This Privacy Policy explains how Sunby Credtech Private Limited collects, uses, stores, shares, and protects your Personal Data when you access the Cred2Tech Platform, in compliance with the Digital Personal Data Protection Act, 2023.
This Privacy Policy ("Policy") is issued by Sunby Credtech Private Limited ("Cred2Tech", "we", "us", or "our"), a company incorporated under the laws of India, and governs the collection, use, storage, sharing, and protection of your Personal Data when you access or use our website at www.cred2tech.com ("Website") and the services offered through our platform ("Platform" or "Services").
This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023("DPDP Act" or "Act"), which received the assent of the President of India on 11 August 2023. The core operative provisions of the Act, including Chapters II and III governing Data Fiduciary obligations and Data Principal rights respectively, came into force eighteen months from 13 November 2025.
Cred2Tech operates as a Data Fiduciarywithin the meaning of Section 2(i) of the DPDP Act, determining the purpose and means of processing of Personal Data of its users ("Data Principals"). By accessing or using the Platform, you acknowledge and accept the practices described in this Policy.
The following describes the data collection journey as it occurs within the Cred2Tech Platform, based on the Platform's user interface and workflow. Personal Data is collected at each of the following touchpoints in four different scenarios as described below:
For the purposes of this Policy, the following terms shall have the meanings assigned to them below, consistent with the definitions under the DPDP Act:
In compliance with Section 5 of the DPDP Act, this Policy, and any consent request made to you on the Platform, constitutes the statutory notice informing you of:
This notice is made available in English. This Policy and all notices under the DPDP Act are provided in English only.
We collect Personal Data only to the extent necessary for the Specified Purpose, in accordance with the principle of data minimisation under the DPDP Act. The categories of Personal Data collected are set out below, organised by the point at which they are collected in the Platform workflow:
We may collect information from third-party service providers, financial institutions, credit bureaus, KYC verification agencies, and publicly available sources (e.g., GST portal, MCA portal) to support verification, analysis, and eligibility assessment.
By accepting the Terms of Use and this Policy at the time of registration or login, you provide your consent for Cred2Tech to persistently store the data you enter into application forms, draft loan applications, or scheme-related application fields, for the Specified Purposes disclosed in this Policy. A separate, stage-wise on-screen consent is not required for each instance of such storage (such as saving your profile, saving a scheme, or submitting an application); this Clause V constitutes the operative consent for such storage.
No mobile device resources such as contacts, call logs, media, or local files are accessed or stored by Cred2Tech.
Cred2Tech processes your Personal Data only on the lawful grounds specified under Section 4 of the DPDP Act โ i.e., (a) based on your consent, or (b) for certain legitimate uses under Section 7 of the DPDP Act.
| Purpose of Processing | Legal Ground Under DPDP Act | Data Categories Used |
|---|---|---|
| Mobile number OTP verification and user authentication | Consent (Section 6) | Mobile number, OTP data, device information |
| PAN-based identity and business detail verification | Consent (Section 6) | PAN, auto-filled legal name, GSTIN, state, constitution |
| AI-powered government scheme eligibility matching | Consent (Section 6); Certain Legitimate Uses โ Section 7(b) (State subsidy/benefit facilitation) | All eligibility and socio-economic profile data (Category C above) |
| Payment processing for unlocking scheme eligibility reports | Consent (Section 6); Performance of contract | Payment data |
| KYC completion and onboarding for credit/loan applications (where you choose to apply) | Consent (Section 6); Legal obligation (Section 7(d)) | PAN, KYC documents, application data expressly submitted by you |
| Credit appraisal, Bureau Soft pull, Loan Information Summary report generation, loan eligibility assessment | Consent (Section 6) | Financial statements, ITR, GSTR-3B, bank statements |
| Sharing with lending partners (Banks, NBFCs) for loan processing | Explicit Consent (Section 6); Section 7(f) (default-related processing, where applicable) | Financial and credit data, KYC documents, CAM reports, application data specifically consented to be shared |
| Fraud prevention and platform security | Legitimate use (Section 7(i)); Consent | Device data, usage data, identity data |
| Legal and regulatory compliance (KYC/AML obligations) | Legal obligation (Section 7(d)) | Identity, KYC, and financial data |
| Service communications, alerts, and account notifications | Consent (Section 6) | Mobile number, email address |
| Analytics and product improvement | Consent (Section 6) | Usage data, technical data, anonymised data |
We do not use your Personal Data for any purpose incompatible with the Specified Purpose notified to you at the time of collection, without obtaining fresh, specific consent.
In accordance with Section 6 of the DPDP Act, consent obtained by Cred2Tech from you is:
In particular, by accepting the Terms of Use and this Policy at the time of registration or login, you provide your consent to the persistent storage of data that you enter in application forms, draft applications, or scheme-related workflows, for the purposes disclosed in this Policy; a separate, stage-wise on-screen consent is not required for each such instance of storage.
Consent requests are presented to you in clear and plain language, in English only.
You have the right to withdraw your consent at any time, with the same ease as it was given, in accordance with Section 6(4) of the DPDP Act. Upon withdrawal:
To withdraw consent, contact our Grievance Officer at the details set out in Clause XIII.
As a Data Principal under Chapter III of the DPDP Act, you have the following rights in respect of your Personal Data processed by Cred2Tech:
To exercise any of the above rights, please contact our Grievance Officer as detailed in Clause XIII. Requests will be processed within the timeline mandated by the DPDP Rules, 2025 (maximum 90 days). Identity verification may be required before processing such requests.
As a Data Principal, you are also obligated under Section 15 of the DPDP Act to: not impersonate another person when providing Personal Data; not suppress material information while providing data for identification purposes; not register false or frivolous grievances; and furnish only verifiably authentic information when exercising the right to correction or erasure.
In accordance with Section 8(7) of the DPDP Act, Cred2Tech shall erase your Personal Data:
The Specified Purpose shall be deemed to no longer be served if you have not approached Cred2Tech for performance of the Specified Purpose and have not exercised any rights in relation to such processing, for such time period as may be prescribed under the rules made under the DPDP Act.
In the context of application data, this means that where you have not specifically consented to ongoing storage of application-related information (for example, by saving your application or agreeing to have it shared with a lending partner), such information will not be retained beyond the limited period necessary to complete the immediate, session-based functionality requested by you.
Where retention is required under applicable legal or regulatory obligations โ such as KYC/AML requirements, RBI-mandated retention of financial records, or other statutory obligations โ your Personal Data will be retained only for the mandated duration.
Upon expiry of the retention period, Personal Data will be securely deleted or anonymised in accordance with applicable legal and security standards. Cred2Tech shall also cause its Data Processors to erase any Personal Data made available to them for processing.
Cred2Tech implements appropriate technical and organisational security measures in accordance with Section 8(4) and Section 8(5) of the DPDP Act to protect your Personal Data against unauthorised access, alteration, disclosure, or destruction. These measures include:
In the event of a Personal Data Breach, Cred2Tech shall, in accordance with Section 8(6) of the DPDP Act, give the Data Protection Board of India and each affected Data Principal intimation of such breach in the form and manner as may be prescribed. Without prejudice to the generality of the foregoing, and in accordance with the DPDP Rules, 2025, Cred2Tech shall: (i) intimate the Data Protection Board of India within seventy-two (72) hours of becoming aware of the Personal Data Breach (or such extended period as the Board may allow); and (ii) without delay, inform each affected Data Principal of the breach, describing its nature, likely consequences, the measures taken to mitigate the risk, and the safety measures such Data Principal may adopt.
While we take commercially reasonable measures to safeguard your Personal Data, no system or network is completely secure, and we cannot guarantee absolute security.
The Platform is not intended for individuals under the age of 18 years, consistent with the definition of "child" under Section 2(f) of the DPDP Act. We do not knowingly collect Personal Data from children without verifiable parental or guardian consent, as required under Section 9(1) of the DPDP Act. We rely on self-declaration of age at the point of registration as a reasonable measure to ascertain that you are not a child, in accordance with the DPDP Rules, 2025.
We do not undertake tracking or behavioural monitoring of children or targeted advertising directed at children, in accordance with Section 9(3) of the DPDP Act. If we become aware that Personal Data of a child has been collected without verifiable parental consent, we will take immediate steps to delete such data. The penalty for breach of obligations relating to children shall be as applicable under, and to the extent prescribed by, the DPDP Act and the rules made thereunder, as amended from time to time.
In accordance with Section 16 of the DPDP Act, Cred2Tech shall not transfer Personal Data to any country or territory outside India that may be restricted by notification of the Central Government under Section 16(1). Any cross-border transfer of Personal Data shall be conducted only in compliance with applicable Indian law and any additional restrictions that may be imposed by the Central Government.
In accordance with Section 8(10) of the DPDP Act and Section 13 of the DPDP Act, Cred2Tech has established an effective mechanism to redress the grievances of Data Principals.
If you have any questions, concerns, or complaints regarding this Policy or the processing of your Personal Data, you may contact our Grievance Officer:
We will acknowledge and address your grievance within the timeline prescribed under applicable rules made under the DPDP Act. You must exhaust this grievance mechanism before approaching the Data Protection Board of India under Section 13(3) of the DPDP Act.
You may also approach the Data Protection Board of India (to be notified under Section 18 of the DPDP Act) for complaints in the event of a breach in observance by Cred2Tech of its obligations under the DPDP Act.
This Policy shall be governed by and construed in accordance with the laws of India, including the DPDP Act. Subject to applicable law, and without prejudice to the jurisdiction of the Data Protection Board of India, the courts at Bengaluru shall have exclusive jurisdiction over any civil disputes arising out of or relating to this Policy.
Notwithstanding the above, the Data Protection Board of India, constituted under Section 18 of the DPDP Act, shall have jurisdiction over matters falling under the DPDP Act, and no civil court shall entertain any suit or proceeding in respect of any matter for which the Board is empowered, in accordance with Section 39 of the DPDP Act.
We may update this Policy from time to time to reflect changes in legal, regulatory, technical, or business requirements. Where required under applicable law, we will provide notice of material changes through the Platform or through a notice served to you in accordance with Section 5 of the DPDP Act. Continued use of the Platform after such updates become effective constitutes your acknowledgement of the revised Policy.
By providing your Personal Data and using the Platform, you acknowledge and declare that:
In addition to the DPDP Act, the processing of your Personal Data on the Platform is also subject to the following sector-specific laws and regulations, to the extent applicable:
Questions about this document? Reach our Grievance Officer at contact@cred2tech.com.