Menu

Privacy Policy

1. Purpose

This Privacy Policy describes how Fintech Association for Consumer Empowerment (FACE) may collect, process, store, and /or use its Users’ (defined below) information.

FACE is fully committed to safeguarding and protecting the privacy, confidentiality, and security of the non-public information we collect and receive. We are dedicated to implementing appropriate measures that prioritise the protection of our stakeholders’ information, always maintaining their trust and confidence in us.

This Privacy Policy is designed to communicate how we collect, use, disclose, delete and protect users’ (including members, customers, vendors, project partners, and stakeholders) information when they engage with FACE by exchanging non-public information. The policy is in accordance with relevant and applicable data protection regulations/laws, and in the event of any conflict or interpretation issues, the regulations/laws will prevail.

You are advised to carefully read the Privacy Policy before sharing information or data (including any Personal Data) with us or our Representatives (defined below), or before accessing our website or interacting with us. We shall not be liable/responsible for any breach of privacy owing to your negligence.

Users have rights under applicable data protection laws, including the right to access, correct, or delete their information as detailed later in this policy.

2. Definitions

3. Applicability

The privacy policy rigorously applies to all the non-public information that FACE receives or collects from a range of stakeholders, including but not limited to members, vendors, project partners, and customers (defined as customers of member companies or general respondents voluntarily participating in our research studies.) It mandates full adherence to data handling practices, ensures transparency in data usage, and provides clear guidelines for data protection measures.

This policy is intended to complement, rather than replace, any previous consents the users may have provided to FACE regarding their data.

This policy also applies to any third-party service providers or partners engaged by FACE for processing data on its behalf. Such entities are required to adhere to equivalent data protection and confidentiality standards as outlined in this policy.

4. Data acquisition, utilisation and storage

FACE ensures that all data, information, and documentation are acquired, utilised, and stored following the terms specified below:

a. Data acquisition

b. Data utilisation

c. Data Storage

All data, information, and documentation collected from members, including employees and board/committee members, will be stored on cloud-based servers in data centres, in accordance with data privacy and storage requirements under applicable Indian laws. Such information may also be stored on employees’ respective systems, subject to ensuring proper safeguards against any unauthorised access or use/data breaches, and business continuity.

Data will be retained only for as long as necessary to fulfil the purpose for which it was collected or as required under applicable law or regulatory obligations. Upon the user’s request or once the retention purpose is met, the data will be securely deleted or anonymised in accordance with FACE’s data retention policy.

FACE employs reasonable administrative, technical, and physical safeguards—such as access controls, encryption, and secure cloud infrastructure—to protect stored information against unauthorised access or disclosure.

5. User’s Representation

6. Cookies

Cookies are small data files often used as anonymous, unique identifiers. When the users access the website, these files are sent to the browser and stored on the computer’s hard drive. The website employs these “cookies” to gather information and enhance its service. Cookies used on the FACE website may include:

FACE does not use cookies for advertising, profiling, or cross-site tracking purposes. Users can accept or decline these cookies and will be notified when a cookie is sent to their computer. Declining cookies may limit access to certain parts of the website. Most browsers automatically accept cookies, but users can modify their browser settings to decline them if preferred. Users can manage their cookie preferences through their browser settings at any time, including deleting existing cookies or restricting new ones. Please note that disabling certain cookies may limit functionality or access to some parts of the website.

7. Links to Other Sites

Our Service may provide links to other websites. Clicking on a third-party link will redirect the user to the respective site. Understanding that these external sites operate independently and are not within our control is essential. Therefore, reviewing the privacy policies of these websites is strongly recommended. We cannot be held responsible for any content of third-party sites or services, privacy policies, or practices. Please be advised that the User’s interaction with websites linked through our service is subject to the terms of use and privacy policies of those third-party websites.

8. Usage Data

FACE may collect information transmitted by the user’s browser each time the user visits the website via a mobile device, referred to as “Usage Data.”

This Usage Data encompasses various details, including but not limited to the user’s computer’s Internet Protocol (IP) address, browser type, browser version, the specific pages navigated on the website, the date and time of visit, the duration spent on those pages, as well as unique device identifiers and other diagnostic data.

The Usage Data is collected solely for internal analytics and technical purposes, such as monitoring website performance, understanding aggregate user interactions, and improving the content and usability of FACE’s digital platforms. FACE does not use Usage Data for profiling, advertising, or behavioural tracking. If any third-party analytics service (such as website traffic or security monitoring tools) is used, such service providers are contractually bound to comply with equivalent data protection and confidentiality standards as set out in this Policy.

When accessing the website through a mobile device, the gathered usage data may extend to details such as the specific type of mobile device utilised, the device’s unique ID, the IP address of the mobile device, the mobile operating system, the type of mobile internet browser utilized, unique device identifiers, and additional diagnostic data.

9. Location Data

With consent, FACE may use and store information about the User’s location (“Location Data”). This information empowers us to tailor features to meet specific needs and continually refine our services. Users can enable or disable location services on the website at any time through their device settings.

10. Retention of Data

FACE will retain user data for the duration necessary to achieve the purposes for which it was collected and as required by legal or regulatory obligations. Any information that is no longer necessary will be retained for a period of eight (8) years until the retention period of such information is specified by the RBI and any other timeline communicated by the government and regulators.

Where required or appropriate, FACE may retain certain anonymised or aggregated data beyond the specified retention period solely for statistical, research, or regulatory reporting purposes, provided that such data no longer contains any information that can identify an individual or organisation.

11. Disclosure

We pledge not to disclose any Information without the user’s prior explicit consent. When collaborating with third parties, we enforce confidentiality standards through Non-Disclosure Agreements (NDAs). Notwithstanding anything contained in this policy, FACE reserves the right to disclose any collected data, information, and documentation to RBI and any government entity and law enforcement agencies inspect, seize, or access such materials when deemed necessary or appropriate by FACE at its sole discretion.

12. Security

We deeply appreciate the User’s trust in sharing their Data and employ commercially acceptable methods to safeguard it. FACE shall undertake Reasonable Security Practices and Procedures and implement appropriate technical and organisational measures to secure the confidentiality, integrity, and availability of your Data.

These measures include, among others, encryption, access control mechanisms, role-based authorisations, secure cloud infrastructure, network firewalls, and regular monitoring of systems for potential vulnerabilities. FACE also conducts periodic security reviews and audits to ensure continued adherence to applicable data protection and information security standards.

13. Modifications to Account Information and Preferences

FACE allows users to update the information provided during registration, including communication preferences with us. Users can discontinue the use/transfer/transmission and sharing of their information by writing to us. FACE will accept such information only from/under the signature of an authorised signatory (Founder/CEO or others). FACE will honour the user’s request to discontinue the use of information promptly upon receipt of the instructions unless otherwise as required by regulator and law enforcement agencies.

14. Revisions

FACE may revise this Privacy Policy from time to time to ensure alignment with forthcoming developments, industry trends, and any pertinent shifts in legal or regulatory frameworks. FACE will publish updates promptly on its website and inform users of any changes.

15. Inquiry and Grievance Redressal

For any further queries, complaints or grievances related to this Privacy Policy, you could write to us sro@faceofindia.org. All grievances or complaints received at this address shall be acknowledged within seven (7) working days and resolved within thirty (30) working days of receipt, to the extent practicable. If you are not satisfied with the resolution provided, or if the complaint remains unaddressed within the specified timeframe, you may escalate the matter to the relevant Data Protection Authority or other competent authority under applicable law.