Privacy Policy

INTRODUCTION

The AIF CFO Association (hereinafter referred to as the “Association”, “we” or “our”) is committed to protecting the privacy and confidentiality of personal data we collect or hold about members of the Association and users of our website and/or services (hereinafter collectively referred to as “you” or “your”).

This Privacy Policy (“Policy”) explains what personal data we collect, why we collect it, how we use and protect it, with whom we may share it, and the rights available to you. This Policy applies to all activities of the Association, including membership registration and management, events and conferences and Executive Council Elections, our website and digital platforms, and its elections.

This Policy is to be read alongside our Memorandum of Association and Articles of Association, code of conduct, and any supplementary notices issued for specific activities. By registering as a member, attending an event, using our website, or participating in an election, you acknowledge and agree to the terms of this Policy.

This Policy has been formulated in compliance with the Information Technology Act, 2000 (“IT Act”), Digital Personal Data Protection Act, 2023 (“DPDP Act”), Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the Digital Personal Data Protection Rules, 2025, as amended from time to time. Further the IT Act will cease to have effect upon full enforcement of the DPDP Act effective May 31, 2027.

PRIVACY PRINCIPLES

The Association shall be guided by the following principles in the processing of your personal data:

2.1 Informed consent notice - Providing clear and accessible information to you before collecting, using, or storing your personal data.

2.2 Free and unambiguous consent - Ensuring that all grounds for processing of personal data are lawful, and that your consent is voluntary, specific, informed, unconditional, and unambiguous.

2.3 Protection of children and persons with disabilities - Processing personal data of children and persons with disabilities only after obtaining verified consent from the respective parent or legal guardian, as applicable.

2.4 Purpose limitation - Restricting the collection and processing of your personal data strictly to what is necessary for specified and lawful purposes.

2.5 Secure erasure of personal data - Ensuring secure erasure of your personal data upon fulfilment of the stated purpose or withdrawal of your consent.

2.6 Facilitation of your rights - Upholding your rights to access, correction, erasure, withdrawal of consent, nomination of a representative, and effective grievance redressal.

2.7 Third-party sharing and processing - Governing all disclosures of your personal data to third parties, including for processing purposes, through binding legal agreements.

2.8 Reasonable security safeguards - Implementing comprehensive technical and organisational measures to protect your personal data against unauthorised access, misuse, or breach.

2.9 Grievance redressal - Ensuring timely and effective resolution of any grievances raised by you.

3. COLLECTION OF PERSONAL DATA

We may collect your personal data across the following activities:

3.1 Membership Registration and Renewals

  1. Full name, professional designation, and employer / fund name;
  2. Contact details such as business and personal email address, phone number, and office address;
  3. KYC documents;
  4. Payment and billing information for membership fees (processed securely via authorised payment gateways); and
  5. Correspondence and communications with the Association Secretariat.

3.2 Events and Conferences

  1. Registration details including name, designation, organisation, and contact information;
  2. Dietary, accessibility, or other logistical preferences shared voluntarily for event management;
  3. Attendance records and session participation data;
  4. Photographs, videos, and audio recordings taken during events;
  5. Feedback and survey responses submitted in the events and subsequently; and
  6. Speaker and panellist profiles, including professional biographies and presentation materials.

3.3 Website and Digital Platforms

  1. Browser type, device information, and IP address collected automatically via cookies and similar tracking technologies;
  2. Pages visited, time spent on the website, and navigation patterns;
  3. Account login credentials for the member portal, where applicable;
  4. Enquiry and contact form submissions; and
  5. Email open and click-through data from Association communications, where analytics are enabled.

3.4 Elections

  1. Name and membership category for voter eligibility verification;
  2. Applications including professional biography, photograph, designation, and conflict of interest declarations, KYC information;
  3. Voting status (whether a ballot has been cast, without disclosure of voting preference); and
  4. Audit logs for the voting platform to maintain electoral integrity.

The secrecy of each member’s vote is absolutely guaranteed. Individual voting preferences are never linked to individual voters and are not accessible to any officer, staff member, or committee of the Association. Please refer to Clause 8 of this Policy for the complete Elections Privacy framework.

4. USE OF PERSONAL DATA

We shall use personal data only for the purposes set out below. We do not use member data for commercial gain or share it for third-party marketing.

4.1 Membership Administration

  1. Processing membership applications, renewals, and fee payments;
  2. Maintaining an accurate and up-to-date member directory;
  3. Communicating Association news, updates, regulatory developments, and member benefits;
  4. Managing member services, queries, and grievances; and
  5. Facilitating professional connections through the Association’s official LinkedIn page.

4.2 Events and Programmes

  1. Processing event registrations, hotel bookings and managing logistics;
  2. Issuing confirmations, joining instructions, and post-event materials;
  3. Producing delegate lists and name badges for in-person events;
  4. Documenting proceedings and producing conference reports or publications, subject to consent; and
  5. Improving future events through feedback and attendance analytics.

4.3 Website and Digital Platforms

  1. Operating and improving the Association website and member portal;
  2. Analysing website usage to enhance user experience;
  3. Responding to enquiries submitted via the website; and
  4. Sending member communications where consent or legitimate interest applies.

4.4 Elections

  1. Verifying voter eligibility and administering the ballot process;
  2. Publishing candidate profiles to facilitate informed voting by members;
  3. Maintaining election records and audit trails for integrity and dispute resolution; and
  4. Constituting elected bodies and notifying results to the membership.

4.5 Institutional and Compliance Purposes

  1. Maintaining statutory and regulatory records as required by applicable law;
  2. Responding to lawful requests from regulatory authorities or courts; and
  3. Protecting the Association’s legal rights and enforcing its bylaws.

5. LEGAL BASIS FOR PROCESSING

The Association shall not undertake processing of any personal data without a valid, lawful, and legitimate basis, in accordance with applicable law, and processes personal data on the following legal bases:

5.1 Consent: The Association shall process your personal data only upon your free, informed, specific, unambiguous, and unconditional consent, obtained prior to the commencement of any processing activity.

5.2 Legitimate Interests: Notwithstanding the primary requirement of consent, the Association reserves the right to lawfully process your personal data without your explicit consent, solely where such processing is necessary for the following legitimate purposes:

  1. Where you have voluntarily provided your personal data to the Association for a specified purpose as detailed in Clause 4, and where such interests are not overridden by your individual rights;
  2. For the performance of a legal contract with you;
  3. For compliance with any judgment, decree, or order issued under any law for the time being in force in India;
  4. For responding to a medical emergency involving a threat to your life or an immediate threat to your health or that of any other individual;
  5. For taking measures to provide medical treatment or health services during an epidemic, disease outbreak, or any other threat to public health;
  6. For ensuring safety or providing assistance or services to any individual during a disaster or breakdown of public order; and
  7. For employment and human resources purposes under applicable labour law.
  8. Regulatory disclosures

6. DISCLOSURE OF PERSONAL DATA

The Association does not sell, rent, or otherwise commercially exploit personal data. We may share data in the following limited and controlled circumstances:

6.1 Technology and Platform Vendors

We engage third-party technology providers to deliver certain services including our website, member portal, event registration systems, and online voting platform. These vendors access personal data only to the extent necessary to provide their services and are bound by written data processing agreements that prohibit use of data for any other purpose. We conduct appropriate due diligence on vendors handling member data.

6.2 Disclosure to Government and Law Enforcement Authorities

We may disclose personal data to government entities, law enforcement agencies, regulatory authorities, or courts where required to do so by law, regulation, or a binding legal order. Where permissible, we will notify affected individuals of such disclosure.

6.3 Within the Association

Access to personal data within the Association is restricted to authorised officers, committee members, consultants, auditors and secretariat staff who require the personal data in the performance of their roles. All such persons are bound by this Policy and subject to confidentiality obligations, whether arising under their terms of engagement, applicable law, or any other binding arrangement with the Association.

6.4 Publicly Available Information

Certain information, such as the names and designations of executive council members and event speakers, may be published on the Association’s website or in official communications as part of the Association’s transparency obligations. Members whose information is to be published will be informed in advance. Any information related to event / person shared through LinkedIn may also be governed by this Policy.

7. RETENTION OF PERSONAL DATA

We retain personal data only for as long as necessary to fulfil the specified purposes for which it was collected, or as required by applicable law and shall not permit any third-party technology providers engaged by us to retain it beyond such period.

We shall promptly and securely erase your personal data, in accordance with applicable law, upon the fulfilment of the specified purpose for which it was collected, or lawful withdrawal of your consent, whichever is earlier.

8. ELECTIONS

In view of the particular sensitivity of electoral processes, the following additional provisions apply to the collection and use of personal data in connection with Association elections.

8.1 Secrecy of the Ballot

The Association guarantees the absolute secrecy of each member’s vote. The voting system is designed and administered such that individual voting preferences cannot be identified or linked to any specific voter by any person, including elections committee members, governing council officers, or secretariat staff. Only aggregate vote counts are disclosed upon declaration of results.

8.2 Voter Data

Personal data of voters is used exclusively to verify eligibility and administer the ballot. Voting credentials are issued individually and are non-transferable. The system records whether a ballot has been submitted, without recording the nature of the vote, to prevent duplicate voting while preserving ballot secrecy.

8.3 Candidate Data

Nominee information, including name, photograph, designation, organisation, and professional biography, is shared with the membership solely to enable informed voting. Such information is published with the explicit consent of the nominee. Nominees may not withdraw consent after the nomination has been accepted and the voting process has commenced.

8.4 Election Integrity

A time-stamped audit trail is maintained for the purpose of post-election verification and dispute resolution. Access to this audit trail is restricted to the Elections Committee and any external auditor or scrutineer appointed for this purpose, each of whom is bound by confidentiality obligations. The audit trail does not record individual voting preferences.

8.5 Disputes and Grievances

Members may raise election-related data privacy grievances with the Elections Committee within 7 (seven) days of the declaration of results. All grievances will be addressed in accordance with the Association’s dispute resolution procedures.

9. USE OF COOKIES

Our website uses cookies and similar technologies to enhance user experience and gather analytics on website usage. Cookies are small data files stored on your device when you visit our website. We use the following types of cookies:

9.1 Essential cookies: Necessary for the operation of the website and member portal. These cannot be disabled without affecting website functionality.

9.2 Analytics cookies: Used to understand how visitors interact with our website, which pages are visited most frequently, and how we can improve content and navigation. These are used in aggregate and anonymised form.

9.3 Preference cookies: Used to remember your settings and preferences for a more personalised experience.

You may control cookie settings through your browser preferences. Please note that disabling certain cookies may affect the functionality of the website or member portal. We do not use cookies for advertising or third-party tracking purposes.

10. SECURITY CONTROLS FOR PERSONAL DATA

The Association implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, accidental loss, or destruction.

Our security measures include:

10.1 Encrypted transmission of data through secure (HTTPS) connections on our website and digital platforms;

10.2 Role-based access controls ensuring data is accessible only to authorised personnel;

10.3 Confidentiality obligations binding all staff, officers, and committee members with access to personal data;

10.4 Due diligence and contractual safeguards governing third-party technology vendors;

10.5 Regular review and testing of security systems and processes; and

10.6 Staff training and awareness on personal data protection obligations.

In the event of a data breach that poses a risk to the rights of individuals, the Association will take prompt remedial action and notify affected individuals and, where required, relevant regulatory authorities, in accordance with applicable law.

No method of digital transmission or storage is entirely free from risk. While we strive to protect your personal data, we cannot guarantee absolute security. We encourage members to use strong, unique passwords for their member portal accounts and to notify us immediately of any suspected unauthorised access.

11. YOUR RIGHTS

Subject to applicable law and the operational requirements of the Association, you shall have the following rights in relation to your personal data collected and processed by us or any third parties engaged by us:

  1. Right to access information about personal data: You shall have the right to obtain, upon submission of a valid request, a comprehensive summary of your personal data being processed by us, the purposes for which it is being processed, the third parties with whom it has been shared, and a description of the specific data so shared.
  2. Right to correction and erasure of personal data: You shall have the right to require us to correct any inaccurate or misleading personal data, complete any incomplete personal data, and update your personal data as necessary. You shall further have the right to request the erasure of your personal data where the purpose for which it was collected has been fulfilled and retention is no longer necessary, except where such retention is strictly required for compliance with a prevailing legal obligation under applicable law.
  3. Right of grievance redressal: You shall have the right to register any grievance concerning our obligations in relation to the processing of your personal data or the exercise of your statutory rights, and to have such grievance addressed in a timely and effective manner. We have appointed the Grievance Officer, who shall acknowledge and conclusively resolve all such grievances. Any requests for the exercise of your rights may be directed to the Grievance Officer identified in Clause 15 of this Policy. We shall respond to all such requests within a time as prescribed under Clause 15 of this Policy and shall make corrections or deletions as appropriate, subject to applicable legal requirements.
  4. Right to nominate: You shall have the right to formally nominate another person, in the manner prescribed by law, to exercise your rights under the applicable law, in the event of your death or incapacity.
  5. Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing carried out prior to withdrawal.

To exercise any of the above rights, please submit a written request to the Grievance Officer identified in Clause 15 of this Policy.

12. THIRD-PARTY LINKS AND SERVICES

Our website may contain links to third-party websites, publications, or resources for the convenience of members. The Association is not responsible for the privacy practices or content of such third-party sites. We encourage members to review the privacy policies of any external sites they visit. The inclusion of a link does not imply endorsement by the Association.

13. DATA OF MINORS

The Association’s services, membership, and activities are directed exclusively at finance and compliance professionals and are not intended for individuals below the age of 18 (eighteen) years. We do not knowingly collect personal data from minors. If we become aware that personal data of a minor has been collected inadvertently, we will take prompt steps to delete such data.

14. AMENDMENTS TO THIS POLICY

The Association reserves the right to revise this Policy from time to time to reflect changes in applicable law, technology, or Association practice. The most current version of this Policy will always be available on the Association’s official website.

15. GRIEVANCE REDRESSAL MECHANISM

The Association has designated Mr. Manoj Borkar as its Grievance Officer, as the primary channel of communication for addressing your queries, discrepancies, and grievances in relation to the collection or processing of your personal data.

The Grievance Officer may be contacted at:

Name: Mr. Manoj Borkar
Designation: Director
Email: connect@aifcfo.com
Address: 25, Floor 1, Plot No. 20, Lawyers Chambers, R.S. Sapre Marg, Lohar Chawl, Kalbadevi, Mumbai - 400002

Upon receipt of your request, the Grievance Officer shall acknowledge it within 7 (seven) days and provide a substantive response within 30 (thirty) days. In complex cases, this period may be extended by a further 30 (thirty) days, and you will be notified of such extension accordingly.

No fee shall be charged for processing your request, unless the request is manifestly unfounded or excessive, in which case we reserve the right to charge a reasonable administrative fee or decline to act on the request, with reasons provided to you in writing.

We are committed to addressing all data privacy concerns promptly and in good faith. If you are not satisfied with our response, you may seek recourse under applicable law.