Ardour Labs markardour labs
FIU-IND registered VDA Service Provider

Privacy Policy

How we collect, use, protect, and lawfully disclose your personal data as a regulated VDA Service Provider in India.

Effective
22 July 2026
Last updated
22 July 2026

1. Introduction & scope

This Privacy Policy explains how Ardour Labs Private Limited(“Ardour Labs”, “we”, “us”, or “our”), a company incorporated in India (CIN U72900KA2017PTC103112) and a FIU-IND registered VDA Service Provider, collects, processes, stores, protects, and discloses personal data when you visit ardourlabs.com, engage our OTC desk, use our on-ramp / off-ramp services, or complete identity verification.

We act as a Data Fiduciaryunder the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and adhere to applicable rules issued thereunder. Where we process data on behalf of a partner institution, we may act as a Data Processor under a separate agreement.

By using our services, you acknowledge the practices described here. If you do not agree, please do not use our services.

2. Personal data we collect

We collect only the data necessary to deliver regulated services and meet our legal obligations:

  • Identity data (KYC): full legal name, date of birth, nationality, photograph, government identifiers (e.g. PAN, Aadhaar/VID as permitted, passport, driving licence), and a liveness/selfie check.
  • Entity data (KYB): corporate name, CIN/registration number, registered address, ownership and control structure, ultimate beneficial owner (UBO) details, and authorised-signatory documentation.
  • Financial & transactional data: bank account details, wallet addresses, transaction amounts, currency pairs, counterparties, and settlement records.
  • Source-of-funds / source-of-wealth data: declarations and supporting evidence gathered during enhanced due diligence (EDD).
  • Technical data: IP address, device and browser information, and cookies strictly necessary for security and site functionality.
  • Communications: records of your correspondence with our team, including quote requests and support enquiries.

Some of the above constitutes sensitive / financial information. We handle it with heightened safeguards and strict access controls.

3. How & why we use your data

We process personal data for the following purposes and lawful bases:

  • Legal obligation & regulatory compliance— to perform Customer Due Diligence (CDD), EDD, sanctions and PEP screening, transaction monitoring, and record-keeping mandated by the Prevention of Money Laundering Act, 2002 (“PMLA”), PML (Maintenance of Records) Rules, and FIU-IND directions.
  • Contractual necessity — to onboard you, execute OTC / on-ramp / off-ramp transactions, and provide settlement and support.
  • Legitimate interest / security — to prevent fraud, secure our systems, and protect our legal rights.
  • Consent — for any optional processing (e.g. product updates), which you may withdraw at any time.

We do not sell your personal data, and we do not use it for behavioural advertising.

4. Identity verification & Sumsub

We use Sumsub (Sum and Substance Ltd) as our identity-verification processor to conduct KYC/KYB, document authentication, biometric liveness, and AML screening. When you complete verification, the documents and data you submit are processed by Sumsub on our behalf under a data-processing agreement and returned to us as a verification result.

Sumsub processes this data under contractual and confidentiality obligations consistent with applicable law. We remain responsible to you as the Data Fiduciary for this processing.

5. Disclosure to regulators & law enforcement

As a FIU-IND registered VDA Service Provider, we are legally required to share certain information with regulators and authorities, and we may do so without prior notice to you where the law requires confidentiality. This is a core part of India's AML/CFT framework and is not optional for us or for you.

We may disclose personal and transactional data to:

  • Financial Intelligence Unit – India (FIU-IND) — including Suspicious Transaction Reports (STRs), Cash Transaction Reports (CTRs), and other reports prescribed under the PMLA and its rules.
  • Regulators & government authorities — such as the Reserve Bank of India, the Income Tax Department, the Directorate of Enforcement, and other competent statutory or judicial bodies.
  • Law enforcement — in response to lawful requests, summons, court orders, or investigations.
  • Banking & settlement partners — to the extent necessary to execute and settle your transactions and satisfy their own regulatory obligations.

Where permitted, we limit disclosure to what is necessary and proportionate. However, we will comply fully with binding legal and regulatory requirements, and certain reporting (such as STRs) is confidential by law — meaning we are prohibited from “tipping off” the subject of a report.

6. Data retention

We retain identification records, account files, and transaction records for a minimum of five (5) years after the end of our business relationship or the date of the relevant transaction, as required by the PMLA and PML (Maintenance of Records) Rules — and longer where a competent authority so directs or where necessary to establish, exercise, or defend legal claims.

After the applicable retention period, we securely delete or irreversibly anonymise personal data unless a continuing legal obligation applies.

7. Data security

We apply reasonable technical and organisational security measures aligned with recognised standards, including encryption in transit and at rest, strict role-based access controls, network segmentation, logging and monitoring, and regular reviews. Access to sensitive KYC/EDD data is restricted to authorised compliance personnel on a need-to-know basis.

No system is perfectly secure. In the event of a personal-data breach that is likely to result in harm, we will notify affected individuals and the Data Protection Board of India as required by the DPDP Act.

8. Your rights

Subject to the DPDP Act and applicable law, you may have the right to:

  • access a summary of the personal data we process about you and how we process it;
  • request correction, completion, or updating of inaccurate or incomplete data;
  • request erasure of data that is no longer necessary for the purpose it was collected;
  • withdraw consent for processing that relies on consent; and
  • nominate another individual to exercise your rights in the event of death or incapacity.

These rights are subject to our overriding legal obligations — in particular, we cannot delete or withhold records we are required to retain and report under AML/CFT law. To exercise a right, contact us at compliance@ardourlabs.com. We may need to verify your identity before acting on a request.

9. Grievance redressal

If you have a complaint about how we handle your personal data, please contact our Grievance Officer / Compliance team at compliance@ardourlabs.com or by post at our registered office:

Ardour Labs Private Limited
204, Block 7C, Provident Sunworth, Off Mysore Road, Venkatapura
Bangalore, Karnataka 560060, India

We will acknowledge and address grievances within the timelines prescribed by law. If unresolved, you may escalate to the Data Protection Board of India.

10. Cookies & changes to this policy

We use only strictly necessary cookies for security and core functionality; we do not use advertising or third-party tracking cookies. We may update this Privacy Policy to reflect legal, regulatory, or operational changes. The “Last updated” date above indicates the latest revision, and material changes will be highlighted on this page. Continued use of our services after an update constitutes acknowledgement of the revised policy. This policy should be read together with our Terms of Service.

Questions about this document or how we handle your data? Contact our compliance team at compliance@ardourlabs.com. You may also review our Terms of Service.