Privacy policy
What we collect, what we deliberately do not, and how to ask us about it.
Last updated 8 October 2026
1Who we are
Shivaay Financial Services is a sole proprietorship owned by Pratik Ganatra. We distribute life-insurance products. We help people understand options, complete proposals, and stay in touch with their insurer after a policy is issued. The policies themselves are issued by the insurance company, not by us.
- Pratik Ganatra, Proprietor
- Shivaay Financial Services
- 75A Bakul Bagan Road, Bhowanipore, Kolkata 700025, West Bengal, India
- Phone and WhatsApp: +91 90078 93908
- Email: pratik.ganatra947@gmail.com
In this policy, “we”, “us” and “our” mean Shivaay Financial Services. “You” means a visitor to this website.
We are a very small firm. This website is a brochure. It is deliberately built so that it collects as little about you as possible, and we would rather say that plainly than publish a long policy describing things we do not do.
2What this website does not do
We want to be specific, because most privacy policies are vaguer than they need to be. This website is a set of static pages. It has:
- No forms. There is no contact form, no enquiry form, no newsletter sign-up, and no “request a callback” box. There is nothing on this site you can type into and send to us.
- No accounts. There is no login, no registration, no customer portal and no password.
- No cookies of our own. We do not set cookies, local storage, or any similar identifier for our own purposes. The Google Map on the contact page is the one exception on the site, and it is Google’s, not ours. See below.
- No analytics. We do not use Google Analytics or any other measurement product. We do not know how many people visit this site or which pages they read.
- No advertising or tracking tags. No advertising pixels, conversion tracking, remarketing tags, tag manager, or social-media scripts.
- No profiling. We do not build profiles of visitors and we do not score or segment anyone based on their use of this site.
- No third-party web fonts. The typefaces are served from this site, so your browser does not contact a font service while a page loads.
Because of all this, simply reading this website does not tell us who you are.
3What we do receive, and how
When you contact us
Several pages carry outbound links: a WhatsApp link, an email link and a phone link. If you use one, you leave this website and start a conversation on your own device, through your own app or dialler.
If you then choose to message or call us, we receive whatever you choose to tell us: typically your name, the mobile number you message from together with whatever display name you have set on your own WhatsApp profile, your email address if you write to us, the content of your message, and anything else you volunteer such as your age, city, family situation or what cover you are looking for.
Some of our WhatsApp links open with a short message already typed in, saying which plan you were reading about. You can edit or delete that text before you send it. Nothing is sent until you press send.
The map on our contact page
Our contact page contains an embedded Google Map showing where our office is. When that page opens, your browser makes a direct request to Google’s servers to fetch the map. That request is not routed through us and we cannot see it, but Google can.
This matters more than it might sound. Google may receive your IP address, information about your browser and device, the page you came from, and the date and time, and may read or set cookies associated with your Google account if you have one. What Google does with that is governed by Google’s own privacy policy, not ours. We have no agreement with Google beyond using a publicly available embed, no account tied to it, and no access to anything it records.
If you would rather your browser did not contact Google, do not open the contact page, or block the frame using your browser’s content settings or an extension. Our address is written out in text on the same page, and the phone number and email work without the map, so nothing is lost.
Links to other companies
The site also links out to Google Maps for directions, and to WhatsApp. These are ordinary links. Nothing is sent anywhere when the page loads, only if you click. Once you click, you are on that company’s service and its privacy policy governs what it does. We cannot control or audit that, and we mention it only so you are not surprised.
Information you give us during a proposal
If you ask us to help you buy or service a policy, we collect what the insurer’s proposal form requires. Depending on the product that can include your full name, date of birth, address, contact details, identity and address documents, PAN, bank details, occupation and income, nominee details, and health and lifestyle information.
Health information is sensitive. We collect it only because the insurer needs it to underwrite the policy, we collect only what the insurer asks for, and we pass it to the insurer. We do not use it for anything else. This happens by phone, WhatsApp, email or in person, not through this website. We describe it here so that this policy covers the whole relationship and not just the brochure.
4Technical records kept by our host
This website is hosted on Amazon Web Services using Amazon S3 and Amazon CloudFront. Like any web host, AWS may generate standard server access logs when a page is served, typically recording the requesting IP address, the date and time, the file requested, the response code and the browser’s user-agent string.
Those logs exist for delivering the site, keeping it available and investigating abuse. We do not use them for analytics, we do not attempt to identify individuals from them, and we do not combine them with anything else.
TO CONFIRM: whether access logging is enabled on the distribution, the retention period if it is, and the AWS hosting region.
5Why we use your information
We use what you send us for these purposes and no others:
- To answer your question or return your call.
- To explain products, compare options and prepare illustrations for you.
- To help you complete a proposal and submit it to the insurer.
- To service a policy after it is issued: renewal reminders, changes of address or nominee, and assistance at claim stage.
- To keep the records we are required to keep, and to respond to the insurer, the intermediary we are registered with, IRDAI, an ombudsman, a tax authority or a court where we are obliged to.
- To deal with a complaint or a dispute.
We do not sell your personal data. We do not rent, trade or share it for anyone else’s marketing. We do not send bulk promotional messages to people who have merely enquired, and we do not pass your number to other agents or to lead-generation businesses.
6Our legal basis, and your consent
India’s Digital Personal Data Protection Act, 2023 is being brought into force in stages. The Digital Personal Data Protection Rules, 2025 were notified on 13 November 2025, and most of the substantive obligations on businesses like ours are scheduled to take effect on 13 May 2027. We do not claim to be already complying with provisions that are not yet in force, and we do not claim certification or approval by any authority.
What we do say is this: we have written this policy to follow the principles the Act sets out: tell people what you are doing, do only what you said, keep only what you need, keep it safely, and answer people when they ask. We will meet the Act’s requirements as they come into force.
In the meantime we also handle personal information under the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, which remain in force. Those rules require a business handling sensitive personal information to publish a privacy policy. This document is that policy.
Where we rely on consent, that consent is the ordinary, visible kind: you contact us because you want to, and you give us your details for a proposal because you want the policy. You can withdraw consent at any time by telling us so. If you withdraw it while a proposal is in progress we may not be able to take it further, and we may still have to keep records the law requires.
7Who we share information with
We share your information only where it is necessary, and only with:
- The insurer. To get you a policy, your proposal and supporting information must go to the insurer you have chosen. From that point the insurer is responsible for the data it holds about you as its own policyholder, under its own privacy policy.
- The intermediary we are registered with, where business is placed through one. TO CONFIRM: the intermediary’s registered name and IRDAI registration number.
- Our hosting and communication providers. Amazon Web Services hosts this website; our email and WhatsApp messages sit with the providers of those services. They hold that data as a consequence of carrying our mail and hosting our pages, not for their own purposes.
- Professional advisers, such as an accountant or a lawyer, where we genuinely need advice and only to the extent needed.
- Authorities and courts, where we are required by law to disclose, or where disclosure is needed to establish or defend a legal claim.
We do not use any outside call centre, tele-calling vendor or marketing agency, and we do not hand your enquiry to one.
8How long we keep things
- Casual enquiries that go nowhere: kept only as long as useful, and in any case no longer than 24 months, then deleted. WhatsApp chats are cleared on the same basis.
- Proposals that are not completed: 24 months from the date the proposal lapses or is declined, unless the insurer requires otherwise.
- Policies that are issued: for as long as the policy is in force, and afterwards for the period required by insurance, tax and record-keeping law. TO CONFIRM: the period your insurer or intermediary requires.
- Complaint records: five years from closure.
Where the law allows us to delete and we have no continuing need, we delete rather than archive.
9How we protect information
We are honest about scale here. We are a one-person firm and our safeguards are proportionate to that.
- The website holds no personal data at all. There is no database behind it and no form endpoint to attack.
- The site is served over HTTPS.
- Messages and documents you send us are held on password-protected, screen-locked devices and accounts under the proprietor’s control, with two-factor authentication on the email account.
- Access is limited to the proprietor. We have no staff with access to client files.
- Documents containing identity, financial or health information are not shared over open channels beyond what is needed to submit them to the insurer, and are removed from devices once no longer needed.
No method of transmission or storage is perfectly secure. If something goes wrong and your personal data is affected, we will tell you promptly and in plain language what happened, what it means for you and what we are doing about it, and we will notify the Data Protection Board of India as and when the law requires that of us.
10Your rights, and how to use them
Under the Digital Personal Data Protection Act, 2023, as its provisions come into force, you have the right to:
- Know what we hold: a summary of the personal data we hold about you, what we are doing with it, and who we have shared it with.
- Correct it: have anything inaccurate or misleading corrected, anything incomplete completed, and anything out of date updated.
- Have it erased: where we no longer need it for the purpose you gave it for and no law requires us to keep it.
- Be heard: raise a grievance about how we have handled your data, and get an answer.
- Nominate someone: name another person to exercise these rights on your behalf if you die or become unable to act for yourself.
- Withdraw consent: with the practical consequences set out above.
To make a request, write to pratik.ganatra947@gmail.com with the subject line “Data request”, send a message on WhatsApp to +91 90078 93908, or write to the postal address above. Please tell us the name and number or email address you dealt with us under, and the policy or proposal number if there is one. We may need to verify that the request is really from you, and we will ask for the least we need to be sure.
We will acknowledge your request within 7 working days and aim to resolve it within 30 days. In no case will we take longer than 90 days. There is no charge. If we cannot do what you have asked, we will tell you why.
The person who answers questions about how we process personal data is the proprietor, Pratik Ganatra, reachable at the contact details above. We are not a Significant Data Fiduciary and are not required to appoint a statutory Data Protection Officer.
11Grievance redressal
If you are unhappy with how we have handled your personal data, or with any response you have had from us, please raise it with our grievance officer.
- Grievance Officer: Pratik Ganatra, Proprietor
- Email: pratik.ganatra947@gmail.com
- Phone: +91 90078 93908
- Post: 75A Bakul Bagan Road, Bhowanipore, Kolkata 700025
- Hours: TO CONFIRM
We will acknowledge your grievance within 7 working days and give you a substantive reply within 30 days, and in any event within 90 days of receipt.
If we have not resolved it, you may approach the Data Protection Board of India once it is operational and accepting complaints. If your complaint is about an insurance policy rather than about data, please also take it up with the insurer’s grievance cell, after which you may use IRDAI’s Bima Bharosa portal or the Insurance Ombudsman for your area. Nothing in this policy limits your right to do so.
12Children
This website is written for adults who are thinking about insurance. It is not aimed at children and nothing on it is designed to appeal to children. Under the Act a child is a person under 18.
We do not knowingly collect personal data about a child from the child, and we do not track, profile or target advertising at children. We do none of those things at all. Children are often insured and often named as nominees; where that happens we take the child’s details from the parent or lawful guardian as part of a proposal the parent is making, and we will not process a child’s personal data without the verifiable consent of the parent or guardian.
If you believe we hold information about a child that we should not, write to us and we will delete it.
13Automated decisions
We do not make any decision about you automatically. There is no algorithm here. Whether a policy is accepted, and on what terms, is decided by the insurer’s underwriters under the insurer’s own process, not by us and not by this website.
14Changes to this policy
If what we do changes, this policy will change with it. In particular, if we ever add a contact form, an analytics tool or any cookie, we will update this policy before we switch it on, and we will say what it does. The date at the top shows when this version was published.