Privacy & Data Protection Policy

Document Title: Privacy & Data Protection Policy
Document Number: NHFL/ISMS/POL/018
Classification: Public / External User-Facing Transparency Framework
Reviewed & approved by: CISO & Head-IT
Policy/Document Owner: Chief Information Security Officer (CISO)
Current Version: 1.0
First Document Release Date: 1st June 2026
Review Cycle: Annual or immediately upon material change to code or regulation
Total No of Pages: 20
    • Prepared by: Lavanya. SA (ISO)
    • Reviewed by: Vijaya Baskar. A (CISO)
    • Approved by: Raja. S (Head- IT)
Modification History
    • Version No.: 1.0
    • Description of Change: Initial Release
    • Date of Change: 1st June 2026
PRIVACY & DATA PROTECTION POLICY
NIVARA HOME FINANCE LTD

Version 1.0 | Effective Date: 1st June 2026
Metadata Field Document Mapping & Governance Control
    • Document Title: Privacy & Data Protection Policy (Direct Lending HFC Application)
    • Application Under Scope: Nivara Partner Mobile Application (Google Play Store)
    • Version / Effective Date: Version 1.0 | Effective Date: 1st June 2026
    • Classification: Public / External User-Facing Transparency Framework
    • Document Owner: Chief Information Security Officer (CISO)
    • Approved By: Head-IT
    • Review Cycle: Annual or immediately upon material change to code or regulation
Scope & Applicability
    • This Policy applies strictly to the Nivara Partner mobile application published on the Google Play Store, along with any associated backend cloud systems, internal databases, or API interfaces operated by NIVARA HOME FINANCE LTD.
    • It strictly governs the collection, storage, cryptographic processing, transmission, sharing, retention, and ultimate deletion of all personal, technical, and sensitive financial data belonging to users (Data Principals).
1. Purpose and Policy Statement
 
NIVARA HOME FINANCE LTD (“Company”, “we”, “us”, “our”) is a legally registered, licensed, and RBI-regulated Housing Finance Company (HFC). We are fundamentally committed to ensuring the protection, containment, and ethical processing of our users’ personal and financial data.
This application, Nivara Partner is used by individuals who can refer/provide leads to Nivara Home Finance Ltd.
Because this App is categorized under Financial Services by the Google Play Store, this Policy enforces the stringent transparency criteria required by Google Play.
 
2. Regulatory & Compliance Framework
 
Our data-processing environment is designed to comply with the following statutory and regulatory regimes:
    • Digital Personal Data Protection Act, 2025 (DPDP Act-2025) – Directing Data Principal consent structures, notice clarity, and data erasure workflows.
    • RBI Guidelines on Digital Lending (DLG) – Enforcing data minimization, strict mobile hardware scoping, and an absolute prohibition on personal data scraping.
    • Information Technology Act, 2000 and the IT Rules, 2011 (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information).
    • Prevention of Money Laundering Act, 2002 (PMLA) – Mandating structural transactional logging and archival data retention thresholds.
    • Income Tax Act, 1961 — Restricting the processing, masking, and validation parameters of Permanent Account Numbers (PAN).
    • Google Play Store Developer Program Policies — Specifically the “Financial Services” policy declaration frameworks.
3. Google Play Console — Financial Features Declaration
 
The following mapping represents the official declarations maintained within the Google Play Console under App Content → Financial Features for Nivara Partner:
Declaration ItemDeclaration StatusRegulatory & Functional Explanation / Justification
Collects Financial Identity InformationYESThe App collects Permanent Account Numbers (PAN), and bank details for registration of the individual.
App Provides Loans DirectlyNOThe App is a dedicated B2B enterprise tool for registered business agents and internal staff to manage leads. It is not a direct consumer-facing loan provisioning app.
App Acts as Intermediary / LSPNOThe App is natively owned and operated by the Regulated Entity (the HFC itself). It does not function as an independent Lending Service Provider (LSP) or third-party loan aggregator.
App Performs KYCNOThe app collects PAN & bank details to identify the individual provided in the lead referral.
App Enables PayoutsNOThe App allows agents to track disbursement statuses and lead progress. It does not initiate or execute liquid payouts or tranches directly within the mobile client UI.

Official Note to Google Play Review Teams:

NIVARA HOME FINANCE LTD is a validly licensed and regulated financial institution under the oversight of the Reserve Bank of India (RBI). The Nivara Partner application is our proprietary B2B digital channel used by any individuals and field executives to securely onboard leads and capture verification documentation. It does not provide direct credit facilities to consumers via the storefront.
 
4. Financial & Personal Data We Collect
 
We practice strict Data Minimization. We do not seek or retain any data that is not functionally essential to verify your identity, evaluate creditworthiness, or service your loan account.
 
4.1 Permanent Account Number (PAN) Collection
  • The App collects the User’s PAN issued by the Income Tax Department, Government of India. This collection is mandatory and is processed exclusively for the following workflows:
  • To execute identity verification under the RBI Master Directions on Know Your Customer (KYC).
  • To comply with anti-fraud and anti-money laundering frameworks under the PMLA, 2002.
  • Security Protocol: PAN data is fully encrypted at rest, masked across all user-facing interfaces (e.g., XXXXXX1234X), and scrubbed from all system-level telemetry and application crash logs.
4.2 Bank Account Detail
The App collects bank account data (Account Number, IFSC, Account Holder Name)  This is processed exclusively for:
  • Setting up automated payment/repayment channels, including NACH (National Automated Clearing House) and e-Mandates.
  • Security Protocol: Full account numbers are never displayed raw in the UI.
4.3 Smartphone Permissions Restrictions 
Nivara Partner enforces the following mobile architecture design boundaries:
Permissions:
Camera- In future (Currently not applicable)
  • Permission: android.permission.CAMERA
  • Access Type: On-demand only — requested at the moment of use, never in the background
  • Purpose: To capture real-time photographs of physical documents submitted by the individual or field staff, specifically: PAN Card (front), and bank statement pages, If required by Nivara Home Finance Ltd’s compliance team.
  • What we do NOT do: The app does not access the camera silently, continuously, or when it is in the background. It does not scan or read QR codes from the system gallery. It does not capture any images beyond those explicitly initiated by the user within the KYC or document upload screens.
  • Data handling: Captured images are transmitted directly over TLS 1.3 to Nivara’s secure cloud storage and are not saved to the device’s local gallery or external storage.
Storage / Media Access
  • Permission: android.permission.READ_MEDIA_IMAGES (Android 13+) / android.permission.READ_EXTERNAL_STORAGE (Android 12 and below)
  • Access Type: On-demand only — triggered when the user taps “Upload from gallery” within a document upload screen
  • Purpose: To allow the individual to select and upload pre-existing document images or scanned PDF files already saved on their device. Specifically used for: uploading PAN Card images, uploading Aadhaar Card (front and back) images, and uploading bank statement files (image or PDF) during the individual KYC and client onboarding workflows.
  • What we do NOT do: The app does not scan, index, or read the full contents of the device’s media library. It does not access photos, videos, or files unrelated to the document upload action. It does not retain access to storage between sessions. Write access to device storage is not requested.
  • Data handling: Selected files are transmitted directly over TLS 1.3 to Nivara’s secure document storage. Files are not copied, cached, or stored locally on the device by the app beyond the duration of the upload.
Location
  • Permission: None (no device location permission is requested)
  • Access Type: Manual text input — no GPS or device location API is used
  • Purpose: The app includes a pin code-based property location search field within the Lead Management workflow. The agent manually enters a 6-digit India Post pin code to link a property address to a loan lead. This lookup queries Nivara’s backend to auto-populate the associated city, district, and state.
  • What we do NOT do: The app does not request ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, or any other device location permission for this feature. The device’s GPS, network location, or IP-based geolocation is not accessed or inferred at any point during a pin code search.
  • Exception: If Video-KYC (V-KYC) is activated for a specific compliance workflow in a future release, a one-time coarse location check may be required by the V-KYC service provider to satisfy RBI geographic verification requirements. This will be disclosed separately at the time of that permission request, and this policy will be updated accordingly before the feature is released.
  • Data handling: The pin code value entered by the user is transmitted to Nivara’s backend solely to resolve the property address. It is stored as part of the lead record and is subject to the same retention and access controls as other lead data described in Section 5.
  • Push notifications: Not Applicable
  • Third-party SDK / analytics: Not Applicable
4.4  KYC Data Collection & Compliance
 
Nivara Partner is used exclusively by any individuals and field executives registered with Nivara Home Finance Ltd. As part of the empanelment and ongoing compliance process, the app may requires individuals need to submit their own identity and bank details directly through the application. This data category is entirely separate from borrower or client data and is collected for the purpose of verifying the individual’s credentials, enabling commission payouts, and satisfying Nivara Home Finance Ltd’s internal compliance obligations.
 
Documents and data collected 
 
Document / Data PointFormat AcceptedPurposeMandatory
PAN Card (agent’s own)Image capture via camera or upload from deviceIdentity verification for empanelment; TDS compliance on commission payouts under the Income Tax Act, 1961; anti-money laundering checks under PMLA, 2002Yes only at the time of successful lead closure
Aadhaar Card — Front (agent’s own)Image capture via camera or upload from deviceAddress and identity verification for empanelment under RBI KYC Master DirectionsNo
Aadhaar Card — Back (agent’s own)Image capture via camera or upload from deviceComplete Aadhaar document verification as required by empanelment complianceNo
Bank Statement (agent’s own account)PDF or image upload from deviceVerification of the individual’s bank account for commission and payout disbursements; fraud preventionNo
Bank Account Details (account number, IFSC, account holder name)Manual text entrySetting up the direct bank transfer channel for commission payouts via NEFT/IMPSYes
Document Submission StatusSystem-generated metadataTracking which documents have been submitted, reviewed, or are pending — visible to the individual or field staff and to authorized Nivara compliance staff.Automatic
How this data is processed
 
Individual’s KYC documents submitted through the app are transmitted immediately over TLS 1.3 to Nivara Home Finance Ltd’s secure document management system. Documents are reviewed by authorized members of Nivara’s compliance and operations teams for the sole purpose of verifying empanelment eligibility and processing payouts. No individual’s KYC document is shared with any external party except in the following circumstances:
  • With the Income Tax Department as required under TDS reporting obligations applicable to any commissions.
  • With law enforcement or regulatory bodies upon receipt of a valid statutory order or judicial direction.
Security protocols specific to Individual’s KYC data
  • Aadhaar data is handled in strict accordance with the Aadhaar (Targeted Delivery of Financial and Other Subsidies, Benefits and Services) Act, 2016 and UIDAI guidelines.
  • The full 12-digit Aadhaar number is masked across all internal interfaces, displaying only the last 4 digits (XXXXXXXX1234).
  • Agent PAN data is masked across all user-facing interfaces using the standard format (XXXXXX1234X) and is scrubbed from all system-level telemetry and crash logs.
  • Bank account numbers are masked to display only the last 4 digits across all screens and logs.
  • Document images are stored in encrypted form using AES-256 and are accessible only to authorized compliance personnel operating under Role-Based Access Control (RBAC) as described in Section 7.1.
  •  
Individual’s rights over their own KYC data
 
An individual may request correction of any inaccurate document or detail submitted through the KYC workflow by contacting [email protected]. Requests to delete their own KYC data will be processed in accordance with Section 9.2 and 9.3, subject to the statutory retention obligations described in Section 5.1 which require retention for the duration of active empanelment plus 3 years following empanelment closure.
 
4.5 Lead/Referral Data Entered by Individuals
 
Nivara Partner enables any individuals and field executives to build and maintain a lead database within the application. individuals enter personal and identity information belonging to prospective or active leads — referred to in this section as “leads” directly into the app as part of the lead creation. This data is entered into by the individual on behalf of NIVARA HOME FINANCE LTD in the individual’s capacity as an authorized representative of the company. Nivara Home Finance Ltd is the Data Fiduciary for all lead data entered through the application, and the individual acts as a data entry intermediary operating under the terms of their empanelment agreement.
 
Data collected about leads/referrals
 
Data PointFormatPurposeMandatory
Lead full legal nameText entryIdentity establishment for loan lead creation Yes
Date of birthText entryAge eligibility verification; identity confirmationNo
Mobile numberText entryPrimary contact identifier; OTP-based verification workflowsYes
Email addressText entrySecondary communication channel; document deliveryOptional
    
PAN Card (lead’s own)Text entry of PAN number + image uploadCredit bureau pull for underwriting; identity verification under RBI KYC Master Directions; PMLA complianceNo
Aadhaar Card — Front (Lead’s own)Image capture or uploadAddress and identity verification for KYCNo
Data PointFormatPurposeMandatory
Aadhaar Card — Back (Lead’s own)Image capture or uploadComplete Aadhaar document verificationNo
Loan amount requestedNumeric entryLead qualification and product assignmentYes
Property pin codeNumeric entryProperty location linking; geographic lending zone verificationYes
Loan product typeSelection from predefined listMatching client to applicable Nivara Home Finance Ltd loan productYes
 
How this data flows through the application
 
When an individual creates a lead record, the data is transmitted immediately over TLS 1.3 to Nivara Home Finance Ltd’s central backend systems. The lead record is not stored locally on the individual’s device beyond the active session. Once submitted, the data becomes part of Nivara Home Finance Ltd’s central loan origination system and is subject to the same security, access control, and retention standards as data collected through any other Nivara channel.
Individuals can view and update lead records they have personally created within the app. They cannot access lead records created by other individuals. Nivara’s authorized underwriting, operations, and compliance staff can access lead records in accordance with the Role-Based Access Control framework described in Section 7.1.
 
Consent and legal basis for processing Lead data
 
Individuals are required under the terms of their empanelment agreement with Nivara Home Finance Ltd to obtain the borrower’s informed consent before entering their personal and identity data into the application. Nivara Home Finance Ltd provides individuals with the required consent language and disclosure format as part of the empanelment onboarding process. The legal basis for processing lead data entered through the app is:
  • Explicit consent obtained by the individual from the referral prior to data entry, as required under the DPDP Act, 2023.
  • Contractual necessity — processing required to evaluate and service the referral’s loan application.
  • Legal obligation — compliance with RBI KYC Master Directions, PMLA, 2002, and Credit Information Companies (Regulation) Act, 2005.
Security protocols specific to lead identity data
  • Lead records such as name, mobile number and pin code were collected, which cannot be exported, downloaded, or shared from within the application by the individuals. Data portability outside the app is restricted to authorized Nivara backend operations only.
     
  • What we do NOT do with lead data entered by individuals
      • Lead data entered by one individual is never made visible to any other individual within the platform.
      • Lead data is never processed outside the sovereign borders of India.
    Lead’s rights as a Data Principal

    Lead’s contact information entered through the app is never used for purposes beyond loan origination as requested, underwriting, and statutory compliance

  • Lead data is never sold, leased, or shared with third-party data brokers, marketing networks, or any entity not listed in Section 7.2.
     
  • Referrals whose personal data has been entered into the system by an individual retain all rights as Data Principals under the DPDP Act, 2023, including the right to access, correct, and request erasure of their data. Since referrals do not have direct access to the Nivara Partner application, they may exercise these rights by contacting Nivara Home Finance Ltd directly at [email protected] or through the Grievance Redressal Officer details listed in Section 9.4. Requests will be acknowledged within 48 hours and resolved within 30 days, subject to the statutory retention obligations described in Section 5.1.
     
    5. Complete Data Collection & Processing Summary Matrix
     
     
     
    Data CategorySpecific Data Points CollectedCore Processing PurposeRetention Window ThresholdAuthorized Shared Parties
    Financial IdentityPermanent Account Number (PAN), Bureau Credit Reports.Credit scoring, algorithmic underwriting, identity confirmation, tax reporting.Statutory 7-Year lock post complete loan account closure (PMLA compliance).Credit Bureaus (CICs), Internal Underwriters, RBI Auditors.
    Data CategorySpecific Data Points CollectedCore Processing PurposeRetention Window ThresholdAuthorized Shared Parties
    Individual KYC & ComplianceIndividual PAN, bank account details, document submission status metadataEmpanelment verification, payout processing, TDS compliance, fraud prevention, RBI compliance obligationsDuration of active empanelment + 3 years following empanelment closure. Statutory financial records retained for 7 years under PMLA, 2002 where applicable.Authorized Nivara compliance and operations teams (internal); Income Tax Department (TDS reporting); law enforcement or regulators upon valid statutory order only.
         
    Personal ProfileFull legal name,  phone, & email string.Account setup, user communication, identity verification via UIDAI/Digi Locker.Active account state + 3 years post structural account closure.Licensed KYC Engines, National Document Registry Platforms.
    Data CategorySpecific Data Points CollectedCore Processing PurposeRetention Window ThresholdAuthorized Shared Parties
    Device & TechnicalDevice ID, IP address, OS version, application crash logsSystem security profiling, multi-device login protection, anti-fraud geofencing.Device identifiers and IP logs are deleted automatically on a rolling 12-month basis calculated from the date of each log entry. Crash logs are purged within 90 days of the app session that generated them. No device data is retained after account closure.Internal IT Infrastructure Security Teams.
     
     


    5.1 Data Retention Schedule — Complete Reference

    The following schedule governs the precise retention period for every data category collected by the Nivara Partner application. Retention periods are calculated from the trigger event specified in each row.

    Data CategoryRetention PeriodTrigger Event for Start of PeriodTrigger Event for DeletionLegal Basis for Retention Period
    Financial Identity (PAN, credit bureau reports)7 yearsDate of loan application submission7 years after complete loan account closure

    PMLA, 2002 — Section 12; RBI KYC Master Directions

         
    Personal Profile (name, address, phone, email)Duration of active account + 3 yearsDate of account closure or last transaction3 years after account closureDPDP Act, 2023 — contractual necessity basis
    Individual KYC Documents (PAN, bank details)Duration of active empanelment + 3 yearsDate of empanelment termination or deregistration3 years after empanelment closureRBI empanelment compliance; PMLA, 2002
    Device & Technical (Device ID, IP address, OS version, crash logs)12 months for identifiers; 90 days for crash logsDate of each individual log entryAutomatic rolling deletion — no manual trigger requiredOperational necessity; no statutory minimum applies
         
    Lead & individual Records (loan lead details, PAN, entered by individual)Duration of active lead lifecycle + 7 yearsDate of lead closure, approval, or drop7 years after lead closurePMLA, 2002; RBI Guidelines on Digital Lending

    Early deletion upon request

    Where a user exercises their Right to Erasure under Section 9.1, Nivara Home Finance Ltd will delete all data categories not subject to a statutory retention obligation within 30 days of identity verification. Data categories governed by PMLA, RBI, or Income Tax Act retention mandates cannot be deleted before their statutory period expires, as described in Section 9.2. In such cases, the user’s active app profile and all non-statutory auxiliary data will be deleted within 30 days, while the statutory financial records remain securely archived in a restricted system inaccessible to operational staff.

    Retention period review

    This retention schedule is reviewed annually by the Chief Information Security Officer (CISO) and updated immediately upon any change to applicable Indian law or RBI regulations. The version number and effective date at the top of this Policy will be updated upon any revision to this schedule.
     
    6. Purpose Limitation: What We Do and What We Will NEVER Do
    We adhere strictly to the principle of Purpose Limitation under the DPDP Act, 2023. Data collected for loan processing is never used for unrelated purposes.
    We Will NEVER:
      • Sell, lease, barter, or distribute your personal or financial data to third-party data brokers, advertising agencies, or marketing networks.
      • Use your PAN, or banking information to build profiles for targeted cross-platform commercial advertising.
      • Share your information with unauthorized peer-to-peer apps, alternative lending apps, or collection aggregators.
      • Process or store your data outside the sovereign borders of India. All user databases are localized domestically within India.

    7. Internal Access & External Sharing Boundaries

    7.1 Internal Role-Based Access Control (RBAC)

    Data access within NIVARA HOME FINANCE LTD is siloed to enforce a strict “need-to-know” security model:
      • Underwriting & Risk Teams: Full access to financial documentation, statements, and credit scores exclusively to evaluate active applications.
      • Customer Support officer: Access is restricted to masked, fractional profile data (e.g., last 4 digits of accounts). Full record retrieval requires an authorized manager override log.
      • Product & IT Teams: Access is limited to fully anonymized usage patterns and system health metrics. No PII or raw financial strings are accessible.

    7.2 External Statutory Disclosures

    Data sharing with external entities is limited to the following regulated scenarios:
      • Credit Bureaus: Reporting repayment behavior and defaults to registered CICs (e.g., CIBIL) as legally required by the Credit Information Companies (Regulation) Act, 2005.
      • Banking Operations Partners: Transmitting encrypted tokens to payment gateways and automated clearing networks (NPCI) to process your authorized transactions.
      • Judicial & Regulatory Mandates: Providing specific information to law enforcement or court systems only upon receipt of a valid statutory order or subpoena.


    8. Data Security and Technical Safeguards

    We deploy robust, military-grade technical controls to keep your data secure:
    Security ControlTechnical Implementation Detail
    Encryption at RestAll PII, PAN records, and banking structures are encrypted using AES-256 standard frameworks across all production databases and cloud storage volumes.
    Encryption in TransitAll data transmitted between the Nivara Partner mobile client and our cloud endpoints is wrapped in TLS 1.2/1.3 transport tunnels with strict certificate pinning enforced.
    Multi-Factor AuthenticationInternal corporate access to production financial environments mandates hardware-backed Multi-Factor Authentication (MFA) under strict privilege monitoring.
    Independent AuditingOur application environment and source code undergo regular penetration testing and vulnerability assessments by independent, CERT-In empaneled cybersecurity firms.
    Incident ResponseWe maintain an active Incident Response Plan. In the event of a confirmed data breach, notifications will be sent to the affected users and CERT-In within 72 hours, as required by the DPDP Act, 2023.

    9. User Rights, Comprehensive Data Deletion, and Redressal

    9.1 Your Rights Under the DPDP Act, 2023

    As a Data Principal, you hold the following rights which can be exercised freely via our portal:
      • Right to Access & Review: Request a clean summary of your personal data processed by the Company.
      • Right to Correction: Correct any inaccurate, outdated, or incomplete records in your profile.
      • Right to Erasure (The Right to be Forgotten): Request the deletion of your data once its operational purpose is complete.

    9.2 Statutory Retention Override Notice

      • Important Legal Notice: If you have an active loan application, an outstanding loan balance, or historical financial transactions with NIVARA HOME FINANCE LTD, we are legally required by the RBI, the Income Tax Act, and the PMLA, 2002 to preserve your financial ledger records and identity logs for the mandated statutory duration. In these cases, a data deletion request will immediately deactivate your app profile and delete auxiliary marketing variables, but your core financial history will remain securely archived until the statutory retention period expires.

        9.3 Data Deletion & Account Closure Process

      • To trigger account closure and request data erasure:
      • Submit a formal written request via email to: [email protected] using the subject line “Data Deletion Request — [Insert Your Registered Mobile Number]”.
      • We will verify your identity within 3 business days and execute all eligible erasures across our live systems within 30 days. You will receive an official deletion confirmation certificate once complete.

    9.4 Grievance Redressal Architecture

    If you have any questions, security concerns, or complaints regarding data handling, please contact our designated Grievance Redressal Officer (GRO) & Data Protection Officer:
    Redressal CategoryCorporate Grievance Record Profile
    Designated OfficerGrievance Redressal Officer & Data Protection Officer
    Corporate EntityNIVARA HOME FINANCE LTD
    Physical Office Address3rd Flr, BNR Complex, 25/101/3, opposite RBI Layout Main Road, Puttenahalli, JP Nagar 7th Phase, J. P. Nagar, Bengaluru, Karnataka 560078
    Electronic Mail Contact[email protected]
    Mandated Response SLAsAcknowledgement within 48 hours; absolute resolution within 30 days.
    Redressal CategoryCorporate Grievance Record Profile
    Escalation PathIf unsatisfied with our resolution, you can appeal directly to the Data Protection Board of India (DPBI) or the RBI Ombudsman.
    DPBI → meity.gov.in
    RBI Ombudsman → rbi.org.in

    10. Consent and Legal Basis for Processing

    We process data on clear, legally defined bases:
      • Explicit Consent: Collected via clear, granular checkboxes before any financial data collection occurs. You may withdraw consent at any time, though doing so may prevent us from servicing your loan application.
      • Contractual Necessity: Processing required to fulfill our commitments under the Loan Agreements and Terms of Service.
      • Legal Obligation: Compliance with mandatory statutory reporting, anti-money laundering regulations, and central banking rules.
      • DPDP Act consent withdrawal mechanism: To withdraw consent, email [email protected]

    11. Policy Changes & Updates

    We reserve the right to modify this Privacy Policy to mirror system changes or new regulations. Material updates will be communicated at least 30 days before taking effect via:
      1. Push notifications or alert banners inside the Nivara Partner interface.
      2. Direct email notifications sent to your registered address.
      3. Postings at the public destination: https://www.nivarahousing.com/

    13. Policy Approval and Corporate Sign-Off

    This policy stands as an approved corporate directive. Any unauthorized deviations by system engineers or operations staff will result in disciplinary action.
    Executive RoleCorporate NameSignature / Execution Date
    Chief Business Officer (COO)Nivara Operations ControlElectronically Signed — June 2026
    Chief Information Security Officer (CISO)Nivara Security Architecture GroupElectronically Signed — June 2026
    Legal CounselNivara Corporate Compliance TeamElectronically Approved — June 2026
    © 2026 NIVARA HOME FINANCE LTD. All rights reserved. This document is publicly accessible to support user transparency and satisfy mobile app store compliance reviews
      •