Hero Background

ENN ENN CAPITAL

Privacy Policy

Privacy Policy


Effective DateJune’ 2026
Version name V2
1. Introduction

Welcome to ENN ENN Capital Pvt. Ltd. (the 'Company' or 'EECPL'). The domain name www.ennenncapital.com ('Website') is owned by EECPL, a company incorporated under the Companies Act, 1956, with its registered office at Enn Enn One, Behind RR Mall, Vesu, Surat, Gujarat, India – 395007. 
We, at EECPL, respect the privacy of everyone who visits EECPL's Website and other digital platforms including Our mobile applications (hereinafter together referred to as 'EECPL Platforms') and are committed to protecting their personal information. This Privacy Policy applies to EECPL, its subsidiaries, and to all visitors of the Website and users of EECPL's mobile applications.
Use of the Website or Our mobile applications signifies Your acknowledgement and free and unconditional consent to this Privacy Policy. If You object to Your information being used, processed, and transferred by Us in the manner described herein, please do not share Your information on EECPL Platforms.

2. Definitions
For the purpose of this Privacy Policy: 
"You", "Your", "User" means any natural or legal person, including online and offline clients, visiting the Website or using Our mobile applications/our DLA/DLA owned by our LSP/website of the LSP. "We", "Us", "Our" means EECPL and its subsidiaries. 
"DLA" means Digital Lending Application —Any digital interface including website and any mobile application either owned by EECPL or its LSP through which information/data/documents pertaining to the proposed borrower/s are collected for offering lending services. 
"LSP" means Loan Service Provider — an entity engaged by EECPL to carry out specific loan application origination including data/document collection physically or through its DLA or servicing activities like recovery of loan dues on its behalf.
"Personal Data" or "Personal Information" means any information relating to an identified or identifiable individual, including financial and transactional information.

3. Scope and Legal Rights
This Privacy Policy is not intended to create any contractual rights beyond those provided under applicable law. Nothing in this Policy limits or restricts any statutory rights available to borrowers under the Reserve Bank of India's directions on digital lending or any other applicable law.

4. Personal Information We Collect

4.1 Information You Provide Directly
We may, for the purpose of rendering services, collect personal information including:
• Identification Information: Name, gender, residential and communication address, contact number, date of birth, marital status, email address, or any other contact information.
• PAN, KYC, Signature, and Photograph.
• Bank account or other payment instrument details.
• Any other detail/documents like your GST returns, financials/ITR, bank statement etc., which may be required by Us for providing the desired services.

4.2 Information Collected from Your Use of Our Services
• Transaction Information: We read, collect and monitor only financial transactional SMS for description of transactions and corresponding amounts for credit risk assessment. Other SMS data is not accessed.
• Storage Information: We may facilitate the user to download and display information which a user may refer to, or to upload relevant documents as per various processes during user account management.
• Media Information: We may facilitate users to capture or upload relevant documents as may be required during user account management.
• Device Information: We collect specific information about Your device when You access Our services, including hardware model, operating system and version, unique device identifier, mobile network information, and information about the device's interaction with Our services.
• Contact and Device Access: EECPL's mobile application does not access or collect data from Your device's file storage, media library, call logs, or telephony functions. Access to Your device camera, microphone, or location is requested on a one-time basis solely for the purpose of KYC verification and onboarding, with Your explicit prior consent. Contact information is accessed only when You voluntarily select a reference contact during the loan application journey and is not uploaded to EECPL servers.

4.3 Log File Information
If You visit or log in to Our website purely to browse, read pages, or download information, certain information about Your visit is automatically stored on Our systems. This information cannot and does not identify You personally. Information gathered automatically includes: browser type; operating system type; domain name of Your Internet Service Provider; date, time, and pages visited. We use this information to improve Our website design and content.

5. Purpose of Collection and Use of Information
On Our platforms, We collect, retain, and use information about You only when We reasonably believeit will help administer Our business or provide products, services, and other opportunities to You. Information is collected for the following specific purposes:
(a) To provide You with the services that You may require.
(b) To process Your financial and non-financial transaction requests.
(c) To undertake research and analytics for offering or improving Our services.
(d) To check and process Your submitted applications for availing financial services.
(e) To share with You any updates or changes in Our services and their terms and conditions.
(f) To take up and investigate any complaints, claims, or disputes.
(g) To respond to Your queries and feedback.
(h) For verification of Your identity and other parameters.
(i) To fulfil the requirements of applicable laws, regulations, court orders, and regulatory directives.

6. Borrower Consent and Data Rights

6.1 Consent-Based Data Collection
EECPL collects personal data on a need-based, purpose-specific basis only. Data collection is subject to prior informed consent from the borrower, except where collection is mandated by applicable law or regulation. EECPL does not collect data beyond what is necessary for the specific purpose disclosed at the time of collection.

6.2 Stage-wise Consent Disclosure
EECPL discloses the purpose of data collection and seeks explicit consent from borrowers at each stage of the loan journey where personal data is collected or processed, including at:
(a) Loan application and onboarding stage;
(b) Credit assessment and underwriting stage;
(c) Disbursement and documentation stage; and
(d) Post-disbursement monitoring and repayment stage.

6.3 Borrower Data Rights
Borrowers have the following rights in respect of their personal data held by EECPL:
(a) Right to Consent: The right to grant or deny consent for the collection of each category of personal data at the time of collection.
(b) Right to Restrict: The right to restrict disclosure of their personal data to specific third parties, where such restriction is not contrary to applicable law.
(c) Right to Revoke: The right to revoke consent previously granted for any category of data processing, with prospective effect.
(d) Right to Delete: The right to request deletion or anonymization of their personal data, subject to applicable legal and regulatory retention requirements.

6.4 Consent Audit Trail
EECPL maintains a digital audit trail of all consents granted, modified, or revoked by borrowers. This audit trail is available to the borrower upon request.

6.5 How to Exercise Your Rights
Requests for revocation of consent, restriction of data sharing, or deletion of personal data may be submitted through the channels listed on www.ennenncapital.com. EECPL will acknowledge and process such requests within 30 working days, except where retention or processing is required under applicable law or regulatory direction.

7. Disclosure of Information
The information provided by You may be disclosed to:
(a) KYC Registration Agencies and other such agencies, solely for the purpose of processing Your transaction requests.
(b) Another entity to carry out any activity in the event of merger or amalgamation of borrower’s business with some other entity.
(c) Any judicial, statutory, or regulatory body.
(d) Auditors.
(e) Law enforcement or any government bodies.
(f) Other third-party service providers engaged by EECPL for specific operational purposes, with the explicit prior consent of the borrower, except where sharing is required under statutory or regulatory mandate.
(g) Seven Fincorp (Noxven Ventures OPC Pvt Ltd), acting as EECPL's LSP (Loan Service Provider), for the purpose of loan origination (i.e. sourcing), preliminary application processing and onward submission to EECPL, and servicing certain activities like recovery of dues on EECPL's behalf by collecting certain data/documents through its DLA. Seven Fincorp is contractually bound to process such data only within the scope of its defined operational mandate and in compliance with applicable data privacy requirements. 
Named Third Parties: Third parties currently authorised to collect or process personal information include: Seven Fincorp (Noxven Ventures OPC Pvt Ltd), operating as LSP (Loan Service Provider) through its DLA (Digital Lending Application). This list will be updated as and when LSP arrangements change. 
EECPL ensures that all LSPs and third-party service providers engaged by it are contractually bound to data privacy and security standards equivalent to those maintained by EECPL, and are prohibited from using borrower data for any purpose beyond their defined operational scope.

8. Retention of Information
EECPL shall not retain or store personal information for periods longer than is required, except when such information may lawfully be used or is otherwise required under any applicable law in force. Specific retention periods applicable to each category of personal data are as follows:
(a) KYC and identity data: retained for the duration of the customer relationship and for 8 years thereafter, in accordance with anti-money laundering and other applicable regulations;
(b) Financial and transactional data: retained for 8 years from the date of loan account closure;
(c) Device and behavioral data: deleted within 6 months of loan account closure;
(d) Communication logs: retained for 3 years from the date of the communication.
Upon expiry of applicable retention periods, personal data shall be permanently and irreversibly deleted from all EECPL systems, servers, and backup media within 30 days of the expiry date. A record of destruction shall be maintained for compliance purposes.
You always have the right to refuse or withdraw Your consent to the collection and use of Your personal data by contacting Our customer care. However, in the event of such refusal or withdrawal, You may not be able to fully avail of EECPL's services.
When You use the Website or send emails or other data to Us, You agree that You are communicating through electronic mode and consent to receive communications from Us periodically, including notifications via email, hard copy, conspicuous posting on Our Website, or push notifications on your mobile device. You may choose to opt out of certain means of notification.

9. Data Storage Policy

9.1 Categories of Data Stored
EECPL stores the following categories of personal data in the course of its lending operations:
• Financial data (income documents, bank statements, credit bureau reports, GST returns);
• Identity data (PAN, Aadhaar reference number, KYC documents, photographs);
• Device and behavioral data (device identifiers, transaction patterns, app usage logs); and
• Communication data (emails, in-app notifications, customer service records).

9.2 Data Access Controls
Access to stored personal data is restricted to authorised EECPL personnel on a need-to-know basis. EECPL maintains documented access control policies. All access is subject to strong authentication, audit logging, and periodic access reviews by EECPL's information security function.

9.3 Data Destruction Protocol
Upon expiry of the applicable retention period set out in Section 8, EECPL shall permanently and irreversibly delete personal data from all servers, storage systems, and backup media using industry- standard data destruction methods within 30 days of the expiry date. A record of destruction shall be maintained for regulatory audit purposes.

9.4 Security Breach Response Standards
In the event of an actual or suspected personal data breach, EECPL shall:
(a) Contain and assess the breach within 24 hours of discovery;
(b) Notify affected borrowers without undue delay where the breach is likely to result in high risk to their rights and interests;
(c) Report the breach to relevant regulatory authorities as required under applicable law; and
(d) Document the breach, its impact, and the remedial action taken, and retain such records. EECPL maintains an incident response plan which is reviewed and approved by its Board at least once annually.

10. LSP Data Restriction
LSPs engaged by EECPL — including Seven Fincorp (Noxven Ventures OPC Pvt Ltd) — are contractually restricted from storing personal or financial information of borrowers beyond basic minimal data (name, address, and contact details) necessary to perform their defined operational scope.
All detailed financial, credit, transactional, and credit bureau data of borrowers is stored solely on EECPL-controlled servers. LSPs process such data only in the capacity of authorised data processors acting on EECPL's behalf and are prohibited from retaining, copying, or using such data for any
purpose not expressly authorised by EECPL.
EECPL retains full responsibility for the privacy and security of all customer information, regardless of any processing performed by LSPs on EECPL's behalf. LSP agreements include enforceable data minimisation obligations and prohibit LSPs from using or sharing borrower data for any purpose not authorised by EECPL and the borrower.

11. India Data Residency
All personal and financial data of borrowers collected or processed by EECPL is stored exclusively on servers physically located within India, in compliance with RBI directions on data localisation. 
In the event any data processing activity requires temporary transfer of data outside India, EECPL shall ensure that such data is deleted from servers outside India and returned to India-based servers within 24 hours of the completion of such processing.

12. Biometric Data Prohibition
EECPL and its LSPs do not collect, access, or store any biometric data of borrowers, includingfingerprints, facial recognition data, or iris scans. 
Any biometric-based authentication required for KYC or identity verification purposes — including Aadhaar-based verification — is performed exclusively through channels authorised by the competent authority (e.g. UIDAI for Aadhaar-based OTP or eKYC authentication). No biometric data is transmitted to or stored by EECPL or its LSPs at any stage.


13. Updating or Reviewing Your Information
You may, upon written request to Us, review the personal data or information provided by You. You shall ensure that any personal information found to be inaccurate or deficient is corrected or amended as feasible. For the procedure to review or update your information, please refer to www.ennenncapital.com.

14. Reasonable Security Practices for Protecting Your Information
We use commercially reasonable physical, managerial, and technical safeguards to preserve the integrity and security of Your personal information. These include internal reviews of Our data collection, storage, and processing practices, appropriate encryption, and physical security measures to guard against unauthorised access to systems where We store personal data.
All information gathered is securely stored within Our controlled database on secured servers. Access to these servers is password-protected and strictly limited to authorised personnel.
EECPL does not knowingly collect data relating to minors. Our services are not intended for anyone under the age of 18. EECPL verifies user age at the time of signup. 
While EECPL employs commercially reasonable security measures, the security of data transmitted over the internet cannot be fully guaranteed. EECPL accepts responsibility for data security within its controlled systems and will respond to any breach in accordance with its incident response obligations as set out in Section 9.4 of this Policy. EECPL's liability for data breaches shall be governed by applicable law. 
Once We receive Your transmission of information, We make commercially reasonable efforts to ensure its security. For details of EECPL's breach response protocol, see Section 9.4.

15. Links to Other Websites
Please note that this Privacy Policy does not extend to third-party websites linked to Our Website. EECPL is not responsible for the content and privacy practices of such linked websites. It is advisable to read each linked website's privacy policy prior to sharing any information.

16. Changes to This Privacy Policy
Our Privacy Policy may change from time to time. If We change Our privacy policies and procedures, We will post the changes on the Website to keep You updated. Changes shall become effective for the Website on the day they are posted. Please visit Our Website to stay updated on any changes to the Privacy Policy.

17. Grievance Redressal
Any discrepancies and grievances related to the processing and use of Your information can be raised to the Grievance Redressal Officer appointed by EECPL. For contact details and further information, please visit www.ennenncapital.com.

18. Cookie Policy
EECPL uses cookies on www.ennenncapital.com (the 'Website'). By using the Website, You consent to the use of cookies.
 
18.1 What are cookies?
Cookies are small pieces of text sent to Your web browser by a website You visit. A cookie file is stored in Your web browser and allows the server or a third party to recognise You and make Your next visit smoother. Cookies can be 'persistent' (remaining when You go offline) or 'session' cookies (deleted when You close Your browser).

18.2 How EECPL uses cookies
When You use and access the Website, We may place cookie files in Your web browser for the
following purposes:
• To enable certain functions of the service;
• To improve user experience; and
• To store user preferences to ease navigation.
We use both session and persistent cookies to provide services smoothly, and essential cookies to authenticate users and prevent fraudulent use of accounts. We may update this clause from time to time to reflect changes in practices or for legal, statutory, or regulatory reasons. 
EECPL is not responsible for cookies placed by any other website. EECPL may share cookies with third parties for offering services based on previous browsing history.

18.3 Your cookie choices
If You would like to delete cookies or instruct Your browser to refuse them, please visit the help pages of Your web browser. Note that disabling cookies may affect Your ability to use certain features of Our Website. For browser-specific guidance, refer to Your browser's official support pages or visit www.allaboutcookies.org.