MAHIR INVESTMENT ADVISERS PRIVATE LIMITED
SEBI Registered Investment Adviser | Registration No. INA000022668
PRIVACY POLICY
Data Fiduciary: Mahir Investment Advisers Private Limited
CIN: U66190PN2025PTC244016
SEBI Reg. No.: INA000022668
Registered Office: PL G/A-9/1 Shop 1, MIDC G Nr Moris So, Chinchwad East, Pune 411019, Maharashtra
1. ABOUT THIS PRIVACY POLICY
Mahir Investment Advisers Private Limited ('MIA', 'we', 'us', 'our') is committed to protecting the privacy and personal data of its clients, prospective clients, and users of the MIA App and Website ('Platform').
Legal Compliance Framework:
- Digital Personal Data Protection Act, 2023 ('DPDP Act')
- Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ('IT SPDI Rules')
- Information Technology Act, 2000;
- SEBI (Investment Advisers) Regulations, 2013 and applicable SEBI Circulars;
- Prevention of Money Laundering Act, 2002 and AML/KYC guidelines;
- All other applicable laws and regulations of India.
This Policy describes how MIA collects, uses, processes, stores, shares, and protects your personal data, and sets out the rights available to you as a Data Principal under applicable law. This Policy forms part of the overall agreement between you and MIA and should be read alongside the Terms and Conditions and Client Agreement.
2. PERSONAL DATA WE COLLECT
2.1 Categories of Personal Data
We collect the following categories of personal data from you directly and through your use of the Platform:
- Identity Data: Full legal name, PAN card number, Aadhaar number (masked/tokenized as permitted), date of birth, photograph, and specimen signature.
- Contact Data: Residential and correspondence address, email address, mobile number, and emergency contact details.
- Financial Data: Gross annual income, net worth, bank account details (for fee payments), investment portfolio information, existing liabilities, tax status, and FATCA/CRS declarations.
- KYC & AML Data: Documentary evidence for KYC compliance, source of funds and wealth, politically exposed person (PEP) status, and sanctions screening data.
- Risk Profile Data: Risk tolerance questionnaire responses, investment objectives, investment horizon, prior investment experience, and financial goals.
- Platform Usage Data: IP address, device identifiers, browser type and version, operating system, pages visited, session duration, click-stream data, and referral URLs.
- Communication Data: Queries, complaints, call recordings (with consent), correspondence, and meeting notes.
- Technical Data: App crash reports, error logs, and performance diagnostic metrics.
2.2 Sensitive Personal Data or Information (SPDI)
The following categories constitute SPDI under the IT SPDI Rules, 2011 and are collected only with your explicit prior consent:
- Financial information: Bank account numbers, credit card/debit card details (solely for fee payment), income details, and net worth information.
- Biometric data: Where applicable and legally permitted (e.g., for eKYC purposes).
- Aadhaar details: As permitted under the Aadhaar (Targeted Delivery) Act, 2016 and applicable guidelines.
2.3 Data We Do Not Collect
MIA does not collect racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health data (unless specifically relevant for insurance advisory, which MIA does not presently offer), genetic data, or sexual orientation data.
3. PURPOSES AND LEGAL BASIS FOR PROCESSING
This section details how your data is used and the legal justification for each use.
| Purpose of Processing | Data Categories Used | Legal Basis |
|---|---|---|
| Client onboarding & KYC completion | Identity, Contact, KYC, Financial | Legal obligation (SEBI IA Reg., PMLA) |
| Providing personalized investment advice | Risk profile, Financial, Usage data | Contract performance |
| AML/CFT compliance & suspicious transaction reporting | KYC, Identity, Transaction data | Legal obligation (PMLA, SEBI) |
| Fee collection and billing | Contact, Financial, Bank data | Contract performance |
| Platform improvement & analytics | Usage, Technical data | Legitimate interest / Consent |
| Regulatory reporting to SEBI, AMFI, FIU-IND | Identity, KYC, Financial | Legal obligation |
| Marketing communications (opt-in only) | Contact, Usage data | Consent |
| Customer support & grievance redressal | Communication data | Contract performance / Consent |
| Internal audit & compliance | All relevant categories | Legal obligation / Legitimate interest |
4. DATA SHARING AND DISCLOSURE
MIA does not sell, rent, or trade your personal data to any third party for commercial purposes. We may share your data strictly on a need-to-know basis with the following:
- Regulatory Authorities: SEBI, AMFI, Stock Exchanges, Depositories (NSDL/CDSL), Registrar and Transfer Agents, and other financial market regulators as required by law.
- Financial Intelligence Unit — India (FIU-IND): for AML/CFT reporting obligations under PMLA.
- KYC Registration Agencies (KRAs) and Central KYC Registry (CKYCRR): for KYC verification and record maintenance.
- Technology Service Providers: Cloud hosting partners, IT vendors, and software service providers who process data strictly on MIA's behalf and are bound by written data processing agreements with equivalent security standards.
- Professional Advisers: Statutory auditors, legal counsel, and tax advisers, subject to appropriate confidentiality obligations.
- Legal Mandates: Courts, Tribunals, or Law Enforcement Authorities pursuant to a valid court order, summons, or statutory requirement.
All third-party data processors are contractually bound to maintain security standards not lower than those maintained by MIA. Cross-border data transfers, if any, shall comply with provisions of the DPDP Act, 2023, including adequate safeguards.
5. DATA RETENTION PERIODS
Data retention is governed by the longest period required by law or regulation.
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| KYC and Client Agreement records | Minimum 5 years post relationship cessation | SEBI IA Regulation 19, PMLA Rule 10 |
| Financial transaction records | Minimum 10 years | PMLA, 2002 — Section 12 |
| Correspondence and complaints records | Minimum 5 years | SEBI IA Regulations |
| Platform usage logs | 12 months (rolling) | IT Act, 2000 / Legitimate interest |
| Marketing data and consent records | Until withdrawal of consent | DPDP Act, 2023 |
| Call recordings (where applicable) | 90 days unless subject to a dispute | SEBI / Legitimate interest |
Upon expiry of the applicable retention period, personal data shall be securely deleted or irreversibly anonymized in accordance with applicable law. Records subject to ongoing legal/regulatory proceedings shall be retained until resolution.
6. DATA SECURITY MEASURES
MIA implements comprehensive technical and organizational security measures in accordance with IT SPDI Rules, 2011 and DPDP Act, 2023 to protect your personal data:
- Encryption: All data in transit is encrypted using TLS 1.2 or higher. Data at rest is encrypted using AES-256 encryption.
- Access Controls: Role-based access controls (RBAC) ensuring data access is strictly limited to authorized personnel on a need-to-know basis.
- Authentication: Multi-factor authentication (MFA) mandatory for all personnel accessing client data and for Platform login.
- Security Audits: Regular security audits, vulnerability assessments, and penetration testing by qualified third-party security professionals.
- Incident Response: Documented incident response procedures for data breach detection, containment, and notification.
- Data Breach Notification: In the event of a personal data breach, MIA will notify the Data Protection Board of India and affected clients within the timelines prescribed under the DPDP Act, 2023.
7. COOKIE POLICY
The MIA Platform uses cookies and similar tracking technologies (web beacons, pixels, local storage) to provide a seamless user experience. Categories:
- Strictly Necessary Cookies: Essential for core Platform functionality including login sessions, security tokens, and fraud prevention. These cannot be disabled without impacting Platform functionality.
- Analytics Cookies: Used to understand Platform usage patterns, page performance, and user behaviour collected only with your explicit consent.
- Preference Cookies: Used to remember your Platform settings and preferences collected with consent.
- Marketing Cookies: Used to deliver relevant financial content and updates collected only with opt-in consent.
You may manage cookie preferences at any time through your browser settings or the Platform's cookie consent manager. Disabling non-essential cookies will not affect your ability to receive core advisory services.
8. YOUR RIGHTS AS DATA PRINCIPAL
Under the DPDP Act, 2023 and applicable law, you have the following rights with respect to your personal data:
| Right | Description | How to Exercise |
|---|---|---|
| Right to Access | Obtain summary of personal data processed and processing activities undertaken | Written request to DPO |
| Right to Correction | Request correction, completion, or updating of inaccurate/incomplete personal data | Written request to DPO |
| Right to Erasure | Request deletion of personal data, subject to legal retention obligations and regulatory requirements | Written request to DPO |
| Right to Grievance Redressal | Raise grievances about personal data processing with the Data Protection Officer | Email to compliance@mahiradvisers.com |
| Right to Nominate | Nominate an individual to exercise data rights on your behalf in case of death or incapacity | Written request to DPO |
| Right to Withdraw Consent | Withdraw consent for processing not based on legal obligation, without affecting prior lawful processing | Written request or Platform settings |
9. CHILDREN'S PRIVACY
The MIA Platform and Services are intended exclusively for persons 18 years of age and above. MIA does not knowingly collect, process, or store personal data from minors under 18 years of age. If MIA becomes aware that personal data of a minor has been inadvertently collected, it shall promptly delete such data in accordance with the DPDP Act, 2023 and notify the parent or guardian.
10. UPDATES TO THIS PRIVACY POLICY
MIA may update this Privacy Policy periodically to reflect changes in legal or regulatory requirements, business practices, data processing activities, or technological changes. Material updates will be communicated via the Platform's notification system and/or by email to registered clients at least 15 days prior to the update taking effect. The date of the latest revision is prominently displayed at the top of this Policy. Continued use of the Platform after notification of changes constitutes acceptance of the updated Policy.
11. CONTACT, DPO, AND GRIEVANCE OFFICER
For privacy-related queries, concerns, or to exercise your data rights, please contact:
Grievance Details
Registered Address: PL G/A-9/1 Shop 1, MIDC G Nr Moris So, Chinchwad East, Pune 411019, Maharashtra
Resolution Timeline: Within 30 days from date of receipt of complaint
YASH MAHAVIR BEDMUTTHA
Principal Officer | admin@mahiradvisers.com
Date: June 01, 2026