Privacy Policy

✓ DPDPA 2023 Compliant

Privacy Policy

Prepared in accordance with the Digital Personal Data Protection Act 2023 (DPDPA 2023), Information Technology Act 2000, SEBI Regulations, and AMFI Guidelines
Gaurav Singhvi | 143128 | Effective: July 2026 | Last Updated: July 2026
Gaurav Singhvi — Our Commitment to Your Privacy Gaurav Singhvi (143128) is an AMFI-registered Mutual Fund Distributor providing services including Mutual Fund Distribution, Insurance Distribution, PMS Distribution. We are committed to protecting the personal data of our investors, website visitors, and all stakeholders. This Privacy Policy explains how we collect, use, store, protect, and share your personal information in compliance with the Digital Personal Data Protection Act 2023 (DPDPA 2023) and all applicable regulations.

By using our services or visiting www.cfpgauravsinghvi.com, you agree to the terms of this Privacy Policy. Please read it carefully.

1. Personal Data We Collect

We collect personal data that is necessary to provide our financial distribution services and comply with applicable regulations. The data we collect includes:

  • Portfolio Management preferences, risk strategy, performance benchmarks
  • Health information and medical history (for health/life insurance only, with explicit consent)
  • Data Category Specific Data Points Collected
    Identity Data Full name, date of birth, gender, photograph, PAN card number, Aadhaar number (last 4 digits only), passport/voter ID
    Contact Data Residential address, email address, mobile number, WhatsApp number
    Financial Data Bank account details (account number, IFSC, bank name), net worth, income range, investment portfolio details, existing investments, liabilities
    KYC Data KYC status, KRA registration details, FATCA/CRS declarations, PEP (Politically Exposed Person) status, AML/CFT related data
    Transaction Data Investment transactions, redemptions, switches, SIP details, folio numbers, NAV history, portfolio valuation
    Risk Profile Data Risk tolerance assessment responses, investment goals, investment horizon, financial objectives
    Technical Data IP address, browser type and version, device information, pages visited, time spent on website (via cookies)
    Communication Data Records of correspondence, emails, phone calls (with consent), WhatsApp messages related to financial services
    Note: We collect only the minimum data necessary for providing our services and meeting regulatory requirements. We do not collect sensitive personal data beyond what is mandated by SEBI, AMFI, IRDAI, or other applicable regulators.

    2. How We Use Your Personal Data

    We use your personal data for the following purposes:

    Purpose Details & Legal Basis
    Service Delivery Processing your investment transactions, portfolio management, account maintenance — Contractual necessity
    KYC & AML Compliance Fulfilling Know Your Customer and Anti-Money Laundering requirements under PMLA 2002 and SEBI/AMFI regulations — Legal obligation
    Regulatory Reporting Submitting mandatory reports to SEBI, AMFI, IRDAI, Income Tax authorities as required — Legal obligation
    Account Statements Generating and sending transaction confirmations, account statements, and CAS — Contractual necessity
    Risk Assessment Assessing your risk profile and recommending suitable investment products — Legitimate interest
    Service Communication Sending portfolio updates, regulatory notices, scheme information, market updates — Legitimate interest
    Grievance Redressal Addressing and resolving your complaints and queries — Legal obligation and legitimate interest
    Fraud Prevention Detecting and preventing fraud, unauthorized transactions, and suspicious activities — Legal obligation and legitimate interest
    We will NEVER use your data for: Selling to third parties for marketing | Sharing with advertisers | Profiling for non-financial purposes | Any purpose not listed above without your explicit consent.

    3. Data Retention — Minimum 8 Years

    📁   Mandatory Retention Period All transaction records, investment documents, KYC data, and related personal data are retained for a minimum of 8 (eight) years from the end of the business relationship or the date of the last transaction — as mandated by SEBI Regulations, PMLA 2002, and AMFI Guidelines.

    After the mandatory retention period expires, personal data is securely deleted or anonymised using industry-standard methods. Technical data (website logs) is retained for a maximum of 12 months.
    Data Type Retention Period & Reason
    KYC Documents 8 years — PMLA 2002, SEBI KYC norms
    Transaction Records 8 years — SEBI Regulations, AMFI Guidelines
    Investment Documents 8 years — SEBI / AMFI compliance
    Correspondence Records 8 years — Regulatory and legal requirements
    Grievance Records 5 years — SEBI SCORES requirements
    Website / Technical Logs 12 months — Internal security purposes

    4. Data Sharing & Third Parties

    We share your personal data only when necessary and only with the following authorised parties:

    We do NOT share your data with: Advertisers | Marketing companies | Data brokers | Social media platforms | Any unauthorised third party for commercial purposes.

    5. Data Security Measures

    6. Cookies Policy

    Our website www.cfpgauravsinghvi.com uses cookies to improve user experience and analyse website traffic. Cookies are small text files stored on your device.

    Cookie Type Purpose & Details
    Essential Cookies Required for website functionality — cannot be disabled. Include session management and security tokens.
    Analytics Cookies Help us understand how visitors use our website (pages visited, time spent). Data is anonymised. You can opt out via browser settings.
    Preference Cookies Remember your settings and preferences for a better experience on return visits.

    You can control cookies through your browser settings. Disabling essential cookies may affect website functionality. We do not use cookies for advertising or cross-site tracking.

    7. Your Rights Under DPDPA 2023

    Right to Access

    Request a copy of all personal data we hold about you at any time, free of charge.

    Right to Correction

    Request correction of any inaccurate, incomplete, or outdated personal data we hold.

    Right to Erasure

    Request deletion of your personal data, subject to mandatory regulatory retention requirements.

    Right to Grievance Redressal

    Contact our Data Protection Officer for any data privacy concern — response within 15 working days.

    Right to Withdraw Consent

    Withdraw consent for non-mandatory data processing (e.g. newsletter) at any time without affecting past processing.

    Right to Nominate

    Under DPDPA 2023, nominate a person to exercise your data rights in case of death or incapacity.

    To exercise any of the above rights, contact our Data Protection Officer at gauravsinghvimf@gmail.com or 9904336060. We will respond within 15 working days. If not satisfied, you may approach the Data Protection Board of India.

    8. Data Protection Officer

    Contact our Data Protection Officer for all privacy-related queries:

    NameGaurav Singhvi
    Designation[DPO Designation]
    Emailgauravsinghvimf@gmail.com
    Phone9904336060
    AddressB - 701, Unicus Shyamal, Shyamal Cross Road, Satellite, Ahmedabad, Gujarat (India) 380 015
    Response TimeWithin 15 working days

    9. Children's Privacy

    Our services are not directed at children under 18 years of age. We do not knowingly collect personal data from minors. Minor investors can invest only through a natural guardian in accordance with SEBI / AMFI guidelines for minor folios. The guardian is responsible for providing accurate information.

    10. Changes to This Privacy Policy

    We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will update the "Last Updated" date on this page and notify registered investors via email. Your continued use of our services after the effective date constitutes acceptance of the updated policy.

    Regulatory References: Digital Personal Data Protection Act 2023 (DPDPA 2023) | Information Technology Act 2000 | SEBI (KYC Registration Agency) Regulations 2011 | PMLA 2002 | AMFI Master Circular January 2026 | IRDAI guidelines (if applicable)

    11. Governing Law & Jurisdiction

    This Privacy Policy is governed by the laws of India. Any disputes arising from this Privacy Policy shall be subject to the exclusive jurisdiction of courts in Ahmedabad. For data protection grievances, you may also approach the Data Protection Board of India as constituted under DPDPA 2023.

    Effective Date: July 2026 | Last Updated: July 2026 | Version 1.0 | Gaurav Singhvi | 143128 | www.cfpgauravsinghvi.com