Privacy Policy
This Privacy Policy is published by CAPLY FINTECH LLP and constitutes the notice required under Section 5 of the Digital Personal Data Protection Act, 2023. Please read it together with the Caply Terms & Conditions.
1. Introduction
This Privacy Policy ("Policy") explains how CAPLY FINTECH LLP ("Caply", "Company", "we", "us", or "our") collects, uses, stores, processes, shares, and protects your personal data when you access or use the CAPLY mobile application ("Application"), our website, and related products and services (collectively, the "Services"). This Policy is published pursuant to Section 5 of the Digital Personal Data Protection Act, 2023 and should be read together with the Caply Terms & Conditions.
Caply operates the Application as a technology platform that enables you to access mutual fund and other financial products. Mutual fund distribution services made available through the Application are provided by MoneyTrail Securities Private Limited, a mutual fund distributor registered with AMFI under ARN-190417 (EUIN E-105308) (the "Distributor").
CAPLY FINTECH LLP is the Data Fiduciary that determines the purposes and means of processing personal data collected through the Application under the DPDP Act. Where personal data is shared with the Distributor to facilitate your transactions, the Distributor processes such data as a Data Fiduciary for its own regulatory and distribution purposes.
2. This Policy, Notice and Your Consent
This Policy serves as the notice describing the personal data we collect, the specific purposes for which it is processed, and the manner in which you may exercise your rights and make a complaint.
We process your personal data on the basis of your consent or on the basis of certain legitimate uses permitted under the DPDP Act. Where we rely on consent, it is obtained through a clear affirmative action at the point of collection. Your consent is free, specific, informed, unconditional, and unambiguous, and is limited to the personal data necessary for the specified purpose.
You may withdraw your consent at any time, as easily as you gave it, through the privacy settings in the Application or by contacting our Grievance Officer (Section 20). Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and may limit or prevent our ability to provide some or all of the Services. Where processing is required to be continued under applicable law, we may continue to process the relevant personal data to that extent.
You may also be able to give, manage, review, or withdraw your consent through a Consent Manager registered with the Data Protection Board of India, as and when such facility is made available.
3. Applicability
- Users of the CAPLY mobile application
- Prospective and registered investors who use the Services
- Visitors to our website and digital platforms
- Individuals who interact with us for customer support or service-related purposes
4. Key Definitions
- "Data Principal" means the individual to whom the personal data relates (i.e., you).
- "Data Fiduciary" means the person who, alone or with others, determines the purpose and means of processing personal data.
- "Data Processor" means any person who processes personal data on behalf of a Data Fiduciary.
- "Personal Data" means any data about an individual who is identifiable by or in relation to such data.
- "Processing" means any operation performed on personal data, including collection, storage, use, sharing, or erasure.
- "DPDP Act" means the Digital Personal Data Protection Act, 2023 together with the Digital Personal Data Protection Rules, 2025, as amended.
5. Personal Data We Collect
Identity Information
- Full name, date of birth, gender
- PAN
- Aadhaar details (processed only through authorised channels)
- Signature and photograph
Contact Information
- Mobile number, email address
- Residential and correspondence address
Financial Information
- Bank account details and IFSC code
- Investment and transaction details
- Mutual fund folio information
KYC and Regulatory Information
- KYC records, FATCA/CRS declarations
- Nominee information
- Regulatory declarations and disclosures
Technical Information
- Device information, operating system, mobile device identifiers
- IP address, browser information
- Application usage and log information
Communication Information
- Customer support interactions, email and chat communications, service requests
6. How We Collect Personal Data
- Directly from you during registration, onboarding, and use of the Services
- Through KYC verification processes, including SEBI-registered KYC Registration Agencies (KRAs) and the Central KYC Registry (CKYC)
- During investment transactions and your interactions with the Application
- Through customer support interactions
- Through cookies, SDKs, and analytics technologies (Section 17)
- From authorised third-party service providers and regulatory databases, where permitted by law
7. Purposes of Processing
We process personal data only for specified, lawful purposes. The table below maps the main categories of personal data to the purposes for which they are processed and the basis of processing.
| Purpose | Personal Data Used | Basis |
|---|---|---|
| Registration, authentication & account management | Identity, Contact, Technical | Consent / Performance of Services |
| KYC verification & onboarding | Identity, KYC/Regulatory, Financial | Legal obligation |
| Processing mutual fund transactions (purchase, SIP, STP, switch, redemption) | Identity, Financial, KYC/Regulatory | Consent / Performance of Services |
| Regulatory compliance, AML monitoring, FATCA/CRS & reporting | Identity, Financial, KYC/Regulatory | Legal obligation |
| Customer support & grievance handling | Contact, Communication, Transaction | Performance of Services |
| Security, risk management & fraud prevention | Technical, Transaction, Identity | Legal obligation / Legitimate use |
| Service-related communications & regulatory notices | Contact, Transaction | Performance of Services |
| Marketing & promotional communications | Contact | Separate opt-in consent |
| Analytics, research & service improvement | Technical, Usage | Consent |
8. Basis of Processing
Under the DPDP Act, we process personal data on one or more of the following bases:
- Consent – where you have given consent through a clear affirmative action for one or more specified purposes
- Certain legitimate uses – as permitted under Section 7 of the DPDP Act, including where you voluntarily provide data for a specified purpose, and for compliance with law
- Legal and regulatory obligations – where processing is necessary to comply with applicable law, including SEBI regulations, AMFI guidelines, the Prevention of Money Laundering Act, 2002, and tax laws
9. Sharing and Disclosure of Personal Data
We share personal data only with the categories of recipients listed below, and only to the extent necessary for the stated purposes and for legal compliance:
- The Distributor – MoneyTrail Securities Private Limited (ARN-190417), to facilitate mutual fund distribution and transactions
- Financial intermediaries – Asset Management Companies (AMCs), Registrar and Transfer Agents (RTAs), stock exchanges, clearing corporations, banks, and payment service providers
- Service providers – cloud and infrastructure providers, technology vendors, KYC and verification providers, customer-support and analytics providers, who act as Data Processors under binding contracts
- Regulatory and government authorities – SEBI, AMFI, the Reserve Bank of India, tax and statutory authorities, courts, and law-enforcement agencies, where required by law
- Corporate transactions – in connection with any merger, acquisition, restructuring, or transfer of business, subject to this Policy and applicable law
Where we engage Data Processors, they are permitted to process personal data only under a valid contract and only in accordance with our instructions and applicable law. We do not sell your personal data to any third party.
10. Cross-Border Transfer
Personal data is ordinarily stored and processed in India. Where personal data is transferred to, or accessed from, a location outside India (for example, by a cloud or service provider), we do so only in accordance with the DPDP Act and subject to any restrictions notified by the Central Government in respect of specified countries or territories.
We also comply with applicable sectoral data-localisation requirements, including the Reserve Bank of India's directions requiring payment-system data to be stored within India.
11. Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, after which it is erased, unless a longer retention period is required under applicable law. Indicative retention periods are set out below.
| Type of Data | Retention Period | Reason |
|---|---|---|
| KYC and transaction records | Minimum 5 years after the end of the relationship or the last transaction | PMLA, 2002; SEBI / AMFI record-keeping |
| Account and profile data | For the duration of your account, and until the purpose is served | Service delivery |
| Communication & grievance records | Typically up to 5 years | Dispute resolution & regulatory record-keeping |
| Technical and security logs | Limited period as required for security and audit | Security & legal compliance |
| Marketing-consent records | Until consent is withdrawn, plus a reasonable evidentiary period | Proof of consent |
Upon withdrawal of consent or completion of the purpose, we will erase your personal data unless retention is required under applicable law, in which case the data will be retained only for the period and purpose required by such law.
12. Data Security
We implement reasonable technical, organisational, and administrative safeguards to protect personal data against unauthorised access, disclosure, loss, misuse, alteration, or destruction. These measures may include:
- Encryption or masking of personal data, and secure storage
- Access controls, authentication mechanisms, and the principle of least privilege
- Logging, monitoring, and periodic security reviews
- Secure infrastructure and reasonable backup arrangements
- Measures to detect, investigate, and respond to security incidents
13. Personal Data Breach
In the event of a personal data breach, we will take steps to mitigate its impact and will intimate each affected Data Principal and the Data Protection Board of India in the manner and within the timelines prescribed under the DPDP Act, including providing the Board with a detailed report within the prescribed period.
14. Your Rights as a Data Principal
Subject to applicable law, you have the following rights in respect of your personal data:
- Right to access – to obtain a summary of the personal data we process and the processing activities, and the identities of recipients with whom it has been shared
- Right to correction and erasure – to request correction, completion, updating, or erasure of your personal data, subject to legal retention requirements
- Right to withdraw consent – to withdraw consent at any time where processing is based on consent
- Right to grievance redressal – to a readily available means of registering a grievance with us (Section 20)
- Right to nominate – to nominate another individual to exercise your rights in the event of your death or incapacity
To exercise any of these rights, please use the privacy settings in the Application or contact our Grievance Officer (Section 20). We will respond within the timelines prescribed under applicable law.
Your duties: As required under the DPDP Act, you agree to provide accurate and complete information, not to impersonate another person, and not to register false or frivolous grievances.
15. How to Delete Your Account and Data
You may request deletion of your account and associated personal data at any time by:
- Using the "Delete Account" option within the Application (Settings → Account → Delete Account)
- Visiting caply.money/delete-account and following the instructions
- Writing to us at grievance@caply.in
On receiving your request, we will delete your personal data unless we are required to retain certain records under applicable law (for example, KYC and transaction records under PMLA and SEBI/AMFI requirements), in which case such records will be retained only for the period and purpose required by law and then erased.
16. Children's Privacy
The Services are intended only for individuals who are 18 years of age or older. We do not knowingly collect or process the personal data of children, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If we become aware that the personal data of a minor has been collected inadvertently, we will take appropriate steps to delete such data.
17. Cookies, SDKs and Analytics
We may use cookies, SDKs, pixels, and similar technologies to authenticate users, improve performance, analyse usage patterns, enhance security, and personalise your experience. You may modify your device or browser settings to restrict certain tracking technologies, subject to limitations in functionality.
18. Third-Party Links
The Application may contain links to third-party websites and services. We are not responsible for the privacy practices, content, or security of such third parties. We encourage you to review their respective privacy policies before providing any personal data.
19. Changes to This Policy
We may update this Policy from time to time. Any changes become effective upon publication on the Application or website, and where the changes are material, we will provide a prominent notice or seek fresh consent where required by law. The "Last Updated" date indicates when the Policy was last revised.
20. Grievance Redressal and Data Protection Contact
For any privacy-related query, request, or complaint, or to exercise your rights, please contact:
Grievance Officer: Sijo Paul E
Email: grievance@caply.in
We will acknowledge and endeavour to resolve your grievance within the timelines prescribed under the DPDP Act. If you are not satisfied with our response, or if your grievance is not resolved within the prescribed period, you may approach the Data Protection Board of India.
Grievances relating to a mutual fund transaction may also be escalated to the concerned AMC and/or RTA, and thereafter to SEBI through the SCORES portal (scores.sebi.gov.in) or the Online Dispute Resolution (ODR) mechanism on the SMART ODR portal (smartodr.in). Grievances relating to the conduct of the Distributor may also be raised with AMFI.
21. Contact Us
CAPLY FINTECH LLP
Registered Office: No. 1130/76/1, 2nd Floor, City Center, Round West, Thrissur, Kerala, India – 680001
Email: grievance@caply.in
Website: caply.money