platform.
● Authorised Personnel ofRegulated Entity Clients: In-house staff orthird-party agents engaged by our regulated entity clients (such as banks andNBFCs) who are authorised by such clients to access the Platform to carry outthe client’s debt collection activities. Rezolv does not appoint or instruct theseagents and does not itself engage in debt recovery.
● Verification and AuthenticationServices: Providers who assist in identityverification and fraud prevention.
All third-party serviceproviders are contractually obligated to process your data in accordance withapplicable data protection laws, and they are prohibited from using your datafor purposes other than those agreed upon with Rezolv.
8.2With Regulatory Authorities
We may disclose your PersonalData to regulatory authorities, government agencies, or law enforcementofficials when required by law, including but not limited to:
● Compliance with LegalRequirements: We may disclose your data to comply withapplicable laws, regulations, or legal processes, such as responding to courtorders, subpoenas, or requests from government authorities.
● Regulatory Reporting: In cases where we are legally required to report certain activities,such as transactions or activities conducted on the Platform by our regulatedentity clients, to government or regulatory bodies.
● Public Safety and RiskPrevention: When necessary, we may share your data toprotect public safety, prevent fraud, or mitigate security risks.
8.3In Case of Business Transfers
In the event of a corporatetransaction such as a merger, acquisition, restructuring, or sale of assets,your Personal Data may be transferred to the new entity or third partiesinvolved in the transaction. This may occur under the following circumstances:
● Mergers and Acquisitions: If Rezolv is acquired by or merges with another company, your datamay be transferred to the acquiring entity as part of the business transaction.
● Asset Transfers: In the case of the sale, liquidation, or transfer of some or all ourassets, your data may be included as part of the transferred assets.
● Business Reorganization: If we undergo any form of restructuring, your data may be shared withthe relevant entities to ensure continuity of service.
In all such cases, we willensure that the receiving party agrees to use your Personal Data in a mannerconsistent with this Privacy Policy.
8.4For Legal Compliance
We may disclose your PersonalData when we believe it is necessary to comply with legal obligations or toprotect our rights, including:
● Legal defence: To defend or enforce our legal rights in the event of legal disputes,including disputes relating to the technology services we provide to ourregulated entity clients.
● Fraud and Security Monitoring: To detect, prevent, or respond to fraud, unauthorized access, orother illegal activities.
● Protection of Others: To protect the rights, property, or safety of our users, employees,or the public.
In all cases, we ensure that anydata shared or disclosed is done in accordance with applicable data protectionlaws and only to the extent necessary for the purpose at hand. We also takesteps to ensure that any third parties receiving your Personal Data maintainconfidentiality and security standards equivalent to those outlined in thisPrivacy Policy.
Data Hosting, Localisation and Cross-Border Transfers
Data Hosting and Location inIndia: Personal Data processed through the Platform is hosted and processed oncloud infrastructure located in India (currently Amazon Web Services (AWS),Mumbai region). Rezolv maintains its production systems and primary datastorage within India.
Compliance with LocalisationRequirements: Where Personal Data includes payment or transaction data governedby directions of the Reserve Bank of India (including the RBI directive onStorage of Payment System Data), such data is stored within India in accordancewith those requirements and the instructions of the relevant regulated entity.
.
9. Data Security Measures
Rezolv is committed to ensuringthe security and confidentiality of your Personal Data. We implement a varietyof technical, administrative, and organizational measures to protect your datafrom unauthorized access, disclosure, alteration, or destruction. The followingoutlines our key data security measures:
9.1Encryption, Firewalls, and OtherSecurity Measures
We employ industry-standardsecurity measures to protect your Personal Data, including:
● Data Encryption: We use encryption protocols (such as SSL/TLS) to protect yourPersonal Data during transmission over the internet. This ensures thatsensitive information such as financial data and login credentials are securelytransmitted between your device and our Platform.
● Firewalls: Our systems are protected by firewalls that help prevent unauthorizedaccess to our networks and servers. Firewalls act as a barrier between trustedinternal networks and untrusted external sources, ensuring that only authorizedtraffic is allowed.
● Access Controls: We limit access to Personal Data to authorized personnel who requiresuch access for the performance of their duties. Access controls, such asmulti-factor authentication (MFA) and role-based access control (RBAC), are inplace to ensure that only authorized individuals can access sensitive data.
● Data Masking and Anonymization: Where possible, we use techniques such as data masking oranonymization to further protect sensitive information, especially whenhandling or storing data that is not required to identify specific individuals.
● Regular Security Audits andVulnerability Testing: We conduct regular securityaudits, vulnerability assessments, and penetration testing to identify andaddress any potential security risks or vulnerabilities in our systems andinfrastructure.
● Monitoring and IncidentResponse: Our systems are continuously monitored forunusual or unauthorized activity. In the event of a security breach or dataincident, we have an incident response plan in place to quickly contain andmitigate any damage.
9.2ISO 27001 or Other Certifications
Rezolv is dedicated tomaintaining a robust information security management system (ISMS) that alignswith industry best practices. As part of this commitment:
● ISO 27001 Certification: We are certified under the ISO 27001 standard, which demonstrates ouradherence to international best practices for information security management.This certification requires us to implement and maintain rigorous securitycontrols to protect the confidentiality, integrity, and availability ofPersonal Data.
● Compliance with IndustryStandards: In addition to ISO 27001, we adhere toother relevant security standards and frameworks applicable to the financialand data processing industries. This includes compliance with regulatorysecurity guidelines set forth by Indian authorities, such as the InformationTechnology (Reasonable Security Practices and Procedures and Sensitive PersonalData or Information) Rules, 2011.
● Periodic Security Audits: Our security practices are regularly audited by external auditors toensure that we maintain compliance with applicable laws, certifications, andinternal policies. These audits help us identify potential areas forimprovement and ensure continuous enhancement of our security measures.
By implementing these securitymeasures, we strive to protect your Personal Data from unauthorized access,loss, or misuse. However, please note that no system can be completely secure,and while we take steps to safeguard your data, we cannot guarantee itsabsolute security. In the event of a data breach, we will notify you asrequired by applicable laws and take immediate steps to mitigate any potentialharm.
10. Data Retention Policy
Rezolv is committed to retainingPersonal Data only for as long as necessary to fulfill the purposes for whichit was collected, or as required by applicable laws and regulations. Thissection outlines our data retention practices and the criteria we use todetermine how long your data will be stored.
10.1Duration for Which Personal DataWill Be Retained
● Service-Related Data: We retain Personal Data for the duration of our engagement with therelevant regulated entity client, including the period during which we providethe technology platform supporting that client’s debt collection operations,and for any post-engagement period reasonably required for transition and exit.Retention of customer data is governed by the instructions of the regulatedentity that acts as the Data Fiduciary in respect of such data. Once therelationship has ended or the services have been completed, we may retain suchdata for a specified period to comply with legal and regulatory obligations,resolve disputes, and enforce agreements.
● Financial Data: Personal financial information, including payment and transactiondata, is retained for as long as necessary to comply with financial reporting,auditing, and taxation requirements under applicable laws.
● Communication Data: We retain records of your communications with us, including emails,phone calls, or other forms of correspondence, for as long as needed to resolveyour inquiries, maintain customer support records, and comply with legalobligations.
● Anonymized or Aggregated Data: In some cases, we may anonymize your Personal Data so that it can nolonger identify you. This anonymized data may beretained indefinitely for analytical purposes, research, or to improve ourservices.[RL13] [ss14]
● Biometric/Face Data Collectionand Retention: We operate as a data processor onbehalf of its institutional customers, such as banks and NBFCs, which controlthe workspace and determine the business purpose of processing. Face data iscollected solely for agent identity verification at the time of access tosensitive field workflows and customer-linked financial operations. This isdone to support the subscribing institution's operational security, fraudprevention, and audit trail requirements.
Face data is retained for the duration of the subscribing institution's activeengagement with the Rezolv platform. This period is necessary to maintain averifiable audit trail for all field operations conducted on the institution'sbehalf, as required under applicable regulatory guidelines.
Express consent and withdrawal: Face data is collected only after theauthorised platform user (agent) has given express, informed, opt-in consent atthe time of enrolment. Providing face data is voluntary; where an agentdeclines, the subscribing institution is offered an alternative means ofidentity verification. An agent may withdraw consent at any time, followingwhich the face data is deleted as set out below, subject to any minimumretention required by law.
Retention and erasure: Face data is retained only for so long as the agentremains active and authorised on the Platform, and in any event is securelydeleted or irreversibly anonymised within thirty (30) days of the agent'sdeactivation or offboarding, or of the termination of the subscribinginstitution's engagement, whichever is earlier, unless a specific legal orregulatory obligation requires longer retention. Other Sensitive Personal Dataor Information, such as passwords and authentication credentials, is storedonly in encrypted or hashed form and is securely deleted or anonymised once itis no longer required for the purpose for which it was collected.
10.2Criteria for Determining RetentionPeriods
The following criteria are usedto determine the retention periods for Personal Data:
● Legal and RegulatoryRequirements: We are obligated to retain certain typesof data to comply with applicable laws, including tax, anti-money laundering(AML), and financial regulations. Data retention periods may vary depending onthe jurisdiction and specific regulatory requirements.
● Contractual Obligations: Data necessary for the performance of a contract, including serviceagreements with our regulated entity clients, will be retained for the durationof the contract and as required for post-contractual obligations, such asdispute resolution or contract enforcement.
● Business Needs: Personal Data may be retained for as long as necessary to meet ourlegitimate business interests, such as fraud prevention, maintaining accuratebusiness records, and defending or enforcing legal claims.
● User Requests: If you request the deletion or anonymization of your Personal Data,we will assess whether we are required to retain the data by law or forlegitimate business purposes. Where no such requirement exists, we will deleteor anonymize your data as requested.
● Data Minimization: We follow the principle of data minimization, ensuring that we onlyretain the minimum amount of Personal Data necessary to achieve the purposesoutlined in this Privacy Policy.
Once the applicable retentionperiod has expired, we will securely delete, anonymize, or otherwise dispose ofyour Personal Data in accordance with our data disposal procedures, unless weare required to retain it for legal, regulatory, or business purposes.
11. Changes to the Privacy Policy
Rezolv reserves the right toupdate or modify this Privacy Policy at any time to reflect changes in ourpractices, legal requirements, or service offerings.
● Continued Use of the Platform: By continuingto use our Platform after any changes to this Privacy Policy become effective,you are deemed to have accepted the revised terms. If you do not agree with theupdated policy, you must discontinue your use of the Platform and may contact usfor further clarification or assistance.
12. Grievance Redressal Mechanism
We take your privacy andconcerns seriously and have implemented a Grievance Redressal Mechanism toaddress any issues related to the collection, use, or protection of yourPersonal Data.
Your Rights: Access, Review and Correction
You have rights in respectof your Personal Data under applicable Indian law, including the InformationTechnology (Reasonable Security Practices and Procedures and Sensitive PersonalData or Information) Rules, 2011 and the Digital Personal Data Protection Act,2023. These include:
● Right to review and correct: In accordance with Rule 5(6) of the SPDI Rules, you may review theinformation you have provided and require that any Personal Data or SensitivePersonal Data or Information found to be inaccurate or deficient is correctedor amended.
● Right of access, correction anderasure: You may request access to, and thecorrection, completion, updating or erasure of, your Personal Data.
● Right to withdraw consent: Where processing is based on your consent, you may withdraw thatconsent at any time, without affecting the lawfulness of processing carried outbefore withdrawal.
● Right to grievance redressal: You may raise any concern or complaint with the Grievance Officer asset out below.
The extent to which Rezolvcan act on such a request depends on its role in relation to the dataconcerned. For Personal Data that Rezolv collects and controls directly as aData Fiduciary (such as data of website visitors, its own personnel andauthorised platform users), Rezolv will give effect to your rights directly.For customer (borrower) data, in respect of which Rezolv acts only as a DataProcessor, Rezolv will forward your request to, and assist, the relevantregulated entity that is the Data Fiduciary, which is responsible for decidingupon it. To exercise any of these rights, please contact the Grievance Officerusing the details below.
● Grievance Officer: In compliance withapplicable Indian laws, we have appointed a Grievance Officer to handle yourconcerns and complaints regarding data privacy. Rezolv is not a SignificantData Fiduciary under the Digital Personal Data Protection Act, 2023, and istherefore not required to appoint a Data Protection Officer. The GrievanceOfficer named below is Rezolv's single designated point of contact for all dataprotection queries and complaints; for customer (borrower) data, in respect ofwhich Rezolv acts only as a Data Processor, the Grievance Officer willcoordinate with the relevant regulated entity that is the Data Fiduciary.
Contact Details of the Grievance Officer:
Grievance Officer: Anil Chatla
Email: anil.chatla@rezolv.com
Phone: 9029693406
Address: Unit #214, D-Wing,Kanakia Zillion, Kurla West, Kurla, Mumbai, Maharashtra 400070
● Process for Raising Concerns orComplaints:
o If you have any concerns or complaints regarding the processing of yourPersonal Data or believe that your privacy rights have been violated, you maycontact the Grievance Officer.
o You may submit your complaint in writing, via email, or through anyother form of communication provided in the contact details above.
o Upon receiving your complaint, the Grievance Officer will acknowledgereceipt and investigate the matter. You will receive a response within areasonable timeframe, typically no later than 30 days from the receipt of yourcomplaint.
o If you are not satisfied with the resolution provided by the GrievanceOfficer, you have the right to escalate the matter to the relevant dataprotection authorities as applicable under Indian law.
13. Applicable Laws and Jurisdiction
This Privacy Policy is governedby and construed in accordance with the laws of India.
In the event of any disputesarising from or relating to this Privacy Policy, the courts of Mumbai,Maharashtra shall have exclusive jurisdiction, subject to any applicabledispute resolution mechanisms agreed upon by the parties.
By using our Platform, youacknowledge that any legal disputes concerning your data and privacy will begoverned by Indian law, and you agree to submit to the jurisdiction of thecourts of India for resolution of such matters.