Privacy & Security Policy

Last Updated: July 21, 2025

Applicable To: OnEMI Technology Solutions Limited, Kissht, and PaywithRing platforms


Overview

This Privacy & Security Policy applies to OnEMI TECHNOLOGY SOLUTIONS LIMITED ("the Company"), a company registered under the Companies Act, 2013, with registered office at 10th Floor, Tower 4, Equinox Park, LBS Marg, Kurla West, Mumbai City, Mumbai, Maharashtra, India, 400070.

This policy governs the collection, use, transfer, disclosure, and sharing of personal data through:

Subsidiary Company

Si Creva Capital Services Private Limited, a wholly owned subsidiary of ONEMI Technology Solutions Limited and a non-banking financial company (NBFC), collects, stores, and processes personal information on behalf of the Company for loan disbursement purposes.

Legal Compliance Framework

This policy is published in compliance with:

  1. Information Technology Act, 2000
  2. Information Technology (Intermediaries Guidelines and Digital Media Ethics Code) Rules, 2021
  3. Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  4. Digital Lending Directions, 2025 issued by the Reserve Bank of India (RBI), dated May 08, 2025
  5. All applicable laws, regulations, and guidelines provided by regulatory authorities including RBI

User Eligibility

To register and use the services:


Definitions

Personal Information

Information that identifies you, directly or indirectly, including:

Processing

An automated operation or set of operations performed on personal data, including:

Publicly Available Information

Any information or data that the Company reasonably believes is lawfully publicly available. All other information is considered non-publicly available.

User

Persons using the Company's services, website, or mobile app to whom this Policy applies. Terms "you" and "customer" are used interchangeably.


Information Collection

Required Information for Loan Applications

When applying for a loan through the platform, you must provide:

Mandatory and optional fields are indicated where possible. You can choose not to provide information by not using a particular service or feature.

User Consent Options

You are provided with options to:

Third-Party Service Providers

Si Creva engages with various third parties, service partners, and affiliates for collecting, storing, transferring, and processing information. The list of third-party service providers is available at: https://sicrevacapital.com/details-of-third-party-service-providers

Users are encouraged to review this list periodically.


Mobile App Permissions

SMS Data & Information

What is collected: Financial/transaction SMS only

Purpose:

Collection frequency: Once during loan onboarding journey

Privacy measures:

Usage:

Location

What is collected: Current location (one-time access)

Purpose:

Collection frequency: Once during loan onboarding journey

Usage:

Phone/Device Information

What is collected:

Collection frequency: Once during loan onboarding journey

Purpose:

Usage:

Camera

What is collected: One-time camera access

Purpose:

Collection frequency: One-time access for onboarding/KYC requirements only, with explicit consent

Usage:

Mobile App Technical Data

The mobile application may automatically collect:

Consent Withdrawal

You may deny access to SMS/E-mail/Location/Call Logs/Contact from your mobile device settings at any time. Upon withdrawal of consent, the Company will not have access to your information.

Important: The platform does not access:


Non-Personal Information Collection

Information Collected

Purpose of Collection

Session Data

Automatically logged generic information about device connection to the Internet:

This data is anonymous and not linked to personal information. It helps analyze user behavior and diagnose server problems.

Cookies

If enabled, cookies may be placed on your machine to:

Cookie Control: Users can control cookie use at the browser level. Rejecting cookies may limit ability to use some features.

Third-Party Cookies: Third-party vendors, including Google, may use cookies to serve ads based on website visits. Users may opt-out of interest-based advertising if the third party offers such an option.


Lawful Grounds for Processing Personal Information

Personal data is processed in compliance with applicable data privacy laws (Digital Lending Guidelines 2022, Information Technology Act 2000) based on:

  1. Consent: You have explicitly agreed to processing for a specific reason
  2. Performance of a Contract: Processing is necessary to perform the agreement with you
  3. Legal Obligation: Processing is necessary for compliance with legal obligations
  4. Legitimate Interest: Processing is necessary for legitimate interests pursued by the company

Purpose of Information Collection and Use

Primary Purposes

  1. Establish identity and verify the same with or without third-party help
  2. Facilitate and complete onboarding and KYC requirements for third-party lending partners
  3. Monitor, improve, and administer the platform
  4. Provide service (perform credit profiling for facilitating loans)
  5. Design and offer customized products and services from third-party financial partners
  6. Analyze platform usage, diagnose service/technical problems, maintain security
  7. Send communication notifications and information regarding requested products/services
  8. Process queries and applications made on the platform
  9. Manage relationship with users and inform about other products/services
  10. Conduct data analysis to improve services/products
  11. Comply with country laws and regulations
  12. Collect KYC for third-party lending partners
  13. Enable users to take financial services from lending partners

Additional Uses

Data Analytics

Collected information may be used to carry out data analytics to:

When used for data analytics, data is generally pseudonymized/anonymized to uphold privacy.


Information Sharing with Third Parties

General Sharing Practices

Explicit consent will be taken before sharing Personal Information with any third party, except where required by statutory or regulatory requirement.

Third-Party Service Provider Functions

Information may be shared with third-party service providers for:

  1. KYC Validation: Validate and authenticate KYC details (PAN, officially valid documents, occupation, income)
  2. Bank Account Validation: Validate preferred bank account and transfer loan amounts
  3. E-signing: E-signing of User Loan Agreement and populating the agreement (information retained for auditing)
  4. E-NACH Setup: Enable autopay functionality
  5. Additional Information Gathering: Gather bank account and statement details if adequate information not provided
  6. Collections: Manually collect sums owed to lending partners

Registered Third Parties

Information may be shared with:

Third-Party SDK

The App links to registered third-party SDK that collects data to:

Privacy Protection: Personal identifiable information and Government IDs (PAN, Aadhaar Card, VID number) are not shared with these third parties. No unauthorized access to non-public personal contacts or financial transaction SMS data.

Mandatory Disclosures

Information may be disclosed without prior notice:

Government Agencies

Government-issued ID numbers (PAN Number, Aadhaar Card, Virtual ID) are requested for:

This data:

KYC Journey Disclosure

KYC journey data may be disclosed to relevant regulatory authorities as part of statutory audit process. Aadhaar number is never disclosed.

Confidentiality Agreements

Information shared with third parties is under confidentiality agreements restricting use only for purposes stated in this privacy policy. The company warrants no unauthorized disclosure of information shared with third parties.

User Consent for Sharing

By using the Platform, users grant consent to:

Restricting Information Sharing

To restrict sharing of information partially or completely with third parties (other than statutory or regulatory authorities), contact: [email protected] or [email protected]


Data Retention

Storage Location

Personal information is stored only on servers located in India.

Retention Categories

Basic Personal Information (Non-Lending Services):

Retained for carrying out non-lending services.

Outsourcing Services Information: Personal information collected for Partners:

Retention Duration

Non-Personally Identifiable Information (Non-PII) including SMS:

Other Data (name, address, contact details, etc.):

General Retention Principles

Information retained:

Compliance

Retention done in compliance with:

Retention continues unless consent is withdrawn by user.


Data Destruction Protocol

All data, including all copies, will be destroyed post completion of:

Digital Data Destruction: Secure erasure of individual folders and/or files done as per the Media Handling and Destruction Policy of the Company.


Security Practices and Procedures

Security Standards

The platform complies with:

Encryption and Secure Communication

All communications between devices and the platform containing Personal Information are encrypted. This prevents:

Data Transmission Security

Access Control

Physical and Administrative Safeguards:

Database Protection:

Employee Access:

Server Security

Security Measures

Stringent security measures to protect against:

Security Features

  1. Encryption to keep data private while in transit
  2. Security features like OTP verification to protect accounts
  3. Review of information collection, storage, and processing practices
  4. Physical security measures to prevent unauthorized system access
  5. Restricted access to Personal Information
  6. Strict contractual confidentiality obligations for those with access
  7. Regular review of Privacy Policy
  8. Compliance with regulations and applicable laws
  9. Aadhaar number never disclosed

Third-Party Service Provider Security

Third-party service providers required to:

Telephone Call Recording

Telephone calls may be recorded and monitored for:

Cyber Security Policy

Cyber security policy implemented for handling all security breaches in compliance with applicable laws and regulations.


Information Security Breach Response

Compliance Framework

In the event of an information security breach, the Company commits to complying with guidelines from:

Incident Management Policy Approach

  1. Immediate Action: Contain and limit exposure of the breach
  2. Assessment: Determine scope and impact to understand affected data and systems
  3. Notification: Inform relevant authorities and affected parties per legal requirements and CERT-In & RBI guidelines
  4. Investigation: Determine cause, gather evidence for potential legal action, improve future security measures
  5. Recovery: Restore disrupted services and secure systems from future breaches
  6. Post-Incident Analysis: Identify lessons learned and implement improvements to policies, procedures, and technologies
  7. Reporting: Report to RBI & CERT-In within reasonable time frame with complete incident details, impact, and remedial actions

Compliance Assurance

The Incident Management Policy is designed for full compliance with:


User Rights Regarding Data

Right to Access

You may request to access your data provided or processed by the company. This enables you to:

How to Access: Log in to your account on the website or contact support at [email protected] or [email protected]

Right to Rectification

If any personal data is inaccurate, incomplete, or outdated, you have the right to:

Users are urged to always provide accurate and correct information to ensure uninterrupted service use.

Right to Withdraw Consent

Methods to Withdraw Consent:

Consent Withdrawal Process:

Impact of Withdrawal:

Continued Access After Withdrawal: Where permitted by law, you may be given option to give express consent to access:

Credit information used for:

Marketing Opt-Out

Marketing Communications: The company may send:

Opt-Out Methods:

Impact of Opting Out:

Account Closure

If you choose to close your account:

Data Deletion/Forget Option

You are provided with an option to:

How to Request Deletion: Write to [email protected] or [email protected]

Other User Options

You can:


Google API Services Compliance

The use of information received from Google APIs will adhere to:


Third-Party Advertising

The company may:

By using the website, you expressly permit Si Creva to access such information for one or more purposes deemed fit.


Children and Minors

The platform is not intended for use by children and minors. Parents are requested to ensure that personal information is not provided by minors.


Changes to Privacy Policy

Amendment Process

This Privacy Policy may change or be amended over time. The recent version is published on the Platform.

User Notification

Material changes to this Privacy Policy will be notified by:

User Responsibility

Keeping Information Current

It is important that Personal Information held/passed to lending partners is up to date and correct. Please inform the company of any changes to Personal Information.


Policy Review

The policy will be reviewed:


Omnibus Clause

All extant and future master circular/directions/guidance/guidance notes issued by Regulatory Authorities and other applicable regulations will:


Contact Information

Grievance Redressal Officer

Detail Information
Name Reefat Shaikh
Address 10th Floor, Tower 4, Equinox Park, LBS Marg, Kurla West, Mumbai, Maharashtra 400070
Contact Number 08044745952
Email [email protected]
Availability 10:30 a.m. to 6:00 p.m., Monday to Friday (except public holidays)

Privacy Concerns

For privacy-related concerns, write to:

Withdrawal of Consent / Deletion of Data or Account

For withdrawal of consent, deletion of data, or account deletion, write to:

Customer Service

Email: [email protected]

Phone Numbers:

Location: Mumbai, Maharashtra


Related Links

Websites

Third-Party Service Providers List

https://sicrevacapital.com/details-of-third-party-service-providers

Support Portal

https://kissht-care.freshdesk.com/support/tickets/new