How DJT Microfinance collects, uses, protects and shares personal data. Placeholder text — have counsel align this with the DPDP Act, 2023 and RBI directions before publication.
What we collect
- Identity and KYC data: name, address, date of birth, government identifiers as mandated for KYC.
- Financial data: household income assessment, bank details, existing obligations and bureau reports.
- Contact and usage data: phone, email, and interactions with our branches, apps and website.
How we use it
- To assess eligibility and repayment capacity, as required by RBI directions.
- To service the loan: disbursal, collection, communication and grievance handling.
- To meet legal obligations: credit bureau reporting, regulatory returns, audits.
What we never do
- Sell personal data.
- Share data with third parties beyond what the loan, the law or the bureau framework requires.
- Use borrower data for unrelated marketing without consent.
Your rights
- Access and correction of your personal data held by us.
- Grievance escalation through the mechanism on this website, including for privacy concerns.
- Withdrawal of consent where processing rests on consent, subject to legal retention duties.
Security and retention
Data is encrypted in transit and at rest, access is role-restricted and logged, and records are retained only for the periods required under applicable law and RBI directions.
PRIVACY POLICY
Document Control
| Field | Details |
| Reference No. | DJTMPL/POL/PP/V2.0 |
| Document Name | Privacy Policy |
| Version No. | 2.0 |
| Status | Definitive |
| Review Date | 01-04-2026 |
| Supersedes | Version 1.0 dated 01-Jun-2024 |
| Next Review Period | Annually or as required by law |
| Classification | Internal Use Only |
| Document Owner | Chief Operation Officer |
| Policy Approving Authority | Board Of Directors |
Document Revision History
| Version | Date | Change Description |
| 1.0 | 01-06-2024 | First version |
| 2.0 | 01-04-2026 | DPDPA 2023, customer rights, grievance redressal, data security and governance framework added |
Table of Contents
| S. No | Particulars |
| 1 | Preamble |
| 2 | Objective & Scope |
| 3 | Terms & Definitions |
| 4 | Applicability |
| 5 | Policy Statement & Guiding Principles |
| 6 | Information Collection |
| 7 | Use of Collected Information |
| 8 | Sharing of Personal Information |
| 9 | Customer Rights |
| 10 | Personal Information Protection & Data Security |
| 11 | Records Management & Data Retention |
| 12 | Customer Training & Awareness |
| 13 | Staff Accountability & Training |
| 14 | Monitoring & Internal Audit |
| 15 | Privacy Policy Changes |
| 16 | Website Terms, Disclaimers & Applicable Law |
| 17 | Effect & Review |
| 18 | Contact Us |
| 19 | Board Approval |
1. PREAMBLE
DJT Microfinance Private Limited is a Non-Banking Financial Company – Micro Finance Institution (NBFC-MFI) registered with the Reserve Bank of India (RBI) and is committed to protecting the privacy, confidentiality, and security of personal and financial information belonging to its customers, employees, and all other stakeholders.
This Privacy Policy ("Policy") describes the Company's framework for the collection, storage, use, protection, sharing, and disposal of information obtained in the course of its business operations. It has been formulated in accordance with:
- RBI Master Directions on Know Your Customer (KYC) norms
- Information Technology Act, 2000 and the IT (Amendment) Act, 2008
- Prevention of Money Laundering Act, 2002 (PMLA) and rules thereunder
- Digital Personal Data Protection Act, 2023 (DPDPA) and rules as applicable
- Microfinance Institutions Network (MFIN) Code of Conduct
- Sa-Dhan Code of Conduct for Responsible Lending
2. OBJECTIVE & SCOPE
The objective of this Policy is to:
- Ensure that personal and financial information shared by customers, employees, and other stakeholders is not used against their interests or shared with third parties without their knowledge and consent.
- Establish clear, enforceable standards for the collection, processing, storage, sharing, and destruction of data across all business functions.
- Demonstrate the Company's commitment to responsible data stewardship, transparency, and customer protection in accordance with applicable laws and RBI regulatory expectations.
- Define roles and accountability of all personnel handling personal data.
This Policy applies to all information collected by DJT MICROFINANCE PVT. LTD.
through its:
- Branch network and field operations
- Website(s) and digital platforms
- Mobile applications
- Third-party service providers and banking correspondents acting on behalf of DJT MICROFINANCE PVT. LTD.
- Internal HR, administrative, and operational systems
3. TERMS & DEFINITIONS
| Term | Definition |
| Customer / Borrower | Any individual or group who has applied for, received, or previously held a loan from DJT MICROFINANCE PVT. LTD., including Joint Liability Group (JLG) members. Includes both active and former customers. |
| Personal Information | Any data about an identifiable individual including name, age, address, identity documents (Aadhaar, PAN, Voter ID), photographs, phone number, email, occupation, income, family particulars, health information, and biometric data. |
| Financial Information | Data relating to a customer's business activity, income, expenditure, loan outstanding, repayment history, credit score, guarantors, or collateral details. |
| Sensitive Personal Data | Financial information, passwords, physical or mental health, sexual orientation, biometric data, and any other category notified under applicable law. |
| Data Principal | The individual to whom personal data relates (equivalent to the data subject). |
| Data Fiduciary | DJT MICROFINANCE PVT. LTD., as the entity that determines the purpose and means of processing personal data. |
| Data Processor / Service Provider | Any third party engaged by DJT MICROFINANCE PVT. LTD. to process personal data on its behalf under a formal agreement. |
| Records | All documents, physical or digital, maintained in the course of business operations. |
| Records Management | Lifecycle management of records from collection to disposal, including classification, storage, security, retrieval, and destruction or archival. |
| Credit Bureau | An RBI-licensed Credit Information Company (e.g., CIBIL, Equifax, CRIF Highmark) that compiles credit data for lending decisions. |
| Consent | Free, informed, specific, and unambiguous agreement of the Data Principal to the processing of their personal data for a stated purpose. |
| Breach | Any unauthorised access, disclosure, alteration, or destruction of personal data. |
Words and expressions used but not defined in this Policy shall have the same meaning assigned to them in applicable RBI regulations, the IT Act 2000, PMLA 2002, DPDPA 2023, or any amendment thereto, as the case may be.
4. APPLICABILITY
This Policy is mandatory and applicable to:
- All permanent, contractual, and temporary employees of DJT MICROFINANCE PVT. LTD.
- All customers, borrowers, and loan applicants
- Third-party service providers, technology vendors, research agencies, and banking correspondents
- External consultants and auditors who access DJT MICROFINANCE PVT. LTD. data
- Board members and senior management in their fiduciary capacity
Non-compliance by employees may attract disciplinary action as per the HR policy. Non-compliance by service providers may result in termination of contract.
5. POLICY STATEMENT & GUIDING PRINCIPLES
DJT MICROFINANCE PVT. LTD. is committed to collecting only the minimum information necessary for legitimate business purposes and to ensuring that such information is used solely in the best interests of the stakeholder and the Company, in full compliance with applicable law.
| Principle | Description |
| Lawfulness & Fairness | Data shall be processed lawfully, fairly, and transparently in accordance with applicable laws and RBI regulations. |
| Purpose Limitation | Data collected for one purpose shall not be used for any other incompatible purpose without fresh consent. |
| Data Minimisation | Only data that is strictly necessary for the stated purpose shall be collected from customers and employees. |
| Accuracy | DJT MICROFINANCE PVT. LTD. shall take reasonable steps to ensure that personal data is accurate and kept up to date. |
| Storage Limitation | Data shall be retained only as long as necessary for its stated purpose or as required under applicable law. |
| Integrity & Confidentiality | Data shall be protected against unauthorised access, loss, destruction, or damage using appropriate technical and organisational measures. |
| Consent | Data will be shared with third parties only with the explicit knowledge and consent of the data subject, except as required by law. |
| Accountability | DJT MICROFINANCE PVT. LTD. shall be responsible for and able to demonstrate compliance with this Policy at all times. |
6. INFORMATION COLLECTION
6.1 Information Collected from Customers
In compliance with RBI KYC norms and NBFC-MFI regulations, DJT MICROFINANCE PVT. LTD. shall collect only the following categories of information from customers:
- KYC Documents: Government-issued identity proof (Aadhaar, PAN, Voter ID, Passport) and address proof as mandated under RBI KYC Master Directions.
- Photographs: Three photographs at loan origination for identification and internal records only. Photographs shall not be used for marketing or shared with external parties without explicit written consent.
- Financial Information: Income, occupation, business activity details, existing loan obligations, and repayment capacity as required for credit assessment.
- Credit Bureau Information: Credit history accessed from licensed Credit Information Companies for loan underwriting purposes only.
- Guarantor / Group Member Details: Details of Joint Liability Group (JLG) members or guarantors as applicable to the loan product.
6.2 Information Collected Through Digital Channels
When customers or visitors interact with DJT MICROFINANCE PVT. LTD.'s website(s) or digital platforms, the following information may be automatically collected:
- IP address and device information
- Browser type and version
- Approximate geographic location based on IP address
- Pages viewed, duration of visit, and frequency of access
- Cookies and web beacons (see Section 6.4 for details)
6.3 Collection from Third-Party Sources
DJT MICROFINANCE PVT. LTD. may also receive information from authorised third parties, including credit bureaus, banking correspondents, and regulatory databases. Such information shall be used solely for purposes consistent with the original collection and applicable law.
6.4 Cookies & Tracking Technologies
DJT MICROFINANCE PVT. LTD.'s website uses cookies and web beacons to enhance user experience and monitor site performance. Users may disable cookies in their browser settings; however, certain site functionalities may be affected. DJT MICROFINANCE PVT. LTD. does not use tracking technologies to collect sensitive personal data.
7. USE OF COLLECTED INFORMATION
DJT MICROFINANCE PVT. LTD. shall use collected personal and financial information strictly for the following purposes:
7.1 Loan Processing & Customer Service
- Processing loan applications and disbursements
- Credit assessment, underwriting, and risk management
- Customer identity verification (KYC/AML compliance)
- Post-disbursement servicing, repayment tracking, and account management
- Providing product and service information relevant to the customer's financial profile
7.2 Regulatory & Legal Compliance
- Reporting to the RBI and other regulatory bodies as mandated
- Filing of Suspicious Transaction Reports (STRs) with the Financial Intelligence Unit (FIU) under PMLA
- Submission of data to licensed Credit Information Companies as required by the Credit Information Companies (Regulation) Act, 2005
- Cooperating with law enforcement, judicial authorities, or statutory auditors upon lawful request
7.3 Operational & Business Improvement
- Improving the Company's products, services, and operational processes
- Conducting internal research and analytics to enhance financial inclusion outcomes
- Website and digital platform performance monitoring
7.4 Communication
- Communicating loan account status, repayment reminders, and transaction alerts
- Providing customer education on financial literacy and product features
- Marketing communications for related products, only with customer consent and subject to opt-out rights
8. SHARING OF PERSONAL INFORMATION
DJT MICROFINANCE PVT. LTD. shall not share, sell, or transfer personal information to any third party for commercial gain. Information may be shared only under the following circumstances:
8.1 Permitted Disclosures
| Category | Recipients | Conditions / Safeguards |
| Regulatory & Legal | RBI, FIU, Courts, Law Enforcement | As mandated by law; no consent required |
| Credit Bureaus | CIBIL, Equifax, CRIF Highmark, Experian | As per Credit Information Companies Act; customers informed at origination |
| Co-lending / BC Partners | Banks, NBFCs, financial institutions | Only where DJT MICROFINANCE PVT. LTD. acts as agent/BC; under formal agreement covering data confidentiality |
| Service Providers | Technology vendors, data processors, record storage providers | Under signed DPA / NDA; audited annually |
| Research Agencies | Authorised external researchers | Anonymised / aggregated data only; no individual identification possible |
| Corporate Transactions | Acquirers, merger counterparties | Only in event of M&A or sale of business; subject to regulatory approval |
| Customer Direction | Any third party nominated by customer | Only upon explicit written authorisation from the customer |
8.2 Prohibition on Direct Marketing by Third Parties
DJT MICROFINANCE PVT. LTD. shall not share customer personal information with any unrelated third party for that party's direct marketing purposes. Any sharing for marketing of DJT MICROFINANCE PVT. LTD.'s own affiliated products shall require the customer's prior consent and shall be subject to the customer's right to opt out at any time.
9. CUSTOMER RIGHTS
In alignment with RBI Fair Practices Code and applicable data protection law, customers have the following rights with respect to their personal data:
- Right to be Informed: Customers shall be made aware of DJT MICROFINANCE PVT. LTD.'s data collection practices before or at the time of data collection, in simple, local-language communication.
- Right of Access: Customers may request a copy of the personal data held by DJT MICROFINANCE PVT. LTD. pertaining to them.
- Right to Correction: Customers may request correction of inaccurate or incomplete personal data. DJT MICROFINANCE PVT. LTD. shall update such data within 15 working days of receiving a valid request.
- Right to Erasure / Deletion: Customers may request deletion of personal data that is no longer necessary for the stated purpose, subject to DJT MICROFINANCE PVT. LTD.'s legal retention obligations.
- Right to Withdraw Consent: Customers may withdraw consent for specific processing activities (e.g., marketing communications) at any time, without affecting the lawfulness of prior processing.
- Right against Automated Decision-Making: Loan decisions made purely on automated processing shall be subject to human review upon customer request.
To exercise any of the above rights, customers may contact DJT MICROFINANCE PVT. LTD. at: collectionmsme@djtmpl.com with the subject line "Data Rights Request".
10. PERSONAL INFORMATION PROTECTION & DATA SECURITY
DJT MICROFINANCE PVT. LTD. maintains physical and electronic safeguards to protect customers' personal and financial information including their photographs. The following mechanisms are in place to ensure information security across all storage, access, retrieval, and sharing of data:
10.1 Physical Security
- Customer KYC documents and physical loan files shall be stored at the originating branch in locked, access-controlled cabinets.
- Only authorised branch staff shall have access to physical customer records.
- Physical records transferred to Head Office or third-party storage shall be under documented custody chain and covered by written SLAs mandating confidentiality.
10.2 IT & Digital Security
- Access to customer databases shall be role-based; branch-level staff may access only their branch data. Head Office staff shall have tiered access privileges.
- All database changes shall require dual authorisation (Branch Manager / Assistant Branch Manager approval).
- Every user accessing the database shall have an individual, non-transferable login ID and password. Passwords shall be changed periodically as per the IT security policy.
- All database access shall be automatically logged (username, data queried, timestamp). Logs shall be retained and reviewed periodically by the IT team.
- DJT MICROFINANCE PVT. LTD. shall maintain encrypted, offsite cloud backups of all customer data, accessible only by the IT team.
- Any unauthorised data access or breach shall be reported immediately to the Chief Risk Officer and the Data Protection Officer (DPO) and, where required by law, to the appropriate regulatory authority.
10.3 Website & Digital Channel Security
DJT MICROFINANCE PVT. LTD. implements SSL/TLS encryption, firewalls, and access controls on its website and digital platforms. No transaction processing involving sensitive personal data shall occur over unsecured channels.
10.4 Security Caveat
While DJT MICROFINANCE PVT. LTD. employs commercially reasonable security measures, no electronic system can be guaranteed to be completely secure. DJT MICROFINANCE PVT. LTD. shall promptly notify affected customers and regulators in the event of a material data breach as required under applicable law.
11. RECORDS MANAGEMENT & DATA RETENTION
11.1 Retention Periods
All customer records shall be retained for such period as required under applicable law, including:
- PMLA: Minimum 5 years from the date of cessation of the customer relationship (for KYC and transaction records).
- RBI KYC Directions: As specified from time to time.
- Loan Documentation: Minimum 7 years from the date of full repayment / write-off.
- Credit Bureau Data: As governed by the Credit Information Companies (Regulation) Act, 2005.
11.2 Archival & Disposal
- Records of customers with no current loan outstanding shall be properly archived and stored with equivalent security as active customer records.
- Upon expiry of mandatory retention periods, physical records shall be securely destroyed (shredded), and digital records shall be permanently deleted or anonymised.
- A register of records disposed of shall be maintained by the Compliance team.
11.3 Third-Party Record Storage
Where DJT MICROFINANCE PVT. LTD. engages third-party service providers for records storage or data management, such engagement shall be governed by a written SLA that mandates compliance with this Policy, confidentiality obligations, and applicable law. DJT MICROFINANCE PVT. LTD. shall audit such providers annually.
12. CUSTOMER TRAINING & AWARENESS
In furtherance of the RBI's mandate on customer protection and financial literacy, DJT MICROFINANCE PVT. LTD. shall:
- Inform all customers of their privacy rights and DJT MICROFINANCE PVT. LTD.'s data practices at the time of loan origination, using simple language in the local vernacular.
- Provide a summary of this Policy to all borrowers as part of the loan documentation package.
- Train field staff to explain data collection practices and customer rights during group meetings (JLG/SHG) prior to loan disbursement.
- Make this Policy publicly accessible on DJT MICROFINANCE PVT. LTD.'s website.
- Advise customers of their responsibility to: keep their personal information updated; store loan cards and documents securely; report any suspected misuse of their data to DJT MICROFINANCE PVT. LTD. immediately; and keep the group's financial data confidential.
13. STAFF ACCOUNTABILITY & TRAINING
13.1 Confidentiality Obligations
- All employees shall sign a Non-Disclosure / Confidentiality Agreement (NDA) at the time of appointment, binding them to protect customer and company data during and after their employment.
- No employee shall access, copy, transmit, or share customer data beyond their authorised scope of work.
13.2 Training
- All new employees shall receive mandatory training on this Privacy Policy, data protection obligations, and applicable legal requirements during induction.
- Refresher training shall be conducted at least annually, or whenever this Policy is materially amended.
- Field staff shall be specifically trained on the collection of customer documents, obtaining photographs, and explaining customer rights.
13.3 Disciplinary Consequences
- Any employee found to have violated this Policy shall be subject to disciplinary action under the Company's HR policy, ranging from formal warning and financial penalty to summary dismissal, depending on the severity of the breach.
- Deliberate or malicious breaches may be referred to law enforcement authorities.
14. MONITORING & INTERNAL AUDIT
To ensure effective implementation of this Policy, regular monitoring of the extent of its adherence by employees is important. DJT MICROFINANCE PVT. LTD. shall maintain the following monitoring and audit framework:
- The Internal Audit team shall include privacy policy compliance as a standing agenda item in all branch audits, reviewing adherence to data collection, storage, access, and sharing procedures.
- Any deviations identified during audit shall be reported to the Compliance Officer and the Board's Risk & Audit Committee with recommended corrective actions.
- The Compliance Officer shall present a quarterly Privacy Compliance report to senior management and an annual report to the Board.
- System access logs shall be reviewed monthly by the IT team for anomalous activity. Suspicious access shall be immediately escalated to the Chief Risk Officer.
- Third-party service providers handling customer data shall be subject to annual privacy audits under their contractual SLA/DPA.
15. PRIVACY POLICY CHANGES
This Policy shall be reviewed at least annually by the Compliance Officer and submitted to the Board for approval. Ad hoc reviews shall be triggered by any of the following:
- Material change in applicable law or RBI regulations
- New products, services, or technology platforms involving personal data
- Significant data security incident or breach
- Change in the Company's business model or ownership structure
Any material amendment to this Policy shall be:
- Approved by the Board of Directors of DJT MICROFINANCE PVT. LTD.
- Communicated to all employees through internal circulars and refresher training
- Published on DJT MICROFINANCE PVT. LTD.'s website within 15 working days of Board approval
- Brought to the attention of customers through appropriate communication channels
Notwithstanding the above, this Policy will stand amended to the extent of any change in applicable laws, including any amendment to RBI regulations, without any further action from the Board of Directors, unless a specific Board resolution is required by applicable law.
16. WEBSITE TERMS, DISCLAIMERS & APPLICABLE LAW
16.1 Website Usage
Access to and use of DJT MICROFINANCE PVT. LTD.'s website constitutes acceptance of the Terms and Conditions and this Privacy Policy. DJT MICROFINANCE PVT. LTD. controls and operates its website from India. Users accessing the site from outside India are responsible for compliance with applicable local laws.
16.2 Copyright & Intellectual Property
All content on DJT MICROFINANCE PVT. LTD.'s website is protected by copyright and intellectual property law. Users may print or store content for personal, non-commercial use only. Unauthorised reproduction, distribution, or commercial use is strictly prohibited.
16.3 Applicable Law & Jurisdiction
This Policy and all related terms and conditions are governed by the laws of India. Any dispute arising in connection with this Policy shall be subject to the exclusive jurisdiction of the courts located in Delhi, India.
17. EFFECT & REVIEW
This Policy shall be effective from the date of Board approval. It shall be reviewed at least once annually, or earlier if significant changes occur in applicable law, RBI regulations, or the Company's operations, to ensure its continuing suitability, adequacy, and effectiveness.
18. CONTACT US
For any questions, requests, or complaints related to this Privacy Policy, please contact:
| Designation | Grievance Redressal Officer / Data Protection Officer |
| Company | DJT Microfinance Private Limited |
| collectionmsme@djtmpl.com | |
| Subject Line | 'Privacy' / 'Data Rights Request' / 'Privacy Complaint' |
| Regulatory Escalation | RBI Ombudsman – Integrated Ombudsman Scheme (https://rbi.org.in) |
19. BOARD APPROVAL
This Privacy Policy (Version 2.0) has been reviewed, approved, and adopted by the Board of Directors of DJT Microfinance Private Limited at a duly convened Board Meeting.