Loading
AMFI Registered Mutual Fund Distributor & SIF Distributor | EUIN E171790 | ARN-115652 | Initial Reg: 20-Sep-2025 | Valid until: 19-Sep-2028

Privacy Policy

Home Privacy Policy

✓ DPDPA 2023 Compliant

Privacy Policy

Prepared in accordance with the Digital Personal Data Protection Act 2023 (DPDPA 2023), Information Technology Act 2000, SEBI Regulations, and AMFI Guidelines
Fintopia Financial Services | ARN-115652 | Effective: July 2026 | Last Updated: July 2026
Fintopia Financial Services — Our Commitment to Your Privacy Fintopia Financial Services (ARN-115652) is an AMFI-registered Mutual Fund Distributor providing services including Mutual Fund Distribution, Insurance Distribution. We are committed to protecting the personal data of our investors, website visitors, and all stakeholders. This Privacy Policy explains how we collect, use, store, protect, and share your personal information in compliance with the Digital Personal Data Protection Act 2023 (DPDPA 2023) and all applicable regulations.

By using our services or visiting www.fintopiafinserv.com, you agree to the terms of this Privacy Policy. Please read it carefully.

1. Personal Data We Collect

We collect personal data that is necessary to provide our financial distribution services and comply with applicable regulations. The data we collect includes:

  • Health information and medical history (for health/life insurance only, with explicit consent)
  • Email address and communication preferences (for newsletter subscription, with opt-in consent)
  • Data Category Specific Data Points Collected
    Identity Data Full name, date of birth, gender, photograph, PAN card number, Aadhaar number (last 4 digits only), passport/voter ID
    Contact Data Residential address, email address, mobile number, WhatsApp number
    Financial Data Bank account details (account number, IFSC, bank name), net worth, income range, investment portfolio details, existing investments, liabilities
    KYC Data KYC status, KRA registration details, FATCA/CRS declarations, PEP (Politically Exposed Person) status, AML/CFT related data
    Transaction Data Investment transactions, redemptions, switches, SIP details, folio numbers, NAV history, portfolio valuation
    Risk Profile Data Risk tolerance assessment responses, investment goals, investment horizon, financial objectives
    Technical Data IP address, browser type and version, device information, pages visited, time spent on website (via cookies)
    Communication Data Records of correspondence, emails, phone calls (with consent), WhatsApp messages related to financial services
    Note: We collect only the minimum data necessary for providing our services and meeting regulatory requirements. We do not collect sensitive personal data beyond what is mandated by SEBI, AMFI, IRDAI, or other applicable regulators.

    2. How We Use Your Personal Data

    We use your personal data for the following purposes:

    Purpose Details & Legal Basis
    Service Delivery Processing your investment transactions, portfolio management, account maintenance — Contractual necessity
    KYC & AML Compliance Fulfilling Know Your Customer and Anti-Money Laundering requirements under PMLA 2002 and SEBI/AMFI regulations — Legal obligation
    Regulatory Reporting Submitting mandatory reports to SEBI, AMFI, IRDAI, Income Tax authorities as required — Legal obligation
    Account Statements Generating and sending transaction confirmations, account statements, and CAS — Contractual necessity
    Risk Assessment Assessing your risk profile and recommending suitable investment products — Legitimate interest
    Service Communication Sending portfolio updates, regulatory notices, scheme information, market updates — Legitimate interest
    Grievance Redressal Addressing and resolving your complaints and queries — Legal obligation and legitimate interest
    Newsletter / Blog Sending educational content, market updates, and newsletter — Consent-based (you can unsubscribe at any time)
    Fraud Prevention Detecting and preventing fraud, unauthorized transactions, and suspicious activities — Legal obligation and legitimate interest
    We will NEVER use your data for: Selling to third parties for marketing | Sharing with advertisers | Profiling for non-financial purposes | Any purpose not listed above without your explicit consent.

    3. Data Retention — Minimum 8 Years

    📁   Mandatory Retention Period All transaction records, investment documents, KYC data, and related personal data are retained for a minimum of 8 (eight) years from the end of the business relationship or the date of the last transaction — as mandated by SEBI Regulations, PMLA 2002, and AMFI Guidelines.

    After the mandatory retention period expires, personal data is securely deleted or anonymised using industry-standard methods. Technical data (website logs) is retained for a maximum of 12 months.
    Data Type Retention Period & Reason
    KYC Documents 8 years — PMLA 2002, SEBI KYC norms
    Transaction Records 8 years — SEBI Regulations, AMFI Guidelines
    Investment Documents 8 years — SEBI / AMFI compliance
    Correspondence Records 8 years — Regulatory and legal requirements
    Grievance Records 5 years — SEBI SCORES requirements
    Website / Technical Logs 12 months — Internal security purposes
    Newsletter Subscription Until unsubscription — Consent-based

    4. Data Sharing & Third Parties

    We share your personal data only when necessary and only with the following authorised parties:

    • Asset Management Companies (AMCs) — To process your investment transactions in the schemes you choose
    • Registrar & Transfer Agents (CAMS / KFintech) — For folio creation, transaction processing, and account statements
    • KYC Registration Agencies (KRAs) — For KYC verification, registration, and updates (CAMS KRA, CVL KRA, CKYC India, NDML)
    • MF Central — For consolidated portfolio management and CAS generation
    • Insurance Companies (IRDAI regulated) — For processing insurance applications and policy issuance
    • SEBI, AMFI, Income Tax, and other Regulators — As required by law for regulatory reporting and compliance
    • Technology Service Providers — Website hosting, email services (bound by strict confidentiality agreements)
    • Legal / Audit Professionals — For statutory audits and legal compliance (under confidentiality obligations)
    We do NOT share your data with: Advertisers | Marketing companies | Data brokers | Social media platforms | Any unauthorised third party for commercial purposes.

    5. Data Security Measures

    • All digital data is stored in password-protected, encrypted systems with restricted access
    • Physical documents are stored in locked, secure premises with access limited to authorised personnel only
    • All staff with access to personal data are bound by strict confidentiality obligations
    • Website data transmission is protected by SSL/TLS encryption (HTTPS)
    • Regular security reviews are conducted to identify and address vulnerabilities
    • In the event of a data breach, affected individuals will be notified as required under DPDPA 2023

    6. Cookies Policy

    Our website www.fintopiafinserv.com uses cookies to improve user experience and analyse website traffic. Cookies are small text files stored on your device.

    Cookie Type Purpose & Details
    Essential Cookies Required for website functionality — cannot be disabled. Include session management and security tokens.
    Analytics Cookies Help us understand how visitors use our website (pages visited, time spent). Data is anonymised. You can opt out via browser settings.
    Preference Cookies Remember your settings and preferences for a better experience on return visits.

    You can control cookies through your browser settings. Disabling essential cookies may affect website functionality. We do not use cookies for advertising or cross-site tracking.

    7. Your Rights Under DPDPA 2023

    Right to Access

    Request a copy of all personal data we hold about you at any time, free of charge.

    Right to Correction

    Request correction of any inaccurate, incomplete, or outdated personal data we hold.

    Right to Erasure

    Request deletion of your personal data, subject to mandatory regulatory retention requirements.

    Right to Grievance Redressal

    Contact our Data Protection Officer for any data privacy concern — response within 15 working days.

    Right to Withdraw Consent

    Withdraw consent for non-mandatory data processing (e.g. newsletter) at any time without affecting past processing.

    Right to Nominate

    Under DPDPA 2023, nominate a person to exercise your data rights in case of death or incapacity.

    To exercise any of the above rights, contact our Data Protection Officer at support@fintopiafinserv.com or +91 90881 00727. We will respond within 15 working days. If not satisfied, you may approach the Data Protection Board of India.

    8. Data Protection Officer

    Contact our Data Protection Officer for all privacy-related queries:

    NameSoumen Bose
    DesignationFounder & Data Protection Officer
    Emailsupport@fintopiafinserv.com
    Phone+91 90881 00727
    AddressKailash Residency, Shivapriya Apartment, 3rd Floor, 7/C, Bijoy Nagar, Baroda Bridge Road, Near Kathgola More, Naihati, North 24 Parganas, West Bengal - 743165
    Response TimeWithin 15 working days

    9. Children's Privacy

    Our services are not directed at children under 18 years of age. We do not knowingly collect personal data from minors. Minor investors can invest only through a natural guardian in accordance with SEBI / AMFI guidelines for minor folios. The guardian is responsible for providing accurate information.

    10. Changes to This Privacy Policy

    We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will update the "Last Updated" date on this page and notify registered investors via email. Your continued use of our services after the effective date constitutes acceptance of the updated policy.

    Regulatory References: Digital Personal Data Protection Act 2023 (DPDPA 2023) | Information Technology Act 2000 | SEBI (KYC Registration Agency) Regulations 2011 | PMLA 2002 | AMFI Master Circular January 2026 | IRDAI guidelines (if applicable)

    11. Governing Law & Jurisdiction

    This Privacy Policy is governed by the laws of India. Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of courts in Kanchrapara, West Bengal. For data protection grievances, you may also approach the Data Protection Board of India as constituted under DPDPA 2023.

    Effective Date: July 2026 | Last Updated: July 2026 | Version 1.0 | Fintopia Financial Services | ARN-115652 | www.fintopiafinserv.com
    Chat with Us