Legal

Privacy Policy

Effective: 1 January 2026 · DPDPA 2023 Compliant · Data stored in India

1. Data Controller

CapitalSync Technologies Pvt. Ltd. ("CapitalSync", "we", "us") is the Data Fiduciary under the Digital Personal Data Protection Act 2023 (DPDPA 2023) for all personal data collected through the Platform.

2. Data We Collect

We collect: (a) Identity data — name, email, phone, PAN, Aadhaar (for KYC); (b) Company data — firm name, sector, financials uploaded to VDR; (c) Usage data — login logs, deal views, document access; (d) Payment data — transaction IDs, plan history (no full card data stored). We do NOT sell personal data.

3. Purpose of Processing

Data is processed for: platform authentication, KYC/AML verification, deal matching, PTLF fee calculation, MSME scheme eligibility, regulatory compliance (SEBI/RBI/PMLA), and platform improvement. We process data only for stated purposes.

4. Data Storage & Sovereignty

All personal data is stored on servers located in India, compliant with DPDPA 2023 data localisation requirements. No personal data is transferred outside India without explicit user consent, except where required by law.

5. Your Rights (DPDPA 2023)

You have the right to: (a) Access your personal data; (b) Correct inaccurate data; (c) Erase your data (soft-delete with 30-day grace period); (d) Withdraw consent for non-essential processing; (e) Nominate a data trustee. Submit requests to: privacy@capitalsync.net.

6. Cookies & Tracking

We use essential cookies for authentication and security. Analytics cookies require explicit consent. We do not use cross-site tracking or third-party ad networks. Cookie preferences can be managed in your account settings.

7. Data Retention

Active account data is retained for the duration of your subscription plus 7 years (GST compliance). KYC documents are retained for 10 years under PMLA requirements. Deleted account data is purged after 30-day grace period.

8. Third-Party Processors

We use: Supabase (database, auth — Indian region); Razorpay (payment processing — RBI compliant); Resend/MSG91 (email/SMS — data processed under DPA agreements). All processors are contractually bound to DPDPA 2023 standards.

9. Security

We implement AES-256 encryption at rest, TLS 1.3 in transit, HMAC-SHA256 webhook verification, row-level security (RLS) on all database tables, immutable audit trails, and regular penetration testing.

10. Contact & Grievance Officer

Data Protection Officer: dpo@capitalsync.net · Grievance redressal (DPDPA 2023): grievance@capitalsync.net · Response within 72 hours as required by law.