DPDP Act Privacy NoticeVersion 1.0  |  04 September 2026
Statutory Disclosure
Vudhi FinTech

Privacy Notice — Book a Meeting

Issued under Section 5 of the Digital Personal Data Protection Act, 2023 and Rule 3 of the Digital Personal Data Protection Rules, 2025.

Vudhi FinTech (“we”, “us”, “our”), a proprietorship of Vijayan N, SEBI Registered Investment Adviser bearing Registration No. INA000022640, is the Data Fiduciary responsible for the personal data processed through this page.

This service is intended for individuals aged 18 years and above. We do not knowingly collect personal data of minors through this page.

01Personal Data Collected and Purpose of Processing

← Swipe table horizontally to view all columns →
#Personal DataPurpose of ProcessingLegal Basis
1NameIdentification and confirmation of the meetingSection 7(a), DPDP Act — voluntarily provided for a specified purpose
2Email addressMeeting confirmation, calendar invitation, and related communicationSection 7(a), DPDP Act
3Mobile numberMeeting reminders, verification, and rescheduling communicationSection 7(a), DPDP Act
4PAN (optional)Where provided, used for identity verification and KYC-related due diligence in connection with SEBI-regulated advisory services, including verification against the Income Tax/Protean PAN database and applicable KYC Registration Agency (KRA) recordsSection 7(a) as to provision; Section 7(c), DPDP Act as to verification and record-keeping, in accordance with SEBI and PMLA regulations

Optional PAN Notice: Provision of PAN is optional at the time of booking. Where PAN is voluntarily provided, its subsequent verification and retention are governed by applicable SEBI and PMLA regulations, independent of the voluntary nature of its initial provision.

We do not collect any personal data beyond what is stated in this notice without providing you a further, specific notice.

Technical Data Collected Automatically

In the course of your use of this page, the following data is generated and collected as an inherent function of the service:

← Swipe table horizontally to view all columns →
#DataPurpose
5IP addressSecurity, fraud and bot prevention, and audit-trail maintenance
6Approximate location (derived from IP address)Fraud and anomaly detection
7Device and browser details (operating system, browser type and version)Service functionality, troubleshooting, and security

02Consent

By checking the box provided and submitting the meeting form, you confirm that you have read and understood this Privacy Notice and consent to the processing of your personal data for the purposes described herein, in accordance with Section 6 of the DPDP Act.

Form checkbox (as implemented):

I have read and agree to the Privacy Notice.

Where PAN has been voluntarily provided and is subject to verification and record-keeping obligations under SEBI/PMLA regulations, such processing constitutes a legitimate use under Section 7(c) of the DPDP Act and continues independent of consent for so long as the applicable regulatory obligation subsists.

You may withdraw consent for processing based on Section 6 at any time by contacting us as set out in Section 8. Withdrawal does not affect the lawfulness of processing carried out prior to withdrawal, does not extend to processing undertaken pursuant to a legal obligation, and may affect our ability to complete or maintain a scheduled meeting or engagement.

03Retention of Personal Data

A. Where the interaction results in a client engagement:

All personal data described in Section 1, together with associated technical data, is retained for five (5) years from the conclusion of the engagement, in accordance with the SEBI (Investment Advisers) Regulations, 2013 and the Prevention of Money Laundering (Maintenance of Records) Rules, 2005. This period stands extended, without limitation, for so long as any dispute, complaint, or regulatory or judicial proceeding remains pending, and for financial or invoice records linked to PAN, up to six (6) years in accordance with the Income Tax Act, 1961.

B. Where the interaction does not result in a client engagement:

Personal data and technical data are retained for twenty-four (24) months from the date of last interaction, for security, fraud-prevention, and dispute-investigation purposes, following which such data is deleted or anonymised.

Statutory CERT-In Requirement: In all cases, a minimum rolling retention of one hundred and eighty (180) days applies to system logs, as mandated under the Directions issued by the Indian Computer Emergency Response Team dated 28 April 2022, under Section 70B(6) of the Information Technology Act, 2000.

04Disclosure of Personal Data

We do not sell personal data. Personal data may be disclosed to the following categories of recipients, strictly to the extent relevant to the product or service availed:

a. Service Providers

Providers of cloud hosting and application infrastructure, database services, and communication services (email, SMS, and/or WhatsApp) engaged to operate our systems.

b. SEBI-Regulated Ecosystem

KYC Registration Agencies (KRAs), Central KYC Records Registry (CKYCR/CERSAI), RTAs, Mutual Fund Utility/MFCentral, Stock Exchanges, Depositories, and Stock Brokers, where relevant to advisory services.

c. Financial Regulated Entities

Entities regulated by RBI, IRDAI, PFRDA, Account Aggregators, credit information companies, and payment infrastructure including NPCI and payment gateways, where relevant to services availed.

d. Regulators & Law Enforcement

Regulators including SEBI and the Data Protection Board of India, courts, and law enforcement authorities where required under applicable law or a valid legal process.

Disclosure under categories (b) and (c) occurs only in connection with the specific product or service to which such disclosure is relevant, and not as a matter of routine practice across all engagements. As our advisory services and the surrounding financial ecosystem evolve, additional recipient categories consistent with the nature of the services described in this notice may become relevant; this notice will be updated accordingly, and fresh consent obtained where required under the DPDP Act.

Location of Processing: Personal data is stored and processed on infrastructure located in India.

Transmission via Communication Channels: While our infrastructure is configured to store and process data within India, communications sent to you by email, SMS, WhatsApp, or any other electronic means may inherently involve routing through infrastructure located outside India, including infrastructure operated by the recipient service (e.g., your email provider or messaging platform), as a technical characteristic of such communication channels that is not within our control. As on the date of this notice, the Central Government has not notified any restriction on transfer of personal data to any country under Section 16 of the DPDP Act. Should such a restriction be notified, we will take necessary steps to ensure continued compliance.

05Security Safeguards

We implement reasonable technical and organisational measures, including encryption in transit, access controls, and audit logging, to protect personal data against unauthorised access, alteration, disclosure, or destruction, in accordance with Section 8(5) of the DPDP Act.

06Rights of the Data Principal

Subject to the provisions of the DPDP Act, you have the right to:

  1. 1.Access a summary of the personal data processed and processing activities undertaken.
  2. 2.Correction and Updation of inaccurate or incomplete personal data.
  3. 3.Erasure of personal data no longer necessary for purpose, subject to legal retention obligations.
  4. 4.Grievance Redressal in accordance with Section 8 below.
  5. 5.Nominate an individual to exercise rights on your behalf in the event of death or incapacity.
  6. 6.Withdraw Consent to the extent described in Section 2.

07Children’s Data

This service is not directed at, and is not intended for use by, individuals below the age of 18 years. We do not knowingly process the personal data of minors in connection with this page.

08Grievance Redressal

Grievance OfficerVijayan N, Proprietor, Vudhi FinTech
Physical AddressVudhi FinTech, G1, #4/608, V.O.C. Street, Desk No. 499, Kottivakkam, Perungudi, OMR, Chennai, Tamil Nadu – 600041
Resolution Timelines: Grievances will be acknowledged within three (3) business days and resolved within thirty (30) days, and in any event no later than ninety (90) days, in accordance with Rule 14(3) of the DPDP Rules, 2025.

09Escalation

Personal Data Grievances

For grievances concerning the processing of personal data, you may approach:

Data Protection Board of IndiaEstablished under the DPDP Act, 2023

Advisory Services Grievances

For grievances concerning the advisory services rendered, you may approach:

10Amendments

We may amend this notice from time to time to reflect changes in our processing activities, the services offered, or applicable law. Material amendments affecting your rights will be communicated to you, and fresh consent obtained where required under the DPDP Act. The version number and date at the head of this notice reflect its most recent revision.

Vudhi FinTech • SEBI RIA INA000022640