This Privacy Policy is published by CAPLY FINTECH LLP and constitutes the notice required under Section 5 of the Digital Personal Data Protection Act, 2023. Please read it together with the Caply Terms & Conditions.
This Privacy Policy ("Policy") explains how CAPLY FINTECH LLP ("Caply", "Company", "we", "us", or "our") collects, uses, stores, processes, shares, and protects your personal data when you access or use the CAPLY mobile application ("Application"), our website, and related products and services (collectively, the "Services"). This Policy is published pursuant to Section 5 of the Digital Personal Data Protection Act, 2023 and should be read together with the Caply Terms & Conditions.
Caply operates the Application as a technology platform that enables you to access mutual fund and other financial products. Mutual fund distribution services made available through the Application are provided by MoneyTrail Securities Private Limited, a mutual fund distributor registered with AMFI under ARN-190417 (EUIN E-105308) (the "Distributor").
This Policy serves as the notice describing the personal data we collect, the specific purposes for which it is processed, and the manner in which you may exercise your rights and make a complaint.
We process your personal data on the basis of your consent or on the basis of certain legitimate uses permitted under the DPDP Act. Where we rely on consent, it is obtained through a clear affirmative action at the point of collection. Your consent is free, specific, informed, unconditional, and unambiguous, and is limited to the personal data necessary for the specified purpose.
You may withdraw your consent at any time, as easily as you gave it, through the privacy settings in the Application or by contacting our Grievance Officer (Section 20). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may limit or prevent our ability to provide some or all of the Services. Where processing is required to be continued under applicable law, we may continue to process the relevant personal data to that extent.
You may also be able to give, manage, review, or withdraw your consent through a Consent Manager registered with the Data Protection Board of India, as and when such facility is made available.
We process personal data only for specified, lawful purposes. The table below maps the main categories of personal data to the purposes for which they are processed and the basis of processing.
| Purpose | Personal data used | Basis |
|---|---|---|
| Registration, authentication & account management | Identity, Contact, Technical | Consent / Performance of Services |
| KYC verification & onboarding | Identity, KYC/Regulatory, Financial | Legal obligation |
| Processing mutual fund transactions (purchase, SIP, STP, switch, redemption) | Identity, Financial, KYC/Regulatory | Consent / Performance of Services |
| Regulatory compliance, AML monitoring, FATCA/CRS & reporting | Identity, Financial, KYC/Regulatory | Legal obligation |
| Customer support & grievance handling | Contact, Communication, Transaction | Performance of Services |
| Security, risk management & fraud prevention | Technical, Transaction, Identity | Legal obligation / Legitimate use |
| Service-related communications & regulatory notices | Contact, Transaction | Performance of Services |
| Marketing & promotional communications | Contact | Separate opt-in consent |
| Analytics, research & service improvement | Technical, Usage | Consent |
We do not use your personal data for any purpose that is incompatible with the purposes set out above without obtaining fresh consent where required.
Under the DPDP Act, we process personal data on one or more of the following bases:
Personal data is ordinarily stored and processed in India. Where personal data is transferred to, or accessed from, a location outside India (for example, by a cloud or service provider), we do so only in accordance with the DPDP Act and subject to any restrictions notified by the Central Government in respect of specified countries or territories.
We also comply with applicable sectoral data-localisation requirements, including the Reserve Bank of India's directions requiring payment-system data to be stored within India.
We retain personal data only for as long as necessary for the purposes for which it was collected, after which it is erased, unless a longer retention period is required under applicable law. Indicative retention periods are set out below.
| Type of data | Retention period | Reason |
|---|---|---|
| KYC and transaction records | Minimum 5 years after the end of the relationship or the last transaction | PMLA, 2002; SEBI / AMFI record-keeping |
| Account and profile data | For the duration of your account, and until the purpose is served | Service delivery |
| Communication & grievance records | Typically up to 5 years | Dispute resolution & regulatory record-keeping |
| Technical and security logs | Limited period as required for security and audit | Security & legal compliance |
| Marketing-consent records | Until consent is withdrawn, plus a reasonable evidentiary period | Proof of consent |
Upon withdrawal of consent or completion of the purpose, we will erase your personal data unless retention is required under applicable law, in which case the data will be retained only for the period and purpose required by such law.
We implement reasonable technical, organisational, and administrative safeguards to protect personal data against unauthorised access, disclosure, loss, misuse, alteration, or destruction. These measures may include:
While we strive to protect personal data using appropriate safeguards, no method of transmission or storage can guarantee absolute security.
In the event of a personal data breach, we will take steps to mitigate its impact and will intimate each affected Data Principal and the Data Protection Board of India in the manner and within the timelines prescribed under the DPDP Act, including providing the Board with a detailed report within the prescribed period.
Subject to applicable law, you have the following rights in respect of your personal data:
To exercise any of these rights, please use the privacy settings in the Application or contact our Grievance Officer (Section 20). We will respond within the timelines prescribed under applicable law.
You may request deletion of your account and associated personal data at any time by:
On receiving your request, we will delete your personal data unless we are required to retain certain records under applicable law (for example, KYC and transaction records under PMLA and SEBI/AMFI requirements), in which case such records will be retained only for the period and purpose required by law and then erased.
The Services are intended only for individuals who are 18 years of age or older. We do not knowingly collect or process the personal data of children, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that the personal data of a minor has been collected inadvertently, we will take appropriate steps to delete such data.
The Application may contain links to third-party websites and services. We are not responsible for the privacy practices, content, or security of such third parties. We encourage you to review their respective privacy policies before providing any personal data.
We may update this Policy from time to time. Any changes become effective upon publication on the Application or website, and where the changes are material, we will provide a prominent notice or seek fresh consent where required by law. The "Last Updated" date indicates when the Policy was last revised.
For any privacy-related query, request, or complaint, or to exercise your rights, please contact:
We will acknowledge and endeavour to resolve your grievance within the timelines prescribed under the DPDP Act. If you are not satisfied with our response, or if your grievance is not resolved within the prescribed period, you may approach the Data Protection Board of India.
Grievances relating to a mutual fund transaction may also be escalated to the concerned AMC and/or RTA, and thereafter to SEBI through the SCORES portal (scores.sebi.gov.in) or the Online Dispute Resolution (ODR) mechanism on the SMART ODR portal (smartodr.in). Grievances relating to the conduct of the Distributor may also be raised with AMFI.
CAPLY FINTECH LLP
If you have any questions regarding this Privacy Policy or our data-handling practices, please contact us using the details above.