Privacy Policy
Our commitment
We are a fee-only, fiduciary investment adviser. Our clients hand us the most sensitive picture of their lives that exists outside a doctor’s file: what they own, what they owe, whom they intend to leave it to, and what they are afraid of. We hold that in trust, and this policy explains how.
In short: we do not sell your data and earn no commission on the advice we give, so we have no incentive to monetise you. We collect only what the advice requires, share it only where necessary or where the law compels us, keep it only as long as regulation demands, and secure it with care. You can ask what we hold, have it corrected, and — where the law allows — have it erased. A named person is accountable for this, and their details are at the end.
1. Who we are and what this covers
This policy is issued by Shreem Datatech Solutions Private Limited (“we”, “us”, “the firm”), operating the myMoneySage brand, a SEBI Registered Investment Adviser (INA200014247, BASL1263), CIN U74900KA2015PTC079474. It covers our website www.mymoneysage.in, the client portal clients.mymoneysage.in, our myMoneySage mobile apps (iOS and Android), and our advisory, onboarding, and client-servicing communications.
It does not cover third-party websites we link to, or the independent privacy practices of exchanges, custodians, AMCs, registrars, or platforms with whom you hold assets directly.
2. The law we operate under
We process personal data as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) and rules made under it, and as a SEBI Registered Investment Adviser under the SEBI (Investment Advisers) Regulations, 2013, including their confidentiality and record-keeping obligations. Other applicable laws include the Prevention of Money-Laundering Act, 2002, the Income-tax Act, 1961, and the Information Technology Act, 2000.
3. What we collect
If you only visit
Basic technical data your browser sends — IP address, device and browser type, and pages viewed — used only for security and to keep the site working. We do not build visitor profiles or track you across the web.
If you enquire
When you submit our enquiry form (which feeds our Zoho environment in India), we collect your name, contact details, city or country of residence, and whatever you tell us in your message. If you do not become a client, we delete this after 24 months.
If you become a client
Advice requires a full financial picture, so we collect materially sensitive data:
- KYC and identity: name, date of birth, PAN, Aadhaar (as permitted by law), address and proof, photograph, signature, nationality and tax-residency (FATCA/CRS), PEP and source-of-wealth declarations, bank and demat details.
- Financial and advisory: income, assets, liabilities, insurance, portfolio holdings, ESOP/RSU details, tax data you provide, and business, trust, or HUF interests.
- Risk and suitability: your risk-profile responses, objectives, horizons, and constraints (required under the IA Regulations).
- Family and succession: details of spouse, dependants, nominees, and beneficiaries where relevant to your planning.
- Records of advice: the advice given, its rationale, correspondence, invoices, and — where a meeting is recorded or AI-assisted notes are taken — the resulting record. See section 6.
When you give us data about family members or nominees, you confirm you may share it and have told them we hold it. We do not use Account Aggregators, and we do not buy personal data from lead-generation vendors.
4. Why we process it
Advice at myMoneySage is delivered by our advisers. We use technology and analytical tools to help our advisers aggregate and assess your data, but the advice is human-led. We do not use your personal data to train AI models, and we engage our technology vendors under terms that prohibit them from using your data to train theirs.
| Purpose | Basis |
|---|---|
| Responding to your enquiry | Your consent |
| Onboarding, KYC, and AML checks | Legal obligation |
| Risk profiling, advice, reviews, rebalancing | The advisory agreement / legal obligation |
| Fee invoicing and collection | The advisory agreement / legal obligation |
| Keeping records of advice and consents | Legal obligation (IA Regulations) |
| Responding to SEBI, BASL, tax, or other authority | Legal obligation |
| Newsletters and market commentary | Your consent (withdrawable) |
| Website security and fraud prevention | Permitted legitimate uses |
Confirm the client advisory agreement discloses the firm’s use of AI/technology tools, consistent with the 2024 IA
amendment.
5. Who we share it with
We share personal data only where necessary, and never with product manufacturers, distributors, or intermediaries so they can market to you. We receive no consideration for sharing your data. Recipients fall into four groups:
- Regulators and authorities — SEBI, BASL, FIU-IND, tax authorities, and courts or law enforcement acting under lawful process.
- Regulatory infrastructure — KYC Registration Agencies and the Central KYC Records Registry.
- Service providers on our instructions — principally Zoho (CRM, mail, e-sign, meetings, storage) and AWS, both India-resident, and Zoom for video. Each is engaged under a written data-processing agreement restricting them to processing on our instructions.
- Parties you direct us to — your custodian, chartered accountant, lawyer, or family office, on your written instruction.
In a merger or transfer of business, data may pass to the successor under the same protections and any required regulatory approval.
Confidentiality. Independently of data-protection law, the IA Regulations require us not to divulge confidential client information without your permission except where the law compels it. Every person at the firm is bound by written confidentiality obligations that survive their engagement.
Our associate distribution entity. An associate under separate branding carries on distribution business. There is no overlap between our advisory clients (and their families) and that entity’s clients, and we do not share advisory-client data with it.
Confirm operationally that no advisory-client data flows to the distribution entity through any shared system (including
Zoho).
6. Where your data sits, and recordings
Your data is held primarily in India, on Zoho and AWS (India region). The one exception is Zoom, which we use for some client video meetings and which may process data outside India under its own architecture.
Meetings may be recorded (optionally) and we use Zoom’s AI Companion to generate meeting notes. Where notes or recording are active, we tell you at the start, and recording happens only with your awareness. Zoom’s terms state it does not use this content to train AI models. If you are a non-resident client, your data may also be subject to FATCA, CRS, or the law of your country of residence.
7. How long we keep it
| Data | Retention Period |
|---|---|
| Records of advice, risk profiling, client agreements | Minimum period required under the IA Regulations |
| KYC and AML records | As required under the PMLA and rules made thereunder |
| Financial and tax records | As required under the Income-tax Act, 1961 |
| Anything under a pending audit, inquiry, or proceeding | Until that proceeding concludes |
| Enquiry data (non-clients) | 24 months, then deleted |
| Newsletter subscribers | Until you unsubscribe |
A candid note on erasure. As a regulated intermediary we cannot delete advisory and KYC records during the statutory retention period. If you ask us to erase your data, we erase what we lawfully can, tell you specifically what we must keep and why, and tell you when it will go.
8. Security
We maintain safeguards proportionate to the sensitivity of the data: encryption in transit (TLS), storage on infrastructure that encrypts data at rest, multi-factor authentication on business-critical systems, role-based access on a need-to-know basis, access logging, regular backups, and written confidentiality obligations on staff and processors. No system is perfectly secure; what we commit to is proportionate controls, honest disclosure when something fails, and prompt remediation.
Your part. Please don’t send PAN, Aadhaar, bank details, or credentials over unsecured channels. We will never ask you for a password or an OTP.
9. Cookies and marketing
Our site uses only strictly necessary cookies required for security and basic function. We set no analytics, advertising, or tracking cookies, so no cookie-consent banner is needed. If you subscribe to our market commentary, we send it on the basis of your consent and every email carries an unsubscribe link; unsubscribing does not stop service communications such as portfolio reviews, invoices, and regulatory notices. Engaging with our public social posts does not by itself create an advisory relationship.
10. Your rights
Subject to the retention limits in section 7, you may: access a summary of the data we hold and whom we’ve shared it with; have inaccurate data corrected; have data erased where no legal obligation requires us to keep it; withdraw consent at any time (which may mean we can no longer provide the service); nominate someone to exercise these rights on your behalf in the event of your death or incapacity; and raise a grievance. To exercise a right, write to the contact in section 12. We may need to verify your identity, particularly for financial data, and we respond within the timelines the law prescribes, and otherwise within 30 days.
11. Breaches, and children
If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals as required, in plain language — what happened, what was involved, what we’ve done, and what you should do.
Our services are for adults. Where a child’s data is processed as part of family planning — education goals, nomination, succession — it is processed on the basis of the client’s verifiable parental consent, limited to what the planning requires, and never used for tracking, profiling, or targeted advertising.
12. Contact and grievances
Data-protection queries. Kishor Kumar B G, kk@mymoneysage.in — the person accountable for how we handle your personal data.
Advisory grievances follow our published escalation:
| Step | Details |
|---|---|
| Step 1 | support@mymoneysage.in — Resolved within 21 calendar days |
| Step 2 | Compliance Officer — Praveen Parthasarathy, pp@mymoneysage.in, 7358700819 |
| Step 3 | SEBI SCORES 2.0 — https://scores.sebi.gov.in |
| Step 4 | Online Dispute Resolution — https://smartodr.in |
| Data Protection Board | If a data-protection grievance is unresolved, you may complain to the Board under the DPDP Act. |
Registered office: No. 800, 7th Cross, 1st A Main Road, BSK 3rd Stage, 3rd Phase, 3rd Block, Bengaluru, Karnataka 560085.
Correspondence: #7, Sree Devi Complex, Spacio Workspace, Cabin 3, 3rd Floor, NAT Street, Basavanagudi, Bengaluru 560004.
Standard Data Fiduciary basis assumed (not a Significant Data Fiduciary). Reassess if the firm scales materially.
13. Changes
We may update this policy. Material changes will be emailed to clients and posted here with a new effective date. This is version 1.0, effective 1 August 2026.