Introducing Maestro — The only Agentic AI engine built from the ground up for post-origination collections.

Privacy Policy

This Privacy Policy (“LSP Privacy Policy”) explains how Statlabs Analytics Ventures Private Limited, trading as CreditNirvana (“CreditNirvana”, “we”, “us” or “our”), handles personal data when it provides recovery and collection services to its regulated financial-institution customers (banks and non-banking financial companies (“NBFCs”), together “FI Customers”). This LSP Privacy Policy applies specifically to CreditNirvana’s activities as a Lending Service Provider and to its processing of borrower personal data in that capacity.


1. Our Role


CreditNirvana acts as a Lending Service Provider (“LSP”) to FI Customers within the meaning of the applicable Reserve Bank of India (“RBI”) Credit Facilities Directions, by engaging human collection and recovery agents (as managed manpower through our empaneled partners) to carry out recovery activities on behalf of FI Customers. CreditNirvana also provides a technology platform to FI Customers on a software-as-a-service (SaaS) basis.

CreditNirvana does not lend, does not have a direct interface with borrowers or end-customers, and does not operate a borrower-facing digital lending application. Under the Digital Personal Data Protection Act, 2023 and the rules made under it (together, the “
DPDP Framework”), CreditNirvana acts as a Data Processor. The FI Customer is the Data Fiduciary and determines the purposes and means of processing borrower personal data.


2. Personal Data and Our Data-Processor Position


CreditNirvana does not collect personal data directly from borrowers. It processes borrower personal data solely on the documented instructions of the relevant FI Customer, and only for the purposes set out in the service agreement and associated data-processing terms entered into with that FI Customer.

Where collection agents engaged by CreditNirvana collect borrower personal data in the course of recovery activities, such collection is carried out solely on behalf of, and under the instructions of, the FI Customer.

CreditNirvana restricts the borrower personal data it stores on its own systems to basic minimal data, namely name, address and contact details, necessary to carry out its operations within the scope of the agreement with the FI Customer, unless that agreement expressly permits the retention of additional categories of data.

CreditNirvana does not process borrower personal data for any purpose beyond the scope expressly agreed with the FI Customer. Any processing outside that scope would be undertaken only with the requisite consents (obtained by or through the FI Customer) and may, for that limited purpose, characterise CreditNirvana as a Data Fiduciary under the DPDP Framework.

 

3. Purposes of Processing
 

On the instructions of the FI Customer, CreditNirvana processes borrower personal data for the following purposes connected with debt recovery and collection:

executing debt collection and recovery on behalf of the FI Customer, including allocating cases to collection and recovery agents;

facilitating permitted communications with borrowers and processing the records (including call records) generated in the course of recovery, on behalf of and under the control of the FI Customer;
reconciling and reporting collection outcomes and payment confirmations to the FI Customer; and
maintaining audit trails and meeting the FI Customer’s and CreditNirvana’s compliance and regulatory obligations.

4. Lawful Basis, Consent and Notice
 

As Data Fiduciary, the FI Customer is responsible for establishing the lawful basis for processing (whether consent or a legitimate use permitted under the DPDP Act), and for issuing the required notice to, and obtaining any required consent from, the borrower before borrower personal data is shared with CreditNirvana and its managed collection and recovery agents. CreditNirvana processes such data only as the FI Customer’s Data Processor and in accordance with the FI Customer’s instructions and the data-processing terms agreed with it.


5. Sharing of Personal Data
 

CreditNirvana does not sell or rent personal data. It shares borrower personal data only in the following circumstances:

with the FI Customer, in the form of collection reports, payment confirmations, records and audit logs;

with managed collection agents engaged only with the FI Customer’s prior written approval, bound by back-to-back data-protection and confidentiality obligations equivalent to CreditNirvana’s own, and holding the applicable debt-recovery-agent certification;
with technology and hosting sub-processors (such as Amazon Web Services) under contractual obligations that meet applicable data-protection standards; and

with regulatory authorities, law-enforcement agencies or courts where required by law or valid legal process.

In the event of a merger, acquisition or change of control, personal data may transfer to the successor entity under equivalent data-protection obligations, with notification to affected parties as required by applicable law.

 

6. Retention, Return and Deletion
 

CreditNirvana retains borrower personal data only for as long as necessary to carry out the FI Customer’s instructions and as required by applicable law. A minimum retention period of one year applies to logs and associated records under the DPDP Framework and, where applicable to recovery communications, under telecom record-keeping requirements.

Upon completion of the recovery purpose or termination of the engagement with an FI Customer, CreditNirvana ceases processing and returns, deletes or purges the borrower personal data in accordance with the FI Customer’s instructions, and provides written certification of such deletion to the FI Customer. The erasure of borrower data once its purpose is served, and any advance notice of erasure to the borrower, are responsibilities of the FI Customer as Data Fiduciary.

 

7. Data Security
 

CreditNirvana implements security safeguards equivalent to those required of a Data Processor under the DPDP Framework, including:
encryption, obfuscation, masking or use of virtual tokens, as appropriate;

access controls over the relevant computer resources;
logging, monitoring and review mechanisms to detect and investigate unauthorised access, with retention of logs for at least one year;
data backup measures; and
equivalent contractual security obligations imposed on collection and recovery agents and other sub-processors.

 

CreditNirvana also complies with the technology and cybersecurity standards prescribed by the RBI and with any further standards stipulated by FI Customers under their respective agreements.

In the event of a personal data breach or a material cyber incident, CreditNirvana promptly notifies the affected FI Customer and assists it in meeting its breach-reporting obligations, including any notification by the FI Customer to the Data Protection Board of India and affected borrowers under the DPDP Framework, and any reporting by the FI Customer to the RBI within applicable timelines.

 

8. Data Localisation
 

All borrower personal data processed by CreditNirvana in its LSP capacity is stored on servers located within India. As at the date of this policy, no cross-border transfer restrictions have been notified under the DPDP Framework.

 

9. Rights of Borrowers
 

The FI Customer, as Data Fiduciary, is responsible for honouring borrowers’ rights under the DPDP Framework (including the rights of access, correction and erasure) and for managing consent and notice. Borrowers who wish to exercise their rights should contact the relevant FI Customer. Where CreditNirvana receives such a request directly, it will forward the request to the relevant FI Customer and assist the FI Customer in responding.

 

10. Conduct of Recovery Agents
 

CreditNirvana’s managed collection and recovery agents act under the instructions and code of conduct of the FI Customer and in accordance with the applicable RBI directions on responsible business conduct and the Fair Practices Code. The FI Customer remains the principal responsible for the conduct of recovery agents. In relation to personal data:

agents must observe strict borrower confidentiality and must not disclose borrower personal data to unauthorised third parties; and
agents are required to hold the applicable debt-recovery-agent certification before undertaking recovery activities.

Advance intimation to the borrower of the identity and contact details of the authorised recovery agent is provided by the FI Customer; CreditNirvana supports the FI Customer in meeting that requirement.

 

11. Grievances
 

CreditNirvana does not have a direct interface with borrowers and is not the entity responsible for resolving borrower grievances. As a matter of good practice, CreditNirvana has designated a nodal officer to receive borrower complaints and escalate them to the relevant FI Customer:

 

Nodal Officer:  Nirithiyan S R

E-mail:  nodalofficer@creditnirvana.ai

Address:  Statlabs Analytics Ventures Private Limited

No. 66/5-25, 5th Floor Indiqube-HM Vibha Building, Lasker Hosur Road, Adugodi, Bangalore, Bangalore South, Karnataka, India, 560030

 

It is clarified that (i) CreditNirvana is not responsible for resolving borrower grievances; (ii) CreditNirvana’s role is limited to collecting borrower complaints and escalating them to the concerned FI Customer; and (iii) the sole responsibility for resolution of borrower grievances rests with the concerned FI Customer. Any complaint or grievance relating to the collection or handling of borrower personal data should be directed to the relevant FI Customer.

 

12. Updates to This Policy
 

CreditNirvana may update this LSP Privacy Policy from time to time to reflect changes in law, RBI directions or operational practice. The effective date at the top of this document will be updated accordingly, and material changes will be notified by posting a notice on our website.

 

13. Contact

Statlabs Analytics Ventures Private Limited (CreditNirvana)