Privacy Policy
Last updated · July 19, 2026
1. Introduction and scope
FinHub is a financial-infrastructure platform operated by Habilelabs Private Limited ("Habilelabs", "we", "us", "our"), a company incorporated in India with its registered office in Jaipur, Rajasthan. FinHub provides verification and KYC APIs, a DPDP compliance platform and AI voice-agent services to banks, NBFCs, insurers and fintech companies (together, "BFSI institutions").
This Privacy Policy explains how we collect, use, disclose, retain and protect personal data in connection with the FinHub website at www.finhub.habilelabs.io, demo and sales enquiries submitted through the website, and the FinHub platform and APIs used by our institutional customers.
It covers three groups of people: visitors to this website; individuals who request a demo, contact sales or subscribe to our communications; and individuals whose data is submitted to the FinHub platform by our customers for verification or compliance purposes. For that third category, we act on the documented instructions of the customer, and the customer's own privacy notice governs how the data was collected — this policy explains our role and safeguards.
This policy is intended to align with the Digital Personal Data Protection Act, 2023 (the "DPDP Act") and the rules framed under it, together with other laws applicable to us in India.
2. Personal data we collect
Contact and business details. When you request a demo, contact sales, register for an event or otherwise get in touch, we collect the information you provide: typically your name, work email address, phone number, organisation, designation and the content of your message. If you enter into a commercial relationship with us, we also collect billing and account-administration details.
Usage data. When you browse the website or use the platform, we collect technical information such as IP address, browser and device type, pages visited, referring pages and timestamps. On the platform, we additionally log API request metadata — such as request identifiers, endpoints called, response codes and timing — needed to operate, secure and bill the service.
Customer-submitted verification data. Our BFSI customers submit personal data to the platform to run verification, KYC and compliance workflows — for example, identifiers such as PAN, GST, CIN or Udyam numbers, bank account details for penny-drop verification, and related documents or attributes. We process this data solely on the instructions of the customer that submitted it, for the purposes set out in our agreement with that customer, and not for our own purposes. If you believe your data has been processed through FinHub by one of our customers, your primary point of contact is that institution, though you may also reach us using the contact details in Section 11.
We do not require you to provide more personal data than is needed for the purpose at hand, and we ask that you do not submit personal data of others through our website forms.
3. Purposes and lawful basis
We process personal data only where we have a lawful basis to do so under the DPDP Act and other applicable law.
Consent. Where you request a demo, subscribe to updates or otherwise share your details with us for a stated purpose, we process that data on the basis of your consent, for the specific purpose for which it was given. You may withdraw consent at any time using the contact details in Section 11; withdrawal does not affect processing already carried out.
Legitimate uses. Certain processing is carried out for legitimate uses recognised under Section 7 of the DPDP Act — for example, where you voluntarily provide data for a specified purpose, where processing is necessary to comply with a law or a judgment, or where it is necessary to respond to a legal obligation binding on us.
Performance of contract. Where we have a contract with you or your organisation, we process the personal data needed to deliver the services, administer the account, provide support and invoice for usage.
Compliance and security. We also process data where necessary to meet our legal and regulatory obligations, enforce our terms, detect and prevent fraud or abuse, and maintain the security of our systems.
4. How we use data
We use personal data to operate, maintain and improve the website and the platform; to respond to enquiries and provide the demos, information or support you request; to administer customer accounts and process billing; to send service communications and, where you have consented, product updates; to monitor for security incidents, fraud and misuse; and to comply with the laws and regulations that apply to us.
We do not sell personal data. We do not rent, trade or otherwise disclose personal data to third parties for their own marketing purposes. We do not use customer-submitted verification data to build our own profiles of individuals or for any purpose other than delivering the contracted services.
5. Cookies and analytics
The website uses a small number of cookies and similar technologies. Functional cookies are used to make the site work — for example, remembering preferences and maintaining session state. We may also use analytics to understand how the website is used in aggregate — such as which pages are visited and how visitors arrive — so we can improve content and performance. Analytics data is used in aggregated or pseudonymised form and is not used to identify individual visitors.
You can control or delete cookies through your browser settings. Disabling cookies may affect some site functionality, but the substantive content of the website remains accessible without them.
6. Data retention
We retain personal data only for as long as it is needed for the purpose for which it was collected, or for as long as we are required to retain it under applicable law, whichever is longer. When data is no longer needed, we delete it or irreversibly anonymise it.
Enquiry and marketing data is retained while the enquiry or relationship is active and for a reasonable period afterwards, unless you ask us to erase it earlier. Account and billing records are retained as required by Indian tax, accounting and corporate law.
Verification data processed on behalf of our BFSI customers is retained in accordance with the customer's instructions and the applicable agreement. Where our customers are subject to record-keeping duties — for example under the Prevention of Money Laundering Act or directions issued by the Reserve Bank of India — retention periods are configured to support those obligations. On termination of a customer agreement, customer-submitted data is returned or deleted as the agreement provides.
7. Data sharing and processors
We share personal data only in limited circumstances. Service providers: we use a small number of vetted service providers — such as cloud-infrastructure, communications and analytics providers — to help us run the website and the platform. Each is bound by contract to process data only on our instructions, to keep it confidential and to apply appropriate security safeguards.
Data sources: when performing a verification requested by a customer, relevant identifiers are transmitted to the applicable government or authorised data source (for example, a registry or bank-account verification rail) to obtain the verification result. This is inherent to the service and occurs only on the customer's instruction.
Legal requirements: we may disclose personal data where required by law, regulation, legal process or an order of a court, tribunal, regulator or other government authority with jurisdiction over us. Where permitted, we assess such requests for validity and scope before responding.
Corporate events: if Habilelabs is involved in a merger, acquisition or reorganisation, personal data may be transferred as part of that transaction, subject to safeguards consistent with this policy.
We do not share personal data with third parties for their own advertising or marketing purposes.
8. Cross-border transfers
FinHub is built for Indian financial institutions, and data processed through the platform is handled and stored on India-region cloud infrastructure. Verification results, consent records and audit logs remain within Indian data-centre regions.
If any personal data ever needs to be transferred outside India — for example, to a service provider operating from another jurisdiction — such transfer will be made only as permitted under the DPDP Act, any restrictions notified by the Central Government, and any sectoral data-localisation requirements applicable to our customers, and subject to contractual safeguards.
9. Security
We apply technical and organisational security measures designed to protect personal data against unauthorised access, disclosure, alteration and loss. Data in transit is protected with TLS, and data at rest — including backups — is encrypted. Access to production systems and personal data is restricted on a least-privilege, need-to-know basis and is subject to authentication controls and periodic review.
Platform activity — including API calls, consent decisions and administrative actions — is written to audit logs so that access and changes are traceable. Personal identifiers are masked in logs and internal tooling by default. Our security practices are described in more detail on our Security page.
No system can be guaranteed to be absolutely secure. If we become aware of a personal data breach affecting you, we will notify the affected individuals and the relevant authorities as required under applicable law.
10. Your rights under the DPDP Act
As a Data Principal under the DPDP Act, you have rights in relation to personal data for which we act as the Data Fiduciary — broadly, the data described in Section 2 that you provide to us directly.
Access: you may request a summary of the personal data we hold about you and the processing activities undertaken with it. Correction and erasure: you may ask us to correct inaccurate or incomplete data, update it, or erase data that is no longer necessary for the purpose for which it was processed, unless retention is required by law. Grievance redressal: you have the right to have your grievances addressed through the mechanism described in Section 11. Nomination: you may nominate another individual to exercise your rights in the event of your death or incapacity.
To exercise any of these rights, write to us at info@habilelabs.io with enough detail for us to locate your data and verify your identity. We respond within the timelines prescribed under applicable law. Withdrawal of consent is as simple as the manner in which consent was given.
Where FinHub processes your data on behalf of one of our BFSI customers, that customer is the Data Fiduciary and requests should be directed to them; we will support our customer in fulfilling your request as our agreement with them requires, and will forward any request we receive to the relevant customer where we can identify them.
11. Grievance Officer and contact
If you have a question, concern or complaint about this policy or our handling of personal data, please contact our Grievance Officer:
Grievance Officer, Habilelabs Private Limited, Sec-93 Agarwal Farm, Mansarovar, Jaipur, Rajasthan 302020, India. Email: info@habilelabs.io.
We acknowledge and respond to grievances within the timelines prescribed under applicable law. If you are not satisfied with our response, you may escalate your complaint to the Data Protection Board of India in accordance with the DPDP Act, once the Board's complaint mechanism is operational for your grievance.
12. Children's data
FinHub is a business-to-business service directed at financial institutions and their professional staff. The website and platform are not directed at children, and we do not knowingly collect or process personal data of individuals under the age of 18 for our own purposes. If you believe a child's data has been provided to us, please contact the Grievance Officer and we will take appropriate steps to delete it.
Where our customers' regulated workflows involve data of minors — for example, a guardian-operated account — the customer, as Data Fiduciary, is responsible for obtaining verifiable consent as required under the DPDP Act, and we process such data only on their instructions.
13. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, technology or legal requirements. When we do, we will revise the "Last updated" date at the top of this page and, for material changes, take reasonable steps to bring the change to your attention — for example, by a notice on the website or by email to registered contacts.
Your continued use of the website or the services after an updated policy takes effect indicates that you have read the revised policy. We encourage you to review this page periodically.