Privacy Policy & Data Architecture - Raj Rupesh Shah

Privacy Policy

Raj Rupesh Shah | SEBI Reg. Research Analyst
Visidhae Tech Platform Infrastructure

Your privacy is important to us. This policy explains how we collect, use, and protect your personal information.

This Privacy Policy ("Policy") describes how Raj Rupesh Shah ("Raj Rupesh Shah", "we", "us", "our"), a SEBI-registered Research Analyst, collects, processes, stores, shares and protects personal data in the course of providing research services to its clients.

We are committed to complying with:

  • • Digital Personal Data Protection Act, 2023 (DPDP Act)
  • • SEBI (Research Analyst) Regulations, 2014
  • • SEBI RA Circular(s) as issued from time to time
  • • SEBI Circular(s) on KYC as issued from time to time
  • • Applicable guidelines issued by SEBI or RAASB

Your use of our research services or interaction with our website signifies your acceptance of this Policy.

Website-Specific Limitation: This website functions as our regulatory digital presence and does not collect KYC documents, onboarding applications, payment information, financial details, or subscription requests. Any submission of KYC or subscription-related information is handled outside this website through secure, designated channels authorised by us or offline means.

1. Data Fiduciary Responsibility

We act as the Data Fiduciary for all personal data collected directly by it for: KYC verification, Subscription and client management, Regulatory compliance, Communication of research, Audit and inspection requirements. We determine the purpose and means of processing such personal data.

2. Categories of Personal Data We Collect

We collect and process the following categories of personal data:

2.1 Identity Data (KYC Data)
Collected as part of mandatory KYC verification under SEBI/PMLA: Full Name, Date of Birth, Gender, PAN, [Aadhaar XML / Masked Aadhaar Data Omitted] or other officially valid document, Photograph, Signature, Address proof, KYC verification results, Verification logs, KYC Reference IDs. Identity Data is essential for onboarding and regulatory compliance.

2.2 Contact Data
Email address, Mobile number, Postal address (if required for communication)

2.3 Subscription & Transaction Data
Subscription plan/plan selected, Payment reference numbers, Billing dates, Expiry and renewal details, Communication history relating to subscription. (We do not store full payment-card or banking credentials.)

2.4 Communication Data
Emails and messages exchanged with clients, Grievance submissions, Support interactions, Regulatory correspondence required to be retained.

2.5 Website Usage Data
Collected to maintain website performance: IP address, Browser type, Device identifiers, Visit timestamps, Pages viewed, Access logs. This data is used only for security, analytics, and operational improvement.

3. Purpose of Processing Personal Data

We process personal data strictly for the following purposes:

3.1 Regulatory Compliance (Primary Purpose): To meet obligations under SEBI RA Regulations, SEBI Circulars on KYC, SEBI audit/inspection requirements, and RAASB reporting.

3.2 Client Onboarding & Verification: To verify your identity, eligibility and suitability to subscribe to research.

3.3 Subscription Management: To activate, validate, renew or suspend access to research services.

3.4 Communication: To send research reports, updates, regulatory disclosures, and mandatory communications.

3.5 Legal Obligations & Enforcement: To comply with regulatory directions, law enforcement requests or court orders.

3.6 Website Functionality & Security: To monitor website performance, detect intrusion attempts, and improve usability.

We do not use your personal data for marketing unless you explicitly opt in.

4. Lawful Basis for Processing

We process personal data under the following lawful bases:

4.1 Consent: Required for onboarding, communication, and certain optional features.

4.2 Compliance with Law: Mandatory KYC retention and record maintenance under SEBI/PMLA.

4.3 Performance of Contract: Enabling your subscription to research services.

4.4 Legitimate Use for Security & Audit: Log files, access records and analytical traces needed for fraud detection and regulatory inspection.

5. Sharing of Personal Data

We may share personal data only under the following circumstances:

5.1 With Regulators & Authorities: SEBI, KRA, RAASB, FIU-IND, Law enforcement agencies, and Courts, in accordance with due process.

5.2 With KYC Verification Partners: Only to the extent necessary for completing identity verification.

5.3 With Technology or Cloud Service Providers: Strictly under data protection regulation–compliant data processing agreements.

5.4 No Commercial Sharing: We do not sell, trade or commercially share personal data with any third party.

6. Retention of Personal Data

6.1 KYC Data: Retained for a minimum of 5 years or such other term as specified after termination of client relationship, as mandated by SEBI and PMLA.

6.2 Subscription & Communication Data: Retained for 5 years or longer if required for audit, dispute resolution, or regulatory proceedings.

6.3 Website Usage Logs: Retained for security and analytics for up to 5 years, unless required longer by law.

7. Storage and Security Measures

We implement robust security controls, including:

  • • Encryption of KYC data
  • • TLS for data transmission
  • • Zero-access policy for unauthorized personnel
  • • Role-based access controls
  • • Multi-factor authentication for compliance staff
  • • Security audits and vulnerability assessments
  • • Immutable and timestamped audit logs

8. Rights of Clients

You have the right to:

8.1 Access Your Data: Receive a copy of your personal data maintained by us.

8.2 Correct Inaccurate Data: Request correction or updating of incorrect data.

8.3 Withdraw Consent: You may withdraw consent for non-essential data processing. (Withdrawal cannot apply to SEBI/PMLA-mandated KYC retention.)

8.4 Request Information About Processing: Know what data is being processed and why.

8.5 Nominate Another Person: Appoint someone to exercise your rights on your behalf in case of incapacity.

9. Cross-Border Data Transfer

We do not transfer KYC or identity documents outside India. Other personal data may be stored on servers located outside India only under encryption, strict contractual safeguards, and DPDP Act compliance.

10. Cookies & Website Tracking

Our website may use: Session cookies; Analytics cookies; Security cookies. No advertising cookies are used unless explicitly approved by the user.

11. Changes to This Policy

We may update this Policy periodically to reflect regulatory amendments or internal governance changes. Updated versions will be published on this page with the revised effective date.

12. Governing Law & Jurisdiction

This Disclaimer & Risk Disclosure is governed by the laws of India.

13. Contact Information

For questions regarding this Disclaimer or to exercise client data actions, requests may be sent to:

Compliance Officer

CA Raj Rupesh Shah
Support@carajshah.in