Legal & Transparency

Privacy Policy

This Privacy Policy explains how Estabizz Fintech Private Limited collects, uses, stores, shares and protects personal information while providing its professional services.

Effective Date

April - 2026

Last Updated

April - 2026

Company

Estabizz Fintech Private Limited

Governing Law

India

This page contains the privacy policy text supplied by Estabizz Fintech Private Limited. It should be read together with applicable Indian data protection, information technology and professional-service requirements.

1

Introduction

Estabizz Fintech Private Limited respects the privacy of its clients, website visitors, business associates, employees, candidates and other persons who interact with us.

This Privacy Policy explains how we collect, use, store, share and protect personal information while providing our professional services.

It also explains the choices and rights available to an individual in relation to their personal information.

This Policy applies to information collected through our website, client portal, service tickets, email, telephone, SMS, WhatsApp, video meetings, physical documents, office visits and other authorised communication channels.

2

About Estabizz Fintech

Estabizz Fintech Private Limited provides regulatory, financial, legal, compliance, licensing, recruitment, audit and business advisory services.

Our assignments may involve interaction with regulators, government departments, financial institutions, professional firms, technology service providers and other authorised parties.

For the personal information processed for our own business and service purposes, Estabizz Fintech acts as the person responsible for deciding why and how such information is processed.

In certain assignments, we may process information only on the instructions of a client or another authorised organisation. In such cases, the respective client or organisation may remain primarily responsible for that information.

3

Scope of This Policy

This Policy applies to information collected from:

Clients and prospective clients.

Promoters, directors, shareholders and key managerial personnel.

Employees, consultants and associate professionals.

Job applicants and candidates.

Vendors, service providers and business partners.

Website visitors and persons submitting enquiries.

Persons whose information forms part of a regulatory, compliance, legal or financial assignment.

The Policy applies to personal information received directly from an individual as well as information received through an authorised representative, employer, client, regulator or publicly available source.

4

Meaning of Personal Information

Personal information means any information that relates to an identified or identifiable individual.

It may include basic contact details, identification documents, financial records, professional information, communication records and online activity.

Information relating only to a company, partnership, trust or other legal entity may not by itself be personal information.

However, information identifying the directors, partners, trustees, shareholders, employees or authorised representatives of such an entity may be treated as personal information.

5

Information We May Collect

The nature of information collected depends upon the service requested and the regulatory or professional requirements applicable to the assignment.

We seek to collect only such information as is reasonably required for a specified and lawful purpose.

Identity Information

We may collect your name, photograph, date of birth, gender, nationality, signature and identification number.

We may also collect copies of PAN, Aadhaar, passport, driving licence, voter identity card, OCI card, residence permit or other identification documents.

Where Aadhaar or another government identity document is provided, it should be shared only where necessary and through an authorised channel.

Contact Information

We may collect your residential address, registered office address, email address, telephone number and WhatsApp number.

We may also collect details of your authorised representative, professional adviser or emergency contact where relevant.

Corporate and Professional Information

We may collect information relating to your designation, employment, qualifications, experience, professional memberships and business interests.

For regulatory assignments, we may collect details of directorships, partnerships, shareholding, beneficial ownership, group entities and related-party relationships.

Financial Information

We may collect bank account details, financial statements, income information, tax returns, net-worth details, assets and liabilities, investment information and source-of-funds documents.

We may also collect payment details, invoice records and transaction references.

Estabizz Fintech ordinarily does not directly store complete debit-card, credit-card, CVV or internet-banking credentials. Such payments may be processed through authorised banks or payment service providers.

Regulatory and Compliance Information

We may collect information required for an application, registration, licence, audit, filing, inspection or regulatory response.

This may include declarations, affidavits, undertakings, due-diligence records, litigation details, regulatory correspondence and fit-and-proper information.

We may also collect information relating to criminal proceedings, defaults, insolvency, disciplinary action or regulatory investigation where disclosure is legally required for the concerned assignment.

Communication Information

We may retain emails, messages, letters, meeting notes, ticket updates and other correspondence exchanged during an assignment.

Calls or online meetings may be recorded where appropriate notice has been provided or where recording is otherwise permitted.

Such records may be used for quality review, training, dispute resolution and verification of instructions.

Website and Technical Information

When you visit our website, certain technical information may be collected automatically.

This may include your Internet Protocol address, browser type, device type, operating system, approximate location, pages visited and the date and time of access.

We may also collect information relating to website performance, referral sources and interactions with forms or website features.

Office Visit Information

Where you visit our office, we may collect your name, contact details, appointment details and purpose of visit.

Premises may be covered by CCTV or access-control systems for security and administrative purposes.

Recruitment Information

Where you apply for employment or are considered for a position, we may collect your résumé, education, experience, present employment and compensation details.

We may also collect references, interview notes, identification documents and background-verification information.

Where recruitment services are provided for a client, relevant candidate information may be shared with that client after appropriate communication or authorisation.

Information from Other Sources

We may receive information from regulators, government records, public databases, professional networks, employers, clients and authorised representatives.

We may also refer to information published on corporate websites, professional profiles, stock-exchange records, regulatory portals and other lawful public sources.

6

How We Collect Information

We may collect information when you:

Submit an enquiry through our website.

Contact us by telephone, email, WhatsApp or social media.

Create or respond through a client service ticket.

Attend a meeting, consultation or webinar.

Make a payment or accept a professional proposal.

Provide documents for an assignment.

Apply for employment or participate in recruitment.

Visit our office.

Authorise another person to provide information on your behalf.

Information may also be collected from a client where your details form part of a professional or regulatory assignment.

7

Purposes for Which Information Is Used

We may use personal information to understand your requirements and assess the proposed assignment.

We may use it to verify identity, eligibility, ownership, experience, qualifications and financial capacity.

Information may be used to prepare applications, reports, policies, agreements, declarations, replies and other professional documents.

We may use information to communicate with regulators, government departments, banks, financial institutions and professional advisers.

We may use contact details to provide ticket updates, reminders, payment information and assignment-related communication.

Information may also be used for billing, accounting, audit, tax and internal record-keeping.

We may process information to prevent fraud, misuse, unauthorised access and unlawful activity.

Information may be used to respond to legal notices, disputes, complaints and regulatory enquiries.

Subject to applicable law and communication preferences, we may use contact details to share service updates, regulatory developments and professional information that may be relevant to you.

8

Basis for Processing Personal Information

We process personal information where you have provided valid consent for a specified purpose.

We may also process information where it is necessary to provide a service requested by you or to take steps at your request before entering into an engagement.

Information may be processed for compliance with a legal, regulatory, tax, accounting or professional obligation.

We may process information for legitimate uses and other lawful purposes recognised under applicable law.

Where information is received from a corporate client, that client is responsible for ensuring that it has the necessary authority to share the information with us.

10

Regulatory and Professional Assignments

Regulatory and licensing assignments may require extensive personal and professional documentation.

Documents may relate to promoters, directors, shareholders, beneficial owners, principal officers, compliance officers, employees and other proposed personnel.

Information may be shared with the concerned regulator or authority as part of the assignment.

Once information is submitted to a regulator or government department, its further processing may be governed by the policies and legal obligations applicable to that authority.

Estabizz Fintech does not control the retention or internal processing practices of a regulator or government authority.

11

Sharing of Personal Information

We do not disclose personal information without a lawful or professional purpose.

Information may be shared only to the extent reasonably required for the assignment or permitted by applicable law.

Regulators and Government Authorities

We may share information with RBI, SEBI, IRDAI, IFSCA, MCA, FIU-IND, income-tax authorities and other competent authorities.

Information may also be shared with courts, tribunals, statutory bodies and law-enforcement agencies where legally required.

Associate Professionals

Estabizz Fintech works with associate professionals across different fields and locations.

Information may be shared with advocates, chartered accountants, company secretaries, auditors, valuers, engineers and other consultants assigned to the engagement.

Such sharing shall be limited to the information reasonably required for their professional role.

Service Providers

We may use service providers for cloud storage, email, client relationship management, ticketing, accounting, communications and cybersecurity.

We may also use payment gateways, document-management platforms, video-conferencing tools and electronic-signature services.

These service providers may process information on our behalf for the limited purpose of providing their contracted services.

Banks and Payment Providers

Payment and banking information may be shared with banks, payment gateways and financial intermediaries to complete and reconcile transactions.

Business Partners

Where a service requires coordination with a business partner, information may be shared after considering the purpose and necessity of such sharing.

A business partner is not permitted to use the information for an unrelated purpose merely because it has received access to it.

Corporate Transactions

Information may be shared during a proposed merger, acquisition, restructuring, investment or transfer of business.

Reasonable confidentiality measures shall be adopted before sharing information for such a transaction.

Legal and Protective Purposes

Information may be disclosed where required to comply with law, enforce contractual rights or respond to a lawful order.

It may also be disclosed where reasonably necessary to prevent fraud, cyber incidents, financial loss or harm to any person.

12

International Processing and Transfers

Estabizz Fintech serves clients and coordinates with professionals in India and other countries.

Accordingly, information may be processed or accessed outside the country in which it was originally collected.

Any international transfer shall be subject to applicable legal requirements and regulatory restrictions.

Where practicable, reasonable contractual and security measures shall be adopted for such processing.

Certain foreign regulators, banks or professional advisers may be required to receive documents for an international assignment.

13

Cookies and Similar Technologies

Our website may use cookies and similar technologies to operate properly and improve user experience.

Cookies are small files stored on a browser or device.

They may help remember user preferences, maintain website security and understand how visitors use the website.

Essential Cookies

Essential cookies support basic website functions.

Disabling these cookies may affect the operation of certain website features.

Analytical Cookies

Analytical cookies help us understand website traffic and performance.

The information obtained may be aggregated for reporting and service improvement.

Preference Cookies

Preference cookies may remember language, location or display settings selected by a user.

Marketing Cookies

Marketing cookies may be used to measure the relevance of promotional campaigns.

Where consent is legally required, such cookies shall be used only after the required choice has been provided.

You may manage cookies through your browser or the cookie settings available on our website.

Blocking certain cookies may affect the performance or availability of some website functions.

14

Third-Party Websites and Platforms

Our website may contain links to third-party websites, portals or applications.

Estabizz Fintech does not control the privacy practices of an independent third party.

You should review the privacy policy of the relevant website before submitting personal information.

Where you communicate with us through WhatsApp, social media or another external platform, the platform provider may process information under its own terms.

15

Marketing Communication

We may send regulatory updates, service information, event invitations and professional insights where permitted by law.

You may opt out of promotional communication by using the unsubscribe facility or writing to us.

Opting out of marketing communication will not prevent us from sending necessary service, payment, compliance or ticket-related messages.

We do not intend to send misleading or unsolicited communication.

16

Client Reviews and Testimonials

We may request feedback regarding our services.

A client’s name, photograph, logo, review or testimonial shall not ordinarily be published for promotional purposes without appropriate permission.

Anonymous or aggregated feedback may be used for internal service improvement.

Where a review has already been made publicly available by the client, we may refer to it subject to applicable law and reasonable professional practice.

17

Data Accuracy

We rely on clients and other individuals to provide accurate and current information.

You should inform us whenever personal information changes or requires correction.

For regulatory assignments, inaccurate information may affect the application or result in further clarification being sought by the authority.

We may request supporting documents before correcting material information.

18

Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected.

The retention period may depend upon the nature of the service, contractual terms and applicable professional requirements.

Certain records may be retained for tax, accounting, audit, legal, regulatory and dispute-resolution purposes.

Documents submitted to a regulator may need to be preserved as part of the assignment record.

Where information is no longer required and no legal reason exists for retaining it, we may delete, anonymise or securely archive it.

Backup copies may continue to exist for a limited period until they are overwritten under normal system processes.

19

Information Security

Estabizz Fintech takes reasonable technical, organisational and administrative measures to protect information.

Measures may include access controls, password protection, user authentication, backups, secure storage and restricted document access.

Access to client information is intended to be limited to persons who require it for authorised professional or operational purposes.

Employees, consultants and associate professionals may be subject to confidentiality obligations.

However, no electronic transmission, cloud system or storage method can be guaranteed to remain completely secure in every circumstance.

Clients should also take reasonable care while sending documents and should avoid using unauthorised communication channels.

20

Personal Data Breach

A personal data breach may involve unauthorised access, disclosure, loss, alteration or destruction of personal information.

Where we become aware of a material incident, we shall assess its nature and likely impact.

We may take steps to contain the incident, secure the affected systems and prevent recurrence.

Where required under applicable law, we shall notify the concerned authority and affected individuals in the prescribed manner.

Clients may be required to cooperate where the incident relates to systems, credentials or information under their control.

21

Individual Rights

Subject to applicable law, you may request information regarding the personal data processed by Estabizz Fintech.

You may request correction, completion or updating of inaccurate or incomplete personal information.

You may request deletion of personal information where it is no longer required and where retention is not legally necessary.

Where processing is based on consent, you may withdraw that consent.

You may also raise a grievance regarding the handling of personal information.

Where permitted by law, you may nominate another individual to exercise your rights in the event of death or incapacity.

A request may be refused or restricted where compliance would conflict with a legal obligation, regulatory requirement, professional privilege or the rights of another person.

22

Exercising Your Rights

A request should be submitted through the privacy or grievance contact mentioned in this Policy.

The request should clearly explain the information concerned and the action required.

We may ask for proof of identity before processing the request.

This verification is intended to protect information from unauthorised disclosure or alteration.

We shall review the request and respond within the period prescribed under applicable law or within a reasonable time where no specific period applies.

Requests that are repetitive, fraudulent or unrelated to the requesting individual may be declined in accordance with law.

23

Information Relating to Children

Our professional services are primarily intended for businesses and adults.

We do not knowingly seek personal information directly from a child for advertising or behavioural monitoring.

Where information relating to a child is necessary for a lawful assignment, it should be provided by a parent, lawful guardian or duly authorised person.

Verifiable parental or guardian consent shall be obtained where required under applicable law.

We shall not knowingly process a child’s information in a manner likely to cause a detrimental effect on their well-being.

24

Employees, Consultants and Candidates

Employee and consultant information may be processed for recruitment, onboarding, attendance, payroll, performance and statutory compliance.

It may also be used for access control, training, workplace administration and disciplinary or grievance processes.

Candidate information may be retained for the concerned recruitment process and, where appropriate, for future opportunities.

A candidate may request that their information not be considered for future positions.

Additional internal notices or policies may apply to employees and consultants.

25

Confidential Client Information

Not all confidential business information is personal information.

Nevertheless, Estabizz Fintech aims to handle client documents, business plans, financial information and regulatory records with professional confidentiality.

Confidentiality obligations may also be governed by the engagement letter, non-disclosure agreement or applicable professional standards.

This Privacy Policy does not reduce any stronger confidentiality obligation separately accepted by Estabizz Fintech.

26

Sale of Personal Information

Estabizz Fintech does not sell personal information as an independent commercial product.

Information may be shared with authorised professionals and service providers only for legitimate business, legal or professional purposes.

Any future material change in this practice shall be reflected in this Policy and handled in accordance with applicable law.

27

Automated Processing

We may use software tools to organise documents, manage service tickets, identify pending requirements and improve operational efficiency.

Important professional or regulatory decisions are not intended to be made solely through automated processing without appropriate human review.

Information generated by software tools may be reviewed by an authorised team member before being used for a material assignment decision.

28

Changes to This Privacy Policy

We may revise this Policy to reflect changes in law, technology, services or internal processes.

The updated Policy shall be published on our website with the revised date.

Where a change materially affects the manner in which personal information is used, we may provide additional notice where required.

Continued use of our services after publication does not remove any consent requirement imposed by applicable law.

29

Grievance Redressal

Any privacy concern should first be raised with the authorised privacy or grievance contact of Estabizz Fintech.

Please provide your name, contact details, ticket number and a clear description of the concern.

We may seek further information to understand and resolve the matter.

The grievance shall be reviewed fairly and responded to within the applicable legal timeline or within a reasonable period.

Where a person remains dissatisfied, they may pursue the remedies available under applicable law.

30

Governing Law

This Privacy Policy shall be governed by the laws of India.

It shall be read with the Digital Personal Data Protection Act, 2023, the rules made under it, the Information Technology Act, 2000 and other applicable laws, as amended or brought into force from time to time.

Nothing in this Policy shall restrict any right that cannot lawfully be restricted.

31

Contact Us

For privacy-related requests, corrections, withdrawal of consent or grievances, please contact:

Estabizz Fintech Private Limited

Privacy Contact: Advocate Charmi Sambhalawala

Grievance Email: info@estabizz.com

Telephone: +91-98256-00907

Website: www.estabizz.com

Please mention "Privacy Request" in the subject line and provide the relevant client ticket number, wherever available.