Skip to main content
DPDP Act 2023 Compliant

Privacy Policy

Apex TechFin is committed to protecting your personal data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and applicable financial regulations under SEBI, AMFI, IRDAI, and RBI.

Effective: 9 June 2025·Updated: 9 June 2025·Indian Law

Who We Are

Entity NameAPEX TECHFIN (Sole Proprietorship)
Role under DPDP ActData Fiduciary (Section 2(i))
AMFI RegistrationARN-354187 (registered in company name)
InsuranceIndividual IRDAI-licensed agents under this brand
Registered OfficeAhmedabad, Gujarat, India
Grievance Officer Emailinfo@apextechfin.com
Business Structure Disclosure
Apex TechFin is a trade name of a sole proprietorship (Proprietor: Ronik Gajjar). Mutual fund distribution is under company ARN-354187. Insurance is handled by individually IRDAI-licensed agents (family members) operating under this brand. We are NOT a SEBI-registered Investment Adviser, NOT an IRDAI Corporate Agent, and NOT an Insurance Web Aggregator.

Apex TechFin (“we”, “us”, or “our”) is an AMFI-registered Mutual Fund Distributor (ARN-354187, registered in the company name “APEX TECHFIN”) providing financial distribution and consultation services. Insurance is solicited by individually IRDAI-licensed agents associated with this brand. This Privacy Policy explains how we collect, use, share, and protect your personal data in our capacity as a Data Fiduciary under the Digital Personal Data Protection Act, 2023.

By using our website, mobile application, or services, you acknowledge that you have read and understood this Policy. If you do not agree, please discontinue use of our services.

Data We Collect

We collect personal data only to the extent necessary to provide our services and comply with applicable financial regulations (data minimisation principle, Section 8(3) DPDP Act).

CategoryData ExamplesBasis
IdentityFull name, date of birth, gender, PAN card, Aadhaar (last 4 digits only)Consent + KYC Legal Obligation
ContactMobile number, email address, residential address, city, pincodeConsent
FinancialIncome range, investment objectives, risk appetite, bank account details for mandate, existing portfolioConsent + Service Delivery
KYC / RegulatoryPAN verification, In-Person Verification (IPV) details, FATCA declarations, nominee detailsLegal Obligation (PMLA, SEBI, IRDAI)
TransactionInvestment history, SIP details, insurance premium records, loan enquiry details, order confirmationsContract Performance
TechnicalIP address, browser type, device ID, pages visited, session duration, referral sourceConsent (cookies) / Legitimate Use
CommunicationEnquiry messages, support tickets, call recordings (with prior notice), email correspondenceConsent / Legitimate Use

* We do not collect biometric data, caste/religion, or any data of persons under 18 years of age. Children are not our intended service audience.

Purpose of Processing

Mutual Fund Distribution
  • KYC completion and AMFI compliance
  • SIP/lumpsum order processing via BSE StarMF
  • Portfolio reporting and statement generation
  • Regulatory reporting to AMFI / fund houses
  • All transactions under company ARN-354187
Insurance (Individual Agents)
  • Proposal form completion by individually licensed IRDAI agent
  • Premium calculation and comparison
  • Policy issuance coordination with insurer
  • Renewal reminders and claim support
  • IRDAI regulatory compliance per individual agent license
Loan Consultation
  • Eligibility assessment and profile matching
  • Lender comparison and recommendation
  • Application assistance and documentation
  • Status tracking and follow-up
Platform & Operations
  • Account creation and authentication
  • Customer support and grievance resolution
  • Website / app improvement via analytics
  • Fraud prevention and security monitoring
  • Legal obligation compliance and audit

Your data will not be used for any purpose other than those specified above without obtaining fresh, specific consent from you (Section 6, DPDP Act).

Lawful Basis for Processing

Under the DPDP Act 2023, we process your personal data on the following lawful grounds:

1
Consent (Section 6)
For contact forms, marketing communications, and data uses beyond regulatory requirements. You may withdraw consent at any time by contacting our Grievance Officer — withdrawal will not affect prior lawful processing.
2
Legal Obligation (Section 7(c))
We are required by SEBI, AMFI, IRDAI, RBI, PMLA (Anti-Money Laundering), and Income Tax regulations to collect and retain KYC data, transaction records, and investor information for prescribed periods.
3
Voluntary Provision (Section 7(a))
When you provide us with personal data to enquire about or avail our financial services (e.g., submitting a contact form or requesting a portfolio review), we process that data for the specified purpose.

Data Sharing & Third Parties

We do not sell your personal data. We share it only with the following categories of parties and only to the extent required for service delivery or legal compliance:

AMFI-Registered Asset Management Companies (AMCs)
Order placement, KYC verification, portfolio statements
SBI MF, HDFC MF, ICICI Prudential, Mirae Asset, etc.
Registrar & Transfer Agents (R&T Agents)
Transaction processing and folio management
CAMS, KFintech (formerly Karvy)
BSE StAR MF / MFU
Online mutual fund transaction routing
Regulated exchange infrastructure
IRDAI-Licensed Insurance Companies
Policy issuance, premium processing, claim support — shared by the individual IRDAI-licensed agent handling your policy
LIC, HDFC Life, ICICI Lombard, Star Health, etc.
NBFC / Bank Lending Partners
Loan eligibility assessment and application forwarding (with your consent)
Regulated lenders only
Technology & Cloud Service Providers
Website hosting, CRM, email delivery, analytics
Data Processors bound by written contracts (Section 8(2) DPDP Act)
Regulatory & Legal Authorities
SEBI, AMFI, IRDAI, Income Tax, courts — only when legally mandated
Section 7(c) DPDP Act

Cross-Border Transfers: Our primary data storage is within India. Where cloud service providers process data outside India, we ensure contractual safeguards and comply with any restrictions notified by the Central Government under Section 16 of the DPDP Act. No restricted destinations (as per Central Government notifications) are used.

Data Retention

We retain personal data only for as long as necessary for the stated purpose or as mandated by applicable law (Section 8(7) DPDP Act — data must be purged once the purpose is fulfilled, subject to legal retention requirements).

KYC documents
10 years after client relationship ends
PMLA 2002 / SEBI guidelines
Mutual fund transaction records
8 years from transaction date
SEBI (MF) Regulations
Insurance proposal / policy records
3 years after policy expiry / claim closure
IRDAI regulations
Loan enquiry data (without disbursement)
2 years after last contact
RBI guidelines
Contact / enquiry form data
2 years, then deleted or anonymised
DPDP Act + consent period
Website analytics / log data
12 months rolling
Legitimate use basis
Communication records (emails, calls)
3 years
Legal / audit requirement

Security Safeguards

We implement reasonable security safeguards as required under Section 8(4) of the DPDP Act to prevent unauthorised access, disclosure, or loss of personal data.

Encryption
TLS 1.3 in transit; AES-256 at rest for sensitive fields
Access Control
Role-based access; least privilege; staff training
Audit Trails
All data access and modifications logged and monitored
Breach Response
Incident response plan; DPBoI notification within 72 hours
Regular Reviews
Periodic security assessments and vulnerability scans
Processor Contracts
Written DPA with all sub-processors per Section 8(2)

Data Breach Notification: In the event of a personal data breach that is likely to cause harm to you, we will notify the Data Protection Board of India and you in the prescribed form and manner under Section 8(6) of the DPDP Act.

Your Rights as a Data Principal

Under the DPDP Act 2023, you have the following rights. Exercise them by contacting our Grievance Officer.

Right to Access InformationSection 11
Obtain a summary of your personal data we process, the purposes of processing, and the identity of all data fiduciaries and processors who have received your data.
Right to Correction and ErasureSection 12
Request correction of inaccurate or misleading personal data, and erasure of data that is no longer necessary for the purpose for which it was collected — subject to legal retention obligations.
Right to Withdraw ConsentSection 6(4)
Withdraw consent for any processing based on consent at any time. Withdrawal will be actioned within a reasonable period and will not affect prior lawful processing.
Right to Grievance RedressalSection 13
Have your grievances addressed by our Grievance Officer within 30 days. If not resolved, you may approach the Data Protection Board of India.
Right to NominateSection 14
Nominate another person to exercise your data principal rights in the event of your death or incapacity.

How to exercise your rights: Send a written request to info@apextechfin.com with your name, registered mobile number, and a description of your request. We will respond within 30 days of receipt. For unresolved grievances, you may file a complaint with the Data Protection Board of India (DPBoI) once it is operationalised.

Children's Data

Section 9 DPDP Act Compliance: Our financial services are intended for adults (18 years and above). We do not knowingly collect personal data of any person under 18 years of age. If you are a parent or guardian and believe we have inadvertently collected data of a minor, please contact our Grievance Officer immediately for prompt deletion. We do not conduct any tracking, behavioural monitoring, or targeted advertising directed at children.

Grievance Officer

In accordance with the DPDP Act and applicable SEBI/IRDAI regulations, we have designated a Grievance Officer to handle data protection queries:

Grievance Officer
Ronik Gajjar (Proprietor)
Organisation
Apex TechFin
Email
info@apextechfin.com
Address
Ahmedabad, Gujarat, India
Response Time
Within 30 days of receipt
Regulatory Authority
Data Protection Board of India (DPBoI)

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, technology, or applicable law. We will notify you of material changes via email or a prominent notice on our website. The updated policy will carry a revised “Last Updated” date. Continued use of our services after the effective date constitutes acceptance.

This Privacy Policy was last reviewed on 9 June 2025 and is compliant with the Digital Personal Data Protection Act, 2023 (Act No. 22 of 2023) and the draft DPDP Rules as available for public consultation.

Questions about your data?

Our Grievance Officer is available to address any data protection concerns you may have.

💬 Chat on WhatsApp