PartnersPersonalPart of the OnEMI group

Legal

Privacy & Security Policy

Last updated 6 August 2026Invincible Minds Private LimitedCIN U66120MH2026PTC472502

1. Introduction

Invincible Minds Private Limited (hereinafter referred to as the “Company”, “we”, “us” or “our”) is a company incorporated under the Companies Act, 2013, bearing CIN U66120MH2026PTC472502, with its registered office at 10th Floor, Tower 4, Equinox Business Park, Kurla, Mumbai, Mumbai- 400070, Maharashtra. This Privacy Policy applies to all products and services offered by the Company through its websites, mobile applications, customer portals, APIs and other digital platforms (collectively, the "Platform"), unless a separate privacy policy is specifically notified for a particular Product/Service.

The Company is engaged in the business of distribution of mutual fund products and is registered with the Association of Mutual Funds in India (“AMFI”) as a mutual fund distributor bearing ARN – 365266 (valid up to 12-JUL-2029). The Company has also made an application for registration as a stock broker with the Securities and Exchange Board of India (“SEBI”) and the stock exchanges, and may in due course also obtain registration as a depository participant and/or in such other capacity as it may determine. Upon grant of any such registration, the corresponding registration particulars shall be displayed on our Website and Mobile Application, and the relevant provisions of this Privacy Policy shall apply to those activities.

The Company may also, from time to time, obtain additional registrations, licences or approvals from the relevant Regulatory Authorities to offer or facilitate other financial products and services and this Policy shall, unless otherwise stated, apply equally to the processing of personal data in connection with such Products/Services.

This Privacy Policy (“Policy”) explains how the Company collects, uses, processes, discloses, stores, transfers, retains and protects the personal data of its clients, investors, users and visitors of our website [www.example.com] (“Website”), customer portals, communication channels and other digital interfaces and our mobile application [App Name] (“Mobile Application”, and together with the Website, the “Platforms”). This Policy is published in accordance with Rule 3(1) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and is an electronic record generated by a computer system that does not require any physical or digital signature.

This Policy has been framed in accordance with, and shall be read together with:

  • the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the rules framed thereunder;
  • the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), to the extent applicable;
  • the SEBI Act, 1992 and the SEBI (Mutual Funds) Regulations, 1996, together with the AMFI Code of Conduct for Intermediaries of Mutual Funds, AMFI Guidelines & Norms for Intermediaries (AGNI) and circulars/best-practice guidelines issued by AMFI and SEBI in respect of mutual fund distributors, including those relating to protection of investor data, use of digital platforms and prohibition on sharing of investor information;
  • upon grant of the relevant registration, the SEBI (Stock Brokers) Regulations, 1992, the SEBI (Depositories and Participants) Regulations, 2018, and the bye-laws, rules, regulations and circulars of the stock exchanges, clearing corporations and depositories of which the Company becomes a member/participant;
  • SEBI's Cybersecurity and Cyber Resilience Framework (CSCRF) for SEBI-regulated entities, as and to the extent applicable to the Company;
  • the Prevention of Money Laundering Act, 2002 (“PMLA”) and the rules thereunder, and SEBI's KYC/AML master circulars and guidelines, including requirements relating to KYC Registration Agencies (“KRAs”) and the Central KYC Records Registry (“CKYCRR”); and
  • directions of the Indian Computer Emergency Response Team (CERT-In) on cyber security incident reporting.

For the purposes of the DPDP Act, the Company acts as a “Data Fiduciary” in respect of the personal data of its clients and users, who are “Data Principals”. Where the Company processes personal data on behalf of another entity under a contract, it may act as a “Data Processor”.

By availing our services, accessing or using our Website or Mobile Application, or submitting your personal data to us, you acknowledge that you have read and understood this Policy and consent to the collection and processing of your personal data as described herein. This Policy is incorporated by reference into, and forms part of, the Terms & Conditions governing the use of our Platforms.

2. Scope of this policy

This Policy:

  • applies to all clients, investors, prospective clients, users, visitors and any other natural persons whose personal data is collected or processed by the Company in connection with its mutual fund distribution business and, upon grant of the relevant registrations, its stock broking, depository participant and any other regulated business;
  • applies uniformly to personal data collected through our Website, our Mobile Application, client portals, web/mobile transaction platforms, email, telephone and instant messaging, as well as through offline modes (physical application forms, KYC documents and correspondence). The Mobile Application is an extension of the Website and is governed by this same Policy;
  • covers the collection, use, storage, processing, sharing, transfer, retention and erasure of personal data, including data collected for onboarding, KYC/CKYC/KRA compliance, execution and routing of mutual fund transactions (purchase, redemption, switch, SIP, STP, SWP), reporting, and client servicing, and (upon commencement of such activities) trading, settlement and demat operations;
  • permits sharing of personal data with asset management companies (“AMCs”), registrars and transfer agents (“RTAs”), stock exchange mutual fund platforms (BSE StAR MF and NSE NMF II), MF Utilities India Private Limited (MFU), KRAs, CKYCRR, SEBI, AMFI, stock exchanges, depositories, clearing corporations, the Financial Intelligence Unit – India (FIU-IND) and other authorities, as required under applicable law or to give effect to your instructions;
  • sets out the security safeguards adopted by the Company and the rights available to Data Principals under the DPDP Act;
  • is limited to activities, systems and processes within the control of the Company, and does not extend to third-party websites, applications, platforms or services that may be linked from or integrated with our Platforms, including the websites and applications of AMCs, RTAs, exchanges, depositories, payment gateways and banks, each of which is governed by its own privacy policy; and
  • applies primarily to services offered within India. Where personal data is transferred outside India, such transfer shall be in accordance with Section 16 of the DPDP Act and any restrictions notified by the Central Government, and with applicable SEBI/AMFI requirements on maintenance of records and data within India.

3. Key definitions

  • “Personal Data” means any data about an individual who is identifiable by or in relation to such data;
  • “Processing” means a wholly or partly automated operation or set of operations performed on digital personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment or combination, indexing, sharing, disclosure by transmission, dissemination or otherwise making available, restriction, erasure or destruction;
  • “Data Principal” means the individual to whom the personal data relates (and includes, in the case of a child, their parent or lawful guardian, and in the case of a person with disability, their lawful guardian);
  • “Data Fiduciary” means any person who alone or in conjunction with other persons determines the purpose and means of processing of personal data;
  • “Data Processor” means any person who processes personal data on behalf of a Data Fiduciary;
  • “Consent Manager” means a person registered with the Data Protection Board of India who acts as a single point of contact to enable a Data Principal to give, manage, review and withdraw consent through an accessible, transparent and interoperable platform;
  • “Board” means the Data Protection Board of India constituted under the DPDP Act.

4. Information we collect

We collect, use and process various categories of personal data about our clients and users. The categories of personal data collected may vary depending on the Product/Service availed by you, your interactions with the Platform, and the legal or regulatory requirements applicable to such Product/Service. The Company shall collect only such personal data as is reasonably necessary for the specified purposes set out in this Policy, as notified to you at the time of collection, or as otherwise required under Applicable Law. Depending on the service availed, this may include:

Identity and KYC Data

  • name, parent's/spouse's name, date of birth, gender, photograph, signature, marital status, nationality, residential status and place of birth;
  • PAN, Aadhaar (in masked/redacted form or through offline/OTP-based verification, as permitted by law), passport, driving licence, voter ID and other officially valid documents;
  • proof of address, contact details (address, mobile number, email address), and where applicable details of authorised signatories, partners, directors, beneficial owners, nominees, guardians and joint holders;
  • FATCA/CRS declarations, tax residency status and Taxpayer Identification Number, where applicable.

Financial and Transactional Data

  • bank account details, income range, net worth, occupation, source of funds and financial profile;
  • mutual fund folio numbers, unit holdings, scheme details, SIP/STP/SWP registrations, transaction and redemption history, and consolidated account statement data;
  • risk profile, investment objectives, investment horizon and suitability-related information;
  • upon commencement of broking/depository services, demat account details, holdings, pledge and margin-pledge details, order and trade data, margin details, ledger balances, contract notes and settlement data.
  • payment instrument details, transaction references, payment confirmations, refunds, charges and other payment-related information;
  • portfolio information, investment preferences, risk tolerance, financial goals and other information voluntarily provided by you for availing Products/Services;
  • any other financial or transactional information generated in connection with the Products/Services availed by you.

Technical, Device and Usage Data

  • device information (device model, operating system and version, unique device identifiers), IP address, browser type, mobile network information, log-in and session records, crash logs and diagnostic data;
  • usage patterns, pages/screens viewed, features used, and cookies and similar technologies on our Website, Mobile Application and client portals;
  • approximate or precise geolocation, camera, photo gallery/storage and SMS/contact permissions on the Mobile Application, only where you grant such permission (see Section 7).

Communication Data

  • recordings of telephone calls (including transaction and order-related calls, where recording is mandated or adopted as a control), emails, in-app chat and support tickets, WhatsApp/instant messages and other electronic communications with the Company.
  • feedback, ratings, survey responses and other voluntary communications submitted by you.

Data from Other Sources

  • information obtained from KRAs, CKYCRR, AMCs, RTAs, stock exchange mutual fund platforms, MFU, depositories, exchanges, credit information companies, publicly available sources, sanction/PEP screening databases and regulatory databases, for verification, due diligence and compliance purposes.

Certain data collected by us may constitute “sensitive personal data or information” under the SPDI Rules (such as financial information, passwords and biometric information) and shall be handled with the higher degree of care required under applicable law. We do not collect any special category of data that is not necessary for the purposes set out in this Policy.

5. Notice, consent and legitimate uses

Notice

In accordance with the DPDP Act, at or before the time of requesting your consent, the Company shall give you a notice informing you of: (i) the personal data proposed to be processed and the purpose of such processing; (ii) the manner in which you may exercise your rights under the DPDP Act, including the right to withdraw consent and the right of grievance redressal; and (iii) the manner in which you may make a complaint to the Data Protection Board of India. On the Mobile Application, such notice is presented at the time of registration and, where applicable, at the point at which a specific permission or data field is requested. Where consent was obtained before the commencement of the DPDP Act, such notice shall be provided as soon as reasonably practicable, and the Company may continue processing until consent is withdrawn.

Consent

Your consent shall be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and shall signify agreement to the processing of your personal data for the specified purpose, limited to such personal data as is necessary for that purpose. A request for consent shall be presented in clear and plain language, with the option to access it in English or any language specified in the Eighth Schedule to the Constitution of India, together with the contact details of our Grievance Officer. Consent may also be given, managed, reviewed or withdrawn through a Consent Manager registered with the Board. Where you choose not to provide personal data that is mandatory for providing a Product/Service or for compliance with Applicable Law, we may be unable to provide, continue or complete such Product/Service or comply with your instructions

Withdrawal of Consent

You have the right to withdraw your consent at any time, with the ease of withdrawal being comparable to the ease with which consent was given. Withdrawal shall not affect the legality of processing carried out before withdrawal. Upon withdrawal, the Company shall, within a reasonable time, cease (and cause its Data Processors to cease) processing your personal data, unless such processing is required or authorised under applicable law. Please note that withdrawal of consent in respect of data essential to regulatory compliance (for example, KYC, transaction records or AML reporting) may result in the Company being unable to continue providing services to you, and may require discontinuance of your account or folio servicing, subject to applicable regulations.

Legitimate Uses

The Company may process your personal data without separate consent for certain legitimate uses permitted under Section 7 of the DPDP Act, including: (i) where you have voluntarily provided personal data for a specified purpose and have not indicated that you do not consent to its use; (ii) for compliance with any judgment, decree or order under law; (iii) for compliance with applicable laws requiring disclosure to the State or its instrumentalities or to regulators (including SEBI, AMFI, exchanges, depositories, FIU-IND and tax authorities); (iv) to respond to a medical emergency or threat to life; and (v) for employment-related purposes in respect of employees.

6. Purposes for which we use personal data

We use and process personal data for the following purposes, which may include, but are not limited to:

  • onboarding and registering you as a client, and facilitating, processing, executing, routing and servicing transactions relating to the Products/Services availed by you, including mutual fund transactions and any other Products/Services offered through the Platform.;
  • conducting KYC, client due diligence, in-person/video verification, risk categorisation and ongoing monitoring as required under the PMLA, SEBI and AMFI requirements, including uploading, downloading and updating KYC records with KRAs and CKYCRR;
  • providing incidental advice in respect of mutual fund products strictly as permitted under the SEBI (Mutual Funds) Regulations, 1996 and AMFI guidelines, and assessing suitability where applicable;
  • providing client servicing, responding to queries, requests and complaints, and sending account statements, transaction confirmations, alerts and other regulatory communications;
  • upon grant of the relevant registrations, opening and maintaining trading and demat accounts and executing, clearing and settling transactions on stock exchanges and with depositories;
  • detecting, preventing and investigating fraud, market abuse, money laundering and terrorist financing, and undertaking surveillance and screening as required by law;
  • verifying the identity of clients, their representatives, nominees, guardians and authorised persons;
  • operating, maintaining, securing, testing analytics, service personalisation, customer experience enhancement and improving the Platform, including troubleshooting, crash analysis and product development;
  • complying with applicable laws, rules and regulations, including tax reporting (FATCA/CRS, where applicable), and responding to lawful requests from public, regulatory, governmental or judicial authorities;
  • recording telephone calls and electronic communications relating to client dealings, as required or as a matter of internal control, and maintaining audit trails;
  • performing internal business processes such as data analysis, internal, statutory and concurrent audit, risk management and management reporting;
  • sending you service-related and, where you have consented, marketing or promotional communications regarding our Products/Services (you may opt out of marketing communications at any time); and
  • effecting any sale, merger, amalgamation, reconstruction or similar change of the business of the Company, subject to applicable law.
  • communicating information regarding products or services offered by our affiliates, partners, asset management companies or other financial institutions.
  • to facilitate seamless onboarding by auto-populating information already provided by you across different stages of the onboarding journey or across products offered through our Platform, subject to Applicable Law and your consent where required

Personal data shall be processed only for lawful purposes and shall not be used in a manner incompatible with the purposes notified to you, except as required or permitted under applicable law. We do not use your personal data for any automated decision-making that produces legal or similarly significant effects on you without human oversight.

7. Mobile application – additional disclosures

This Policy applies in full to our Mobile Application. The following additional disclosures apply specifically to your use of the Mobile Application:

Device Permissions

The Mobile Application may request the following device permissions. Each permission is optional, is requested only when the related feature is used, may be declined, and may be revoked at any time through your device settings. Declining a permission may limit the related functionality but will not prevent you from using the core services:

  • Camera – to capture photographs, signatures and documents for KYC, video in-person verification (VIPV) and cheque/document upload;
  • Photos, media and storage – to upload documents and to save statements and reports to your device;
  • Location – to record the geo-coordinates required for video in-person verification and to support fraud prevention and regulatory record-keeping;
  • Microphone – for video/audio-based verification and recorded support calls, where applicable;
  • Notifications – to deliver transaction alerts, regulatory communications and service messages;
  • Biometric/device authentication – to enable secure log-in using the biometric or PIN facility provided by your device operating system. Biometric data is processed by your device and is not transmitted to, or stored by, the Company.

We do not access your contacts, call logs or SMS content for marketing purposes. Where SMS-read permission is used, it is solely for automatic reading of one-time passwords for authentication.

Software Development Kits and Analytics

The Mobile Application may integrate third-party software development kits (SDKs) and services for analytics, crash reporting, push notifications, customer support, payment processing and KYC/e-sign facilitation. Such providers act as our Data Processors under contract and are permitted to process personal data only on our instructions and for the purposes specified. A current list of such providers may be obtained from our Grievance Officer.

Application Data, Updates and Deletion

Data cached on your device is protected by device-level security and application controls. You may delete your account or request erasure of your personal data through the “Profile/Settings” section of the Mobile Application or by writing to our Grievance Officer, subject always to the retention obligations set out in Section 12. Uninstalling the Mobile Application does not by itself result in erasure of personal data held in our records. We recommend that you keep the Mobile Application updated to the latest version, as updates may contain important security fixes.

App Store Disclosures

The data-safety and privacy disclosures published by us on the Google Play Store and the Apple App Store are consistent with this Policy. In the event of any inconsistency, this Policy shall prevail, save to the extent that the app-store disclosure imposes a higher standard of protection.

8. Data sharing and disclosure

We may share personal data for the purposes described in this Policy with the following categories of recipients:

Product Manufacturers and Market Infrastructure

  • AMCs and their RTAs (such as CAMS and KFin Technologies), stock exchange mutual fund transaction platforms (BSE StAR MF and NSE NMF II), MF Utilities India Private Limited (MFU), and, upon commencement of broking/depository activity, stock exchanges, clearing corporations and depositories (NSDL/CDSL), for the purpose of processing, routing, settling and reporting your transactions and maintaining your folios/accounts.

Regulatory and Statutory Authorities

  • SEBI, AMFI, stock exchanges, clearing corporations, depositories, KRAs, CKYCRR, FIU-IND, the Reserve Bank of India, income-tax and other tax authorities, CERT-In, and judicial or law-enforcement authorities, as required under applicable law — this being a legitimate use under Section 7 of the DPDP Act and not requiring separate consent.

Group Entities and Affiliates

  • our affiliates and related group companies, which are required to protect personal data and to use it only for legitimate purposes consistent with this Policy.

Service Providers (Data Processors)

  • service providers engaged by us under valid contracts, including KYC/e-KYC and e-sign agencies, technology, SDK and software vendors, cloud and data-centre providers, payment aggregators and gateways, banks, printing and dispatch agencies, call-recording and communication service providers, customer-support platforms, and professional advisers (legal, audit, accounting).

In accordance with the DPDP Act, the Company engages Data Processors only under a valid contract and remains responsible for compliance with the DPDP Act in respect of processing undertaken by such Data Processors on its behalf. We supervise our service providers and contractually require them to implement appropriate security safeguards, to process personal data only on our instructions, and to delete or return such data on termination.

Third Parties Authorised by You

Where you have, or propose to have, a relationship with a third party (such as a bank, AMC, insurer or other intermediary) in connection with a product or service, we may share information with such third party as authorised by you. The handling of that information by such party will be governed by your agreement with that party and its privacy policy.

No Sale of Data

We do not sell, rent or trade your personal data to any third party. We do not share your personal data with any person for that person's independent marketing purposes without your consent.

9. Data security

In accordance with the DPDP Act, the Company implements reasonable security safeguards to prevent breach of personal data, including:

  • Encryption of personal data in transit and at rest (wherever applicable);
  • Role-based access controls, so that personal data is accessible only to authorised personnel on a need-to-know basis;
  • Multi-factor authentication for administrative and privileged access;
  • Logging and monitoring of access to systems holding personal data;
  • Periodic security testing, review and updation of our applications, systems and controls;
  • Internal information security policies and training for our personnel.
  • data backup, business continuity and disaster recovery arrangements;
  • employee confidentiality obligations, background checks and periodic training on data protection and information security; and
  • vendor risk management and contractual security obligations on Data Processors.

While we adopt industry-standard measures, no method of transmission or storage is completely secure. You are urged to protect your login credentials, passwords, PINs and OTPs, to use the latest version of the Mobile Application, and never to share such credentials with any person, including employees of the Company. The Company will never ask you for your password or OTP.

Data location

Personal data collected by us is stored on servers located within India

10. Personal data breach

In the event of a personal data breach, the Company shall, in accordance with the DPDP Act and the rules thereunder, give intimation of such breach to the Data Protection Board of India and to each affected Data Principal, in such form and manner and within such timelines as may be prescribed. The Company shall also comply with applicable incident reporting obligations to CERT-In and, as applicable, to SEBI, AMFI, stock exchanges and depositories, and shall take reasonable steps to contain the breach, mitigate its impact and prevent recurrence.

11. Data retention and erasure

In accordance with the DPDP Act, the Company shall erase personal data upon withdrawal of consent, or as soon as it is reasonable to assume that the specified purpose is no longer being served, whichever is earlier, unless retention is necessary for compliance with applicable law. Indicative retention periods include:

  • records relating to mutual fund distribution, including client onboarding records, transaction records, communications and evidence of incidental advice – minimum five (5) years, in line with the PMLA, SEBI and AMFI requirements;
  • KYC records and transaction records – minimum five (5) years from the date of the transaction or from the date of cessation of the client relationship, as applicable, under the PMLA and the rules thereunder;
  • upon commencement of broking/depository activity, books of account, records and documents of a stock broker – minimum five (5) years under the SEBI (Stock Brokers) Regulations, 1992 and exchange requirements, and depository participant records – minimum five (5) years, or eight (8) years where required under applicable depository bye-laws and business rules;
  • call recordings and electronic communications relating to orders and client dealings – as per the timelines prescribed by SEBI, AMFI and the exchanges;
  • website and application logs and audit trails – as required under the Information Technology Act, 2000, CERT-In directions and applicable SEBI requirements.

Where records are subject to ongoing litigation, investigation, audit, arbitration or regulatory direction, they shall be retained until conclusion of such matter and any consequential appeal period. Upon expiry of the applicable retention period, personal data shall be securely deleted, destroyed or anonymised, and our Data Processors shall be required to do the same.

12. Rights and duties of data principals

Subject to the DPDP Act and the rules thereunder, you have the following rights in respect of your personal data:

  • Right to access information – to obtain a summary of the personal data being processed by us and the processing activities undertaken, the identities of all other Data Fiduciaries and Data Processors with whom your personal data has been shared, and a description of the data shared;
  • Right to correction, completion, updating and erasure – to have inaccurate or misleading personal data corrected, incomplete data completed, data updated, and personal data erased where it is no longer necessary for the purpose for which it was collected, unless retention is required under law;
  • Right of grievance redressal – to have readily available means of registering a grievance with us in respect of any act or omission regarding the performance of our obligations, and to receive a response within the prescribed timelines;
  • Right to nominate – to nominate any other individual who shall, in the event of your death or incapacity, exercise your rights under the DPDP Act on your behalf;
  • Right to withdraw consent – as set out in Section 5.3 above.

Requests may be made by writing to our contact details in Section 17. We may require verification of your identity before acting on a request, and may decline a request to the extent that acting on it would contravene applicable law, including our record-retention obligations.

As a Data Principal, you also owe certain duties under Section 15 of the DPDP Act, including to comply with applicable law while exercising your rights, not to impersonate another person while providing personal data, not to suppress any material information while providing personal data for any document or identifier issued by the State, not to register a false or frivolous grievance or complaint, and to furnish only such information as is verifiably authentic when seeking correction or erasure.

We shall not be responsible for the authenticity or accuracy of Personal Data submitted by you.

13. Children's data

Our services are intended for persons who are competent to contract under the Indian Contract Act, 1872. Where a folio, demat or trading account is opened in the name of a minor, it is operated through the parent or lawful guardian, who acts as the Data Principal on the minor's behalf. In accordance with the DPDP Act, the Company shall obtain verifiable consent of the parent or lawful guardian before processing the personal data of a child (an individual below eighteen (18) years of age), and shall not undertake any processing that is likely to cause any detrimental effect on the well-being of a child, nor undertake tracking or behavioural monitoring of children or targeted advertising directed at children. The same standard applies to persons with disability who have a lawful guardian.

14. Cookies and tracking technologies

Our Website and Mobile Application use cookies, SDKs and similar technologies for essential functions (such as secure log-in and session management), preferences, analytics and service improvement. Cookies may be persistent or session-based. You may accept or decline non-essential cookies through the cookie banner on our Website or through your browser or device settings; however, disabling essential cookies may affect the functionality of our Platforms. Where third-party analytics tools are used, such use is governed by our contracts with those providers and applicable Indian law. We do not use cookies or similar technologies to undertake tracking or behavioural monitoring of children or targeted advertising directed at children.

15. Links to third-party websites and applications

Our Website, Mobile Application or communications may contain links to, or integrations with, third-party websites, applications or services, including those of AMCs, RTAs, exchanges, depositories, payment gateways and banks. We are not responsible for the privacy practices or content of such third parties. This Policy applies solely to personal data collected by the Company, and you are encouraged to review the privacy policies of such third parties before providing them with any information.

16. Obligations of the company as data fiduciary

In addition to the obligations set out elsewhere in this Policy, the Company shall, in accordance with the DPDP Act:

  • comply with the DPDP Act irrespective of any agreement to the contrary or any failure by a Data Principal to carry out their duties;
  • process personal data only for a lawful purpose for which the Data Principal has given consent or which constitutes a legitimate use;
  • ensure the completeness, accuracy and consistency of personal data where it is likely to be used to make a decision affecting the Data Principal or is likely to be disclosed to another Data Fiduciary;
  • implement appropriate technical and organisational measures to ensure effective observance of the DPDP Act, and protect personal data in its possession or under its control by taking reasonable security safeguards;
  • publish the business contact information of the Data Protection Officer or the person able to answer questions about the processing of personal data;
  • establish an effective grievance redressal mechanism; and
  • if notified by the Central Government as a Significant Data Fiduciary, additionally appoint a Data Protection Officer based in India who is responsible to the Board of Directors, appoint an independent data auditor, and undertake periodic Data Protection Impact Assessments, audits and other prescribed measures.

17. Grievance redressal and contact details

For any questions, requests, grievances or complaints regarding this Policy or the processing of your personal data, you may contact:

Email care@profyt.com

We shall acknowledge and respond to grievances within the timelines prescribed under the DPDP Act and the rules thereunder and under applicable SEBI/AMFI requirements. If you are not satisfied with our response, or if you do not receive a response within the prescribed period, you may approach the Data Protection Board of India in the manner prescribed under the DPDP Act. Grievances relating to mutual fund distribution or other securities-market services may also be lodged with the concerned AMC or with AMFI.

18. Review and updates to this policy

This Policy shall be reviewed by the Board of Directors of the Company at least annually, and updated as required to incorporate changes introduced by the DPDP Act and the rules thereunder, SEBI, AMFI, the stock exchanges, depositories or any other regulatory authority, and to reflect any additional registrations obtained by the Company (including stock broking and depository participant services).

19. Omnibus clause

All extant and future Acts, rules, regulations, master circulars, directions, guidelines, guidance notes, advisories and clarifications issued from time to time by the Central Government, the Data Protection Board of India, the Ministry of Electronics and Information Technology, SEBI, AMFI, the stock exchanges, the depositories and any other regulatory or statutory authority having jurisdiction over the Company shall be the directing force and shall prevail over the contents of this Policy to the extent of any inconsistency.

Your data, your call.

Write to us and we will action any request under the DPDP Act.