Loading your workspace. Please wait...
Loading your workspace. Please wait...
Governed by: DPDPA 2023 · IT Act 2000 · IT (Intermediary Guidelines) Rules 2021 as amended 2026
Finucity Technologies Private Limited is the company responsible for your data. Under India's DPDPA 2023, we are classified as a 'Data Fiduciary' — meaning we decide how your personal data is processed and we're legally accountable for it.
Finucity Technologies Private Limited ("Company", "Finucity", "we", "us", "our"), incorporated under the Companies Act, 2013, with its registered office in Pune, Maharashtra, India, operates the Finucity platform ("Platform").
Under the Digital Personal Data Protection Act, 2023 ("DPDPA 2023"), the Company is classified as a Data Fiduciary as defined under Section 2(5) of the Act. As Data Fiduciary, we determine the purpose and means of processing your personal data and bear primary responsibility for compliance with all data protection obligations under the DPDPA 2023.
We also operate in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 (as amended 2026).
We collect information needed to verify CAs, match you with the right professional, process payments, and provide AI-powered document parsing. Here's the full list of what we collect.
Identity & Verification Data:
Financial & Business Documents:
Technical & Device Data:
Under DPDPA 2023, bundled consent is illegal. Each data processing purpose has a separate consent toggle. Some are mandatory for the platform to function; others are optional and you can turn them off anytime from your privacy settings.
Under DPDPA 2023 Section 5, consent must be granular, itemized, and purpose-specific. Bundled consent is not permitted. The Company processes your data under the following distinct consent modules, each requiring separate affirmative action at registration/onboarding:
Consent Toggle 1 — Identity Verification (MANDATORY)
PAN, ICAI MRN, Aadhaar (masked) collected for credential verification via Decentro API. Non-waivable — platform cannot function without this.
Consent Toggle 2 — Service Delivery (MANDATORY)
Contact details and uploaded documents shared with assigned CA for service execution. Non-waivable.
Consent Toggle 3 — Escrow Payment Processing (MANDATORY)
Financial data processed through RazorpayX for payment collection and release. Non-waivable.
Consent Toggle 4 — AI Document Parsing (OPTIONAL)
Uploaded documents processed by Groq-powered AI pipeline (Llama models) and Fal.ai for automated data extraction. User can opt for manual CA-only review without AI processing.
Consent Toggle 5 — Platform Analytics (OPTIONAL)
Anonymized usage data for feature improvement and platform optimization.
Consent Toggle 6 — Marketing Communications (OPTIONAL)
Platform updates, offers, and newsletter communications.
Consent Ledger
All consent decisions are logged in an immutable consent ledger. Users may review and modify optional consents at any time via Account Settings > Privacy Preferences. Full operationalization of the Consent Manager Registry (as per DPDPA Rules) is planned for November 2026.
Your data is encrypted using military-grade AES-256 encryption at rest and TLS 1.3 in transit. Everything is stored on Indian servers (Mumbai region). We use Supabase with Row Level Security — so even at the database level, users can only access their own data.
Encryption Standards:
Server Localization: All persistent data is stored exclusively on servers located in India, specifically in the ap-south-1 (Mumbai) region through our infrastructure provider (Supabase). Personal data at rest is not stored on servers outside India.
Database Security: We utilize Supabase with Row Level Security (RLS) policies ensuring that: (a) Users can only access their own data; (b) Practitioners can only access data shared with them by their clients; (c) Administrative access requires multi-factor authentication and is logged in an immutable audit trail.
Infrastructure: Our infrastructure includes regular security audits, automated vulnerability scanning, DDoS protection, and Web Application Firewall (WAF) rules.
We keep your data for a minimum of 1 year and maximum of 3 years after you leave the platform. Some data may be kept longer if required by tax or anti-money-laundering laws. If you request deletion, we process it within 30 days.
Standard Retention: Personal data is retained for a minimum of one (1) year and a maximum of three (3) years after the termination of the business relationship, unless a longer retention period is required by applicable law.
Legal Exceptions:
Erasure SLA: Upon receiving a valid erasure request from a Data Principal, the Company commits to completing data deletion within thirty (30) days, subject to legal retention requirements and ongoing dispute resolution obligations.
Document Retention Notice: Uploaded financial documents are retained according to service context, legal obligations, and dispute requirements. Users may request erasure at any time, and valid requests are processed within thirty (30) days subject to statutory retention duties.
We share some data with trusted third-party providers who help us run the platform. Each one is bound by a Data Processing Agreement (DPA). Here's who they are and what they access.
The Company engages the following third-party Data Processors, each bound by a Data Processing Agreement (DPA) that complies with DPDPA 2023 requirements:
RazorpayX (RBI-Licensed Payment Aggregator)
Purpose: Payment processing, escrow management, payout disbursement
Data Shared: Name, email, PAN (for KYC), payment amounts, bank account details
Location: India
Decentro Technologies
Purpose: PAN verification, ICAI membership verification, GSTIN validation
Data Shared: PAN number, ICAI MRN, GSTIN
Location: India
Groq, Inc. (US) — Llama LLM Models
Purpose: AI document parsing, AI chat assistant, AI content generation
Data Shared: Document content (processed transiently in-memory via API)
Location: United States (transient API processing — see Section 9)
Fal.ai
Purpose: Document visual parsing and image processing for financial documents
Data Shared: Document images (processed transiently via API)
Location: United States (transient API processing — see Section 9)
Supabase (ap-south-1, Mumbai)
Purpose: Database hosting, authentication, file storage
Data Shared: All platform data (stored at rest in India)
Location: India (Mumbai region)
No third-party processor is authorized to use your data for purposes beyond those specified in their DPA. The Company conducts annual compliance audits of all Data Processors.
Under DPDPA 2023, you have the right to access, correct, or delete your data. You can withdraw consent anytime. You can also nominate someone to manage your data if something happens to you. Some data cannot be deleted if required by tax or anti-money-laundering law — but we'll tell you exactly why.
Under the DPDPA 2023, you (as a "Data Principal") have the following rights:
Erasure Rights — Statutory Override Hierarchy
Erasure requests will be processed within thirty (30) days subject to legal supremacy of the following overriding statutory retention mandates:
Where erasure is declined due to statutory obligation, the Company will notify the Data Principal in writing within 30 days, identifying the specific law that mandates retention and the expected expiry of that obligation.
To exercise any of these rights, contact our Data Protection Officer at hello@finucity.com. We will acknowledge your request within 48 hours and fulfill it within 30 days.
AI document processing involves sending data to Groq (US) and Fal.ai (US) via API calls — this constitutes a transient cross-border transfer. If you opted into AI processing (Consent Toggle 4), you've consented to this. If you opted out, your documents stay entirely in India on our Mumbai servers.
Acknowledgment of Transient Cross-Border Transfer: AI document processing features involve API calls to Groq, Inc. (United States) — powering Llama-based LLM models — and Fal.ai (United States) — powering document visual parsing. These API calls constitute a transient cross-border data transfer under DPDPA 2023 Section 16, regardless of whether the provider retains the data.
Legal Basis: This transfer occurs under the DPDPA 2023 Section 16 framework. As of the date of this policy, the Central Government has not notified a restriction on data transfers to the United States under Section 16(1).
Contractual Safeguards: Standard Contractual Clauses (SCCs) are enforced with both Groq and Fal.ai, contractually prohibiting: (a) persistent storage of user data; (b) use of user data for model training; (c) further sub-processing without authorization.
Consent Linkage: Users who have opted in to AI document parsing (Consent Toggle 4 in Section 3) have explicitly consented to this transient cross-border transfer as part of the AI processing consent.
India-Only Processing Path: Users who have NOT opted into AI processing (Consent Toggle 4) have their documents processed exclusively within India on Supabase infrastructure (Mumbai region, ap-south-1). No document data is transmitted to servers outside India for these users.
Non-AI Data: All non-AI personal data (identity, payment, contact details) is stored and processed exclusively within India at all times.
If a confirmed data breach is likely to cause harm, we notify both the Data Protection Board of India AND all affected users within 72 hours, with full details including what happened, who's affected, and what we're doing about it.
In case of a confirmed personal data breach that is likely to result in significant harm to Data Principals, the Company will issue breach notifications without undue delay and, where reasonably feasible, within seventy-two (72) hours of confirmation.
Dual Notification Obligation: Breach notifications shall be simultaneously issued to: (a) the Data Protection Board of India (DPBI) as constituted under Chapter V of the DPDPA 2023; AND (b) each affected Data Principal via their registered email address.
Required Notification Content: Notifications shall include: (i) nature and description of the breach; (ii) categories and approximate number of affected Data Principals; (iii) name and contact details of the Data Protection Officer (hello@finucity.com); (iv) likely consequences of the breach; (v) mitigation measures taken or proposed.
Public Notice Fallback: Where notification to all affected Data Principals is not reasonably feasible within 72 hours, Finucity shall issue a public notice via the Platform homepage and the DPO contact page, updated as new information becomes available.
The Company will preserve forensic logs, coordinate containment actions, and maintain an incident record for regulatory reporting and audit purposes.
We've appointed a DPO who handles all privacy-related requests. You can reach them via email at hello@finucity.com. They'll get back to you within 48 hours.
Designation: Data Protection Officer
Organization: Finucity Technologies Private Limited
Email: hello@finucity.com
Acknowledgement: Within 48 hours
Resolution: Within 30 days as per DPDPA 2023
Escalation: Data Protection Board of India
We track every change we make to this policy. Below is the complete history so you can see exactly what changed and when.
| Version | Date | Changes |
|---|---|---|
| 2.0 | July 18, 2026 | Full DPDPA compliance audit: granular consent modules, cross-border transfer disclosure for Groq/Fal.ai, breach notification strengthening, erasure rights override hierarchy, Consent Manager Registry section |
| 1.1 | April 11, 2026 | Added breach notification section, clarified retention language, and aligned cookie consent disclosures with implementation. |
If you have a complaint about how your data is handled, contact our Grievance Officer. We'll respond within 72 hours and resolve within 30 days. If you're not satisfied, you can escalate to the Data Protection Board of India.
Grievance Officer: Sumeet Sangwan (Founder & CEO)
Email: hello@finucity.com
Response Time: Within 72 hours of receipt
Resolution SLA: Within 30 days as mandated by DPDPA 2023
Escalation Path: If unresolved, complaints may be escalated to the Data Protection Board of India as constituted under Chapter V of the DPDPA 2023.
India's DPDPA rules will soon require a registered Consent Manager. We're building this infrastructure now. Until it's officially launched (expected November 2026), you can manage your consents directly in your Privacy Preferences settings.
In anticipation of the operationalization of the Consent Manager Registry under DPDPA 2023 Rules (expected November 2026), Finucity is implementing a DPDPA-compliant Consent Manager infrastructure.
Upon registry operationalization, users will be able to grant, review, and withdraw consent through the registered Consent Manager interface as per the prescribed Rules.
Until operationalization, consent is managed directly through the Platform's Privacy Preferences module accessible via Account Settings > Privacy Preferences. All consent changes are logged in the immutable consent ledger referenced in Section 3.
© 2026 Finucity Technologies Private Limited. Incorporation Pending — MCA Filing in Progress. All rights reserved.