Legal
Privacy notice
This notice covers the public website at www.thezenithwealth.com. It is written to the Digital Personal Data Protection Act 2023, and it describes what actually happens today rather than what the platform may do later.
Who is responsible for your data
Zenith Wealth is the trading name of the practice carried on by Rajesh Kumar Pancholi, AMFI-registered Mutual Fund Distributor, ARN-331900, with offices in Udaipur, Rajasthan and Bengaluru, Karnataka. Every registration under which this practice operates is held personally by him.
For anything in this notice, including a request to access, correct or erase your data, write to grievance@thezenithwealth.com. That mailbox is read by Rajesh Kumar Pancholi, who is the person accountable for data protection in this practice. There is no separate Data Protection Officer, because at this size appointing one would be a title rather than a control.
What this website collects, and what it does not
This site sets no cookies. Not for analytics, not for advertising, not for anything. It stores nothing in your browser, there is no advertising pixel, and there is no account to create. You can confirm that yourself: open your browser's developer tools on any page here and both the cookie store and local storage are empty.
Two things are measured on every page, and neither of them identifies you: how the site is used, and when it breaks. Both are set out in full in the next two sections.
Everything else reaches us only when you choose to send it, through one of the routes below.
| What | Why | How long |
|---|---|---|
| Name, city and phone number submitted through an enquiry form, along with the answers you selected | So the desk can call you back about the product you asked about, with enough context that the first call is useful | 24 months from your last contact, then deleted, unless you become a client |
| Whatever you write to us by email or on WhatsApp | To answer you | As long as the conversation is live, then per the retention rule below |
| Standard server logs at our host: IP address, browser, page requested, timestamp | Security and diagnosing faults. Not used to build any profile of you | Retained by Vercel per its own policy, typically around 30 days |
| Which page was viewed, when, the link or campaign that brought you here, and an approximate location: country, state and city | To see which pages people actually read and where the site is being found, so the next thing we write is the thing worth writing | Held by PostHog under its own retention policy. Carries no identifier for you |
| An error report when something on the site fails: what broke, the page it broke on, and your browser and operating system version | So a fault that would otherwise fail silently gets found and fixed | Held by Sentry under its own retention policy, typically 90 days |
| Page loading speed on your device | To find the pages that are slow on a real phone on a real network rather than on a developer's laptop | Held by Vercel as aggregate performance figures, with no identifier |
How the site is measured
Analytics on this site is PostHog, running on its European servers in what PostHog calls cookieless mode. That is a deliberate choice and it costs us something, so it is worth being precise about what it means.
Nothing is written to your browser. No cookie, no local storage, no session storage, no device fingerprint. In place of an identifier, PostHog derives a value on its own servers from a salt that is rotated every day, which means a visitor cannot be recognised from one day to the next, and cannot be recognised by us at any point. We can see that a page was read. We cannot see that you read it, and we cannot join today's visit to last week's.
Automatic capture is switched off. Analytics tools normally record the text of whatever you click by default, which on this site would sweep up the answers you select on the risk questionnaire and the labels sitting beside money figures. We record page views and nothing else, each one written by hand in the code rather than collected automatically.
Session replay is off. There is no recording of your screen, your typing or your mouse anywhere.
Approximate location is attached to each page view: country, state and city, worked out from the network your request arrives on. Your IP address is not stored. A postal code is deliberately never read, even though it is available to us, because a postal code alongside two or three other details starts to narrow toward one household, and city does not.
When something breaks
Errors are reported to Sentry, also on its European servers, so that a fault which would otherwise fail silently gets fixed. This matters most where you would never see the failure yourself: an enquiry form that appears to submit but does not reach the desk.
A report carries what went wrong, the page it happened on, your browser and operating system version, and the technical trace of the failure. Your IP address is not attached, because the setting that would attach it is switched off.
Before any report leaves your browser it is stripped of anything named like a regulated field. Any value labelled PAN, Aadhaar, phone, mobile, email, bank account, date of birth or income is replaced with a redaction marker, wherever it sits in the report. That stripping walks the whole report rather than a fixed list of known places, because the same value can arrive as a form field, a stored step or a request body depending on where the failure happened, and a fixed list is how one gets missed.
Session replay is off here too, for the same reason it is off in the analytics: it would need browser storage, and this site does not use any.
The lawful basis for each of those
- Enquiry details: your consent, given by submitting the form. You can withdraw it at any time and we will delete what you sent.
- Correspondence: your consent, and where you become a client, the performance of that relationship.
- Server logs: our legitimate interest in keeping the site available and secure.
- Records kept about clients: legal obligation, under the record-keeping rules that apply to a registered distributor.
- Error reports: our legitimate interest in a website that works, with regulated fields stripped out before the report is sent.
Why there is no consent banner
Analytics is missing from the list above, and the reason is worth stating rather than burying. We do not treat page view events as personal data, because nothing in them identifies you: no cookie, no device identifier, no stored IP address, and no way to link one event to a person or to another event on another day. On that reading the Digital Personal Data Protection Act does not attach to them, which is why this site shows you no banner and asks you to dismiss nothing.
That is a considered reading of Section 2(t) rather than a settled one, and we would rather you heard that from us than found it out later. It is on the list for our compliance counsel, and if the answer comes back differently then this notice changes and so does the site.
The honest summary is that we would rather build a site that does not need your consent than one that asks for it and measures you anyway.
Where it is stored
The website is hosted on Vercel, which serves it from a global edge network. Page content is public and carries nothing about you.
Enquiry details reach the desk in India and are held there. When the client platform launches, client data will be stored in Firebase in the asia-south1 region, which is Mumbai. That is a speed choice rather than a legal one: the DPDP Act does not require personal data to be kept in India, and we would rather say so than imply an obligation we are not under.
The analytics and the error reporting are operated in the European Union, both chosen over their United States equivalents. Section 16 of the DPDP Act permits a transfer to any country the government has not placed on a restricted list, and no country has been placed on one. Separately from that permission, nothing which identifies you reaches either service in the first place.
We do not otherwise transfer your personal data outside India for our own purposes. The remaining tools below are operated abroad and are named for that reason.
Who else can see it
The complete list of third parties involved in running this site today. It is short on purpose, and it gets longer as the platform does. This notice is updated when that happens.
| Service | What it handles | Where |
|---|---|---|
| Vercel | Website hosting and server logs | United States, global edge |
| PostHog | Which pages are read, in cookieless mode. Sets nothing in your browser and holds no identifier for you | European Union |
| Sentry | Error reports when something fails, with regulated fields stripped before the report is sent | European Union |
| Vercel Speed Insights | How quickly pages load on real devices. Performance timings only, with no identifier | United States, global edge |
| Telegram | Delivers the contents of an enquiry form to the desk as a message, so nothing sits in an unread queue | International |
| WhatsApp (Meta) | Only if you choose to open a chat with us. Your message is subject to WhatsApp's own terms | International |
| Calendly | Only if you choose to book a call. You provide your details to Calendly directly, on their page | United States |
Not yet in use
The build plan for this practice also includes a client portal with a document store, email delivery and a WhatsApp business channel. None of them is running on this website today, and this notice will be updated before any of them is.
We would rather tell you what is true this month than publish a list that covers us for everything we might do later. Analytics and error reporting sat in this section until 2026-08-25, when they went live and moved up into the sections above.
Your rights
Every right below starts at the same address: grievance@thezenithwealth.com. You will get a written acknowledgement within 3 working days.
- Access: ask what we hold about you, and we will tell you.
- Correction: ask us to fix anything inaccurate or incomplete.
- Erasure: ask us to delete what we hold, except where a record-keeping obligation requires us to keep it. Where that applies we will tell you which record and for how long.
- Withdraw consent: at any time, with no reason required, and without affecting anything done before you withdrew it.
- Nominate: name someone who may exercise these rights for you if you are unable to.
- Complain: to us first, and to the Data Protection Board of India if we do not resolve it.
What we cannot show you, or delete
Two of the rights above have a limit where analytics and error reports are concerned, and it is a real one worth stating plainly. Because neither carries an identifier for you, we cannot search either of them for your data, which means we can neither show it to you nor delete it on request.
The reason it cannot be found is the same reason it does not need to be: it was never linked to you in the first place. A site that could delete your analytics on request would be a site that knew which events were yours.
If you would rather the site did not measure your visit at all, any content blocker will stop both the analytics and the error reporting, and every page here works normally without them. Nothing here is withheld from a visitor who blocks them, and nothing asks you to turn them back on.
How long we keep things
Enquiries that do not become a relationship: 24 months from your last contact with us.
Client records: for as long as the relationship is active, and then for 8 years afterwards, which is what the record-keeping norms applying to a registered distributor require.
Anything you have asked us to erase: removed as soon as we can, except where the 8-year rule above applies to that specific record.
Analytics events and error reports: held by PostHog and Sentry under their own retention policies, which for Sentry is typically 90 days. Neither is held by us, and neither carries anything that would let us or them connect it to you.
Children
We do not knowingly collect personal data from anyone under 18, and nothing on this site is directed at children. Minor accounts opened by a guardian are handled under that relationship, with the guardian as the data principal.
If you believe a child's data has reached us, write to us and it will be deleted.
Changes to this notice
When the substance changes, the date at the top changes with it, and the previous version is retained so you can see what moved. A material change affecting how your data is used will be notified to anyone we hold data for before it takes effect.
