customercare@devvratcapital.com
Mon - Fri : 09 AM - 09 PM

DCPL PRIVACY POLICY

Devvrat Capital Private Limited   |   For devvratcapital.com and the DCPL mobile application

1. Who we are

Devvrat Capital Private Limited (referred to in this policy as the Company, we, us or our) is a Non Banking Financial Company registered with the Reserve Bank of India (Certificate of Registration No. 0020/2026 dated 27 May 2026), with its registered office at 101, 1st Floor, Dol Bin Shir, Janmabhoomi Marg, Fort, Town Hall, Mumbai, Maharashtra 400001. We provide loan products to businesses and individuals. This policy explains what personal data we collect through our website and our mobile application, why we collect it, how we protect it, and the rights you have over it. It is published in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the applicable directions of the Reserve Bank of India, including the Master Direction on Know Your Customer and the guidelines on digital lending.

2. What we collect, and why

  • contact information: your name, mobile number, email address, date of birth and address. We use these to create and secure your account, to communicate with you about your application and loan, and to meet our legal duty to know our customer.
  • Identity documents: images of officially valid documents you provide, such as Aadhaar (with details masked as required by law), PAN and other permitted documents, including documents you choose to share with us from your DigiLocker account with your consent. We use these solely to verify your identity and complete Customer Due Diligence as required under the Prevention of Money Laundering Act, 2002 and RBI directions.
  • face verification: images captured through your device camera during onboarding, used to confirm that the person applying is genuinely present and matches the identity documents provided. This is part of our regulatory verification process.
  • Financial information: details of your income, bank account, existing obligations and the documents you upload in support of your loan application. We use these to assess your application and, after disbursal, to service your loan.
  • Consent records: when you give a consent in our app, we record which consent you gave, the exact text you agreed to, its version and the time. We keep this so that both you and we have reliable evidence of what was agreed.
  • Technical information: basic device and usage information necessary to operate the service securely, such as IP address and request logs. Our systems mask personal identifiers in logs.

3. What we deliberately do not collect

The app does not read your contacts, call logs or location, and it cannot browse the files or photos on your device; when you upload a document, you choose the specific image or file through your device's own picker, and we receive only what you select. On Android, with your consent, the app automatically reads only the one-time password that we ourselves send you by SMS, so that you need not type it; it cannot and does not read any other message. The app requests only the permissions it genuinely needs: the camera, for document capture and face verification, and your device's biometric unlock, to protect access to the app on your own device; the fingerprint or face data used for unlocking never leaves your device. We do not collect data for advertising, we do not sell personal data to anyone, and we do not display third party advertisements.

4. The legal basis for our processing

We process your personal data with your consent, which we request clearly and specifically inside the app before the relevant processing begins, and for legitimate uses recognised by law, including compliance with the Prevention of Money Laundering Act, 2002, the Reserve Bank's directions, and other legal obligations that apply to a regulated lender. Where processing rests on your consent, you may withdraw it at any time (see section 8); withdrawal does not affect processing already carried out, and we may be required by law to continue certain processing necessary for servicing an active loan or meeting regulatory obligations.

5. Where your data is kept and how it is protected

  • All personal data is stored on servers located in India (Mumbai region), consistent with the Reserve Bank's requirements for digital lending data.
  • Identity documents and sensitive records are encrypted at rest using strong modern encryption (AES 256), and all communication between the app and our servers is encrypted in transit (HTTPS).
  • One time passwords are stored only as cryptographic digests. Document reference identifiers that could reveal a document number are stored only in non reversible hashed form.
  • Access to personal data within the Company is restricted to personnel who need it to perform their duties, and our systems are subject to independent security audit by CERT-In empanelled auditors.

6. Who we share data with

  • Regulators and authorities: the Reserve Bank of India and other authorities where the law requires or permits.
  • Credit information companies: as a regulated lender we report credit information to credit information companies registered under the Credit Information Companies (Regulation) Act, 2005, and may obtain your credit report with your consent when assessing your application.
  • Service providers: carefully selected providers who help us run the service, such as cloud infrastructure (located in India), communication services for sending you verification codes and notices, and Government enabled verification platforms such as DigiLocker when you choose to use them. Service providers act on our instructions and are bound to protect your data.

We never sell personal data, and we do not share it with any third party for their marketing.

7. How long we keep it

As a regulated financial company we are required to retain customer identification records and transaction records for the periods prescribed under the Prevention of Money Laundering Act, 2002 and RBI directions, which is generally at least five years after the end of the business relationship or the transaction, whichever is later. Where no legal retention duty applies, we keep personal data only as long as needed for the purpose it was collected, and then delete or anonymise it.

8. Your rights

  • To know what personal data of yours we hold, and to receive a summary of it and of our processing activities.
  • To have inaccurate or incomplete data corrected, and data that is no longer necessary erased, subject to the retention the law requires of us.
  • To withdraw a consent you have given, as easily as you gave it, by writing to us at the contact below.
  • To nominate a person to exercise your rights in the event of death or incapacity.
  • To an accessible means of raising a grievance, and to escalate to the Data Protection Board of India if you are not satisfied with our response.

9. Grievances and contact

For any question, request or complaint about your personal data, contact our Grievance Officer: Aditya Agarwal, Company Secretary, Devvrat Capital Private Limited, 101, 1st Floor, Dol Bin Shir, Janmabhoomi Marg, Fort, Town Hall, Mumbai 400001. Email: grievance\@devvratcapital.com. Phone: +91 22 2204 2000. We acknowledge complaints promptly and aim to resolve them within the timelines prescribed by law. Our general grievance redressal mechanism, including escalation to the RBI Ombudsman for service complaints, is published on our Grievance Redressal page.

10. Children

Our products are offered only to persons aged 18 years and above. We do not knowingly collect personal data of children.

11. Changes to this policy

We may update this policy from time to time. The current version will always be available on this page with its effective date, and material changes affecting your rights will be notified through the app or by email.