Privacy Policy and Data Protection Notice
Version 1.0 · Effective date: 21 September 2026 · Last updated: 21 September 2026
1. Who is responsible for your data
Kenstone Capital Debt Consulting Private Limited is the Data Fiduciary: it decides why and how personal data is processed. Contact: info@kenstonecapital.in (subject: "Privacy") · +91 80 6824 8827 · Sabari Complex, Field Marshal Cariappa Road, Shanthala Nagar, Ashok Nagar, Bengaluru 560025.
Grievance Officer (under the DPDP Act and the IT Rules): Shraddha Rathod, Head of B2B Collections, info@kenstonecapital.in (subject: "Grievance Officer"), +91 80 6824 8827.
Kenstone Credit and Kenstone Auctiondunia are separate entities with their own privacy policies. We do not share client or debtor data with them.
2. Whose data we process, what, and from where
| Data Principal | Data we process | Source |
|---|---|---|
| Client representatives (directors, finance heads, signatories, staff) | Name, designation, work phone, work email, signature, identity of authorised signatories, communications with us | You; your organisation |
| Debtor-business representatives (directors, partners, proprietors, accounts and finance staff, named contacts on invoices and correspondence) | Name, designation, business phone and email, registered-office and business addresses, communications with us (calls, messages, letters, visits), payment promises and disputes, publicly registered information (MCA, GST, Udyam), field-visit records | Our client (the creditor); public registries; you, when you speak to us; our own records of contact |
| Guarantors (only where a valid guarantee exists) | Name, contact details, the guarantee | Our client |
| Website visitors | Form entries (name, company, phone, work email, situation, optional bands, message), page URL and campaign parameters, IP address, device and usage data through analytics (see Cookie Policy) | You; your browser |
| Vendors, advocates, partners | Business contact details, engagement records, invoices | You |
| Job applicants | CV, contact details, interview notes | You |
We do not knowingly process data of children; our services are for businesses. We do not collect Aadhaar numbers from anyone. We do not ask debtors' representatives for identity documents.
Call recordings: we do not record calls at present. When recording is introduced we will update this policy and the Communications Notice first; recorded calls will then be kept with their date, time and the collector's identity. Field-visit records: time, place, persons met, outcome; photographs of premises only where the visit report needs them, never of individuals.
3. Why we process it and on what basis
| Purpose | Data Principals | Legal basis |
|---|---|---|
| Responding to an enquiry and assessing a possible engagement | Website visitors, client representatives | Consent given when you submit the form (DPDP s.6); performance of a contract at your request |
| Contracting, KYB, invoicing, tax and statutory records | Client representatives | Legitimate use — compliance with law (DPDP s.7(c)); contract |
| Verifying a claim and validating the debtor business | Debtor representatives | Legitimate use — the client, as the creditor, provides the data for the specified purpose of recovering its receivable (DPDP s.7(a) where the data was voluntarily provided to the client for that business relationship); our legitimate business need to perform the contract; publicly available information |
| Contacting the debtor business to recover a commercial debt | Debtor representatives | As above; performance of our contract with the client |
| Keeping records of calls, messages and visits (and call recordings, once introduced) | Debtor and client representatives | Evidence of the contact and of what was said; quality monitoring; complaint handling; DPDP s.7 and our legitimate need to prove conduct |
| Coordinating legal proceedings | Debtor representatives, client representatives | Compliance with law; establishing, exercising or defending legal claims |
| Handling complaints and rights requests | Everyone | Compliance with law |
| Website analytics | Visitors | Consent through the cookie banner |
| Security, fraud prevention, audit | Everyone | Legitimate use; compliance with CERT-In directions |
We do not sell personal data. We do not use personal data for advertising. We do not send marketing communications to debtors.
4. Client-supplied data and public-source data
Most data about debtor representatives reaches us from our client, who obtained it in the course of trading with the debtor. Our client warrants that it may share the data with us for collection. If you believe your data was shared with us without a proper basis, tell the Grievance Officer and we will pause and check. We also use public registries (Ministry of Corporate Affairs, GST, Udyam, court and tribunal cause lists) to confirm that a business exists and who represents it. We do not use pretexting, hacking, or unlawful access to telecom or bank data.
Work for banks and financial institutions. When we act for a bank or financial institution that has empanelled us — for example in enforcement of security interest under the SARFAESI Act — the lender decides why and how borrower and guarantor data is processed and is the Data Fiduciary for it. We process that data as the lender's Data Processor, only on its instructions, under its outsourcing contract and the Reserve Bank's guidelines, and we keep it separate from our other work. Requests about that data are best made to the lender; if you send one to us, we pass it to the lender within two working days and tell you we have done so.
5. Sharing
We share personal data only as needed for the purposes above:
- Our client (the creditor): reports on the account, records of contact, disputes raised and payment promises.
- Independent advocates and law firms engaged for a matter — ordinarily our empanelled law firm, TrueNorth Legal Partners, or an advocate the client chooses — under professional confidentiality.
- Courts, tribunals, arbitrators, mediators and Facilitation Councils, when a matter is filed.
- Service providers (Data Processors) that act on our instructions under written contracts: hosting (Hostinger); website delivery, DNS and security (Cloudflare); business email and telephony providers; WhatsApp Business (Meta Platforms) for messages on our business number; and analytics (Google Tag Manager and Google Analytics, only with your consent). Our collection and case-management platform is built and operated in-house. We update this list when a provider changes.
- Regulators, law-enforcement and authorities where the law requires.
- A successor to our business, on notice.
We do not share debtor data with the debtor's customers, suppliers, family or staff who are not connected to the account.
6. International transfers
Where our client is outside India, reports about the account — which include debtor-representative data — are sent to that client in its country. We limit such reports to what the client needs. Some of our service providers (including Hostinger, Cloudflare and Google) may store or process data in data centres outside India; where they do, the data stays protected by our contract with them and by this policy. The Central Government may restrict transfers to certain countries under DPDP s.16; we will comply with any such restriction.
7. Retention
We keep personal data only as long as needed for the purpose, for legal defence, and for periods the law requires. Our schedule:
| Record | Retention | Basis |
|---|---|---|
| Enquiries that do not lead to an engagement | 12 months from last contact | Minimisation |
| Client contracts, invoices, KYB | 8 years after the engagement ends | Companies Act s.128; Income-tax Act |
| Case files (claims, contact records, disputes, settlements, reports) | 8 years after case closure | Limitation and legal defence |
| Call recordings (once introduced) | 3 years after case closure, unless a complaint, dispute or legal hold requires longer | Evidence; proportionality |
| Field-visit records | With the case file | Evidence |
| Complaints and rights requests | 5 years after closure | Accountability |
| Website analytics data | As set by the analytics provider and our cookie settings (see Cookie Policy) | Consent |
| Processing logs required by the DPDP Rules | At least one year | DPDP Rules, 2025 r.8 |
| Job applications | 12 months if unsuccessful | Fairness |
When a period ends and no legal hold applies, data is deleted or anonymised and processors are instructed to do the same.
8. Security
We use role-based access, encryption in transit (HTTPS) for our website and platforms, logging of access, quarterly access reviews, removal of access on the day a person leaves, watermarking of downloaded reports, and a prohibition on debtor contact from personal devices. Our staff are trained on this policy and the Responsible Collection Policy. No system is perfectly secure; we work to reduce the risk.
9. Personal data breaches
If a breach affects your personal data we will notify you without undue delay with what happened, the likely consequences, what we are doing and whom to contact, and we will notify the Data Protection Board of India as the DPDP Rules require. We also report cyber-security incidents to CERT-In within the time its directions require.
10. Your rights
Under the DPDP Act you may: ask what personal data we hold about you, its source and with whom it has been shared; ask for correction, completion or updating; ask for erasure where the purpose is served and no legal retention applies; withdraw consent where processing is based on consent (this does not affect processing already done or processing that rests on another basis); nominate a person to exercise your rights if you die or are incapacitated; and complain to the Grievance Officer and, if unresolved, to the Data Protection Board of India. Under the IT Rules you may review and correct sensitive personal data we hold.
How to exercise them: the Privacy Rights Request form, or email info@kenstonecapital.in (subject: "Privacy"). We verify identity before responding. We respond within 30 days, and in every case within the period the law sets (currently 90 days under the DPDP Rules for grievances).
A debtor's representative asking us to erase the contact record does not extinguish the client's claim; we may retain what is needed to establish, exercise or defend legal claims, and we say so in our reply.
11. Correction and accuracy
We take reasonable steps to keep data accurate and complete for the purpose. If you tell us a detail is wrong, we correct it and, where we shared it, tell the recipient.
12. Automated processing and AI
Our collection platform ranks accounts by ageing, amount and payment behaviour to decide the order of follow-up, and flags whether a debtor entity appears functional from registry data. These are prioritisation tools; a named practitioner decides every contact, every proposal and every recommendation. No decision affecting you is made solely by automated means.
13. Children
We do not knowingly process the personal data of anyone under 18. If you believe we have, tell the Grievance Officer and we will delete it.
14. Cookies and analytics
See the Cookie Policy. Analytics runs only if you accept it on the banner; you can change your choice at any time from the footer link "Cookie settings".
15. Changes
We update this policy when our practices or the law change. The version and dates at the top change; earlier versions are available on request. Material changes affecting clients are notified to the client's nominated contact.
16. Contact and grievance
Data Fiduciary: Kenstone Capital Debt Consulting Private Limited, Sabari Complex, Field Marshal Cariappa Road, Shanthala Nagar, Ashok Nagar, Bengaluru 560025. Registered office: Lakshmi Nilaya, 1st Main, 2nd Cross, Ranganatha Extension, Gopala, Shivamogga 577205. Privacy contact: info@kenstonecapital.in (subject: "Privacy"). Grievance Officer: Shraddha Rathod, Head of B2B Collections, info@kenstonecapital.in (subject: "Grievance Officer"), +91 80 6824 8827.
Earlier versions of this document are available on request from info@kenstonecapital.in. Questions or complaints: Grievance Redressal Policy.

