Hero FinCorp Limited (“HFCL”, “we”, “us” or “our”) provides financial products and payment-related features through the Hero Digital Lending and UPI (“App”). For personal data processed through the App, HFCL acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), to the extent applicable. This Notice explains, in a standalone manner, the personal data we process, the purposes and services enabled by that processing, the parties with whom data may be shared, retention and security practices, and how you may withdraw consent, exercise your rights or raise a grievance.
This policy applies to registered and prospective users of the App, applicants, borrowers, UPI users, co-applicants, guarantors, nominees, beneficiaries and other individuals whose personal data is provided to HFCL in connection with an App journey. If you provide another person’s data, you must be authorized to do so and must make this policy available to them.
This policy should be read together with the product terms, loan documents, UPI terms, consent screens and just-in-time permission notices shown in the App. A permission request is not, by itself, consent for unrelated processing.
| Product / feature | Journey in the App | What the App enables |
|---|---|---|
| UPI | End-to-end digital | Registration, bank-account discovery/linking, device verification and binding, creation or selection of a UPI identifier / VPA, and applicable UPI payment features and transactions. |
| Personal Loan | End-to-end digital | Eligibility assessment, application, KYC and verification, credit assessment, sanction documentation, disbursement, servicing, repayment and support, as applicable. |
| Two-Wheeler Loan | Digital enquiry / lead generation only | Captures enquiry and contact details and routes the lead for follow-up. The remaining journey is assisted by a salesperson at dealership. |
| Unsecured Business Loan | Website enquiry redirection | The App redirects users to the HFCL website enquiry page for Unsecured Business Loan products. No loan application, underwriting, document collection, or loan servicing is undertaken within the App for this product. |
| Loan Against Property | Website enquiry redirection | The App redirects users to the HFCL website enquiry page for Loan Against Property products. No property documentation, KYC, underwriting, or loan processing is undertaken within the App for this product. |
| Home Loan | Website enquiry redirection | The App redirects users to the HFCL website enquiry page for Home Loan products. No application processing, property assessment, underwriting, or loan servicing is undertaken within the App for this product. |
We process only the personal data reasonably necessary for the product, feature or purpose selected by you, subject to applicable law. The data actually collected may differ by journey.
| Personal data item / category | Specified purpose | Goods, services or uses enabled |
|---|---|---|
| Name, date of birth, gender, photograph, signature, customer / application identifiers | Identify you, create and manage your profile or application, prevent duplicate or fraudulent accounts. | App registration, customer onboarding, loan or UPI journey. |
| Mobile number, email address, residential / correspondence address, communication preference | Authenticate and contact you; send service, security, regulatory and transactional communications. | Login, OTP, application updates, support, statements and alerts. |
| PAN, Aadhaar-related information where legally permitted, Officially Valid Documents, CKYC identifier, video / digital KYC records | Perform identity and address verification and meet KYC / AML obligations. | Personal Loan onboarding and any assisted loan application where KYC is required. |
| Bank account number, IFSC, account holder name, cancelled cheque, account verification result | Verify an account, disburse a loan, process repayment, refund or reconciliation. | Loan disbursement and servicing; UPI-linked bank account verification as applicable. |
| UPI ID / VPA, PSP / bank response, transaction reference, amount, beneficiary / payer details and transaction status | Initiate, route, authenticate, complete, reconcile, reverse, dispute and support UPI transactions. | UPI payments and related services. |
| Income, salary slips, bank statements, Form 16, tax returns, employment / business details, liabilities and financial statements | Assess eligibility, income sufficiency, affordability, fraud and credit risk. | Personal Loan and assisted loan underwriting. |
| Credit bureau report, credit score, repayment, overdue, default and credit behavior data | Conduct credit appraisal, risk assessment, bureau enquiry / reporting, servicing and collections. | Loan decisioning, account management and regulatory reporting. |
| Loan type, application and account number, sanctioned and disbursed amount, EMI, repayment schedule, transaction history, prepayment / foreclosure / closure records | Originate, administer, service, collect and close a loan; provide statements and customer support. | Personal Loan and assisted loan servicing. |
| Product interest, requested amount / range, city, and enquiry source | Create and route a lead and enable salesperson follow-up. | Two-Wheeler Loan enquiry; Unsecured Business Loan, Loan Against Property and Home Loan assisted journeys. |
| Property, security, ownership and valuation documents, co-applicant / guarantor data | Assess security, title, valuation, eligibility and legal enforceability. | Loan Against Property / Home Loan assisted journey, where applicable. |
| Device identifiers, operating system, app version, IP address, network information, app events, authentication and security logs | Secure the App, prevent fraud, diagnose issues, maintain audit trails and support service delivery. | All App journeys. |
| Customer service requests, complaints, call / email / chat / WhatsApp records and feedback | Respond to requests, investigate disputes, improve support and evidence instructions. | Customer service and grievance handling. |
| Marketing preferences, product interest and campaign response | Send promotional communications and personalize offers where separate consent is obtained. | Optional marketing and cross-sell. |
UPI services are available to eligible registered App users. Using UPI generally requires a bank account linked with the mobile number used on the device. UPI registration is a one-time process that follows the protocol and directions applicable to the UPI ecosystem, including requirements issued by the National Payments Corporation of India (NPCI), PSP banks and participating banks, as applicable.
The App may use mobile network access and SMS verification to verify the mobile number and device, discover or link eligible bank accounts and create or bind a UPI identifier / VPA. The precise technical flow may change to comply with applicable UPI ecosystem requirements.
| Permission / data | Status for UPI | Purpose and limitation | If permission is denied / withdrawn |
|---|---|---|---|
| SMS | Mandatory for UPI onboarding and device verification | Use SMS capability only to initiate, send, detect or verify the UPI registration / device-binding message required for mobile number and device verification. HFCL will not use this permission to access unrelated personal messages. | UPI registration or device re-verification may not be completed. |
| Location | Mandatory for applicable UPI features and transactions | Use location only at the time and for the UPI feature or transaction for which it is required, including applicable security, risk, regulatory or transaction enablement purposes. | The relevant UPI feature or transaction may be unavailable. |
| Phone / device state | Mandatory for applicable UPI features and transactions | Verify the device, securely bind the UPI ID to the device and prevent misuse. | UPI registration may not be completed. |
| Camera | Optional | Scan a UPI QR code when you select the scanner. | You may use another supported payment method, if available. |
| Contacts | Optional, if offered | Let you select a contact for a UPI payment. The current public policy states contacts are not accessed or stored beyond this use. | You can enter supported payment details manually. |
| Photos / gallery | Optional, if offered | Let you select a stored UPI QR image. The App should not access unrelated media. | You can scan or enter supported details manually. |
Directly from you through App forms, document uploads, camera capture, video / digital KYC, UPI instructions, customer support and assisted interactions.
Automatically from your device and use of the App, including permissions you enable, device and network information, security logs and transaction events.
From banks, PSP banks, NPCI / UPI participants, payment processors and technical service providers for UPI registration and transactions.
From credit information companies, KYC / CKYC and identity-verification providers, account aggregators or other authorized sources, subject to applicable law and required authorization.
From HFCL branches, salespersons, lending service providers, service providers and partners involved in an assisted loan journey.
From public or regulatory sources where lawful and necessary.
HFCL will process personal data on a ground permitted by applicable law. Depending on the activity, this may include:
Your consent for a specified purpose, obtained through a clear affirmative action.
A specified purpose for which you voluntarily provide personal data and do not indicate that you do not consent, where the conditions for such use are met.
Compliance with legal or regulatory obligations, judgments, decrees or orders.
Other uses expressly permitted under applicable law.
Optional analytics, personalization, promotional communications and sharing for third-party financial or insurance offerings will require separate, purpose-specific consent where applicable. Refusing or withdrawing optional consent will not affect a core service unless the data is necessary for that service or is required by law.
HFCL may use rules, models, or automated tools to support identity verification, fraud detection, credit risk assessment, eligibility, or underwriting. The role of automated tools in final adverse decisions, the availability of human review or appeal, the categories of information considered, a general description of the assessment logic, and the potential consequences of the assessment may vary by App product.
We may share only the personal data necessary for the stated purpose, on a need-to-know basis, with the following recipients:
| Recipient category | Purpose |
|---|---|
| RBI, NPCI, FIU-IND, CKYC registry, tax authorities, courts, tribunals, law-enforcement and other competent authorities | Regulatory reporting, KYC / AML, lawful verification, investigation, audit, supervision and enforcement. |
| PSP (Axis Bank) / participating banks, NPCI and UPI ecosystem participants | Register and operate UPI, link bank accounts, route and settle transactions, manage disputes, fraud and compliance. |
| Banks, payment gateways / aggregators, mandate processors and collection partners | Disbursement, EMI / mandate registration, repayments, refunds, reconciliation and payment support. |
| Credit information companies and verification agencies | Credit enquiry, reporting, monitoring, identity and document verification. |
| LSPs, sales and field partners, KYC providers, technology / cloud / cybersecurity / analytics / communication / customer-support providers | App operation, onboarding, verification, underwriting support, lead routing, service delivery, security and support. |
| Co-lenders, lending partners, assignees, investors, securitization or debenture trustees, rating agencies, auditors and transaction advisers | Co-lending, financing, assignment, securitization, due diligence, audit, servicing and related compliance. |
| Advocates, collection / recovery agencies, enforcement agencies and professional advisers | Collections, legal claims, dispute resolution, regulatory response and enforcement. |
| Affiliates and third-party financial or insurance partners | Only for a requested product, with separate consent where required, or where otherwise permitted by law. |
HFCL requires processors to act only on documented instructions and to maintain confidentiality, security and data-protection safeguards. HFCL does not sell personal data.
We store personal data, including identification details, financial information, credit information, loan application data, transaction records, and other information relevant to your relationship with HFCL, on secure systems and servers located within the territory of India. HFCL implements reasonable technical, organizational and security safeguards to protect personal data against loss, theft, misuse, unauthorized access, disclosure, alteration or destruction, and follows reasonable security practices and procedures in accordance with applicable law.
HFCL retains personal data only for as long as is necessary to fulfil the purposes for which it was collected, or as required or permitted under applicable law, regulation, internal policy, contractual requirement, or lawful business need. Where personal data may lawfully be used for a longer period, including for compliance, audit, fraud prevention, dispute resolution, enforcement, or defense of legal claims, HFCL may retain such data for such longer duration as may be required.
Retention periods may vary depending on the nature of the records and the legal or regulatory obligations applicable to them. For example:
KYC, customer identification, account opening and loan-related records may be retained in accordance with the Prevention of Money-Laundering Act, 2002, the Prevention of Money-Laundering (Maintenance of Records) Rules, 2005, and applicable RBI directions on KYC, AML and record management.
Credit, repayment, and account performance information may be retained in accordance with applicable credit information reporting and sharing requirements, including under the Credit Information Companies (Regulation) Act, 2005 and related RBI directions.
Financial, accounting, tax, contractual and corporate records may be retained in accordance with applicable legal requirements, including under the Income-tax Act, 1961, the Companies Act, 2013, and other applicable laws.
Digital logs, system records, communication records and interaction data may be retained for such period as is necessary to meet security, fraud monitoring, audit, cybersecurity, operational continuity and regulatory requirements under applicable law and internal governance standards.
Retention timelines for various categories of records are further elaborated in HFCL’s applicable internal policies, including the Preservation of Documents and Archival Policy hosted on the HFCL website under “Company Policies”. As per HFCL’s current policy, records may be retained for a minimum period of 10 years from the date of cessation of the transaction or relationship between the borrower and HFCL, and for a minimum period of 12 years where loan records involve mortgage of property.
Upon expiry of the applicable retention period, personal data is securely deleted, destroyed, anonymized, or otherwise disposed of in accordance with HFCL’s data retention and destruction protocols and applicable legal requirements, including ensuring that physical records are shredded or otherwise rendered unreadable and digital records are securely deleted or destroyed.
HFCL has expended considerable time, effort and resources, and implements reasonable technical, organizational and security safeguards to protect personal data against loss, theft, misuse, unauthorized access, disclosure, alteration or destruction. Such safeguards include, as appropriate, access controls, encryption, masking or obfuscation, monitoring, audit logs, backups, incident management processes, and contractual safeguards with Data Processors and other service providers.
HFCL maintains a comprehensive documented information security programme, supported by relevant policies, standards and processes, and implements managerial, technical, operational and physical security measures designed to support its business activities and protect the personal data that it collects, uses, stores and discloses. HFCL’s incident response framework is designed to enable its teams to detect, analyze, contain, eradicate and recover from information security incidents. HFCL also states that it complies with ISO 27001:2022 and maintains processes aligned with such standard for managing information security risks and responding to qualifying security incidents or breaches.
In the event of a personal data breach, HFCL shall take such action as may be required under applicable law, including notifying affected Data Principals and the Data Protection Board of India, and where applicable, any other competent regulator or authority, within the timelines prescribed under applicable law.
While HFCL endeavors to use reasonable safeguards and maintain appropriate security standards, no method of transmission over the internet or method of electronic storage is completely secure. Accordingly, HFCL shall not be responsible for any loss, unauthorized access or harm caused to the information provider, except where such loss, unauthorized access or harm is a direct and foreseeable consequence of HFCL’s negligence or non-compliance with applicable law. HFCL shall, in particular, not be responsible for any third-party actions, events beyond its reasonable control, or any act or omission of the information provider that results in loss, damage or harm.
Subject to the DPDP Act and other applicable law, you may:
| Right | Description |
|---|---|
| Right to Access Information | You have the right to obtain from us a summary of the personal data we hold about you and the processing activities carried out in respect of such data. |
| Right to Correction and Erasure | You have the right to request correction of inaccurate or incomplete personal data and, subject to applicable legal and regulatory retention obligations, erasure of personal data that is no longer necessary for the purpose for which it was processed. |
| Right to Grievance Redressal | You have the right to have your grievances addressed by HFCL in a timely manner, and to escalate unresolved grievances to the Data Protection Board of India. |
| Right to Nominate | You have the right to nominate another individual who may exercise your rights in the event of your death or incapacity. |
| Right to Withdraw Consent | Where processing is based on your consent, you have the right to withdraw such consent at any time. |
Withdrawing consent does not affect prior lawful processing. If required data or permission is withdrawn, HFCL may be unable to provide the relevant feature.
You remain responsible for complying with the duties of a Data Principal under applicable law, including not impersonating another person, not filing false or frivolous grievances, and furnishing authentic information when seeking correction or erasure.
| Channel | Details |
|---|---|
| Customer.Care@HeroFinCorp.com | |
| Postal address | Hero FinCorp Limited, A-44, Mohan Co-operative Industrial Estate, Mathura Road, New Delhi - 110044 |
Please first contact HFCL so we can review and address your concern. Current grievance contact details referenced in the supplied policy are:
| Role | Contact |
|---|---|
| Grievance Officer | Nodal.officer@herofincorp.com | 0120-4035320 |
| Address | Hero FinCorp Limited, A-44, Mohan Co-operative Industrial Estate, Mathura Road, New Delhi - 110044 |
The App and UPI services are not intended for children unless the product is lawfully offered to them.
The App may use software development kits, local storage, analytics, crash reporting, fraud prevention and similar technologies to operate, secure and improve the App.
Optional advertising or cross-app tracking must not occur without the choices and disclosures required by applicable law and platform policy.
HFCL may send promotional communications about HFCL products, schemes or offers only where the required consent has been obtained. You can withdraw marketing consent without affecting transactional, security, regulatory, servicing, recovery or loan-account communications. The in-App opt-out path and channel-specific stop mechanisms are mentioned in section 12 of this policy.
The App may link to or interoperate with third-party services. Their privacy practices are governed by their own policies when they act independently. HFCL is not responsible for independent third-party processing but remains responsible for processing carried out by processors on HFCL’s behalf as provided by applicable law.
HFCL may update this Policy to reflect changes in law, product design, permissions, partners or processing. Material changes will be communicated through the App, website or another appropriate channel, and fresh consent will be obtained where required. The effective date and version will be displayed at the top of the Policy.