Back
LEGAL DOCUMENT

KammaCash Privacy Policy

Effective Date: July 10, 2026

KammaCash Privacy Policy

Effective Date: July 10, 2026

Chapter 1: Introduction and Overview

1.1 About This Policy

Welcome to KammaCash! This Privacy Policy (hereinafter referred to as the "Policy") is formulated by KAMMA SOFTWARE INNOVATIONS PRIVATE LIMITED (hereinafter referred to as the "Company," "we," or the "Platform") to explain how we collect, use, store, share, and protect your personal data.

KammaCash is a personal loan service application (hereinafter referred to as the "App"). We take your privacy very seriously and commit to processing your personal information in a transparent, lawful, and necessary manner in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) and other applicable regulations.

1.2 Scope of Application

This Policy applies to the following channels:

  • The KammaCash mobile application;
  • The official website: https://www.kammasoftware.com/;
  • Other online portals and digital interaction scenarios related to the services.

1.3 Your Consent

By using our services, you signify that you have read, understood, and accepted all the provisions of this Policy. In accordance with Section 6 of the DPDP Act, your consent must be free, specific, informed, and unambiguous. If you do not agree to any term of this Policy, please stop using the App and related services immediately.

1.4 Business Model Description

KammaCash is a financial technology service and loan distribution platform focused on providing users with information display, application facilitation, and process support services for loan products. We do not directly provide loan funds.

All loan products are offered by our partner NBFCs (Non-Banking Financial Companies) , which hold valid certificates of registration from the Reserve Bank of India (RBI) and are regulated by the RBI.

Partner Institution Information:

Partner NBFC Name: Pushpak Fincap Private Limited

CIN: U45201DL2002PTC115680

Address: 404 Pratap Chamber, Gurudwara Road, Karol Bagh, New Delhi 110005

The partner institution independently assumes the following responsibilities:

  • Loan product design, pricing, and risk management;
  • Borrower credit assessment and approval decision-making;
  • Loan fund disbursement and management;
  • Repayment processing and account maintenance;
  • Regulatory compliance and reporting.

Limitation of Liability: The Platform does not participate in credit decisions and does not assume any loan performance obligations or financial risks.

Chapter 2: Collection of Personal Data

2.1 Information You Voluntarily Provide

To complete the loan application and service matching process, you are required to provide the following categories of information:

Identity Information: Your name, date of birth, gender, PAN card number, Aadhaar number, and other government-issued valid identification document information, used to verify your true identity.

Personal Background Information: Your educational background, marital status, number of dependents, family income, email address, and mobile phone number, as well as other basic contact and social information.

Financial and Employment Information: Your income details, bank account information, occupation type, employer name, and employment details, used to assess your repayment capacity.

Loan Application Information: The loan amount you are applying for, your preferred repayment term, and other data directly related to your loan request.

2.2 Device Permissions Obtained

To ensure service security, prevent fraud, and optimize user experience, we may request the following device permissions with your explicit authorization:

Camera Permission

  • Purpose: Used for identity verification (KYC) and liveness detection to ensure account security and prevent identity impersonation or fraudulent activities;
  • Usage Scenarios: Photographing identification documents (e.g., PAN card, Aadhaar card) for identity verification; capturing user facial photos for facial comparison and liveness detection (e.g., blink and head-turn verification);
  • Data Types: Images of identification documents, user selfie photos, liveness detection footage;
  • Usage Restrictions: Used solely for identity verification and risk control purposes, not for marketing; not shared with unrelated third parties (except to NBFC partners with your authorization).

Location Permission

  • Purpose: Used for risk assessment, fraud detection, and service availability determination, ensuring that loan services are provided within legal and compliant regions;
  • Usage Scenarios: Verifying whether the user is located within permitted service areas; assisting in detecting abnormal logins or high-risk activities; used for anti-fraud model analysis;
  • Data Types: GPS precise location, network-based approximate location (IP/Wi-Fi/cell tower information);
  • Usage Restrictions: Used solely for risk control and compliance purposes; no continuous background tracking (except in necessary risk control scenarios); not used for advertising or data sale.

Contacts Permission

  • Purpose: Used to simplify contact entry during the loan application process and to assist the risk control system in authenticity verification;
  • Usage Scenarios: Users may quickly read local contacts when voluntarily selecting emergency contacts or referral contacts; risk control models analyze contact structure consistency;
  • Data Types: Contact names and phone numbers;
  • Usage Restrictions: We will not proactively contact anyone in your contacts; not used for marketing or promotion; data is encrypted and used only within the authorized scope.

Device Advertising Identifier

  • Purpose: Used for analyzing user behavior, optimizing product experience, and providing personalized recommendations and advertising effectiveness evaluation;
  • Usage Scenarios: Analyzing in-app feature usage; optimizing loan product recommendation strategies; tracking advertising conversion effectiveness;
  • Data Types: IDFA on iOS or AAID on Android;
  • Usage Restrictions: This identifier cannot directly identify an individual; it is not linked to your identification information for marketing profiling; users may disable ad tracking in system settings.

2.3 Automatically Collected Information

While you use our services, we may automatically record the following technical information:

  • Basic device information (model, operating system version, app version);
  • Log information (access time, operation path, feature click sequences);
  • Error reports and crash logs;
  • Preference settings and usage behavior data collected through cookies or similar technologies.

2.4 Information Collection by Third-Party SDKs

To ensure business security and risk control, we may use third-party SDKs for fraud risk identification. These SDKs may obtain device identifiers, network information, device type, and sensor data to construct device fingerprints and risk profiles. All third-party SDKs are used in accordance with the data minimization principle and collect information only to the extent necessary.

Chapter 3: Use of Personal Data

3.1 Core Service Purposes

We use your information solely for lawful, clear, and necessary business purposes, including:

Identity Verification and KYC: Completing the full "Know Your Customer" (KYC) process, using technical means such as document comparison, facial recognition, and liveness detection to verify your identity authenticity and effectively prevent identity impersonation risks.

Loan Application Processing: Systematically organizing your submitted application information and securely transmitting it to NBFC partners, while continuously tracking the approval progress.

Risk Assessment and Anti-Fraud: Building device fingerprints, behavioral models, and multi-dimensional correlation analysis to identify abnormal application behaviors, multiple account registrations, and potential fraud risks.

Account Management and Customer Service: Continuously maintaining the security status of your account and promptly responding to various inquiries and requests you may have during use.

Credit Assessment Assistance: With your explicit authorization, providing necessary information to NBFC partners to assist them in credit assessment and repayment capacity analysis.

3.2 Compliance and Legal Obligations

We may process your information based on the following legal or regulatory requirements:

  • Compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) and its implementing rules;
  • Fulfilling the regulatory requirements of the Reserve Bank of India (RBI) applicable to NBFC partners;
  • Responding to lawful information disclosure requests from government agencies or judicial authorities;
  • Complying with anti-money laundering laws and regulations.

3.3 Service Optimization and Product Improvement

Without identifying individuals, we may conduct the following analyses on aggregated or anonymized data:

  • Optimizing app feature interactions and operational workflows;
  • Improving system stability, loading speed, and error fixes;
  • Optimizing loan product display and recommendation strategies based on user behavioral characteristics.

3.4 Notifications and Communications

We will send the following service-related information to you via SMS, in-app notifications, email, and other means:

  • Loan application status updates (submission successful, under review, approval result, disbursement notification);
  • Repayment reminders (upcoming due date reminders, overdue notices, repayment confirmations);
  • One-Time Password (OTP) verification messages;
  • Account security notifications (login alerts, device changes);
  • Platform announcements (system maintenance, feature updates, policy changes).

3.5 Marketing and Promotions (Subject to Your Separate Consent)

With your explicit opt-in consent, we may push:

  • Information about new products, new features, or new partner institutions;
  • Limited-time offers, interest rate promotions, or user reward programs;
  • Personalized product recommendations based on your usage preferences.

You have the right to withdraw your marketing consent at any time by adjusting settings within the app, contacting customer service, or clicking the unsubscribe link. Withdrawal of marketing consent does not affect your ability to use core loan services.

In accordance with the DPDP Act, withdrawal of consent must be as easy as giving consent. We commit to processing your withdrawal request within a reasonable timeframe.

Chapter 4: Sharing and Disclosure of Personal Data

4.1 Sharing with NBFC Partners

To facilitate loan application and disbursement, we share necessary application information with the relevant NBFC partners upon your knowledge and consent, for the following purposes:

  • Credit assessment and repayment capacity analysis;
  • Loan approval decision-making;
  • Loan disbursement, account management, and repayment tracking;
  • Risk control and collections handling.

4.2 Sharing with Service Providers

We may engage third-party service providers to assist us in operating the Platform, including but not limited to:

  • Cloud infrastructure and data storage services;
  • Data analysis and statistics services;
  • Customer service systems and ticket management;
  • Security monitoring and risk control technical support.

The above service providers have access to data only to the minimum extent necessary for providing services and are contractually bound to confidentiality obligations. In accordance with the RBI guidelines on digital lending, as a Lending Service Provider (LSP), we ensure the robustness of our data privacy policy and storage systems.

4.3 Disclosure as Required by Law

We may disclose your information in accordance with the law in the following circumstances:

  • Providing credit-related information to Credit Information Companies (CICs). In accordance with the RBI (NBFC – Credit Information Reporting) Guidelines (2025), NBFCs are required to periodically submit credit data to all registered CICs;
  • When required by laws, regulations, judicial authorities, government agencies, or regulatory bodies with lawful directives;
  • When necessary to protect the personal or public safety of users or the general public;
  • In the event of major transactions such as mergers, acquisitions, or asset transfers, data may be transferred in accordance with the law (we will provide advance notice);
  • Other circumstances with your explicit authorization.

4.4 What We Commit Not to Do

  • We will not sell or rent your personal data to any third party;
  • We will not use your contacts for any form of marketing or promotion;
  • We will not push advertisements to third parties without your separate authorization;
  • We will not access your personal data without authorization.

Chapter 5: Data Storage and Security

5.1 Storage Location

Your personal information is primarily stored on servers within India and is subject to Indian law.

5.2 Security Protection Measures

We employ a multi-layered security protection system covering technology, management, and personnel to fulfill the obligation of "reasonable security safeguards" under Section 8(5) of the DPDP Act:

  • Transmission Encryption: Using TLS/SSL protocols to encrypt all network-transmitted data, ensuring information is not intercepted or tampered with during transmission.
  • Storage Encryption: Encrypting sensitive fields such as identification document numbers and bank account information at the database level.
  • Access Control: Establishing strict access control mechanisms, granting only authorized personnel in necessary positions access to user data on a minimum-necessary basis.
  • Log Retention: Retaining logs of access, modification, and deletion for at least one year in accordance with DPDP rules.
  • Regular Audits: Conducting periodic reviews of system security, data access logs, and operational activities.
  • Personnel Management: All employees sign strict confidentiality agreements and receive regular data protection and privacy security training.

5.3 Data Retention Period

We retain your data only for as long as necessary to provide services and as required by law:

  • Retaining necessary information during the existence of your account and the validity period of the loan agreement;
  • After account closure or loan repayment completion, data shall be deleted upon completion of the purpose in accordance with DPDP rules, unless legal requirements mandate extended retention;
  • After the retention period expires, data will be securely deleted or anonymized.

5.4 Personal Data Breach Response

In the event of a personal data breach, we will:

  • Report to the Data Protection Board within 72 hours of becoming aware of the breach;
  • Notify affected users without undue delay, explaining the nature of the breach, potential impact, and measures taken;
  • Cooperate with the Data Protection Board's investigation and rectification requirements in accordance with the law.

Chapter 6: Your Data Subject Rights

6.1 Overview of Rights

Under the Digital Personal Data Protection Act, 2023 (DPDP Act, 2023), as a data subject, you have the following statutory rights over your personal data:

Right to Information and Access: You have the right to know whether we hold your personal data and to access its contents, including information on data recipients, processing purposes, and methods.

Right to Consent and Withdrawal: You have the right to grant or refuse consent for data processing. You may withdraw your consent at any time, and withdrawal must be as easy as giving consent.

Right to Correction: You have the right to request correction of your personal data when it is inaccurate or outdated.

Right to Update: You may request updates to personal information that has changed (such as new address or contact details).

Right to Erasure: Under certain circumstances (e.g., data is no longer necessary, consent has been withdrawn and no other legal basis exists), you have the right to request deletion of your personal data.

Right to Complain: You have the right to lodge a complaint with the Data Protection Board if you believe your personal data has been misused or your privacy rights have been violated.

Right to Nomination: You may designate another person to exercise your data rights on your behalf (e.g., in cases of illness or other limitations).

6.2 How to Exercise Your Rights

To exercise any of the above rights, please contact us through the contact information provided in Chapter 9 of this Policy. In accordance with DPDP rules, we will respond to your request within 90 days. We may require you to provide necessary identity verification information to authenticate your identity.

6.3 Withdrawal of Consent

You have the right to withdraw specific data processing authorizations previously granted to us at any time. Such withdrawal does not affect the lawfulness of processing based on your consent before the withdrawal.

Please note that if you object to the processing of certain personal data, it may affect your application processing time and our assessment of your creditworthiness. While you still have loan obligations with us, withdrawal of consent does not relieve us of our rights and obligations to continue processing your personal data lawfully.

Chapter 7: Automated Decision-Making

7.1 Explanation of Automated Decision-Making

We and our NBFC partners may use automated systems to assess your creditworthiness, including credit scoring, behavioral analysis, and fraud risk identification. Such automated decisions are designed to improve approval efficiency and risk assessment accuracy.

7.2 Your Rights

Under the DPDP Act, you have the right to:

  • Understand the factors considered in automated decision-making;
  • Object to decisions based solely on automated processing;
  • Request human review of decisions when your application is rejected.

If you choose to opt out of automated assessment, it may affect our ability to provide loan matching services, as this is a core component of the credit decision-making process.

Chapter 8: Children's Privacy

This service is not intended for users under 18 years of age. In accordance with the DPDP Act and rules, we do not provide services to children, nor do we engage in behavioral monitoring, profiling, or targeted advertising of children.

If we discover that we have inadvertently collected personal information from a child, we will promptly delete such information.

Chapter 9: Cross-Border Data Transfer

Your personal data is stored by default within India. In accordance with the DPDP Act, should cross-border data transfer be necessary, we will ensure that:

  • Applicable legal requirements are complied with;
  • Adequate data protection measures are implemented;
  • Such transfer is conducted only when necessary and with a lawful basis.

Chapter 10: Cookies and Tracking Technologies

We use cookies for:

  • User experience optimization;
  • Risk analysis;
  • Usage behavior analysis.

You may disable cookies through your device system settings, though this may affect the user experience of certain features.

Chapter 11: Policy Updates

11.1 Right to Update

We reserve the right to revise this Privacy Policy from time to time.

11.2 Notification Methods

In the event of material changes involving changes in data processing purposes, scope of permissions, reduction of user rights, or other significant modifications, we will notify you prominently through in-app pop-ups, website announcements, or email notifications.

11.3 Effectiveness and Acceptance

Revised policies will be marked with a new effective date. Your continued use of the services constitutes your acceptance of the revised policy terms. If you do not agree to the updated terms, you may stop using the App and contact our Data Protection Officer.

Chapter 12: Contact Us

12.1 Contact Information

If you have any questions, complaints, or requests to exercise your rights regarding this Privacy Policy or data processing, please contact us through the following means:

  • Company Name: KAMMA SOFTWARE INNOVATIONS PRIVATE LIMITED
  • Application Name: KammaCash
  • Customer Support Email: info@kammasoftware.com
  • Official Website: https://www.kammasoftware.com/

Response Time: We commit to responding within a reasonable timeframe after receiving your request, typically confirming receipt within 15 working days, and completing the processing within 90 days in accordance with DPDP rules.

12.2 Complaints to the Data Protection Board

You also have the right to file a complaint directly with the Data Protection Board of India to seek remedies. The Data Protection Board is an independent body established under the DPDP Act, responsible for monitoring compliance, investigating violations, and taking corrective measures.

12.3 Grievance Mechanism

In accordance with DPDP rules, we have established a 90-day internal grievance redressal mechanism. Before lodging a complaint with the Data Protection Board, you should first seek resolution through our internal grievance channels.

Chapter 13: Governing Law and Jurisdiction

13.1 Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of India, including but not limited to:

  • The Digital Personal Data Protection Act, 2023 (DPDP Act, 2023) and the Digital Personal Data Protection Rules, 2025;
  • Relevant guidelines issued by the Reserve Bank of India (RBI), including the NBFC – Credit Facility Guidelines (2025) and the NBFC – Credit Information Reporting Guidelines (2025);
  • The Information Technology Act, 2000, and related rules.

13.2 Dispute Jurisdiction

Any dispute arising out of or in connection with this Policy shall be submitted to the exclusive jurisdiction of the courts in Delhi, India.

Chapter 14: Consent and Acknowledgment

14.1 User Consent

By using the KammaCash services and providing us with your personal data, you hereby acknowledge that you have read, understood, and agree to our use, processing, and disclosure of your personal data in accordance with this Privacy Policy.

14.2 Statement Regarding Third-Party Data Providers

If you, as a representative or agent of the Company, provide personal data of third parties (including but not limited to your emergency contacts, family members, etc.), you hereby represent and warrant that:

  • You have obtained lawful and valid consent from such third parties;
  • You have the authority to provide us with their personal data;
  • Such personal data may be used, processed, and/or disclosed in accordance with this Privacy Policy.

Version Date: July 10, 2026