Legal
Privacy Policy
How we collect, use and protect the information you share with Carnelian Mutual Fund — in plain terms, not just legal ones.
Privacy Policy
VERSION 1.0 – DATED APRIL 29, 2026
1. BACKGROUND AND PURPOSE
Carnelian Investment Managers Private Limited (hereinafter “the AMC”, “we”, “us”, or “our”) is committed to protecting the privacy of investors, prospective investors, distributors, website and mobile application users and other individuals who interact with the AMC (“Provider(s) of Information”, “you”, “your”). This Privacy Policy explains how we collect, use, store, disclose and protect personal data and is aligned with the Digital Personal Data Protection Act, 2023 (DPDP Act), the DPDP Rules, 2025, SEBI (Mutual Funds) Regulations, 1996, PMLA and related rules and SEBI’s Cybersecurity and Cyber Resilience Framework.
2. SCOPE AND APPLICABILITY
This Policy applies to personal data collected through our application forms, website, mobile applications, investor service centres, call centres and any other channels through which individuals interact with the AMC. By accepting the terms and conditions of our website, mobile application, or by providing information through physical forms, you expressly acknowledge that you have read and understood this Privacy Policy and consent to the processing of your personal information as described herein.
3. DEFINITIONS
- Personal Information / Personal Data: Any information that relates to an identified or identifiable natural person, including information that, alone or in combination with other information, can identify you.
- Sensitive Personal Data: Includes biometric data, financial information and other categories as defined under applicable laws.
- Data Principal: The individual whose personal data is processed.
- Data Fiduciary / AMC: The entity that determines the purpose and means of processing personal data.
4. CATEGORIES OF PERSONAL INFORMATION COLLECTED
We collect only such personal information as is necessary for the purposes described in this Policy. Categories include:
- Identity & KYC: Full name, date of birth, PAN, Aadhaar (if provided), photograph, signature.
- Contact Details: Residential/correspondence address, email ID, mobile number.
- Financial Information: Bank account details, income range, net worth, investment details.
- Biometric Data: Facial images, fingerprints, iris scans, or other physiological/behavioural identifiers where required and permitted by law.
- Tax & Regulatory: FATCA/CRS declarations, TIN, country of tax residency, NRI/foreign status.
- Nominee Details: Nominee name, relationship, date of birth, contact details.
- Transaction Data: Purchase, redemption, switch, SIP/SWP/STP instructions, folio details.
- Digital Identifiers: IP address, device ID, login credentials, cookies.
- Correspondence: Complaints, queries, grievance records, call recordings (with consent where required).
- Other data: Any other data required under Rule 3 of the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, or other applicable laws.
Information that is freely available in the public domain is not treated as Personal Information under this Policy.
5. SOURCES OF COLLECTION
We collect personal information from the following sources:
- Directly from you via application forms (online or offline), account opening forms, investor service centres and mobile applications.
- Call recordings and interactions with our call centres (subject to applicable consent).
- Third-party distributors, registrars and transfer agents (RTAs), payment processors, custodians, depositories and other service providers.
- KYC Registration Agencies (KRAs) and other regulatory or statutory databases.
- Website and mobile application interactions, cookies and analytics tools.
- Publicly available sources and other third parties where permitted by law.
6. PURPOSES AND LEGAL BASIS FOR PROCESSING
We process personal information for the following purposes and on the legal bases indicated:
- Investor onboarding & account creation: Consent; regulatory obligation under SEBI (Mutual Funds) Regulations.
- KYC verification & due diligence: Legal obligation / legitimate use under PMLA and SEBI KYC requirements.
- Transaction processing & account servicing: Legitimate use to provide services you have requested.
- Regulatory reporting: Legal obligation to SEBI, Income Tax authorities, FIU-IND and other statutory bodies.
- FATCA / CRS reporting: Legal obligation under tax laws and international agreements.
- Grievance redressal & dispute resolution: Legitimate use / consent.
- Fraud detection, risk management & compliance: Legitimate use.
- Marketing & promotional communications: Consent (explicit opt-in).
- Analytics, service improvement & anonymised reporting: Legitimate use; aggregated statistics shared with affiliates and service providers will not identify individuals.
- Any other purpose required to comply with applicable laws or to protect the AMC’s legal rights.
We will notify you if we intend to use your personal information for any purpose not listed above and obtain consent where required.
7. ACCEPTANCE AND CONSENT
By using our website, mobile application, or by submitting information through physical forms, you expressly agree and acknowledge that you have read this Privacy Policy and consent to the collection, processing, retention and transfer of your personal information for the purposes described herein. Consent may be withdrawn as described in Section 9.
8. CORRECTION, ACCURACY AND DATA QUALITY
We shall take reasonable steps to ensure that personal information collected and processed by us is accurate, complete and not misleading. If, in your opinion, any information collected by the AMC is distorted, mutilated, inaccurate or incomplete, you may request in writing that such information be modified or corrected. Upon receipt of such request, the AMC will, on a best-efforts basis, correct the personal information within 30 (thirty) days and will inform you of the correction.
9. WITHDRAWAL OF CONSENT
You may withdraw consent for consent-based processing at any time by submitting a written request to our Customer Service Department. Upon receipt of such request, the AMC will, on a best-efforts basis, cease further disclosure and use of the personal information within 30 (thirty) days. Withdrawal of consent will not affect the lawfulness of processing carried out prior to withdrawal.
Important: Withdrawal of consent for processing necessary for onboarding or core account servicing may result in the AMC being unable to continue providing investment services. All legal consequences arising from such withdrawal shall be borne by the Provider of Information. Processing carried out on the basis of legal obligation (e.g., PMLA, tax reporting) will continue notwithstanding withdrawal.
10. USE OF PERSONAL INFORMATION AND COMMUNICATIONS
We may use your personal information to:
- Provide and administer investment services and related account servicing.
- Process transactions, execute instructions and maintain folio records.
- Send statutory communications, account statements and regulatory disclosures.
- Respond to service requests, resolve grievances and seek feedback.
- Generate anonymised statistics and reports for internal use and for sharing with affiliates, intermediaries, vendors and service providers; such reports will not contain personally identifiable information.
- Conduct analytics and improve our services and digital platforms.
- Send marketing communications only where you have provided explicit consent; you may opt out at any time.
Any change in the use of personal information will be notified to you.
11. DATA SHARING AND DISCLOSURE
We do not sell or rent your personal information. We may share personal information with the following categories of recipients to the extent necessary for the purposes set out in this Policy:
- Registrar & Transfer Agents (RTAs): Folio maintenance and transaction processing.
- Distributors / ARN holders: Where you have engaged a distributor for your investments.
- Custodians & Depositories (NSDL / CDSL): Dematerialised holdings and related services.
- Banks & Payment Gateways: Processing of payments and refunds.
- KYC Registration Agencies (KRAs): KYC verification and centralised KYC records.
- Regulatory & Government Authorities: SEBI, FIU-IND, Income Tax Department, RBI and other statutory authorities as required by law.
- Auditors, legal advisors and professional service providers: For audit, compliance and legal proceedings.
- Technology & Cloud Service Providers: For IT infrastructure, hosting and data processing under contractual safeguards.
- Courier / Postal Service Providers: For dispatch of physical communications and payment instruments.
- Other third parties where required for compliance with law or with your consent.
All third-party processors are bound by contractual obligations to process data only for specified purposes and to maintain appropriate security safeguards.
12. CROSS-BORDER TRANSFERS
As a rule, personal data is stored and processed within India. Where cross-border transfer is necessary (for example, FATCA/CRS reporting or cloud hosting), such transfer will be carried out in accordance with the DPDP Act and any directions issued by the Central Government. No transfer will be made to jurisdictions prohibited by applicable law.
13. SECURITY MEASURES AND LIABILITY
We implement reasonable technical and organisational measures to protect personal information, including:
- Encryption of data in transit and at rest.
- Role-based access controls and least-privilege principles.
- Periodic vulnerability assessments and penetration testing.
- Data breach detection, incident response and notification procedures.
- Employee training and awareness programs.
- Vendor due diligence and contractual safeguards.
Liability disclaimer: Notwithstanding the above, if you disclose your credentials or fail to follow security instructions provided by the AMC, any unauthorised disclosure or breach resulting from such actions shall be your responsibility. The AMC will not be liable for losses arising from your failure to safeguard credentials or from attacks beyond reasonable control (e.g., sophisticated external hacking) where the AMC has implemented reasonable security measures.
In the event of a personal data breach, we will notify the Data Protection Board of India and affected Data Principals as required under the DPDP Act and Rules.
14. RETENTION OF PERSONAL INFORMATION
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected or as required by law. Where multiple statutes apply, the longest retention period will govern.
Requests for erasure under Section 12 of the DPDP Act will be processed subject to overriding statutory retention obligations and record retention policy of the company.
15. COOKIES AND INCIDENTAL INFORMATION
Our website and mobile applications use cookies and similar technologies to:
- Maintain session state and user preferences.
- Detect device type and present content optimally.
- Perform analytics to understand usage patterns and improve services.
Cookies do not collect or store personal information unless you provide it. You may refuse cookies through your browser settings; however, refusal may limit certain website functionalities. We may use third-party analytics services; such incidental information will be used only to assist in providing an effective service and will be anonymised where possible.
16. DIRECT MARKETING AND OPT-OUT
Marketing communications are sent only with your explicit opt-in consent. You may withdraw marketing consent at any time without affecting mandatory or service-related communications. Personal information will not be shared for direct marketing without your express permission.
For marketing opt-out, the request should be submitted in writing to the contact details mentioned in Section 18.
17. RIGHTS OF DATA PRINCIPALS
Under the DPDP Act, you have the following rights:
- Right to Access: Request a summary of personal data we hold, processing purposes and third parties with whom data has been shared.
- Right to Correction & Erasure: Request correction of inaccurate or incomplete data and erasure where data is no longer necessary, subject to statutory retention obligations.
- Right to Withdraw Consent: Withdraw consent for consent-based processing; withdrawal does not affect prior lawful processing.
- Right of Grievance Redressal: Raise grievances with our Grievance Officer; unresolved matters may be escalated to the Data Protection Board of India.
- Right to Nominate: Nominate an individual to exercise your data rights in the event of death or incapacity.
Requests to exercise these rights should be submitted in writing to the contact details mentioned in Section 18.
18. DATA PRIVACY GRIEVANCE REDRESSAL AND CONTACT DETAILS
To submit requests for access, correction, erasure, withdrawal of consent or grievances related to data, please email or letter to Data Protection Officer (DPO) at the registered address / email id of the Company as stated below
At Email: dpo@carnelianmf.com OR
Data Protection Officer (DPO),
Carnelian Investment Managers Private Limited
Address: 1211/1212, One Lodha Place, Senapati Bapat Marg, Lower Parel (West), Mumbai – 400013.
We will verify identity before processing requests and will maintain records of requests and actions taken in accordance with statutory retention requirements.
Service Levels: We will respond within the timelines prescribed under the DPDP Rules. If you are not satisfied with the resolution or the grievance remains unresolved, you may escalate to the Data Protection Board of India once the Board.
19. REVIEW / AMENDMENTS TO THIS POLICY
This Privacy Policy will be reviewed annually. Where a change in law, regulation, or our data processing practices requires an update before the annual review, such change will be made immediately and placed before the Board of AMC & Trustees at its next meeting for ratification. All other amendments will require Board approval before they take effect.
The current version will always be available on our website. Providers of Information are advised to visit this page regularly in order to view the same. Continued use of our services after publication of any amendment will be treated as acknowledgement of the updated Policy.
20. MISCELLANEOUS
- Third-party links: This Policy does not apply to third-party websites linked from our site. We are not responsible for the privacy practices of such third parties.
- Legal compliance: We will disclose personal information to the extent required by law, regulation, or legal process.
- No waiver: Failure to exercise any right under this Policy does not constitute a waiver of that right.