This Privacy Policy outlines HDFC Bank Limited’s approach to processing of Data.
HDFC Bank is committed to treating data privacy seriously. It is important that you know exactly what we do with the personal data you and others provide to or for us, why it is processed and what it means to you. Please read this Privacy Policy carefully.
Definitions
The following capitalised terms shall have the meanings assigned to them as under:
“Bank” or “HDFC Bank” shall have the meaning as ascribed to the term in the first paragraph of this Privacy Policy.
“Covered Person(s)” or “You” shall have the meaning as ascribed to the term in the ‘Applicability’ section of this Privacy Policy.
“Data” shall have the meaning as ascribed to the term in the ‘Data’ section of this Privacy Policy.
“Derivation” shall have the meaning as ascribed to the term in the ‘Data’ section of this Privacy Policy.
“Derivative Data” shall have the meaning as ascribed to the term in the ‘Data’ section of this Privacy Policy.
“Processing Entity” shall have the meaning as ascribed to the term in the ‘Who we share your Data with?’ section of this Privacy Policy.
“Product(s)” shall have the meaning as ascribed to the term in the ‘Applicability’ section of this Privacy Policy.
“Specified Purposes” shall collectively mean, credit assessment, risk assessment, risk analysis, obtaining credit information reports, scores, scrubs, fraud checks, fraud detections, fraud prevention, detecting and preventing crime including crime/ terror funding, detecting malpractices or discrepant documents or information, prevention of misuse, assessment of credit worthiness, financial standing, due diligence, background check, physical and other inspections, verifications, obtaining any reports for any of the above, KYC/ AML checks, customer service, monitoring, collections, default detection, default prevention, default investigation, recovery, any legal proceedings, actions, enquiries, investigations, pursuing any remedies, enforcing rights, reporting including credit reporting, KYC reporting, default reporting, filing, perfections etc., whether any of these are undertaken internally or through any Processing Entity or through a combination of multiple options.
Applicability
This Privacy Policy applies to personal data of any natural person (“Covered Person(s)” or “You” or any cognate variations thereof) which is processed by or for HDFC Bank, whether in physical or electronic mode. This Privacy Policy applies in relation to all products, services and/or businesses [of our own/ of subsidiaries/ affiliates, or where we/ subsidiaries/ affiliates distribute, refer or act as agent or act as a sponsor bank or a Payment Service Provider (PSP) bank etc. in relation to any products or services, including any credit facilities, credit cards, debit cards, forex instruments, cheques, any other payment instruments, remittance services (both inward and outward), currency exchange services, prepaid payment instruments, loans, any other credit transactions or products or services, insurance products, investments, wealth management, estate management, credit assessment, financial products, advisory services, investment advisory services, capital markets, demat accounts, trading accounts, savings or current accounts, any other accounts, deposits, transfers, referrals, cash management, payment services and products, payment gateway, wallets, merchant acquiring, PSP services, Third Party Application Provider (TPAP) services, Unified Payments Interface (UPI), Point of Sale (POS) services, collections, distributions, agencies, trusts etc. (collectively “Product(s)” including where the initiation of any transaction is not directly with us but is with a relevant Processing Entity like in case of a UPI transfer through a TPAP where your account is not with us but we are a PSP bank)], intermediaries or consultants, Products as applicable to the Covered Persons, whether we are in direct relationship or indirect relationship through any other intermediary/ entity, vis-à-vis you, as also if you are an authorised signatory or authorised person or representative of a non-individual applicant/ customer/ user of any services, whether direct or indirect. Your Products’ terms and conditions will cover specific matters in addition to this Privacy Policy and this Privacy Policy does not limit any of those specific matters or any other consent that you may have given or may give to or for the benefit of HDFC Bank. Therefore, please also read such specific terms and conditions in relation to the Products and such other consents, wherever applicable.
Who we are
Throughout this document, “we”, “us”, “our” and “ours” or any cognate variations thereof refer to HDFC Bank.
“HDFC Bank” or “Bank” means:
HDFC Bank Limited having its registered office at Senapati Bapat Marg, Lower Parel (West), Mumbai 400013, Mumbai, India.
Website: https://www.hdfcbank.com/
Our contact details are given at the end of this Privacy Policy.
Data
The personal data collected or received falls into various categories as under:
Out of the aforesaid data points, the following are ‘sensitive personal data or information’:
Provided that, any information that is freely available or accessible in public domain or furnished under the Right to Information Act, 2005 or any other law for the time being in force shall not be regarded as ‘sensitive personal data or information’.
Any of the aforesaid data (whether personal data or sensitive personal data or information), information, know your customer (KYC) related data, any derivative thereof ("Derivative Data”) like any credit scores or behavioural projections, profiling, analytical results, reports (prepared by us or others) including through any algorithms, analytics, software, automations, profiling etc., and whether such derivative is from the information collected from you or in combination with any other information sourced from any other person, database or source whether by us or others, shall collectively be referred to as “Data” and any part of the process relating to arriving at the Derivative Data as above, whether through internal or external sourcing, shall be referred to as “Derivation”.
When and how your Data is collected?
Your Data may be collected or processed through any of the following:
By accepting this Privacy Policy or by applying for or using any Product (including where the initiation of any transaction is not directly with us but is with a relevant Processing Entity like in case of a UPI transfer through a TPAP where your account is not with us but we are a PSP bank), you agree that any person who submits any Data or part thereof to us or from whom we source the same (including Derivation), shall be deemed to have been authorised by you to submit such Data to us and you hereby further authorise the processing of any such Data by us or for us, for any of the purposes mentioned in this Privacy Policy.
How we process your Data?
Whether we’re using it to confirm your identity, to help in the processing of an application for any Products or to improve your experiences with us, your Data is always handled with care and the principles outlined in this Privacy Policy are always applied.
Purposes of processing Data
The processing of the Data may be done by us or any of the Processing Entities for any of the following purposes, and you agree and consent to the same:
You agree that HDFC Bank may engage with any Processing Entity, for any of the aforesaid purposes or part thereof for any incidental or ancillary purposes, and may accordingly share Data with any of them and allow them to further process/ share the same, for the said purposes.
Automated processing
The way your personal information is analysed in relation to the Products including applications, credit decisions, determining your eligibility for the Products, may involve automated profiling and decision making, this means that your Data may be processed using software that is able to evaluate your personal aspects and predict risks or outcomes as also where the decision making may be automated.
We may also carry out automated anti-money laundering and sanctions checks. This means that we may automatically decide that you pose a fraud or money laundering risk if the processing reveals your behaviour to be consistent with money laundering or known fraudulent conduct, is inconsistent with your previous submissions, or you appear to have deliberately hidden your true identity.
Who we share your Data with?
We may share the Data with the following persons and/or in the following circumstances:
The Data may also be shared by any of the aforesaid entities/ persons with their service providers, consultants, agents, subsidiaries, affiliates, co-brand entity/partner, distributors, selling/ marketing agents, any partners, fintech companies, other players/ intermediaries in any ecosystem of which we are a part, TPAPs (for whom we act as PSP bank), collaborators, co-lenders, co-originators, merchants, aggregators, lead generators, sourcing entities, clients, customers or other persons with whom we have a tie-up or contract for any products or services etc. for any of the aforesaid purposes or any purposes incidental or necessary thereto. Any person or entity with whom the Data or any part thereof is shared by us or further shared by any of them, for any of purposes under this Privacy Policy, shall be referred to as a “Processing Entity”. [Wherever the Data is shared with any Processing Entity (with whom we have direct contract), we will through such contracts restrict the processing by them of such Data for the aforesaid purposes.]
For further information, please refer to the Products’ specific terms and conditions and application form.
Period of storage of the Data
We will keep the Data we collect on our systems or with third parties for as long as required for the purposes set out above or even beyond the expiry of transactional or account based relationship with you: (a) as required to comply with any legal and regulatory obligations to which we are subject, or (b) for establishment, exercise or defence of legal claims, or (c) as specified in this Privacy Policy, or (d) in accordance with specific consents.
Reasonable security practices and procedures
HDFC Bank is ISO 27001:13 compliant. We seek to use reasonable organizational, technical and administrative measures to protect Data within our organization. However, if you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the ‘How to contact us’ section.
Links/ Re-direction to Other Websites/ Platforms
From time to time, our website/ webpage/ platform/ apps may contain links or have a mechanism of re-direction to and from websites/ webpages/ platforms/ apps of other networks, advertisers, affiliates and Processing Entities. If you follow a link or such re-direction to any of these websites/ webpages/ platforms/ apps, please note that these websites/ webpages/ platforms/ apps may have their own privacy notices and that we do not accept any responsibility or liability for any such notices. Please check such notices, where available, before you submit any Data to these websites/ webpages/ platforms/ apps.
Right to review
Please note that the accuracy of the Data provided to us is essential, among others, for the provision of Products to you. It is therefore mandatory that you ensure the accuracy and completeness of all Data disclosed or shared. Without prejudice to any rights and remedies of the Bank under any contract in this regard, you shall be able to review the Data that you had provided and correct or amend as feasible any such Data which you find to be inaccurate or deficient. You may do this by following the process prescribed by HDFC Bank in this regard. For knowing the process you may contact HDFC Bank as per the section ‘How to contact us’ under this Privacy Policy.
Provided that HDFC Bank shall not be responsible for the authenticity of the Data supplied by you to Bank or any other person acting on behalf of the Bank.
Cookies
We may use cookies and similar technologies on our websites, mobile apps, and in our emails. Cookies are text files that get small amounts of information, which your computer or mobile device stores when you visit a website or use a mobile app. For more details in this regard you may please refer to our separate Cookie Policy available on our website.
How to contact us
You may contact our Privacy Contact at [email protected]
Changes to this Privacy Policy
Our products, services, facilities, features, functionalities, and nuances thereof change constantly and our Privacy Policy will change also. You will be responsible for apprising yourself about the Privacy Policy and change, if any, on each use of our website or Apps, platforms or while applying for or making service requests for any Product or during usage of any Product or usage of any functionality. Without limiting your responsibility to keep yourself updated as above, we may update you that a change has been made through any channels of communication including in App notifications, general banner on website, sms, e-mail, social media messages, etc. The changed Privacy Policy shall be effective as soon as it is published/posted/hosted on our website/respective Apps/platforms. If you use our website or Apps, platforms or make any application/request for any Product or use any Product or make any service requests for or during usage of any Product or if you use any functionality provided by or for us, such act of any of aforesaid uses shall by itself amount to your acceptance of the Privacy Policy with changes, if any.
This Privacy Policy shall be governed by the laws of India and any disputes arising out of or in relation to this Privacy Policy shall be subject to the jurisdiction of courts/ tribunals of Mumbai, India.
This Privacy Notice outlines HDFC Bank Limited’s (“HDFC Bank”) approach to data protection to fulfil its obligations under the EU General Data Protection Regulation 2016/679 ("GDPR"). This Privacy Notice applies to personal data of the Covered Person(s) which is processed by or for HDFC Bank as a controller, whether in physical or electronic mode. In this Privacy Notice, the expressions ‘personal data’, ‘data subject’, ‘controller’, ‘processor’ and ‘processing’ shall have the meanings given to them in the GDPR.
HDFC Bank is committed to treating data privacy seriously. It is important that you know exactly what we do with the personal data you and others provide to us, why we process it and what it means to you. Please read this Privacy Notice carefully to understand our views and practices regarding your personal data and how we will treat it.
Data Privacy Matters
This Privacy Notice applies in relation to all our products and services as applicable to the Covered Persons. Your product or service terms and conditions will specify which of our businesses is providing the relevant product or service to you. If you are a customer of one of these businesses, please also read the Data Privacy Notice applicable to such respective businesses. If you have any questions about how your personal data is processed, please contact our Privacy Contact.
Who we are
Throughout this document, “we”, “us”, “our” and “ours” refer to HDFC Bank.
HDFC Bank means:
HDFC Bank Limited having its registered office at Senapati Bapat Marg, Lower Parel (West), Mumbai 400013, Mumbai, India and includes its branches in and outside India and subsidiary companies.
Website : https://www.hdfcbank.com/
Our contact details are given at the end of this Privacy Notice. Should you need further details about HDFC Bank, please visit the about us page in our website.
Who is covered under this Notice (Covered Persons)?
Any natural person in relation to whose personal data (to the extent processed by or for HDFC Bank), the GDPR applies, shall be to the extent of such personal data and such processing be the "Covered Person(s)" or “You”.
The information we collect about you
The information we collect falls into various categories as under:
When and how we collect personal data about you?
Personal data about you is gathered or collected:
How we process your Personal Data?
Whether we’re using it to confirm your identity, to help in the processing of an application for a product or service or to improve your experiences with us, your personal data is always handled with care and the principles outlined in this Data Privacy Notice are always applied.
Lawfulness and Purposes of the processing
The lawfulness and legal basis for obtaining, processing personal data about you will be one or more of the following:
The table below sets out the purposes for which we use your personal data and our legal basis for doing so. Where we are relying on a legitimate interest, these are also set out below
What we use your personal data for | The legal basis for doing so (one of more under each sub-heading) |
---|---|
|
|
|
|
|
|
|
|
|
|
When we process personal data to meet our legitimate interests, we put in place robust safeguards to ensure that your privacy is protected and before collecting, we ensure that our legitimate interests are not overridden by your interests or fundamental rights and freedoms.
We will send you messages by post, telephone, text, email and other digital methods, including for example via our ATMs, mobile applications, push notifications, or online banking services (and new methods that may become available in the future). These messages may be:
The way we analyse personal information in relation to our products and services including applications, credit decisions, determining your eligibility for the products or services, may involve automated profiling and decision making, this means that we may process your personal data using software that is able to evaluate your personal aspects and predict risks or outcomes as also where the decision making may be automated.
We may also carry out automated anti-money laundering and sanctions checks. This means that we may automatically decide that you pose a fraud or money laundering risk if the processing reveals your behaviour to be consistent with money laundering or known fraudulent conduct, is inconsistent with your previous submissions, or you appear to have deliberately hidden your true identity.
If we, or a fraud prevention agency, determine that you pose a fraud or money laundering risk:
You expressly acknowledge that the automated decision is necessary for entering into or performance of contract and/or you explicitly consent to such automated decision making, hence you subject to even the decisions which are solely based on automated processing. You have rights in relation to automated decision making: if you want to know more please contact us using the details set out in the Contact Us section.
Recipients: Who we share your personal data with:
We only share your personal data with the following persons and/or in the following circumstances,and only as may be necessary:
For further information, please refer to our product specific terms and conditions and application form.
Period of storage of your personal data
We will keep the personal data we collect about you on our systems or with third parties for as long as required for the purposes set out above or even beyond the expiry of transactional or account based relationship with you: (a) as required to comply with any legal and regulatory obligations to which we are subject or (b) for establishment, exercise or defence of legal claims.
Implications of not providing personal data or Withdrawing Consent
Sharing personal data with us is in both your interest and ours.
We need your personal data in order to:
When we request personal data, we will inform you if providing it is a contractual requirement, a statutory requirement or not, and whether or not we need it to comply with our legal obligations.
You may choose not to share personal data or withdraw consent, but doing so may limit the services we are able to provide to you (unless consent is not the only legal basis for processing and there are other legal basis as well), particularly as under.
However, if you withdraw your consent, it will not affect the lawfulness of processing based on your consent before its withdrawal or the other legal basis which we may have for such processing.
Processing your personal data outside the EEA
HDFC Bank is incorporated and regulated in India, its overseas branches are regulated by host country regulations and subsidiaries are governed under applicable laws. As such, your personal data is stored on secure systems within HDFC Bank premises within India and with providers of secure information storage in India. Further, we may transfer or allow the transfer of personal data about you and your products and services with us to our service providers and other organisations outside the European Economic Area (EEA), with adequate safeguards to ensure your personal data remains adequately protected.If you need copy of safeguards provided to transferred personal data, please notify us in accordance with the “How to contact us?” section below. These jurisdictions and countries outside EEA may have different and less stringent laws relating to the degree of confidentiality afforded to the personal data and that such information can become subject to the laws and disclosure requirements of such countries, including disclosure to governmental bodies, regulatory agencies and private persons, as a result of applicable governmental or regulatory inquiry, court order or other similar process. In addition, a number of countries have agreements with other countries providing for exchange of information for law enforcement, tax and other purposes.
For example, we may process payments using third parties (including other financial institutions such as banks and the worldwide payments system operated by the SWIFT organisation)
How do we secure your Personal data?
HDFC Bank is ISO 27001:13 compliant. We seek to use reasonable organizational, technical and administrative measures to protect Personal data within our organization. However, if you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “How to contact us?” section below.
How to exercise your information rights (including the right to object)?
You have the following rights, in accordance with and subject to the qualifications and provisions under GDPR:
Right to object
You shall have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which processing is based on necessity for the purposes of legitimate interests pursued by us or third party, including profiling. Upon such exercise of your right, we shall no longer process the personal data unless we demonstrate compelling legitimate grounds: (a) for the processing which override your interests, rights and freedoms or (b) for the establishment, exercise or defence of legal claims.
Where personal data are processed for direct marketing purposes, you shall have the right to object at any time to processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. If you object to this use, we will stop using your information for direct marketing purposes.
If you exercise any of the aforesaid rights, in most instances, we will respond within one calendar month. If we are unable to deal with your request fully within a calendar month (due to the complexity or number of requests), we may extend this period by a further two calendar months. Should this be necessary, we will explain the reasons.However, where we have reasonable doubts concerning your identity, we may request the provisions of additional information necessary to confirm your identity. Ordinarily, we will not charge a fee for the exercise by you of any rights as above. However, we may charge a reasonable fee if your request for access is found to be excessive or unfounded. Alternatively, we may refuse to comply with the request in such circumstances.
If you make your request electronically, we will, where possible, provide the relevant information electronically unless you ask us otherwise.
Links to Other Websites
From time to time, our website may contain links to and from websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites may have their own privacy notices and that we do not accept any responsibility or liability for any such notices. Please check these notices, where available, before you submit any personal data to these websites
Children
If you are a parent of a child under 16 (or such age as applicable for GDPR purposes in the respective EU Member States), you give your consent or authorise the consent if you wish your child to access HDFC Bank Services.
In How to contact us
If you have any questions about how your personal data is gathered, stored, shared or used, or if you wish to exercise any of your information rights, please contact our Privacy Contact at [email protected]
Phone Banking: +91 22 67606161
Changes to this notice
We will update this Data Privacy Notice from time to time. Any changes will be communicated to you and made available on this page and, where appropriate, notified to you by SMS, e-mail or when you log onto website or start one of our mobile apps.
Dated: 11 Oct-2022
Date of most recent update: 1st July 2022.
PLEASE READ THIS POLICY CAREFULLY BEFORE USING OUR WEBSITES
This policy explains how cookies are used on our websites.
This policy may be amended from time to time and the latest policy will be posted on this page.
By using our websites, you agree that we can place cookies on your device. Please be aware that some of our services will not function if your browser or device does not accept our cookies.
Please note that where we have another type of presence on a site owned by a third party, such as a page or handle on a social media site, that third party’s privacy policy and terms of use, rather than this Policy, will govern, unless specifically stated otherwise.
What are cookies?
Cookies are text files containing small amounts of information, which your computer or mobile device downloads when you visit a website. When you return to websites — or visit other websites that use the same cookies — they recognise these cookies and therefore your browsing device.
Cookies do lots of different jobs, like helping us understand how this website is being used, letting you navigate between pages efficiently, remembering your preferences, and generally improving your browsing experience. Cookies can also help ensure marketing you see online is more relevant to you and your interests.
You can learn about the cookies we use and how to manage them below.
What type of cookies Bank use?
The type of cookies used on most websites can generally be put into 1 of 4 categories: Strictly Necessary, Performance, Functionality and Targeting.
Strictly Necessary Cookies
These cookies are essential, as they enable you to move around the website and use its features, such as accessing secure areas. Without these cookies, services you've asked for can't be provided. These cookies don’t gather information about you that is used for marketing or remembering where you've been on the internet.
Performance Cookies
These cookies collect information about how you use a website, for example which pages you go to most often and if you get error messages from certain pages. These cookies don't gather information that identifies you. All information these cookies collect is anonymous and is only used to improve how a website works.
These cookies are not used to target you with online marketing. Without these cookies we can't learn how our website is performing and make relevant improvements that could better your browsing experience.
Functionality Cookies
These cookies allow a website to remember choices you make (such as your user name, language or the region you're in) and tailor the website to provide enhanced features and content for you.
Without these cookies, a website cannot remember choices you've previously made or personalise your browsing experience.
Targeting Cookies
These cookies are used to tailor marketing to you and your interests. They are also used to limit the number of times you see an advertisement as well as help measure the effectiveness of the advertising campaign. They remember that you have visited a website and this information may be shared with other organisations such as advertisers. Although these cookies can track your visits to other websites, they don’t usually know who you are.
Without these cookies, online advertisements you encounter will be less relevant to you and your interests.
What happens if I disable cookies?
If cookies are disabled on your computer, tablet or mobile your experience on the website may be limited. For example, you may not be able to browse freely or use specific functions or features.
How do I disable/enable cookies?
To disable or enable cookies you will need to change some settings on your Internet browser.
We have provided step-by-step guides for the major desktop browsers below.
For information on how to manage cookies on your tablet or mobile please consult your documentation or online help files.
Google Chrome
In the settings menu, select 'show advanced settings' at the bottom of the page
Select the 'content settings' button in the privacy section
In the page that appears tells you can manage and/or clear stored cookies.
Firefox
In the menu, select 'options'
Select the privacy tab in the options box
From the dropdown choose, 'use custom settings for history'. This will present the options for cookies and you can choose to enable or disable cookies.
Internet Explorer 6+
In the tools menu, select 'Internet options'
Click the privacy tab
You will see a privacy settings slider which has six settings that allow you to control the number of cookies that will be placed: Block All Cookies, High, Medium High, Medium (default level), Low, and Accept All Cookies.
Safari
In the settings menu, select the 'preferences' option
Open the privacy tab
Select the option you want from the 'block cookies' section
Any other browser
For information on how to manage cookies via other desktop browsers please consult your documentation or online help files.
What happens to cookies that have been downloaded in the past?
If you've disabled through your browser we may still use information collected from existing cookies, but we'll stop using the disabled cookies to gather any further information. For information on deleting stored cookies in your browser please visit the All About Cookies website.
SDKs Information We Collect and Services We Provide
If you use our apps (e.g. mobile application which integrates with Advertising services), we may use SDK’s to gather non PII information. At no point will these SDKs capture any personally identifiable information. We refer to the information we collect from our SDKs as the ‘SDKInformation .” The SDK Information includes (or may include) the following:
1. Information Collected About End Users by Our SDKs
As noted above, we refer to all of the above collectively as the “SDKInformation .”
2. How We Use the SDK Information
We use the SDK Information to provide following Services to our users:
3. How and Why We Share the SDK Information.
We share the SDK Information with service providers, to perform any of the activities set forth in Section 2.
HDFC Bank does not share SDK information with third parties except those who process the data on behalf of HDFC Bank.