Privacy Policy
Compliant with: DPDP Act, 2023 & IT (SPDI) Rules, 2011
1.0
June 01, 2026
MAHIR Investment Advisers Private Limited
U66190PN2025PTC244016
INA000022668
PL G/A-9/1 Shop 1, MIDC G Nr Moris So, Chinchwad East, Pune 411019, Maharashtra
Bharat Makkar
compliance@mahir.in
1. About This Privacy Policy
MAHIR Investment Advisers Private Limited ('MIA', 'we', 'us', 'our') is committed to protecting the privacy and personal data of its clients, prospective clients, and users of the MIA App and Website ('Platform').
Legal Compliance Framework:
- Digital Personal Data Protection Act, 2023 ('DPDP Act')
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ('IT SPDI Rules')
- Information Technology Act, 2000
- SEBI (Investment Advisers) Regulations, 2013 and applicable SEBI Circulars
- Prevention of Money Laundering Act, 2002 and AML/KYC guidelines
- All other applicable laws and regulations of India
This Policy describes how MIA collects, uses, processes, stores, shares, and protects your personal data, and sets out the rights available to you as a Data Principal under applicable law.
2. Personal Data We Collect
We collect the following categories of personal data from you directly and through your use of the Platform:
- Identity Data: Full legal name, PAN card number, Aadhaar number (masked/tokenized as permitted), date of birth, photograph, and specimen signature.
- Contact Data: Residential and correspondence address, email address, mobile number, and emergency contact details.
- Financial Data: Gross annual income, net worth, bank account details (for fee payments), investment portfolio information, existing liabilities, tax status, and FATCA/CRS declarations.
- KYC & AML Data: Documentary evidence for KYC compliance, source of funds and wealth, politically exposed person (PEP) status, and sanctions screening data.
- Risk Profile Data: Risk tolerance questionnaire responses, investment objectives, investment horizon, prior investment experience, and financial goals.
- Platform Usage Data: IP address, device identifiers, browser type and version, operating system, pages visited, session duration, click-stream data, and referral URLs.
- Communication Data: Queries, complaints, call recordings (with consent), correspondence, and meeting notes.
- Technical Data: App crash reports, error logs, and performance diagnostic metrics.
3. Purposes and Legal Basis for Processing
This section details how your data is used and the legal justification for each use.
| Purpose of Processing | Data Categories Used | Legal Basis |
|---|---|---|
| Client onboarding & KYC completion | Identity, Contact, KYC, Financial | Legal obligation (SEBI IA Reg., PMLA) |
| Providing personalized investment advice | Risk profile, Financial, Usage data | Contract performance |
| AML/CFT compliance & suspicious transaction reporting | KYC, Identity, Transaction data | Legal obligation (PMLA, SEBI) |
| Fee collection and billing | Contact, Financial, Bank data | Contract performance |
| Platform improvement & analytics | Usage, Technical data | Legitimate interest / Consent |
| Regulatory reporting to SEBI, AMFI, FIU-IND | Identity, KYC, Financial | Legal obligation |
| Marketing communications (opt-in only) | Contact, Usage data | Consent |
| Customer support & grievance redressal | Communication data | Contract performance / Consent |
| Internal audit & compliance | All relevant categories | Legal obligation / Legitimate interest |
4. Data Sharing and Disclosure
MIA does not sell, rent, or trade your personal data to any third party for commercial purposes. We may share your data strictly on a need-to-know basis with the following:
- Regulatory Authorities: SEBI, AMFI, Stock Exchanges, Depositories (NSDL/CDSL), Registrar and Transfer Agents, and other financial market regulators as required by law.
- Financial Intelligence Unit — India (FIU-IND): for AML/CFT reporting obligations under PMLA.
- KYC Registration Agencies (KRAs) and Central KYC Registry (CKYCRR): for KYC verification and record maintenance.
- Technology Service Providers: Cloud hosting partners, IT vendors, and software service providers who process data strictly on MIA's behalf and are bound by written data processing agreements with equivalent security standards.
- Professional Advisers: Statutory auditors, legal counsel, and tax advisers, subject to appropriate confidentiality obligations.
- Legal Mandates: Courts, Tribunals, or Law Enforcement Authorities pursuant to a valid court order, summons, or statutory requirement.
5. Data Security Measures
MIA implements comprehensive technical and organizational security measures in accordance with IT SPDI Rules, 2011 and DPDP Act, 2023 to protect your personal data:
- Encryption: All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 encryption.
- Access Controls: Role-based access controls (RBAC) ensuring data access is strictly limited to authorized personnel on a need-to-know basis.
- Authentication: Multi-factor authentication (MFA) mandatory for all personnel accessing client data and for Platform login.
- Security Audits: Regular security audits, vulnerability assessments, and penetration testing by qualified third-party security professionals.
- Incident Response: Documented incident response procedures for data breach detection, containment, and notification.
- Data Breach Notification: In the event of a personal data breach, MIA will notify the Data Protection Board of India and affected clients within the timelines prescribed under the DPDP Act, 2023.
6. Your Rights as Data Principal
Under the DPDP Act, 2023 and applicable law, you have the following rights with respect to your personal data:
- Right to Access: Obtain summary of personal data processed and processing activities undertaken (Written request to DPO).
- Right to Correction: Request correction, completion, or updating of inaccurate/incomplete personal data (Written request to DPO).
- Right to Erasure: Request deletion of personal data, subject to legal retention obligations and regulatory requirements (Written request to DPO).
- Right to Grievance Redressal: Raise grievances about personal data processing with the Data Protection Officer (Email to compliance@mahir.in).
- Right to Nominate: Nominate an individual to exercise data rights on your behalf in case of death or incapacity (Written request to DPO).
- Right to Withdraw Consent: Withdraw consent for processing not based on legal obligation, without affecting prior lawful processing (Written request or Platform settings).
Processing Timeline: Requests to exercise rights will be responded to within the timeframe prescribed under the DPDP Act, 2023 (currently 30 days). MIA may require identity verification before processing requests.
7. Contact, DPO, and Grievance Officer
For privacy-related queries, concerns, or to exercise your data rights, please contact:
Bharat Makkar
compliance@mahir.in
+91 9084945151
PL G/A-9/1 Shop 1, MIDC G Nr Moris So, Chinchwad East, Pune 411019, Maharashtra
Within 30 days from date of receipt of complaint
Courts at Pune, Maharashtra, India. If your complaint or concern is not satisfactorily resolved by MIA's DPO, you may approach the Data Protection Board of India or SEBI SCORES (scores.gov.in) for SEBI-related grievances.