OneNDF Customer Data Storage, Retention, Use, Destruction and Security Breach Policy
1. Objective
This Policy sets out the standards followed by OneNDF for collection, storage, use, sharing, retention, archival, deletion, and destruction of customer data processed through its website, borrower journeys, and digital lending interfaces.
2. Scope
This Policy applies to:
- OneNDF website
- borrower-facing digital journeys / DLA
- internal systems used for borrower processing
- integrations used for matching, underwriting support, servicing support, and grievance handling
- employees, consultants, service providers, and technology vendors handling customer data on behalf of OneNDF
3. Guiding Principles
OneNDF shall process customer data only on the basis of:
- lawful purpose
- explicit and purpose-specific consent, where required
- minimum necessary collection
- role-based access
- controlled sharing
- retention only for as long as necessary or legally required
- secure deletion / destruction after expiry of the applicable retention period
4. Categories of Customer Data That May Be Stored
OneNDF may store the following categories of data, strictly on a need-to-know and need-to-process basis:
A. Identity and profile data
- name
- mobile number
- email address
- date of birth
- PAN / masked PAN where appropriate
- address
- occupation / business profile
B. Loan application data
- loan requirement
- product selected
- amount requested
- tenor requested
- property details
- purpose of loan
- lender preferences, if any
C. Financial and underwriting-support data
- credit bureau response / score output
- banking summary / statement-derived outputs
- GST-derived outputs
- income / turnover details
- eligibility and rule-engine outputs
- matched / unmatched lender status
- internal risk / fit assessment outputs
D. Documents uploaded by customer
- KYC documents
- property papers
- income documents
- bank statements
- GST records
- company / firm documents
- sanction-related documents
E. Consent and audit data
- consent text version
- timestamp
- IP address
- device / session metadata
- OTP / authentication logs
- consent withdrawal / deletion request logs
F. Communication and grievance data
- emails
- call notes
- chatbot / form submissions
- complaint records
- grievance redressal records
5. Data That Shall Not Be Stored
OneNDF shall not store:
- biometric data in DLA/LSP systems unless specifically permitted by applicable law
- personal mobile phone resources such as contact list, call logs, file/media gallery, telephony functions, except one-time permitted access strictly required for onboarding / KYC with explicit consent
- any data not necessary for the disclosed purpose of processing
This is consistent with RBI's digital lending framework.
6. Purpose Limitations and Restrictions on Use
Customer data shall be used only for the purposes disclosed to the customer, including:
- onboarding and verification
- eligibility assessment
- lender matching
- sharing with matched lenders where consented or otherwise legally permitted
- servicing support
- fraud detection / prevention
- audit and compliance
- grievance handling
- legal defense and dispute resolution
- communications relating to the customer's active application or account
Customer data shall not be:
- sold
- used for undisclosed profiling
- shared with unrelated third parties without valid consent or legal basis
- used for marketing where the customer has withdrawn marketing consent
- retained indefinitely without purpose or legal basis
7. Data Storage Standards
- Customer data shall be stored on secure servers located in India, subject to applicable law and regulatory instructions.
- Sensitive records shall be encrypted at rest and in transit.
- Access shall be role-based and logged.
- Production and non-production environments shall be segregated.
- Downloads and exports shall be restricted to authorized users.
- Vendor access, if any, shall be controlled through contractual and technical safeguards.
8. Retention Timelines
The timelines below are recommended for OneNDF as an LSP. They should be aligned with lender contracts, litigation holds, tax/corporate record needs, and any more specific legal requirement.
A. Lead / enquiry data where application does not proceed
Retention: 12 months from last customer activity
Then: delete or anonymise
B. Incomplete applications
Retention: 12 months from last customer activity
Then: delete or anonymise unless dispute / fraud / regulatory hold applies
C. Rejected / withdrawn applications
Retention: 24 months from closure / withdrawal / rejection date
Then: delete or anonymise, except records required for audit, grievance, fraud monitoring, or legal defense
D. Application and underwriting records shared with lenders
Retention: 8 years from closure of application or from final closure of the associated lender relationship known to OneNDF, whichever is later
Reason: strong compliance, audit, dispute, outsourcing, and litigation-defence posture
E. KYC and core onboarding records
Retention: 8 years from end of business relationship / closure of application journey, unless a longer statutory requirement applies
F. Sanction / disbursal / servicing support records
Retention: 8 years from closure of the loan relationship known to OneNDF, unless a longer statutory or contractual requirement applies
G. Consent logs, audit logs, and access logs
Retention: 8 years from the relevant transaction / consent event
H. Customer communications
Retention: 3 years from last communication, unless linked to an active loan, complaint, investigation, or legal matter
I. Complaint / grievance records
Retention: 8 years from closure of the complaint
J. Security incident / breach investigation records
Retention: 8 years from closure of the incident
K. Marketing suppression records
Retention: 5 years from unsubscribe / withdrawal, only to ensure the customer is not contacted again in breach of their preference
L. Analytics data
Retention: 12 months in identifiable form; thereafter aggregate or anonymise where feasible
9. Inactivity and Pre-Deletion Notice
Where OneNDF maintains a user account or registered borrower account, and where deletion is scheduled due to prolonged inactivity and no legal retention requirement applies, OneNDF should provide notice before deletion. The 2025 DPDP Rules provide for notice at least 48 hours before expiry of the applicable destruction period in relevant cases.
Recommended OneNDF practice:
- inactive account with no active application or legal hold: notify at 30 days before deletion
- final reminder: 48 hours before deletion
10. Deletion and Destruction Protocol
At the end of the applicable retention period, OneNDF shall:
- identify records due for deletion
- check for legal hold, complaint hold, fraud hold, audit hold, or lender / contractual hold
- delete data from active systems
- purge or overwrite from archives as per backup cycles
- securely destroy physical copies through shredding / certified destruction
- record the deletion / destruction event in a deletion register
Deletion methods:
- cryptographic erasure where supported
- secure overwrite / purge for digital records
- cross-cut shredding for paper records
- deletion certificates from vendors where relevant
11. Customer Rights and Requests
Subject to applicable law and legitimate retention requirements, customers may request:
- access to their data
- correction / update
- withdrawal of consent for specific purposes
- restriction of sharing with third parties
- deletion / forgetting of eligible data
RBI's digital lending framework specifically contemplates customer controls to give or deny consent, restrict disclosure to third parties, revoke consent, and request deletion / forgetting of data.
12. Exceptions to Deletion
OneNDF may retain data beyond normal timelines where necessary for:
- statutory or regulatory compliance
- audit requirements
- fraud detection / prevention
- cyber-security investigation
- grievance handling
- dispute resolution / litigation
- enforcement of contractual rights
- directions from lenders, regulators, courts, or law-enforcement, where legally valid
13. Standards for Handling Security Breaches
In case of an actual or suspected security breach involving customer data, OneNDF shall follow the process below:
A. Detection and containment
Timeline: immediately, and in any event within 24 hours of detection
- isolate affected systems
- revoke compromised credentials / sessions
- block unauthorized access pathways
- preserve logs and evidence
B. Internal escalation
Timeline: within 6 hours of material incident identification
Notify:
- information security lead
- technology head
- compliance / legal
- senior management
- relevant incident-response team
C. Preliminary assessment
Timeline: within 24 hours
Assess:
- category and volume of data affected
- whether financial / KYC / document data is involved
- whether active borrower harm is likely
- whether lender / regulator / customer notifications are required
D. Customer and partner protection actions
Timeline: without undue delay after risk assessment
- force password reset / re-authentication where needed
- suspend risky workflows
- notify impacted partners / lenders where relevant
- activate fraud monitoring on affected cases
E. Notification and reporting
OneNDF shall notify affected customers, lenders, and competent authorities as required under applicable contracts, laws, and regulatory instructions. The exact reporting timeline may vary by incident and applicable law, so this should be governed by the incident response SOP and legal review.
Recommended internal standard:
- internal materiality determination: within 24 hours
- borrower communication draft: within 48 hours where warranted
- final remediation plan: within 7 days
- root cause closure report: within 30 days
14. Security Controls
OneNDF shall maintain reasonable technical and organisational controls including:
- encryption
- MFA for privileged access
- role-based access control
- periodic access review
- logging and monitoring
- secure SDLC controls
- vulnerability management
- vendor due diligence
- backup protection
- employee confidentiality obligations
- incident response playbooks
15. Website and DLA Disclosure
This Policy, or an accurate short-form summary with a link to the full Policy, shall be displayed prominently on:
- OneNDF website
- borrower onboarding journey
- Privacy & Consent section
- relevant DLA / application pages
This matches RBI's requirement that such policy guidelines be disclosed prominently on the website and app / DLA at all times.
16. Customer Support & Complaints
OneNDF shall prominently publish on its website / app the contact details of the relevant grievance / privacy contact for data processing queries.
Level 1: Customer Support
Email: [email protected]
Phone: +91 7290041855
Level 2: Grievance Officer
Name: Shipra Kochhar
Email: [email protected]
TAT: 7–15 working days
Level 3: Lender / RE Grievance Channel
ICICI Grievance Channel: Raise a Complaint with ICICI
ICICI GRO: ICICI Digital Lending Guidelines
Level 4: RBI CMS
If any complaint lodged by the borrower against the Regulated Entity (RE) or the Lending Service Provider (LSP) engaged by the RE is rejected wholly or partly by the RE, or if the borrower is not satisfied with the response received, or if no response is received within 30 days from the date of receipt of the complaint by the RE, the borrower may lodge a complaint through the Reserve Bank of India's Complaint Management System (CMS) under the Reserve Bank – Integrated Ombudsman Scheme (RB-IOS).
The borrower may also submit a physical complaint to:
Centralised Receipt and Processing Centre
4th Floor, Reserve Bank of India
Sector-17, Central Vista
Chandigarh – 160017
17. Review and Version Control
This Policy shall be reviewed at least once every 12 months, and earlier if required due to:
- regulatory change
- lender / partner onboarding
- material product change
- data breach / incident
- audit findings
Retention Summary Table
| Data type | Retention period | Action after retention |
|---|---|---|
| Lead / enquiry data | 12 months from last activity | Delete / anonymise |
| Incomplete applications | 12 months from last activity | Delete / anonymise |
| Rejected / withdrawn cases | 24 months from closure | Delete / anonymise unless hold applies |
| KYC / onboarding records | 8 years | Secure deletion / archive purge |
| Credit Bureau | 180 Days | Delete |
| Application / underwriting records | 8 years | Secure deletion / archive purge |
| Consent and audit logs | 8 years | Secure deletion / archive purge |
| Communications | 3 years | Delete unless linked to complaint / dispute |
| Complaints / grievances | 8 years | Secure deletion / archive purge |
| Security incident records | 8 years | Secure deletion / archive purge |
| Marketing suppression records | 5 years | Delete once no longer needed |
| Analytics data | 12 months identifiable | Aggregate / anonymise |