Privacy Policy

Privacy Policy

This Privacy Policy ("Policy") describes how Indipe ("Indipe", "we", "us", "our") collects, uses, processes, stores, shares, retains, and protects information relating to its partners, distributors, and other permitted users ("Users") in the course of providing access to its technology platform and related services.

This Policy is framed in accordance with applicable law, SEBI regulations, AMFI regulations, AMFI Data Sharing Principles, and Asset Management Company ("AMC") requirements, and forms an integral part of the contractual and regulatory framework governing use of the Indipe platform.

1. APPLICABILITY AND SCOPE

  1. 1.1. This Policy applies to all information collected, received, accessed, or processed by Indipe in connection with:
    1. 1.1.1. Partner onboarding and Know Your Customer / Know Your Distributor (KYC / KYD);
    2. 1.1.2. facilitation of mutual fund distribution under Regular Plans;
    3. 1.1.3. regulatory, compliance, audit, reporting, and due diligence obligations;
    4. 1.1.4. operational support, system access, and communication; and
    5. 1.1.5. prevention of fraud, misuse, or unauthorised activity.
  2. 1.2. This Policy applies irrespective of the mode of interaction, including electronic, digital, physical, or telephonic means.

2. NATURE OF INFORMATION COLLECTED

  1. 2.1. Indipe collects only such information as is necessary, relevant, and mandated for lawful and regulatory purposes. This may include:
    1. 2.1.1. Identity and Registration Information: Name, PAN, AMFI Registration Number (ARN), ARN validity, KYC/KYD status, and constitution of the Partner (individual or non-individual).
    2. 2.1.2. Contact Information: Registered address, correspondence address, email address, and mobile number.
    3. 2.1.3. Entity and Authorisation Details (where applicable): Details of proprietors, partners, directors, authorised signatories, and supporting authorisation documents.
    4. 2.1.4. Financial and Banking Information: Bank account details required for regulatory verification, commission crediting, or reconciliation, strictly in accordance with AMFI and AMC norms.
    5. 2.1.5. Regulatory and Compliance Information: Declarations, self-certifications (including DSC forms, where applicable), audit confirmations, and compliance-related communications.
  2. 2.2. Indipe does not intentionally collect information beyond what is required for compliance, operations, or lawful purposes.

3. PURPOSE AND LAWFUL BASIS OF PROCESSING

  1. 3.1. Information is collected and processed strictly for the following purposes:
    1. 3.1.1. verification and validation of KYC / KYD;
    2. 3.1.2. onboarding, authentication, and access management;
    3. 3.1.3. facilitation of permitted mutual fund distribution activities;
    4. 3.1.4. compliance with applicable laws, SEBI regulations, AMFI guidelines, and AMC requirements;
    5. 3.1.5. audit, inspection, reporting, and regulatory disclosures;
    6. 3.1.6. communication relating to operational, compliance, or support matters; and
    7. 3.1.7. detection, prevention, and investigation of fraud, misuse, or regulatory violations.
  2. 3.2. Information is processed on the basis of:
    1. 3.2.1. legal and regulatory obligations;
    2. 3.2.2. contractual necessity;
    3. 3.2.3. legitimate business interests; and
    4. 3.2.4. consent provided by Users at the time of onboarding or continued use.

4. REGULATORY AND THIRD-PARTY DISCLOSURES

  1. 4.1. The Partner expressly acknowledges and agrees that, in order to comply with applicable laws, SEBI regulations, AMFI guidelines, AMFI Data Sharing Principles, and Asset Management Company (AMC) requirements, Indipe may be required to access, use, process, and disclose information relating to the Partner and associated records strictly on a need-to-know and compliance-driven basis.
  2. 4.2. Accordingly, Indipe may disclose such information, without further consent or notice, to the extent legally or contractually required, to:
    1. 4.2.1. Asset Management Companies (AMCs);
    2. 4.2.2. Registrars and Transfer Agents (RTAs);
    3. 4.2.3. KYC Registration Agencies (KRAs);
    4. 4.2.4. AMFI, SEBI, or any other statutory, regulatory, or supervisory authority;
    5. 4.2.5. auditors, due diligence agencies, and professional advisers; and
    6. 4.2.6. technology, infrastructure, or operational service providers engaged for lawful support functions.
  3. 4.3. Any disclosure under this Policy shall be limited strictly to the minimum information necessary to fulfil regulatory, contractual, audit, operational, or legal obligations, and shall not be made for any unauthorised, promotional, or commercial exploitation.
  4. 4.4. The Partner expressly understands and agrees that such disclosures are an integral and mandatory part of the regulatory framework governing mutual fund distribution, and that refusal, restriction, or objection to such disclosure may render continued association or onboarding non-viable from a compliance standpoint.
  5. 4.5. Indipe does not sell, lease, rent, monetise, or commercially exploit personal or KYC-related data and shall not permit use of such information for cross-marketing or unrelated purposes.

5. DATA STORAGE, ACCESS CONTROL, AND SECURITY

  1. 5.1. Indipe implements and maintains robust administrative, technical, and organisational security measures that are commensurate with the nature, sensitivity, and volume of information processed, and are designed to prevent unauthorised access, alteration, disclosure, loss, misuse, or compromise of data, in accordance with applicable laws, SEBI regulations, AMFI guidelines, and AMC requirements.
  2. 5.2. Access to information is strictly controlled and governed through:
    1. 5.2.1. role-based access permissions,
    2. 5.2.2. authentication and authorisation mechanisms, and
    3. 5.2.3. enforcement of the principle of least privilege and need-to-know basis.
  3. 5.3. Only duly authorised personnel with a legitimate business or regulatory requirement are permitted access to such information.
  4. 5.4. Information may be stored in secure electronic or physical form, within systems and environments that are subject to:
    1. 5.4.1. access controls,
    2. 5.4.2. logging and monitoring,
    3. 5.4.3. internal security policies, and
    4. 5.4.4. periodic review to mitigate unauthorised or inadvertent exposure.
  5. 5.5. Indipe takes reasonable steps to ensure that any third-party service providers engaged for storage, processing, or operational support implement security standards and controls consistent with this Policy and applicable regulatory expectations.
  6. 5.6. Notwithstanding the above, the Partner acknowledges that no data transmission, storage system, or security framework can be entirely immune from risk, including risks arising from force majeure events, cyber incidents, or factors beyond reasonable control. Indipe does not provide any warranty of absolute security but shall take commercially reasonable and regulator-aligned measures to safeguard information.

6. DATA ACCURACY AND USER RESPONSIBILITY

  1. 6.1. The User shall be solely and entirely responsible for ensuring that all information, declarations, and documents provided to Indipe, including KYC / KYD details, are true, complete, accurate, current, and not misleading at all times.
  2. 6.2. Indipe shall rely conclusively and in good faith on the information furnished by the User and shall have no obligation to independently verify the accuracy, completeness, or continued validity of such information, except to the extent expressly required under applicable law or regulatory guidelines.
  3. 6.3. The User expressly acknowledges that any error, omission, misrepresentation, suppression of material information, or failure to update information, including KYC, ARN, contact, or bank details, shall be at the User's sole risk and responsibility, and Indipe shall not be liable for any loss, delay, regulatory issue, or adverse consequence arising therefrom.
  4. 6.4. The User shall promptly update Indipe of any change in KYC, KYD, registration, contact, or other material particulars through the prescribed process, and failure to do so shall be deemed a breach of the User's regulatory obligations.

7. CONFIDENTIALITY

  1. 7.1. Indipe shall treat non-public information as confidential, subject always to regulatory, statutory, audit, and supervisory requirements.
  2. 7.2. Confidentiality obligations shall not apply where disclosure is:
    1. 7.2.1. required by law or regulator,
    2. 7.2.2. required by AMFI, AMC, or SEBI,
    3. 7.2.3. necessary for audit or due diligence, or
    4. 7.2.4. required to protect Indipe's legal or regulatory interests.
  3. 7.3. Indipe shall not be liable for disclosures made in good faith pursuant to such obligations.

8. DATA RETENTION

  1. 8.1. Information shall be retained for as long as required under law, regulation, AMFI / AMC requirements, or legitimate compliance needs, irrespective of cessation of association or usage.
  2. 8.2. Indipe shall not be obligated to delete or anonymise information where retention is required for:
    1. 8.2.1. audit,
    2. 8.2.2. investigation,
    3. 8.2.3. regulatory reporting,
    4. 8.2.4. dispute resolution, or
    5. 8.2.5. enforcement of legal rights.
  3. 8.3. Users acknowledge that data retention periods are determined by regulatory necessity and not user preference.

9. CONSENT

  1. 9.1. By submitting information and continuing to access the platform, the User irrevocably consents to the collection, use, processing, and disclosure of information in accordance with this Policy.
  2. 9.2. Such consent shall be deemed to be:
    1. 9.2.1. informed,
    2. 9.2.2. explicit for compliance purposes, and
    3. 9.2.3. continuing in nature.
  3. 9.3. Withdrawal of consent shall not affect processing undertaken to meet regulatory or legal obligations, and may render continued access non-viable.

10. DISCLAIMER OF LIABILITY

  1. 10.1. Indipe shall not be liable for any loss, damage, regulatory consequence, or third-party claim arising from:
    1. 10.1.1. incorrect or incomplete information provided by the User;
    2. 10.1.2. failure by the User to update KYC or contact details;
    3. 10.1.3. acts or omissions of AMCs, RTAs, KRAs, or regulators; or
    4. 10.1.4. events beyond reasonable control, including cyber incidents.
  2. 10.2. Use of the platform and submission of information is entirely at the User's risk, subject to applicable law.

11. POLICY AMENDMENTS

  1. 11.1. Indipe reserves the right to amend this Policy at any time to reflect changes in law, regulation, or operational requirements.
  2. 11.2. Amendments shall be effective upon publication, and continued use shall constitute acceptance.
  3. 11.3. No separate consent shall be required where amendments are driven by regulatory changes.

12. SEVERABILITY AND INTERPRETATION

  1. 12.1. If any provision of this Policy is held invalid or unenforceable, the remaining provisions shall continue in full force.
  2. 12.2. This Policy shall be interpreted in a manner that maximises regulatory compliance and risk mitigation for Indipe.

13. GOVERNING LAW AND JURISDICTION

  1. 13.1. This Policy shall be governed by the laws of India.
  2. 13.2. Courts at Pune shall have exclusive jurisdiction, subject to regulatory forums having overriding authority.

This Privacy Policy is framed to ensure strict compliance with SEBI regulations, AMFI guidelines, AMFI Data Sharing Principles, and AMC requirements. Compliance with this Policy is mandatory and non-negotiable and is integral to Indipe's regulated operations.