Aspero

Invest with aspero

4.6 App store rating

Legal Effective Date · May 2026

Privacy Policy.

Your privacy is important to us. This Policy explains how Aspero Markets Private Limited collects, uses, processes, and protects your Personal Data.

01

Introduction

This Privacy Policy ("Policy") explains how Aspero Markets Private Limited, a private limited company incorporated under the provisions of the Companies Act, 2013, having its registered office at 12th Floor, Prestige Polygon, No. 471, Anna Salai, Nandanam, Chennai, Tamil Nadu, India – 600035 ("Aspero", "Company", "we", "us", or "our") collects, uses, processes, discloses, and protects the Personal Data of visitors, users, and investors ("you", "your") who access or use:

  • the website available at https://www.aspero.in/;
  • the web-based investment application available at https://aspero.in/invest/sign_in;
  • the mobile application available on iOS and Android platforms under the brand name 'Aspero'; and
  • any other online interfaces, tools, portals, or platforms that are owned, operated, or controlled by Aspero (collectively, the "Platform").

Aspero is a SEBI-registered entity operating as a Stock Broker (INZ000310534), Depository Participant (NSDL DP Registration No. IN-DP-752-2023), Merchant Banker (INM000012883), Research Analyst (INH000010256), and Online Bond Platform Provider (OBPP), providing retail investors access to fixed income securities including corporate bonds, government bonds, fixed deposits, sovereign gold bonds, and other debt instruments.

This Policy, inter alia, outlines:

  • The categories of Personal Data we collect;
  • The legal basis and manner in which we collect Personal Data;
  • The purposes for which we process your Personal Data;
  • The conditions under which your Personal Data is disclosed to third parties;
  • Our data retention practices and timelines;
  • The security safeguards we employ to protect your Personal Data;
  • Your rights as a Data Principal under applicable law; and
  • Our grievance redressal and breach notification mechanisms.

We are committed to protecting your privacy and processing your Personal Data in full compliance with the following Applicable Laws:

  • Digital Personal Data Protection Act, 2023 ("DPDPA") and all rules, regulations, and guidelines framed and notified thereunder;
  • The Information Technology Act, 2000 ("IT Act") and the rules thereunder, including the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), to the extent applicable;
  • SEBI Cybersecurity and Cyber Resilience Framework ("CSCRF") and all SEBI circulars applicable to registered intermediaries;
  • Prevention of Money Laundering Act, 2002 ("PMLA") and the rules framed thereunder; and
  • All other applicable acts, regulations, circulars, guidelines, and directions issued by SEBI, RBI, or any other competent regulatory authority from time to time (collectively, "Applicable Laws").
02

Definitions

For the purposes of this Policy, the following terms shall have the meanings assigned to them below:

TermDefinition
Applicable LawsAll laws, rules, regulations, circulars, guidelines, and directions issued by competent authorities applicable to Aspero's operations and data processing activities, as described in Section 1 above.
ConsentA free, specific, informed, unconditional, and unambiguous indication of your agreement to the processing of your Personal Data, given through a clear affirmative action as required under the DPDPA.
CookieA small text file placed on your device by the Platform to enable functionality, analytics, preferences, and marketing.
Data FiduciaryAspero, which determines the purpose and means of processing Personal Data, as defined under the DPDPA.
Data PrincipalYou, the individual to whom the Personal Data relates, as defined under the DPDPA.
Data ProcessorA third party that processes Personal Data on behalf of Aspero, under contract and under Aspero's instructions.
Data Protection BoardThe Data Protection Board of India established under Section 18 of the DPDPA.
DPDPAThe Digital Personal Data Protection Act, 2023, as amended from time to time.
KYCKnow Your Customer — the regulatory process for verifying the identity and particulars of users as mandated by SEBI and other applicable regulators.
OBPPOnline Bond Platform Provider, a SEBI-registered category of intermediary that provides an electronic platform for issuance and trading of debt securities.
Personal DataAny data about an individual who is identifiable by or in relation to such data, as defined under the DPDPA. This includes Sensitive Personal Data.
Personal Data BreachAny unauthorized processing, accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to Personal Data.
PlatformThe website at https://www.aspero.in/, web application, mobile application, and all other online interfaces owned or controlled by Aspero.
ProcessingAn automated or manual operation or set of operations performed on Personal Data, including collection, recording, organization, structuring, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
Sensitive Personal DataPersonal Data pertaining to passwords, financial data, health data, official identifiers (PAN, Aadhaar), biometric data, and other categories notified by the Central Government under the DPDPA.
ServicesAll investment, advisory, depository, brokerage, and ancillary services offered by Aspero through the Platform.
03

Applicability

This Policy applies to all individuals who:

  • Access or browse the Platform, whether or not they register or create an account;
  • Register as users or investors on the Platform;
  • Avail any Services offered through the Platform;
  • Contact Aspero through any channel including email, phone, chat, or social media; and
  • Participate in surveys, promotions, or marketing communications conducted by or on behalf of Aspero.

This Policy does not apply to:

  • Anonymous information that cannot be used to identify an individual;
  • Personal Data collected or processed by third-party websites, platforms, or services that are linked from our Platform. You are encouraged to review the privacy policies of such third parties independently; and
  • Personal Data of employees, contractors, or service providers of Aspero, which is governed by separate internal data protection policies and employment agreements.
05

Personal Data We Collect

Aspero collects only such Personal Data as is necessary, adequate, and relevant for the purposes for which it is collected (the principle of data minimisation). We collect and process your Personal Data on the following legal bases:

  • Your free, specific, informed, unconditional, and unambiguous consent provided through an explicit affirmative action at the time of registration, account creation, or service initiation;
  • Compliance with legal or regulatory obligations under Applicable Laws; and
  • Legitimate purposes of the Data Fiduciary, to the extent permitted under the DPDPA and other Applicable Laws.
5.1

Categories of Personal Data Collected

(a)

Identity and Contact Information: Full legal name as per PAN / Aadhaar records; date of birth and gender; residential and correspondence address (current and permanent); mobile number and email address; nationality and residential status (Resident Indian / NRI / Foreign National); occupation, income range, and tax residency details.

(b)

Official Identification and KYC Documents: Permanent Account Number (PAN); Aadhaar details (only masked/last four digits and derived KYC data as specified in Section 5.3); passport, Voter ID, or Driver's License (as address proof); live photograph for identity verification; signature for account and transaction authentication; and CKYC identifier.

(c)

Financial and Investment Information: Bank account details (account number, IFSC code, bank name, branch); cancelled cheque or bank statement; demat account details (DP ID, client ID, depository); investment preferences, risk profile, and suitability information; transaction history, portfolio holdings, and order details on the Platform; and dividend/interest payment details and bank mandate information.

(d)

Beneficiary and Nominee Information: Full name, relationship, date of birth, and contact details of nominated beneficiaries; PAN and other identification details of nominees, where required by Applicable Laws.

(e)

Authentication and Security Information: User credentials (passwords are stored in hashed/encrypted form and are never accessible to Aspero in plain text); One-Time Passwords (OTPs) used for login and transaction authentication; and device identifiers, IP addresses, and session tokens for security and fraud prevention.

(f)

Behavioral and Technical Data: Log data including IP address, browser type, operating system, referring URLs, and pages visited; device information including device type, model, and unique device identifiers; usage data including time spent on pages, clicks, search queries, and feature interactions; and geolocation data to comply with SEBI and FEMA regulations.

(g)

Communication and Interaction Data: Records of customer service interactions including voice calls, chats, and emails; feedback, grievances, and survey responses submitted by you; and marketing communication preferences and opt-in/opt-out records.

(h)

Career and Employment Data (if applicable): Resume, work history, educational qualifications, and references if you apply for a position with Aspero.

5.2

Data You Are Not Required to Provide: You are not required to submit data beyond what is mandated by Applicable Laws or necessary for the specific Service you avail. Where a field is optional, this will be indicated on the relevant form or screen on the Platform.

5.3

Collection of Aadhaar Information: In compliance with the Aadhaar Act, 2016, applicable UIDAI regulations, and the DPDPA, Aspero does not collect or store your complete 12-digit Aadhaar number directly on the Platform.

  • During online account opening and KYC verification, you will be redirected to a UIDAI-authorised third-party service provider such as DigiLocker or CKYC;
  • Upon your explicit consent on such third-party platform, only the following limited details will be shared with Aspero: (i) the last four digits of your Aadhaar number or a Virtual ID (VID); (ii) full name; (iii) date of birth; (iv) gender; (v) address; and (vi) photograph;
  • Such Aadhaar-derived data is stored in encrypted and masked form and is never shared or disclosed in unmasked form; and
  • The use and storage of Aadhaar-derived information is strictly governed by the Aadhaar Act, 2016 and UIDAI regulations.
5.4

Obligation to Provide Accurate Data: As a user and Data Principal, you acknowledge and agree that you are solely responsible for providing complete, accurate, and up-to-date Personal Data to Aspero for the purposes of availing our Services. Inaccurate or incomplete data may result in your inability to complete KYC, access certain Services, or comply with regulatory obligations.

06

How We Collect Your Personal Data

6.1

Data Collected Directly from You

We collect Personal Data directly from you when you:

  • Register, create, or update an account on the Platform;
  • Complete the KYC and account opening process;
  • Submit investment orders or instructions;
  • Contact our customer support team;
  • Respond to surveys, promotions, or marketing communications;
  • Apply for career opportunities with us; or
  • Interact with any feature or form on the Platform.
6.2

Data Collected from Third-Party Sources

We may also collect Personal Data from authorised third-party sources, including:

  • KYC Registration Agencies (KRA) and Central KYC (CKYC) Registry;
  • Depositories (NSDL and CDSL) and Depository Participants;
  • Government databases including DigiLocker, UIDAI, and Income Tax Department portals;
  • Banks and financial institutions for account and mandate verification;
  • SEBI-authorised market infrastructure institutions (MIIs);
  • Payment gateways and settlement service providers; and
  • Authorised e-sign service providers.
6.3

Data Collected Automatically — Cookies and Tracking Technologies

We use cookies, web beacons, tracking pixels, and similar technologies to collect data automatically when you access or use the Platform. The cookies used on the Platform are categorised as follows:

Cookie NameCategoryPurposeDuration
aspero_csrf, aspero_auth, aspero_sess, aspero_keyNecessaryEssential for Platform security, authentication, login sessions, and fraud prevention. Cannot be disabled.Session / Persistent
aspero_lang, aspero_reg, aspero_theme, aspero_pref, aspero_viewFunctionalRemember your preferences such as language, theme, and notification settings to enhance your experience.Persistent (up to 1 year)
aspero_uuid, aspero_log, aspero_err, aspero_load, aspero_speed, aspero_durPerformanceCollect anonymised data on Platform usage, load times, error rates, and user journeys for analytics and optimisation.Session / Persistent
aspero_mkt, aspero_ad, aspero_px, aspero_re, aspero_src, aspero_segMarketingUsed to display relevant advertisements and track the effectiveness of marketing campaigns.Persistent (up to 2 years)

You may accept or reject non-essential cookies through the cookie preference centre on our Platform or through your browser settings. Please note that disabling necessary cookies may impair the functionality and security of the Platform.

6.4

Voice and Call Recording: We may record telephone calls and voice interactions with our customer service team for the purposes of quality assurance, training, dispute resolution, and regulatory compliance. You will be informed of recording at the start of such calls.

07

How We Process Your Personal Data

Aspero processes your Personal Data solely for specific, clear, and lawful purposes. We do not process your Personal Data for any purpose incompatible with those for which it was originally collected without your further consent (where required).

7.1

Account Creation and Platform Access: Creating and managing your user account on the Platform; verifying your identity and eligibility to access the Platform and Services; updating your dashboard and maintaining your investment profile; and enabling secure login and authentication.

7.2

KYC and Regulatory Compliance: Conducting Know Your Customer (KYC) verification as mandated by SEBI and other applicable regulators; processing and validating your financial information with regulated entities, financial institutions, and service providers; complying with Anti-Money Laundering (AML) and Combating the Financing of Terrorism (CFT) obligations under PMLA and RBI guidelines; maintaining records as required by SEBI, depositories, stock exchanges, and other regulatory bodies; and meeting data localisation requirements under Applicable Laws.

7.3

Service Delivery and Transaction Processing: Providing access to investment products and Services available on the Platform; processing your investment orders, redemptions, and transactions; settling transactions through authorised depositories and settlement agencies; processing coupon/interest payments and other disbursements to your registered bank account; verifying and updating your bank and demat account details; and facilitating e-sign for account opening and transaction documents.

7.4

Communication and Customer Support: Communicating with you regarding your account, transactions, and regulatory requirements; responding to your queries, complaints, and grievances; sending transactional notifications including order confirmations, contract notes, account statements, and tax documents; and sharing investor education content and platform updates.

7.5

Personalisation and Platform Improvement: Analysing your usage patterns to improve Platform design, functionality, and user experience; personalising investment recommendations and content where applicable; and conducting internal analysis, reporting, and business intelligence to enhance our Services.

7.6

Risk Management, Fraud Prevention, and Security: Conducting risk assessments, including investment suitability analysis; detecting, investigating, and preventing fraudulent activity, money laundering, and other illegal conduct; monitoring Platform access for unauthorised or suspicious activity; maintaining and testing our cybersecurity systems in compliance with SEBI CSCRF; and conducting internal and external audits.

7.7

Marketing and Promotions (With Your Consent): Sending marketing communications, newsletters, and promotional offers related to new products and Services — subject to your explicit consent for such marketing; and conducting surveys, market research, and feedback campaigns. You may withdraw your consent to marketing communications at any time by following the unsubscribe instructions in any marketing email or by contacting us directly.

7.8

Career Applications: Reviewing and assessing applications for employment or engagement with Aspero; and conducting background verification as permitted under applicable law.

7.9

Legal and Regulatory Obligations: Complying with court orders, directions from government authorities, and requests from law enforcement or regulatory agencies; protecting the legal rights and interests of Aspero, its employees, clients, and investors; and defending against legal claims and proceedings.

08

Disclosure of Your Personal Data

8.1

General Principles: Aspero will not disclose your Personal Data to any third party except in the circumstances described in this Policy, with your consent, or as required or permitted by Applicable Laws. All disclosures are made on a need-to-know basis, and recipients are subject to confidentiality obligations.

8.2

Disclosure to Regulated Entities and Market Infrastructure: As a SEBI-registered intermediary, Aspero is required to share your data with certain regulated entities in the ordinary course of providing Services:

  • Stock exchanges (BSE / NSE) and their clearing corporations;
  • Depositories (NSDL and CDSL) and your Depository Participant;
  • KYC Registration Agencies (KRA) and CKYC Registry;
  • Bond issuers, fixed deposit issuers, and other product originators on the Platform;
  • RBI, SEBI, and other regulatory authorities as mandated;
  • SCORES (SEBI Complaints Redress System) and SMART ODR Portal for grievance resolution; and
  • Payment system operators, clearing banks, and settlement agents.
8.3

Disclosure to Third-Party Service Providers: We work with third-party service providers who assist in delivering our services to you through the Platform. Your Personal Data may be shared with these service providers for website hosting, payment processing, KYC verification, identity authentication, financial data analysis, settlement of transactions, cloud storage, advertising, and marketing. Any Personal Data disclosed shall be limited to that which is strictly necessary for the performance of the services. A non-disclosure agreement (NDA) and/or a data processing agreement (DPA) will be signed with all third-party service providers.

8.4

Disclosure Upon Your Consent: Where Applicable Law requires us to obtain your prior express consent before disclosing your Personal Data to a third party not covered above, we will seek and obtain such consent before making the disclosure.

8.5

Disclosure for Business Transfers: In the event of a merger, acquisition, corporate restructuring, fund-raising, or sale of assets involving Aspero, your Personal Data may be disclosed in a secure manner to professional advisors, potential acquirers, or investors as part of due diligence, subject to appropriate confidentiality and data protection obligations. You will be notified of any such transaction to the extent required by Applicable Laws.

8.6

Disclosure Under Applicable Laws: We may disclose your Personal Data without prior notice if we are required to do so by law, including to respond to a court order or subpoena; comply with a direction from a government authority, law enforcement agency, or regulator; protect against or prevent fraud, security breaches, or unauthorized transactions; or protect the rights, property, or safety of Aspero, its employees, clients, or the public.

8.7

No Sale of Personal Data: Aspero does not sell, rent, or trade your Personal Data to any third party for commercial gain. Any disclosure of Personal Data is limited to what is strictly necessary for the performance of the Services or compliance with Applicable Laws.

09

Data Retention

We retain your Personal Data only for as long as is necessary to fulfill the specific purpose for which it was collected, or as required or mandated by Applicable Laws, whichever is longer. The following table summarises our key retention practices:

Data CategoryRetention PeriodLegal Basis
KYC / Account Opening Records8 years from account closurePMLA 2002; SEBI OBPP Circular; KRA Regulations
Behavioral and Usage DataDuration of relationship + 90 days following cessation of services or withdrawal of consentNecessary for platform optimization, fraud prevention, and ensuring a seamless user experience
Transaction Records (Orders, Contract Notes, Trade Confirmations)8 years from date of transactionSEBI (Stock Brokers and Sub-Brokers) Regulations, 1992; Depositories Act
Demat / Depository Records8 years from account closureNSDL Bye-Laws; Depositories Act, 1996
Voice Call Recordings90 days (or longer if subject to dispute or regulatory inquiry)SEBI CSCRF; Internal Policy
Access Logs and Monitoring RecordsMinimum 180 days as required by lawIT Act, 2000; CERT-In Directions
Marketing Communication Records (Consent Logs)Duration of relationship + 3 yearsDPDPA; TRAI Regulations
Grievance / Complaint Records3 years from resolutionSEBI Grievance Redressal Circular; DPDPA
Career Application Data (Unsuccessful)1 year from receipt unless consent given for longer retentionDPDPA
Investor Education and Interaction DataDuration of relationshipSEBI Investor Protection Guidelines
Data of Users Who Did Not Complete KYC60 days from account creation or withdrawal requestDPDPA; SEBI KYC Regulations
9.1

Cessation of Relationship and Data Deletion

  • Users who have not completed KYC and/or executed any transactions: We will delete your Personal Data within 60 (sixty) days of your request, subject to any legal hold requirements;
  • Users who have completed KYC and/or executed transactions: We will retain your Personal Data for the period required under Applicable Laws following the conclusion of your investment and withdrawal of funds; and
  • In all cases, Personal Data required to be retained under Applicable Laws will be retained for the duration mandated by law, following which it will be securely purged.
9.2

Secure Deletion: Once the applicable retention period has expired, Personal Data will be securely deleted, anonymised, or destroyed in a manner that prevents recovery or reconstruction, in accordance with Applicable Laws and our internal data disposal procedures.

10

Data Security

The security of your Personal Data is a primary obligation for Aspero. In accordance with Section 8(5) of the Digital Personal Data Protection Act, 2023, and the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF), we have implemented and maintain reasonable security safeguards — comprising technical, administrative, and physical controls — to prevent unauthorised access, accidental loss, or any other form of Personal Data breach.

10.1

Data Storage and Localisation: All Personal Data collected from users in India is stored on secure servers located within India, in compliance with applicable data localisation requirements under SEBI circulars and RBI guidelines. We do not transfer or store your Personal Data outside India except as specifically permitted by Applicable Laws.

10.2

Security Safeguards: Our security infrastructure includes, but is not limited to:

  • Industry-standard encryption (AES-256 or equivalent) for data at rest and TLS 1.2 or higher for data in transit;
  • Multi-factor authentication (MFA) for Platform access and high-value transactions;
  • Role-based access controls (RBAC) restricting access to Personal Data on a strict need-to-know basis;
  • Regular Vulnerability Assessment and Penetration Testing (VAPT) conducted by CERT-In empanelled auditors, including System Audit Reports (SAR) as mandated by SEBI;
  • Compliance with ISO 27001:2022 Information Security Management System standards;
  • Web Application Firewall (WAF), Intrusion Detection and Prevention Systems (IDS/IPS), and DDoS protection;
  • Secure Software Development Lifecycle (SDLC) practices; and
  • Regular security awareness training for employees and contractors.
10.3

User Responsibilities: As a Data Principal, you must: never disclose your username, password, OTP, or any other authentication credentials to any person, including Aspero employees (Aspero will never ask for your password); immediately report any suspected unauthorised access to your account to our customer support team; ensure that your registered mobile number and email address are kept up to date on the Platform; and log out of the Platform after each session, particularly when using shared or public devices.

10.4

Access Logs and Monitoring: We maintain detailed access logs and continuous monitoring systems to track all access to Personal Data and detect unauthorised access attempts. These logs are retained for a minimum of 180 days as required by Applicable Laws.

10.5

Enhanced Safeguards for Sensitive Personal Data (SPD): In addition to the general security safeguards described above, Aspero implements the following enhanced controls specifically for Sensitive Personal Data:

  • Encryption at Rest: All SPD stored on Aspero's servers is encrypted using AES-256, the industry standard mandated under SEBI CSCRF;
  • Encryption in Transit: All SPD transmitted between your device and the Platform is encrypted using TLS 1.3 (or TLS 1.2 where TLS 1.3 is not supported);
  • Aadhaar-Derived Data — Masking and Tokenisation: Aadhaar-derived data is maintained in permanently masked and encrypted form — only the last four digits of the Aadhaar number (or Virtual ID) are retained;
  • Financial Data — Field-Level Encryption: Bank account numbers, demat account identifiers, and PAN are stored with field-level encryption. Displayed values are masked in the user interface (e.g., bank account numbers are shown as XXXXXX followed by the last four digits only); and
  • Encryption Key Management: Encryption keys are managed through a dedicated Key Management System (KMS) and rotated at least annually in accordance with ISO 27001:2022 requirements and SEBI CSCRF guidelines.
11

Personal Data Breach — Detection and Notification

11.1

Detection and Internal Escalation: Upon detection of an actual or suspected Personal Data Breach, Aspero will immediately activate its Incident Response Plan. Our Security and Compliance teams will conduct a prompt assessment to determine the nature, scope, and likely impact of the breach.

11.2

Mandatory Notification to the Regulator: In compliance with Section 8(6) of the DPDPA and applicable SEBI CSCRF requirements, upon confirmation of a Personal Data Breach, Aspero will:

  • Notify the Data Protection Board of India (DPBI) without undue delay, and not later than 72 (seventy-two) hours of becoming aware of the breach;
  • Notify SEBI and other applicable regulators as required under SEBI CSCRF and relevant circulars; and
  • Cooperate fully with the Data Protection Board and all regulatory authorities during any investigation.
11.3

Notification to Affected Data Principals: We will notify you if a Personal Data Breach is likely to result in significant harm or risk to your privacy, rights, or freedoms. Such notification will be made via your registered email address and/or registered mobile number, and via a prominent notice on the Platform if the breach affects a large number of users, not later than 72 (seventy-two) hours after the risk assessment is complete.

11.4

Content of Breach Notification: Any breach notification provided to you will include: a clear description of the nature of the Personal Data Breach and the type of data affected; the approximate number of Data Principals and records concerned; the likely consequences resulting from the breach; the measures taken or proposed to be taken by Aspero to address the breach; contact information for our Grievance Officer; and steps you can take to protect yourself, including changing passwords or monitoring your financial accounts.

12

Your Rights as a Data Principal

As a Data Principal under the Digital Personal Data Protection Act, 2023, and subject to Aspero's obligations as a SEBI-registered intermediary and the requirements of other Applicable Laws, you have the following rights:

12.1

Right to Access and Correction: You have the right to obtain a summary of Personal Data that Aspero has processed about you; know the identities of all Data Fiduciaries and Data Processors with whom your Personal Data has been shared; and request correction or completion of any inaccurate, incomplete, or outdated Personal Data. We will action valid access or correction requests within 30 (thirty) days of receipt.

12.2

Right to Withdraw Consent: You may withdraw your previously given consent for the processing of your Personal Data at any time. Withdrawal of consent will not affect the lawfulness of any processing carried out prior to its withdrawal. Processing that is required under Applicable Laws (including KYC maintenance, AML compliance, and regulatory reporting) will continue even after withdrawal of consent. You may withdraw consent by contacting our Compliance Team or through the account settings on the Platform.

12.3

Right to Erasure: You may request the erasure of your Personal Data. However, this right is subject to applicable legal retention obligations. We will not be able to erase data that we are required to retain under Applicable Laws (including SEBI regulations, PMLA, and DPDPA). Upon expiry of the applicable retention period, data will be securely deleted as described in Section 9.

12.4

Right to Nominate: You have the right to nominate another individual to exercise your data rights on your behalf in accordance with the DPDPA, including in the event of your death or incapacity. You may exercise this right by emailing our Data Privacy Team with the subject line "Data Principal Nomination." We will require basic identity verification for both you and your nominee.

12.5

Right to Grievance Redressal: If you have any grievances regarding the processing of your Personal Data or a breach of this Policy, you have the right to register a grievance with our Privacy Office (see Section 17). We will respond to all legitimate grievances within 30 (thirty) days. If not satisfied with our response, you may escalate the matter to the Data Protection Board of India.

12.6

Right to Opt-Out of Automated Decision-Making: We may use automated systems to process your data for service personalisation and credit eligibility. Under the DPDPA, you have the right to be informed when a significant decision is made solely by automated means; to request a manual review of any automated decision that significantly impacts you; and to object to automated profiling used for marketing or behavioral tracking. To contest a decision or opt-out, please contact our Privacy Office at privacy@aspero.in.

12.7

How to Exercise Your Rights: You may exercise any of the rights described above by writing to our Privacy Team at privacy@aspero.in. Please include your registered name, registered mobile number, and a description of your request. We may request additional information to verify your identity before processing your request.

13

Your Duties as a Data Principal

As a user of the Platform and a provider of Personal Data, you are expected to fulfill the following duties in accordance with applicable legal, regulatory, and contractual obligations:

(a)

Information Accuracy: You must ensure that all Personal Data submitted to Aspero is accurate, complete, and up to date. You are expected to promptly notify us of any changes to your information, including changes to your residential status, marital status, contact details, bank account, or demat account.

(b)

No Impersonation or Misrepresentation: You must not provide false, misleading, or another person's Personal Data. Impersonation or misrepresentation of identity is a violation of Applicable Laws.

(c)

Proper Conduct: You must not submit false grievances, misuse data access rights, or engage in any conduct that disrupts or impairs the Platform or its Services.

(d)

Compliance with Applicable Laws: Any access requests, grievances, or exercise of data rights must be legitimate, in good faith, and compliant with the DPDPA, this Policy, and all other Applicable Laws.

(e)

Account Security: You are responsible for maintaining the confidentiality of your login credentials and for all activities conducted through your account. Aspero shall not be liable for losses arising from your failure to secure your credentials.

15

Minors and Children

The Platform and Services are not directed at, intended for, or designed to be used by individuals below the age of 18 years. Aspero does not knowingly collect Personal Data from minors. If you are a parent or guardian and believe that your child has provided Personal Data to Aspero without your consent, please contact us immediately at privacy@aspero.in. We will take prompt steps to delete such data upon verification.

16

Updates to This Policy

Aspero may modify this Policy from time to time to reflect:

  • Changes in Applicable Laws (including amendments to the DPDPA, new SEBI circulars, or regulatory directions);
  • Changes in our data processing practices, Services, or Platform features; or
  • Changes in our business structure or operations.

We distinguish between two types of changes:

  • Material Changes: Changes that significantly affect your rights or the way we process your Personal Data — for example, introducing new processing purposes, adding new third-party sharing arrangements, or materially altering your rights. For material changes, we will provide prior notice via a prominent notice on the Platform, email notification to your registered address, and/or in-app notification, before the change takes effect.
  • Administrative or Minor Changes: Corrections to typographical errors, updates to contact information, or clarifications that do not affect your rights. These take effect immediately upon posting.

The updated Policy will be published on the Platform with the revised effective date. Continued use of the Platform or Services after the effective date of any update constitutes your acknowledgment of and agreement to the revised Policy. If you disagree with any material change, you may withdraw your consent and/or close your account, subject to our mandatory legal data retention obligations.

17

Grievance Redressal

If you have any complaints, concerns, or grievances about the manner in which Aspero collects, processes, or handles your Personal Data, you may contact our Privacy Team. We will take all reasonable steps to resolve your grievance in an expeditious and effective manner.

NamePrivacy Team
Emailprivacy@aspero.in
AddressAspero Markets Private Limited, 12th Floor, Prestige Polygon, No. 471, Anna Salai, Nandanam, Chennai – 600 035, Tamil Nadu, India
Response Timeline30 (thirty) days from receipt of a written grievance
17.1

Escalation to SEBI and Regulatory Bodies: If your grievance is not resolved to your satisfaction through our internal mechanism, you may escalate to:

  • SEBI SCORES Portal: https://scores.sebi.gov.in (for securities market related complaints);
  • SMART ODR Portal: https://smartodr.in/login (for online dispute resolution);
  • Data Protection Board of India (DPBI): by writing to mljoffice@gov.in — the regulatory authority established under the DPDPA; and
  • NSE Investor Service Cell / BSE Investor Services: for exchange-related complaints.

Filing complaints on SCORES is easy and quick: (1) Register on the SCORES portal; (2) Provide mandatory details including Name, PAN, Address, Mobile Number, and Email ID; (3) Submit your complaint electronically for effective communication and speedy redressal.

18

Governing Law and Dispute Resolution

18.1

Governing Law: This Privacy Policy and all matters related thereto shall be governed by and construed in accordance with the laws of the Republic of India, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, SEBI regulations, and all other Applicable Laws and the rules and regulations framed thereunder.

18.2

Dispute Resolution Hierarchy: In the event of any grievance or dispute relating to the processing of your Personal Data or a breach of this Policy, the following resolution hierarchy shall apply:

  • Step 1 — Internal Grievance Redressal: As a first step, you are required to exhaust the Company's internal grievance redressal mechanism by contacting our Privacy Office (as detailed in Section 17). We are committed to resolving your concerns within 30 (thirty) days.
  • Step 2 — SEBI SCORES / SMART ODR: For investment-related disputes, you may raise a complaint on the SEBI SCORES portal (https://scores.sebi.gov.in) or seek resolution through the SMART ODR portal (https://smartodr.in/login).
  • Step 3 — Data Protection Board of India: If you are not satisfied with the resolution provided by our Grievance Officer, or if your grievance pertaining to data protection remains unresolved, you have the right to lodge a complaint with the Data Protection Board of India (DPBI).
18.3

Civil Jurisdiction: Subject to the specialized jurisdiction of the Data Protection Board of India and the Appellate Tribunal under the DPDPA, all other legal proceedings arising out of or in connection with this Policy shall be subject to the exclusive jurisdiction of the courts of competent jurisdiction located in Chennai, Tamil Nadu, India.

Questions about your data?

Write to us at privacy@aspero.in. This Policy is issued by Aspero Markets Private Limited, Chennai, and may be updated from time to time; the version posted here is effective May 2026.