FFastRupee
Apply now

FastRupee

Privacy notice

Clear, responsible and secure lending information, written to be understood.

Effective 25 July 2026

Version PUBLIC_PRIVACY_2026-07-25. The English master text and deployment legal details require counsel approval before production launch.

Controller and contact

FastRupee.lk is responsible for the personal data used by this service. Privacy questions and rights requests: privacy@fastrupee.lk. Company registration: Deployment configuration required.

Information we collect

Identity and contact details; address; employment, income, expenses and commitments; bank and repayment details; NIC/selfie documents; application, loan, payment and support history; device, security, consent and audit evidence; provider verification and credit results where lawfully available.

Why we use it

To respond to enquiries, verify identity, prevent fraud, assess eligibility and affordability, administer applications and loans, collect repayments, provide support, meet accounting/legal duties, secure the service and improve operations. Marketing requires a separate choice and can be withdrawn.

Automated and human decisions

Rules and scores can assist risk review, but approval authority, exceptions and adverse outcomes remain permission-controlled and auditable. Customers can ask for an explanation, correction or human review where applicable.

Sharing and processors

Data is shared only with authorized staff and configured processors needed for identity, credit, payments, communications, telephony, accounting, secure hosting and legal compliance. Provider activation requires a reviewed contract, purpose, security controls and retention terms.

Retention and deletion

Records are retained according to lending, accounting, fraud, complaint, limitation and regulatory duties. A deletion request may be restricted by those duties, legal hold or an active contract. Expiry, anonymisation and disposal must be auditable.

International transfers

A provider or cloud region outside Sri Lanka is used only after transfer purpose, destination, safeguards, access, breach and deletion terms are reviewed and configured.

Your choices and rights

Subject to applicable law, request access, correction, restriction, objection, portability or deletion; withdraw optional consent; change communication preferences; and complain. Identity must be verified before protected information is released.

Security

Sensitive values are encrypted at rest, searchable identifiers use blind indexes, documents are encrypted and quarantined for scanning, APIs enforce authentication and permissions, and security-relevant access is audited. No security control eliminates all risk.

Cookies and local storage

Essential session, security, language and application-draft storage supports sign-in and continuity. Non-essential analytics or advertising storage must remain disabled until the user is informed and any required consent is recorded.