Last updated · September 9, 2026

Privacy Policy.

How we collect, use, retain and protect your personal data across the Idlewise website and mobile application.

We at Idlewise are committed to protecting your institution's personal and financial information, keeping your data secure, and maintaining transparency about how we use it.

Idlewise operates a website and a mobile application accessible on smartphones, tablets, desktops, and laptops, collectively referred to as the "Platform." By using our Platform, you agree to the practices described in this policy.

This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, SEBI and AMFI guidelines on KYC and investor data protection, and the Prevention of Money Laundering Act, 2002 (PMLA).

02 Legal Entities

Who We Are

The services under the Idlewise brand are provided by Sigfyn Financial Services Private Limited (AMFI-registered mutual fund distributor, operating the Idlewise platform) and Sigfyn Technologies LLP (owns the underlying technology — app/website development, infrastructure, and security).

03 Collection Framework

What Data We Collect

We collect the following categories of information to fulfil regulatory requirements and operate the Platform:

A · Identity & KYC data — of your institution's authorised signatories: full legal name, PAN, date of birth, government-issued ID, and CKYC reference number.

B · Institutional data — your constitutional document (Certificate of Incorporation, Trust Deed, or equivalent), PAN, GST registration, board or trustee resolutions, and authorised signatory details.

C · Financial & account data — your registered bank account details, mutual fund folio numbers, and sweep-out / sweep-in transaction history.

D · Approval & audit data — every proposal, approval, and transaction, together with the approving signatory's identity, timestamp, and IP address.

E · Usage data — page views, clicks, time spent, device and browser information, and IP address.

F · Analytics data — via Google Analytics and Microsoft Clarity: session activity, user flow, and interaction data.

04 Application Purposes

How We Use Your Data

Provide and manage your institution's account.

Process and execute sweep-out and sweep-in transactions.

Maintain approval workflows and audit trails.

Comply with KYC/AML obligations under PMLA, SEBI, and AMFI regulations, including reporting to the Financial Intelligence Unit – India (FIU-IND) where required.

Detect and resolve technical issues, and prevent fraud.

Improve the platform's user experience and analyse performance.

05 Privacy Guarantees

Data Sharing

We share your data with Asset Management Companies and registrars (CAMS/KFintech), to process transactions and maintain your institution's folio; banking partners, for payment processing; KYC Registration Agencies, for KYC verification; and regulators or courts, where legally required.

We do not sell, rent, or trade your personal data to third parties for their independent marketing purposes.

Your data is primarily processed and stored within India. Where any processing occurs outside India — for example, via cloud infrastructure — it is carried out in compliance with applicable data protection law.

In the event of a merger, acquisition, or sale of assets, your data may be transferred to the successor entity, subject to equivalent data protection obligations.

06 Lifecycle Policies

Data Retention

KYC and AML records are retained for a minimum of five years from the end of our relationship with your institution, as required under PMLA.

Approval and audit records are retained for a minimum of three years.

Other account data is retained for the duration of your account, unless you specifically request deletion and applicable law permits it.

07 Consent & Ownership

Your Rights

Under the Digital Personal Data Protection Act, 2023, and applicable law, you have the right to:

Access — request a copy of the personal data Idlewise holds about your institution.

Correct — request correction of inaccurate or outdated personal data.

Delete — request erasure of your account records, subject to our obligation to retain KYC, AML, and transaction records for the periods above.

Withdraw consent — where processing relies on consent, at any time.

To exercise any of these rights, write to grievance@sigfyn.com.

08 Browser Cookies

Cookies & Tracking Technologies

We use cookies to enhance platform functionality and collect analytics data to improve user experience. You can manage your preferences:

09 Systems Security

Security Practices

We use industry-standard HTTPS encryption to protect your data during transmission, along with role-based access controls and multi-factor authentication. We comply with the Information Technology Act, 2000, and applicable law.

If you believe your account has been compromised, contact us immediately at grievance@sigfyn.com.

10 Incident Response

Incident Response

In the event of a personal data breach, we will take immediate containment action and notify the Data Protection Board of India, as required under the DPDP Act, along with affected institutions as required by applicable law.

11 Policy Updates

Changes & Contact

We may update this Privacy Policy from time to time. Continued use of our Platform after any update indicates acceptance.

General Inquiries · contact@sigfyn.com
Grievance Redressal · grievance@sigfyn.com