Privacy Policy

Tenali Credit Mitra is committed to protecting your personal data in full compliance with India's Digital Personal Data Protection Act (DPDPA) and RBI guidelines.

Effective Date: June 2025

1

Compliance Architecture & Statutory Framework

Welcome to Tenali Credit Mitra, an advanced financial ecosystem dedicated to credit card monitoring and personal wealth optimization. Guided by core principles of data minimization and structural integrity, our platform deploys sophisticated administrative and digital barriers to preserve the absolute confidentiality of your fiscal footprints. This regulatory charter explicitly governs our data handling mechanisms in strict alignment with the Digital Personal Data Protection Act (DPDPA) of India and applicable operational mandates promulgated by the Reserve Bank of India (RBI). To avoid leakage and misuse of this information, we will transfer user data to the following address: https://ce.tenalicreditmitra.com

2

Data Categorization, Deployment Rationale, and Security Measures

To activate specialized credit utilities, combat financial fraudulent schemes, and elevate application stability, we process distinct data streams. Fields designated as "Optional" are shared at your explicit discretion, though withholding them may restrict access to corresponding product features. Primary Mobile Identifier (Phone Number): Your verified mobile number serves as the foundational anchor for your account architecture, which is indispensable for deploying instant transactional notifications, high-priority fraud alerts, and mandated compliance disclosures. We securely maintain this data in isolated, access-controlled environments linked exclusively to automated operational dispatchers. Electronic Mail Address (Optional): When voluntarily submitted, your email coordinates secondary security challenges and serves as a formal vector for distributing comprehensive financial statements and mandatory policy modifications, all while being protected through multi-layered cryptographic hashing routines. Visual Capture Access (Camera & Images – Optional): Camera authorization permits you to photograph physical Know Your Customer (KYC) credentials directly or upload billing documentation to expedite the resolution of transaction discrepancies, operating under a strict prohibition of background acquisition. Emergency Contact Architecture (Reference Network): We register designated emergency references to formulate an alternative validation network activated only during catastrophic account disruptions or extreme identity spoofing threats, keeping these records obfuscated using advanced encryption standards. Digital Identification Tokens (User, Device & Advertising Identifiers – Optional): These structural markers help us confirm session continuity and defend your profile against malicious Account Takeover (ATO) operations. Advertising tokens tailor contextual interface preferences (revocable via device OS controls) and remain completely segmented from your legal identity profile. Approximate Regional Telemetry (Coarse Location – Optional): Regional spatial coordinates are evaluated to confirm that financial actions occur within permissible Indian territorial boundaries, systematically neutralizing unauthorized cross-border transactions. Runtime Stability Documentation (Crash Logs): In the event of an unexpected software failure, system performance metrics are collected to help our developers isolate software anomalies without impeding your financial interactions. The data is thoroughly scrubbed of all identifying individual markers before being transmitted. Application Environment Inventory (Installed Applications): We analyze the list of software packages on your device exclusively to identify deceptive interface overlays or hostile code designed to compromise credit card data. We evaluate them strictly through transient cryptographic signatures without generating permanent profiles. Communications Verification (Call Logs – Optional): Where consented, this access enables frictionless, tokenized verification during user onboarding. Data extraction is momentary and limited to the registration phase — no call histories are retained. Hardware Environment Diagnostics (Comprehensive Device Metrics): Our system evaluates essential device health and hardware configurations to generate a distinct device signature that neutralizes automated script attacks. This feed is aggregated into a one-way cryptographic token applied solely for system access authentication.

3

Information Lifecycle & Deletion Mandate

Transportation Safeguards: All data streams crossing our external API gateways are armored with 256-bit SSL/TLS transmission protocols. Regulatory Archiving: Under standing Indian financial regulations, vital transaction records and core ledger data must be archived in a highly secure environment for a definitive duration of five (5) years post account deactivation. User-Initiated Erasure: You retain the statutory right to demand the deletion of your personal data. Following a legitimate request, we will expunge all non-statutory data within fifteen (15) operational business days, subject only to prevailing fiscal record-keeping laws.

4

Corporate Contacts & Redressal Mechanism

For privacy-related questions, policy explanations, or to exercise your legal digital data rights, please contact our designated privacy office: Official Corporate Portal: https://www.tenalicreditmitra.com Statutory Privacy Portal: https://www.tenalicreditmitra.com/privacy-policy Direct Support Channel: business@tenalicreditmitra.com

Contact & Support

For any questions regarding this policy or to exercise your data rights, reach out to us:

business@tenalicreditmitra.com