Privacy Policy
CopperHive Technologies Private Limited
1. Introduction and Scope
CopperHive Technologies Private Limited ("CopperHive", "AlphaRupee", "Company", "we", "us", or "our") owns and operates the digital platform, mobile application and website branded as "AlphaRupee" (collectively, the "Platform"). CopperHive functions as a Lending Service Provider ("LSP") in accordance with the Reserve Bank of India's ("RBI") Guidelines on Digital Lending and related circulars issued from time to time ("RBI Digital Lending Guidelines"), and provides loan sourcing, origination-support, servicing, collection and other associated technology and support services to Non-Banking Financial Companies (each, a "Lender" or "RE", collectively "Partner Lenders") on the Platform.
This Privacy Policy ("Policy") explains how we collect, use, store, process, share, and protect the Personal Data of individuals who visit, register on, or transact through the Platform ("you", "your", "User", or "Data Principal"), and describes the rights available to you under applicable law. This Policy applies to prospective borrowers, borrowers, guarantors, co-applicants, authorised representatives, and any other individual whose Personal Data is processed by us in connection with the Platform.
This Policy is published in compliance with, inter alia: (a) the Digital Personal Data Protection Act, 2023 and rules framed thereunder ("DPDPA"); (b) the Information Technology Act, 2000, and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"); (c) the RBI Digital Lending Guidelines, including Chapter III (Digital Lending) of the Reserve Bank of India (Non-Banking Financial Companies – Credit Facilities) Directions, 2025 and the Reserve Bank of India (Non-Banking Financial Companies – Responsible Business Conduct) Directions, 2025 ("RBI RBC Directions"), as applicable to Partner Lenders and, by extension, to us as their LSP; (d) the RBI Master Direction on Credit Information Companies and applicable credit bureau reporting norms; and (e) other applicable Indian laws, rules, and regulatory guidance as may be amended or replaced from time to time (collectively, "Applicable Law"). Terms not defined herein shall have the meaning assigned to them under the DPDPA and Applicable Law.
2. Our Role: LSP, Data Fiduciary and Data Processor
In line with the RBI Digital Lending Guidelines, all loans sourced through the Platform are ultimately sanctioned, funded, and disbursed by a Partner Lender. CopperHive, as LSP, undertakes customer acquisition, credit-assessment support, disbursement facilitation, servicing, recovery/collection support, and related technology functions on behalf of, and under agreement with, the relevant Partner Lender.
Depending on the specific activity and the terms of our agreement with the relevant Partner Lender:
- CopperHive acts as a "Data Fiduciary" under the DPDPA in respect of Personal Data collected directly through the Platform for its own permitted business purposes (e.g., platform registration, analytics, fraud checks, marketing where consented); and
- CopperHive acts as a "Data Processor"/processor on behalf of the Partner Lender (who remains the Data Fiduciary) in respect of Personal Data processed strictly for loan origination, underwriting, disbursement, servicing and collection on the Partner Lender's instructions.
Where CopperHive processes Personal Data as a processor for a Partner Lender, such processing is governed by a data processing/outsourcing agreement between CopperHive and the relevant Partner Lender, which requires CopperHive to process Personal Data strictly in accordance with the Partner Lender's instructions and Applicable Law, including confidentiality and data security obligations no less stringent than those undertaken by the Partner Lender towards its regulator.
The name(s) of the Partner Lender(s) associated with a specific loan product, and the applicable Key Fact Statement ("KFS"), are disclosed to you prior to execution of the loan agreement, in accordance with the RBI Digital Lending Guidelines.
3. Personal Data We Collect
We collect only such Personal Data as is necessary for the specified and lawful purposes set out in this Policy, in a need-based and data-minimised manner consistent with the RBI Digital Lending Guidelines. The exact fields, documents, and data points collected may vary depending on the specific product, feature, or stage of your engagement with the Platform (for example, registration, application, verification, disbursement, or servicing), and are disclosed to you at the relevant point of collection, through in-app notices, consent screens, permission prompts, and/or the Key Fact Statement, as applicable. Without limiting the generality of the foregoing, such Personal Data may broadly fall within one or more of the following categories:
3.1 Identity and Contact Information
Information that identifies you or enables us to contact or verify you, such as your name, demographic details, contact details, address, and government-issued identity or address-proof documents accepted under Applicable Law, including any identifiers derived therefrom through permitted verification channels.
3.2 Financial and Credit Information
Information relating to your financial position and creditworthiness, such as income, employment/business details, bank account and transaction information, existing credit obligations, and credit history/credit score obtained from Credit Information Companies or other permitted sources, with your consent, together with your application, repayment, and transaction history on the Platform.
3.3 Technical, Device, and Usage Information
Information generated through your use of the Platform, such as device and connection identifiers, log and diagnostic data, application usage and analytics data, and, only where you have given explicit, purpose-specific consent, location or other device-permission-based data, used for purposes such as security, fraud prevention, and service delivery.
3.4 Sensitive Personal Data or Information ("SPDI")
Where any of the above, or other information collected, constitutes "sensitive personal data or information" under the SPDI Rules (such as financial information, or biometric information used solely through UIDAI or other authorised e-KYC/e-sign channels), such information is collected only with your explicit consent, used strictly for the purpose disclosed at the time of collection, and afforded the enhanced security safeguards described in Clause 10.
3.5 Device Permissions and Access
Consistent with the RBI Digital Lending Guidelines, we seek access to information or functionality on your device (such as any permission classified as sensitive by your device's operating system) only where strictly necessary for a specific, disclosed purpose, and only after you have granted a one-time, purpose-specific, revocable consent through your device's permission settings. In particular, our Platform does not accesses your device's file and media storage, contact list, call logs, or telephony functions. A one-time, purpose-specific, revocable consent may be sought only for your camera, microphone, location, or such other facility as is strictly necessary for on-boarding or KYC verification, in accordance with the RBI Digital Lending Guidelines. You may decline or withdraw any such permission at any time through your device settings, subject to the consequence that certain Platform features may not function without it. The specific permissions sought by the Platform, and the purpose of each, are disclosed to you within the app at the time such permission is requested.
4. How We Collect Personal Data
- Directly from you, when you register on the Platform, complete a loan application, upload KYC documents, communicate with our customer support, or respond to surveys.
- Automatically, through cookies, SDKs, and similar tracking technologies when you use the Platform.
- From third parties, including CICs, KYC Registration Agencies, Account Aggregators (with your explicit consent under the Account Aggregator framework), fraud-check and verification service providers, and Partner Lenders, strictly for the purposes described in this Policy.
- From publicly available sources, such as statutory registries, solely to the extent permitted by Applicable Law and necessary for verification or fraud-prevention purposes.
5. Purposes for Which We Use Your Personal Data
We process your Personal Data only for specified, lawful purposes for which you have given consent, or which are otherwise permitted under the DPDPA (such as compliance with a legal obligation), including to:
- Verify your identity and perform KYC/AML checks in accordance with RBI and Prevention of Money Laundering Act requirements;
- Assess your loan eligibility, creditworthiness, and facilitate underwriting decisions of Partner Lenders;
- Facilitate loan disbursement, servicing, repayment collection, and recovery on behalf of Partner Lenders;
- Generate and share the Key Fact Statement, loan agreement, and related disclosures;
- Report to and obtain information from Credit Information Companies;
- Detect, prevent, and investigate fraud, security incidents, or Platform misuse;
- Comply with Applicable Law, respond to regulatory or judicial requests, and maintain statutory records;
- Provide customer support and respond to grievances;
- Improve and personalise the Platform, subject to your consent for non-essential analytics or marketing communications; and
- Send transactional and, where separately consented, promotional communications (you may opt out of promotional communications at any time).
6. Consent and Lawful Basis for Processing
Where our processing of your Personal Data relies on your consent, such consent shall be free, specific, informed, unconditional, and unambiguous, communicated through a clear affirmative action, in accordance with Section 6 of the DPDPA. Requests for consent are accompanied by, or provided along with, an itemised notice describing the Personal Data sought and the purpose of processing, in clear and plain language. Such notice will also inform you of the manner in which you may exercise your right to withdraw consent under this Clause 6 and your rights under Clause 11 and Clause 13 of this Policy, and the manner in which you may make a complaint to the Data Protection Board of India, in accordance with Section 5(1) of the DPDPA. You will also be given the option to access such notice, and any request for consent, in English or in any language specified in the Eighth Schedule to the Constitution of India, through the Platform's language-selection settings, in accordance with Sections 5(3) and 6(3) of the DPDPA.
You have the right to withdraw consent at any time, with the ease of withdrawal being comparable to the ease with which consent was given. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to withdrawal, and, where applicable, may result in our inability to continue providing the relevant service (for example, an active loan cannot be serviced without continued processing of repayment-related data).
Where processing is necessary for compliance with a legal obligation (e.g., reporting to CICs or regulators), for performance of a contract to which you are a party, or falls within the "legitimate uses" recognised under Section 7 of the DPDPA, we may process Personal Data without seeking fresh consent, to the extent permitted by Applicable Law. In addition, where you have defaulted in repayment of a loan, we may process your Personal Data (including to ascertain your financial information, assets, and liabilities) for the purpose of recovery and collections, in accordance with Section 17(1)(f) of the DPDPA read with the Insolvency and Bankruptcy Code, 2016, and Applicable Law, regardless of whether consent for such processing has been withdrawn.
7. Sharing and Disclosure of Personal Data
We do not sell your Personal Data. We may share Personal Data, on a need-to-know basis and under appropriate contractual safeguards, with the following categories of recipients:
Any third party engaged by us to process Personal Data on our behalf is bound by written data processing terms requiring confidentiality, purpose limitation, and security measures at least as stringent as those described in this Policy. We do not permit our technology service providers or lending partners to store borrower data on servers located outside India, except where such cross-border processing is expressly permitted under Applicable Law and subject to Clause 9.
7.1 Illustrative Technology and Service Partners
Without limiting the general categories described above, and by way of illustration only, we engage specialised technology and service partners for specific, limited functions in connection with loan applications sourced, processed, or facilitated through the Platform for our Partner Lenders. As on the date of this Policy, these include:
Each such partner is engaged strictly for the limited purpose(s) indicated above, under a written agreement that imposes confidentiality, purpose-limitation, data-security, and (where applicable) data-localisation obligations consistent with this Policy and Applicable Law, and is permitted to process Personal Data solely on our instructions (or, as applicable, on the instructions of the relevant Partner Lender) and not for its own independent purposes.
7.2 Data Accuracy and Quality
Where Personal Data processed by us is likely to be used to make a decision that affects you (such as a credit or underwriting decision) or is likely to be disclosed to a Partner Lender or other Data Fiduciary, we take reasonable steps to ensure that such Personal Data is complete, accurate, and consistent, in accordance with Section 8(3) of the DPDPA. You are requested to promptly inform us of any inaccuracy in, or change to, your Personal Data (such as updated contact details, income, or employment information), so that we may correct our records and those shared with the relevant Partner Lender accordingly.
8. Data Storage, Retention, and Localisation
We retain Personal Data only for as long as is necessary to fulfil the purposes described in this Policy, to comply with our legal, regulatory, and contractual obligations (including RBI-mandated record retention periods and limitation periods under applicable statutes), or as otherwise required to establish, exercise, or defend legal claims. On expiry of the applicable retention period, and absent a legal requirement to retain the data, we will erase or anonymise the Personal Data, or notify you that the specified purpose is no longer being served and provide an opportunity to withdraw consent, as required under the DPDPA.
Personal Data collected in connection with loans is primarily stored on servers located within India. Any storage or processing of Personal Data outside India is undertaken only where permitted under Applicable Law, including RBI's data localisation requirements applicable to payment and financial data, and subject to contractual and technical safeguards no less protective than those applicable within India. Where any Personal Data is processed outside India in such permitted circumstances, it shall be deleted from the servers located outside India and brought back to India within 24 (twenty-four) hours of completion of such processing, in accordance with the RBI Digital Lending Guidelines.
9. Cross-Border Transfer of Personal Data
Where permitted under the DPDPA and other Applicable Law, we may transfer Personal Data outside India to group entities, service providers, or other recipients, provided that such transfer is not to a country or territory restricted by the Central Government, and is subject to contractual safeguards ensuring a standard of protection substantially equivalent to that provided under this Policy and Applicable Law.
10. Data Security Measures
We implement reasonable security practices and procedures, as contemplated under Section 43A of the Information Technology Act, 2000 and the SPDI Rules, and reasonable security safeguards under Section 8(5) of the DPDPA, to protect Personal Data against unauthorised access, disclosure, alteration, or destruction. These measures include, without limitation:
- Encryption of data in transit and at rest, using industry-standard protocols;
- Role-based access controls and multi-factor authentication for internal systems;
- Periodic vulnerability assessments, penetration testing, and security audits;
- Secure application development practices and regular patching of systems;
- Contractual data-protection obligations imposed on vendors, processors, and Partner Lenders; and
- An incident response plan for detection, containment, and notification of personal data breaches.
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals in the manner and within the timelines prescribed under the DPDPA, and will cooperate with Partner Lenders and regulators as required under Applicable Law and our contractual arrangements.
11. Your Rights Under the DPDPA
Subject to the exemptions and conditions prescribed under the DPDPA, you have the following rights in respect of your Personal Data processed by us as Data Fiduciary:
11.1 Right to Access Information
You may request a summary of the Personal Data we hold about you, the processing activities undertaken, and the identities of all other Data Fiduciaries and Data Processors with whom such data has been shared, along with a description of the data so shared.
11.2 Right to Correction and Erasure
You may request correction of inaccurate or misleading Personal Data, completion of incomplete Personal Data, updating of Personal Data, and erasure of Personal Data that is no longer necessary for the purpose for which it was processed, unless retention is required under Applicable Law.
11.3 Right to Grievance Redressal
You have the right to have readily available means to register a grievance with us, and to escalate the same in accordance with Clause 13 of this Policy.
11.4 Right to Nominate
You may nominate another individual to exercise your rights under the DPDPA in the event of your death or incapacity, in the manner prescribed under Applicable Law.
11.5 Right to Withdraw Consent
You may withdraw consent previously granted, as described in Clause 6, without affecting the lawfulness of prior processing.
You may exercise the above rights by writing to our Grievance Redressal Officer/Data Protection Officer at the contact details provided in Clause 14. We will endeavour to respond to verified requests within the timelines prescribed under Applicable Law.
12. Cookies and Tracking Technologies
The Platform uses cookies, SDKs, pixels, and similar technologies to enable core functionality, remember preferences, perform analytics, and, where you consent, deliver personalised content. You may control or disable non-essential cookies through your browser or device settings; disabling certain cookies may affect Platform functionality. Essential cookies necessary for security, fraud prevention, and core loan-servicing functions cannot be disabled.
13. Grievance Redressal Mechanism
In accordance with the Information Technology Act, 2000, the DPDPA, and the RBI Digital Lending Guidelines, we have appointed a Grievance Redressal Officer (who may also serve as our Data Protection Officer, as applicable) to address your queries and grievances relating to the processing of your Personal Data. Consistent with the institutional-framework requirements under the RBI RBC Directions, our grievance redressal mechanism ensures that disputes are heard and disposed of at, at least, the next higher level of management.
We will acknowledge and address grievances within the timelines prescribed under Applicable Law. If you are not satisfied with the resolution provided, you may escalate the grievance to the Nodal Grievance Redressal Officer of the relevant Partner Lender, and thereafter, if unresolved, to the RBI through the channels indicated in the applicable Key Fact Statement. You agree to first exhaust the grievance redressal mechanism set out in this Clause 13 before approaching the Data Protection Board of India in respect of any grievance relating to your Personal Data, in accordance with Section 13(3) of the DPDPA.
14. Contact Us
For any questions, clarifications, or requests relating to this Policy or the processing of your Personal Data, please contact us at:
CopperHive Technologies Private Limited
Corporate Office: 02A-116, WeWork Vista Earth Centre, EPIP Zone, Whitefield Road, Bengaluru 560048, India
Email: [email protected]
15. Children's Personal Data
The Platform and its lending products are intended solely for individuals who are at least 18 (eighteen) years of age and competent to contract under the Indian Contract Act, 1872. We do not knowingly collect Personal Data of any individual below 18 years of age. If we become aware that we have inadvertently collected Personal Data of a minor without verifiable parental/guardian consent, we will take steps to delete such data promptly, in accordance with Section 9 of the DPDPA.
16. Third-Party Links and Services
The Platform may contain links to third-party websites, applications, or services (including Partner Lender portals, payment gateways, or Account Aggregator interfaces) that are not owned or controlled by us. This Policy does not apply to such third-party platforms, and we encourage you to review their respective privacy policies before sharing any Personal Data with them.
17. Amendments to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, legal or regulatory requirements. The updated Policy will be posted on the Platform with a revised "Last Reviewed" date, and, where the changes are material, we will notify you through the Platform, email, SMS, or other appropriate means, and, where required under Applicable Law, seek your fresh consent before continuing to process your Personal Data under the revised Policy. Your continued use of the Platform after such notice constitutes acceptance of the updated Policy, save where fresh consent is legally required.
18. Governing Law and Jurisdiction
This Policy shall be governed by and construed in accordance with the laws of India. Subject to the dispute resolution/arbitration provisions, if any, contained in your loan agreement with the relevant Partner Lender, the courts at Bangalore shall have exclusive jurisdiction over any disputes arising out of or in connection with this Policy.