01
A privacy policy built on Indian law.
This Privacy Policy is drafted in full compliance with the Information Technology Act 2000, the SPDI Rules 2011, the Digital Personal Data Protection Act 2023, and all applicable Indian financial regulatory frameworks including SEBI, RBI, IRDAI, FEMA, PMLA, and KYC Master Directions — and governs every service delivered across all four GlobeeOne verticals.
At GlobeeOne, every piece of information shared with us is treated with the same professional authority, the same depth of care, and the same genuine commitment that every individual receives across every engagement. This Privacy Policy sets out the complete legal framework governing how GlobeeOne collects, processes, stores, transfers, and protects personal data and sensitive personal data or information across all four of its integrated verticals.
02
GlobeeOne — Registered Entity and Contact Information.
In accordance with the Digital Personal Data Protection Act 2023 and the SPDI Rules 2011, the following are the complete identity and contact details of GlobeeOne as the Data Fiduciary for all personal data processed across its platform and services:
| Legal name |
GlobeeOne |
| Nature of entity |
India's first fintech-powered 360° growth ecosystem |
| Registered address |
209, Town Plaza, Near Sardar TV, New India Colony, Nikol Ahmedabad- 82350, Gujarat, India |
| Jurisdiction |
India — governed by Indian law |
| Privacy email |
privacy@globeeone.com |
| Grievance email |
grievances@globeeone.com |
| E-Counselling email |
ecounselling@globeeone.com |
| Website |
www.globeeone.com |
| Data Fiduciary |
GlobeeOne (under DPDPA 2023) |
| Regulatory frameworks |
SEBI · RBI · IRDAI · FEMA · IT Act 2000 · DPDPA 2023 · PMLA 2002 |
| Effective from |
1 June 2026 |
03
This Privacy Policy covers all four GlobeeOne sub-brands and every service they deliver.
GlobeeOne operates as an integrated 360° growth ecosystem across four verticals. This Privacy Policy applies in full to every service delivered by every GlobeeOne vertical — and governs all personal data and sensitive personal data or information collected, processed, and stored across all four:
3.1
Where Potential Finds Its Purpose.
Career counselling and guidance · Academic coaching · Life skills development · Financial literacy programmes · NISM certification support · Industry readiness · Free E-Counselling for every student · Academic pressure and performance support · Cultural adjustment and emotional wellbeing support · Career direction and life planning · Mental health and emotional wellbeing support · Conflict and communication guidance · Emergency support and crisis guidance. And other related services.
3.2
Every Global Dream — Guided to Reality.
Career assessment and counselling · Course and discipline selection · Destination and country guidance · University shortlisting and selection · Academic profile building · Scholarship and financial aid identification · Study abroad feasibility assessment · IELTS, TOEFL, PTE, Duolingo, Cambridge, GRE, GMAT, SAT and ACT preparation and coaching · Test registration and scheduling support · Application strategy and management · Statement of Purpose and Personal Statement writing · Letter of Recommendation guidance · CV and resume building · Portfolio preparation · Offer letter evaluation and negotiation · Student visa application support · Visa documentation preparation · Visa interview preparation and training · Financial documentation for visa · Dependent visa guidance · Visa refusal analysis and reapplication · Legal compliance and regulatory guidance · Immigration advisory · Education loan facilitation (domestic and international) · GIC account opening · Block account opening · Overseas bank account opening support · Forex management and currency exchange · Tuition fee remittance · Living expense remittance planning · Scholarship application support · Moratorium and repayment planning · Section 80E tax benefit guidance · Pre-departure orientation · Accommodation search and booking · Flight and travel booking assistance · Health insurance advisory · Travel insurance guidance · Post-arrival settling-in support · University registration assistance · Local banking and financial setup · Academic integration support · Part-time work permit guidance · Career and internship guidance · Post-study work visa guidance · Permanent residency pathway advisory · Alumni network and community connection. And other related services.
3.3
Financial Solutions, Simplified.
Home purchase loans · Mortgage and property loans · Balance transfer and top-up loans · Loan Against Property · Construction and renovation loans · Pre-approved loan facilitation · Tax benefit optimisation · Interest rate and EMI optimisation · Loan restructuring and repayment planning · Documentation and end-to-end processing · Domestic education loans · International education loans · Secured and unsecured loan options · Co-applicant and guarantor structuring · GIC arrangements · Block accounts · Overseas bank account support · Moratorium and repayment planning · Scholarship and financial planning guidance · Working capital loans · MSME and SME financing · Business expansion funding · Machinery and equipment loans · Startup funding support · Cash flow-based lending · OD and CC facility assistance · Trade and vendor financing · MUDRA loan assistance · Invoice discounting · Project finance and term loans · Debt consolidation and restructuring · Business credit profile assessment · Loan Against Receivables · Personal loans · Medical emergency financing · Critical illness financing · Wedding and lifestyle loans · Travel and relocation funding · Home renovation and interior loans · Consumer durable loans · Professional development loans · EV and green vehicle financing · Gold loan facilitation · Fixed deposit backed loans · Insurance policy backed loans · Shares and mutual fund backed loans · Loan Against Mutual Funds · Loan Against Shares and Bonds · Loan Against Insurance Policies · Portfolio-backed liquidity solutions · Structured interest and repayment planning · Foreign currency exchange · International money transfers · Forex cards and travel currency solutions · Tuition fee remittance assistance · Overseas student banking support · International compliance guidance · End-to-end documentation coordination. And other related services.
3.4
Grow. Protect. Prosper.
Wealth creation and investment management · Mutual fund portfolio management · Direct equity management · Portfolio Management Services (PMS) · Alternative Investment Funds (AIF) · Goal-based investment planning · Life insurance structuring · Health insurance advisory · General insurance protection · Insurance portfolio review · Tax planning and optimisation · Section 80C and 80D planning · Capital gains tax planning · Estate tax structuring · Retirement planning · Inflation-protected retirement corpus building · Pension and annuity planning · Succession and legacy planning · Will drafting advisory · Trust structuring · Nomination management · Estate framework advisory · HNI and ultra-HNI wealth management · Structured products · Concentrated wealth management · Cross-border financial structuring · Multi-generational legacy planning. And other related services.
04
All laws governing this Privacy Policy.
This Privacy Policy is governed by and constructed in full compliance with the following Indian statutes, rules, regulations, and regulatory directions. Every individual engaging with any GlobeeOne service is entitled to every protection afforded by each of the following:
India's primary legislation governing electronic commerce, digital data, and cybersecurity. Section 43A imposes strict liability on companies that fail to implement reasonable security practices to protect sensitive personal data and information. Section 72A provides criminal liability for disclosure of information in breach of a lawful contract. The IT Act forms the foundational legal framework for all digital data handling in India.
GlobeeOne applicability: GlobeeOne implements reasonable security practices and procedures as defined under Section 43A of the IT Act 2000 across all personal data collected through its digital platform, mobile interface, and service engagements. All data handling by GlobeeOne is in full compliance with the IT Act 2000.
Defines Sensitive Personal Data or Information (SPDI) — including financial information, health data, biometric data, passwords, PAN, and other categories — and mandates specific security practices for its collection, storage, transfer, and processing. Requires publication of a Privacy Policy, designation of a Grievance Officer, and obtaining prior written consent before collecting SPDI. Rule 5 sets out the mandatory requirements for collecting SPDI. Rule 6 governs disclosure. Rule 7 governs transfer.
GlobeeOne applicability: GlobeeOne identifies and treats all Sensitive Personal Data or Information under Rule 3 of the SPDI Rules 2011 with the highest level of protection. Financial profile data, loan information, investment details, health-related data, insurance information, and identity documents submitted across all four GlobeeOne verticals are all classified and protected as SPDI.
India's landmark personal data protection legislation. Establishes the rights of Data Principals (individuals) and obligations of Data Fiduciaries (organisations processing personal data). Introduces consent-based processing, the right to erasure, the right to grievance redressal, and the Data Protection Board of India. Section 4 mandates lawful processing. Section 6 governs consent. Section 7 lists legitimate uses. Sections 8 and 9 set out obligations of Data Fiduciaries. Sections 11–14 establish the rights of Data Principals. Section 17 establishes the Data Protection Board of India.
GlobeeOne applicability: GlobeeOne is a Data Fiduciary under the DPDPA 2023. Every individual is a Data Principal. GlobeeOne processes personal data only with the informed, specific, and unambiguous consent of every Data Principal — for specific, lawful purposes — in accordance with every obligation imposed on Data Fiduciaries under the Act. GlobeeOne is committed to full compliance with every provision of the DPDPA 2023.
Mandates Know Your Customer (KYC) verification, customer due diligence (CDD), enhanced due diligence (EDD) for high-risk customers, and maintenance of all financial transaction records for a minimum of five years. Requires reporting of suspicious transactions to the Financial Intelligence Unit of India (FIU-IND). Applicable to all entities providing financial services — including lending, investment management, insurance, and forex services.
GlobeeOne applicability: GlobeeOne Finserv and GlobeeOne Wealth collect, verify, and maintain KYC documentation in full compliance with PMLA 2002. All financial transaction records across every Finserv and Wealth service are maintained as required. Suspicious transactions are reported to FIU-IND as mandated. Customer Due Diligence and Enhanced Due Diligence are conducted as required by the risk profile of every engagement.
The RBI's comprehensive Know Your Customer framework governing all RBI-regulated entities, lending institutions, NBFCs, and their agents and partners. Mandates customer identification, address verification, PAN verification, Aadhaar-based verification (where applicable), Politically Exposed Person (PEP) screening, and ongoing due diligence for all financial services engagements. The KYC Master Direction is updated periodically and all updates are incorporated into GlobeeOne's compliance framework.
GlobeeOne applicability: GlobeeOne Finserv collects and processes KYC documentation across all its 30+ lending partners in full compliance with RBI Master Directions on KYC. All identity documents, address proof, PAN, and financial information collected for home loans, education loans, business loans, personal loans, LAS, and forex services are handled strictly within the RBI KYC framework and the requirements of each lending partner.
SEBI regulates investment advisors, portfolio managers, mutual fund distributors, Alternative Investment Fund managers, and all entities operating in India's securities market. The SEBI (Investment Advisers) Regulations 2013 mandate client suitability assessment, KYC compliance, and maintenance of client records for a minimum of five years. The SEBI (Portfolio Managers) Regulations 2020 govern PMS operations. The SEBI Cybersecurity and Cyber Resilience Framework mandates data protection standards for all SEBI-regulated entities.
GlobeeOne applicability: GlobeeOne Wealth is registered with SEBI as an Investment Adviser. All client data collected for wealth creation, investment management, PMS, AIF, goal-based planning, retirement planning, and HNI wealth management is processed in full compliance with SEBI regulations — including KYC requirements, client suitability records, investment advisory records, and the SEBI Cybersecurity Framework. Client records are maintained for a minimum of five years as mandated.
IRDAI regulates the insurance sector in India. The IRDAI (Protection of Policyholders' Interests) Regulations mandate disclosure, consent, and data protection for all insurance-related engagements. Policyholder data — including health information, nominee details, and policy terms — is classified as sensitive and must be protected against unauthorised access and disclosure. Insurance agents and advisors are subject to IRDAI licensing and compliance requirements.
GlobeeOne applicability: GlobeeOne Wealth collects and processes insurance-related personal data — including life insurance, health insurance, and general insurance information — in full compliance with IRDAI regulations. All health data, medical information, policyholder details, nominee information, and insurance policy data are treated as Sensitive Personal Data or Information under the SPDI Rules 2011 and IRDAI regulations. GlobeeOne operates in compliance with all IRDAI licensing requirements applicable to insurance advisory and distribution services.
FEMA governs all foreign exchange transactions in India — including international remittances, overseas bank account establishment, GIC arrangements, block account opening, forex card loading, and tuition fee remittance. The RBI's Liberalised Remittance Scheme (LRS) governs the remittance of funds abroad for education expenses, living costs, and overseas investments. All overseas financial transactions must comply with FEMA reporting requirements, and authorised dealer banks must file reports with the RBI.
GlobeeOne applicability: GlobeeOne Finserv and GlobeeOne Study Abroad collect and process personal and financial information for forex management, overseas remittance, GIC facilitation, block account establishment, forex card issuance, and overseas banking setup in full compliance with FEMA 1999 and applicable RBI Directions under the LRS. All LRS transactions are reported to authorised dealer banks as required. Financial data shared for overseas transactions is transmitted in compliance with RBI cross-border data requirements.
Establishes KYC Registration Agencies (KRAs) for centralised KYC verification for all securities market participants. KYC records registered with a KRA are valid across all SEBI-regulated entities. Reduces duplication of KYC verification for investment and securities market clients.
GlobeeOne applicability: GlobeeOne Wealth registers KYC records through SEBI-authorised KYC Registration Agencies for all investment management, PMS, AIF, and wealth management clients — ensuring seamless KYC verification across all SEBI-regulated entities and eliminating duplication of documentation requirements.
The Central KYC Registry operated by the Central Registry of Securitisation Asset Reconstruction and Security Interest of India (CERSAI) provides a centralised KYC repository for all financial sector regulators — RBI, SEBI, IRDAI, and PFRDA. CKYC records are valid across all financial institutions and regulators.
GlobeeOne applicability: Where applicable, GlobeeOne registers KYC records with the Central KYC Registry through CERSAI — ensuring that every individual's KYC verification is recognised across all financial institutions and regulators, simplifying the engagement process across GlobeeOne Finserv and GlobeeOne Wealth services.
PFRDA regulates pension and retirement products in India — including the National Pension System (NPS). Where retirement planning services under GlobeeOne Wealth involve NPS or pension fund products, PFRDA regulations apply to the collection and processing of retirement-related personal data.
GlobeeOne applicability: GlobeeOne Wealth processes retirement-related personal data in compliance with PFRDA regulations where retirement planning services involve NPS or pension fund products. All retirement planning data is treated as SPDI and handled with the highest standard of data protection.
Establishes the rights of consumers in India and the obligations of service providers and digital platforms. The Consumer Protection (E-Commerce) Rules 2020 impose specific obligations on digital platforms including transparent disclosure of data use, grievance officer appointment, and prohibition on unfair trade practices. The Consumer Protection Act provides every individual the right to seek compensation for deficiency in service and unfair trade practices.
GlobeeOne applicability: GlobeeOne complies with the Consumer Protection Act 2019 and the E-Commerce Rules 2020 across all four verticals. Every individual engaging with GlobeeOne is entitled to the full consumer protections afforded by the Act — including the right to transparent information, the right to grievance redressal, and the right to seek compensation for any deficiency in service.
Governs digital platforms and intermediaries operating in India. Mandates publication of a Privacy Policy and Terms of Service, appointment of a Grievance Officer, resolution of user complaints within 15 days (for significant social media intermediaries) or 30 days (for other intermediaries), and periodic compliance reporting. Rule 3(1)(a) requires a Privacy Policy to be published. Rule 3(2)(a) requires a Grievance Officer to be designated.
GlobeeOne applicability: GlobeeOne publishes this Privacy Policy and its Terms of Service in compliance with the IT Intermediary Guidelines 2021. A designated Grievance Officer is available at grievances@globeeone.com to address all privacy and service-related complaints within 30 days of receipt.
Governs all contractual relationships in India. Every GlobeeOne engagement — including the acceptance of this Privacy Policy and the Terms of Service — constitutes a binding contract between GlobeeOne and the individual. Consent to this Privacy Policy constitutes valid contractual consent under Section 10 of the Indian Contract Act.
GlobeeOne applicability: Every individual's acceptance of this Privacy Policy constitutes a binding agreement under the Indian Contract Act 1872. GlobeeOne's obligations under this Privacy Policy are fully enforceable as contractual obligations — and every individual's rights under this Policy are legally protected contractual rights.
05
Categories of SPDI collected across all GlobeeOne verticals.
Rule 3 of the SPDI Rules 2011 defines Sensitive Personal Data or Information. GlobeeOne collects the following categories of SPDI in the course of delivering services across its four verticals — each collected only with prior written consent and for a specific, stated purpose:
| Category |
Details |
Financial information (Finserv and Wealth) |
Bank account details, loan account information, income details, salary slips, ITR, credit history, investment portfolio, net worth statements, business financials, and all financial data shared across GlobeeOne Finserv and Wealth services. |
Health information (Wealth and Academy) |
Medical or health-related information shared for insurance advisory through GlobeeOne Wealth — including pre-existing conditions, medical history, and health declarations. Health and emotional wellbeing information shared in E-Counselling sessions through GlobeeOne Academy. |
Official identifiers (All verticals) |
PAN, Aadhaar (where provided), passport number, voter ID, driving licence, and other government-issued identity documents — collected for KYC compliance across GlobeeOne Finserv and Wealth, and for visa processing through GlobeeOne Study Abroad. |
All Sensitive Personal Data or Information collected by GlobeeOne is subject to the following mandatory protections:
- Collected only with the prior, informed, and written consent of the individual concerned — as required under Rule 5(1) of the SPDI Rules 2011
- Used only for the specific purpose for which consent was obtained — and for no other purpose without fresh consent
- Never transferred to any third party without the explicit consent of the individual — except where required by applicable law or regulation
- Stored with AES-256 encryption and role-based access controls meeting the standards prescribed under the SPDI Rules 2011
- Retained only for the periods specified in the Data Retention section of this Privacy Policy
- Available for review, correction, and withdrawal of consent at any time upon written request to privacy@globeeone.com
06
What GlobeeOne collects — across every vertical.
GlobeeOne collects only the information that is genuinely necessary to deliver the right guidance, the right financial solution, or the right educational support to every individual. Every category of information collected serves a specific, legitimate purpose aligned to the services of one or more GlobeeOne verticals.
- Full name, email address, phone number, and city of residence
- Communication preferences and enquiry details submitted through forms, consultations, and calls
- Service interests and engagement history with GlobeeOne across any vertical
GlobeeOne Academy
- Career goals, academic background, current education level, and life stage
- E-Counselling session information shared in strict confidence with GlobeeOne counsellors
- Academic performance data, test scores, and study habits for academic coaching
- Financial literacy assessment data for personalised financial education
GlobeeOne Study Abroad
- Academic qualifications, grades, and test score history (IELTS, TOEFL, PTE, GRE, GMAT, SAT)
- Preferred study destinations, courses, and university shortlists
- Statement of Purpose, Personal Statement, CV, and Letter of Recommendation drafts
- Passport details, visa history, immigration status, and travel records for visa processing
- Financial information for education loan applications and visa financial documentation
- GIC, block account, and overseas banking requirements for destination-specific financial arrangements
- Accommodation preferences, flight details, and pre-departure logistics information
GlobeeOne Finserv
- Complete financial profile — income, employment status, business turnover, credit score, and existing liabilities
- Identity and address documents for KYC compliance — PAN, Aadhaar, passport, utility bills, and bank statements
- Property documents, valuation reports, and legal title documents for home and mortgage loan processing
- Business documents — GST registration, MSME registration, MOA, AOA, and audited financials for business loan processing
- Investment portfolio details and securities statements for Loan Against Securities processing
- Forex requirements, remittance details, and overseas banking preferences
- Loan amount requirements, tenure preferences, and repayment capacity information
GlobeeOne Wealth
- Complete financial profile — income, assets, liabilities, existing investments, and net worth
- Investment goals, risk appetite, investment horizon, and retirement objectives
- KYC documentation — PAN, Aadhaar, passport, bank account details, and photograph
- Insurance requirements — health status, pre-existing conditions, nominee details, and coverage needs
- Tax information — ITR, capital gains statements, and tax bracket for tax planning
- Retirement and succession planning objectives — including estate details and nominee preferences
- For HNI and ultra-HNI clients — cross-border financial information and multi-jurisdictional asset details
- Device type, browser, operating system, and IP address
- Pages visited, time spent, search queries, and interactions with GlobeeOne content
- Cookies and similar tracking technologies — for platform functionality and user experience improvement
- Geographic location data — only where explicitly permitted by the individual
07
How GlobeeOne obtains and manages consent under Indian law.
In compliance with the DPDPA 2023 and the SPDI Rules 2011, GlobeeOne obtains the free, specific, informed, and unambiguous consent of every Data Principal before collecting or processing their personal data or SPDI across any GlobeeOne vertical.
- Consent is obtained through a clear and plain language notice — presented before or at the time of data collection
- The notice specifies: the personal data to be collected, the purpose of processing, the names of all Data Processors, and the rights of the Data Principal
- Consent is freely given — it is never bundled as an unconditional requirement for service access where the data is not genuinely necessary
- Every individual has the right to withdraw consent at any time by writing to privacy@globeeone.com
- Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal
- Separate consent is obtained for each distinct purpose — general consent does not extend to additional uses
7.1
All information shared in E-Counselling sessions is treated as confidential. Separate, explicit consent is obtained before any E-Counselling session commences — covering the purpose of the session, the confidentiality framework, and the individual's rights. E-Counselling content is never shared, disclosed, or used for any purpose beyond the session without fresh, explicit consent.
7.2
For all financial services engagements, separate KYC consent is obtained covering the specific collection, verification, and processing of identity, address, and financial documents. KYC consent is distinct from general platform consent and complies with RBI Master Directions, SEBI regulations, and IRDAI requirements.
08
Rights of Data Principals under Indian law.
Under the DPDPA 2023 and the SPDI Rules 2011, every individual engaging with any GlobeeOne service has the following rights in relation to their personal data:
| Right |
Description |
Right to information DPDPA 2023, S.11 |
Every individual has the right to know what personal data GlobeeOne holds, the purpose of processing, and the identity of all third parties to whom data has been disclosed. |
Right to correction and erasure DPDPA 2023, S.12 |
Every individual has the right to correct inaccurate or incomplete personal data and to request erasure where data is no longer necessary for the purpose for which it was collected — subject to legal and regulatory retention requirements. |
Right to grievance redressal DPDPA 2023, S.13 |
Every individual has the right to have any grievance regarding the processing of their personal data addressed by GlobeeOne within 30 days. Unresolved grievances may be escalated to the Data Protection Board of India. |
Right to nominate DPDPA 2023, S.14 |
Every individual has the right to nominate another individual to exercise their data rights in the event of death or incapacity. |
Right to withdraw consent DPDPA 2023, S.6 |
Every individual has the right to withdraw consent for the processing of their personal data at any time — without prejudice to the lawfulness of processing prior to withdrawal. |
Right to access SPDI Rules, Rule 5 |
Every individual has the right to review the personal data and SPDI collected by GlobeeOne and to request correction of any inaccuracy. |
Right to Data Protection Board DPDPA 2023, S.17 |
Every individual has the right to make a complaint to the Data Protection Board of India where a grievance is not resolved to their satisfaction by GlobeeOne. |
Right to portability DPDPA 2023 |
Every individual has the right to receive their personal data in a structured, commonly used, machine-readable format. |
To exercise any right, every individual may write to GlobeeOne at privacy@globeeone.com. GlobeeOne will respond within 30 days as mandated under the DPDPA 2023.
09
How GlobeeOne protects every piece of personal data.
GlobeeOne applies industry-standard and regulatory-mandated security measures to protect every piece of personal data and SPDI against unauthorised access, disclosure, alteration, loss, and destruction — across all four verticals and every service delivered.
9.1
All data transmitted between individuals and GlobeeOne is encrypted using TLS 1.2 or higher. All Sensitive Personal Data or Information stored by GlobeeOne is encrypted at rest using AES-256 encryption. Financial data and KYC documents are stored in encrypted, access-controlled repositories meeting RBI and SEBI security standards.
9.2
Access to personal data and SPDI is strictly limited to authorised GlobeeOne professionals who require it to deliver the specific service requested. Role-based access controls ensure data segregation across all four verticals. All access is logged, monitored, and subject to periodic audit. No cross-vertical data sharing without explicit consent.
9.3
GlobeeOne collects only the minimum information genuinely necessary for each specific service. No information is collected beyond what is required for its stated purpose. SPDI is collected only where mandated by the nature of the service — financial data for Finserv and Wealth services, visa and academic data for Study Abroad, and counselling data for Academy services.
9.4
All information shared during GlobeeOne E-Counselling sessions is treated with the highest level of professional confidentiality — equivalent to clinical confidentiality standards. E-Counselling content is never shared, disclosed, or used for any purpose beyond the session itself without the explicit, fresh consent of the individual. E-Counselling records are deleted immediately following each session unless the individual explicitly requests retention.
9.5
In the event of a personal data breach, GlobeeOne will notify the Data Protection Board of India and all affected Data Principals in accordance with the timelines and procedures mandated under the DPDPA 2023. Every individual will be informed of the nature of the breach, the data affected, and the steps GlobeeOne is taking to address it.
10
When and how GlobeeOne shares personal data.
GlobeeOne does not sell, rent, or trade personal data or SPDI to any third party under any circumstances. Personal data is shared only in the specific circumstances described below — and always with the protection of every individual as the primary consideration.
Financial and KYC information is shared with the specific lending institution, NBFC, or financial partner selected for each loan or financial service engagement — solely for the purpose of processing the application. All financial partners are RBI-regulated or SEBI-registered entities operating under applicable Indian regulatory frameworks. Data is shared only to the extent required for the specific transaction.
KYC and investment profile information is shared with SEBI-registered Portfolio Management Service providers, AIF managers, mutual fund companies, insurance companies, and other regulated entities — solely for the purpose of delivering the specific wealth management service requested. All partners are regulated by SEBI or IRDAI as applicable.
Academic records, personal information, and financial documentation are shared with universities, visa authorities, overseas banking institutions, GIC providers, and block account institutions — solely for the purpose of processing applications and delivering the specific international education service requested.
GlobeeOne shares personal data and transaction records with SEBI, RBI, IRDAI, FIU-IND, and other applicable regulatory bodies — where required by law or regulation. All such disclosures are made in strict compliance with applicable legal requirements and are limited to the specific data required.
KYC records are registered with SEBI-authorised KYC Registration Agencies and the Central KYC Registry (CERSAI) as required by SEBI and RBI regulations — to enable centralised KYC verification across financial institutions and reduce documentation duplication for every individual.
GlobeeOne engages trusted technology providers, cloud service providers, and platform service providers who support GlobeeOne operations. All such providers are contractually bound through Data Processing Agreements to maintain the same data protection standards that GlobeeOne applies — and are prohibited from processing personal data for any purpose other than providing the contracted service.
Personal data is shared beyond the above circumstances only with the explicit, informed, and specific consent of the individual concerned. Such consent is obtained separately — and is never bundled into general platform consent.
11
Where GlobeeOne stores and transfers personal data.
In compliance with RBI data localisation requirements and the DPDPA 2023, GlobeeOne stores all personal data of Indian residents on servers located within India. Cross-border data transfers are made only in the following limited circumstances:
- To countries or territories notified by the Central Government as having adequate data protection standards under the DPDPA 2023
- With the explicit consent of the Data Principal — obtained separately for cross-border transfer
- Where required for the specific service requested — such as overseas university applications, GIC facilitation, block account opening, or overseas banking setup under GlobeeOne Study Abroad and Finserv
- In compliance with FEMA 1999, RBI LRS Directions, and applicable cross-border data transfer requirements
All financial data processed by GlobeeOne Finserv and GlobeeOne Wealth is stored exclusively on servers located within India in compliance with RBI data localisation requirements. All KYC records are maintained in India in compliance with RBI and SEBI requirements.
12
Know Your Customer and Anti-Money Laundering obligations.
GlobeeOne Finserv and GlobeeOne Wealth are subject to comprehensive KYC and Anti-Money Laundering obligations under Indian law. Every individual engaging with GlobeeOne's financial services is subject to KYC verification:
| Framework |
Requirements |
| RBI Master Directions on KYC 2016 |
Customer Identification, Address Verification, PAN Verification, PEP Screening, Beneficial Ownership Identification, Ongoing Due Diligence, and Enhanced Due Diligence for high-risk customers. |
| SEBI KYC Registration Agency (KRA) |
Centralised KYC for all investment and securities market participants through SEBI-authorised KRAs — valid across all SEBI-regulated entities. |
| Central KYC Registry (CERSAI) |
CKYC registration for cross-regulatory KYC recognition across RBI, SEBI, IRDAI, and PFRDA-regulated entities. |
| PMLA 2002 — CDD and EDD |
Customer Due Diligence for all financial service clients. Enhanced Due Diligence for high-risk, PEP, and high-value clients. Suspicious transaction reporting to FIU-IND. |
| IRDAI KYC Norms |
KYC verification for insurance policy issuance, claim processing, and insurance advisory services through GlobeeOne Wealth. |
| Video KYC (V-CIP) |
Where applicable and as permitted by RBI, video-based Customer Identification Process is offered as an alternative to in-person KYC for digital onboarding. |
KYC documents collected
- Proof of Identity: PAN card (mandatory), Aadhaar card, Passport, Voter ID, or Driving Licence
- Proof of Address: Aadhaar card, Passport, Utility bills (not older than 3 months), Bank statements, or Rent agreement
- Photograph: Recent passport-size photograph
- Financial documents: Bank statements (6–12 months), ITR (2–3 years), salary slips, Form 16, or audited financial statements
- Business documents: GST registration certificate, MSME / Udyam registration, MOA, AOA, Board resolution, and audited business financials
- Additional documents for HNI clients: Source of wealth declaration, net worth certificate, and cross-border asset declarations as required
13
Retention periods under Indian regulatory requirements.
GlobeeOne retains personal data only for the period genuinely necessary for the purpose for which it was collected — or as mandated by applicable Indian law and regulation.
14
Protection of personal data of minors under Section 9 of the DPDPA 2023.
The Digital Personal Data Protection Act 2023 imposes specific obligations on Data Fiduciaries in relation to the processing of personal data of children (individuals below the age of 18 years). GlobeeOne complies fully with Section 9 of the DPDPA 2023 and all applicable obligations:
- GlobeeOne does not process the personal data of any child without the verifiable consent of the parent or lawful guardian of that child
- GlobeeOne does not undertake tracking or behavioural monitoring of any child through its platform or services
- GlobeeOne does not serve targeted advertising to any child
- GlobeeOne does not process personal data in a manner that is detrimental to the wellbeing of any child
- Where personal data of a child is identified to have been collected without verifiable parental consent, it is deleted immediately
- GlobeeOne Study Abroad services provided to students below the age of 18 require the involvement and consent of a parent or lawful guardian at all stages
- GlobeeOne Finserv and GlobeeOne Wealth do not provide financial services directly to individuals below the age of 18 without the involvement and consent of a parent or lawful guardian
- GlobeeOne Academy's free E-Counselling service is available to all students including minors — with parental consent required for students below the age of 18 for formal counselling engagements
15
Grievance Officer and escalation to the Data Protection Board of India.
In compliance with Rule 5(9) of the SPDI Rules 2011, Rule 3(2)(a) of the IT Intermediary Guidelines 2021, and Section 13 of the DPDPA 2023, GlobeeOne has designated a Grievance Officer to address all privacy, data protection, and service-related concerns across every GlobeeOne vertical.
| GlobeeOne Grievance Officer |
| Designation |
Grievance Officer — GlobeeOne |
| Appointed under |
IT Act 2000, SPDI Rules 2011, IT Intermediary Guidelines 2021, and DPDPA 2023 |
| Grievance email |
grievances@globeeone.com |
| Privacy email |
privacy@globeeone.com |
| Registered address |
209, Town Plaza, Near Sardar TV, New India Colony, Nikol Ahmedabad- 82350, Gujarat, India |
| Response time |
Within 30 days of receipt of every grievance — as mandated under DPDPA 2023 |
| Languages |
English and Hindi |
- Write to grievances@globeeone.com with the subject line: Privacy Grievance — [nature of concern]
- Include full name, contact details, the specific GlobeeOne service concerned, the nature of the grievance, and any supporting documentation
- GlobeeOne will acknowledge every grievance within 5 working days and resolve it within 30 days
- Where a grievance cannot be resolved within 30 days, GlobeeOne will inform the individual of the reason for the delay and the expected resolution timeline
Where a grievance is not resolved to the satisfaction of the Data Principal within 30 days, every individual has the right to escalate their complaint to the Data Protection Board of India established under Section 17 of the DPDPA 2023. The Data Protection Board has the authority to investigate complaints, impose penalties on Data Fiduciaries, and award compensation to affected Data Principals.
16
Reach GlobeeOne on any privacy matter.
For any question, concern, request, or grievance relating to this Privacy Policy or the handling of personal data across any GlobeeOne service, every individual may contact GlobeeOne through the following channels:
17
How GlobeeOne communicates updates to this Policy.
GlobeeOne reserves the right to update this Privacy Policy at any time to reflect changes in applicable Indian law, regulatory requirements, GlobeeOne services, or data processing practices. Where material changes are made to this Privacy Policy:
- Every individual will be notified by email to the address registered with GlobeeOne
- A prominent notice will be displayed on the GlobeeOne platform and website
- The updated version will be published at www.globeeone.com with the date of the most recent update
- For material changes affecting SPDI processing, fresh consent will be obtained before the updated processing commences
Continued use of any GlobeeOne service following notification of a change to this Privacy Policy constitutes acceptance of the updated terms. Every individual who does not wish to accept the updated terms may withdraw from the relevant GlobeeOne service and request deletion of their data in accordance with the rights set out in this Policy.
18
- Identity & contact details: name, email, phone number, address, date of birth, government ID where required for KYC.
- Education & financial data: academic records, university choices, income, employment, co-applicant details, credit information for loan processing.
- Account & usage data: login credentials, preferences, device information, IP address, browser type, pages visited, and interaction logs.
- Communications: messages, call recordings (where permitted), support tickets, and feedback you provide.
- Payment information: processed through secure third-party payment partners; we do not store full card numbers on our servers.
16
- Provide, operate, and improve our education loan, counseling, wealth, and academy services.
- Process applications, verify eligibility, coordinate with lending partners, and communicate status updates.
- Personalise your experience and deliver relevant content, offers, and recommendations.
- Comply with legal obligations, prevent fraud, and enforce our terms and policies.
- Send service-related notices; marketing communications only with your consent where required by law.
17
We do not sell your personal information. We may share data only in these circumstances:
- With banks, NBFCs, universities, and partners necessary to deliver services you request.
- With service providers (hosting, analytics, customer support) bound by confidentiality agreements.
- When required by law, regulation, court order, or to protect rights, safety, and security.
- In connection with a merger, acquisition, or sale of assets, with notice where applicable.
18
We retain personal information only as long as necessary to fulfil the purposes outlined in this policy, comply with legal and regulatory requirements (including loan documentation retention periods), and resolve disputes. When data is no longer needed, we securely delete or anonymise it.
19
We implement administrative, technical, and physical safeguards including encryption in transit, access controls, and regular security reviews. No method of transmission over the internet is 100% secure; we encourage you to use strong passwords and protect your account credentials.
20
Depending on your location, you may have the right to:
- Access, correct, or delete your personal data.
- Object to or restrict certain processing activities.
- Withdraw consent where processing is consent-based.
- Request a portable copy of your data.
- Lodge a complaint with a supervisory authority.
To exercise these rights, contact us using the details below. We will respond within applicable legal timeframes.
21
We use cookies and similar technologies to remember preferences, analyse traffic, and improve site performance. You can control cookies through your browser settings. Disabling cookies may limit some features of our website.
22
As a global education and finance platform, your information may be processed in countries other than your own. We ensure appropriate safeguards are in place when transferring data across borders, consistent with applicable data protection laws.
23
Our services are not directed to children under 16. We do not knowingly collect personal information from children. If you believe we have collected such data, please contact us and we will promptly delete it.
24
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Continued use of our services after changes constitutes acceptance of the revised policy.
25
For privacy-related questions or requests, contact our Data Protection team: