Privacy Policy
Last updated: 6 September 2026
This Privacy Policy explains how Mintants AI LLP collects, uses, shares, and protects personal data, with particular focus on the white-labelled Advisory Platform licensed to SEBI-registered Research Analysts (RA) and Registered Investment Advisers (RIA). It also covers data we collect through this website.
1. Who we are and what this policy covers
Mintants AI LLP ("Mintants", "we", "us", or "our") operates the mintants.in website and licenses a white-labelled advisory platform (the "Advisory Platform") to SEBI-registered RA and RIA subscribers for paperless KYC onboarding, risk profiling, research-call publishing and tracking, subscriptions and payments, and compliance record-keeping.
This policy covers two distinct situations. First, data we handle as the deciding party: website visitors, enquiries, and the accounts of RA/RIA subscribers who license the platform from us. Second, data we handle on behalf of a subscriber: the end-investor client data that an RA/RIA processes through their branded instance of the Advisory Platform.
2. Controller and processor roles
For the website, marketing enquiries, and subscriber account and billing data, Mintants AI LLP is the Data Fiduciary (controller) and decides why and how that data is processed.
For end-investor data inside a subscriber's white-labelled instance, the subscribing RA/RIA is the Data Fiduciary and Mintants acts only as a Data Processor. We process that data on the subscriber's documented instructions, to deliver and support the platform. The RA/RIA is responsible for the lawful basis of collection, for issuing their own privacy notice to their clients, and for the accuracy and retention decisions applying to that data.
Because the platform is white-labelled, end investors interact with the subscriber's brand. Those investors should direct privacy requests to the RA/RIA they engaged. If such a request reaches us directly, we forward it to the relevant subscriber rather than acting on it ourselves.
3. Data we collect as a Data Fiduciary
Website and enquiries: name, email address, phone number, company name, and the content of any message you send through our contact form, WhatsApp, email, or a scheduled call. We also collect standard technical data such as IP address, browser and device type, referring page, and pages viewed.
Subscriber accounts: the name, business name, email, phone number, and SEBI registration details of the RA/RIA licensing the platform, together with authentication credentials, plan and billing records, invoices, support correspondence, and administrative activity logs.
We do not collect sensitive personal data through the website beyond what you choose to include in a message, and we ask that you do not send financial account numbers or identity documents by email.
4. Data we process on behalf of RA/RIA subscribers
When a subscriber runs their advisory practice on the Advisory Platform, the platform stores and processes end-investor data on their behalf. Depending on the modules a subscriber enables, this may include identity and KYC data (name, address, date of birth, PAN and other identifiers, identity-document images, photographs or liveness captures), contact details, e-signed advisory agreements and consent records, risk-profiling questionnaire responses and suitability outcomes, subscription and payment records, research calls issued to the client, and timestamped audit trails of these actions.
We access this data only to operate, secure, support, and troubleshoot the platform at the subscriber's request, or where required by law. We do not use end-investor data for our own marketing, do not sell it, and do not share it with other subscribers.
We do not use identifiable end-investor data to train machine-learning models. Where we improve platform features using usage analytics, that analysis is performed on aggregated or de-identified data that cannot reasonably be linked back to an individual.
5. How we use personal data
As a Data Fiduciary, we use personal data to respond to enquiries and provide requested information, to create and administer subscriber accounts, to process subscription payments and issue invoices, to provide customer support, to send service and security notices, to improve and secure our website and platform, and to meet our legal, tax, and regulatory obligations.
As a Data Processor, we use end-investor data only to provide the platform functionality the subscriber has configured, to maintain the audit and record-keeping trails that SEBI norms require of that subscriber, and to provide technical support and incident response.
We send marketing communications only where you have asked to receive them or where we have an existing business relationship, and every such message includes a way to opt out.
6. Legal bases
In India, we process personal data under the Digital Personal Data Protection Act, 2023, relying on your consent, on the voluntary provision of data for a specified purpose, or on legitimate uses recognised by that Act. Where the UK GDPR or EU GDPR applies to a visitor or subscriber, we rely on consent, on performance of a contract, on our legitimate interests in operating and securing our services, or on compliance with a legal obligation, as applicable.
Where processing depends on your consent, you may withdraw it at any time. Withdrawal does not affect processing carried out before the withdrawal, and may mean we can no longer provide part of a service.
7. Cookies and analytics
Our website uses a small number of cookies and similar technologies that are necessary for the site to function and to understand aggregate usage patterns. Embedded third-party components, such as our scheduling widget, may set their own cookies when you interact with them.
You can block or delete cookies through your browser settings. Disabling strictly necessary cookies may prevent parts of the site or platform from working correctly.
8. Sharing and sub-processors
We do not sell personal data. We share it only with service providers who help us run the website and platform, under contracts that limit them to processing data on our instructions and require appropriate security. These typically include cloud hosting and storage providers, KYC and identity-verification providers, e-signature providers, payment gateways, email and SMS delivery providers, error monitoring and analytics providers, and customer-support tooling.
We may also disclose personal data where required by law, court order, or a lawful request from SEBI or another regulator or law-enforcement authority, and where necessary to establish, exercise, or defend legal claims. If our business is involved in a merger, acquisition, or transfer of assets, personal data may transfer as part of that transaction, subject to this policy.
Subscribers are notified of material changes to the sub-processors used for their instance, so they can meet their own obligations to their clients.
9. Data location and international transfers
Advisory Platform data is hosted on infrastructure located in India by default, which supports subscribers in meeting SEBI record-keeping expectations. Some supporting services, such as error monitoring or email delivery, may process limited data outside India.
Where personal data is transferred outside India or outside the region in which it was collected, we put appropriate safeguards in place, including contractual protections with the receiving party and transfer mechanisms recognised under applicable law.
10. Data retention
Website enquiries are retained for up to 24 months from the last contact unless a business relationship begins. Subscriber account, billing, and tax records are retained for as long as the subscription is active and afterwards for the period required by Indian tax and company law.
End-investor data inside a subscriber's instance is retained for as long as the subscriber's account is active, or for the longer period the subscriber must observe under SEBI record-keeping requirements, which commonly extends to five years and longer where a proceeding is pending. On termination, we make the data available for export for a limited window and then delete or irreversibly anonymise it, except where law requires us to keep it. Backups are purged on a rolling schedule.
11. Security
We apply technical and organisational measures appropriate to the sensitivity of the data we hold: encryption in transit and at rest, role-based access controls with least-privilege administrative access, tenant isolation between subscriber instances, audit logging of privileged actions, regular backups, vulnerability patching, and secure software-development practices.
No system can be guaranteed completely secure. Subscribers are responsible for safeguarding their own login credentials, enabling available account-security features, and promptly removing users who no longer need access. If a personal data breach affecting your data occurs, we will notify affected subscribers and the relevant authority as required by applicable law, without undue delay.
12. Your rights
Subject to applicable law, you may request access to the personal data we hold about you, ask us to correct or complete inaccurate data, request erasure, ask us to restrict or object to certain processing, request a portable copy, withdraw consent, and nominate another individual to exercise your rights in the event of death or incapacity.
To exercise a right in respect of data for which we are the Data Fiduciary, contact us at hello@mintants.in. We respond within the timelines set by applicable law and may need to verify your identity first.
If you are an end investor whose data sits inside an RA/RIA's white-labelled instance, please contact that adviser directly, as they control that data. We will assist them in responding to you.
If you believe your rights have not been honoured, you may complain to the Data Protection Board of India or another competent supervisory authority.
13. Children's data
Our website and the Advisory Platform are not directed at children. Where a subscriber onboards a minor as an investor, the subscriber is responsible for obtaining verifiable consent from a parent or lawful guardian as required under applicable law. We do not knowingly collect data from children through the website, and will delete any such data brought to our attention.
14. Changes to this policy
We may update this Privacy Policy from time to time. Changes take effect when posted on this page, and the "last updated" date will be revised accordingly. Where a change materially affects how we handle personal data, we will provide additional notice to subscribers.
15. Contact us
For any privacy question, request, or complaint, contact Mintants AI LLP at hello@mintants.in. We will acknowledge your request and respond within the period required by applicable law.
