Data Processing Agreement (DPA)

Data Processing Agreement (DPA)

Effective Date 18-Dec-25

This Data Processing Agreement (“Agreement” or “DPA”) forms part of the terms governing the use of services provided by Multifarious Finvisors Private Limited (“Company”, “Data Processor”, “we”, “our”, “us”) and applies to the processing of personal data of clients, users, or business partners (“Data Subject”) on behalf of the client (“Data Controller”).

 

This Agreement is intended to ensure compliance with applicable data protection laws and to define the responsibilities of both parties regarding personal data processing.

1. Purpose of Data Processing

The Company processes personal data solely for the purpose of providing financial facilitation, advisory support, documentation assistance, and coordination services, as requested by the Data Controller.

 

Processing is carried out only to the extent necessary to perform agreed services and in accordance with applicable laws.

Depending on the nature of services, personal data processed may include:

 

  1. Name, contact details (email, phone number, address)
  2. Identity and KYC-related information (as provided by the client)
  3. Financial and employment details required for service facilitation
  4. Business or professional information
  5. Any other data voluntarily shared for service-related purposes

The Company does not knowingly process data beyond what is necessary for the stated purpose.

Data Controller

The Data Controller:

  1. Determines the purpose and means of processing personal data
  2. Confirms that all personal data shared is collected lawfully
  3. Ensures appropriate consent has been obtained from Data Subjects

Data Processor

The Company:

  1. Processes personal data only on documented instructions of the Data Controller
  2. Does not use personal data for its own independent purposes
  3. Ensures confidentiality and security of personal data

The Company implements reasonable technical and organizational security measures to protect personal data against unauthorized access, disclosure, alteration, or loss.

Such measures may include:

  1. Access controls
  2. Secure storage practices
  3. Restricted internal access
  4. Confidentiality obligations for personnel

No method of data transmission or storage is completely secure; however, reasonable safeguards are maintained.

All personnel, contractors, or service providers who have access to personal data are bound by confidentiality obligations and are permitted to process data only as necessary to perform their duties.

Personal data may be shared only when necessary:

  1. With banks, NBFCs, insurers, or regulated institutions for service facilitation
  2. With service providers supporting IT, communication, or operations

All such sharing is subject to confidentiality and data protection obligations.
The Company does not sell personal data.

Personal data is retained only for as long as required to:

  1. Fulfill service obligations
  2. Meet legal or regulatory requirements

Upon completion of services or upon lawful request, personal data may be deleted or anonymized, subject to applicable laws.

Where applicable, Data Subjects may request:

  1. Access to personal data
  2. Correction of inaccurate information
  3. Deletion of data, subject to legal obligations

Such requests may be routed through the Data Controller or directly to the Company where legally permitted.

This Agreement is intended to support compliance with:

  1. Information Technology Act, 2000
  2. Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  3. Other applicable Indian data protection and privacy regulations

This DPA does not override any mandatory legal or regulatory obligations.

The Company shall not be liable for:

  1. Data inaccuracies provided by the Data Controller
  2. Lawful disclosures required by authorities
  3. Breaches caused by factors beyond reasonable control

Liability, if any, shall be limited to the extent permitted under applicable law.

This DPA remains effective for the duration of the data processing activities.
Termination of services shall not affect obligations related to confidentiality and data protection.

The Company reserves the right to update this DPA to reflect changes in law, regulation, or operational practices. Updates will be published on the website and will take effect upon posting.

This Agreement shall be governed by and construed in accordance with the laws of India.
Any disputes shall be subject to the jurisdiction of competent courts in India.

For questions or requests related to data protection or this Agreement, please contact us through the details provided on the Contact Us page.