Website Privacy Notice
1. Who we are
This Privacy Notice is issued by Apex Fund Services LLP and Apex Fincore LLP, BEST Alternative Advisory Services LLP, Annet Technologies (Mumbai) LLP, and Annet Retransform (Gujarat) LLP, as applicable (together “Apex India”, “us” or “we”). The relevant Apex India entity acts as the Data Fiduciary for the personal data described in this notice, except where it processes personal data solely on behalf of a client or another Data Fiduciary as a Data Processor. Apex India is part of the Apex Group. For more information on Apex Group please visit www.apexgroup.com.
2. About this notice
This privacy notice covers how Apex India, acting as a Data Fiduciary where it determines the purposes and means of processing, collects, uses, discloses, transfers and stores your personal data in connection with your interactions with Apex India via our website, as a client, a prospective client, a vendor, an event attendee or a website user. Where an Apex India entity processes personal data solely on a client’s documented instructions, that client may be the Data Fiduciary for that processing and its privacy notice may also apply. This notice summarises the personal data processed, the specified purposes and applicable legal basis, your rights as a Data Principal, and the safeguards we use to protect your data. For employees and job candidates, the employee privacy notice and candidate privacy notice will apply respectively.
In relation to personal data processed under this privacy notice, Apex India is responsible for ensuring that such processing complies with the Digital Personal Data Protection Act, 2023 (the “DPDPA”), the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules”) and other applicable Indian data protection and privacy laws, subject to the applicable statutory commencement dates. Under the DPDPA, an individual to whom personal data relates is a “Data Principal”; an entity that determines the purpose and means of processing is a “Data Fiduciary”; and an entity that processes personal data on behalf of a Data Fiduciary is a “Data Processor”.
3. What personal data Apex India collects and where we get it from
“Personal data” means any data about an individual who is identifiable by or in relation to such data. We collect only the personal data that is reasonably necessary for the specified purposes described in this notice and as otherwise permitted by the DPDPA.
We will collect and process the following personal data about you, depending on your relationship with us and how you use our website:
Categories of Data Principals | Personal data processed |
|---|---|
Representatives of delegates, investment funds and service providers (including directors) |
|
Ultimate beneficial owners of delegates and service providers |
|
Representatives of regulators and other public authorities |
|
Representatives and employees of clients and vendors |
|
Office visitors |
|
Attendees of events organised by Apex India |
|
Marketing recipients and subscribers to Apex India communications |
|
Website users |
|
We do not intentionally collect categories of personal data beyond what is reasonably necessary for the specified purposes. In limited circumstances, we may process information that may reveal health or accessibility requirements, biometric identifiers, criminal-record information or other sensitive information where necessary for legal, regulatory, security, AML/KYC, event or service purposes. We will provide any notice and obtain any consent required by applicable law and apply appropriate safeguards. Apex India does not intend to collect or process personal data relating to children in the ordinary course of its business. If child personal data is identified or proposed for processing, we will review the activity before processing begins and implement processes to obtain verifiable consent from the parent or lawful guardian where required under the DPDPA and DPDP Rules.
We collect this data in a variety of ways, mainly directly from you when you contact us, use our website, request information, enter into or perform an agreement, receive services from us or provide services to us, including:
Information set out in any agreements entered into with us;
As part of client due diligence and onboarding documentation, including ongoing due diligence;
When you register for our events, subscribe to our newsletters or mailing lists, or submit a form through our website; and
Personal data provided by you in correspondence with us by telephone, email, online forms or otherwise.
We also collect information from third parties or publicly available sources. These may include lawyers, accountants and professional advisers; other financial institutions and service providers; credit reference agencies and financial crime databases; regulators and public authorities; and other Apex Group companies, where permitted by applicable law.
Website and cookies: we may collect your personal data through your use of our website via cookies and similar technologies. These technologies help us provide an optimised experience, understand how you use the website, provide personalised features and content, deliver advertisements, and ensure that the website functions correctly. Where required by law, we will obtain your consent before using non-essential cookies. You can manage or withdraw cookie consent through the cookie controls or by contacting us. For further information, please see our cookie notice here.
4. How do we use your personal data?
Categories of Data Principals | Specified purpose and applicable DPDPA basis |
|---|---|
Representatives of delegates, investment funds and service providers (incl. directors) |
|
Ultimate beneficial owners of delegates and service providers |
|
Representatives of regulators and other public authorities |
|
Office visitors |
|
Attendees of events organised by Apex India |
|
Marketing recipients and subscribers to Apex India communications |
|
Website users |
|
Where we rely on consent, consent must be free, specific, informed, unconditional and unambiguous, and given through clear affirmative action. You may withdraw consent with ease comparable to the way consent was given. Withdrawal will not affect processing carried out before withdrawal, and we may continue processing where the DPDPA or another applicable law permits or requires us to do so. The DPDPA does not recognise “legitimate interests” as an independent lawful basis. Any reference in this notice to DPDPA legitimate uses means only those legitimate uses permitted under the DPDPA.
5. Use of AI and Automated Technologies
We may use artificial intelligence and other automated technologies to support website functionality and security, analyse interactions, assist with repetitive or administrative tasks, improve our services, and help detect fraud or other risks. We assess these tools and the providers that support them, limit their use to the purposes described in this notice, and maintain appropriate safeguards and human oversight where appropriate. We do not use solely automated processing to make a decision that produces legal or similarly significant effects on you without safeguards required by applicable law. If you have questions about our use of AI or automated technologies or wish to exercise a right relating to such processing, contact the India Grievance Officer using the details in section 12.
6. Disclosure and Sharing of Data
Your personal data may be disclosed to Data Processors and other third parties in connection with the services we provide, our website and the specified purposes in this notice. Recipients depend on the services, relationships and permissions applicable to the processing.
Subject to confidentiality and applicable law, such disclosures may include:
to other entities in the Apex Group for the purposes described in this privacy notice;
to Data Processors and third-party service providers, including website hosting, data analysis, client research, payment processing, order fulfilment, information technology and related infrastructure, customer service, email delivery, auditing and other services;
to professional advisers and agents, including legal counsel, notaries, auditors and tax advisers;
to payment, banking and communications infrastructure providers, financial institutions or intermediaries, insurers and insurance brokers, central counterparties, clearing houses, settlement systems, exchanges, trading platforms, regulated markets, credit institutions and other providers assisting with transactions;
to storage providers, archive service providers, document repositories and trade data repositories;
to distribution platforms, communications or transmission facilities and mail or courier services;
to transaction participants, including issuers, borrowers, advisers and translation service providers, and in prospectuses and marketing materials where relevant;
to counterparties, vendors, beneficiaries and other entities connected with our clients;
to other persons where agreed with you or a client, or as required or expressly permitted by applicable law;
to regulators, government authorities, central banks, courts, law-enforcement agencies and approved reporting mechanisms, including those outside India where permitted by applicable law; and
to litigation counterparties and other persons where reasonably necessary to enforce our terms, prepare for or conduct litigation, arbitration or similar proceedings, or comply with legal and regulatory requirements.
Where personal data is transferred within the Apex Group or to a third party in another jurisdiction, including outside India, we will take appropriate steps to ensure that the transfer is permitted under the DPDPA and other applicable Indian law, including any restrictions or conditions prescribed by the Central Government, and that appropriate contractual, organisational and technical safeguards are in place. Data Processors may use personal data only on our documented instructions for the specified purposes, must keep it confidential and must not further share it except as permitted by us or applicable law.
7. Retention of your personal data
We will retain your personal data only for as long as it is reasonably necessary to fulfil the specified purposes for which it was collected, unless a longer period is required or permitted by applicable law. We consider the amount, nature and sensitivity of the personal data, the risk of harm from unauthorised use or disclosure, the purposes and whether they can be achieved through other means, and applicable legal, regulatory, accounting and dispute-related requirements. When the purpose is no longer served and retention is not otherwise required, we will delete or anonymise the personal data in accordance with our retention procedures.
8. Security of personal data
We use reasonable security safeguards appropriate to the risk of processing, including access controls, confidentiality obligations, secure systems and technical and organisational measures designed to prevent personal data from being accidentally lost, destroyed, altered, disclosed or accessed in an unauthorised way. We limit access to people and service providers who have a legitimate need to know and require them to process personal data only as instructed and subject to confidentiality obligations.
We maintain procedures to detect, assess and respond to suspected personal data breaches. Where required by the DPDPA, DPDP Rules or other applicable law, we will notify the Data Protection Board of India without delay and provide prescribed further information within seventy-two (72) hours, or within any extended period permitted by the Board. Where Apex India acts as a Data Fiduciary, we will also notify affected Data Principals without delay in a concise, clear and plain manner and include the information prescribed under applicable law.
9. Your choices and rights as a Data Principal
Subject to the DPDPA and other applicable law, you may exercise your rights as a Data Principal by contacting the India Grievance Officer using the details in section 12. We may ask for information to verify your identity and authority before responding.
Under the DPDPA, your rights may include the rights listed below. We aim to acknowledge requests promptly and, pending any different statutory requirement, operate to an internal target of acknowledgement within 3 business days and closure within 30 calendar days where reasonably practicable.
Right to access information: You may request information about the personal data we process, the manner in which it is processed, and other information required to be provided under the DPDPA.
Right to correction and updating: You may request correction, completion and updating of inaccurate or incomplete personal data.
Right to erasure: You may request erasure of personal data that is no longer necessary for the specified purpose, subject to applicable legal retention requirements.
Right to withdraw consent: You may withdraw consent at any time by contacting us or using the relevant preference controls, with ease comparable to giving consent. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal. It may affect our ability to provide certain services or features, and we may continue processing where another lawful basis applies.
Right to grievance redressal: You may raise a grievance about our processing or our response to a rights request with the India Grievance Officer (use the contact details set out in section 12 below).
Right to nominate: You may nominate another individual, in the manner prescribed by applicable law, to exercise your rights under the DPDPA in the event of your death or incapacity.
We may be unable to comply with a request, or may provide limited access, where permitted or required by applicable law, including to protect the rights of another individual, comply with legal or regulatory obligations, preserve confidentiality, prevent fraud or protect security. We will explain the reasons where permitted and tell you how to raise a grievance with the India Grievance Officer.
If we are unable to comply with your request, we will notify you of the reasons (unless prohibited by law) and explain how to raise a grievance with the India Grievance Officer and, after using that route, how to complain to the Data Protection Board of India.
10. Recording of communications
When individuals communicate with Apex India by telephone and electronic communications, including emails, text messages and instant messages, we may record or monitor those communications for evidentiary, compliance, quality assurance, security and governance purposes, or as required or permitted by applicable law.
11. Email marketing and unsubscribing
You can stop the delivery of marketing emails from Apex India at any time by unsubscribing or opting out via the link included in every email. Alternatively, you can make a direct request to unsubscribe by contacting the India Grievance Officer using the contact details in section 12.
12. How to contact us
If you have concerns or questions about this privacy notice or would like to exercise your rights as a Data Principal, you can contact the India Grievance Officer, who is responsible for receiving, acknowledging and coordinating responses to Data Principal grievances and rights requests:
India Grievance Officer: Head of Compliance & Data Protection, India
Email: IndiaDPO@apexgroup.com
Post: Apex Group, Unit No 1302, 13th Floor, 656 Hiranandani Signature, GIFT SEZ, GIFT City, Gandhinagar, Gift City, Gujarat-382355, India
13. Right to lodge a complaint with the Data Protection Board of India
If you are not satisfied with our response, or if your grievance is not resolved within the period prescribed by applicable law, you may complain to the Data Protection Board of India in accordance with the DPDPA and applicable rules. Please first use the grievance redressal route in section 12. Complaints may be filed through the procedure and official channels prescribed by the Board.
Other remedies: This complaint route does not limit any other remedy available to you under applicable law.
14. Updates
We will update this privacy notice when necessary to reflect changes in the DPDPA, other applicable law, our practices and our services, as well as to ensure it is accurate and up to date. When we make an update we will amend the date at the top of this notice, and you are therefore advised to check this privacy notice periodically. We may also notify you in other ways from time to time about the processing of your personal data.