Skip to navigation

Partner Consent Specification

Regulatory consent framework, UI compliance rules, and LIQ-PARTNER-CONSENT-v1 copy template.

Draft Specification — Pending Legal Sign-Off:
LIQ-PARTNER-CONSENT-v1 is currently a draft specification under review by Legal. Legal must formally approve this consent text before any partner renders it in production. Partners must render the text exactly as specified without modifications, filling in only the bracketed placeholder fields.

Overview

The Digital Personal Data Protection (DPDP) Act and regulatory guidelines require explicit, purpose-specific, unbundled consent before accessing customer KYC data or fetching registrar mutual fund records.

Liquify provides the LIQ-PARTNER-CONSENT-v1 contract to standardize the consent capture journey across all partner applications.


UI & Display Compliance Rules

To ensure legal validity and seamless API processing, partner applications must adhere to the following rules:

  1. Dedicated Standalone Screen: Display the entire consent text on its own dedicated screen in your mobile or web flow. It must not be placed behind a link, hidden in an accordion, or embedded inside your application’s general Terms & Conditions.
  2. No Pre-Ticked Checkboxes: Checkboxes must never be checked by default. The customer must actively and individually select each purpose.
  3. Mandatory vs. Optional Checkboxes:
    • Box 1 (KYC_PAN) is required to proceed with onboarding and account creation.
    • Boxes 2 (MF_HOLDINGS) and Box 3 (PARTNER_SHARE) are optional; however, computing borrowing eligibility requires all three consents to be granted.
  4. Granular Purpose Relay: Relay only the purpose codes corresponding to the checkboxes the customer actually ticked.
  5. Accurate Timestamping: The captured_at parameter must represent the exact ISO 8601 timestamp at which the customer tapped the submit button.
  6. Strict Version Validation: The backend checks consent_text_version against a7.vendor.consent.text-versions. Any wording, translation, or language modification requires a newly registered version code; unregistered strings return 400 VALIDATION_FAILED.

Purpose Code Mapping

CheckboxUI PurposeAPI Purpose CodeRequirement
Box 1Create my Liquify accountKYC_PANMandatory to continue onboarding.
Box 2Fetch my mutual fund holdingsMF_HOLDINGSRequired for CAMS/KFintech CAS portfolio sync.
Box 3Share my result with partnerPARTNER_SHARERequired to display borrowing limits to partner.

Partners must render the exact wording below, replacing only the bracketed variables ([Partner name], [mobile number], [name], [email], [phone], [link]):

Partner Screen Mockup · LIQ-PARTNER-CONSENT-v1

Your consent to Liquify

[Partner name] works with Sumanju Technologies Private Limited (“Liquify”) to check how much you can borrow against your mutual funds. Liquify needs your consent for each step below. Tick only what you agree to.


☐ 1. Create my Liquify account (needed to continue)
I allow Liquify to verify my PAN, and to use my PAN, name, date of birth, gender and mobile number [mobile number] to create my Liquify account. I can sign in to it with an OTP sent to this number.

☐ 2. Fetch my mutual fund holdings
I allow Liquify to fetch my mutual fund holdings from MF Central, CAMS or KFintech, using an OTP they send to the mobile number or email registered with them, and to use those holdings to work out how much I can borrow against them.

☐ 3. Share my result with [partner name]
I allow Liquify to share with [partner name] the amount I can borrow, the value of my mutual fund portfolio and the date my holdings were last fetched. Nothing else about my holdings is shared.


Disclosures & Policies:

  • The amount I can borrow is an estimate, not a loan offer. Any loan is decided by the lender, whose name, interest rate and charges I will see before I apply.
  • Liquify stores this data in India, uses it only for the purposes I ticked, and keeps it only as long as the law requires.
  • I can withdraw any of these consents at any time in the Liquify app or by writing to the Grievance Officer. Withdrawing stops future use; it does not undo what was done before.
  • Grievance Officer: [name], [email], [phone]. If my complaint is not resolved, I can complain to the Data Protection Board of India.
  • Privacy policy: [link] · Consent text LIQ-PARTNER-CONSENT-v1

Relaying & Reading Consents via API

Once the customer submits the consent screen, relay their choices to the customer consent endpoint:

curl -X POST "https://a7.liquifyfin-uat.in/v1/customers/ObEDjNxG/consents" \
-H "Authorization: Bearer <vendor_token>" \
-H "Content-Type: application/json" \
-d '{
"purposes": [
"KYC_PAN",
"MF_HOLDINGS",
"PARTNER_SHARE"
],
"granted": true,
"captured_at": "2026-10-02T10:20:00+05:30",
"ip": "49.36.10.1",
"device": "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X)",
"consent_text_version": "LIQ-PARTNER-CONSENT-v1"
}'

Reading Consent State: The customer may withdraw any purpose in the Liquify app at any time. Before performing operations that require consent, check their active status via:

curl -X GET "https://a7.liquifyfin-uat.in/v1/customers/ObEDjNxG/consents" \
-H "Authorization: Bearer <vendor_token>"

Success Response

{
"data": [
{
"purpose": "KYC_PAN",
"granted": true,
"recorded_at": "2026-10-02T04:28:40Z",
"consent_text_version": "LIQ-PARTNER-CONSENT-v1"
},
{
"purpose": "MF_HOLDINGS",
"granted": true,
"recorded_at": "2026-10-02T04:28:40Z",
"consent_text_version": "LIQ-PARTNER-CONSENT-v1"
},
{
"purpose": "PARTNER_SHARE",
"granted": true,
"recorded_at": "2026-10-02T04:50:03Z",
"consent_text_version": "LIQ-PARTNER-CONSENT-v1"
}
],
"meta": {
"request_id": "c4129a01-1b92-4fc3-a7c8-479e0a29ef19",
"ts": "2026-10-02T10:20:01Z"
}
}

Architectural & Compliance Rationale

DPDP Granular Consent

Per DPDP requirements, bundling multiple purposes into a single agreement is prohibited. Distinct checkboxes ensure customers independently consent to account creation, portfolio ingestion, and partner sharing.

Mobile Handle Notice

Box 1 explicitly identifies the mobile number and notifies the user of OTP login access, providing notice since accounts are created via partner handoff before initial OTP challenge.

Unnamed Lender by Design

Co-branding banking partners (e.g. Bajaj Finance Limited) requires separate marketing approvals. The text designates the lender generically until formal loan application presentation.

Data Localization & Redressal

All customer data resides strictly within India. Customers can withdraw consent via the Liquify app or Grievance Officer, with escalation rights to the Data Protection Board of India.