Welcome to Dezerv! We appreciate your interest in our services and products. Dezerv values your privacy and recognizes the importance of safeguarding the privacy and security of your personal information. This Privacy Policy explains our privacy commitment and practices. It identifies the personal information that we collect and store, and describes how we use, share and secure it.

1. About this Privacy Policy

Dezerv is a group of companies which includes Dezerv Investments Private Limited (“DIPL”), a private limited company incorporated under the Companies Act, 2013 (CIN: U65999MH2021PTC358833); Dezerv Distribution Services Private Limited (“DDSPL”), a private limited company incorporated under the Companies Act, 2013 (CIN: U67190MH2022PTC385467); Dezerv Securities Private Limited (“DSPL”), a private limited company incorporated under the Companies Act, 2013 (CIN: U65929MH2023PTC397580); and includes all present and future affiliates of DIPL, DDSPL and DSPL respectively (together “Dezerv”, “we”, “our” and “us”). This Privacy Policy (“Policy”) applies to all companies within the Dezerv Group from time to time.

This Policy governs the collection, use, and protection of Personal Information, including confidential information, of clients, prospective clients, and other individuals (collectively referred to as “Users,” “you,” or “your”) who access Dezerv’s Platform or Services (as defined below), or whose information is otherwise collected by us. For the purposes of this Policy, “Personal Information” means any data provided by you or otherwise made available to Dezerv that enables your identification. Information that is publicly available shall not be considered Personal Information under this Policy.

This Policy is published in compliance with the Information Technology Act, 2000 and the rules and regulations framed thereunder, including Rule 4 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011. This Policy explains our data handling practices for our products, Services, and Platform.

2. User Consent and Acknowledgement

By submitting your Personal Information through browsing or accessing our Platform or Services (each as defined in our Terms of Use), or by providing us with your Personal Information for any other reason, you explicitly and voluntarily agree to its collection, use, and disclosure as outlined in this Policy. You also consent to the transfer and storage of your Personal Information at Dezerv's offices, on its servers, and with authorized third parties, in accordance with the terms of this Policy. This Policy is incorporated into and subject to the Terms of Use of our Platform and should be read harmoniously and in conjunction with the terms therein.

While we have established and are maintaining reasonable security practices and procedures consistent with industry standards and appropriate for the information we maintain and the nature of our business, we cannot guarantee the complete security of all internet-transmitted data due to its inherent vulnerabilities.

3. What Information We Collect

Information You voluntarily submit: We collect Personal Information from you when you voluntarily provide such information, such as when you contact us with inquiries, register for access to the Platform or purchase products or Services from the Platform.

Interaction with Dezerv's Promotional Material: We collect information you provide when you interact with our Promotional Material, which includes without limitation our emails, newsletters, and advertisements (collectively “Promotional Material”). This information includes the number of clicks, time spent viewing links within the Promotional Material, and your Personal Information.

Platform Usage Data: When you visit, access, or use our Platform, we automatically collect specific information about your interaction, including but not limited to:

  • Links clicked, Pages visited, and average time spent
  • Your IP address
  • Your device's unique identifier and device information (e.g., operating system, version, browser plugins, cache, system activity, hardware settings)
  • Date and time of your request
  • Referral URL
  • Cookies that may uniquely identify your browser, browser data, mobile application, and mobile information

We use this data to analyze how you engage with our Platform and to enhance the services we provide.

Using Dezerv as a Registered User:

  1. When you register and use Dezerv's Platform, we collect certain Personal Information you provide, including the following types of data:
    • First name, last name, current contact and address details, email address, password, date of birth, and signature
    • PAN, Demat details, place of birth, city, country, and pin code
    • Annual income/net worth, and banking information
    • Information regarding your Politically Exposed Person (PEP) status, and your residential and nationality details, to fulfil our anti-money laundering (AML) and Foreign Account Tax Compliance Act (FATCA) compliance obligations
    • Data collected through the Aadhaar Digilocker KYC & eSign process, may include the last four digits of your Aadhaar, geolocation, name, gender, live image capture, year of birth, IP, and device details. This process is conducted in accordance with the Information Technology Act, 2000, and is facilitated by our third-party service provider, acting as an Aadhaar Authentication User Agency (AUA) or Sub-AUA. Collection and processing of this data occurs only with your explicit consent.
    • Your age, investing experience, and risk appetite to complete your profile and risk assessment
  2. We may require additional information and disclosures for the use of certain Services and product features.
  3. We may record and retain audio interactions, written correspondence, feedback, and other communications for service improvement and query resolution purposes.
  4. To provide the specific Services or products you select during onboarding, we will request your explicit consent to collect income and expense transactions from your bank accounts and access your investment details (including stocks and Mutual Fund investments). You retain complete control over which bank accounts and investment portfolios you choose to connect and share data from.
    • Banking & Investment Details: We access your banking transactions, other financial information, and investment details pertaining to securities (as defined under the Securities Contracts (Regulation) Act, 1956) through entities duly licensed and regulated by the Reserve Bank of India (RBI) under the Account Aggregator (AA) framework. Such data is transmitted to us securely and in encrypted form by the Account Aggregator, in accordance with applicable laws and regulations.
    • Mutual Fund Investment Data: For Mutual Fund investment data, we retrieve this information directly from the MF Central Platform. The data for Mutual Funds will be refreshed based on the consent received.
  5. Where the Services are availed through our online Platform as a family, each participating family member must expressly consent to Dezerv sharing their respective data and Personal Information with the other members of the family, solely for the purpose of delivering the Services as intended.
  6. Where applicable, we will collect details of nominees to comply with regulatory requirements.

Information we collect from Other Sources: We may receive information, including your Personal Information, from our affiliates within the Dezerv Group, or from external sources such as third-party websites, applications or service providers with whom we have contractual relationships. Please see the section below for further details on our use of third-party service providers.

  1. We may obtain information pertaining to you from another entity within the Dezerv Group when you utilize services or products offered by said entity through the Platform. Such information may be transferred to us to facilitate service delivery and fulfill our inter-group contractual obligations.
  2. We use cookies, which are small data files stored on your browser by Dezerv to collect certain information. These may include session cookies, which are deleted when the browser is closed, and persistent cookies, which remain until removed. The use of cookies enables us to offer you a more customized experience on the Platform.
  3. We may collect information about you from a variety of third-party sources, including marketing and referral partners, social media platforms where you engage with our content, and other distribution related entities. Such information is provided to us under agreements that govern its use and protection.

4. Web Analytics and Data Collection

Dezerv utilizes third-party web analytics service providers, such as Google Analytics, Mixpanel, and Microsoft Clarity, to help us better understand and improve our Services. We may also engage additional service providers or adopt new software tools to support various business functions. These analytics services may collect aggregated Personal Information, geographical data, and cookie-based information. We use this data to identify popular areas of the Services and to optimize and enhance your experience on the Platform.

For security purposes, we may use the unique identifier of your device to monitor suspicious activity. For example, if we detect that your Dezerv account is accessed from multiple devices, we may contact you to confirm that such access has been authorized by you.

By using our Services, you consent to the processing of the information you provide, including Personal Information, through these third-party web analytics providers in accordance with this Policy. Please be assured that all service partners and vendors engaged by Dezerv are required, by law and contract, to adhere to the same rigorous standards of data security and privacy that we uphold.

5. Use of Google API Data

Dezerv's use of information obtained through Google APIs is strictly governed by the Google API Services User Data Policy , including its Limited Use requirements. This means that any data accessed from your Google account, such as Gmail or Calendar data, is used solely to provide or improve the features explicitly requested by you.

Dezerv does not use this information for advertising or marketing purposes, nor does it transfer or share this data with any third party unless required to operate the service or comply with applicable laws.

6. How We Use and Share Your Personal Information

[A] We use Personal Information for various functions, such as:

Client Onboarding and Relationship Management: We may process your information in connection with onboarding and maintaining our relationship with you. This may include, without limitation -

  1. Respond to your questions about our Services.
  2. Send you communications related to your use of our Services.
  3. Offer you products or Services we believe may interest you.
  4. Personalise your experience on the Platform, showing you relevant content and tailoring displays to your preferences.
  5. Understand and use your IP address to diagnose and resolve server problems, administer the Platform, identify you, and gather broad demographic data.

Promotional/Non-Promotional Communication: We may use your contact information to communicate with you by sending emails, text messages, or other notifications about our products and Services. While you can opt out of receiving promotional communications at any time, we may still send you non-promotional messages related to your account, the Services, or your use of the Platform. Additionally, we may use your device’s IP address to deliver the content and data you request directly to your device.

To ensure Security, Compliance and Risk Management:

  1. Verify your identity, maintain Platform security and detect errors, fraud, or other prohibited activities.
  2. Contact you via phone, SMS, WhatsApp, or email for technical issues, feedback, and security reasons.
  3. Enforce our Terms of Use, and protect our contractual or other legal rights or to bring or defend legal proceedings.
  4. To comply with applicable legal and regulatory obligations under Indian law, including SEBI regulations, know your client (KYC) norms, anti-money laundering (AML) compliances, and tax laws. This includes risk profiling, monitoring and recording transactions and communications, making necessary disclosures to tax authorities, financial regulators, judicial or government bodies, and assisting in the investigation or prevention of fraud and other unlawful activities.
  5. To facilitate audits conducted by our internal/external auditors or by any third party auditors appointed in accordance with regulatory requirements.
  6. To address complaints, requests, or reports from you or others.

Business Functions: We employ cloud-based software solutions to fulfill various essential business functions. This includes, for instance, the management of databases and servers, the processing of digital communications (text messages, phone calls, chats, and emails), and conducting marketing and sales analytics.

[B] We may share your Personal Information in the following circumstances:

  1. Within the Dezerv Group to enable internal operations and improve our Services.
  2. With trusted strategic partners and third-party service providers who assist in:
    • Payment processing
    • Marketing and Advertising
    • Performance Monitoring
    • Technology and Platform development
    • Technology Service Provider (TSP) and Account Aggregators (AA)

    These third parties are contractually obligated to follow strict confidentiality and data protection standards.

  3. You specifically agree and consent to Dezerv sharing your information (including Personal Information) with various third parties, including but not limited to, banks, payment gateways, SEBI-registered entities, Stock Exchanges, CERSAI, and KRAs. This is done solely for the purpose of reviewing your profile and processing your transaction requests for Dezerv's Services or other products.
  4. Upon receipt of your explicit consent, Dezerv and third-party platforms where our Services are offered or marketed, may exchange your information to enable your access to and use of such Services directly through those platforms. This data sharing is governed by mutual contractual arrangements, under which the third parties are obligated to maintain the confidentiality of your Personal Information (to the extent shared) and to process it solely for the purposes for which it was disclosed.
  5. To protect the rights, property, or safety of Dezerv, our users, or others, this may include:
    • Sharing information with external organizations for fraud detection and prevention
    • Disclosures required for legal or regulatory obligations, including cooperation with law enforcements or regulatory bodies

[C] Anonymised and Aggregated Data Usage

We may collect, analyse, and use non-personal, anonymised, or aggregated information derived from your activity on the Platform. This includes behavioural data, demographic insights, and interaction patterns, which are automatically tracked and compiled in a manner that does not identify you personally.

Such anonymised and aggregated information may be used for purposes, including but not limited to, improving our Services, enhancing customer experience, conducting internal research and analytics, understanding usage trends, and generating market or statistical reports. We may also share this de-identified data with third-party partners and service providers for similar lawful purposes.

7. Payment Details and Processing

When you use the Platform to access our Services or products, you may be required to provide payment details such as debit card numbers, bank account information, or billing addresses. This information is entered directly into a PCI-DSS-compliant third-party payment gateway(s) engaged by us. Dezerv does not process or store any of your payment information on its own systems.

These third-party payment processors are strictly authorized to use your billing information solely for the purpose of completing transactions on our behalf. They are not permitted to store, retain, or use your payment details for any other purpose.

8. Third-Party Websites and Their Data Practices

When you access third-party websites through links provided on the Dezerv Platform, those external sites may collect your personal information, such as your IP address, browser type, or operating system. Dezerv does not control and is not responsible for the privacy practices, data handling, or content of these third-party websites.

You may also encounter cookies or similar tracking technologies on these websites. Please note that Dezerv has no control over how such tools are used by third parties.

Each of these third-party services operates under its own privacy policy, which governs how your information is collected, stored, and used. This Privacy Policy does not apply to any data you share with or that is collected by such third parties. We strongly encourage you to review their privacy policies before interacting with their websites or services.

9. Personal Information of Minors

Our Platform is not intended for individuals under the age of 18 (“Minors”). Dezerv does not knowingly collect Personal Information of Minors, except where such information is provided by a parent, legal guardian, or authorized adult in compliance with applicable laws and solely for the purpose of accessing the Services offered on the Platform.

By submitting a Minor’s Personal Information, the parent, legal guardian, or authorized adult (as applicable) expressly consents to Dezerv’s collection, storage, and use of such information in accordance with this Policy.

10. Data Retention

Dezerv keeps your Personal Information only for as long as needed for the reasons we collected it. This includes providing the Platform and our Services, or for other legitimate purposes like meeting legal obligations, enforcing our Terms of Use , preventing violations, or protecting our rights, property, and users. How long we store your information varies and depends on factors such as the type of data, why we collected and processed it, relevant legal or operational needs, and any legal requirements. We ensure the deletion of your Personal Information once its purpose is served or it is no longer necessary for Dezerv's operations.

11. Data Security and Storage Practices

Our ISO 27001 certified-platform employs stringent security measures to protect your information from loss, misuse, and alteration. As a registered user, whenever you access or change your account information, we use a secure server. Once your information is with us, we follow strict security guidelines to prevent unauthorized access. We operate in compliance with Indian privacy laws and are not governed by the privacy laws of any other jurisdiction.

Dezerv adheres to industry best practices and established principles for transferring and storing your data. All user data is securely stored on Amazon Web Services (AWS) cloud. Dezerv follows industry best practices and established principles for data transfer and storage. All user data is securely stored on Amazon Web Services (AWS) cloud. However, please note that no method of transmitting information over the internet or storing it electronically can guarantee absolute security. To know more about how we handle data transmission, please refer to the "Data Transmission" section below.

We train our employees to safeguard your information and use physical, electronic, and procedural safeguards. Access to your Personal Information is granted only to employees, agents, or affiliates on a need-to-know basis. To know more about our security practices, visit Security at dezerv.

While Dezerv implements reasonable and industry-standard security measures to protect your Personal Information on the Platform including but not limited to strong Role-based Access Control (RBAC), data tokenisation, and data encryption practices; however, certain risks may still arise due to factors beyond our control. These risks may include, but are not limited to, unauthorized access attempts such as hacking or phishing attacks, malware or ransomware infections, denial-of-service (DoS) or distributed denial-of-service (DDoS) attacks, vulnerabilities in third-party systems, network or system outages, firewall or encryption failures, and force majeure events. Additionally, human error or unintended disclosures during data transmission may also lead to security breaches. Dezerv shall not be held liable for any loss, unauthorized access, or disclosure of your information arising from such events or other circumstances beyond our reasonable control.

If you suspect your Dezerv account's security is compromised, change your login details and contact us immediately for further assistance.

12. Data Transmission

Your information, including Personal Information, is securely transmitted between your device and our servers using the HTTPS protocol for encryption (you'll see a padlock icon in your browser). Beyond this secure transmission, we ensure your Personal Information is always encrypted or hashed using industry-standard algorithms when stored. You play a vital role in keeping your Personal Information secure. We urge you to keep your account information confidential and secure. Sharing your password, OTP, or other sensitive credentials may expose your Personal Information to risk. Dezerv is not liable for any loss or unauthorised access caused by your actions or negligence.

13. Disclosure of Your Information

We do not sell or rent your Personal Information to any third party. We are committed to exercising reasonable care to prevent any unauthorized disclosure of your Personal Information. We will, however, share your information with judicial, administrative, and regulatory bodies as necessary to comply with legal and regulatory obligations under applicable laws.

Additionally, if Dezerv or its affiliates undergo business restructuring (merger, sale, reorganization, etc.), your Personal Information may be shared with the new entity, in compliance with applicable laws.

14. Your Control over Personal Information

You maintain control over your Personal Information held by us:

  1. Review Access: You may access and review your Personal Information at any time by logging into the Platform. If you believe any data provided on the Platform or through our communications is inaccurate, outdated, or if you have questions regarding its accuracy or security, please contact us at the email address provided below.
  2. Withdrawal of Consent: You have the right to withdraw your consent for the collection and use of your Personal Information under this Policy at any time.
  3. Deletion: Upon receiving your request for deletion for Personal Information, Dezerv will erase your Personal Information, unless retention is required under applicable laws and regulations. Please note that deletion of your Personal Information may impact your ability to access or use certain features of the Platform or Services.

For any of the above requests, you may write to us at member@dezerv.in

15. Disclaimer on User Information

Dezerv shall not be held responsible for verifying the accuracy or authenticity of any information submitted by you. The responsibility for any misrepresentation, inaccuracy, fraud, negligence, or any related civil or criminal liability arising from the information you provide rests solely with you.

16. Client Support and Grievance Officer

If you have any questions, concerns, or complaints regarding this Policy, or the collection and use of your Personal Information, or for requests concerning your Personal Information subject to applicable laws, please contact us using the details provided below. Any Personal Information shared with us may be recorded and retained as needed to address your request or grievance effectively.

Grievance Officer: Mr. Neil Mendonca

Dezerv Investments Private Limited

Email: member@dezerv.in

Address: Unit No. 301, Trade Centre, Bandra East, Mumbai, Maharashtra - 400051

17. Governing Law and Jurisdiction

This Policy is governed by the laws of India. Any disputes arising from it will be subject to the exclusive jurisdiction of the courts in Mumbai, Maharashtra.

18. Updates to this Policy

Our policies and security practices are continuously reviewed and updated to adapt to evolving legal, technological, and business developments. Dezerv retains the right to modify this Privacy Policy at its sole discretion, without prior notification. It is your responsibility to review the Policy periodically for any revisions. If you do not agree with any aspect of the updated Policy, you must promptly notify us and cease using our Platform.

Your continued engagement with the Platform subsequent to such changes signifies your acceptance of the updated Policy and your consent to the collection and use of your Personal Information as per its revised terms. All amendments become effective on the 'Last Updated' date specified within the Policy.