Privacy Policy

This page explains what happens to the information you give this website: what is collected, why, where it is kept, who else sees it, and what you can require us to do about it. It is written in the language of the Digital Personal Data Protection Act, 2023 — the law that governs personal data in India. Under that Act you are the Data Principal and this practice is the Data Fiduciary.

Where the law currently stands. The Digital Personal Data Protection Act, 2023 is in force, but it is being switched on in stages by the Rules made under it, which were notified in November 2025. The provisions setting up the Data Protection Board of India started then. The main obligations on a Data Fiduciary, and the machinery for enforcing your rights, are due to start on 13 May 2027. We are not waiting for that date to apply this policy — but you should know that some of what is described below is a commitment we are making now, ahead of the point at which it becomes enforceable against us.

Who is responsible for your personal data?

This practice is the Data Fiduciary for what you give this site — it decides what is collected and why. It is a sole proprietorship, which is not a company and is not separate from the person who runs it, so the person legally answerable for your data is the proprietor herself.

Data Fiduciary
Prakash Financial Services, trading as Prakash Finserv.
Registered category
Individual insurance agent (life), operating as a sole proprietorship. IRDAI agent registration code RLH20775410.
Registered office
Site 7, House No. 8, LGF, New Rajinder Nagar, New Delhi, Central Delhi, Delhi 110060
Who answers questions about your data
Dr. Sonali Walia — [email protected], +91 87968 39997.

Section 8(9) of the Act requires a Data Fiduciary to publish the contact details of a Data Protection Officer, where one applies, or of a person who can answer your questions about how your data is processed. This practice has not been notified as a Significant Data Fiduciary and has no Data Protection Officer. The person who answers those questions is the proprietor, named above.

The words this policy uses

The Act has its own vocabulary, and using it loosely is how privacy notices end up saying nothing. These are the terms that matter here.

Data Principal
You — the person the personal data is about. Where the data is a child's, it also means the parent or lawful guardian.
Data Fiduciary
Whoever decides why and how your personal data is processed. For what you submit through this site, that is this practice.
Data Processor
A company that processes personal data on a Data Fiduciary's instructions and is not allowed to use it for its own purposes. Our database provider is a Data Processor. It is not free to do anything with your data that we have not asked it to do.
Consent notice
The plain-language statement shown to you before you agree, saying what is being collected, what it will be used for, and how to withdraw. On this site it appears at the point where the application form is submitted — not buried in a link.
Personal data
Any data about you from which you can be identified. The Act does not sort personal data into ordinary and "sensitive" classes the way older Indian data rules did. Health information is nonetheless sensitive in the ordinary meaning of the word, and this policy treats it as the most sensitive thing on the page.

What does the application form collect, and why?

The application form asks for identity, contact details, income band, occupation, residency, lifestyle including tobacco use, and health information. It asks because an insurer's underwriter cannot assess an application without those answers. Nothing on the form is collected for marketing, and nothing is collected that an underwriter does not need.

What the application form collects, and the reason for each part
Category What it covers Why it is asked
Who you are Your name, date of birth and gender. To identify the person the cover would be on, and to match your application to you.
How to reach you Your mobile number, email address and city. To send you your application, answer your questions, and let the insurer contact you.
Income band and occupation A band your annual income falls into, and what you do for a living. An underwriter sizes cover against income, and some occupations carry a different risk.
Residency Whether you live in India or abroad, and your tax residency. Residency changes which application route and which documents apply.
Lifestyle Tobacco use, alcohol use, and hazardous pursuits. These change how an underwriter assesses risk. Tobacco use in particular does.
Health information Your height and weight, your medical history, and your family's medical history. An underwriter cannot assess a life insurance application without it. This is the most sensitive thing you will tell us.

Health information is the part of this to be most careful about, and we would rather say so plainly than tuck it into a list. It goes to an underwriter so that a decision can be made on an accurate picture of you. You do not have to give it. If you do not, an application cannot be made, because there is nothing for an underwriter to assess.

What is the lawful basis for using it?

Consent. You are shown a consent notice before you submit the form, and nothing is sent anywhere until you act on it. Consent under the Act has to be free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to what is necessary for the stated purpose (Section 6).

You can withdraw that consent at any time, and it has to be as easy to withdraw as it was to give. Two honest consequences follow. Withdrawing does not make what was lawfully done before the withdrawal unlawful. And withdrawing it with us does not reach into the insurer's systems. Once your application has gone to the insurer, the insurer holds your data as a Data Fiduciary in its own right, under its own privacy notice and its own record-keeping duties. To withdraw it there, write to the insurer.

Where is your information stored?

A submitted application is stored in a managed database in our provider's Mumbai region (ap-south-1), which means the stored record stays in India. That is our choice about how to run this practice. The Act itself does not require personal data to be held in India; we hold it here anyway, because your application concerns an Indian insurance contract and the record ought to sit in the same jurisdiction as the contract.

That provider processes the record on our instructions as a Data Processor, under a contract, and may not use it for its own purposes. The Act requires that relationship to rest on a contract (Section 8).

Insurance record-keeping rules also govern records relating to Indian policies, and those obligations are written for insurers. Your application is sent to the insurer, which holds its own record of it, in its own systems, under its own retention policy — that record is not affected by anything on this page. What this site keeps is a copy, for the purposes set out above.

Who is your information shared with?

We email your completed application to the underwriter at the life insurer this practice is appointed by — the insurer named in the footer of every page on this site. That sharing is not an add-on you can opt out of while still applying: placing an application is sending it to an insurer. There is no application without it.

Beyond that, your information goes to:

  • Our database provider, which stores the submission as a Data Processor on our instructions, and may not use it for anything else.
  • Anyone we are legally obliged to give it to — a court, a regulator, or a law enforcement authority acting under a power that requires us to produce it.

We do not sell personal data. We do not share it with advertisers, data brokers or lead aggregators. We do not pass it to any other insurer, because this practice is appointed by one life insurer and places business with that insurer only. Once your application reaches the insurer, the insurer becomes responsible for it as a Data Fiduciary in its own right, and its own privacy notice governs what it then does.

When you consent, we write a record of the act of consenting: the date and time, the IP address the consent came from, your browser's user agent string, and a hash of the version of the consent wording you were shown. That record is immutable — it can be added to but not edited or deleted. The database itself refuses the change; it is not a matter of us choosing not to make one.

Each entry is also signed when it is written, using a key held outside the database entirely. That covers the narrower case of someone with enough access to switch the database's own rule off: the signature would stop matching, and the alteration would show. We check this periodically and before answering any dispute that turns on it.

This is deliberate, and it cuts both ways, so here is the reasoning. If it is ever disputed whether you agreed to something, the only thing that settles it is a record neither side can quietly rewrite — which protects you at least as much as it protects us. The cost is that this particular record is not erased on request, because a consent record that disappears when it becomes inconvenient would be worthless as evidence of consent. It holds no health information and no application answers.

What do the calculators do with what you type?

Nothing. The calculators on this site run entirely inside your browser. What you type into one is never sent to us, never sent to the insurer, never stored, and never logged. Close the tab and it is gone. You can use them without telling us anything at all, and you do not need to give us your contact details to see a result.

What does this site record about your visit?

Analytics on this site is server-side only. When a page is served, we record the page requested, the referring page, any campaign tags in the link (UTM values), a session identifier and a device class such as mobile or desktop. That list is complete as at launch. Your IP address is not part of that record.

There is no third-party analytics script on this site — nothing from an advertising network, nothing that follows you elsewhere — and no cookie is set for analytics. There is no cookie banner at launch because there is nothing to ask you about. What is and is not set is listed in full on the cookie policy. If that changes, that page changes first, and this one changes with it.

What about the link that resumes an application?

If you leave the form part-finished, you can be sent a link to come back to it. That link carries a signed token that expires 7 days after it is issued, after which it stops working and a new one has to be issued.

Treat that link as you would treat the form itself: anyone holding it can open your part-finished application and read what is in it until it expires. Do not forward it, and do not post it anywhere. If you think someone else has it, tell us and we will cut it off — the answers behind it are erased and the link stops working from that point.

How long is your information kept?

Two principles decide this. The Act says a Data Fiduciary should erase personal data once the purpose it was collected for is no longer being served, unless retention is required by law (Section 8). But an insurance application is exactly the kind of record that record-keeping obligations require us to keep. What was asked, what was answered and what was placed have to survive long enough to answer a question about the policy years later — including a question at claim.

So: enquiry data that never became an application is not kept indefinitely, and we will erase it on request. Data that formed part of an application is kept for as long as the record-keeping obligations on insurance business require. We will refuse a request to erase that for as long as those obligations run, and if we refuse one on that basis we will tell you that is the reason.

Not verified for this page: no number of years is stated above, on purpose. The period is set by the record-keeping rules that bind insurance business and by the insurer's own retention policy, and we have not confirmed it from those sources. The principle above holds. A period will appear here once we have checked it.

How is your information protected?

In general terms:

  • this site is served over an encrypted connection;
  • submitted applications sit in a managed database in India, not in a spreadsheet or an inbox;
  • access is limited to the people who need it to do the work;
  • the consent ledger is append-only, and every record in it is signed as well, so an alteration is both refused and detectable;
  • no third-party script runs on these pages, which removes an entire category of leak.

Two limits are worth stating rather than glossing over. Ordinary email is not encrypted end to end, and your application is emailed to the underwriter — that is how applications are placed, and it is not a perfectly private channel. And no security measure is absolute. If personal data in our care is ever breached, we will tell you and the authority in the manner the Act requires.

What rights do you have as a Data Principal?

The Act gives you five things you can require, and they are rights rather than favours: to know what we hold, to have it corrected or erased, to complain and be answered, to nominate someone to act for you, and to withdraw your consent. Each is set out below with the section it comes from.

The right to know what we hold (Section 11)
You can ask for a summary of the personal data we hold about you, what we are doing with it, and who we have shared it with.
The right to have it corrected, completed or erased (Section 12)
You can ask us to correct anything inaccurate, fill in anything incomplete, update anything out of date, or erase what we no longer need. Erasure is not absolute — see how long information is kept, below.
The right to complain to us and be answered (Section 13)
You can raise a grievance about how your data has been handled, and we have to give you a route to do it and a response. The Act expects you to use that route before you go to the regulator.
The right to nominate someone (Section 14)
You can nominate another person to exercise these rights on your behalf if you die or become unable to exercise them yourself.
The right to withdraw your consent (Section 6)
You can withdraw consent at any time, and it must be as easy to withdraw as it was to give. Withdrawing does not make what was lawfully done beforehand unlawful.

How to exercise them

Email [email protected], or call +91 87968 39997. Say which right you are exercising and give us enough detail to find your record and be satisfied you are the person it belongs to — the email address or mobile number you used on the form is usually enough. There is no form to fill in and no fee.

Not verified for this page: the Rules made under the Act do not set one answering period for everybody. They require a Data Fiduciary to publish the period within which it will deal with a request or a grievance of this kind — and that requirement is among the provisions not yet in force. We have not settled and verified ours, so none is stated here. In the meantime we will acknowledge your request and answer it as quickly as we can.

How do you complain?

Come to us first. Section 13 of the Act gives you a right to grievance redressal from the Data Fiduciary, and expects you to use it before approaching the regulator. Write to Dr. Sonali Walia at [email protected], saying what happened and what you want done about it.

If our answer does not satisfy you, the Act's escalation route is the Data Protection Board of India, which you can approach without a lawyer.

Check this when you complain: the provisions establishing the Data Protection Board came into force in November 2025, but the Board's remaining powers are among those due to commence on 13 May 2027. Before you rely on the Board, check whether it is taking complaints of this kind that day. The Ministry's data protection framework page is where to look.

A complaint about the insurance side of things — an application, a policy, a premium, the conduct of this practice — is a different route with a different regulator. It has four steps: us, then the insurer, then the Insurance Regulatory and Development Authority of India, then the Insurance Ombudsman. The grievance redressal page sets out each one.

Children's information

This site is meant for adults. The application form is not designed for anyone under 18 to use, and we do not knowingly collect a child's personal data through it. If you are under 18, do not submit the form.

Section 9 of the Act requires a Data Fiduciary to obtain verifiable consent from a parent or lawful guardian before processing a child's personal data, and forbids tracking, behavioural monitoring of children and targeted advertising directed at them. We do no tracking or behavioural advertising of anyone, of any age. If we find we hold a child's data that was given to us without the consent the Act requires, we will delete it.

How are changes to this policy notified?

The version on this page is always the current one, and the review date at the foot of the page tells you when it was last checked. When we change it, we change that date.

A change that affects how your personal data is used — a new purpose, a new recipient, a different place it is stored — is described here rather than made quietly. Where a change goes beyond what you consented to, we will ask you again rather than assume your old consent covers it.

This policy applies to prakashfinserv.com and to the application form on it. It does not govern any other website you reach from here, including the insurer's. What this site stores on your own device is a separate question, answered on the cookie policy; the terms the site is provided on are in the Terms of Use.

Questions about this policy

Write to Dr. Sonali Walia at [email protected], or call +91 87968 39997. If something on this page is unclear, or reads as though it is hiding something, say so — a privacy notice nobody can follow is not doing its job.

Last reviewed: 31 August 2026