Privacy Policy

By accessing the "Haycode" mobile and/or web applications ("Apps") (collectively, the "Platforms") and By utilizing the services we provide ("Services"), you agree to be bound by these terms and conditions Privacy Policy.

By mere access to the Platform or any part thereof, you signify your assent to this Privacy Policy and consent to the processing of your personally identifiable information (Personal Information, Sensitive Personal Data or Information) to GRIFFIN MICROFINANCE COMPANY LIMITED("we" or "our" or "us" or "Haycode"). This Privacy Policy is incorporated into and subject to the Terms of Use of the Platform.

For the purpose of this Privacy Policy, the users of the Services may be customer/applicant / borrower/ consumers, or any other persons using Services or accessing our Platform ("user" or "you" or "your").

Details of the privacy policy

Account

means the unique account you create to access our Services or parts of our Services.

Affiliate

means an entity that controls, is controlled by, or is jointly controlled by a party, where "control" means ownership of 50% or more of shares, equity or other securities entitled to vote for directors or other governing bodies.

Application

means that you download and use a software program named "Haycode" on any electronic device.

Device

means any device that can access the Service such as a computer, a cellphone or a digital tablet.

Personal Data

is any information that relates to an identified or identifiable individual.

Service

represents the current application.

Service Provider

means any natural or legal person who processes this data on behalf of the Company. Refers to third-party companies or individuals employed by the Company to facilitate the Services, provide the Services on behalf of the Company, perform the Services in connection with the Services, or assist the Company in analyzing the use of the Services.

Usage Data

means data collected automatically, or data generated by using the Services, or data generated from the service infrastructure itself (for example, the duration of page visits).

You

means the individual accessing or using the Service, or the Company, or other legal entity on whose behalf such individual is accessing or using the Service.

KYC

means know your customer, that is to fully understand your customer, conduct a comprehensive review of the customer, understand the legitimacy of their identity, and prevent fraud.

Collection of personal information of users

Get a better understanding of who you are with the app and ensure your users meet their credit needs. Therefore, before you submit your application, your authorization will be required to collect "Contact" and "SMS" information and upload it to "Haycode.com". We are committed to encrypting data and ensuring the security of information using secure data transfer protocols. Feel free to use it. If you do not agree, we will not do this, and the application will not be able to provide you with normal services and exit the application.

In short, to create an account on the platform, you must provide us with some basic information required to customize our service. The information that needs to be collected includes:

We highlight required fields and optional fields. You can fill in the information based on your actual needs.

We also collect user account data, including email addresses and user public profile information such as name, photo, ASID, depending on the social media or web platform you use, such as Google or Facebook to log into an app. This information is part of accessing our services and is also used to automatically populate relevant fields during the application's interface process.

When you establish a free account with us, we will further collect additional identifiable information such as Your transaction records, details, etc. on the platform. Also you can browse some parts of our platform Without the above-mentioned registered members, certain activities (such as in platform) is only available after registration, you should provide the above information when registering registration process.

The platform will clearly display the personal information it collects from you that you can choose not to provide. However, this will limit the services available to you on the platform.

Collection Of Device Information

Description of requested permissions:

_android.permission.access_coarse_location_

_android.permission.read_phone_state_

We collect and monitor the information about the location of your device to provide serviceability of your loan application, to reduce risk associated with your loan application and to provide pre-approved customised loan offers. This also helps us to verify the address, make a better credit risk decision and expedite KYC process.

Information the App collects, and its usage, depends on how you manage your privacy controls on your device. When you install the App, we store the information we collect with unique identifiers tied to the device you are using. We collect information from the device when you download and install the App and explicitly seek permissions from You to get the required information from the device.

The information we collect from your device includes the hardware model, build model, RAM, storage unique device identifiers like IMEI, serial number, SSAID SIM information that includes network operator, roaming state, MNC and MCC codes, WIFI information that includes MAC address and mobile network information to uniquely identify the devices and ensure that no unauthorized device acts on your behalf to prevent frauds.

We collect information about your device to provide automatic updates and additional security for your Account is not in use on someone else's device. Additionally, this information provides us with valuable feedback Your identity as the device owner and your device behavior, allowing us to improve our service and provide you with an enhanced customized user experience.

Collection Of Camera/Image Description of requested permissions:

_android.permission.camera_

_android.hardware.camera_

_android.hardware.camera.autofocus_

We require camera access to scan and capture the required KYC documents thereby allowing us to auto-fill relevant fields.

As a part of our KYC process, we require access to your camera to enable you to initiate your KYC process. This permission allows us or our authorised agents to perform your Photo KYC while also taking screenshots of your original Officially Verified Documents that you present during your Photo KYC process. Photo KYC enables you to complete your KYC digitally, smoothly and efficiently. Your photo shall be recorded and retained for regulatory purpose along with original Official Verified Documents. We will delete the images after we have determined your risk profile.

CALL RECORDS

_READ_CALL_LOG_

In order to ensure that real users use the application in a normal environment, instead of using a simulator for fraudulent activities, we need to obtain your call records, including phone number, name and call time. Call log information will not be shared with third parties.

Collection Of Installed Applications Description of requested permissions:

We collect a list of the installed applications information which includes the application name, package name, installed time, updated time, version name and version code of each installed application on your device to assess your credit worthiness and enrich your profile with pre-approved customized loan offers. We will delete the images after we have determined your risk profile.

Link To Third-party Sdk

The App has a link to a registered third party SDK which collects data on our behalf and data is stored to a secured server to perform a credit risk assessment. We ensure that ourselves /our third party service provider takes extensive security measures in order to protect your personal information against loss, misuse or alteration of the data.

Our third-party service provider employs separation of environments and segregation of duties and have strict role-based access control on a documented, authorized, need-to-use basis. The stored data is protected and stored by application-level encryption. They enforce key management services to limit access to data.

Furthermore, our registered third party service provider provides hosting security – they use industry-leading anti-virus, anti-malware, intrusion prevention systems, intrusion detection systems, file integrity monitoring, and application control solutions.

Collection Of Other Non-personal Information

We automatically track certain information about you based upon your behaviour on our Platform. We use this information to do internal research on our users’ demographics, interests, and behaviour to better understand, protect and serve our users and improve our services. This information is compiled and analysed on an aggregated basis. We also collect your Internet Protocol (IP) address and the URL used by you to connect your computer to the internet, etc. This information may include the URL that you just came from (whether this URL is on our Website or not), which URL you next go to (whether this URL is on our Website or not), your computer browser information, and your IP address.

Cookies are small data files that a Website stores on Your computer. We will use cookies on our Website similar to other lending websites / apps and online marketplace websites / apps. Use of this information helps Us identify You in order to make our Website more user friendly. Most browsers will permit You to decline cookies but if You choose to do this it might affect service on some parts of Our Website.

If you choose to get a loan through the Platform, we collect information about your applying behavior.

We retain this information as necessary to resolve disputes, provide customer support and troubleshoot problems as permitted by law.

If you send us personal correspondence, such as emails or letters, or if other users or third parties send us correspondence about your activities or postings on the Website, we collect such information into a file specific to you.

We Use The Collected Data For Various Purposes:

Use And Disclosure Of Your Personal And Other Information

We understand the importance of your information and ensure that it is used for the intended purpose only. We access, store and use the information we collect from you in accordance with the applicable laws to provide our Services, to research and develop new ones subject to the limitations set out in this Privacy Policy.

We use the information to:

SMS

During filing the form on our App, we collect and monitor your contact information which includes name, phone number, account type, contact last modified, favourites and other optional data like relationship and structural address to enable you to autofill the data during the loan application process. This information is required for the purposes of risk analysis, enable us to detect credible references assess your risk profile and to determine your loan eligibility. as well as to inform you of the outcome of your application and loan repayment reminders via SMS.

Location

We need your device location authorization to collect location-related information, which includes the location method of the user device, location time, longitude, latitude, current location, location area code, etc. Using your location information, we will be able to check your credit rating as well as increase the security of your account. In the event that an abnormality is discovered, you will be notified promptly.

Camera

Only for photographing document information.

Application list

We will also read the list of applications installed on your device, which will be used to screen for malware and cheaters, so as to maintain the environment of the mobile phone system and the security of lending services.

Purpose Of Collecting Information

The intended purpose of collecting information provided by you is to:

Disclosure To Third Parties

We will share Your information with only our registered third parties including our regulated financial partners for provision of Services on the Website/ App. We will share Your information with third parties only in such manner as described below:

Detailed Information on the Processing of Personal Information

The Service Providers We use may have access to Your Personal Data. These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies.

Analytics

We may use third-party Service providers to monitor and analyze the use of our Service.

Firebase

Firebase is an analytics service provided by Google Inc.

You may opt-out of certain Firebase features through your mobile device settings, such as your device advertising settings or by following the instructions provided by Google in their Privacy Policy: https://policies.google.com/privacy

We also encourage you to review the Google's policy for safeguarding your data: https://support.google.com/analytics/answer/6004245

For more information on what type of information Firebase collects, please visit the How Google uses data when you use our partners' sites or apps webpage: https://policies.google.com/technologies/partner-sites

Appsflyer

Their Privacy Policy can be viewed at https://www.appsflyer.com/cn/product/security-and-privacy/

Payments

We may provide paid products and/or services within the Service. In that case, we may use third-party services for payment processing (e.g. payment processors).

We will not store or collect Your payment card details. That information is provided directly to Our third-party payment processors whose use of Your personal information is governed by their Privacy Policy. These payment processors adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of payment information.

Wavepay

Their Privacy Policy can be viewed at https://wavemoney.com.mm/privacy-policy

Behavioral Remarketing

The Company uses remarketing services to advertise to You after You accessed or visited our Service. We and Our third-party vendors use cookies and non-cookie technologies to help Us recognize Your Device and understand how You use our Service so that We can improve our Service to reflect Your interests and serve You advertisements that are likely to be of more interest to You.

These third-party vendors collect, store, use, process and transfer information about Your activity on Our Service in accordance with their Privacy Policies and to enable Us to:

Measure and analyze traffic and browsing activity on Our Service Show advertisements for our products and/or services to You on third-party websites or apps Measure and analyze the performance of Our advertising campaigns

Some of these third-party vendors may use non-cookie technologies that may not be impacted by browser settings that block cookies. Your browser may not permit You to block such technologies. You can use the following third-party tools to decline the collection and use of information for the purpose of serving You interest-based advertising:

The NAI's opt-out platform:http://www.networkadvertising.org/choices/

The EDAA's opt-out platform:http://www.youronlinechoices.com/

The DAA's opt-out platform:http://optout.aboutads.info/?c=2&lang=EN

You may opt-out of all personalized advertising by enabling privacy features on Your mobile device such as Limit Ad Tracking (iOS) and Opt Out of Ads Personalization (Android). See Your mobile device Help system for more information.

We may share information, such as hashed email addresses (if available) or other online identifiers collected on Our Service with these third-party vendors. This allows Our third-party vendors to recognize and deliver You ads across devices and browsers. To read more about the technologies used by these third-party vendors and their cross-device capabilities please refer to the Privacy Policy of each vendor listed below.

The third-party vendors We use are:

Google Ads (AdWords)

Google Ads (AdWords) remarketing service is provided by Google Inc.

You can opt-out of Google Analytics for Display Advertising and customise the Google Display Network ads by visiting the Google Ads Settings page: http://www.google.com/settings/ads

Google also recommends installing the Google Analytics Opt-out Browser Add-on https://tools.google.com/dlpage/gaoptout for your web browser. Google Analytics Opt-out Browser Add-on provides visitors with the ability to prevent their data from being collected and used by Google Analytics.

For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy

Facebook

Facebook remarketing service is provided by Facebook Inc.

You can learn more about interest-based advertising from Facebook by visiting this page: https://www.facebook.com/help/516147308587266

To opt-out from Facebook's interest-based ads, follow these instructions from Facebook: https://www.facebook.com/help/568137493302217

For more information on the privacy practices of Google, please visit the Google Privacy & Terms web page: https://policies.google.com/privacy

Facebook adheres to the Self-Regulatory Principles for Online Behavioural Advertising established by the Digital Advertising Alliance. You can also opt-out from Facebook and other participating companies through the Digital Advertising Alliance in the USA http://www.aboutads.info/choices/, the Digital Advertising Alliance of Canada in Canada http://youradchoices.ca/ or the European Interactive Digital Advertising Alliance in Europe http://www.youronlinechoices.eu/, or opt-out using your mobile device settings.

For more information on the privacy practices of Facebook, please visit Facebook's Data Policy: https://www.facebook.com/privacy/explanation

Changes In This Privacy Policy

We reserve the right to change, modify, add, or remove portions of this Privacy Policy at any time for any reason. In case, any changes are made in the Privacy Policy, we shall update the same on the Platform. Once posted, those changes are effective immediately, unless stated otherwise. We encourage you to periodically review this page for the latest information on our privacy practices. Continued access or use of the Services constitute Your acceptance of the changes and the amended Privacy Policy.

Accessing Your Information / Contacting Us

At any point of time Users can choose to edit/modify or delete/withdraw any Personal Information shared for use of the Platform. Please note that deleting or withdrawing information may affect the Services we provide to you. In case of modification of Personal Information, Users will be required to furnish supporting documents relating to change in Personal Information for the purpose of verification by the Company.

Your Privacy Controls

You have certain choices regarding the information we collect and how it is used:

I. Device-level settings: Your device may have controls that determine what information we collect. For example, you can modify permissions on your Android device for access to Camera or Audio permissions.

II. Delete your entire App account.

III. You can also request to remove content from our servers based on applicable law or by writing to our Grievance Officer.

Security Precautions

The Platform intends to protect your information and to maintain its accuracy as confirmed by you. We implement reasonable physical, administrative and technical safeguards to help us protect your information from unauthorized access, use and disclosure. For example, we encrypt all information when we transmit over the internet. We also require that our registered third party service providers protect such information from unauthorized access, use and disclosure.

Our Platform has stringent security measures in place to protect the loss, misuse and alteration of information under control. We endeavour to safeguard and ensure the security of the information provided by you. We use Secure Sockets Layers (SSL) based encryption, for the transmission of the information, which is currently the required level of encryption in Sri Lankan as per applicable law.

We blend security at multiple steps within our products with the state of the art technology to ensure our systems maintain strong security measures and the overall data and privacy security design allow us to defend our systems ranging from low hanging issue up to sophisticated attacks.

In addition, the Website and App have been certified for the following security certifications:

1. ISO 9001: being the international standard that details requirements for a quality management system (QMS). Organizations use the standard to demonstrate the ability to consistently provide products and services that meet customer and regulatory requirements with the requisite security protections.

2. ISO 27001 (formally known as ISO/IEC 27001:2005): is a specification for an information security management system (ISMS) and is the suggested level of certification required under the Information Technology Act, 2000. An ISMS is a framework of policies and procedures that includes all legal, physical and technical controls involved in an organization’s information risk management processes.

3. We aim to protect from unauthorized access, alteration, disclosure or destruction of information we hold, including:

Links To Other Sites

Our Platform links to other websites that may collect information about you. We are not responsible for the privacy practices or the content of those linked websites. With this Policy we’re only addressing the disclosure and use of data collected by Us. If You visit any websites through the links on the Website, please ensure You go through the privacy policies of each of those websites. Their data collection practices, and their policies might be different from this Policy and We do not have control over any of their policies neither do we have any liability in this regard.

Your Consent

By using the Platform and by providing your information, you consent to the collection, sharing, disclosure and usage of the information that you disclose on the Platform in accordance with this Privacy Policy.

If we decide to change our Privacy Policy, we will post those changes on this page so to make you aware of the information we collect, how we use it, and under what circumstances we share and disclose it.

Feedback contact email:haycode.cs@outlook.com