LegalPrivacy Policy

Privacy Policy

Compliant with: DPDP Act, 2023 & IT (SPDI) Rules, 2011

Version

1.0

Effective Date

June 01, 2026

Data Fiduciary

MAHIR Investment Advisers Private Limited

CIN

U66190PN2025PTC244016

SEBI Reg. No.

INA000022668

Registered Office

PL G/A-9/1 Shop 1, MIDC G Nr Moris So, Chinchwad East, Pune 411019, Maharashtra

Data Protection Officer

Bharat Makkar

Email

compliance@mahir.in

1. About This Privacy Policy

MAHIR Investment Advisers Private Limited ('MIA', 'we', 'us', 'our') is committed to protecting the privacy and personal data of its clients, prospective clients, and users of the MIA App and Website ('Platform').

Legal Compliance Framework:

  • Digital Personal Data Protection Act, 2023 ('DPDP Act')
  • Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ('IT SPDI Rules')
  • Information Technology Act, 2000
  • SEBI (Investment Advisers) Regulations, 2013 and applicable SEBI Circulars
  • Prevention of Money Laundering Act, 2002 and AML/KYC guidelines
  • All other applicable laws and regulations of India

This Policy describes how MIA collects, uses, processes, stores, shares, and protects your personal data, and sets out the rights available to you as a Data Principal under applicable law.

2. Personal Data We Collect

We collect the following categories of personal data from you directly and through your use of the Platform:

  • Identity Data: Full legal name, PAN card number, Aadhaar number (masked/tokenized as permitted), date of birth, photograph, and specimen signature.
  • Contact Data: Residential and correspondence address, email address, mobile number, and emergency contact details.
  • Financial Data: Gross annual income, net worth, bank account details (for fee payments), investment portfolio information, existing liabilities, tax status, and FATCA/CRS declarations.
  • KYC & AML Data: Documentary evidence for KYC compliance, source of funds and wealth, politically exposed person (PEP) status, and sanctions screening data.
  • Risk Profile Data: Risk tolerance questionnaire responses, investment objectives, investment horizon, prior investment experience, and financial goals.
  • Platform Usage Data: IP address, device identifiers, browser type and version, operating system, pages visited, session duration, click-stream data, and referral URLs.
  • Communication Data: Queries, complaints, call recordings (with consent), correspondence, and meeting notes.
  • Technical Data: App crash reports, error logs, and performance diagnostic metrics.

3. Purposes and Legal Basis for Processing

This section details how your data is used and the legal justification for each use.

Purpose of ProcessingData Categories UsedLegal Basis
Client onboarding & KYC completionIdentity, Contact, KYC, FinancialLegal obligation (SEBI IA Reg., PMLA)
Providing personalized investment adviceRisk profile, Financial, Usage dataContract performance
AML/CFT compliance & suspicious transaction reportingKYC, Identity, Transaction dataLegal obligation (PMLA, SEBI)
Fee collection and billingContact, Financial, Bank dataContract performance
Platform improvement & analyticsUsage, Technical dataLegitimate interest / Consent
Regulatory reporting to SEBI, AMFI, FIU-INDIdentity, KYC, FinancialLegal obligation
Marketing communications (opt-in only)Contact, Usage dataConsent
Customer support & grievance redressalCommunication dataContract performance / Consent
Internal audit & complianceAll relevant categoriesLegal obligation / Legitimate interest

4. Data Sharing and Disclosure

MIA does not sell, rent, or trade your personal data to any third party for commercial purposes. We may share your data strictly on a need-to-know basis with the following:

  • Regulatory Authorities: SEBI, AMFI, Stock Exchanges, Depositories (NSDL/CDSL), Registrar and Transfer Agents, and other financial market regulators as required by law.
  • Financial Intelligence Unit — India (FIU-IND): for AML/CFT reporting obligations under PMLA.
  • KYC Registration Agencies (KRAs) and Central KYC Registry (CKYCRR): for KYC verification and record maintenance.
  • Technology Service Providers: Cloud hosting partners, IT vendors, and software service providers who process data strictly on MIA's behalf and are bound by written data processing agreements with equivalent security standards.
  • Professional Advisers: Statutory auditors, legal counsel, and tax advisers, subject to appropriate confidentiality obligations.
  • Legal Mandates: Courts, Tribunals, or Law Enforcement Authorities pursuant to a valid court order, summons, or statutory requirement.

5. Data Security Measures

MIA implements comprehensive technical and organizational security measures in accordance with IT SPDI Rules, 2011 and DPDP Act, 2023 to protect your personal data:

  • Encryption: All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 encryption.
  • Access Controls: Role-based access controls (RBAC) ensuring data access is strictly limited to authorized personnel on a need-to-know basis.
  • Authentication: Multi-factor authentication (MFA) mandatory for all personnel accessing client data and for Platform login.
  • Security Audits: Regular security audits, vulnerability assessments, and penetration testing by qualified third-party security professionals.
  • Incident Response: Documented incident response procedures for data breach detection, containment, and notification.
  • Data Breach Notification: In the event of a personal data breach, MIA will notify the Data Protection Board of India and affected clients within the timelines prescribed under the DPDP Act, 2023.

6. Your Rights as Data Principal

Under the DPDP Act, 2023 and applicable law, you have the following rights with respect to your personal data:

  • Right to Access: Obtain summary of personal data processed and processing activities undertaken (Written request to DPO).
  • Right to Correction: Request correction, completion, or updating of inaccurate/incomplete personal data (Written request to DPO).
  • Right to Erasure: Request deletion of personal data, subject to legal retention obligations and regulatory requirements (Written request to DPO).
  • Right to Grievance Redressal: Raise grievances about personal data processing with the Data Protection Officer (Email to compliance@mahir.in).
  • Right to Nominate: Nominate an individual to exercise data rights on your behalf in case of death or incapacity (Written request to DPO).
  • Right to Withdraw Consent: Withdraw consent for processing not based on legal obligation, without affecting prior lawful processing (Written request or Platform settings).

Processing Timeline: Requests to exercise rights will be responded to within the timeframe prescribed under the DPDP Act, 2023 (currently 30 days). MIA may require identity verification before processing requests.

7. Contact, DPO, and Grievance Officer

For privacy-related queries, concerns, or to exercise your data rights, please contact:

Data Protection Officer

Bharat Makkar

Email

compliance@mahir.in

Phone

+91 9084945151

Registered Address

PL G/A-9/1 Shop 1, MIDC G Nr Moris So, Chinchwad East, Pune 411019, Maharashtra

Resolution Timeline

Within 30 days from date of receipt of complaint

Jurisdiction

Courts at Pune, Maharashtra, India. If your complaint or concern is not satisfactorily resolved by MIA's DPO, you may approach the Data Protection Board of India or SEBI SCORES (scores.gov.in) for SEBI-related grievances.