Who We Are and What This Policy Covers
This Privacy Policy explains how FIIFO Ventures Private Limited ("FIIFO," "we," "us," "our") — a company incorporated in Kerala, India (CIN: U58191KL2026PTC103090), with its registered office at Rohini Nivas, Mannakallu, Nellimoodu P.O. – 695524, Kerala — collects, uses, stores, shares, and protects your personal data.
FIIFO operates a platform, accessible through our website (fiifo.com) and our iOS and Android applications (together, the "Platform"), that lets people co-own and participate in special-purpose vehicles ("SPVs") formed for individual film projects. Because participation involves the subscription and holding of shares in these SPVs, we are required by law to collect and verify certain identity and financial information — this policy tells you what we collect and why.
This policy applies to everyone who uses the Platform, including:
• Participants / Co-Owners — people who subscribe to, hold, or transfer shares in a film SPV;
• Creators / Producers — people and entities who list a film project or onboard with us;
• Backstage users — people who complete verification to express interest in a project before it is listed;
• Visitors — anyone who browses the Platform without creating an account.
For the personal data covered by this policy, FIIFO acts as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), except where stated otherwise in Section 5 (where each SPV is the Data Fiduciary for its own shareholder register and FIIFO acts as its Data Processor).
By using the Platform, you acknowledge you have read this policy. Where the law requires your consent, we ask for it separately and explicitly — your continued use of the Platform is not treated as consent on its own.
The Personal Data We Collect
We collect personal data in three ways: what you give us directly, what we collect automatically when you use the Platform, and what we receive from third parties who help us verify you.
3.1 Data You Give Us Directly
• Account data — your name, email address, mobile number, and login credentials. Passwords are cryptographically hashed (Argon2 / PBKDF2) and are never stored in plain text.
• Identity / KYC and e-sign data — PAN, date of birth, photograph, and proof of address. Identity verification uses offline Aadhaar verification (OKYC XML / DigiLocker) in accordance with UIDAI guidelines; your full 12-digit Aadhaar number is not stored — only UIDAI-compliant transaction references and masked tokens are processed.
• Financial data — bank account details (account number, IFSC, account-holder name) you provide for penny-drop verification and payouts.
• Depository / demat data — your DP ID and client ID, required so that shares can be allotted and held in dematerialised form under applicable law.
• Nominee data — the name and details of any nominee you appoint.
• NRI / OCI data — for participants residing outside India, passport or OCI details and overseas address information required under FEMA.
• Communications — the content of support requests, grievances, and other messages you send us.
3.2 Data We Collect Automatically
When you use the Platform, we automatically collect the limited technical data needed to run it securely — device and browser type, operating system, IP address, and session identifiers. We do not currently use analytics tools or tracking cookies to monitor how you browse, and we do not build behavioural profiles of you.
3.3 Data We Receive from Third Parties
• From our KYC verification agency — the result of identity verification checks.
• From our payment gateway — confirmation of payment status and a transaction reference. We never receive or store your full card number, CVV, or UPI PIN.
• From our eSign provider — confirmation that you have digitally signed an agreement.
• From the depository / registrar and transfer agent (RTA) — confirmation of demat account status and allotment.
We do not buy personal data from data brokers, and we do not collect special categories of data beyond what is described here.
Why We Collect Your Data and Our Legal Basis
4.1 To provide and operate the Platform — Creating and managing your account, letting you browse and use Backstage, processing your subscription to an SPV, letting you electronically sign your SPV participation and related agreements, allotting and recording your shares, and processing payouts to you.
4.2 To verify your identity and meet anti-money-laundering obligations — We are required to identify and verify every participant and creator under the Prevention of Money-Laundering Act, 2002 (PMLA). This is why KYC is mandatory and why we cannot let you subscribe without it.
4.3 To create and maintain statutory records — Recording you in the SPV's register of members, arranging dematerialisation of your shares, and filing statutory returns, as required under the Companies Act, 2013.
4.4 To meet tax and reporting obligations — Deducting tax where applicable, issuing statements, and maintaining records under the Income-tax Act, 1961; and for NRI / OCI participants, making FC-GPR / FC-TRS filings under FEMA.
4.5 To communicate with you — Sending transactional messages about your account, subscriptions, and holdings; and, only with your consent, marketing or promotional messages, which you can opt out of at any time.
4.6 To keep the Platform secure and prevent fraud — Detecting, preventing, and investigating fraud, abuse, security incidents, and violations of our Terms.
4.7 Automated processing for verification and risk screening — As part of our KYC and AML obligations, some checks are carried out by automated means. Where an automated check flags a concern, a human compliance officer reviews the result before any final account restriction.
Who We Share Your Data With
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
6.1 Service providers who process data on our behalf:
• Payment gateway — Razorpay Software Private Limited — to process your subscription payments and payouts.
• KYC verification agency — Zoop One Technology Private Limited — to verify your identity documents (PAN / CKYC / Aadhaar-XML) and run AML checks.
• eSign provider — Zoop (Zoop.one) — to let you digitally sign your SPV participation and related agreements using Aadhaar eSign.
• Cloud hosting — Google Cloud Platform — our infrastructure provider, hosting Platform data on servers located in India.
• Communication providers — services we use to send you transactional emails, SMS, and notifications.
6.2 The film SPV you subscribe to — When you subscribe to a film SPV, the personal data required for your shareholding is recorded in that SPV's register of members.
6.3 Depository, RTA, and financial-market infrastructure — Your demat and shareholding details are shared with the depository and RTA so your shares can be allotted and held in dematerialised form.
6.4 Regulators, authorities, and legal requirements — We share personal data with regulators, tax authorities, FIU-IND, courts, and other authorities where required by law.
Where We Store Your Data
All personal data collected through the Platform — including KYC records, financial ledgers, identity verifications, signed agreements, backups, snapshots, and application logs — is stored and processed exclusively on Google Cloud Platform infrastructure located within India (primary regions: asia-south1, Mumbai and asia-south2, Delhi).
Where a service provider is part of a group headquartered elsewhere (for example, our cloud provider), the data itself continues to reside on infrastructure located in India, and that provider processes it only on our instructions and under a written agreement.
If, in future, any transfer or access outside India becomes necessary, we will do so only as permitted under Section 16 of the DPDP Act and applicable sectoral law, and we will update this policy before doing so.
How Long We Keep Your Data
We keep your personal data only for as long as we need it for the purposes described in this policy, or for as long as the law requires us to — whichever is longer. Because we operate under securities, anti-money-laundering, and tax laws, several categories of data must be retained for fixed statutory periods even after you close your account or exit an SPV, and cannot be deleted on request during that time.
8.2 After the retention period — Once a retention period ends and no legal obligation or legitimate purpose requires us to keep the data, we securely delete it or irreversibly anonymise it so it can no longer identify you.
8.3 If you close your account — When you do, we remove your personally identifiable information from active Platform systems within 30 days — except for the categories we are legally required to keep. Closing your account does not affect any SPV participation agreement you have already signed; the financial and statutory records relating to that participation are retained for the legally required period regardless of closure.
Your Rights and How to Exercise Them
The DPDP Act gives you rights over your personal data. Subject to the limits noted below, you have:
• The right to access — to ask us for a summary of the personal data we hold about you.
• The right to correction and updating — to have inaccurate or incomplete data corrected.
• The right to erasure — to ask us to delete your personal data where we are no longer required to keep it.
• The right to withdraw consent — where our processing is based on your consent, you can withdraw it at any time.
• The right to nominate — to nominate another individual to exercise your rights in the event of your death or incapacity.
• The right to grievance redressal — to raise a complaint with us about how we handle your data, before approaching the Data Protection Board.
9.1 The limits set by law
Some of your data is retained because the law requires it, not because you consented. For that data, erasure and withdrawal of consent do not apply for as long as the statutory retention period runs — we cannot delete KYC, transaction, or statutory-register records that PMLA, the Companies Act, or the Income-tax Act require us to keep.
9.2 How to exercise your rights — You can exercise any of these rights by contacting our Data Protection Contact / Grievance Officer using the details in Section 16. We acknowledge receipt within 48 hours and provide a full response within 30 days.
How We Protect Your Data
We work to protect your data using measures appropriate to its sensitivity:
• Data in transit is encrypted using TLS 1.3.
• Data at rest is encrypted using AES-256.
• PAN and bank account fields are subject to application-layer encryption under key management services.
• Passwords are hashed using Argon2 / PBKDF2 and are never stored in plain text.
11.2 Our people and processors — Access to personal data inside FIIFO is limited to those who need it to do their jobs, and they are bound by confidentiality obligations.
11.3 If a data breach happens — Our notification will describe what happened, the data involved, the likely consequences, and the steps we are taking.
11.4 Your part — Keep your login credentials confidential, use a strong and unique password, do not share one-time passwords with anyone (including anyone claiming to be from FIIFO — we will never ask for them).
Children and Minors
The Platform is intended for use by adults only. You must be at least 18 years old to create an account, complete KYC, or participate in any SPV. This is not only our policy — participation involves the subscription and holding of securities, which cannot lawfully be done by a minor in their own right.
We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected personal data from someone under 18, we will delete it promptly, unless we are required by law to retain it. If you believe a minor has provided us with their data, please contact us at support@fiifo.com.
How to Contact Us
If you have any questions about this policy, want to exercise your rights, or wish to raise a concern about how we handle your personal data, you can reach us as follows.
Data Protection Contact & Grievance Officer:
Ancy Jose, Data Protection Contact & Grievance Officer
FIIFO Ventures Private Limited
Rohini Nivas, Mannakallu, Nellimoodu P.O. – 695524, Kerala
Email (data rights / grievances): legal@fiifo.com
Email (account / general support): support@fiifo.com
We acknowledge receipt of your request within 48 hours, and provide a full response to data-rights requests within 30 days.
Related documents: This policy should be read together with our
Terms & Conditions, Disclaimer & Risk Disclosure, Refund & Cancellation Policy, Cookie Policy, Data Localisation & Retention Policy, and Grievance Redressal Policy. The commercial treatment of Creator / Producer project material is governed by the Producer Agreement.