Privacy Policy
Version 1.2 · Effective 3 October 2026
1. Who we are
This Privacy Policy explains how MostlyNRI, a brand operated by Housewise Services Private Limited ("MostlyNRI," "we," "us"), a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), collects, uses, shares, and protects personal data through www.mostlynri.com and related services (the "Site"). It forms part of, and should be read with, our Terms of Service. By using the Site or our Services and providing the consents we request, you agree to this Policy. If you do not agree, do not use the Site.
2. Data we collect
To provide NRI tax, compliance, and financial-facilitation services, we collect the following, much of which is sensitive and collected with your consent:
-
Identity and eligibility data: name, date of birth, photograph, contact details, PAN, Aadhaar (only where legally permissible and necessary), passport and OCI details, and other government-issued identifiers.
-
Residency and tax data: country of residence and tax-residency status, FATCA/CRS self-declarations, income details, Form 16/26AS and AIS data, prior returns, capital-gains and asset details, tax notices, and related documents.
-
Financial and investment data: NRE/NRO and other bank-account details, KYC documents, investment holdings and transactions, and repatriation details.
-
Account data: login credentials and preferences.
-
Communications and recordings: your correspondence with us and recordings of calls, where made, for quality, training, and compliance.
-
Usage, device, and cookie data: IP address, browser and device details, pages visited, and time/date of access, collected in anonymous/aggregate form where possible.
-
Data from other sources: social-login profile data, public databases, and information from our partners, where you have authorised it.
We request and use Aadhaar only where legally permissible and necessary for a specific service, handle it in line with the Aadhaar Act and applicable law, and do not use it for any purpose beyond that service. Where we ask for consent to collect a specific category, that consent is recorded.
How your data reaches us. Documents and information are generally provided to us by email or through secure online forms (including third-party form platforms such as Jotform) rather than stored on the Site; the Site itself does not store your documents. Information you share is held in our business systems or those of our form provider, which processes it on our behalf under data-protection terms. Because email in particular is a less secure channel, we apply the measures in Section 8 and recommend you take care when sharing sensitive documents.
3. How and why we use your data
We process personal data to: provide the tax, compliance, documentation, and investment-facilitation Services you request; verify identity and eligibility (including KYC and FATCA/CRS); prepare and file returns and applications on the basis of what you supply and approve; coordinate with regulated partners to deliver a Service; process Service-fee payments and issue invoices; communicate with you and provide support; secure the Site and prevent fraud; comply with legal, tax, audit, and regulatory obligations; and establish, exercise, or defend legal claims. We process on the lawful bases of your consent and the performance of our contract with you, and, where applicable, our legal obligations and legitimate interests.
4. Consent and its withdrawal
Where we rely on consent, we obtain it through a clear affirmative action and record it. You may withdraw consent at any time, as easily as you gave it, by writing to our Grievance Officer (Section 12) or using in-account controls; withdrawal does not affect processing already carried out, and may mean we can no longer provide a Service. Marketing consent is separate from Service consent and can be withdrawn without affecting your Services.
5. Sharing and disclosure
We share personal data only as needed: with regulated and third-party partners who deliver a Service (chartered accountants; Wealthy and other mutual-fund distributors; PMS and AIF providers; asset-management companies; banks; and payment, hosting, online-form, and technology providers), who process it on our instructions or under their own regulatory obligations and confidentiality and data-protection terms; with legal, tax, and professional advisers; with law-enforcement, regulators, or courts where we believe in good faith it is required or justified, or to protect rights, property, or safety; and with an acquirer in a merger, financing, restructuring, or sale of assets. We do not sell, rent, or trade your personal data. We are not liable for the independent acts of partners who process data in compliance with their own obligations.
6. Cross-border transfer
Our systems are in India; some partners or processors may be located outside India, and you may be accessing our Services from outside India. Where we transfer personal data across borders, we do so in accordance with the DPDP Act and applicable law, under appropriate contractual and security safeguards. By using the Services from outside India, you understand your data will be processed in India and in the locations of our partners and processors.
7. Data retention
We retain personal data only as long as necessary for the purposes collected, including while you are a registered user or receiving Services, and thereafter for the period required to meet our legal, tax, audit, accounting, and dispute-resolution obligations — typically up to 8 years after the end of the relevant engagement (reflecting income-tax record and re-assessment periods), or longer where the law requires or a claim, notice, or assessment is unresolved. KYC records are retained for the period required by applicable law. When no longer needed, we delete or anonymise data, and may retain anonymised or aggregated data indefinitely.
8. Security
We implement reasonable technical and organisational security measures appropriate to the sensitivity of the data — including access controls, encryption in transit where appropriate, credential protection, and need-to-know access limited to trained personnel and partners. Because documents are generally received by email or through online forms and held in our business systems or those of our form provider rather than on the Site, and because email in particular is a less secure channel, you acknowledge that transmission carries inherent risk. No system is fully secure; any liability for a data incident is subject to the limitation of liability in our Terms of Service, to the fullest extent permitted by law.
9. Your rights
Subject to the DPDP Act and applicable law, you may: access a summary of your personal data and its processing; correct, complete, or update inaccurate data; request erasure of data no longer needed; withdraw consent; nominate another person to exercise your rights in the event of death or incapacity; and grieve or complain. To exercise a right, contact our Grievance Officer (Section 12); we will respond within the timelines required by law. To request deletion, contact our Grievance Officer; we will delete or anonymise your data within a reasonable period, except data we must retain by law (for example, tax and KYC records — Section 7) and data needed to complete an active Service or resolve a dispute. We will not delete data while a Service is in progress or an obligation is outstanding. We may verify your identity before acting and may decline requests where the law permits.
10. Children
The Site and Services are intended for adults (18+). We do not knowingly process the personal data of children except as part of a transaction conducted by their lawful guardian and with verifiable consent as required by law. If you believe we hold a child's data without proper consent, contact us and we will address it.
11. Breach notification
In the event of a personal-data breach, we will notify the Data Protection Board of India and affected individuals as, and within the timelines, required by the DPDP Act and Rules.
12. Grievance Officer / contact
For any question, request, or complaint about your personal data or this Policy, contact:
Grievance Officer: Sathi Paul · Housewise Services Private Limited (MostlyNRI) · E-901, Costa Rica Society, Wakad, Pimpri-Chinchwad, Pune, Maharashtra 411057 · Email: [email protected] · Phone: +91 8448440693
We will acknowledge and address grievances within the timeframes required by law. If unsatisfied, you may complain to the Data Protection Board of India.
13. Cookies
We and our providers use cookies and similar technologies to recognise your device and improve the Site; the data is collected in anonymous/aggregate form where possible. You can control cookies through your browser settings; disabling them may affect functionality. To opt out of interest-based advertising, visit http://www.aboutads.info/choices/.
14. Users in the EU/EEA/UK and California (US)
Where and only to the extent the EU/UK GDPR applies to our processing of your data, we act as a controller and additionally honour the rights and transfer safeguards that regime requires, including the right to complain to your local supervisory authority. Where the California Consumer Privacy Act applies, California residents may exercise their rights to know, delete, correct, and opt out of any "sale" or "sharing" of personal information; we do not sell your personal information. These apply only where that law is legally triggered; otherwise the DPDP Act governs.
15. Changes to this Policy
We may update this Policy. For material changes, we will give notice through the Site or by email before they take effect, and update the "Version" and date. Your continued use after a change takes effect signifies acceptance.
16. Contact
[email protected] · Housewise Services Private Limited (MostlyNRI), E-901, Costa Rica Society, Wakad, Pimpri-Chinchwad, Pune, Maharashtra 411057 · Correspondence: 91Springboard, Creaticity Mall, Yerwada, Pune 411006.
Version 1.2 · Last updated: 3 October 2026
