Privacy Policy

Last Updated: June 29, 2026

Introduction & Legal Status

AarneX FinServ ("we," "us," or "our") is operated as a sole proprietorship under Indian law by its Proprietor, Mr. Rahul Tripathi. For the purposes of applicable data protection law, AarneX FinServ acts as a Data Fiduciary. We serve strictly as an independent, non-lender, Digital Lending Facilitator and Direct Sales Associate (DSA). We do not provide loans, extend credit, or make underwriting decisions—all of which remain the exclusive responsibility of our partner regulated lending institutions.

We are committed to protecting the privacy, security, and integrity of the data shared with us by our users, business partners, and applicants (collectively referred to as "Data Principals" or "you") in strict accordance with the Digital Personal Data Protection Act (DPDP Act), 2023, the Information Technology Act, 2000, and applicable Reserve Bank of India (RBI) guidelines. While AarneX FinServ implements reasonable measures to protect the integrity of data shared with us, please note that no method of electronic transmission or storage is entirely secure. By using our services, you acknowledge that you understand these inherent risks.

1. Data Minimization Principle

We collect and process personal data solely for the purposes described in this policy, ensuring that we only access the minimum information necessary to facilitate your requested financial services.

2. Legal Basis for Processing

In compliance with the DPDP Act, 2023, we process personal data only under valid legal grounds:

  • Consent: Where you have granted explicit, specific, and clear consent for targeted processing or promotional updates.
  • Contractual Necessity: To perform a contract or fulfill an active service request made by you prior to entering into a contract.
  • Legal Obligation & Legitimate Uses: To comply with statutory requirements under Indian law or enforcement directives.

3. Information We Collect

To evaluate partnership inquiries, facilitate customer referrals, and provide financial distribution services, we limit collection to the following specific fields:

  • Identity & Contact Data: Full name, business or firm name, corporate structure, email address, and mobile phone number.
  • Location & Business Operational Data: PIN code, city, state, years of professional experience, and target geographic areas of operation.
  • Compliance & Statutory Identifiers: Business PAN, GSTIN, or professional credentials submitted voluntarily by the applicant. (Note: AarneX FinServ does not collect, access, or retain [Aadhaar Redacted] numbers under any circumstances).
  • Verification Data: Timestamps, transaction identifiers, and related verification logs. We do not store or retain OTP values under any circumstances after successful verification.

4. How We Use Your Data

We process your personal and professional information for the following specific mandates:

  • To evaluate, screen, and verify partner registration inquiries.
  • To communicate operational updates, activity logs, and administrative notifications.
  • To evaluate partnership inquiries, facilitate customer referrals, provide documentation assistance, and offer application submission assistance through authorized corporate sourcing partners, institutional distribution arrangements, or lending institutions.
  • To comply with fraud prevention tracking, security audits, or statutory requirements under applicable Indian laws.
  • With your explicit consent, to distribute promotional circulars, incentive updates, and financial product announcements.

5. Data Sharing, Lending Ecosystem Rules, & Retention Schedule

A. Field-Level Sharing Policy & Recipient Scoping

We do not sell, rent, or trade your personal data to third parties for marketing purposes. We do not authorize third parties receiving personal data from us to use such information for their own independent marketing purposes unless you have separately consented to such use or such use is otherwise permitted by applicable law.

Data is shared strictly on a need-to-know basis according to recipient types:

  • Trusted Technical Providers (e.g., Secure Cloud Hosting, CRM Platforms): Shared fields are restricted to Identity, Contact, and Location data solely to log pipelines and maintain secure platform operations under strict confidentiality mandates.
  • Regulated Lending Ecosystem Networks (Banks/NBFCs): Shared fields include Identity, Business Operational Data, Compliance Identifiers, and Verification logs. This data is transferred solely to facilitate credit evaluation flows for your referred clients, subject to applicable law and required consents. Once your information is transferred to an authorized lender at your request, its processing is governed exclusively by the privacy terms of that receiving institution.
  • Regulatory & Legal Authorities: Shared data includes identification and transaction logs when legally demanded under the Information Technology Act, 2000, DPDP Act, 2023, or other lawful governmental directions.

B. Discretionary Limits & Automated Decisioning

As stated in our Introduction, we do not engage in automated credit profiling or algorithmic decision-making. All credit assessments, approvals, pricing, and disbursements remain solely at the discretion of the respective lending institution in accordance with its internal policies and applicable laws.

C. RBI Digital Lending Compliance

Where applicable, AarneX FinServ facilitates customer referrals in accordance with applicable RBI Digital Lending regulations, directions, and guidelines. Customer data is shared with partner Regulated Entities (REs), including Banks and NBFCs, only with explicit borrower consent and solely for credit evaluation purposes. AarneX FinServ does not store or access device-level data (such as contacts, media, or call logs) beyond what is strictly required for application service delivery.

D. PMLA and Statutory Retentions

Where required by the Prevention of Money Laundering Act (PMLA), 2002, RBI KYC Master Directions, or other applicable laws, we retain and share customer identification and verification records with authorized regulatory or government bodies for the mandated retention periods.

E. Data Retention Schedule

In accordance with applicable data protection laws, data is retained strictly according to the following purpose-linked schedule:

Data Category Specific Purpose Retention Period
Loan Facilitation & Enquiry Data Tracking credit applications and partner pipelines 36 months from the last recorded interaction with the user or earlier where deletion is requested and permitted under applicable law.
KYC & Partner Registration Documents Onboarding verification and identity checks 5 years from account closure (Statutory PMLA mandate).
Customer Complaints & Disputes Operational grievance and resolution tracking Up to 7 years from the date of absolute closure.
Resume & Career Applications Evaluating candidates for internal positions 12 months from submission date.

Note: Where required by law, regulatory directives, or ongoing legal proceedings, data may be retained for longer than the above stated periods. Upon expiry of the applicable retention period, personal data will be securely deleted, anonymized, or archived where required by law.

F. Cross-Border Processing

We utilize enterprise cloud service providers and supporting technical infrastructure located within India and/or in jurisdictions permitted under applicable Indian data protection laws and government notifications. We implement appropriate contractual, technical, and organizational safeguards to protect personal data during its processing, storage, and transfer.

6. Technical Security & Data Breach Notification Commitment

  • Security Measures:We implement appropriate technical and organizational security measures, including role-based access controls, encryption of personal data during transmission and at rest, system logging, secure authentication mechanisms, continuous security monitoring, and other reasonable safeguards designed to protect personal data against unauthorized access, use, alteration, disclosure, or destruction. Access to personal data is restricted to authorized personnel who require such access for legitimate business purposes and are subject to confidentiality obligations.
  • Data Breach Notification SLA:In the event of an identified personal data breach involving our systems, we will notify the competent authority established under applicable Indian law and the affected individuals as soon as reasonably practicable, in accordance with applicable law, aiming for a response window of 24 to 72 hours upon verifying and confirming the nature and scope of the breach.
  • Unsecured Communication Warning: Users should avoid transmitting highly confidential passwords, credentials, or sensitive documents through unsecured public communication grids.

7. Data Principal Rights & Consent Withdrawal

Under the DPDP Act, 2023, you hold specific statutory rights regarding your personal data. To protect your privacy, we may request reasonable identity verification before processing any privacy request relating to your personal data.

  • Right to Access, Correction, and Erasure: You maintain rights available under applicable law to request a summary of your processed data, correct inaccurate or misleading information, or request complete data erasure, subject to statutory retention obligations (such as PMLA or tax rules).
  • Right to Nominate: You have the right to nominate a specific person to exercise your data rights on your behalf in the event of death or physical/mental incapacity, in accordance with applicable legal provisions.
  • Right to Withdraw Consent: You may withdraw your consent for promotional or processing activities at any time. In compliance with applicable data protection laws, withdrawing consent is engineered to be as accessible as providing it.
  • Mechanism: To withdraw consent, send an email to privacy@aarnexfinserv.com with the exact subject line "Withdraw Consent", or click the "Unsubscribe" link present at the bottom of any digital marketing communication. Valid withdrawal requests are systematically processed without undue delay and in accordance with applicable law. Withdrawal will not affect the lawfulness of any data processing carried out prior to such withdrawal.

All privacy requests regarding your rights or nominations should be formally directed to privacy@aarnexfinserv.com.

8. Minors and Child Data Protection

Our loan facilitation and financial distribution services are strictly intended only for individuals aged 18 years or above. In accordance with applicable laws, we do not knowingly collect personal data from minors, nor do we engage in behavioral monitoring or targeted advertising directed at children. If we become aware that personal data has been inadvertently submitted by a minor under 18 years of age without verifiable parental consent, we will promptly and securely delete such information from our business records. Parents or guardians may contact us directly at privacy@aarnexfinserv.com to request the immediate deletion of a child's data.

9. Cookies & Tracking Technology

Our website utilizes tracking cookies divided into specific operational categories:

  • Essential Cookies: Strictly necessary to secure our portal, authenticate access, and maintain basic site functionalities.
  • Analytics Cookies: Used to analyze traffic trends and user behavior to help improve our platform, deployed only where explicit consent has been provided.
  • Functional Cookies: Configured to remember your custom portal selections and optimize your step-by-step onboarding journey.
  • Marketing Cookies: Used to deliver relevant financial product announcements and track the effectiveness of our marketing communication based on your explicit preferences.

Performance, functional, marketing, and analytics cookies are disabled by default and are only deployed once you actively click "Accept" on our Consent Banner. You can modify or revoke your cookie choices at any time through your browser settings or by utilizing the preference controls provided directly within our interface.

10. Policy Updates

We reserve the right to update or modify this Privacy Policy at any time to reflect changing operational, legal, or regulatory requirements. Material changes will be clearly indicated by updating the "Effective Date" at the top of this page. Where required by applicable law, we will obtain fresh consent before changes affecting the processing of your personal data become effective. Continued use of our website after any updates constitutes acceptance of the revised Privacy Policy, where permitted by applicable law and where additional consent is not otherwise required.

11. Named Grievance Officer & Redressal Matrix

In compliance with the DPDP Act, 2023, and information technology rules, any privacy questions, data updates, or unresolved data handling grievances must be directed to our designated Grievance Officer:

  • Grievance Officer Name: Mr. Rahul Tripathi
  • Designation: Proprietor & Grievance Officer
  • Registered Office Address: 557, 5th Floor, Cloud 9, Vaishali, Sector 1, Ghaziabad, Uttar Pradesh - 201010, India
  • Dedicated Privacy Desk Email: privacy@aarnex.com
  • General Support Line Email: care@aarnex.com
  • Official Office Contact Number: +91-8700315236
  • Statutory Response SLA: We strive to formally review, investigate, and address all privacy-related complaints or grievances within 30 calendar days of official receipt.