Legal-Privacy Policy
Effective Date: April 2026 | Version 1.0
1. About This Policy
Gauvik Wealth Management ("Gauvik", "we", "us", or "our") is a SEBI-registered Portfolio Management Services (PMS) provider. We are committed to protecting the privacy and confidentiality of your personal and financial information. This Privacy Policy explains how we collect, use, store, share, and protect your information in connection with our portfolio management services.
This Policy applies to all clients, prospective clients, and website visitors who interact with us, and is issued in compliance with:
-
Securities and Exchange Board of India (Portfolio Managers) Regulations, 2020
-
Digital Personal Data Protection Act, 2023 (DPDP Act)
-
SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), 2024
-
Information Technology Act, 2000 and applicable Rules
-
Prevention of Money Laundering Act, 2002 (PMLA) and associated KYC
2. Information We Collect
We collect information that is necessary to provide portfolio management services, meet regulatory obligations, and manage our relationship with you.
2.1 Information You Provide Directly
Category | Example |
|---|---|
Identity Information | Full name, PAN, Aadhaar number, passport or government-issued ID, date of birth, photograph |
Contact Information | Residential address, email address(es), phone number(s) |
Financial Information | Bank account details, income details, net worth, existing investments and liabilities, tax residency status |
Investment Profile | Risk appetite, investment objectives, investment horizon, prior investment experience |
KYC & Compliance Data | FATCA/CRS declarations, politically exposed person (PEP) status, source of funds, nominee details
Portfolio management agreement, power of attorney, client questionnaires, correspondence
|
Agreements & Documents | Portfolio management agreement, power of attorney, client questionnaires, correspondence |
2.2 Information Collected Automatically
-
Transaction data: trades executed, portfolio valuations, fees charged, income received
-
Website usage data: IP address, browser type, pages visited, time on site (where applicable)
-
Communication records: emails, letters, meeting notes, and records of instructions given
2.3 Information from Third Parties
-
Custodian and broker confirmations
-
KYC records from CKYC Registry (Central KYC Registry)
-
Credit and identity verification agencies
-
Regulatory databases (e.g. SEBI, NSDL, CDSL)
Title | Description |
|---|---|
Identity Information | Full name, PAN, Aadhaar number, passport or government-issued ID, date of birth, photograph |
Contact Information | Residential address, email address(es), phone number(s) |
Financial Information | Bank account details, income details, net worth, existing investments and liabilities, tax residency status |
Investment Profile | Risk appetite, investment objectives, investment horizon, prior investment experience |
3. How We Use Your Information
We process your personal data only for lawful purposes in connection with the provision of portfolio management services. Our primary purposes are:
Purpose | Legal Basis |
|---|---|
Sending market updates or investment insights (where consented) | Consent (you may withdraw at any time) |
Resolving disputes and managing legal claims | Legitimate interest; legal obligation |
Regulatory reporting to SEBI, income tax authorities, or other bodies | Legal obligation |
Sending portfolio reports and performance updates | Contractual necessity; SEBI reporting obligations |
Executing investment transactions | Contractual necessity; client instruction |
KYC verification and AML compliance | Legal obligation under PMLA 2002 and SEBI KYC norms |
Opening and managing your portfolio account | Contractual necessity; SEBI PMS Regulations 2020 |
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects without human oversight.
Title | Description |
|---|---|
Sending market updates or investment insights (where consented) | Consent (you may withdraw at any time) |
Resolving disputes and managing legal claims | Legitimate interest; legal obligation |
Regulatory reporting to SEBI, income tax authorities, or other bodies | Legal obligation |
Sending portfolio reports and performance updates | Contractual necessity; SEBI reporting obligations |
4. How We Share Your Information
Gauvik does not sell your personal or financial information to any third party. We share information only to the extent necessary to deliver our services or meet legal obligations.
Reason For Sharing | Do we share? | Can you limit? |
|---|---|---|
Custodians, brokers, and depositories (e.g. NSDL, CDSL) | Yes | No — required to service account |
SEBI, IRDAI, income tax authorities, or law enforcement | Yes | No — legal obligation |
Registered intermediaries (for transaction processing) | Yes | No — required to service account |
CKYC Registry and KYC Registration Agencies (KRAs) | Yes | No — regulatory requirement |
Authorised representatives or nominees (as designated by you) | Yes | Yes — notify us in writing |
Third-party marketing partners | No | Not Applicable |
Title | Description | can you limit? |
|---|---|---|
Custodians, brokers, and depositories (e.g. NSDL, CDSL) | Yes | No — required to service account |
SEBI, IRDAI, income tax authorities, or law enforcement | Yes | No — legal obligation |
Registered intermediaries (for transaction processing) | Yes | No — required to service account |
5. Data Retention
We retain your personal and financial data for as long as required to fulfil the purposes described in this Policy, and as mandated by applicable law.
-
KYC and client identification records: minimum 5 years after the end of the client relationship, as required under PMLA 2002
-
Transaction and portfolio records: minimum 5 years from the date of each transaction, as required under SEBI PMS Regulations 2020
-
Communication and correspondence: minimum 5 years
-
Tax-related records: as required under the Income Tax Act, 1961
After the applicable retention period, your data will be securely deleted or anonymised in a manner that prevents reconstruction of personal identity.
6. How We Protect Your Information
Gauvik implements security measures aligned with the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) 2024. Our safeguards include:
-
Encryption of data in transit and at rest using industry-standard protocols
-
Restricted access controls — data is accessible only to authorised personnel on a need-to-know basis
-
Secure physical office environment with access management
-
Regular security audits and vulnerability assessments
-
Incident response procedures for data breaches, including mandatory notification obligations under the DPDP Act 2023
-
Employee training on data handling responsibilities and confidentiality obligations
All third-party service providers who receive your data are contractually required to maintain equivalent standards of data protection.
7. Your Rights as a Data Principal
Under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data:
Right | What it means |
|---|---|
Right to Access | Request a summary of the personal data we hold about you and how it is being used. |
Right to Correction | Request correction of inaccurate or incomplete personal data. |
Right to Erasure | Request deletion of your personal data once the purpose for which it was collected is fulfilled and no legal retention obligation exists. |
Right to Nominate | Nominate an individual to exercise your data rights in the event of your death or incapacitation. |
Right to Grievance Redressal | File a complaint with our Data Protection Officer and, if unresolved, with the Data Protection Board of India. |
To exercise any of the above rights, please contact our team using the details in Section 10. We will respond to your request within the timelines prescribed under the DPDP Act, 2023. Please note that some rights may be limited where their exercise conflicts with our regulatory or legal obligations.
Title | Description |
|---|---|
Right to Access | Request a summary of the personal data we hold about you and how it is being used. |
Right to Correction | Request correction of inaccurate or incomplete personal data. |
Right to Erasure | Request deletion of your personal data once the purpose for which it was collected is fulfilled and no legal retention obligation exists. |
8. Transfer of Data Outside India
Where the processing of your data requires transfer to entities located outside India (for example, global custodians or foreign correspondent banks), we will ensure such transfers are conducted in accordance with the provisions of the DPDP Act, 2023, and any applicable SEBI guidelines on cross-border data transfer. We will implement appropriate contractual and technical safeguards to protect your data.
9. Website and Digital Communications
Our website and digital communications may use cookies and similar tracking technologies to improve user experience and gather aggregate analytics. We do not use tracking technologies to identify you personally without your consent. Where consent is required, you will be presented with a clear option to accept or decline. You may also adjust your browser settings to disable cookies at any time.
10. Contact Us & Grievance Redressal
If you have questions about this Policy, wish to exercise your data rights, or wish to raise a complaint, please contact our designated Data Protection Officer:
Title | Description |
|---|---|
Compliance Officer | Mr. Mallesham V. |
Email | compliance@gauvikwealth.com |
Phone | (+91)7013414160 |
Address | 8-2-269/S/88, Plot no. 88, Rd Number 2, Sagar Society, Banjara Hills, Hyderabad, Telangana 500034 |
SEBI Registration | INP000009931 |
If your grievance is not resolved to your satisfaction within 30 days, you may escalate to the Data Protection Board of India (once constituted under the DPDP Act, 2023) or to SEBI through its SCORES platform at scores.gov.in.
The Grievance redressal form and other regulatory disclosures are available on the contact page of this website.
Title | Description |
|---|---|
Compliance Officer | Mr. Mallesham V. |
Email | compliance@gauvikwealth.com |
Phone | (+91)7013414160 |
Address | 8-2-269/S/88, Plot no. 88, Rd Number 2, Sagar Society, Banjara Hills, Hyderabad, Telangana 500034 |
SEBI Registration | INP000009931 |
11. Changes to This Policy
Gauvik reserves the right to update this Privacy Policy from time to time to reflect changes in law, regulation, or our business practices. We will communicate material changes to you via email or written notice at least 30 days before they take effect. Continued use of our services after the effective date of a revised Policy constitutes your acknowledgement of the changes.
