Aspero

Invest with aspero

4.6 App store rating

Privacy Effective · 19 December 2023

Privacy Policy.

We are committed to protecting your privacy and handling the data we collect about an individual who is identifiable by or in relation to such data ("Personal Data") in compliance with applicable law. This Policy explains what we collect, how we use it, who we share it with, and the rights you hold over your data.

01

Use and Acceptance

(a)

This Policy should be read in conjunction with the Terms of Use, available on the Platform, and the privacy practices described therein.

(b)

We encourage you to read both documents carefully before accessing the web/Platform and/or availing the Services through the Platform.

(c)

By either clicking on “I Agree”, or by accepting any other clear, affirmative action that may be prompted by Aspero for your consent, your consent is recorded to the terms of this Policy and to processing of your Personal Data for the purposes of your consent and access to the Platform or usage of services. You have the full right not to provide your consent and may choose not to disclose your Personal Data. However, in such cases, certain services or features that require the use of your Personal Data may not be available to you.

(d)

If you disclose to us any Personal Data relating to other people, you represent that you have the authority to do so and permit us to use such data in accordance with this Policy.

02

Applicability of this Policy

()

This Policy applies to all clients, users and any other stakeholders who access or use the Platform and provide Personal Data on the Platform (or to whom Aspero provides its Services). Please note this Policy does not apply to any Personal Data dealt by any third-party sites.

03

The Data We Collect

(a)

We strive to collect only the Personal Data that is necessary for the purposes for which it is processed, subject to your explicit consent. The collection and processing of your Personal Data are carried out based on: your affirmative and explicit consent provided through an explicit action displayed to you at the time of registration or account creation on the Platform; and legitimate purposes, where processing is carried out under applicable law.

(b)

“Personal Information” includes your full name, mobile number, email address, residential address, gender, date of birth, permanent account number (PAN), Aadhaar number, bank details, and other financial information necessary for investment purposes.

(c)

“Sensitive Personal Data”, including financial information such as bank account details, payment instrument details, and information relating to your transactions, is collected and processed strictly in accordance with applicable law.

(d)

“Beneficiary Information”: all personal information of a nominated beneficiary asserted by you. You agree and acknowledge that you shall be responsible for providing complete and accurate information to us for the purpose of availing the services.

04

Collection of Aadhaar Information

(a)

During the online account opening and registration process, you shall not be required to input your complete 12-digit Aadhaar number directly on the Platform. Instead, you will be redirected to third-party service providers like Digilocker or other, where, upon your explicit consent, such third parties will share limited details with us.

(b)

The Platform for verification purposes. These details shall be restricted to (i) the last four digits of your Aadhaar number or virtual ID (VID); (ii) full name; (iii) date of birth; (iv) gender; and (v) photograph stored in an encrypted & masked form. The use of such information is subject to applicable laws, including the Aadhaar Act, 2016 and rules framed thereunder.

05

How We Collect Your Data

(a)

We collect your Personal Data from various third-party sources such as: KYC registration agencies (KRAs), credit information companies and other databases, such as Know Your Customer (KYC) Registration Agency (KRA), government records like Digilocker, bank verification services, e-sign service providers, payment gateways, financial institutions, and depositories (CDSL/NSDL). Such verification may require additional documentation or verification steps as mandated by regulatory requirements.

(b)

We may also obtain your data from various third-party sources such as: responses to surveys or marketing communications initiated by us or by our authorised vendor partners; voice recordings or record of interaction of customer service conversations to address queries or grievances; any other media subject to your explicit consent; and cookies and tracking technologies.

06

How We Process Your Data

(a)

We ensure that your Personal Data is processed to provide you our services, to improve, modify or enhance our services, to comply with our legal and regulatory obligations, and for other ancillary legitimate business purposes in connection with the services, including but not limited to customer support, operational efficiency, internal analysis, reporting obligations, and any other purposes permitted under applicable law.

(b)

In particular, we process your Personal Data for: creation of your user account on the Platform; verification of your identity and access privileges on the Platform; enabling you to transact and access the financial securities available on the Platform through an authorised seller or business partner.

(c)

To contact Know Your Customer (KYC) records and to comply with all legal and regulatory requests as per the Applicable laws, and to process and validate your financial information from various sources, including but not limited to financial institutions, and other service providers as may be required.

(d)

To process payments on your behalf and as your behalf, in connection with your regarding your queries, transactions, and any regulatory requirements, etc.

(e)

Without prejudice to the above, where required to do so under applicable law, we may disclose your Personal Data to courts and other government entities to comply with valid legal process or to defend or protect our rights or property, or that of our customers.

07

Disclosure of Your Personal Data

(a)

As a general rule, Aspero will not disclose Personal Data except where Aspero is required or permitted per your agreement/Terms of Use, including pursuant to a national security of law enforcement requirements; or otherwise, such as when the Aspero believes in good faith that the law requires disclosure or other circumstances outlined in this Policy require or permit disclosure.

(b)

Aspero may disclose your Personal Data: where permitted or required by law; trying to protect against or prevent actual or potential fraud or unauthorised transactions; or in investigating fraud which has already taken place.

(c)

Third Party Service Providers: we work with third-party service providers who assist in delivering our services to you through the Platform. Your Personal Data may be shared (subject to your explicit consent) to these service providers and to enable processing, KYC verification, identity authentication, financial data analysis, settlement of transactions, payment processing, verification of bank/demat account details and other ancillary services such as reporting, customer relationship management, cloud storage, advertising, and marketing etc.

(d)

Disclosure with your consent: where applicable, before we disclose your Personal Data to any third party, we will use our best endeavours to make sure the Personal Data is secured and processed as per the agreement between us and you.

08

Data Retention

(a)

Legal or Regulatory Obligations: we retain your Personal Data for as long as it is necessary to fulfil the purposes for which it was collected, or as required by Applicable Law. We may retain your Personal Data even after you request deletion for the following specific purposes: compliance with statutory obligations; regulatory and reporting requirements; and resolution of disputes, audits, and the enforcement of our rights.

(b)

Cessation of Relationship & Data Cessation: if a user requests to terminate their relationship with us without completing KYC and/or executing transactions, we delete their Personal Data on a commercially reasonable effort basis within 90 (ninety) days. However, the Personal Data so required and applicable laws is retained and will be purged once the legal/contractual time frame expires. Any regulatory requirements that we are obligated to retain may also be retained for the period prescribed under applicable law.

09

Data Security

(a)

Data Storage Location: your information is stored on secure servers located in India, ensuring that your Personal Data remains within the Indian jurisdiction.

(b)

Security Safeguards and Inherent Risks: we prioritise the confidentiality and security of the Personal Data that you share with us. Accordingly, we adopt industry standard security safeguards to protect your Personal Data, from unauthorised access, use and disclosure. We maintain high standards through regular testing, ensuring our systems are resilient against working threats. Furthermore, we adhere to the following industry certification: ISO 27001:2022. We regularly test and update our security measures to protect your data against evolving threats.

(c)

Our Commitment to Confidentiality: we shall disclose in the event of a Personal Data breach, we will fulfil our mandatory obligations under Section 8(6) of the DPDPA by notifying the Data Protection Board of India (DPBI) and each affected Data Principal without undue delay.

(d)

Mandatory Notification to the Regulator: upon detection and confirmation of a Personal Data Breach, the Company will promptly assess the risk to Data Subjects. We are obligated to notify the Competent Authority (Data Protection Board) of the breach without undue delay (and later than 72 hours) once we become aware of an incident that compromises the confidentiality, integrity, or availability of Personal Data.

(e)

Notification to the Data Subject (You): we will notify you, the Data Subject, of the Personal Data breach if the breach is likely to result in significant harm or risk to your privacy, rights, or freedoms. Timing: notification to the Data Subject will be made as soon as practically feasible (not later than 72 hours) after the risk assessment is complete, and the Competent Authority has been informed (where required). Method: notification will typically be sent via compliance/security communication channels.

(f)

Data Access Logs & Monitoring: we may maintain detailed access logs and monitoring systems to track all access to Personal Data and detect any unauthorised access attempts. We keep these logs for a defined period and use them for security purposes, internal review and as needed for making enquiries, orders, feedback or other purposes for monitoring services effectively and efficiently.

10

Your Rights and Duties

(a)

As a Data Principal, you have the following rights under the Digital Personal Data Protection Act, 2023 (DPDPA), subject to the Aspero’s obligations as a Data Fiduciary and the applicable legal and regulatory framework.

(b)

Right to access information: you may request to access and review your Personal Data, and the purpose for which it is processed.

(c)

Right to correction and erasure: you may request the correction of any inaccurate or misleading Personal Data, or the completion of any incomplete data. You may also request that we erase Personal Data that is no longer required for the purpose it was collected, subject to our legal and regulatory retention obligations.

(d)

Right to grievance redressal: you have the right to readily available means of grievance redressal provided by Aspero in respect of any act or omission regarding your Personal Data or the exercise of your rights.

(e)

Right to nominate: you have the right to nominate another individual to exercise your rights in the event of death or incapacity.

Questions about your data?

Write to us at privacy@aspero.in. This Policy is issued by Aspero Markets Private Limited (formerly Credavenue Securities Private Limited), Chennai, and may be updated from time to time; the version posted here is effective 19 December 2023.