Skip to main content
  • +917680990163
  • support@candlesignals.com
  • Motinagar, Hyderabad, Telangana

DPDP Consent & Privacy Notice

This DPDP Consent & Privacy Notice explains how CandleSignals, the research services brand of B-CUBE Consulting Private Limited, collects, processes, stores, uses, shares, retains and protects personal data relating to clients and prospective clients.The same substantive document is presented through the CandleSignals eKYC and onboarding portal for review and electronic consent. It forms part of the contractual and regulatory framework governing the provision of research services.

Estimated reading time: 20–25 minutes

ParticularDetails
DocumentDPDP Consent & Privacy Notice
Version1.0
Effective Date1st July 2026
Last Reviewed21 July 2026
Applicable ToAll clients availing research services
Regulatory FrameworkSEBI (Research Analysts) Regulations, 2014

Regulatory & Compliance Library

Access all regulatory disclosures, investor information, grievance mechanisms, statutory policies and accessibility documents published by CandleSignals.

Registration & Disclosures

Investor Grievance Redressal

Documents & Policies

Accessibility


1. PURPOSE OF COLLECTION AND PROCESSING OF PERSONAL DATA

The Company may collect and process personal data for the following lawful purposes:

Regulatory Compliance

  • KYC verification;
  • KRA registration and validation;
  • SEBI compliance;
  • Regulatory reporting;
  • Audit requirements;
  • Regulatory verification;
  • Compliance verification;
  • Beneficial ownership verification where applicable;
  • Prevention of misuse of services.

Client Onboarding

  • Client identification;
  • Account creation;
  • Subscription management;
  • Service activation;
  • Client due diligence.

Service Delivery

  • Research reports;
  • Investment recommendations;
  • Model portfolios;
  • Alerts and notifications;
  • Educational content;
  • Client support.

Communication

  • Service updates;
  • Regulatory disclosures;
  • Client communications;
  • Grievance handling;
  • Compliance notifications.

Legal and Administrative Purposes

  • Record retention;
  • Internal administration;
  • Risk management;
  • Legal proceedings;
  • Regulatory inspections and investigations.

2. PURPOSE LIMITATION

The Company shall process personal data only for lawful purposes connected with:

  • Research Analyst services;
  • Regulatory compliance;
  • KYC requirements;
  • Client servicing;
  • Risk management;
  • Internal administration;
  • Business continuity; and
  • Other purposes permitted under applicable law.

Personal data shall not be processed for unrelated purposes except where permitted under applicable law or with the Client’s consent.

3. PERSONAL DATA COLLECTED

The Company may collect, receive, verify, and process the following categories of personal data:

Identity Information

  • Name;
  • PAN;
  • Date of Birth;
  • Photograph;
  • Signature;
  • Government-issued identification documents.

Contact Information

  • Mobile Number;
  • Email Address;
  • Residential Address;
  • Correspondence Address.

Service and Subscription Information

  • Subscription details;
  • Service preferences;
  • Communication preferences;
  • Client declarations;
  • Family information where required for regulatory compliance;
  • Other information voluntarily provided by the Client.

KYC Information

  • PAN copy;
  • Address proof;
  • KYC documents;
  • KRA records;
  • Verification records.

Technical Information

  • IP address;
  • Device information;
  • Browser information;
  • Login activity;
  • Usage information.

Communication Records

  • Emails;
  • Phone communications;
  • WhatsApp communications;
  • Telegram communications;
  • Client portal interactions;
  • Customer support records.

4. CONSENT FOR PROCESSING

I hereby provide my free, specific, informed, unconditional, unambiguous, and affirmative consent for the collection, storage, processing, use, transmission, verification, retention, and lawful handling of my personal data for the purposes described in this Notice.

5. CONSENT FOR KYC VERIFICATION

I authorize the Company to:

  • Verify my identity and KYC information;
  • Upload, access, retrieve, and update KYC records through KRA systems;
  • Verify information through regulatory databases;
  • Verify information through government-authorized systems;
  • Conduct due diligence required under applicable regulations;

Maintain records required by law.

6. CONSENT FOR DATA SHARING

I authorize the Company to share my personal data, where reasonably necessary, with:

Regulatory Authorities

  • SEBI;
  • RAASB;
  • KRA;
  • Stock Exchanges;
  • Government authorities;
  • Courts and tribunals.

Service Providers

  • KYC service providers;
  • Verification agencies;
  • Cloud service providers;
  • Technology service providers;
  • CRM providers;
  • Communication service providers;
  • Payment gateway providers.

Professional Advisors

  • Auditors;
  • Legal advisors;
  • Compliance consultants;
  • Tax advisors.

Such sharing shall be limited to lawful business, regulatory, compliance, operational, audit, or legal purposes.

7. DISCLOSURE REQUIRED BY LAW

The Company may disclose personal data without obtaining additional consent where such disclosure is required by:

  • Applicable law;
  • Court orders;
  • Regulatory directions;
  • Government authorities;
  • SEBI;
  • RAASB;
  • KRA;
  • Law enforcement agencies; or
  • Any competent authority.

Such disclosures shall be limited to the extent required under applicable law.

8. CROSS-BORDER PROCESSING

The Client acknowledges that certain technology service providers engaged by the Company may process, transmit, back up, host, or store data in jurisdictions outside India, subject to applicable laws, contractual safeguards, and reasonable security measures.

9. USE OF AI AND THIRD-PARTY TECHNOLOGY PLATFORMS

The Client acknowledges that the Company may utilize:

  • Artificial Intelligence systems;
  • Large Language Models (LLMs);
  • Cloud infrastructure providers;
  • CRM platforms;
  • Automation systems;
  • Analytics platforms;
  • Communication platforms; and
  • Technology service providers

for lawful business purposes.

The Company shall take reasonable measures to engage such service providers in accordance with applicable legal and regulatory requirements.

10. AUTOMATED PROCESSING

The Client acknowledges that certain activities may be carried out through automated systems, including:

  • KYC workflows;
  • Client onboarding processes;
  • Communication systems;
  • Research delivery systems;
  • CRM systems;
  • Compliance monitoring systems; and
  • AI-enabled systems.

Where appropriate, reasonable human oversight shall be maintained.

11. CONSENT FOR ELECTRONIC COMMUNICATION

I consent to receiving communications through:

  • Email;
  • SMS;
  • WhatsApp;
  • Telegram;
  • Mobile applications;
  • Client portal; and
  • Other electronic communication channels.

12. CONSENT FOR COMMUNICATION RETENTION

I understand and consent that communications with the Company may be monitored, stored, archived, retained, or recorded where applicable and permitted by law for:

  • Regulatory compliance;
  • Audit purposes;
  • Risk management;
  • Grievance handling;
  • Legal proceedings; and
  • Internal controls.

13. DATA RETENTION

Personal data may be retained:

  • During the client relationship;
  • During regulatory retention periods;
  • During audit periods;
  • During investigations;
  • During legal proceedings; and
  • For such periods as required under applicable law.

Upon expiry of applicable retention requirements, data may be deleted, anonymized, archived, or otherwise processed in accordance with applicable law.

14. BUSINESS CONTINUITY AND DISASTER RECOVERY

The Client acknowledges that personal data may be stored in:

  • Backup systems;
  • Disaster recovery systems;
  • Archival systems; and
  • Business continuity environments

maintained by the Company or its authorized service providers.

15. DATA SECURITY

The Company shall implement reasonable administrative, technical, organizational, and operational safeguards to protect personal data.

However, no technology system can guarantee absolute security and the Client acknowledges the inherent risks associated with electronic systems.

15A. DATA ACCURACY

The Client shall ensure that personal data provided to the Company is accurate, complete, current, and not misleading.

The Client shall promptly notify the Company of any material change in information previously provided.

16. CLIENT RIGHTS

Subject to applicable law, the Client may:

Request Access

Seek information regarding personal data processed by the Company.

Request Correction

Request correction, updating, or completion of personal data.

Withdraw Consent

Withdraw consent in accordance with applicable law.

Raise Grievances

Submit complaints or concerns regarding personal data processing.

Right to Nominate

Nominate another individual who may exercise rights on behalf of the Client in accordance with applicable law in the event of death or incapacity.

17. WITHDRAWAL OF CONSENT

A Client may withdraw consent by submitting a written request to the Company’s Grievance Officer or Compliance Officer through designated communication channels.

Withdrawal of consent shall not affect processing undertaken prior to such withdrawal.

The Client acknowledges that withdrawal of consent may impact the Company’s ability to provide Research Services or comply with regulatory obligations.

18. REGULATORY RETENTION EXCEPTION

Withdrawal of consent shall not require deletion of personal data that the Company is required to retain under:

  • SEBI regulations;
  • KYC regulations;
  • Tax laws;
  • Court orders;
  • Regulatory directions; or
  • Other applicable laws.

Such data may continue to be retained for the duration mandated under applicable law.

19. CONSEQUENCES OF WITHDRAWAL OF CONSENT

Withdrawal of consent may result in:

  • Suspension of services;
  • Restriction of services;
  • Inability to complete KYC requirements;
  • Inability to maintain KRA records; or
  • Termination of Research Services where legally necessary.

20. GRIEVANCE OFFICER UNDER DPDP ACT

For privacy-related requests, complaints, or grievances:

Name: Sailaja Boddu
Designation: Compliance Officer
Email: sailaja.b@b-cube.in
Mobile: +91 76809 90168

21. CLIENT DECLARATION AND CONSENT

I hereby declare and confirm that:

  1. I have carefully read and understood this Consent and Privacy Notice.
  2. I voluntarily provide my personal information to B-CUBE Consulting Private Limited.
  3. I provide my free, specific, informed, unconditional, unambiguous, and affirmative consent for the collection, storage, processing, verification, transmission, retention, and lawful use of my personal data.
  4. I consent to KYC verification and KRA processing.
  5. I consent to data sharing for lawful regulatory, compliance, operational, and service-delivery purposes.
  6. I consent to electronic communications.
  7. I consent to communication retention and recording where applicable and permitted by law.
  8. I acknowledge the use of cloud systems, technology platforms, automation systems, and AI-enabled systems by the Company.
  9. I understand my rights under applicable data protection laws.
  10. I undertake to promptly notify the Company regarding any change in my personal information, contact information, KYC information, or other information previously provided.
  11. I understand that withdrawal of consent may affect the Company’s ability to provide services.
  12. I voluntarily agree to the processing of my personal data in accordance with this Notice.

Note: This page is published for transparency and investor reference. Clients subscribe to CandleSignals research services only after completing the electronic onboarding process on the CandleSignals eKYC platform, where acceptance of this Agreement and other applicable regulatory documents is obtained electronically.