Legal & Regulatory
Privacy Policy
Your privacy and data protection are fundamental to our trust principles. This policy explains what information we collect, why we collect it, how it is secured, and your rights under Indian law.
Last updated: January 2026 · Version 1.0 · Status: Published
1. Information We Collect
To provide SEBI-compliant trading and demat accounts, we collect personal and financial information, including:
- Identity Details: Full name, Date of Birth, Gender, PAN, and Aadhaar information obtained via authorized Digilocker or UIDAI e-KYC channels.
- Contact Information: Mobile number, email address, registered residential address, and correspondence address.
- Financial & Banking Details: Bank account number, IFSC code, cancelled cheque specimen, and income range or ITR documents (for derivatives trading).
- Technical & Session Data: IP address, device identifier, and access logs required for exchange audit and fraud detection.
2. Purpose of Collection
All data requested is collected strictly for regulatory, legal, and operational purposes:
- Verifying identity in compliance with SEBI KYC Master Circulars and Prevention of Money Laundering Act (PMLA).
- Facilitating the opening of demat accounts with central depositories (CDSL/NSDL).
- Reporting transactions, trading volume, and margins to Stock Exchanges (NSE/BSE).
- Sending mandatory transaction alerts, contract notes, and statutory disclosures.
3. Strict Commitment Against Data Selling
5. Data Storage & Encryption
We implement industry-standard cryptographic protocols:
- All website and API communications utilize Transport Layer Security (TLS 1.3) with 256-bit encryption.
- Sensitive data at rest (including Aadhaar numbers masked per UIDAI rules) is stored in encrypted databases with strict role-based access control.
- Internal infrastructure access requires multi-factor authentication (TOTP) and IP-allowlisted VPN connections.
6. Data Retention Period
Under PMLA and SEBI regulations, stock brokers are legally required to preserve client records, KYC documents, and transaction logs for a minimum statutory period of 5 years following account closure or cessation of business relationships. Upon expiration of this statutory period, client records are safely purged.
7. Your Rights & Access
You have the right to inspect your account records, review personal information on file, and request correction of inaccurate data. Changes to key identifiers (such as bank details or mobile number) require re-verification via OTP and signed verification to protect against unauthorized account takeover.
8. Data Protection & Privacy Officer
For inquiries, corrections, or grievances concerning your personal data, contact:
- Officer
- Information to be verified
- Designation
- Grievance & Data Protection Officer
- Information to be verified
- Address
- Information to be verified, Information to be verified