DATA SECURITY & COMPLIANCE

Protecting Your Data. Securing Your Practice.

Last Updated: 16-12-2025

At ARN Booster, the security of your data – and the trust of your clients – is our highest priority.
We are committed to providing a secure, compliant, and privacy-first platform designed specifically for Mutual Fund Distributors (MFDs), RIAs, and financial professionals across India.

This page explains exactly how we protect your information and how our systems align with applicable Indian regulations.

๐Ÿ” 1. Our Security Philosophy

Your data is your property – we only safeguard it.

  • We do not sell, rent, or trade user or client data.
  • We do not access any data unless required for support and explicitly permitted.
  • You remain the sole owner of all client and business information stored on ARN Booster.

๐Ÿ”‘ 2. Data Encryption Standards

  • Encryption in Transit
    All data transmitted between your device and our servers is protected using TLS 1.2+ encryption, preventing interception or tampering.
  • Encryption at Rest
    All sensitive personal and financial data is stored using AES-256 encryption, the global standard used by banks and fintech platforms.
  • Secure API Communication
    Every API call is authenticated, rate-limited, and protected against:

    • Man-in-the-middle attacks
    • Injection attempts
    • Replay attacks
    • Unauthorised data exposure

๐Ÿ›ก 3. Infrastructure & Server Security

  • India-based Servers
    All data is stored on secure AWS servers located in India, ensuring compliance with:

    • Indian IT Act
    • RBI, SEBI, and AMFI data-handling expectations
  • Firewall & Network Protection
    We use enterprise-grade firewalls, VPC isolation, and traffic monitoring to block malicious traffic.
  • Regular Security Audits
    • Vulnerability assessments
    • Penetration testing
    • Periodic third-party audits

    These audits ensure our systems remain hardened and updated.

๐Ÿ‘โ€๐Ÿ—จ 4. Zero Unauthorised Access Guarantee

  • Role-based Access Control (RBAC)
    Only authorised personnel with defined roles can access internal systems.
  • Principle of Least Privilege
    Team members only access the minimum data required to perform their tasks.
  • Audit logs
    Every critical action is logged and monitored for security and compliance.

ARN Booster never accesses your client data unless:

  • You explicitly request support.

Access is revoked immediately after resolution.

๐Ÿงฉ 5. Compliance With Indian Regulations

  • SEBI / AMFI Compliance (advisor expectations)
    While ARN Booster is not a regulated entity, our platform follows compliance practices that advisors must adhere to:

    • Secure record-keeping
    • Reliable audit trails
    • Data confidentiality
    • No unauthorised sharing of investor information
    • Proper access control and logging
  • IT Act, 2000 & SPDI Rules Compliance
    We adhere to requirements for handling:

    • Personal data
    • Sensitive personal data (SPDI)
    • Financial information
    • Identity documents
  • Email Data Handling (Gmail Integrations)
    If you connect Gmail:

    • Only transaction-related RTAs emails (CAMS, KFin, FT) are scanned
    • No personal emails are read or stored
    • Data is not sold or shared for advertising
    • Access is granted only with your explicit consent

๐Ÿงฎ 6. Data Retention & Backup Policies

  • Retention
    Transaction history for active users is retained for 5 years.
    Older records may be archived securely and retrieved on request.
  • Backup
    We maintain encrypted daily backups with:

    • Multi-region redundancy
    • Disaster recovery protocols
    • Automatic restoration capability
  • Business Continuity
    In the event of unforeseen outages:

    • Critical systems auto-failover
    • No loss of user or client data
    • Minimum downtime

๐Ÿ“ 7. User Data Ownership & Control

You are the exclusive owner of:

  • Client data
  • Portfolio records
  • Contact information
  • Uploaded files
  • Notes & communication logs

ARN Booster is only a technology custodian.

You can:

  • Export your data
  • Request corrections
  • Request deletion (where legally allowed)
  • Withdraw access to integrations

โš ๏ธ 8. Data Sharing Policy

We never share personal or client data with:

  • Advertisers
  • Unrelated third parties
  • External entities without your consent

We may share limited data only when:

  • Required by law (court orders, regulatory authorities)
  • Necessary for service delivery (e.g., payment gateway, cloud hosting)
  • Explicitly authorised by you

No data is shared for marketing purposes without consent.

๐Ÿง‘โ€๐Ÿ’ป 9. Internal Security Practices

  • Background-verified personnel
    All employees undergo verification and confidentiality agreements.
  • Mandatory security training
    Team members are trained on:

    • Data handling
    • Cybersecurity best practices
    • Incident response
    • Privacy norms
  • Access Rotation
    Login credentials and access rules are rotated and monitored regularly.

๐Ÿšซ 10. Incident Detection & Response

We employ:

  • Real-time monitoring
  • Automated anomaly detection
  • Alerts for suspicious logins or API calls

If an incident occurs:

  • Affected systems are isolated immediately
  • Users are notified as required
  • Root cause analysis is conducted
  • Preventive measures are implemented

๐Ÿ“ฒ 11. Your Responsibilities as a User

To maintain security, Users should:

  • Keep login credentials confidential
  • Use strong passwords
  • Enable 2FA (if available)
  • Inform us of suspicious activity immediately

๐Ÿค 12. Transparency & Trust

We believe MFDs deserve:

  • Clear answers
  • Transparent data policies
  • No hidden practices

If you have questions about how your data is handled, weโ€™re here to help.

๐Ÿ“ฉ 13. Contact & Compliance Officer

Data Protection & Compliance Officer
Rise 2 XL Private Limited
๐Ÿ“ง contact@arnbooster.com
๐Ÿ“ž +91-9315790599
๐ŸŒ www.arnbooster.com

Frequently Asked Questions

Everything you need to know about data security and privacy.

Yes. All data is encrypted using bank-grade AES-256 encryption and stored safely on servers located in India.
You remain the exclusive owner of your client data.

No. We do not access or use your client data unless:
(a) you request support.

All access is logged and revoked after resolution.

All data is stored on secure, firewall-protected AWS servers within India, ensuring compliance with Indian IT laws and advisor expectations.

Absolutely not. We do not sell, rent, or share personal or client data with advertisers or unrelated third parties.

ARN Booster scans only RTA transaction emails (CAMS, KFin, Franklin Templeton, etc.) to auto-update portfolios.
We do not open or read personal emails.

โ€ข Role-based access control
โ€ข Multi-layer encryption
โ€ข Firewall protection
โ€ข Continuous monitoring and alerts
โ€ข Secure login and API authentication

Yes. You can request export or deletion of your data anytime, subject to legal and compliance requirements.

We ensure minimal downtime. All upgrades follow secure deployment processes, and your encrypted data remains protected throughout.

Report it immediately.
We will lock access, investigate the activity, and restore account security.

Yes. While we are a technology provider (not a regulated entity), our security practices align with:
โ€ข SEBIโ€™s expectations for advisory confidentiality
โ€ข AMFI code of conduct requirements
โ€ข Indian SPDI data protection rules

Ready to Scale Your AUM Effortlessly?

Unlock smarter, faster, and more secure AUM management with ARN Booster your all in one platform for financial growth.