Loading your workspace. Please wait...
Loading your workspace. Please wait...
Governed by: DPDPA 2023 · IT Act 2000 · IT (Intermediary Guidelines) Rules 2025
Finucity Technologies Private Limited is the company responsible for your data. Under India's DPDPA 2023, we are classified as a 'Data Fiduciary' — meaning we decide how your personal data is processed and we're legally accountable for it.
Finucity Technologies Private Limited ("Company", "Finucity", "we", "us", "our"), incorporated under the Companies Act, 2013, with its registered office in Pune, Maharashtra, India, operates the Finucity platform ("Platform").
Under the Digital Personal Data Protection Act, 2023 ("DPDPA 2023"), the Company is classified as a Data Fiduciary as defined under Section 2(5) of the Act. As Data Fiduciary, we determine the purpose and means of processing your personal data and bear primary responsibility for compliance with all data protection obligations under the DPDPA 2023.
We also operate in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (as amended 2025).
We collect information needed to verify CAs, match you with the right professional, process payments, and provide AI-powered document parsing. Here's the full list of what we collect.
Identity & Verification Data:
Financial & Business Documents:
Technical & Device Data:
Every piece of data we collect has a specific, lawful purpose — from verifying that CAs are real to processing escrow payments. We never collect data 'just because'.
Under DPDPA 2023, all data processing must be purpose-bound. We process your data for the following specific purposes:
Your data is encrypted using military-grade AES-256 encryption at rest and TLS 1.3 in transit. Everything is stored on Indian servers (Mumbai region). We use Supabase with Row Level Security — so even at the database level, users can only access their own data.
Encryption Standards:
Server Localization: All data is stored exclusively on servers located in India, specifically in the ap-south-1 (Mumbai) region through our infrastructure provider. No personal data is stored on or transferred to servers outside India.
Database Security: We utilize Supabase with Row Level Security (RLS) policies ensuring that: (a) Users can only access their own data; (b) Practitioners can only access data shared with them by their clients; (c) Administrative access requires multi-factor authentication and is logged in an immutable audit trail.
Infrastructure: Our infrastructure includes regular security audits, automated vulnerability scanning, DDoS protection, and Web Application Firewall (WAF) rules.
We keep your data for a minimum of 1 year and maximum of 3 years after you leave the platform. Some data may be kept longer if required by tax or anti-money-laundering laws. If you request deletion, we process it within 30 days.
Standard Retention: Personal data is retained for a minimum of one (1) year and a maximum of three (3) years after the termination of the business relationship, unless a longer retention period is required by applicable law.
Legal Exceptions:
Erasure SLA: Upon receiving a valid erasure request from a Data Principal, the Company commits to completing data deletion within thirty (30) days, subject to legal retention requirements and ongoing dispute resolution obligations.
Document Retention Notice: Uploaded financial documents are retained according to service context, legal obligations, and dispute requirements. Users may request erasure at any time, and valid requests are processed within thirty (30) days subject to statutory retention duties.
We share some data with trusted third-party providers who help us run the platform. Each one is bound by a Data Processing Agreement (DPA). Here's who they are and what they access.
The Company engages the following third-party Data Processors, each bound by a Data Processing Agreement (DPA) that complies with DPDPA 2023 requirements:
Razorpay / RazorpayX
Purpose: Payment processing, escrow management, payout disbursement
Data Shared: Name, email, PAN (for KYC), payment amounts, bank account details
Surepass Technologies
Purpose: PAN verification, ICAI membership verification, GSTIN validation
Data Shared: PAN number, ICAI MRN, GSTIN
Groq (Llama models) / Fal.ai
Purpose: AI document parsing, AI chat assistant, AI content generation
Data Shared: Document content (processed in-memory, not stored by AI provider)
No third-party processor is authorized to use your data for purposes beyond those specified in their DPA. The Company conducts annual compliance audits of all Data Processors.
Under DPDPA 2023, you have the right to access, correct, or delete your data. You can withdraw consent anytime. You can also nominate someone to manage your data if something happens to you.
Under the DPDPA 2023, you (as a "Data Principal") have the following rights:
To exercise any of these rights, contact our Data Protection Officer at hello@finucity.com. We will acknowledge your request within 48 hours and fulfill it within 30 days.
We do NOT transfer your personal data outside India. Period. All data stays on Indian servers. If we ever need to transfer data internationally (e.g., for a global AI provider), we'll get your explicit consent first.
The Company does not transfer personal data of Indian Data Principals outside the territory of India, except: (a) where the Data Principal has provided explicit, informed consent for such transfer; (b) where the transfer is to a country or territory notified by the Central Government under Section 16(1) of the DPDPA 2023 as permitting such transfers; (c) where the transfer is necessary for the performance of a contract to which the Data Principal is a party.
For AI processing: all document parsing is performed using APIs that process data in-memory without persistent storage. The AI model provider does not retain, store, or train on user-uploaded documents.
If a confirmed personal data breach is likely to cause significant harm, we notify affected users and relevant authorities within 72 hours of confirmation, along with mitigation guidance.
In case of a confirmed personal data breach that is likely to result in significant harm to Data Principals, the Company will issue breach notifications without undue delay and, where reasonably feasible, within seventy-two (72) hours of confirmation.
Notifications may include: (a) nature of the breach; (b) likely impact categories; (c) mitigation steps already taken; (d) actions Data Principals should take; and (e) grievance escalation details.
The Company will preserve forensic logs, coordinate containment actions, and maintain an incident record for regulatory reporting and audit purposes.
We've appointed a DPO who handles all privacy-related requests. You can reach them via email at hello@finucity.com. They'll get back to you within 48 hours.
Designation: Data Protection Officer
Organization: Finucity Technologies Private Limited
Email: hello@finucity.com
Acknowledgement: Within 48 hours
Resolution: Within 30 days as per DPDPA 2023
Escalation: Data Protection Board of India
We track every change we make to this policy. Below is the complete history so you can see exactly what changed and when.
| Version | Date | Changes |
|---|---|---|
| 1.1 | April 11, 2026 | Added breach notification section, clarified retention language, and aligned cookie consent disclosures with implementation. |
If you have a complaint about how your data is handled, contact our Grievance Officer. We'll respond within 72 hours and resolve within 30 days. If you're not satisfied, you can escalate to the Data Protection Board of India.
Grievance Officer: Sumeet Sangwan (Founder & CEO)
Email: hello@finucity.com
Response Time: Within 72 hours of receipt
Resolution SLA: Within 30 days as mandated by DPDPA 2023
Escalation Path: If unresolved, complaints may be escalated to the Data Protection Board of India as constituted under Chapter V of the DPDPA 2023.
© 2026 Finucity Technologies Private Limited. CIN: [Pending Registration]. All rights reserved.