Privacy Policy
Last Updated: 25th June 2026
1. INTRODUCTION
Finanza InvesTek Private Limited, operating under the brands InvesTek, SheFin, and NRI Wealth (collectively referred to as the “Company”, “Group”, “We”, “Us”, or “Our”), is committed to protecting the privacy and personal data of individuals interacting with our services.
This Privacy Policy describes how we collect, use, store, process, share, transfer, retain, and protect personal data when you interact with us through:
- websites
- mobile applications
- client onboarding channels
- communications
- webinars and events
- digital forms
- social media channels
- products and services offered by the Group
This Privacy Policy is intended to comply with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), applicable rules thereunder, and other relevant Indian laws.
By accessing or using our services, you acknowledge that you have read and understood this Privacy Policy.
2. APPLICABILITY
This Privacy Policy applies to all products, services, websites, platforms, and digital channels operated by Finanza InvesTek Private Limited, including but not limited to:
InvesTek: Wealth and financial distribution services.
SheFin: Women-focused financial platform and digital ecosystem.
NRI Wealth: Financial services and wealth facilitation platform for Non-Resident Indians.
This Policy applies to:
- website visitors
- prospective clients
- existing clients
- users of mobile applications
- business partners
- employees and consultants
- vendors and service providers
- referral sources and introducers
Where a platform-specific privacy notice or addendum exists, such notice shall supplement this Policy.
3. ABOUT OUR SERVICES
Finanza InvesTek Private Limited is engaged in financial services and related support activities, including but not limited to:
- mutual fund distribution
- insurance facilitation
- wealth management support services
- investor education
- financial product distribution
- private market access facilitation
- technology-enabled financial engagement services
- NRI-focused financial facilitation
The Company operates subject to applicable registrations, licenses, empanelments, approvals, and regulatory permissions.
Regulatory Disclosure
Finanza InvesTek Private Limited is an:
- AMFI Registered Mutual Fund Distributor (ARN-278016)
- APRN Holder (APRN05039)
Nothing contained in this Privacy Policy or on any Group platform shall be construed as providing investment advisory, tax, legal, accounting, immigration, or fiduciary advisory services, unless specifically permitted under applicable law and expressly agreed in writing.
4. PERSONAL DATA WE COLLECT
We may collect personal data directly from you or through authorized third parties.
A. Identity Data
- full name
- date of birth
- gender
- PAN
- Aadhaar or masked Aadhaar (where legally permissible)
- passport details
- photograph
- signature
- nominee details
- identification documents
B. Contact Data
- phone number
- email address
- mailing address
- city / state / country
- postal code
C. Financial Data
- bank account details
- investment records
- transaction history
- source of funds
- income range
- net worth information
- portfolio holdings
- financial goals
- risk appetite and investment preferences
D. Regulatory / Compliance Data
- KYC records
- AML verification data
- FATCA declarations
- CRS declarations
- tax residency information
- residency documentation
- nominee data
- regulatory declarations
E. Technical Data
- IP address
- browser type
- operating system
- device ID
- app analytics
- cookies
- referral source
- login activity
- session information
F. Communication Data
- emails
- chats
- WhatsApp messages
- call logs / call recordings (where lawful)
- support requests
- survey responses
- webinar registrations
- event participation data
5. HOW WE COLLECT DATA
We may collect data through:
- website forms and app registration
- KYC submissions and client onboarding documents
- customer support interactions, calls and meetings
- social media interactions
- events and webinars
- cookies and analytics tools
- third-party intermediaries and regulated financial service providers
6. PURPOSE OF PROCESSING PERSONAL DATA
We process personal data only for lawful purposes.
A. Client Onboarding
- identity verification
- registration
- account setup
- onboarding completion
B. Service Delivery
- transaction facilitation
- account servicing
- product access
- customer support
- relationship management
C. Compliance & Risk Management
- KYC compliance
- AML compliance
- fraud prevention
- suitability checks
- audit requirements
- regulatory reporting
- internal risk monitoring
D. Operational Purposes
- analytics
- troubleshooting
- product improvement
- system maintenance
- internal administration
E. Communication
- account notifications
- support responses
- service alerts
- transaction communications
- operational notices
F. Marketing (subject to consent where required)
- newsletters
- campaigns
- event invitations
- educational content
- product updates
You may opt out of non-essential marketing communications at any time.
7. CONSENT AND LEGAL BASIS OF PROCESSING
We process personal data on one or more of the following bases:
- your specific, informed, and affirmative consent
- voluntary disclosure by you
- contractual necessity
- compliance with legal obligations
- legitimate uses permitted under applicable law
Consent Mechanism
Where consent is required under the DPDP Act, it must be free, specific, informed, unconditional, and given through a clear affirmative action. We collect and record consent through:
- digital consent checkboxes at onboarding (with a timestamped audit log)
- app permission prompts requiring explicit acceptance
- digital confirmation flows for specific processing activities
- email confirmations with a verifiable record
Important: Verbal consent is not accepted as a standalone mechanism. All consents are recorded digitally with a timestamp and audit trail maintained in our Consent Management System.
Consent Withdrawal
You may withdraw consent at any time by contacting us at invest@investek.in with the subject line “Consent Withdrawal Request”. Withdrawal of consent shall not affect the lawfulness of processing undertaken prior to withdrawal. Where retention is mandated by law or regulation, consent withdrawal may not require immediate deletion of data.
8. YOUR RIGHTS UNDER THE DPDP ACT
Subject to applicable law, you may exercise the following rights:
Right to Access (Section 11)
You may request a summary of personal data processed by us and the purposes for which it is processed.
Right to Correction and Updating (Section 12)
You may request correction, completion, or updating of inaccurate or incomplete personal data held by us.
Right to Erasure (Section 12)
You may request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations.
Right to Withdraw Consent (Section 12)
You may withdraw previously granted consent at any time. See Section 7 above.
Right to Grievance Redressal (Section 13)
You may raise a complaint regarding the collection, storage, sharing, or processing of your personal data with our designated contact (Section 19). If your grievance is not resolved within 30 business days, you may escalate to the Data Protection Board of India once constituted.
Right to Nominate (Section 14)
You may nominate another individual to exercise your rights in the event of your death or incapacity.
Rights Request Mechanism
Submit your request by email to invest@investek.in with the subject line “Privacy Rights Request”. We aim to respond within 30 business days, subject to legal and operational constraints.
For investment-related complaints (including disputes with AMCs, RTAs, or regarding transactions), you may also raise a complaint on the SEBI SCORES portal at https://scores.gov.in the mandatory grievance redressal platform for all SEBI-registered intermediaries.
9. SHARING OF PERSONAL DATA
We do not sell personal data.
We may share personal data strictly on a need-to-know basis with the following categories of recipients:
Financial Institutions & Regulated Intermediaries
- Asset Management Companies (AMCs) – for mutual fund transaction execution and regulatory reporting
- Registrars and Transfer Agents (RTAs) such as CAMS and KFINTECH – for transaction processing and investor servicing
- KYC Registration Agencies (KRAs) mandatory data recipients for KYC upload and retrieval under SEBI KYC Registration Agency Regulations, 2011
- insurers, custodians, banks, payment processors, PMS / AIF counterparties, and regulated intermediaries
Service Providers
- cloud vendors (operating India-resident infrastructure for payment and regulated data)
- CRM providers
- analytics vendors
- IT support providers
- communication platforms
- KYC verification vendors
Professional Advisors
- auditors
- lawyers
- consultants
- compliance advisors
Regulatory Authorities
- SEBI, AMFI, and other financial regulators
- courts and law enforcement
- statutory authorities and government agencies
- Income Tax Department (for FATCA/CRS reporting where applicable)
10. CROSS-BORDER DATA TRANSFER
Certain service providers or cloud infrastructure providers may store or process data outside India. Where cross-border transfers occur:
- We implement reasonable contractual and technical safeguards
- Transfers are limited to jurisdictions with adequate data protection standards
- We will restrict transfers to countries approved by the Central Government under the DPDP Act once the permitted country list is notified by MeitY
Payment system data and banking transaction data relating to Indian payment systems is stored exclusively within India in compliance with the Reserve Bank of India’s directive on storage of payment system data (RBI/2017-18/153) and shall not be transferred outside India.
11. DATA RETENTION
We retain personal data only as long as reasonably necessary for the purpose for which it was collected, or as required by applicable law.
Data Category | Retention Period |
Website enquiries | Up to 24 months |
Prospect / lead records | Up to 24 months |
Client onboarding records | As required by law |
Transaction records | 5–10 years or longer if required by law |
KYC / AML records | As required by law |
Marketing consent logs | Until withdrawal + applicable audit period |
Support communications | As operationally necessary |
We may retain data longer for litigation, investigations, fraud prevention, dispute resolution, or regulatory compliance requirements.
12. DATA SECURITY
We implement reasonable technical and organisational including:
- access controls and role-based permissions
- encryption of sensitive data in transit and at rest where appropriate
- secure storage with restricted database access
- vendor due diligence and contractual security obligations
- periodic security reviews and vulnerability assessments
Despite these safeguards, no electronic system is completely secure. In the event of a suspected security incident, please notify us immediately at invest@investek.in.
13. PERSONAL DATA BREACHES
In the event of a personal data breach, we will:
- Identify and contain the breach as soon as practicable
- Assess the impact and likelihood of harm to affected individuals
- Mitigate harm to affected data principals
- Notify the Data Protection Board of India within the prescribed timeline (anticipated to be approximately 72 hours from discovery) once the Board is constituted and rules are notified
- Notify affected data principals promptly where the breach is likely to result in high risk to their rights
Records of all breaches, whether notified or not, will be maintained internally for audit purposes.
14. COOKIES AND TRACKING TECHNOLOGIES
Our digital platforms use the following categories of cookies and tracking technologies:
- Strictly Necessary Cookies: Required for the platform to function. Cannot be disabled.
- Functional Cookies: Enable personalised features such as saved preferences.
- Analytics Cookies: Help us understand usage patterns and improve the platform. Used with your consent.
- Marketing Cookies: Used to measure campaign performance. Used only with your explicit consent.
You may manage your cookie preferences through our cookie consent banner or through your browser settings. Disabling certain cookies may affect platform functionality. We do not use cookies to serve targeted third-party advertising without your explicit consent.
15. CHILDREN’S PRIVACY
Our services are intended for individuals aged 18 years and above. We do not knowingly collect personal data directly from children below 18 years without verifiable consent from a parent or lawful guardian, as required by Section 9 of the DPDP Act. Where minors are nominees, beneficiaries, or dependents under financial products, such data may be provided by authorised adult users and is used strictly for lawful and regulatory purposes.
16. THIRD-PARTY LINKS
Our platforms may contain links to third-party websites or services. We are not responsible for the privacy practices, security standards, or content of such third-party services. Users should review their privacy policies independently.
17. PLATFORM-SPECIFIC ADDENDUMS
This Privacy Policy is supplemented by platform-specific addendums, each of which governs platform-specific processing activities:
- SheFin Privacy Addendum – applicable to the SheFin mobile application and website (www.shefin.org)
- NRI Wealth Privacy Addendum – applicable to the NRI Wealth platform (www.nri-wealth.com)
In the event of conflict between an addendum and this Master Policy, the addendum shall prevail with respect to platform-specific processing activities.
18. CHANGES TO THIS POLICY
We may update this Privacy Policy periodically. Material changes will be communicated via website notices, app notifications, or email communications. Where required by law, we will seek fresh consent for material changes to the purposes for which your data is processed. Continued use of services after updates constitutes acknowledgment of revised terms where permitted by law.
19. GRIEVANCE OFFICER / CONTACT DETAILS
For privacy concerns, grievances, consent withdrawal, or rights requests, please contact:
Ms. Divya Sharma
Chief Legal & Compliance Officer
Finanza InvesTek Private Limited
18th Floor, One Horizon Centre, Phase 5, Sector 43, Golf Course Road, Gurgaon – 122002, India
Email: invest@investek.in
Subject Line: Privacy Rights Request
Response timeline: 30 business days from receipt of request.
If your grievance remains unresolved after 30 business days, you may escalate to: (a) the Data Protection Board of India (once constituted under the DPDP Act); or (b) SEBI SCORES (https://scores.gov.in) for investment-related complaints.