Legal
Effective: 1 January 2026 · DPDPA 2023 Compliant · Data stored in India
CapitalSync Technologies Pvt. Ltd. ("CapitalSync", "we", "us") is the Data Fiduciary under the Digital Personal Data Protection Act 2023 (DPDPA 2023) for all personal data collected through the Platform.
We collect: (a) Identity data — name, email, phone, PAN, Aadhaar (for KYC); (b) Company data — firm name, sector, financials uploaded to VDR; (c) Usage data — login logs, deal views, document access; (d) Payment data — transaction IDs, plan history (no full card data stored). We do NOT sell personal data.
Data is processed for: platform authentication, KYC/AML verification, deal matching, PTLF fee calculation, MSME scheme eligibility, regulatory compliance (SEBI/RBI/PMLA), and platform improvement. We process data only for stated purposes.
All personal data is stored on servers located in India, compliant with DPDPA 2023 data localisation requirements. No personal data is transferred outside India without explicit user consent, except where required by law.
You have the right to: (a) Access your personal data; (b) Correct inaccurate data; (c) Erase your data (soft-delete with 30-day grace period); (d) Withdraw consent for non-essential processing; (e) Nominate a data trustee. Submit requests to: privacy@capitalsync.net.
We use essential cookies for authentication and security. Analytics cookies require explicit consent. We do not use cross-site tracking or third-party ad networks. Cookie preferences can be managed in your account settings.
Active account data is retained for the duration of your subscription plus 7 years (GST compliance). KYC documents are retained for 10 years under PMLA requirements. Deleted account data is purged after 30-day grace period.
We use: Supabase (database, auth — Indian region); Razorpay (payment processing — RBI compliant); Resend/MSG91 (email/SMS — data processed under DPA agreements). All processors are contractually bound to DPDPA 2023 standards.
We implement AES-256 encryption at rest, TLS 1.3 in transit, HMAC-SHA256 webhook verification, row-level security (RLS) on all database tables, immutable audit trails, and regular penetration testing.
Data Protection Officer: dpo@capitalsync.net · Grievance redressal (DPDPA 2023): grievance@capitalsync.net · Response within 72 hours as required by law.