Privacy Policy

1. Introduction

This Privacy Policy explains how Adlytick, operated by Mr. Aditya Arora (SEBI Registered Research Analyst), collects, processes, stores, and protects your information.

By accessing our website, mobile application, social-media channels, or services, you agree to the practices outlined in this Policy.

We comply with:
1. The SEBI (Research Analyst) Regulations, 2014 and circulars issued there under
BSE/NSE guidelines applicable to Research Analysts.
2. The Information Technology Act, 2000 and SPDI Rules, 2011
3. The Digital Personal Data Protection Act, 2023 (DPDP Act)
4. RBI guidelines and PCI-DSS standards for payment data security


2. Scope

This Policy applies to all users, clients, vendors, and partners (“Users”) interacting with Adlytick services.
It governs the lawful collection, processing, storage, and transfer of personal data strictly for permitted Research Analyst activities, including:
1. Client onboarding and SEBI-compliant KYC verification
2. Distribution of SEBI-compliant research reports
3. 
Subscription-based research services
4. Record-keeping, disclosures, and regulatory reporting

We do not provide portfolio-management or execution-based advisory services.


3. Applicability

This Policy applies to all individuals who:
1. Visit or use Adlytick website, app, or affiliated platforms
2. Subscribe to research services, reports, or communications
3. Interact with our social-media pages or third-party service portals
4. Share personal data for KYC or engagement purposes


4. Information Collected

4.1 Principle of Collection

We collect only data that is relevant, necessary, and lawful under the SEBI RA Regulations, IT Act, SPDI Rules, and DPDP Act.

4.2 Categories of Information

a. Identity Information
1. Full name and date of birth (as per PAN)
2. Masked Aadhaar number (collected with consent)
3. PAN card number and date of birth (KYC verification)
4. Voter ID, Passport, or equivalent document (if submitted voluntarily)
5. Purpose: Identity verification and SEBI-mandated compliance (Reg. 16 & 18).

b. Contact Information
1. Mobile number(s) (including Aadhaar-linked for OTP e-consent)
2. Email address
3. Permanent and correspondence address
4. Purpose: Communication, verification, grievance redressal, and SEBI record-keeping.

c. Demographic Information
1. Date of Birth, Gender, Nationality
2. Purpose: Suitability and legal capacity checks per SEBI Code of Conduct.

d. Statutory KYC Information
1. PAN & DOB (mandatory)
2. KRA/CKYC Identifier (if retrieved via SEBI-registered KRAs)
3. Other KYC documents under SEBI framework
4. 
Purpose: Onboarding and compliance.

e. Technical & Session Data (auto-collected)
1. IP address, device type, OS, browser, timestamp, location metadata, cookies, user-agent string
2. Purpose: Security, IT Act Sec. 43A compliance, fraud prevention.

f. Consent Records & Communication Metadata
1. OTP timestamps, IP logs, digital consent receipts, email delivery status
2. Purpose: Proof of explicit consent under DPDP Act & SEBI rules.

g. Payment Data
1. Transaction ID, payment method, billing info (processed via PCI-DSS-compliant gateways)
2. We do not store card numbers, CVV, or UPI PINs.
3. Purpose: Subscription billing & statutory reporting.

4.3 Cookies & Tracking Technologies

Our website may use cookies, tracking pixels, and analytics tools to enhance user experience, measure performance, and prevent fraud.
Users may disable cookies in their browser settings; however, some features may not function properly.


5. Purpose of Processing

We process data for:
1. SEBI compliance, audit, and record-keeping
2. KYC verification and risk profiling
3. Delivery of research reports and services
4. Fraud prevention and platform security
5. Regulatory and statutory reporting (SEBI, BSE, NSE, RBI)

All records are maintained per Regulation 25 of the SEBI (Research Analyst) Regulations, 2014.


6. Consent & Authorization

By using our services, you provide:
1. Free, specific, and informed consent for collection and processing under the IT Act and DPDP Act.
2. Authorization for Aadhaar-linked e-KYC (OTP-based verification under UIDAI & Aadhaar Act 2016).
3. Consent for regulatory sharing with SEBI, Exchanges, KRAs, or other regulators.
4. 
Legal validity: OTP/digital acceptance constitutes valid consent under law.

6A. Marketing Communication Consent

By subscribing, you consent to receive transactional and informational messages related to your subscriptions or research reports.
Promotional or marketing messages (via email, WhatsApp, or social media) will be sent only with your explicit consent, as per the DPDP Act.
You may opt out at any time by using the unsubscribe option or contacting adlytick@gmail.com.


7. Data Sharing & Disclosure

We may share your data with:
1. SEBI, BSE, NSE, KRAs, RBI (for regulatory compliance)
2. Auditors, consultants, and service providers under confidentiality agreements
3. Law enforcement or courts when legally mandated

We never sell or commercially exploit your data.


8. Payment Data Compliance

1. All payments are processed via PCI-DSS-compliant gateways.
2. We comply with RBI data-localization rules; payment data remains in India.
3. Limited offshore processing (fraud checks or chargebacks) occurs only with safeguards and retention in India.


9. Data Security

We implement reasonable security practices including:
1. SSL/TLS encryption, firewalls, intrusion detection
2. Secure hosting with restricted access
3. Regular audits and vulnerability testing
4. Employee confidentiality obligations


10. Data Breach & Notification

In the event of a data breach:
1. Immediate containment and risk mitigation steps will be taken.
2. Users will be notified within a reasonable timeframe.
3. The Data Protection Board of India will be informed if required.
4. Corrective actions (audits, patches, monitoring) will follow.


10A. Your Rights under the Digital Personal Data Protection Act, 2023

As a Data Principal, you have the right to:
1. Access, review, and request correction or update of your personal data;
2. Withdraw consent for specific processing activities;
3. Request erasure of data no longer required for lawful purposes;
4. Lodge a grievance with our Grievance Officer;
5. Escalate unresolved issues to the Data Protection Board of India.


11. Data Retention
1. Personal/KYC data: Retained for a minimum of 5 years or as mandated by law.
2. Payment records: Retained per RBI and Income Tax requirements.
3. Upon expiry, data is securely deleted, anonymized, or archived.


12. Children’s Data

Services are for individuals 18 years and above. We do not knowingly collect children’s data.


13. Limitation of Liability

We are not liable for losses arising from unauthorized access, breaches, cyber-attacks, third-party API errors, or service outages.
Services are provided on an “as is” basis.


14. Third-Party Services, SaaS Platforms & Integrations

Our website, mobile app, and digital channels may use third-party or SaaS providers (e.g., analytics, hosting, marketing, email, CRM).
These providers operate under their own privacy policies. We ensure they:
1. Process data only under our instructions;
2. Comply with Indian data protection laws; and
3. Maintain security and confidentiality.
4. Users are encouraged to review the privacy policies of those services.


14A. Social Media Interactions

We maintain official pages and handles on platforms such as LinkedIn, X (Twitter), YouTube, and Instagram to share research insights.
Any personal data shared via these channels (e.g., comments, messages) will be handled per this Policy.
However, these platforms have their own privacy practices beyond our control.


15. Indemnification

You agree to indemnify and hold harmless Mr. Aditya Arora / Adlytick from any claims or damages arising from misuse of data, breach of this Policy, or violation of law.


16. Cross-Border Data Transfer

Certain third-party service providers (e.g., cloud hosting, email or analytics tools) may process data outside India.
Such transfers occur only when necessary for legitimate business purposes and under adequate technical and contractual safeguards as per the DPDP Act, 2023 and RBI data-localization rules.


17. Grievance Officer

In compliance with Rule 5(9) of the IT Rules, 2011:

Name: Mr. Aditya Arora
Designation: Compliance & Grievance Officer
Mobile: +91 7434000132
Email: adlytick@gmail.com
Address: Office 616, Sixth Floor, Zion Z1, Nr. Avalon Hotel, Off Sindhu Bhavan Road, Bodakdev, Ahmedabad, Gujarat - 380054


18. Updates & Amendments

This Policy may be updated periodically. Updated versions will carry a revised “Last Updated” date, and significant changes will be communicated via our website or email.


19. Governing Law & Jurisdiction

This Policy is governed by the laws of India.
Courts at Ahmedabad, Gujarat shall have exclusive jurisdiction over any disputes.