AMFI-Registered Mutual Fund Distributor | ARN: 151181
PRIVACY POLICY
Website, Mobile Application & Digital Services
Dhhuria Family Office Private Limited | myfirstgoal.in | MyFirstGoal App
Entity: Dhhuria Family Office Private Limited
Brand: MyFirstGoal
CIN: U93090PB2017PTC046252 | ARN: 151181 | GSTIN: 03AAGCD0871M1ZN
Address: Street No. 2, Ganesh Nagar, Near Gaushala, Bathinda, Punjab 151001
Email: support@myfirstgoal.in | Phone: +91 9888465065 | Web: www.myfirstgoal.in
Effective Date: 01/03/2026 | Last Updated: March 2026 | Version: 2.0
This Privacy Policy applies to: the website www.myfirstgoal.in, the MyFirstGoal mobile application (Android & iOS), WhatsApp Business communications, email correspondence, phone interactions, and all digital services provided by the entity.
- Introduction
Dhhuria Family Office Private Limited (hereinafter referred to as ‘we’, ‘us’, ‘our’, or ‘the Company’), operating under the brand name ‘MyFirstGoal’, is an AMFI-Registered Mutual Fund Distributor (ARN: 151181). We are committed to protecting the privacy and personal data of all individuals who visit our website, use our mobile application, or engage with our services.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you interact with us through any medium — website, mobile app, WhatsApp, email, phone, or in person.
This policy is published in compliance with:
- Digital Personal Data Protection Act, 2023 (DPDPA 2023)
- Information Technology Act, 2000 and IT (Reasonable Security Practices) Rules, 2011
- SEBI Master Circular for Mutual Funds
- AMFI Master Circular for MFDs and Code of Conduct — Data Sharing Principles
By accessing our website, downloading our app, signing up for our services, or providing us your personal information, you acknowledge that you have read, understood, and agree to this Privacy Policy.
- Data Fiduciary
Under the DPDPA 2023, we act as the Data Fiduciary — the entity responsible for determining the purpose and means of processing your personal data.
Data Fiduciary: Dhhuria Family Office Private Limited
Grievance Officer: Mr. LLovegeet Dhuria (Director)
Email for Privacy Queries: support@myfirstgoal.in
Phone: +91 9888465065
Address: Street No. 2, Ganesh Nagar, Near Gaushala, Bathinda, Punjab 151001
- Personal Data We Collect
We collect the following categories of personal data depending on how you interact with us:
3.1 Identity Data
- Full name (as per PAN card)
- PAN (Permanent Account Number)
- Aadhaar number (masked/last 4 digits for KYC verification)
- Date of birth, gender, nationality, and residential status
- Photograph and signature (for KYC)
3.2 Contact Data
- Residential and correspondence address
- Email address, mobile number, WhatsApp number
- Landline number (if provided)
3.3 Financial Data
- Bank account details (account number, IFSC, bank name, branch)
- Income details, occupation, and employer information
- Investment objectives, risk profile, and existing portfolio details
- Tax filing status and tax residency
3.4 Transaction Data
- Mutual fund folio numbers and scheme details
- Transaction history — purchase, SIP, redemption, switch, STP, SWP
- SIP registration and bank mandate details
3.5 Technical Data (Website & App)
- IP address, device identifier, browser type, and operating system
- Device model, screen resolution, and app version
- Pages visited, time spent, click patterns, and navigation path
- Cookies and similar tracking technologies
- Push notification token (mobile app)
- App crash reports and performance logs
- Approximate location derived from IP address (NOT precise GPS location)
3.6 Communication Data
- Email and WhatsApp correspondence
- Phone call records (date, time, duration — not recordings unless separately disclosed)
- Meeting notes, feedback, and survey responses
- Complaint and grievance records
3.7 KYC & Regulatory Data
- CKYC / KRA verification status
- FATCA / CRS declarations
- Nomination details and PEP status declaration
3.8 Data Collected by Mobile App — Specific Declarations
If you use the MyFirstGoal mobile application, we additionally collect:
- Device ID and unique app instance identifier
- Push notification preferences and tokens
- Camera access — ONLY for KYC photo/document upload, with your explicit permission
- Storage access — ONLY for downloading statements/reports as PDF, with your explicit permission
We explicitly declare that the following data is NOT collected by our mobile app:
- Phone Contacts — NOT accessed
- SMS messages — NOT read or accessed
- Call logs — NOT accessed
- Microphone — NOT accessed
- Precise GPS location — NOT collected
- Purpose of Data Collection & Processing
We collect and process your personal data strictly for the following lawful purposes:
- Mutual Fund Distribution — Processing transactions (purchase, SIP, redemption, switch, STP, SWP) via BSE STAR MF platform on your behalf.
- KYC/CKYC Compliance — Verifying your identity as mandated by SEBI, AMFI, and KYC Registration Agencies before processing any transaction.
- Risk Profiling — Assessing your risk tolerance, capacity, and required risk using the NFP Risk Profiler to determine suitable mutual fund categories for you.
- Suitability Assessment — Matching recommended schemes to your assessed risk profile as per SEBI Master Circular requirements.
- Portfolio Servicing — Generating portfolio reports, account statements, performance reviews, and rebalancing recommendations.
- Communication — Sending transaction confirmations, SIP reminders, market updates, scheme information, NAV alerts, and regulatory notices via email, WhatsApp, SMS, or push notifications.
- Grievance Redressal — Processing and resolving investor complaints within prescribed timelines.
- Regulatory Reporting — Filing returns and reports as required by SEBI, AMFI, income tax authorities, and other regulatory bodies.
- Audit & Compliance — Maintaining records for AMFI DDQ audit, internal self-audit, and regulatory inspections.
- Service Improvement — Analysing website and app usage patterns to improve user experience, fix technical issues, and enhance functionality.
- Legal Obligations — Complying with court orders, legal processes, and regulatory directions.
We do NOT collect or process personal data for any purpose beyond what is stated above. We do NOT sell, rent, trade, or share your data with any third party for advertising, marketing, or commercial purposes.
- Data Sharing & Third-Party Processors
Your personal data is shared only with the following authorised entities for the specific purposes mentioned. All data processors are bound by contractual obligations to protect your data:
- BSE STAR MF — Mutual fund transaction processing platform
- CAMS (Registrar & Transfer Agent) — Folio management, Consolidated Account Statements
- KFintech (Registrar & Transfer Agent) — Folio management, Consolidated Account Statements
- MF BOX — KYC verification and processing
- Asset Management Companies (AMCs) — Investment processing, servicing, commission
- Sanchay CRM — Client relationship management system
- Redvision / Advisorkhoj / IFA Now — Back-office analytics, portfolio reporting
- NGen Market — Scheme research and analytics (no personal investor data shared)
- AnchorEdge / MasterStroke — Marketing material creation (no personal investor data shared)
- KYC Registration Agencies (KRAs) — CKYC compliance and verification
- SEBI / AMFI / Tax Authorities — Regulatory reporting and audit as required by law
- Google Play Store / Apple App Store — App distribution, crash reporting, anonymised analytics
[Hosting Provider — Please fill: e.g., AWS / GoDaddy / Hostinger / Bluehost — Website and app hosting infrastructure
We do NOT share your personal data with any entity other than those listed above for the stated purposes.
- Cookies & Tracking Technologies
Our website and mobile app use cookies and similar technologies to enhance your experience:
- Essential Cookies — Required for the website/app to function (session management, authentication, security). These cannot be disabled.
- Analytics Cookies — Help us understand how visitors use our website/app (pages visited, time spent, bounce rate). Powered by Google Analytics or similar tools. Retained for up to 12 months.
- Functional Cookies — Remember your preferences such as language, display settings, and login status. Retained for up to 6 months.
- Push Notification Tokens (Mobile App Only) — Used to send transaction alerts, SIP reminders, and market updates. Can be disabled in app settings or device settings.
You can manage cookie preferences through your browser settings. Disabling essential cookies may affect website functionality. Our mobile app does not use advertising or third-party tracking cookies.
- Data Retention Policy
We retain your personal data only for as long as necessary to fulfil the purposes stated in this policy, or as required by applicable law:
- Active Client Data — Throughout the period of engagement plus 8 years after last transaction, as per SEBI/AMFI requirements.
- KYC Records — As mandated by KYC Registration Agency regulations and PMLA requirements.
- Transaction Records — Minimum 8 years from date of transaction.
- Complaint Records — Minimum 8 years from date of resolution/closure.
- Communication Records — 8 years for client communications. 10 years for regulatory communications.
- Website/App Analytics — Anonymised analytics retained for 24 months. Personal identifiers purged after 12 months.
- App Crash Logs — 6 months from date of incident.
- Inactive Client Data — If no transaction for 3 consecutive years, data is archived with restricted access. Retained for the regulatory period, then securely deleted.
Upon expiry of the retention period, or upon a valid erasure request (subject to regulatory retention obligations), data is securely deleted or anonymised.
- Your Rights as Data Principal (DPDPA 2023)
Under the Digital Personal Data Protection Act, 2023, you have the following rights:
- Right to Access — Request a summary of your personal data held by us and details of processing activities performed on your data.
- Right to Correction — Request correction of any inaccurate, incomplete, or misleading personal data.
- Right to Erasure — Request deletion of your personal data. Note: SEBI and AMFI require us to retain certain data for prescribed periods even after your request. We will inform you of any data that cannot be erased due to regulatory obligations.
- Right to Nomination — Nominate any individual to exercise your data protection rights on your behalf in the event of your death or incapacity.
- Right to Grievance Redressal — Lodge a privacy-related complaint with our Grievance Officer (details in Section 2). We will acknowledge within 48 hours and resolve within 30 days.
- Right to Approach Data Protection Board — If not satisfied with our response, you may file a complaint with the Data Protection Board of India as established under DPDPA 2023.
- Right to Withdraw Consent — Withdraw your consent for data processing at any time by writing to support@myfirstgoal.in. Withdrawal of consent may impact our ability to provide distribution services and may require closure of your account. Consequences will be communicated before processing.
9. Data Security Measures
We implement the following technical and organisational measures to protect your personal data:
- Access Controls — Role-based access to client data. Only authorised personnel (Directors and designated staff) can access investor records. Access logs are maintained.
- Encryption — Sensitive data (PAN, Aadhaar, bank details) stored with encryption at rest. All data transmitted via HTTPS/SSL encrypted connections.
- Password Protection — All platform credentials (BSE STAR MF, Sanchay CRM, Redvision, MF BOX) are password-protected with mandatory periodic rotation.
- Physical Security — Paper records stored in locked cabinets with restricted key access. Office premises are secured.
- Device Security — Work devices are password-protected and encrypted. Remote wipe capability for mobile devices.
- Data Backup — Regular encrypted backups with secure off-site/cloud storage.
- Incident Response — Any suspected data breach will be reported to affected Data Principals and the Data Protection Board of India within 72 hours of discovery, as required under DPDPA 2023.
- Vendor Security — All data processors (listed in Section 5) are contractually bound to maintain equivalent security standards.
- Periodic Review — Security practices reviewed semi-annually. Vulnerabilities assessed and addressed promptly.
- Children’s Privacy
We do not knowingly collect personal data from children below the age of 18 years without verifiable parental consent. Mutual fund investments in the name of a minor are processed through the parent/legal guardian’s account as per SEBI regulations.
If you are a parent or guardian and believe that your child has provided us with personal data without your consent, please contact us at support@myfirstgoal.in, and we will take steps to delete such data.
The MyFirstGoal mobile application is intended for users aged 18 years and above. We do not target, collect data from, or market to children.
- Third-Party Links & Services
Our website and app may contain links to third-party websites including AMC websites, SEBI, AMFI, CAMS, KFintech, MF Central, and other financial service portals. We are not responsible for the privacy practices of these third-party websites. We encourage you to read their respective privacy policies before providing any personal information.
Third-party services embedded in our app (e.g., Google Analytics, Firebase, push notification services) may collect technical data as described in Section 3.5. We ensure that such services comply with applicable privacy regulations.
- Consent Mechanism
We obtain your consent for data processing through the following mechanisms:
- At Client Onboarding — Explicit consent obtained via signed Client Data Gathering Form and/or electronic consent on BSE STAR MF platform.
- On Website — By using our website, you consent to the use of essential cookies. Analytics cookies require your explicit acceptance via cookie consent banner.
- On Mobile App — App permissions (camera, storage) are requested individually at the time of use with clear explanation of purpose. You can revoke permissions at any time through your device settings.
- For Communications — Consent for marketing communications (WhatsApp broadcasts, email newsletters) is obtained at onboarding. You may unsubscribe at any time by replying ‘STOP’ or clicking ‘Unsubscribe’.
You may withdraw consent at any time by writing to support@myfirstgoal.in. We will process the withdrawal within 7 working days. Consequences of withdrawal will be communicated before processing.
- Cross-Border Data Transfer
Your personal data is primarily stored and processed within India. In some cases, data may be processed by cloud service providers or analytics platforms whose servers may be located outside India.
In such cases, we ensure that:
- The data transfer complies with DPDPA 2023 requirements for cross-border data transfer.
- The receiving jurisdiction is not on the restricted list notified by the Central Government under DPDPA 2023 Section 16(1).
- Adequate contractual safeguards are in place to protect your data.
[Note: Update this section once the Central Government notifies the restricted jurisdiction list under DPDPA 2023 Section 16(1).]
- Mobile App — Play Store & App Store Disclosures
This section provides additional disclosures required by Google Play Store and Apple App Store policies.
14.1 Google Play Store — Data Safety Declarations
- App Name: MyFirstGoal
- Developer: Dhhuria Family Office Private Limited
- Data Collected: Identity (Name, PAN), Contact (Email, Phone), Financial (Bank, Income), Location (Approximate, from IP only)
- Data Shared With: BSE STAR MF, AMCs, RTAs, CRM — strictly for transaction processing and regulatory compliance
- Data NOT Collected: Contacts, SMS, Call Logs, Precise Location, Photos/Videos (except for KYC upload with explicit permission)
- Data NOT Shared for Advertising: Data is never shared with third parties for advertising, marketing, or commercial purposes
- Data Encryption: Yes — encrypted in transit (HTTPS/SSL) and at rest
- Data Deletion: Users can request account and data deletion by emailing support@myfirstgoal.in. Processed within 30 days, subject to regulatory retention.
14.2 Apple App Store — App Privacy Labels
- Data Used to Track You: NONE — We do not track users across other apps or websites
- Data Linked to You: Name, Email, Phone, Financial Info, Investment Data (linked to your account for service delivery)
- Data Not Linked to You: Analytics data, crash logs (collected anonymously)
- Purpose Categories: App Functionality, Account Management, Analytics (first-party only)
- Account Deletion: Available via email request to support@myfirstgoal.in. Processed within 30 days.
14.3 App Permissions
Permissions required and not required by the MyFirstGoal app:
- Internet Access — Required for all app functionality
- Camera — Optional. Only for KYC document upload and selfie verification. Requested at time of use.
- Storage — Optional. Only for downloading portfolio reports as PDF. Requested at time of use.
- Push Notifications — Optional. For SIP reminders, transaction alerts, market updates. Can be disabled.
- Biometric / Fingerprint — Optional. For app login security. Biometric data stored only on device, NOT on our servers.
Permissions NOT required by our app:
- Contacts — NOT accessed
- SMS — NOT read or accessed
- Call Logs — NOT accessed
- Microphone — NOT accessed
- Precise GPS Location — NOT collected
- Changes to This Privacy Policy
We reserve the right to update this Privacy Policy at any time. Changes will be communicated through:
- Prominent notice on our website (www.myfirstgoal.in)
- In-app notification on the MyFirstGoal mobile app
- Email notification to registered users for material changes
The updated policy will include the revised ‘Last Updated’ date at the top. Continued use of our services after changes constitutes acceptance of the updated policy.
- Grievance Officer & Contact
For any privacy-related concerns, data access requests, correction requests, erasure requests, or complaints, please contact:
Grievance Officer: Mr.LLovegeet Dhuria, Director
Email: support@myfirstgoal.in
Phone: +91 9888465065
Address: Street No. 2, Ganesh Nagar, Near Gaushala, Bathinda, Punjab 151001
Response: Acknowledgement within 48 hours. Resolution within 30 days.
If not satisfied with our response, you may approach the Data Protection Board of India under DPDPA 2023.
- Governing Law & Jurisdiction
This Privacy Policy is governed by the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, SEBI regulations, and AMFI guidelines. Any dispute arising out of this policy shall be subject to the exclusive jurisdiction of the courts in Bathinda, Punjab, India.
- Acknowledgement
By using our website, downloading our app, or engaging with our services, you acknowledge that:
- You have read and understood this Privacy Policy in its entirety.
- You consent to the collection, processing, storage, and sharing of your personal data as described herein.
- You understand your rights under DPDPA 2023 as described in Section 8.
- You may withdraw consent at any time, subject to the consequences communicated to you.
Mutual Fund investments are subject to market risks, read all scheme related documents carefully.
AMFI-Registered Mutual Fund Distributor | ARN: 151181