Privacy Policy

M/s Taransh Pinnacle LLP/ RupeeFlex
Effective date: 20.04.2026
Last Updated: 08.06.2026
Next review: Scheduled for December 2026 or as required by regulatory changes

1. INTRODUCTION

1.1 This Privacy Policy explains how RupeeFlex, owned and operated by M/s Taransh Pinnacle (“we”, “our”, “us”), is committed to protecting and safeguarding your personal data.

1.2 RupeeFlex respects your privacy and is committed to protecting it. It meticulously details how we collect, process, store and protect your information, strictly adhering to the principles and provisions of India’s Digital Personal Data Protection Act, 2023, This policy governs all digital interactions and services provided through this platform, ensuring transparency and trust in every engagement.

1.3 RupeeFlex recognizes that your data is sensitive personal data and undertakes to maintain highest level of confidentiality, integrity, and accountability in processing such data.

1. CONTACT INFORMATION

1.1 Parent Company: M/s Taransh Pinnacle LLP

1.2 LLPIN NO: ACI-0130

1.3 Data Protection Officer (DPO)

· Name: Harshita Gupta

· Email: adv.harshitagupta18@gmail.com

· Phone: 8384031478

· Response time: Within 48 hours

1.4 Grievance Officer:

· Name: Tarang Gupta

· Email: solutions@rupeeflex.com

· Phone: 9958822236

· Response time: Within 24 hours

1.5 Registered Office:

Plot No-33, RZ-531405, Street Number 15 Shivpuri, West Sagarpur, Sagarpur South West Delhi, New Delhi, Delhi, India-110046

2. DEFINITIONS

For the purpose of this Privacy Policy

2.1 “Data Principal” means the individual to whom the personal data relates.

2.2 “Data Fiduciary” means RupeeFlex, which determines the purpose and means of processing personal data.

2.3 “Data Processor” means any person or entity processing data on behalf of RupeeFlex.

2.4 “Personal Data” means any information relating to an identified or identifiable individual.

2.5 “Processing” means any operation performed on personal data, including collection, use, storage, disclosure, or erasure,

2.6 “Consent” means free, informed, specific, unconditional, unambiguous agreement by a Data Principal to processing

2.7 “Child” means an individual below eighteen (18) years of age

2.8 Sensitive Personal Information” shall mean and include (i) passwords and financial data (except the truncated last four digits of credit/debit card), (ii) health data, (iii) official identifier (such as biometric data, aadhar number, social security number, driver’s license, passport, etc.,), (iv) information about sexual life, sexual identifier, race, ethnicity, political or religious belief or affiliation, (v) account details and passwords, or (vi) other data/information categorized as ‘sensitive personal data’ or ‘special categories of data’ under the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, General Data Protection Regulation (GDPR) and / or the California Consumer Privacy Act (CCPA) (“Data Protection Laws”) and in context of this Policy or other equivalent / similar legislations.

3. TYPE OF PERSONAL INFORMATION COLLECTED

We may collect both personal and non-personal identifiable information from You in a variety of ways, including, but not limited to, when You visit our Platform, register on the Platform, and in connection with other activities, services, features or resources we make available on our Platform. However, please note that:

· We do not ask You for Personal Information unless we truly need it; like when You are registering for any Content on the Platform.

· We do not share Your Personal Information with anyone except to comply with the applicable laws, develop our products and services, or protect our rights.

· We do not store Personal Information on our servers unless required for the on-going operation of our Platform.

·

3.1 Registration Details: Includes full name, age, mobile number, email, date of birth, gender, address, contact details, passwords, GSTIN No., company name (wherever applicable) etc. at the time of registering with Our Website and/or while creating a user account or while filling questionnaires or forms or when you subscribe to RupeeFlex services by email.

3.2 Technical Data: Includes IP address, device type, browser information, operating system, location data (where permitted), app usage patterns, and crash reports.

3.3 Communication Data: Includes messages, support interactions, feedback, surveys.

3.4 Transaction Data: Includes payment details, FGST number, billing information, transaction history in respect of subscriptions availed on the platform/web.

4. PURPOSES OF PROCESSING

The information we collect is processed for purposes including but not limited to:

4.1 Platform Operations & improvement- including operating and maintaining website debugging, analytics, improvisation, personalize and feature development, and fraud prevention.

4.2 Customer Support-responding to queries, training support teams, and assisting users.

4.3 Development -improve, personalize and expand our services in accordance with feedback received

4.4 Legal & Regulatory Compliance – fulfilling legal and financial obligations such as tax, and regulatory laws.

4.5 Communication & Marketing – sending reminders, financial updates inform of newsletters, WhatsApp updates, and promotional content (only with explicit consent).

5. LEGAL BASIS FOR PROCESSING

5.1 Consent: For optional services such as finance tips, research participation, personalized course development

5.2 Legitimate Interest: For essential services, fraud prevention, security measures

5.3 Legal Obligation: Compliance with Court Orders, tax laws and regulatory requirements

5.4 Contractual necessity: To fulfill our service agreement with you

6. GDPR PROTECTION RIGHTS OF DATA PRINCIPALS

6.1 Right to information- You have the right to know categories of data collected, purposes of processing, and entities with whom data is shared.

6.2 Right to Rectification & Completion- You have the right to correct inaccuracies and complete incomplete data.

6.3 Right to Erasure – to request deletion, subject to legal and regulatory obligations.

6.4 Right to Grievance Redressal – to raise complaints with the Grievance Officer and escalate to the Data Protection Board if unsatisfied.

6.5 Right to Nominate – to appoint a nominee to exercise rights in case of death or incapacity.

6.6 Right to access- You have the right to request copies of your personal data.

6.7 Right to Restrict processing- You have the right to request that we restrict the processing of your personal data, under certain conditions.

6.8 Right to object to processing - You have the right to object at any time to processing of your personal data, under certain conditions.

6.9 Right to data portability- You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.

Remember, you are entitled to exercise your rights as stated above only with respect to your information, including Personal Information, and not that of other Learners. Further, when we receive any requests or queries over email to the address specified in the ‘Grievances’ section below, then, as per the applicable Data Protection Laws, we may need to ask you a few additional information to verify your identity in association with the Platform and the request received.

7. YOUR CHOICES:

7.1 Limit the information you provide

7.2 Limit the communications you receive from us

7.3 Reject cookies and other similar technologies

8. CONSENT MANAGEMENT

8.1 Consent must be free, specific, informed, unconditional, unambiguous, based on affirmative action, and revocable at any time.

8.2 Methods for obtaining Consent

a. Unticked consent boxes at registration;

b. In-app consent prompts for optional features;

c. Separate consent forms for specific purposes;

d. Explicit agreement for sensitive financial and personal data.

8.3 Consent may be withdrawn at any time by:

a. Adjusting privacy settings in the account dashboard;

b. Emailing the Data Protection Officer;

c. Calling customer support;

d. Using unsubscribe links in communications

9. DATA RETENTION PERIOD

9.1 Active Account Data: Retained while your account is active and for 3 years after account closure

9.2 Communication Data: Retained for 2 years for customer service purposes

9.3 Legal Hold: Data may be retained longer if required by law or legal proceedings

9.4 Technical Logs: Retained for 1 year for security and debugging purposes

Further, please note that we may not be able to delete all communications or photos, files, or other documents publicly made available by you on the Platform (for example: comments, feedback, etc.), however, we shall anonymize your Personal Information in such a way that you can no longer be identified as an individual in association with such information made available by you on the Platform. We will never disclose aggregated or de-identified information in a manner that could identify you as an individual.

Upon expiry, data will be surely deleted, anonymized, or destroyed in compliance with law.

10. DATA SHARING DISCLOSURES

10.1 Service Providers: Cloud storage, payment processors, communication vendors, analytics providers.

10.2 Regulatory Bodies: Government departments, courts, tax authorities, financial regulators.

10.3 Safeguards: All third parties are bound by confidentiality agreements, access controls, and compliance audits.

11.INTERNATIONAL DATA TRANSFERS

11.1 While data is primarily stored in India, certain processing may involve cross-border transfers.

11.2 Transfers are protected through Standard Contractual Clauses, binding corporate rules, encryption, and adequacy assessments.

11.3 Data Principals may opt for localization or request details of transfer destinations.

12.SECURITY MEASURES

We take all measures reasonably necessary to protect against the unauthorized access, use, alteration or destruction of Personal Information or such other data on the Platform. Security measures undertaken by us includes but are not limited to:

12.1 All data is in encrypted form

12.2 Role based access and multi factor authentication in place

12.3 Staff training, NDAs, background checks, access logs

12.4 We only collect data necessary for specified purposes

12.5 Regular privacy and security training for all employees

12.6 24*7 monitoring and rapid response to security incidents

13. DATA BREACH NOTIFICATIONS

13.1 Breaches will be contained, assessed, and documented within 24 hours.

13.2 Notifications will be made to the Data Protection Board within 72 hours and to affected individuals without undue delay where risks are high.

13.3 Notifications will include nature, scope, risks, remedial measures, and contact details.

14. THIRD-PARTY LINKS

Our platform may contain links to third-party websites. Please note that we are not responsible for the privacy practices of such external sites and encourage you to review their respective privacy policies.

By clicking on links to third-party websites, you will be subject to their terms of use and privacy policies. We do not control how these third parties collect, use, or process your personal data and information, and we do not endorse such websites. Accordingly, we shall not be held responsible for any data breach, infringement of your privacy rights, or any loss or damage that may arise from your access to or use of such third-party websites.

15.CHILDREN’S PRIVACY

RupeeFlex does not knowingly collect any personally identifiable information from minors under the age of 18. If you are under 18, please do not submit any personal data through the Website. We encourage parents and legal guardians to monitor their children’s internet usage and to help enforce this Privacy Policy by instructing them not to provide personal data without prior consent

If a parent or guardian believes that RupeeFlex has collected personal data of a child under 16, they should contact us immediately at solutions@rupeeflex.com We will make reasonable efforts to promptly remove such information from our records

Parental or guardian consent is required for users under the age of 18. We do not engage in profiling, targeted advertising, or any processing of children’s data that may be harmful. Parents or guardians have the right to access, correct, or request deletion of their child’s personal data at any time.

16.COOKIES AND TRACKING

RupeeFlex uses essential, functional, performance, and analytics cookies to enhance user experience. You may manage your cookie preferences through your browser settings or in-app controls.

We may engage third-party service providers to track user activity and support analytics. Additionally, we may use remarketing tools, including tracking cookies and conversion pixels from vendors such as Google and Facebook (Meta), to display relevant advertisements and special offers for our products or services across the Google Content Network and social media platforms.

As a result, you may see advertisements for our products or services after visiting our website. We may also use custom audience features based on user email addresses and phone numbers to present tailored offers via Google and Facebook. However, your personally identifiable information is not used by these remarketing services for any purpose other than displaying our advertisements.

We may continue to engage third-party service providers for remarketing and related services.

17.GOVERNING LAW & JURISIDICTION

The Policy is governed by the laws of India. Courts in Delhi shall have exclusive jurisdiction.

18. SEVERABILITY

If any provision of this Policy is held invalid, the remaining provisions shall continue in force.

19. CHANGES TO PRIVACY POLICY

We reserve the right to update and modify this Privacy Policy any time and from time to time without prior notice due to legal changes, new services, or user feedback.

· Minor updates will be published on our website.

· Material changes will be notified at least 30 days in advance via email

· Consent-impacting changes will require fresh consent.

· Previous versions will be archived and available upon request

20. ACKNOWLEDGEMENT

Please review our Privacy Policy regularly to stay informed of any changes, alterations, or modifications. Any updates to this Privacy Policy shall become effective once they are posted on this page, or as otherwise specified in the updated policy. We encourage you to review this Privacy Policy periodically, particularly before providing any personal data. Your continued use of this Website following any changes or revisions to this Privacy Policy shall constitute your acceptance of the terms of the revised Privacy Policy

For the latest version, visit: https://www.rupeeflex.com/privacypolicy

21. GRIEVANCE REDRESSAL

In case of any queries or concerns in any matter related to this Privacy Policy, or you wish to exercise your rights, express concern about privacy, you may reach out to solutions@rupeeflex.com for assistance.

Grievance may be filed through via email or online portal (with details)

Please note that an acknowledgment of your query will be provided within 24 hours of receipt, and a response to your request will be issued within 30 business days. Kindly note that the escalation may be made to senior management or the Data Protection Board.

IMPORTANT NOTE: THIS PRIVACY POLICY COMPLIES WITH THE DIGITAL PERSONAL DATA PROTECTION ACT, 2023, AND WILL BE UPDATED AS NECESSARY TO REFLECT ANY CHANGES IN THE LAW OR OUR DATA PROCESSING PRACTICES.