Privacy policy
What personal data we collect, why, how long we keep it, and the rights you have over it.
Last updated [PLACEHOLDER: date]
[PLACEHOLDER: This document has not been reviewed by a lawyer. Have counsel familiar with Indian financial services regulation review and complete it before launch.] This policy should be drafted against the Digital Personal Data Protection Act, 2023 and the rules made under it.
What we collect
When you use this website. Pages visited, approximate location derived from IP address, device and browser type, and referring site. Collected through analytics cookies only where you have consented.
When you submit an enquiry. Your name, email address, phone number, the service you asked about, the investment range you selected, and anything you wrote in the message field.
When you become a client. Identity and address documents, PAN, bank account details, income and net worth information, risk profile responses, nominee details, and transaction records — collected because KYC and AML obligations require it.
Why we use it
- To respond to your enquiry and arrange a consultation.
- To meet KYC, AML and record-keeping obligations under the Prevention of Money Laundering Act, 2002 and applicable SEBI and FIU-IND requirements.
- To provide, administer and report on the services you have engaged.
- To send the market note, where you have subscribed. You can unsubscribe from every one of those emails.
We do not sell your personal data. We do not share it for third-party marketing.
Who we share it with
[PLACEHOLDER: list every processor and recipient — custodian, broker, KYC verification provider, email provider, analytics provider, cloud host — and the country each stores data in. The DPDP Act requires this to be specific rather than generic.]
We also disclose data where required by law, to a regulator, or to a court.
How long we keep it
Client and transaction records are retained for the period required by law, which for records maintained under the Prevention of Money Laundering Act is generally five years from the end of the relationship or the transaction. Enquiries that do not become client relationships are deleted after [PLACEHOLDER: state period]. Newsletter subscriptions are kept until you unsubscribe.
How we protect it
Data is encrypted in transit using TLS and at rest. Access is restricted to staff who need it. KYC documents are stored separately from general business data with additional access controls. [PLACEHOLDER: describe your actual technical and organisational measures, your breach notification process, and your breach notification timeline.]
Your rights
Under the Digital Personal Data Protection Act, 2023 you may request access to your personal data, correction of inaccurate data, erasure where retention is not legally required, and withdrawal of consent where processing relies on it. You may also nominate someone to exercise these rights on your behalf.
To exercise any of these, contact our Data Protection Officer at [PLACEHOLDER: DPO name and email]. We will respond within [PLACEHOLDER: period].
Cookies
Strictly necessary cookies are set to make the site work. Analytics cookies are set only with your consent and can be withdrawn at any time. [PLACEHOLDER: if you deploy a consent banner, describe it here and make sure analytics genuinely does not load before consent.]
Complaints
If you are not satisfied with how we have handled your data, you may complain to the Data Protection Board of India.