Legal
Privacy Policy
Effective date: 1 January 2026 · Version: 2.0
A plain-language version is below each section header. The detailed clauses follow.
1. Who we are
In plain English
WealthGuard Global LLP operates DhanSafe — a financial vault and claim recovery service for Indian families.
We are registered in Bengaluru, India (CIN: U72900KA2024PTC000000). For privacy matters, our Data Protection Officer can be reached at service@dhansafe.com.
2. What information we collect
In plain English
We collect what you give us — your identity, the financial documents you upload, and basic device info to keep your account secure.
2.1 Information you provide
- Identity: name, date of birth, PAN, Aadhaar (for verification only, not stored in plaintext), mobile number, email.
- Financial documents: insurance policies, bank statements, mutual fund statements, EPF passbook, property papers — uploaded by you.
- Family & nominee details: names and relationships of those you grant access to.
- Communications: emails, chats and call recordings you have with our team.
2.2 Information collected automatically
- Device data: IP address, device type, OS, browser version.
- Usage data: pages visited, features used, error logs.
- Authentication tokens (encrypted, in your browser/app only).
3. How we use your information
In plain English
We use it to deliver the service you signed up for. That's it. We don't sell your data, we don't show you ads.
- To organise your financial vault and run the Readiness Score.
- To process claim recoveries on your authority.
- To verify your identity via UIDAI-issued Aadhaar OTP.
- To communicate transactional updates (recovery status, KYC nudges).
- To comply with Indian financial and tax law (e.g., GST invoices).
- To detect, prevent and respond to security incidents.
4. When we share data
In plain English
Only with institutions you authorise us to file claims with, and with auditors/regulators when legally required.
- With your authorisation: banks, insurers, AMCs, EPFO, registrars and other institutions during claim recovery.
- With service providers: infrastructure providers (AWS Mumbai, an India-resident audited vendor), strictly for processing on our instructions; bound by data-processing agreements.
- With your family: only members you explicitly invite, after Aadhaar verification.
- With authorities: when required by valid Indian legal process. We push back on overbroad requests and notify you unless legally restrained.
- We do not sell, lease, rent, or share your data with advertisers, brokers, or marketing partners.
5. How we protect your data
In plain English
AES-256 encryption, zero-knowledge architecture, Indian data centres, quarterly pen-tests.
- Encryption: AES-256 at rest, TLS 1.3 in transit.
- Zero-knowledge: decryption keys stored only on your device.
- Residency: all data stored in AWS Mumbai (ap-south-1) and replicated to AWS Hyderabad.
- Access control: least-privilege, MFA-mandatory, full audit log of staff access.
- Pen-testing: quarterly by a CERT-In empanelled vendor.
- Incident notification: within 72 hours of any qualifying breach, per the DPDP Act.
6. Your rights under the DPDP Act
In plain English
You can see, fix, or delete everything we have. One-click export available anytime.
- Right to access: request a copy of all personal data we hold.
- Right to correction: ask us to update or correct inaccurate data.
- Right to erasure: ask us to delete your data, except where retention is legally required.
- Right to grievance redressal: contact our DPO; we respond within 30 days.
- Right to nominate: appoint a person to exercise your rights if you become incapacitated.
- Right to withdraw consent: at any time, with one-click export of your data.
Exercise any of these by writing to service@dhansafe.com.
7. Data retention
In plain English
While you're a member, plus 7 years for tax & regulatory records. You can delete sooner.
- Active accounts: retained for the duration of your membership.
- Closed accounts: financial records retained for 7 years per Indian tax law; the rest deleted within 30 days of cancellation.
- Anonymised analytics: may be retained indefinitely; no individual identity attached.
8. Cookies & analytics
In plain English
Only the bare minimum to keep you logged in. No third-party tracking on logged-in surfaces.
- Strictly necessary cookies: session, CSRF token, locale. Cannot be disabled.
- Analytics: privacy-preserving (Plausible) on marketing pages only. No cookies, no personal identifiers.
- No Google Analytics, no Facebook Pixel, no advertising cookies anywhere.
9. Children's data
In plain English
We don't knowingly collect data from anyone under 18.
DhanSafe is intended for adults aged 18 and above. We do not knowingly collect personal data from minors. If you believe we have, contact us at service@dhansafe.com and we will delete it.
10. Changes to this policy
In plain English
We'll email you before any material change takes effect.
Material changes will be notified via email at least 30 days before they take effect, and the previous version will remain accessible in your account history.
11. Contact us
Data Protection Officer · service@dhansafe.com
Grievance Officer · service@dhansafe.com
Registered office · WealthGuard Global LLP, 1237, First Floor, Sri Sai Crystal, 5th Main, 7th Sector, HSR Layout, Bangalore 560102.
