Data Privacy Policy

1. Privacy Commitment

The Policy is in compliance with the Information Technology (Reasonable security practices and procedures and sensitive personal data or information) Rules 2011 (the "IT Rules") contained in the Information Technology Act 2000.

2. Definitions

(i) Personally identifiable information (PII)

"Personally identifiable information" (PI) means any information that relates to a natural person, which either directly or indirectly, in combination with other information available or likely to be available with the Bank, is capable of identifying such person.

Some examples of PII are

a. Name

b. Date of birth

c. Gender.

d. Bank account or credit card number.

(ii) Sensitive personal data or information (SPDI)

"Sensitive personal data or information" (SPDI) of a person means such personal information, which consists of information relating to:

a. Password;

b. Financial information such as Bank account or credit card or debit card or other payment instrument details;

c. Physical, physiological and mental health condition;

d. Sexual orientation;

e. Medical records & history;

f. Biometric information;

g. Any detail relating to the above clauses as provided to body corporate for providing service;

h. Any of the information received under above clauses by body corporate for processing, stored or processed under lawful contract or otherwise.

Provided that, any information that is freely available or accessible in public domain or furnished under any law for the time being in force shall not be regarded as sensitive personal data or information for the purposes of this policy.

3.Applicability of the Policy

This Policy is applicable to the personal information and sensitive personal data or information collected by the Bank or its affiliates directly from the customer or through the Bank's online portals, mobile apps and electronic communications as also any information collected by the Bank's server from the customer's browser.

4. Accuracy

The Bank shall have processes in place to ensure that the personal information residing with it is complete, accurate and current. If at any point of time, there is a reason to believe that personal information residing with the Bank is incorrect, the customer may inform the Bank in this regard. The Bank shall correct the erroneous information as quickly as possible.

5.Purpose of Collection and Use of Personal Information/ Sensitive Personal Data or Information

The Bank collects the PI and SPDI from its customers via direct interactions, automated technologies and third parties. The Bank uses the same for specific business purposes or for other related purposes designated by the Bank or for a lawful purpose to comply with the applicable laws and regulations. The Bank does not store/ collect any biometric data unless allowed under extant statutory guidelines. The Bank shall not divulge any personal information collected from the customer, for cross selling or any other purposes, without the consent of the customer. If a customer does not wish to provide consent for usage of its sensitive personal data or information or later withdraws the consent, the Bank shall have the right not to provide services or to withdraw the services for which the information was sought from the customer.

The Bank complies with all applicable regulatory guidelines. The Bank may store the Data on its systems or with third parties in servers located within India for as long as required or even beyond the expiry of transactional or account-based relationship with the customer:

a. as required to comply with any legal and regulatory obligations to which we are subject, or

b. for establishment, exercise or defence of legal claims, or

c. In accordance with specific consents. For further information on data retention, please refer to ‘Record Management Policy’ available on the website of the Bank. Customer can update all or specific details previously provided at any time by contacting his/her nearest branch of the Bank.

6. Disclosure of Personal Information

The Bank limits the collection and use of Customer Information on need-to-know basis to deliver better services to its customers. The Bank may share or store customer data with third parties. These third parties may include Bank’s affiliates, service providers, vendors, and partners. The data sharing and storage will be subject to suitable confidentiality obligations, and in accordance with contractual terms and applicable laws. The personal information collected by the Bank shall not be disclosed to any other organization except:

a. Where the disclosure has been agreed in a written contract or otherwise between the Bank and the customer;

b. Where the Bank is required to disclose the personal information to an affiliate/ third party/ service provider on a need-to-know basis, for providing services/ related activities, provided that in such case the Bank shall inform such affiliate/ third party / service provider of the confidential nature of the personal information and shall keep the same standards of information/ data security as that of the Bank.

c. To statutory and regulatory authorities on their specific request as per rules in force.

7. Type of user data collected and their purpose

All the below permissions are used when Utkarsh Small Finance Bank Digital Platforms is in usage (foreground).

a. SMS - Collect this permission to send and view messages to verify your registered mobile number and SIM card for meeting the mandatorily required provision by Reserve Bank of India (RBI) rules for Mobile Banking receive via SMS on your device. We collect and monitor only financial transactional SMS initiated by Utkarsh Bank for description of the transactions and the corresponding amounts.

b. Location - Collect and monitor information about the location of your device, to offer you customized products and services.

c. Phone - Collect and monitor specific information about your device including your hardware model operating system and version, serial number, user profile information, wi-fi information, and mobile network information to uniquely identify the devices and ensure that unauthorized devices are not able to act on your behalf to prevent frauds.

8. Reasonable Security Practices and Procedures

The Bank is ISO 27001:2022 certified. The security of personal information is a priority and is protected by maintaining physical, electronic and procedural safeguards that meet applicable laws. The Bank shall take reasonable steps and measures to protect the security of the customer’s personal information from misuse and loss, un-authorized access, modification or disclosure. The Bank maintains its security systems to ensure that the personal information of the customer is appropriately protected and follows the extant standard protection norms followed for the transmission of information. The Bank follows a Board approved policy for handling security incidents. The same is designed to align with the bank’s regulatory obligations, internal governance policies, and widely recognized industry best practices & standards.

9. Cookie Policy

The Bank’s digital platforms may use various third-party analytical tools. These tools may use cookies, which are downloaded to the customer’s device when the customer visits a website in order to provide a personalized browsing experience. Cookies are used for other purposes like remembering the customer’s preferences & settings, provide personalized browsing experience and analyze site operations. These cookies collect information about how users use a website. By using the Bank’s website, the user agrees that these types of cookies can be placed on his/ her device. User is free to disable/ delete these cookies by changing his/ her device/ browser settings. The Bank is not responsible for cookies placed in the device of user/s by any other website and information collected thereto.

10. Social Media

Social media applications/ sites are owned by third parties unaffiliated with the Bank. The customers may independently be guided by their privacy policies and Bank has no control over them. The Bank is not responsible for the privacy or security at these applications/ sites or other third-party sites that may be linked to/ from within our social media channels. The Bank does not endorse and is not responsible for any content, products, ads, advice, recommendations, opinions or other material of third-party sites that may be promoted via advertising within any social media properties.

11. Grievance Redressal

In order to address any discrepancies or grievances related to the personal information residing with the Bank, the customer may visit: Grievance Redressal on the official website of the Bank.

12. Confidentiality

This document is the sole property of USFBL. Any use or duplication of this document without express permission of USFBL is strictly forbidden and illegal.

13. Review of the Policy

This policy would be reviewed annually taking into account the various amendments to guidelines and regulations (if any), Business models and would be placed to the Board for their approval

go-to-top

TOP