Privacy Policy

INTRODUCTION

This document is an electronic record in terms of the Indian Contract Act, 1872, the Information Technology Act, 2000 and rules thereunder as applicable and the amended provisions pertaining to electronic records in various statutes as amended by the Information Technology Act, 2000. This electronic record is generated by a computer system and does not require any physical or digital signatures. By clicking on the ‘Proceed’ button, you agree and acknowledge that you have read, understood, and agree to be legally bound by this Privacy Policy, which is to be read with the Terms of Use at https://www.famlilife.com/terms-of-use/.This action signifies your free, specific, informed, unconditional, and unambiguous consent for the collection, processing, transfer, use, storage, disclosure, and sharing of your personal data as described herein for the purposes outlined in below clause 3.

Thank you for choosing to be part of our community at Famli Technology Products Private Limited (“Famli,” “we,” “our,” or “us”). When you visit the website domain at www.famlilife.com or any application and/or interface for mobile and handheld devices that Famli may own and operate in the future (referred to collectively as the “Famli Platform” or “Platform”) and access, visit or use any products, and services provided by us (“Services”), we may collect personal information from you. Our team is committed to protecting your personal information and your right to privacy in accordance with applicable laws. The term “User”, “client” or “you” refers to the users of Famli Platform or the Services on the Platform.

In this privacy policy (“Privacy Policy”), we seek to explain to you (i) what information we collect; (ii) how we use it; (iii) your rights in relation to it; and (iv) security processes maintained by us in relation to the same. This Privacy Policy applies to all information collected through our Services (which, as described above, includes our Platform), as well as any related services, sales, or events. This Privacy Policy constitutes a legal agreement between you, as a User of the Services and/or the Platform, and Famli, and this Privacy Policy shall be enforceable against you.

Please carefully go through this Privacy Policy prior to accessing the Platform or availing Services using the Platform or submitting any personal information on the Platform. If a User continues to browse and use the Platform and/or avail Services, the User irrevocably and unconditionally is agreeing to comply with, abide by and be bound by all the obligations as stipulated in this Privacy Policy, read with our Terms available at https://www.famlilife.com/terms-of-use/ and any other applicable policies referred to herein or made available on the Platform. You agree and consent to the collection, transfer, use, storage, disclosure and sharing of your information as described and collected by us in accordance with this Privacy Policy.

You represent and warrant that you have the right, authority and capacity to enter into this Privacy Policy (on behalf of yourself and/or, as applicable, the entity that you represent) and that the consent so given constitutes free, specific, informed, unconditional and unambiguous consent for the purpose of applicable law. If the individual entering into this Privacy Policy or otherwise accessing or using the Platform or Services is doing so on behalf of, or within his or her capacity as a representative, agent or employee of an entity, such individual and such entity agree that you represent and warrant that the individual entering into this Privacy Policy has the power, right, authority, and capacity to enter into this Privacy Policy on behalf of such entity. If you do not agree to be bound by this Privacy Policy or if you are an individual under the age of 18 (eighteen) or your access to or use of the Platform or the Services is illegal or prohibited under applicable law, you may not access or use the Platform or the Services. IF YOU DO NOT AGREE TO BE BOUND BY THIS PRIVACY POLICY, PLEASE DO NOT USE THE PLATFORM OR SERVICES.

INFORMATION WE COLLECT

We collect personal information that you voluntarily provide to us when you register on the Platform, express an interest in obtaining information about us or our Services, when you participate in activities on the Platform or otherwise when you contact us.

The personal information that we collect depends on the context of your interactions with us and the Platform, the choices you make and the products and features you use. The personal information we collect may include the following:

CATEGORY OF PERSONAL INFORMATION COLLECTEDSPECIFIC ITEMS OF PERSONAL DATA
Personal information voluntarily provided by you
Registration InformationDetails such as the following:
• Your name
• Details of family members (names, age, contact details),
• Nationality,
• Contact details,
• Email address,
• Gender,
• Date of birth,
• Age,
• Marital status,
• Organization name,
• Organization email id,
• Demographic information (addresses, pin code),
• PAN,
• Aadhar number,
• Passport details,
• Driving license details,
• Voter id,
• Other government issued identification numbers,
• Photo identity,
• Biometric data (fingerprints, facial recognition data),
• Business and employment related information (employer details, designation, income information, employment records).
ContentDetails such as:
• Name,
• Contact details,
• Address
• Email address,
• Demographic information,
• Social media information about any individual identified by you in relation to the services,
• Emails in your inbox.
SMS Data Access and ProcessingSMS for the purposes of fetching the one-time password
Other information (Voluntarily provided)Data from
• Forms,
• Survey responses,
• Promotion participation,
• Communications with support team,
• Address book contacts,
• Emails.
• Data for determining risk profile
Information we collect from you automatically
Log Data & Technical InformationData from:
• Internet protocol (IP) address,
• Device or browser type,
• Internet service provider (isp),
• Referring or exit pages,
• Clickstream data,
• Operating system,
• Hardware model,
• Operating system version,
• System log,
• Network log,
• Security log,
• Performance logs,
• Performance logs,
• Event logs,
• Unique device identifiers,
• Usage information,
• User statistics,
• Mobile network.
Device Access and PermissionsData from:
• Device camera access,
• Device microphone access,
• Device’s biometric features (fingerprint, facial-recognition sensors),
• Device information (storage capacity, device model, mobile network information, device type, IP address),
• Precise and/or coarse location data, and
• Device unique identifiers
Geological Information• Data from precise or approximate location (from IP address, GPS, or shared information)
Usage Data and InferencesData from:
• User activity data, analytics event data, viewing patterns of documents, clickstream data.
Information we collect through Cookies
Information through Cookies• Small text files (cookies), device identifiers, SDK-based analytics tools, local device storage.
Information we require for the providing the Services
Financial Goals• Data from your financial goals
Demat Account Statements• Demat account statements.
Bank Account Details and Transaction History• Details and transaction history from savings, current, recurring deposit, and fixed deposit accounts
Portfolio Holdings and Transaction Records• Portfolio holdings, transaction records, and statements from demat accounts, mutual funds, equities, ETFs, EPF, NPS and other securities.
Insurance Policies• Insurance policies and related premium, claim or coverage information.
Credit Information• Credit information, credit scores or credit ratings issued by credit-information companies.
• Details of home loans, car loans, personal loans, credit cards and any other liabilities
Real-Estate Assets• Details of real-estate assets and related documents.
Precious Metals Holdings• Holdings in precious metals such as gold, silver and other similar commodities.
Crypto or other Digital Assets• Information on crypto or other digital assets.
Other non-traditional assets• Details of other non-traditional or alternative assets including art, private investments in securities or otherwise, investment in and involvement with start-ups, and other financial information
Information we receive from third-parties
Third-party platforms• Information from third-party platforms used to register or log into the Service, data from linked accounts.
Data Through Account Aggregators• Bank Account Data (details and transaction history), investment information (portfolio holdings, stock holdings, transaction records, statements from demat accounts, mutual funds, ETFs), provident and pension fund data (balances, transactional information from PPF, EPF, NPS accounts), insurance data (policy details, premium history, transaction history), other financial information (pension fund information, GST linked data).
• Data linked to PAN
Credit Information and User Uploaded Financial Data• Credit reports, credit scores, loan histories, repayment patterns, and related financial data from licensed credit information companies (e.g., TransUnion CIBIL, Experian). User Uploaded-Financial Data (bank statements, credit card statements, demat account statements, transaction confirmations, payment receipts, other financial correspondence or records).

All of the above referred to as “Information”.

PURPOSE OF COLLECTING INFORMATION

1. Unless otherwise instructed by you, we use the Information for a variety of business purposes described below. We process the Information for these purposes, in reliance on our legitimate business interests, in order to enter into or perform a contract with you, with your consent, and/or for compliance with our legal obligations. Further, the information provided to us and processed by us is likely to be (a) used to
make a decision that affects you; or (b) disclosed to another data fiduciary, we shall process such information such that it ensures its completeness, accuracy, and consistency.

2. We use the Information which we collect or receive:

(i) To provide the Services: We may use the Information for providing Services to all Users, including, without limitation in the following manner: (i) use the Information to conduct certain tests on open source programmes; (ii) analyse your financial position to provide effective investment advisory services; (iii) organize the data and content provided by you and facilitate usage of such content between team members; (iv) analyse your usage of the Services; (v) share Information with artificial intelligence platforms for the purpose of generating analysis and providing the Services, and, for the avoidance of doubt, your Information shall not be used by such artificial intelligence platforms for training their models, and

(ii) shall be used solely for the provision of Services to you, subject to appropriate contractual safeguards and data minimization to ensure secure and limited use of your Information]; (vi) draft emails to share with potential targets and analyse emails to understand usage of the Services; (vii) studying your use of the Services to improve our services; (viii) communicate with our team and train our team; (ix) use the Information to provide Services to other Users and share it with third parties in relation to provision of Services, only to the extent required; (x) share Information with third party service providers, vendors, account aggregators, technology partners, and other business associates as required for the provision of Services and compliance with the applicable regulatory requirements; and (xi) other purposes ancillary to the Services provided by us.

(iii) For KYC Compliance and Regulatory Requirements: We may use the Information to conduct Know Your Customer (KYC) compliance processes as a mandatory prerequisite in accordance with SEBI guidelines and other applicable regulatory authorities for investment advisory services. This includes validation, verification, processing, and sharing of your KYC details, identity Information, nominee details, and beneficiary information with mutual fund houses, depository participants, account aggregators, or other service providers as may be required for compliance with applicable laws and for the provision of the Services through the Platform.

(iv) Risk Profiling and Suitability Assessment: We use the Information you provide to perform risk profiling and suitability assessments for investment advice. This Information includes the following: (i) age; (ii) investment objectives (including intended investment period and purpose); (iii) income details; (iv) existing investments/assets; (v) risk appetite/tolerance; and (vi) liabilities/borrowings. We assess both your willingness and ability to take risk by

(a) evaluating your capacity to absorb loss, (b) identifying if you are unwilling or unable to accept potential loss of capital, and (c) appropriately interpreting your responses without attributing inappropriate weight to any single answer. Where we use questionnaires or other tools, we ensure they are fit for purpose and, that any limitations are identified and mitigated; all questions and descriptions are designed to be fair, clear and not misleading, avoiding vagueness, double negatives, complex language, and leading questions. We communicate your risk profile to you after the assessment and periodically update both the Information and the assessment to keep our advice appropriate.

(a) To manage User accounts: We may use the Information for the purposes of managing your account and keeping it in working order.

(b) To request feedback: We may use the Information to request feedback and to contact you about your use of our Platform.

(c) To protect the Platform: We may use the Information as part of our efforts to keep our Platform safe and secure (for example, for fraud monitoring and prevention).

(d) To send administrative information to you: We may use the Information to send you product, administrative notices, alerts, advisories, and communications relevant to your use of the Services, including important notices regarding policy changes, terms and conditions updates, service modifications, and Platform administration.

(e) To post testimonials: If you authorize us to post testimonials about our Services, we may post your name and such other personal information that you permit us to post. We will provide you with an opportunity to review the testimonial before posting it on our website. If you wish to amend or delete the testimonial containing your personal data, you may reach out to support@famlilife.com with the subject line as “Testimonial”

(f) For other business purposes: We may use the Information for other business purposes, such as data analysis, customize the content and features of the Platform, request reviews of our Services, identifying usage trends, determining the effectiveness of our promotional campaigns and to evaluate and improve our Platform, products, marketing and your experience.

(g) Anonymized Data: We may aggregate Information and analyse it in a manner to further accentuate the level of Services that we offer to our Users. This Information includes average number of Users of the Platform, the average clicks of the services, the features used, the response rate, etc. and other such statistics regarding groups or individuals.

(h) For legal requirements: To comply with legal and regulatory requirements including disclosing the information to the government as per the applicable laws or in connection with our contract.

All of the above, “Purposes”.

SHARING OF YOUR INFORMATION

We may share the Information with the following persons for the following purposes:

1. External Partners and Service Providers: We may disclose the Information to third-party vendors, consultants, and service providers entrusted to carry out tasks or to aid Famli, including website analytics companies and artificial intelligence providers (specifically Anthropic for natural language processing and Perplexity for web search functionality), for the purpose of providing Services. We ensure that no Personally Identifiable Information (PII) is shared with these AI providers, and your data is processed through private enterprise connections that are strictly not used for training third party AI models. Transaction data is exclusively shared with our payment service providers to facilitate payments, process refunds, and address concerns or questions related to such transactions.

2. Communication: To send you service-related updates, security alerts, support responses, and, where you have opted in, information about new features or offers whether through Platform or third party service provider.

3. Revealing Information for National Security and Law Enforcement: We may need to reveal the Information in response to requests from public authorities, either due to our legitimate interest or legal obligation. There are instances where personal information may be disclosed without seeking your permission, including but not limited to the following reasons:

(i) Adherence to legal or regulatory obligations;
(ii) To comply with any written request, direction, or order issued by any authority or person authorised under law;
(iii) In the interest of prevention, detection, investigation, or prosecution of offences or cyber incidents, or for the imposition or enforcement of penalties or punishment;

(i) Adherence to legal or regulatory obligations;

(ii) To comply with any written request, direction, or order issued by any authority or person authorised under law;

(iii) In the interest of prevention, detection, investigation, or prosecution of offences or cyber incidents, or for the imposition or enforcement of penalties or punishment;

(iv) For the enforcement of legal rights or claims, including in connection with legal or regulatory proceedings;

(v) Ascertaining financial information, assets, or liabilities of any person who has defaulted in payment of amounts due in respect of a loan or advance taken from a financial institution, subject to compliance with applicable laws governing disclosure of information;

(vi) Disclosure for reasons of national security; or

(vii) Compliance with legitimate interests or legal obligations;

Furthermore, in such cases, we may be prohibited from notifying you about the disclosure of your personal data if it is deemed to prejudicially affect the sovereignty and integrity of India or the security of the State.

4. Disclosure to SEBI and its Intermediaries: You acknowledge that SEBI or other regulatory authorities may, at their discretion, inspect or call for client records, and we as an investment adviser may be required to disclose such information without prior notice. You further consent that, in the course of providing advisory services, the Investment Adviser may share client data with custodians, brokers, research analysts, technology service providers, or other regulated intermediaries, as may be necessary or required under applicable law.

5. Sharing with Affiliates: Subject to the applicable law, we may share the Information with our affiliates, in which case we will require those affiliates to honour this Privacy Policy. Affiliates include our parent company and any subsidiaries, joint venture partners or other companies that we will control or that are or will be under common control with us.

6. Business Transfers: If Famli engages in any transaction that alters the business structure of Famli such as merger, acquisition, reorganization, or joint venture, we may process the Information for facilitating and concluding such transaction, and disclose the Information to the entity that acquires, or merges or engages in joint venture with Famli in which case the resultant entity will be bound by this Privacy Policy.

7. Other Purposes: In addition to the above, we may share your personal data where necessary (i) to respond to a medical emergency involving a threat to your life or an immediate threat to your health or the life or health of any other individual, (ii) to take measures to provide medical treatment or health services during an epidemic, outbreak of disease, or any other threat to public health, (iii) and to take measures to ensure the safety of, or provide assistance or services to, any individual during a disaster or any breakdown of public order.

COOKIES AND OTHER TRACKING TECHNOLOGIES

1. Cookies and Web Beacons

For Web-Based Access: We may use cookies, web beacons, tracking pixels, and other tracking technologies on the Platform to help customize the Platform and improve your experience. Most browsers are set to accept cookies by default. You can remove or reject cookies but be aware that such action could affect the availability and functionality of the Platform. You may not decline web beacons. However, they can be rendered ineffective by declining all cookies or by modifying your web browser’s settings to notify you each time a cookie is tendered, permitting you to accept or decline cookies on an individual basis. Certain features may also rely on your browser settings or permissions related to cookies or local storage if you use our web application.

For Mobile Applications: For mobile applications on iOS and Android, we may use device identifiers, SDK-based analytics tools (such as Mixpanel, AppsFlyer, or Firebase), and local device storage to monitor app usage, collect crash logs, and analyze engagement patterns. These technologies help us enhance your experience, monitor app performance, and offer personalized content.

You may exercise control over or disable certain tracking mechanisms through your device settings, including but not limited to “Limit Ad Tracking” functionalities on iOS devices or “opt out of Ads Personalization” settings on Android devices). Please note that disabling such settings may affect the performance or functionality of the Platform.

For more details or to manage your preferences, please refer to your browser or device privacy settings.

2. Website Analytics

We may also partner with selected third-party vendors to allow tracking technologies and remarketing services on the Platform through the use of first party cookies and third- party cookies, to, among other things, analyse and track Users’ use of the Platform, determine the popularity of certain content and better understand online activity.

SECURITY OF YOUR INFORMATION

1. We review the Information collection, storage, and processing practices, including physical security measures to guard against any unauthorized access to systems. These measures include, but are not limited to, encryption, obfuscation, masking, and the use of virtual tokens mapped to personal data, as well as appropriate measures to control access to the computer resources used by Famli or any data processor engaged by us. However, as effective as these measures are, no security system is impenetrable. We cannot guarantee the security of our database, nor can we guarantee that the Information will not be intercepted while being transmitted to us over the internet. You accept the inherent security implications of data transmission over the internet and the internet cannot always be guaranteed as completely secure. Therefore, your use of the Platform will be at your own risk.

2. Technical Security Measures: The Platform utilizes reliable and strong encryption mechanism such as TLS (Transport Layer Security, also referred to as SSL) certificates to secure transmission of your Information, particularly financial and payment data. We maintain secure hosting infrastructure with continuous monitoring, access controls, and authentication mechanisms on the computer, computer system, computer network, computer data base or software to prevent unauthorized access and misuse of your Information.

3. Continued Processing and Data Backups: The Platform ensures to take reasonable measures for continued processing through data backups in case of any compromise to confidentiality, integrity or availability of personal data.

4. Employee and Receiver’s Obligations: We have put in place procedures and technologies as per good industry practices and in accordance with the applicable laws, to maintain security of all personal data and information from the point of collection to the point of destruction. Our employees and third-party who have access to your Information are bound by strict confidentiality obligations and contractual requirements to respect the privacy and security of your personal and financial data, however, this is carried out strictly on a need-to-know basis for provision of the Services. Any third-party receiving and processing your Information must comply with our security procedures or maintain equivalent protective
measures. We ensure that our contracts with data processors engaged by us who are categorised as data processor include adequate safeguards to ensure their compliance with our security standards and applicable data protection laws. However, we are not responsible for confidentiality breaches by partners and third parties outside the scope of our agreements with such entities.

5. User Security Responsibilities: You are responsible for maintaining the confidentiality of your login credentials, MPIN, OTP, and account access information. We do not undertake liability for unauthorized use of your account due to compromised credentials. You must immediately notify us at support@famlilife.com if you suspect any unauthorized access to your account and shall indemnify us for any losses arising from such unauthorized use.

6. Security Breach Notification: In case of any security breach leading to breach of personal data such unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction or loss of access to personal data, that compromises the confidentiality, integrity or availability of personal data, or affecting your Information in any manner, we shall make all legally required disclosures to you via email, SMS or Platform notification (through your registered user account) without unreasonable delay, consistent with law enforcement requirements and measures necessary to determine breach scope and safeguard data integrity. Such notification will include the nature of the breach, its extent, timing, location, possible consequences, mitigation measures taken by us, and steps you can take to protect yourself. Further, up on becoming aware of any such data breach, we shall, in the manner specified and without unreasonable delay, make the required intimations to the relevant jurisdiction governmental authority including Data Protection Board of India (when constituted) as required under the applicable data protection laws.

7. Security during Cross Border Transfer: We shall ensure that any data that we transfer outside the territory of India will meet the requirements in accordance with the applicable law, in respect of making such personal data available to any foreign State, or to any person or entity under the control of or any agency of such a State. We will ensure compliance with any such specified requirements before initiating any cross-border transfer of personal data.

8. You hereby acknowledge that Famli is not responsible for any information sent via the internet that has been intercepted beyond our control after having adopted reasonable security practices and procedures, and you hereby release us from any and all claims arising out of or related to the use of intercepted information in any unauthorized manner.

LINKS TO THIRD PARTY

The links to third-party advertisements, third-party websites or any third-party electronic communication services or licensed payment platforms’ (referred to as “Third-Party Links”) may be provided on the Platform which are operated by third parties and are not controlled by, or affiliated to, or associated with Famli, unless expressly specified on the Platform. If you access any such Third-Party Links, we request you to review the concerned website’s privacy policy. We shall not be responsible for the policies or practices of such third parties.

CHILDREN’S PRIVACY

We do not knowingly solicit data from children under 18 (eighteen) years of age. Before processing any personal data relating to a child, we shall obtain verifiable consent from the child’s parent or lawful guardian.
Such verification may be carried out by referring to reliable details of identity and age already available with Famli, or to identity and age details voluntarily provided by the individual. These details may be submitted directly by the individual or made available through a virtual token mapped to such identity and age information, issued by an authorised entity in accordance with law. The authorised entity referred to in this section shall be (i) an entity entrusted by law or by the Central Government, or (ii) by the relevant State Government with the issuance of details of the identity and age or a virtual token mapped to such details or a person appointed or permitted by the entity specified under paragraph (i), for such issuance, and also includes details of identity and age or token made available and verified by a Digital Locker Service Provider, as such recognised under Information Technology Act, 2000.

By using the Platform and Services, you represent that you are at least 18 (eighteen) years of age or that you are the parent or guardian of such a minor and consent to such minor dependent’s use of the Platform. If we learn that personal information from Users less than 18 (eighteen) years of age has been collected, we will deactivate the Services and take reasonable measures to promptly delete such data from our records. However, in any case we shall not undertake such processing of personal data of a child that is likely to cause any detrimental effect on the well-being of such child or undertake tracking or behavioural monitoring of children or targeted advertising directed at children. If you become aware of any data that we may have collected from children under age 18 (eighteen), please contact us at support@famlilife.com and request the deletion of that child’s Information from our systems.

PRIVACY OF PERSONS WITH DISABILITY WHO HAS LAWFUL GUARDIAN

Before processing any personal data relating to a person with disability, we require verifiable consent from an individual identifying herself as the lawful guardian of such person. Such verification will be carried out with due diligence to ensure that the guardian is appointed by:

(i) a court of law, or

(ii) a designated authority as per the Rights of Persons with Disabilities Act, 2016, or

(iii) a local level committee as constituted under the National Trust for the Welfare of Persons with Autism, Cerebral Palsy, Mental Retardation and Multiple Disabilities Act, 1999.

As we do not currently automate this verification, it is performed manually. If you are a lawful guardian seeking to provide consent or manage the account of a person with a disability, please contact us at support@famlilife.com. We will guide you through the submission of necessary identification and guardianship records.

If we learn that personal data from Users with disability who has lawful guardian has been collected or processed without obtaining verifiable consent from the lawful guardian, we will deactivate the Services and promptly delete such personal data from our records in compliance with the applicable data protection laws. If you become aware of any data that we may have collected from a person with disability who has a lawful guardian, without verifiable guardian consent, please contact us at support@famlilife.com and request the deletion of such persons Information from our systems.

For the purposes of this section of Privacy Policy, a person with disability means (i) an individual who has long term physical, mental, intellectual or sensory impairment which, in interaction with barriers, hinders her full and effective participation in society equally with others and who, despite being provided adequate and appropriate support, is unable to take legally binding decisions; and (ii) an individual who is suffering from any of the conditions relating to autism, cerebral palsy, mental retardation or a combination of any two or more of such conditions and includes an individual suffering from severe multiple disability and who,
despite being provided adequate and appropriate support, is unable to take legally binding decisions.

DATA RETENTION

In case you request for deletion of your Information or cease to use our Services, we may retain such portion of Information for a period as may be permitted/ required under applicable law and notwithstanding anything contained herein, including in, but not limited to, aggregated and / or anonymized form; or we may retain such data after account deletion / closure for reasons including but not limited to the following purposes:

(i) if there is an unresolved issue relating to your account, or an unresolved claim or dispute;

(ii) if we are required to by applicable law; or

(iii) if necessary for its legitimate business interests, such as fraud prevention and enhancing Users’ safety and security.

We will erase personal data once the specified purpose is no longer being served or you do not exercise your right in relation to data processing, unless its retention is required to comply with applicable law.

Further, at least 48 (forty-eight) hours prior to such erasure, we will notify you that the personal data will be deleted unless you log into your account or reach out to us for the performance of the specified purpose or exercise your rights in relation to the processing.

Without prejudice other provisions of this section, we will retain personal data processed by us, as well as associated traffic data and processing logs, for a minimum period of 1 (one) year from the date of such processing even if you delete your account on the Platform. After completion of this mandatory retention period, we will erase such personal data and logs unless a longer retention period is required to comply with applicable law or any Government direction.

YOUR RIGHTS

Subject to the applicable law, you or your lawful nominee have the following rights regarding your Information collected and processed by us in connection with the Platform and Services:

1. Right of access: You have the right to access any Information that we process about you and to request:

(i) information about the categories of your personal data that we process and the processing activities we carry out on such data;

(ii) the identities of all other third party with whom we have shared your personal data (including the categories of personal data so shared); and

(iii) any other information relevant to your personal data as required under the applicable data protection law.

2. Right to rectification and update: If you believe that we hold any incomplete or inaccurate data about you, you have the right to ask us to correct and/or complete the Information. Further, you may also update your information which may or may not be available with us.

3. Right to deletion: You also have the right to request deletion of your Information, however, please note that in such case, Famli may not be able to provide the Services to you, subject to our legal and
regulatory obligations to retain certain financial and compliance records under applicable laws.

4. Right to object and/or restrict: You have the right to object / restrict the processing of your Information by utilizing the opt-out mechanisms that we provide to you, in which case all or certain Services may not be available to you.

5. Right to redress your grievances: You have the right to redress your grievances by reaching out to our Grievance Officer (details are available below).

6. Right to withdraw your consent: If you do not agree with this Privacy Policy, you may refuse or withdraw your consent any time or alternatively choose to not provide us with any Information. Under such circumstance, we may be unable to render Services. An intimation to withdraw your consent can be sent to support@famlilife.com with the subject line as “Withdrawal of Consent”. Such request for withdrawal of consent must be sent from the User’s registered email address.

7. Right to appoint a nominee: You have the right to appoint a nominee to exercise the rights on your behalf in the event of your death or incapacity to exercise your rights.

8. Right to Information and Grievance: You have the right to obtain information regarding whether your Information is transferred to third parties, or account aggregators, and the safeguards applicable to such transfers. You may also file complaints with appropriate supervisory authorities regarding our data processing practices.

9. If we receive a request from you to exercise any of the above rights, we may ask you to verify your identity before acting on the request. This is to ensure that your data is protected and kept secure. We will handle your requests related to the exercise of your rights within 30 (thirty) days upon the receipt of your request. You may reach out to support@famlilife.com and/or co@famlilife.com for the exercise of these rights. Further, in case you wish to nominate a person on your behalf to exercise these rights, please reach out to us on aforesaid email address and we shall guide your through the process of nomination and help completing the same seamlessly.

PASSWORD SECURITY

1. You agree and warrant that you shall:

(i) Comply with the provisions of all applicable laws while exercising your rights under this Privacy Policy or any relevant data protection legislation.

(ii) Not impersonate any other person while providing your personal data for any purpose.

(iii) Not suppress any material information while providing your personal data, particularly where it is required for any document, unique identifier, or proof of identity or address.

(iv) Not register a false or frivolous grievance or complaint with Famli or the Data Protection Board of India.

(v) Furnish only such information as is verifiably authentic when exercising your right to the correction or erasure of your personal data.

Further, you acknowledge that any failure to comply with these duties may result in consequences as prescribed under applicable law.

2. When you register as a member or login to the Platform, authentication is completed through your registered mobile number using a one-time password (“OTP”) and/or the biometric credentials stored on your device; we do not presently require you to create a or maintain separate password for the Platform. You are solely responsible for securing your device, safeguarding access to your SIM card, and keeping each OTP confidential. You must not share OTPs or allow any third party to register their biometrics on your device if that device is used to access your account on the Platform. Any voluntary disclosure of an OTP or biometric access to a third party will be deemed authorised by you, and you will remain responsible for all activities and charges that may arise from such access. Any compromise of your device, SIM card or biometric credentials may result in loss of control over your account and personal information, as well as legally binding actions carried out on your behalf. If you believe your credentials or device has been compromised, you should immediately notify us, through the registered email address, at support@famlilife.com without delay if unauthorized use persists.

CHANGES & UPDATES TO PRIVACY POLICY

3. This Privacy Policy may be amended by Famli in its sole discretion at any time. When any change is made to this Privacy Policy, Famli will make the copy of the amended Privacy Policy available on the Platform and Services and by clicking on the ‘I Accept’ button with respect to the amended Privacy Policy, you consent to and agree to be legally bound by such amended Privacy Policy. Your continued use of the Services constitutes your acceptance of such change(s). If you do not agree to any change(s) after receiving a notice of such change(s), you may not be permitted to continue using the Services.

4. Further, we retain the right at any time to deny or suspend access to all, or any part of, the Service to anyone who we reasonably believe has violated any provision of this Privacy Policy.

GRIEVANCE REDRESSAL MECHANISM

5. We only process your Information in compliance with this Privacy Policy and in accordance with the relevant data protection laws. If, however, you wish to raise a complaint regarding the processing of your Information or are unsatisfied with how we have handled your Information, you have the right to lodge a complaint with us at co@famlilife.com

6. In case of any discrepancy or grievance with respect to all or any Information shared with Famli, please feel free to contact our Grievance Officer:

Attention: Compliance Officer
Email ID: co@famlilife.com; and
Address: 507, Orville Business Port, Viman Nagar, Pune 411014.

We commit to responding to all grievances within 90 (ninety) days of receipt.

7. We assure you that we shall ensure implementation of the Privacy Policy and shall make the Privacy Policy available to individuals and put our best efforts to redress the grievances of the User expeditiously within the timelines prescribed under applicable laws, specifically within 90 (ninety) days for all grievances. The User agrees and acknowledges that Famli shall address and attempt to resolve the complaint received in accordance with the standard policies and procedures adopted by Famli.

8. Please feel free to reach out to us by e-mail at support@famlilife.com in case of any concerns,
grievances, or questions relating to our privacy or data related practices including the in respect of how we process your data.