Back to Home

Privacy Policy

IFAclick — CRM Platform for Mutual Fund Distributors

Effective Date: 18 August 2026

This Privacy Policy ("Policy") describes how Techcanopy Software Labs Private Limited ("Techcanopy", "Company", "we", "us", or "our"), the company that owns and operates IFAclick ("IFAclick"), a web-based customer relationship management ("CRM") platform designed for Mutual Fund Distributors ("MFDs") and financial advisory firms, having its registered office in Bangalore, Karnataka, India, collects, uses, discloses, stores, and protects information in connection with the website www.ifaclick.com, the application hosted at app.ifaclick.com, and all related services (collectively, the "Platform" or "Service").

This Policy is published in accordance with, and forms part of the Terms of Service governing, applicable Indian law, including the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Digital Personal Data Protection Act, 2023 ("DPDP Act") together with rules framed thereunder from time to time. By accessing or using the Platform, you agree to the collection, use, and disclosure of information as described in this Policy. If you do not agree with this Policy, please do not access or use the Platform.

1. Definitions

"Account Holder" or "User" means the MFD, advisory firm, or authorised individual who registers for and operates an account on the Platform.

"Client Data" means any personal data, KYC information, financial information, or other information relating to a User’s clients or prospects that the User uploads, inputs, or stores on the Platform.

"Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under the DPDP Act.

"Data Fiduciary", "Data Processor", and "Data Principal" shall have the meanings assigned under the DPDP Act.

"Sensitive Personal Data or Information" (SPDI) has the meaning assigned under the SPDI Rules and includes financial information, and other categories specified therein.

"Services" means the CRM software, dashboards, communication tools, document repository, and related features made available through the Platform, on a subscription basis.

2. Our Role: Data Fiduciary and Data Processor

2.1 As Data Fiduciary. In respect of the personal data of Users themselves — such as account registration details, billing information, and usage data generated through the User’s own interaction with the Platform — IFAclick acts as a "Data Fiduciary" and determines the purpose and means of processing such data, subject to this Policy.

2.2 As Data Processor. In respect of Client Data that a User uploads, inputs, or stores on the Platform relating to that User’s own clients or prospects, IFAclick acts solely as a service provider / data processor, processing such Client Data strictly on the instructions of, and for the purposes determined by, the User. The User remains the data fiduciary/data controller in respect of such Client Data and is solely responsible for (a) obtaining all necessary consents from its clients for collection and processing of their personal data, including KYC and financial information; (b) ensuring the lawfulness of such collection under applicable law, including SEBI regulations and the DPDP Act; and (c) responding to any requests, complaints, or grievances raised by its clients regarding their personal data. IFAclick will provide reasonable assistance to Users in meeting their obligations as data fiduciary in respect of Client Data, including through appropriate technical and organisational measures on the Platform.

3. Information We Collect

3.1 Information You Provide to Us

Account and registration information: name, email address, mobile number, company name, designation, ARN/EUIN details, and password.

Billing information: billing address, GSTIN, and payment details processed through our third-party payment gateway partners; payments for subscription fees are made to Techcanopy Software Labs Private Limited, the company that owns and operates the IFAclick platform.

Communications: information you provide when you contact us for support, fill the "Contact Us" form, request a demo, or otherwise correspond with us.

Client Data uploaded to the Platform, including client names, contact details, KYC documents, PAN, address proof, risk-profiling responses, family relationship mapping, financial goals, portfolio and transaction-related notes, and communication logs, entered by Users in the course of using the Service.

3.2 Information Collected Automatically

Usage data: pages visited, features used, log-in timestamps, session duration, clicks, and interactions with the dashboard.

Device and technical data: IP address, browser type and version, operating system, device identifiers, and general location derived from IP address.

Cookies and similar tracking technologies as described in Section 9 below.

3.3 Information from Third-Party Integrations

Where you choose to connect the Platform with third-party services such as WhatsApp Business, email providers (including Google Workspace and Office 365), or other integrations, we may receive information from those services as permitted by your account settings and the relevant third party’s terms, solely to enable the requested integration (e.g., syncing communications into the CRM).

4. How We Use Information

We use the information described above for the following purposes:

To create and administer User accounts and provide access to the Service;

To operate, maintain, and improve the features of the Platform, including lead management, risk profiling, task and follow-up management, document storage, and reporting;

To process payments, renew subscriptions, and send billing-related communications;

To provide customer support and respond to enquiries;

To send service-related notifications, updates, and, where consented to, marketing communications (with an opt-out available at any time);

To monitor usage, detect and prevent fraud, unauthorised access, and misuse of the Platform;

To comply with applicable law, regulatory requests, and to enforce our Terms of Service; and

To generate aggregated, anonymised, or de-identified analytics that do not identify any individual, for product improvement and internal research.

We do not use Client Data uploaded by Users for any purpose other than to provide, maintain, and support the Service to that User, unless required by law or with the User’s prior written consent.

5. Legal Basis and Consent

We process personal data on the basis of your consent given at the time of registration and continued use of the Platform, for performance of the contract between you and IFAclick (i.e., providing the Service), for compliance with legal obligations, and for our legitimate interests in operating and securing the Platform, in a manner consistent with the DPDP Act. You may withdraw consent for optional processing (such as marketing communications) at any time, without affecting the lawfulness of processing carried out prior to such withdrawal, by writing to us at the contact details in Section 14.

6. How We Share and Disclose Information

We do not sell, rent, or trade personal data or Client Data. We may share information in the following circumstances:

With sub-processors and service providers who assist us in operating the Platform, including cloud hosting providers, payment gateways, email/SMS/WhatsApp delivery providers, and analytics providers, each bound by contractual confidentiality and data-protection obligations no less protective than this Policy;

With third-party integrations that you affirmatively enable (e.g., WhatsApp Business API, Google Workspace, Office 365), strictly to the extent necessary to provide the requested functionality;

With professional advisors such as auditors, legal counsel, and insurers, where necessary and subject to confidentiality obligations;

Where required to comply with applicable law, a court order, or a lawful request by a government or regulatory authority (including SEBI, tax, or law-enforcement authorities);

In connection with a merger, acquisition, restructuring, or sale of assets, subject to the acquiring entity agreeing to honour the commitments made in this Policy; and

With your explicit consent, for any other purpose disclosed to you at the time of collection.

7. Data Storage, Security, and Location

We implement reasonable security practices and procedures, including encryption in transit and at rest where applicable, access controls, role-based permissions, firewalls, regular backups, and audit logging, in line with the standards contemplated under the SPDI Rules, to protect personal data and Client Data against unauthorised access, alteration, disclosure, or destruction.

Data collected through the Platform is primarily hosted on cloud infrastructure located within India. Where any data is processed or backed up outside India, such transfer will be carried out in compliance with the DPDP Act and any applicable notifications issued by the Central Government from time to time. No security system is impenetrable, and we cannot guarantee the absolute security of information transmitted to or stored on the Platform; Users are encouraged to use strong passwords and safeguard their login credentials.

8. Data Retention

We retain personal data and Client Data for as long as your account remains active and for such additional period as is necessary to fulfil the purposes described in this Policy, comply with our legal and regulatory obligations (including record-keeping requirements applicable to financial intermediaries), resolve disputes, and enforce our agreements. Upon termination of an account, Client Data will be retained for a reasonable transition period to allow export by the User, after which it will be deleted or anonymised from our active systems, save for data we are required by law to retain, or that resides in encrypted backups until their scheduled deletion cycle.

9. Cookies and Tracking Technologies

We use cookies, local storage, and similar technologies to operate the Platform, remember your preferences, keep you logged in, and understand how the Platform is used, including for analytics purposes. You can control cookies through your browser settings; disabling certain cookies may affect the functionality of the Platform. For further details, please refer to our Cookie Policy.

10. Your Rights as a Data Principal

Subject to applicable law, you have the right to:

Access and obtain a summary of the personal data we hold about you and the processing activities undertaken;

Request correction, completion, or updating of inaccurate or outdated personal data;

Request erasure of personal data that is no longer necessary for the purpose for which it was collected, subject to our legal retention obligations;

Withdraw consent for processing that is based on consent, at any time;

Nominate another individual to exercise these rights on your behalf, in the event of death or incapacity; and

Register a grievance with our Grievance Officer (Section 13) and, if unresolved, with the Data Protection Board of India, once constituted and operational.

Requests may be sent to the contact details set out in Section 14. We will verify your identity before acting on any request and will respond within the timelines prescribed under applicable law. Where the request relates to Client Data, we may direct you to the relevant User (data fiduciary) who controls that data, or assist the User in responding to such a request.

11. Children’s Privacy

The Platform is intended for use by business professionals and is not directed at, nor knowingly used to collect personal data from, individuals under the age of 18. If we become aware that we have inadvertently collected personal data of a child without verifiable parental/guardian consent, we will take steps to delete such data promptly.

12. Third-Party Links and Services

The Platform may contain links to, or integrations with, third-party websites and services (such as payment gateways, WhatsApp, Google Workspace, and Office 365) that are governed by their own privacy policies. We are not responsible for the privacy practices of such third parties, and we encourage you to review their respective policies.

13. Grievance Officer

In accordance with the Information Technology Act, 2000, the rules made thereunder, and the DPDP Act, the details of the Grievance Officer are provided below. Any complaints, concerns, or discrepancies with respect to this Policy or the processing of your personal data may be addressed to:

Grievance Officer / Data Protection Contact: IFAclick Support Team

Email: support@ifaclick.com

Address: Bangalore, Karnataka, India

We will acknowledge and endeavour to resolve grievances within the timelines prescribed under applicable Indian law.

14. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data-handling practices, please contact us at:

Email: support@ifaclick.com

Registered Office: Bangalore, Karnataka, India

15. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. The updated Policy will be posted on this page with a revised "Effective Date." Material changes will be notified to Users via email or an in-app notice. Your continued use of the Platform after such changes constitutes your acceptance of the revised Policy.

16. Governing Law and Jurisdiction

This Policy shall be governed by and construed in accordance with the laws of India. Subject to the dispute resolution mechanism set out in our Terms of Service, the courts at Bangalore, Karnataka shall have exclusive jurisdiction over any disputes arising out of or in connection with this Policy.