Legal
Last updated: 3 August 2026
This Privacy Policy (“Policy”) outlines the practices of Delviant AI Labs Private Limited (“Delviant”, “we”, “us”, or “our”) in relation to the storage, use, processing, and disclosure of personal data handled in connection with our website at delviant.in and the services we provide (together, the “Platform” and “Services”, as defined in our Terms & Conditions). Please read this Policy together with the Terms.
Delviant is a technology company and lending service provider (LSP). We facilitate parts of the lending journey on behalf of regulated lenders — banks, non-banking financial companies (NBFCs), and other authorised financial institutions. We are not a lender: we do not make credit decisions, sanction or disburse loans, or collect repayments in our own name. Where we process the personal data of borrowers or applicants, we do so on the instructions of, and on behalf of, the regulated lender responsible for that lending relationship, and that lender remains the primary data controller.
We are committed to protecting your personal data and respecting your privacy. By providing us with consent to process your personal data, you acknowledge that we will collect, store, use, and disclose your personal data in accordance with this Policy.
We collect and process only the personal data needed to provide or support the Services, after obtaining the appropriate consent. Depending on your interaction with us, this may include:
We collect only the minimum data required. Where processing is on a lender’s behalf, the categories and scope of data are defined by that lender’s instructions and applicable law. Any one-time access to a device facility (such as camera or microphone for a KYC check) is requested only with your explicit consent for that specific purpose. If you do not provide data we reasonably require, we may be unable to provide the relevant Services.
We use different methods to collect and process personal data about you, including:
We have no control over personal data you choose to make publicly available. If you post content in public forums or app stores, you do so at your own risk.
We use personal data only in accordance with applicable law — most commonly to provide the Services or to comply with a legal obligation. Our purposes include:
We do not sell personal data. Subject to your consent and solely to deliver the Services, we may share information with: the regulated lender on whose behalf we process it; trusted service providers who support our operations under confidentiality and security obligations; and other Delviant group entities in connection with the purposes above. We may also disclose data where required by law, a court, or a government authority, in good faith and to the extent reasonably necessary.
You warrant that the personal data you provide is accurate, current, and true. We make reasonable efforts to let you review and correct inaccurate or incomplete data, subject to legal requirements, and we may verify the accuracy of the data you provide.
We implement appropriate security measures and access controls designed to protect your personal data from unauthorised access, following the technology standards prescribed by applicable law — including the Information Technology Act, 2000, the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Digital Personal Data Protection Act, 2023 (as and when enforced), and applicable RBI requirements. These include physical safeguards, electronic safeguards such as passwords, firewalls, and encryption, and secure development practices. Mandatory personal information is encrypted in transit and at rest, and access is restricted to personnel who need it to deliver the Services. We maintain internal processes to detect, contain, and respond to security incidents, and will take timely measures and keep you informed where your data is materially impacted. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
For our retention and destruction practices, please refer to the Schedule at the end of this Policy.
Subject to applicable law, you have the right to:
Where you deny or withdraw consent or provide inaccurate information, you may not be able to avail the full scope of the Services. Notwithstanding a request to erase or restrict, we may retain information to comply with applicable laws, enforce our legal rights, or assist regulatory authorities investigating fraud or unlawful activity. Where your data relates to a lending relationship, the relevant lender (as primary controller) may continue to process and retain it as required by applicable law and for as long as any dues remain outstanding. To exercise your rights, contact our Grievance Officer (Section 15). We aim to respond within 30 days of receiving a valid request, and will inform you if more time is needed.
All personal data we handle in connection with the Services, including financial data, is stored on systems located in India. We do not transfer such data to any third country. We share information with lender partners and authorised service providers only for purposes such as loan application processing, KYC checks, verification, and related Services.
The Services may contain links to, or services provided by, our partner networks, service providers, financial institutions, and affiliates (“Third-Party Services”). These are governed by their own privacy policies. We do not accept responsibility for the policies of, or any data collected through, such Third-Party Services. Please review their policies before submitting any personal data.
Cookies are small data files stored on your device. We use cookies and similar technologies to distinguish you from other users and remember your preferences, which helps us provide a good experience and improve the Services. Cookies do not give us access to data on your device such as email addresses, or any data that can personally identify you beyond what you provide. Most browsers can be set to notify you of, or refuse, cookies; refusing them may limit certain website features. Some pages may contain cookies placed by third parties, whose use we do not control.
If we undergo a business transition — such as a merger, acquisition, or sale of all or part of our assets — your personal data may be among the assets transferred.
We keep this Policy under regular review and may amend it from time to time at our discretion. Changes take effect when posted on this page, and where appropriate we may notify you by email or SMS.
You may contact our Grievance Redressal Officer with any query relating to this Policy or your personal data:
Name: Ms. Neha Gupta
Email: grievance@delviant.in
This Policy is governed by the laws of India. The governing-law and dispute-resolution provisions of our Terms & Conditions apply to this Policy, with the courts of New Delhi having exclusive jurisdiction.
This Schedule describes Delviant’s approach to data retention and destruction. Your personal data is retained for as long as required or permitted by applicable laws or regulatory requirements, or as needed to establish or defend legal claims. Data that is not required to be retained will be deleted or anonymised upon a valid request, provided there is no active Service or lending relationship that requires it. In some cases we may be unable to delete data where a legal or regulatory obligation, or a lender’s instruction as primary controller, requires us to retain it for a longer period.