Privacy Policy

1. Privacy Commitment

Debjani Chattopadhyay (ARN-121737), AMFI Registered Mutual Fund Distributor, is committed to maintaining the privacy, confidentiality, and security of personal information collected from investors and website visitors. This Privacy Policy explains how personal data is collected, used, stored, shared, and protected in accordance with the Digital Personal Data Protection Act, 2023 (DPDPA), the Information Technology Act, 2000, the SEBI Master Circular for Mutual Funds dated 20-Mar-2026, and the AMFI data sharing principles prescribed under the AMFI Master Circular for MFDs dated 14-Jan-2026. For the purposes of the DPDPA, Debjani Chattopadhyay acts as a Data Fiduciary in respect of the personal data of her clients.

2. Scope and Applicability

This policy applies to all individuals interacting with Debjani Chattopadhyay through this website, during client onboarding, Know Your Customer (KYC) verification, risk profiling, and mutual fund transaction processing. It extends to any service provider or vendor authorised to access or process client information on her behalf. By engaging with Debjani Chattopadhyay or using this website, you consent to the collection and use of your personal information as described in this policy.

3. Information We Collect

We collect personal information that is necessary to provide mutual fund distribution services and to comply with law. This includes identity information such as name, date of birth, Aadhaar reference where mandated for KYC, photograph, and signature; contact information such as address, mobile number, and email; financial information such as bank account details, income range, and investment details; risk profiling responses; and transaction records generated on the BSE STAR MF platform and through AMC and Registrar and Transfer Agent (RTA) feeds. Information is collected directly from you at the point of onboarding and transaction, with notice of the purpose of collection given at that point as required by the DPDPA.

4. How We Use Your Information

Personal information is used only to process KYC and account opening, execute mutual fund transactions you instruct, complete risk profiling and suitability assessment, service your folios including nomination and bank changes, communicate account statements, portfolio reviews and regulatory updates, comply with the Prevention of Money Laundering Act, 2002 and rules made under it, respond to grievances, and meet record-keeping obligations under SEBI and AMFI regulations. We do not sell personal data, and we do not share personal data with third parties for their marketing purposes.

5. Sharing and Disclosure

Personal data is shared only with entities that require it to complete your transactions and comply with law: Asset Management Companies whose schemes you invest in, Registrar and Transfer Agents (CAMS and KFintech), KYC Registration Agencies and the Central KYC Registry, the BSE STAR MF platform, and statutory or regulatory authorities including SEBI, AMFI, and the Financial Intelligence Unit – India when legally required. Any service provider engaged for record-keeping or communication is bound to confidentiality obligations consistent with this policy.

6. Data Security

Reasonable security safeguards are maintained to prevent unauthorised access, alteration, disclosure, or destruction of personal data. These include password protection and multi-factor authentication on devices and platforms used for client servicing, restricted access to physical records, and secure disposal of records after the retention period. In the event of a personal data breach, affected Data Principals and the Data Protection Board of India will be notified in the form and within the timelines prescribed under the DPDPA and its rules.

7. Data Retention

KYC and PMLA records are retained for a minimum of five years after the end of the business relationship, and transaction records for a minimum of five years from the date of the transaction, as required by the PML Rules, 2005. Other records are retained only as long as necessary for the purposes stated in this policy or as required by applicable law, after which they are securely deleted or destroyed.

8. Your Rights

Under the DPDPA you have the right to access a summary of your personal data and the processing activities carried out, the right to correction and updation of inaccurate or incomplete data, the right to erasure of data that is no longer necessary for the stated purpose or required to be retained by law, the right to withdraw consent for processing that is based on consent, and the right to grievance redressal. Requests may be made in writing to the Grievance Officer named below and will be acknowledged within 3 working days and addressed within 15 working days.

9. Children’s Data

Investments in the name of minors are accepted only through a registered guardian. Personal data of minors is collected with the verifiable consent of the parent or lawful guardian, is used only for folio servicing and legal compliance, and is never used for advertising directed at the minor, in line with the DPDPA.

10. Cookies

This website may use basic cookies to remember preferences and measure site usage. A consent banner allows you to accept or decline non-essential cookies. Declining cookies does not prevent you from reading any compliance content on this website.

11. Grievance Officer (DPDPA)

Grievance Officer: Debjani Chattopadhyay, Harop, Near Harop Agradoot Club, Bagnan, Howrah, West Bengal – 711303. Email: debjanichattopadhyay5@gmail.com. Phone: +91 98308 57549. If you are not satisfied with the response to a data-related grievance, you may approach the Data Protection Board of India as provided under the DPDPA.

12. Changes to This Policy

This policy is reviewed at least annually and whenever law or practice changes. The current version, with its effective date, is always available on this page.