MMFDTools

Privacy Policy

Effective: 13 May 2026 · Version 1.0 · DPDP Act 2023 compliant

🛡 Your data, your control.

MFDTools.com is committed to protecting your privacy and personal data in line with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011.

1. Who we are (Data Fiduciary)

MFDTools.com is operated by DigiMutual Goals Pvt. Ltd. ("we", "us", "the Company"), the Data Fiduciary under the DPDP Act. Registered office: SCO-01, Near IndusInd Bank, Aastha Hospital Street, Chotala Road, Mandi Dabwali – 125104, District Sirsa, Haryana. AMFI ARN-332982.

Grievance Officer / Data Protection Officer: Deepak Singla[email protected], +91 95412 23377.

2. What data we collect

2.1 From Customers (paying MFDs/advisors)

CategoryExamplesSource
IdentityFirm name, founder name, professional credentials (ARN, COP, IRDAI etc.)Self-provided
ContactEmail, mobile, office addressSelf-provided
AuthenticationHashed password (SHA-256 or PBKDF2), Access PIN hash, session tokensDerived from your inputs; raw passwords are never stored
Brand assetsLogo image, theme color preference, taglineSelf-uploaded
TransactionalPayment amount, tier, validity dates, license IDGenerated during purchase
UsageLogin times, IP-derived rate-limit data, audit log entriesAutomatic when you use the Service

2.2 From visitors of branded suites (your clients)

When end-clients use your branded calculator at mfdtools.com/c/yourfirm, we may temporarily process:

3. Why we collect (Purpose & Legal Basis)

Under DPDP Act, processing of personal data requires a lawful purpose. Our purposes:

  1. Provide the Service — generate branded suites, host them, enable login
  2. Process payments and manage subscriptions
  3. Authenticate users — verify password/PIN to prevent unauthorised access
  4. Security & fraud prevention — rate limiting, audit logs, anomaly detection
  5. Communication — renewal reminders, support responses, important Service updates
  6. Compliance — comply with applicable laws (AMFI, IT Act, DPDP Act), respond to lawful requests
  7. Service improvement — aggregate, anonymised analytics

Legal basis: Contractual necessity (Sec 7 DPDP Act) for items 1-4; Legitimate interest (within limits) for items 5-7; Your explicit consent for any marketing communications.

4. How we use cookies and similar tech

We use minimal cookies and browser storage:

5. Who we share data with

We share minimal data only with the following Data Processors, under strict confidentiality:

ProcessorPurposeLocation
SupabaseDatabase hosting (PostgreSQL), file storage, authenticationAWS Singapore (ap-southeast-1) — encrypted at rest, TLS in transit
VercelStatic site hosting + CDN deliveryMulti-region edge, primary India
CloudflareDNS, CDN, DDoS protectionGlobal edge network
WhatsApp / MetaOnly when YOU click "WhatsApp" buttons — message handover to WhatsAppMeta's own infrastructure

We do NOT share customer or visitor data with marketing platforms, ad networks, or unrelated third parties. We do NOT sell your data.

6. Data retention

7. Your rights under DPDP Act

You have the following rights regarding your personal data:

  1. Right to information: Know what data we hold about you (request via portal or email)
  2. Right to correction / update: Update your details via Customer Portal anytime
  3. Right to erasure ("Right to be Forgotten"): Request full deletion (subject to legal retention requirements above)
  4. Right to grievance redressal: Contact our Data Protection Officer (Sec 13 DPDP Act)
  5. Right to nominate: You may nominate another person to exercise these rights on your behalf in case of incapacity / death

To exercise any right, email [email protected] with subject "DPDP Request — [your request]". We will respond within 30 days as required by law.

8. Security measures

9. Children's privacy

Our Service is intended for licensed financial professionals only. We do not knowingly collect data from anyone under 18. If we learn we have collected data from a minor, we will delete it immediately.

10. International transfers

While our primary operations are India-based, our Data Processors (Supabase AWS Singapore, Vercel multi-region) may store data outside India. All such transfers are subject to standard contractual clauses and equivalent data-protection safeguards per DPDP Act Sec 16.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be notified via email and shown on this page with a new effective date. Continued use after changes constitutes acceptance.

12. Grievance & complaints

If you believe your personal data has been mishandled or your rights violated:

  1. Email our Grievance Officer at [email protected]
  2. We will respond within 7 days and resolve within 30 days
  3. If unsatisfied, you may approach the Data Protection Board of India once established under Sec 18 DPDP Act
  4. Consumer disputes may be filed at the appropriate Consumer Forum under Consumer Protection Act, 2019
© 2026 DigiMutual Goals Pvt. Ltd. (MFDTools.com)
Home   Terms   Refunds