Privacy

1. DEFINITIONS

For the purpose of this Privacy Policy (hereinafter referred to as the “Policy”), wherever the context so requires:

a) The term ‘Monexo’ shall mean ‘Monexo Fintech Private Ltd’ a company registered under the Companies Act, 2013 and having its registered office at 1D, Apex Plaza, Old #3, New #77, Nungambakkam High Road, Nungambakkam, Chennai 600 034 with CIN # U65921TN2016PTC103548.

b) The term ‘website’ shall mean https://zapmoney.in/. “App” shall mean ZapMoney mobile application and any other application or software run under the brand name “ZapMoney”.

ZapMoney is owned by Monexo. This App may be used by Monexo, which is Regulated by RBI as NBFC-P2P and other Regulated Entities Approved by Reserve Bank of India (NBFCs & Banks) for digital lending and other activities including promotional activities may be undertaken via the App in the future.

c) The term ‘You’, ‘Your’ & ‘User’ shall mean any legal person or entity accessing or using the services provided on this Website / App, who is competent to enter into binding contracts, as per the provisions of the Indian Contract Act, 1872.

d) The terms ‘We’, ‘Us’& ‘Our’ shall mean the website/domain and Monexo (collectively referred to as the “Platform”), as the context so requires.

This Policy will be applicable to Monexo to the extent applicable under the IT (RSP) Rules (defined hereinafter) and the DLG Guidelines to the extent applicable.

2. GENERAL

a) We are committed to safeguarding your privacy and ensuring that you continue to trust us with your personal data. When you interact with us you may share personal information with us which allows identification of you as an individual. This is known as personal data.

b) This document is an electronic record in terms of Information Technology Act, 2000 and rules there under as applicable and the amended provisions pertaining to electronic records in various statutes as amended by the Information Technology Act, 2000. This electronic record is generated by a computer system and does not require any physical or digital signatures. This document is published in accordance with the provisions of Rule 3 (1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (“Intermediary Rules”) that require publishing the rules and regulations, privacy Policy and Terms of Use for access or usage of the Platform. We confirm that our privacy Policy is compliant with applicable laws, associated regulations and RBI guidelines.

c) Monexo / Various banks / non–banking financial institutions are responsible for the loan and other facilities provided through the App. You acknowledge that Monexo / such banks / non–banking financial institutions, as per the Reserve Bank of India’s (“RBI”) guidelines, will be responsible for their respective contents displayed on the App, loan and other facilities offered. Monexo reserves the right, subject to prevailing RBI guidelines, in its sole discretion to remove any content or data, information or material from the App from time to time.

d) We shall periodically inform its users, at least once every year, that in case of non-compliance with rules and regulations, privacy Policy or user agreement for access or usage of the computer resource. We shall also periodically, and at least once in a year, inform its users any change in the rules and

regulations, privacy Policy or user agreement, as the case may be. When we collect information from a user for registration on the computer resource, we shall retain his information as per Data Retention Policy narrated in clause 10.2 of this policy.

e) Please do not host, display, upload, modify, publish, transmit, store, update or share any information on the Platform: (i) belongs to another person and to which the user does not have any right; (ii) is defamatory, obscene, pornographic, paedophilic, invasive of other’s privacy including bodily privacy, insulting or harassing on the basis of gender, libellous, racially or ethnically objectionable, relating or encouraging money laundering or gambling, or otherwise inconsistent with or contrary to the laws in force. (iii) is harmful to child; (iv) infringes any patent, trademark, copyright or other proprietary rights; (v) violates any law for the time being in force; (vi) deceives or misleads the addressee about the origin of the message or knowingly and intentionally communicates any information which is patently false or misleading in nature but may reasonably be perceived as a fact; (vii) impersonates another person; (viii) threatens the unity, integrity, defence, security or sovereignty of India, friendly relations with foreign States or public order or causes incitement to the commission of any cognisable offence or prevents investigation of any offence or is insulting other nation;

(ix) contains software virus or any other computer code, file or program designed to interrupt, destroy or limit the functionality of any computer resource; (x) is patently false and untrue, and is written or published in any form, with the intent to mislead or harass a person, entity or agency for financial gain or to cause any injury to any person.

3. SCOPE AND ACCEPTANCE OF THIS PRIVACY POLICY

a) This Policy applies to the personal data and the sensitive personal data that we collect about you for the purposes of providing you with our services. Personal data or information as used in this Policy shall include sensitive personal data or information, as applicable. This Policy is formulated under the Information Technology Act 2000, the IT (RSP) Rules (defined hereinafter) and the Guidelines on Digital Lending issued by the Reserve Bank of India dated 2 September 2022(“DLG Guidelines”).

b) By using this website or by giving us your personal data and sensitive personal data, you accept the practices described in this Policy, its contents, and have provided your informed consent to us collecting, storing, processing, transferring and sharing your Personal Information with lenders, partners, service providers for the purposes set out in this Policy. If you do not agree to this Privacy Policy, please do not use this website or give us any personal data or sensitive personal data.

c) We reserve the right to change this Policy without prior notice. We encourage you to regularly review this policy to ensure that you are aware of any changes and how your personal data may be used.

4. DATA COLLECTED BY US

To create an account on the App or Website, you must provide us with the basic details and information required as part of our Customer Identification process and you agree to our User Terms and Conditions and this Privacy Policy, which governs how we treat your information. App Collects basic information required to provide customized services (for example: loan offers, content, more relevant ads), including your name, mailing address, postal code, job title, family details, employer details, phone number, PAN No., employment information, salary slips, declarations, your description and details in your account, financial information such as bank account etc. Such data is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the Information Technology

Reasonable security Practices and procedures and sensitive personal data or information) Rules, 2011 (“IT RSP Rules”).

You will register with us using your Facebook or LinkedIn account or Google identity or any other third-party website mentioned on our Platform (“Third Party Sites”). You understand that, by creating an account or by registering through Third Party Sites, we and others will be able to identify you by your profile. We will also not be liable for the photographs and data that the users might upload, which are not in accordance with applicable law. We will ask for your bank account details only for the service provided by us. Such data is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the IT RSP Rules.

All the information that you shall provide us is voluntary, including sensitive personal information. You understand that we may use certain information of yours, which has been designated as ‘sensitive personal data or information’ under the IT RSP Rules for the purpose of providing you the services and for sharing the information only with affiliates such persons who are identified in this Privacy Policy who are subject to this Privacy Policy, as will be explained further below.

Please note that we always ask for your permission before accessing the information on your phone. We collect and monitor only your financial transaction SMS, names of transacting parties, transaction description and amount to perform a credit risk assessment. Such data is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the IT RSP Rules. No personal SMS data is collected, read or stored. All information requested is relevant to create a credit score which helps us make faster credit disbursals and better credit limits. You may choose not to provide the information requested. However, your credit score may be inaccurate or unavailable for your application as a result.

We hereby confirm that we do not store your personal information, except the following personal information provided in Clause 4.1 of the Policy which is necessary to carry out our business operations which may be shared with third parties. The App does not store personal information of borrowers/users except some basic minimal data (viz., name, address, contact details of the customer, etc.) that may be required to carry out business operations.

We may collect data about you from a variety of sources, including through:

a) Online and electronic interactions with us, including via the website, mobile applications, text messaging programs or through our pages on third party social networks.

b) Your interaction with online targeted content (such as advertisements) that we or service providers on our behalf provide to you via third party websites and/or applications.

4.1 DATA THAT YOU PROVIDE US DIRECTLY

This includes the types of personal or sensitive personal data that you provide us, in addition to the data mentioned in Section 4 above, with your consent for a specified purpose of providing you the services as mentioned in the Platform, including the following, under Rule 3 of the IT RSP Rules.

Some of these may be regarded as sensitive personal data or information under Rule 3 of the IT RSP Rules. We shall use the information collected by us only for the purpose for which it has been collected, for a specified purpose of providing you the services as mentioned in the Platform.

a) Personal contact information, including any information allowing us to contact you in person. It would include, but is not limited to, users’ KYC details, borrowers’/users’ academic information and documents, co–borrowers/users’ financial documents, etc.

b) Demographic information, including date of birth, age, gender, location. We may also collect the location data, if enabled by you to do so. Geolocation includes country of access, IP address, etc.

c) User image, for us to cross check and verify the authenticity of the User and for prevention of fraud.

d) Account login information including any information that is required for you to establish a user account with us. (e.g. login ID/ email, user name, password and security question/answer);

e) Consumer feedback, including information that you share with us about your experience in using our services (e.g. your comments and suggestions, testimonials and other feedback)

f) We may collect the Usage data, including but not limited to access date and time, platform features and/or pages viewed, type of browser, hardware models, operating systems and versions, software, mobile network data, etc.

g) The data collected, as mentioned above, is solely restricted to the above–mentioned activities and will not be in further used for any other purpose. In case we use the data for any other purpose, explicit consent shall be taken from the customers.

h) We will desist from accessing mobile phone resources like file and media, contact list, call logs, telephony functions from user phone resources.

i) We will ensure that access to camera, microphone, location or any other facility necessary for the purpose of on–boarding/ KYC requirements and only with the explicit consent of the user.

j) We will ensure that biometric data is stored/collected in the systems, only in accordance with applicable law and the IT RSP Rules.

k) We will ensure that all data is stored only in servers located within India, while ensuring compliance with statutory obligations/ regulatory instructions.

l) You are provided with an option to give or deny consent for use of specific data, restrict disclosure to third parties, data retention, revoke consent already granted to collect personal data and if required, make the App (as defined under the DLG Guidelines) delete/forget the data. In case of withdrawal or modification of your consent or your amendment of any of your choices in this regard, we reserve the option not to provide the services or modify the services provided to you for which such information was sought.

4.2 DATA WE COLLECT WHEN YOU VISIT OUR PLATFORM

APP Permissions

SMS Permission: We will request permission to view SMS messages relating to financial transactions only in order to determine your income and expense profile. Monexo and/ or the App will only access financial SMSs sent by 6– digit alphanumeric senders from the inbox which helps us identify the various accounts held by the user and to help perform an optimal ‘credit risk assessment’ of the user.

The data is accessed by our machine learning models only. We will only access those messages that are relevant to this purpose and will not read / store/share irrelevant or personal messages in any form or manner. The permission is voluntary and can be revoked at any time. However, denying access may lead to an inaccurate assessment of the user’s credit assessment on the platform. The data accessed by the said permission is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the IT RSP Rules.

Phone Permission: Collect and monitor specific information about your device including your hardware model, operating system and version, unique device identifiers like IMEI and serial number, user profile information and mobile network information to uniquely identify the devices and ensure that unauthorized devices are not able to act on your behalf to prevent frauds. The data accessed by the said permission is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the IT RSP Rules.

Phone Book Contacts: When you grant us access to the address book on your mobile device, then we access the names and contact information from your address book to facilitate invitations and to assess your phone usage and habits. As part of the loan journey, we access your phonebook contacts which includes their contact names, phone numbers, account types, favourites (starred) and contact labels to enrich your financial profile. We use this data to identify fraudulent contacts in your network, for underwriting purposes and for promotional and marketing purposes. This helps us in detecting fraud loan applications and reducing credit risk. The data accessed by the said permission is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the IT RSP Rules.

Location Permission: Monexo and/or the App will request permission to capture the user’s location for verification, risk analysis and operational purposes. The user’s location will enable Monexo and/ or the App to verify addresses, determine serviceability and expedite the KYC process. The data accessed by the said permission is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the IT RSP Rules.

Apps Permission: Collect and monitor a list of installed apps on your device for credit profile enrichment Accounts Permissions Collect and monitor the list of accounts on your device for credit profile enrichment. The data accessed by the said permission is stored in our systems in accordance with Rule 3(h) of the Intermediary Rules and the IT RSP Rules.

Information Collection and Use

For a better experience, while using our service, we may require you to provide us with certain personally identifiable information, including but not limited to User info. The information that we request will be retained by us and used as described in this privacy policy.

The app does use third party services that may collect information used to identify you.

Certain third–party providers’ services are used by the App including the following: (i) Google; (ii) Facebook; (iii) IOS/ Apple, (iv) LinkedIn etc.

Log Data

We want to inform you that whenever you use our service, in a case of an error in the app we collect data and information (through third party products) on your phone called Log Data. This Log

Data may include information such as your device Internet Protocol(“IP”) address, device name, operating system version, the configuration of the app when utilizing our service, the time and date of your use of the service, and other statistics.

Cookies

Cookies are files with a small amount of data that are commonly used as anonymous unique identifiers. These are sent to your browser from the websites that you visit and are stored on your device’s internal memory.

We may set cookies to track your usage on our web application platforms. We use data collection devices such as “cookies” on certain pages of the App and Website to help analyse our web page flow, measure promotional effectiveness, and promote trust and safety.

These are used to enhance your experience with our App. We use cookies to help us identify who you are, so your login experience is smooth each time. Cookies also allow us to collect Non–Personally Identifiable Information from you, like which pages you visited and what links you clicked on. Use of this information helps us to create a more user–friendly experience for all visitors. In addition, we may use Third Party Advertising Companies to display advertisements on our App. By using the app, you signify your consent to our use of cookies.

Please note that if you decline or delete these cookies, some parts of the App may not work properly.

Service Providers

We may employ third–party companies and individuals due to the following reasons:

  • To facilitate our service.
  • To provide the service on our behalf.
  • To perform service–related services; or
  • To assist us in analysing how our service is used.

We want to inform users of this service that these third parties have access to your personal information. The reason is to perform the tasks assigned to them on our behalf. However, they are obligated not to disclose or use the information for any other purpose.

Security

We value your trust in providing us your Personal Information, thus we are striving to use commercially acceptable means of protecting it. But remember that no method of transmission over the internet, or method of electronic storage is 100% secure and reliable, and we cannot guarantee its absolute security.

You can access your personal identity details on our App through your login and password. We recommend that you do not share your password with anyone. In addition, your personal details are stored on a secure server located in India that only selected personnel contractors and authorised Agencies have access to on a need– to– know basis. We encrypt certain sensitive information using Secure Socket Layer (SSL) technology to ensure that your personal details are safe as it is transmitted to us.

Protection of your privacy and your data security is a top priority for us. We encrypt your data and store it in multiple databases. There are security group and firewall checks to control the APIs with

multi–level authentication, authorisation and verifications.

However, you understand and accept no data transmission over the Internet can be guaranteed to be completely secure. We cannot ensure or warrant the security of any information that you transmit to us and you do so at your own risk. Data pilferage due to unauthorized hacking, virus attacks, technical is possible and we take no liabilities or responsibilities for it, except to the extent permitted in law. In case such security breach happens, we take the following steps as mentioned in Para 10 of this Policy.

Links to Other Sites

This service may contain links to other sites. If you click on a third–party link, you will be directed to that site. Note that these external sites are not operated by us. Therefore, we strongly advise you to review the Privacy Policy of these websites. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third–party sites or services.

5. DIVULGING/SHARING OF PERSONAL INFORMATION

a) We may share your personal information with other corporate entities and affiliates to help detect and prevent identity theft, fraud and other potentially illegal acts; correlate related or multiple accounts to prevent abuse of our services, to facilitate joint or co–branded services, where such services are provided by more than one corporate entity, or if required to do so in course of our business operations. The third parties to whom your data may be disclosed shall not disclose the data further.

b) We may disclose personal information if required to do so by law or if we in good faith believe that such disclosure is reasonably necessary to respond to subpoenas, court–orders, or other legal processes.

c) If we are involved in a merger, acquisition, or sale of assets, we’ll continue to ensure the confidentiality of your personal information and give affected users notice before personal information is transferred or becomes subject to a different privacy policy. Business Transfers: As we continue to develop our business, we might sell or buy business units. In such transactions, customer information generally is one of the transferred business assets but remains subject to the promises made in any pre–existing Privacy Policy (unless, of course, the customer consents otherwise). Also, in the unlikely event that Monexo’s assets or substantially all of its assets are acquired, customer information maybe one of the transferred assets.

d) Third party service providers: We may employ other companies and individuals, call centres, payment gateways, banks to perform functions on our behalf. Examples include delivering e–mail, analyzing data, providing marketing assistance, providing search results and links (including paid listings and links) and providing customer service. They have access to personal information needed to perform their functions but may not use it for other purposes. Further, they must process the personal information in accordance with this Privacy Policy and as permitted by applicable law.

e) Protection of App: We release personal information when we believe, release is appropriate to comply with the law; enforce or apply our User Terms and Conditions and other agreements; or protect the rights, property or safety of App, our users or others. This includes exchanging information with other companies, organizations, government or regulatory authorities for fraud protection and credit risk reduction.

6. USE OF PERSONAL INFORMATION

We and our affiliated partners may use the personal information submitted by you to contact you in relation to the services offered. This shall override any calling preferences, which you may have registered in the NDNC.

7. SECURITY

Transactions on the Website are secure and protected. Any information entered by the User when transacting on the Website is encrypted to protect the User against unintentional disclosure to third parties. The User’s credit and debit card information is not received, stored by or retained by Monexo / Website in any manner. This information is supplied by the User directly to the relevant payment gateway, which is authorized to handle the information provided, and is compliant with the regulations and requirements of various banks and institutions and payment franchisees that it is associated with.

8. THIRD PARTY ADVERTISEMENTS / PROMOTIONS

We use third–party advertising companies to serve ads to the users of the Website. These companies may use information relating to the User’s visits to the Website and other websites to provide customised advertisements to the User. Furthermore, the Website may contain links to other websitesthat may collect personally identifiable information about the User. Monexo/Website is not responsible for the privacy practices or the content of any of the aforementioned linked websites, and the User expressly acknowledges the same and agrees that any and all risks associated will be borne entirely by the User. We strongly advise you to review the privacy policy of every site you visit.

9. DATA PROTECTION OFFICER AND GRIEVANCE REDRESSAL OFFICER

If you have any complaint under the Information Technology Act 2000, the IT RSP Rules or any FinTech/ digital lending related complaints/issues, the contact details of the Data Protection Officer and Grievance Redressal Officer are provided below. The Data Protection and Grievance Redressal Officer should acknowledge the complaint within 24 (twenty–four) hours and dispose of such complaint within a period of 15 (fifteen) days from the date of its receipt.

Mr. Sundar Mahalingam,
Monexo Fintech Pvt Ltd, 1D, Apex Plaza,
Old #3, New #77, Nungambakkam High Road,
Chennai 600 034
Phone number: 044-69006363,
E–Mail ID: grievance@zapmoney.in

10. DATA SECURITY & RETENTION

10.1 DATA SECURITY

In order to keep your personal data secure, we have implemented a number of security measures including:

We value your Personal Information, and protect it on the Platform against loss, misuse or alteration by taking extensive security measures. In order to protect your Personal Information, we have implemented adequate technology and will update these measures as new technology becomes

available, as appropriate. All Personal Information is securely stored on a secure cloud setup and all communication happens via secure SSL communication channels.

You are responsible for all actions that take place under your User Account. If you choose to share your User Account details and password or any Personal Information with third parties, you are solely responsible for the same. If you lose control of your User Account, you may lose substantial control over your Personal Information and may be subject to legally binding actions.

No data collected and allowed to be stored by us shall be stored in any server which is not located in India.

Standards for handling security breach:

(i) All suspected or reported security breaches or violations shall be logged and tracked from initiation of the preliminary analysis to determine whether there was a security breach or violation till completion of actions taken.

(ii) Appropriate contacts with relevant authorities shall be maintained to escalate to respective authorities as required, including the local cyber cell information.

(iii) Below mentioned are the steps for handling security breach:

  • Move quickly to secure the systems and fix vulnerabilities that may have caused the breach.
  • Switch off the servers and change the access code to prevent additional data loss.
  • Mobilize the breach response team right away to prevent additional data loss.
  • Additional security required will be placed.
  • Securely delete personally identifiable information (PII) and other sensitive data when it no longer needed for business purposes.

(iv) if any security breach comes to our knowledge, then we may take all steps required to protect misuse of such information and may attempt to notify you electronically so that you can take appropriate steps.

(v) As per the Indian Computer Emergency Response Team (“CERT–In”) cyber–security directions under Section 70B (6) of the Information Technology Act, 2000 (CERT Directions), we shall report cyber incidents (as mentioned in Annexure I of the CERT Directions) within 6(six) hours of noticing such incidents or being brought to notice about such incidents. For incidents not covered herein, we shall report cyber security incidents within a reasonable time of occurrence or noticing the incident to have scope for timely action under Rule 12(1)(a) of the CERT Rules, any entity affected by cyber–security incidents should. We shall report the cyber security incidents if they arise to: CERT– In via an email (incident@cert– in.org.in), Phone (1800–11–4949) and Fax (1800–11-6969). We shall comply with the Information Technology Act 2000 and the rules thereunder with respect to the applicable cyber security standards.

10.2 RETENTION & DATA PURGING

We will only retain your personal data for as long as it is necessary for the stated purpose, taking into account also our need to answer queries or resolve problems, provide improved and new services, and comply with legal requirements under applicable laws. This means that we may retain your personal data for a reasonable period after your last interaction with us. Kindly note that we do not sell your personal data to any third party and the use of your personal data is strictly restricted to the services provided by us, as mentioned herein. Your data will be stored in our systems in

accordance with the Information Technology Act, 2000, Rule 3(h) of the Intermediary Rules and the IT RSP Rules (“IT RSP Rules”).

When there is no longer a business, legal, or regulatory requirement to keep the data, then the data will be purged in a secure manner.

Data Destruction Protocol: All the data, including all the copies thereof will be destroyed post the completion of the business, legal or regulatory requirement. In case the data are stored in physical form, that is, CDs, DVDs, Pen Drive, tapes, etc., then the physical device storage shall be destroyed. In case the data are stored in digital form, then secure erasure of individual folders and/or files will be done.

11. YOUR RIGHTS

As per the applicable data protection law, your principal rights are as follows. Please read this in in conjunction with the Policy, specifically Clause 4.1:

Right to withdraw consent: You have the option, at any time while availing our Services or otherwise, to withdraw your consent given to us, for processing your data. In case of withdrawal of your consent, we reserve the option not to provide the Services for which such information was sought. In case the Services are already availed and then you raise a request to withdraw consent, then we have the right to retain to stop the provision of the Services.

You have the right to exercise any of the above rights by contacting our Data Protection Officer(“DPO”) as mentioned under Clause 9 of this Policy. Once we receive your request and verify the same satisfactorily, we shall proceed with assisting you on your request.

12. APPLICABLE LAWS & DISPUTE RESOLUTION

Any controversy or claim arising out of or relating to this policy shall be decided by Arbitration in accordance with the Arbitration and Conciliation Act 1996 and the governing law shall be the laws of India. The Arbitral Tribunal shall consist of one arbitrator who shall be appointed in accordance with the Arbitration and Conciliation Act 1996.Any such controversy or claim shall be arbitrated on an individual basis and shall not be consolidated in any arbitration with any claim or controversy of any other party. Any other dispute or disagreement of a legal nature will also be decided in accordance with the laws of India, and the Courts at Chennai shall have exclusive jurisdiction in all such cases, subject to the foregoing.

13. REGULAR REVIEW OF PRIVACY POLICY

We keep our Policy under regular review and may update the same to reflect changes to our information related practices. We encourage you to periodically review this page for the latest information on our privacy practices, your continued use and access of our platform will be taken as acceptance of the updated policy