Data Protection Agreement

How Floatr processes personal data, safeguards information, and complies with applicable regulations in India

Updated on: 09 Feb, 2026ValueFloat Technologies Private Limited

Supplement to Terms & Privacy

This Data Protection Agreement (“DPA”) supplements Floatr’s Terms and Conditions and Privacy Policy. It describes how personal data is processed, secured, retained, and governed across Floatr’s financial wellness platform and related services.

1

1. Introduction

This Data Protection Agreement (“DPA”) describes howFloatr (Valuefloat Technologies Private Limited)processes personal data in connection with its financial wellness platform, investment facilitation services, retirement planning support, lending enablement, and related financial services.

This DPA supplements Floatr’s Terms of Use and Privacy Policy and is intended to provide transparency regarding:

  • Processing of personal data
  • Security and privacy safeguards
  • Sub-processors and infrastructure
  • Data localisation practices
  • Compliance with applicable regulations including:

Digital Personal Data Protection Act, 2023 (India)
Financial regulatory obligations (including AMFI, SEBI, RBI, PFRDA where applicable)

2

2. Scope of Processing

Floatr processes personal data for:

  • Financial wellness services – financial planning, retirement planning, wealth management
  • Investment & lending facilitation (mutual funds, NPS, lending etc.)
  • Compliance verification and KYC
  • Customer support and platform operations
  • Security monitoring and fraud prevention

Processing activities may include:

  • Collection
  • Storage
  • Analysis
  • Transmission
  • Deletion or anonymisation
3

3. Controller and Processor Roles

Floatr may act in multiple capacities depending on service context:

Data Controller

Where Floatr:

  • Determines purposes and means of processing
  • Collects personal data directly from users
  • Provides direct financial services or advisory tools

Data Processor

Where Floatr:

  • Processes data on behalf of employers, financial partners, or regulated institutions
  • Acts under contractual instructions

These roles may overlap depending on the service relationship.

4

4. Data Localisation

All personal and financial data processed by Floatr:

  • Is stored within secure cloud infrastructure located in India
  • Is processed within India
  • Is not transferred outside India unless legally mandated

Floatr primarily services customers within the Indian jurisdiction only.

5

5. Security Safeguards

Floatr maintains administrative, technical, and organisational security measures including:

  • Encryption of data in transit and at rest
  • Role-based access controls and least privilege principles
  • Multi-factor authentication for sensitive systems
  • Secure cloud infrastructure
  • Vulnerability assessments and penetration testing
  • Continuous monitoring and logging
  • Incident response framework
  • Employee confidentiality obligations

Security practices align with recognised industry standards ISO 27001, SOC-2 & DPDPA compliances.

6

6. Personal Data Breach Management

Floatr maintains a documented incident response program.

In case of confirmed breach:

  • Initial notification typically within 24 hours where applicable
  • Investigation and mitigation measures initiated immediately

Regulatory notifications made where required.

7

7. Data Retention Principles

Personal data is retained only as long as necessary for:

  • Service delivery
  • Regulatory compliance
  • Security monitoring
  • Financial record-keeping obligations
  • Dispute resolution

Data is securely deleted or anonymised when retention requirements expire.

One can also send request to delete their data by sending an email to privacy@floatr.in

8

8. Data Protection Governance

Floatr has appointed a Data Protection Officer responsible for:

  • Privacy compliance
  • Data governance
  • Incident coordination
  • Regulatory engagement

Data Protection Officer:
Sumit Kumar Srivastava
sumit@floatr.in

9

9. Updates to this Addendum

This DPA may be updated periodically to reflect:

  • Regulatory changes
  • Service enhancements
  • Security improvements

Latest version will always be available on Floatr’s website.

10

10. Document Version and Release Information

VersionRelease DateDescription of ChangesApproved By
1.009 Feb, 2026Initial public release of Floatr Data Processing Addendum aligned with DPDPA compliance and data processing transparency disclosures.Floatr Compliance Team
A

Annexure A — Categories of Personal Data Processed

CategoryData TypesPurpose
Identity / KYC DataName, PAN, Aadhaar last 4-digit, DOB, photographs, address proof, signatureIdentity verification, regulatory compliance
Family, NomineesName, Relation, DOB, Email Mobile, ID ProofAssign nominee to investments
Contact DataEmail, phone number, addressCommunication, account management
Financial DataBank account details, investment accounts, NPS data, loan dataFinancial service facilitation
Employment DataEmployer information, corporate email id, employee ID, IncomeCorporate benefits, compliance
Transaction DataInvestment transactions, contributions, financial activityReporting and service execution
Technical DataDevice info, IP logs, login activity, usage analyticsSecurity and optimisation
B

Annexure B — Sub-Processors

Sub-ProcessorPurposeData TypeLocation
AWS India RegionCloud hosting and storageApplication dataIndia
CRA (KFINTECH, Protean, CAMS)NPS recordkeepingPersonal Information, Pension account dataIndia
Point of Presence (POP)NPS servicesPersonal Information, Investment dataIndia
RTA (KFINTECH, CAMS)Mutual fund facilitationPersonal Information, Investment dataIndia
Lending Partners, NBFC, BanksLending enablementPersonal Information, Financial dataIndia
Other SEBI, RBI Registered IntermediariesFor investment & lending servicesPersonal Information, Financial dataIndia
Security Assessment VendorsSecurity testingControlled system accessIndia
C

Annexure C — Security Controls Overview

Control AreaMeasures
EncryptionTLS encryption in transit, encrypted storage at rest
Access ControlRBAC, MFA, least privilege
Infrastructure SecurityCloud firewall, segmentation
MonitoringAudit logging and monitoring
TestingVAPT and vulnerability scans
ComplianceISO 27001, SOC 2 and DPDPA
D

Annexure D — Data Retention Overview

Data TypeRetention Basis
Customer Account DataDuration of service + regulatory obligations
KYC / Financial RecordsAs required by financial regulators
Application LogsTypically ~1 year operationally
Security LogsMinimum 12 months
Backup DataAs per disaster recovery policy, 2 years

Questions about data protection?

Reach our Data Protection Officer or contact us for privacy and compliance queries.