LEGAL · GDPR · DPDPA · CCPA · DIFC · PDPA

Privacy Policy

Effective Date: 1 July 2026 · Last Updated: 1 July 2026 · Governing Entity: CapitalSync Technologies Pvt. Ltd.

This Privacy Policy applies globally to all users of CapitalSync platforms across 192 countries. It is compliant with the Indian Digital Personal Data Protection Act 2023 (DPDPA), EU General Data Protection Regulation (GDPR), UAE DIFC Data Protection Law 2020, Singapore PDPA, US CCPA/CPRA, South Africa POPIA, and other applicable data protection laws as of July 2026.

1. Who We Are (Data Controller)

CapitalSync Technologies Pvt. Ltd. ("CapitalSync", "we", "us", "our") is the data controller for personal data collected through the CapitalSync platform, APIs, mobile applications, and associated services. Registered in India under the Companies Act 2013.

For EU/EEA users, we act as a data controller under GDPR Article 4(7). For UAE operations, CapitalSync is registered under DIFC Data Protection Law No. 5 of 2020. For Singapore operations, we comply with PDPA 2012 (amended 2021).

Data Protection Officer (DPO): privacy@capitalsync.net

Grievance Officer (India — DPDPA): grievance@capitalsync.net · Response within 72 hours

2. Data We Collect

Identity & Contact: Full name, email, phone number, government-issued ID (for KYC), business registration numbers (PAN, GST, CIN, DIFC number, company registration).

Financial Data: Bank account details (for payment processing only), investment amounts, valuation data, funding history. We do NOT store raw card numbers — all payments are processed via PCI-DSS compliant gateways (Razorpay, Stripe, PayTabs).

Business Data: Pitch decks, financial statements, cap table entries, grant applications, compliance records — uploaded into the Virtual Data Room (VDR) or provided during onboarding.

Usage Data: IP address, browser type, pages visited, time spent, AI agent interactions, feature usage patterns. Collected via server logs and anonymised analytics.

Communications: WhatsApp messages sent through the platform, email correspondence, Telegram notifications (only if you opt-in).

AI-Generated Data: PERSIST scores, valuation models, grant eligibility results, investor match scores — generated by our AI engines based on data you provide.

3. Why We Collect It (Legal Basis)

  • Contract performance — to provide the services you signed up for (GDPR Art. 6(1)(b))
  • Legal obligation — KYC/AML compliance under PMLA, SEBI AIF Regulations, DIFC AML Rules (GDPR Art. 6(1)(c))
  • Legitimate interests — fraud prevention, platform security, AI model improvement with anonymised data (GDPR Art. 6(1)(f))
  • Consent — marketing communications, HeyGen AI video generation, WhatsApp outreach (GDPR Art. 6(1)(a) · DPDPA Sec. 6)
  • Vital interests — not applicable to our services

You may withdraw consent at any time. Withdrawal does not affect lawfulness of processing before withdrawal.

4. Virtual Data Room (VDR) — Special Data Handling

Documents uploaded to the VDR are encrypted at rest (AES-256) and in transit (TLS 1.3). Access is controlled by NDA-gating — no investor can view documents without executing the required NDA on-platform.

All document accesses are logged with timestamp, user ID, IP address, and device fingerprint. Watermarking is applied automatically to all PDFs. AI classification of documents is performed by our models — no document content is shared with third-party AI providers.

VDR data is stored in Supabase (hosted on AWS Mumbai for India), with EU data stored in AWS Frankfurt under Standard Contractual Clauses (SCCs).

Retention: VDR documents are retained for the duration of your subscription + 7 years (Indian Companies Act requirement for financial records). You may request deletion at any time; we will comply within 30 days unless legal retention obligations apply.

5. AI Agents & Automated Decision-Making

CapitalSync operates 11 specialist AI agents (CapitalBot, FundRaise AI, Valuation AI, GrantFinder AI, Legal AI, KYB Verifier, DebtMatch AI, TradeSync AI, Retention AI, GrowthPath AI, Platform Health AI) that make recommendations on investment matching, valuation, grant eligibility, and compliance.

Under GDPR Article 22 and DPDPA Section 12, you have the right to not be subject to a decision based solely on automated processing that produces legal or significant effects. You may request human review of any AI-generated decision (PERSIST score, investor match, KYC result) by emailing privacy@capitalsync.net.

AI models are trained on anonymised, aggregated market data and do NOT use your personal business data to train models without explicit consent. AI outputs are recommendations only — not financial advice.

6. Data Sharing & Third Parties

We share data only where necessary:

  • Payment processors: Razorpay (India), Stripe (Global), PayTabs (UAE/GCC) — for subscription and transaction processing
  • KYC/AML providers: Digio, Signzy, Sumsub — for identity verification under regulatory obligation
  • Cloud infrastructure: Supabase (Postgres), Railway (compute), Vercel (CDN/edge) — under DPAs
  • Communication: Resend/SendGrid (email), WhatsApp Business API (Meta), Telegram Bot API — only for messages you initiate or opt into
  • AI video: HeyGen — only if you explicitly request AI pitch video generation; your data is not retained by HeyGen beyond the generation session
  • Regulatory bodies: SEBI, RBI, MCA, FIU-IND, DIFC, FCA — when legally compelled
  • Investors/Counterparties: only data you explicitly share via the VDR or deal room, subject to NDA

We do NOT sell personal data. We do NOT share data with advertisers.

7. International Data Transfers

Data may be processed in India, UAE, UK, EU, Singapore, and the US depending on service used. All transfers are protected by:

  • EU → India: Standard Contractual Clauses (SCCs) under GDPR Art. 46(2)(c)
  • UK → India: UK IDTA (International Data Transfer Agreement)
  • UAE DIFC: Adequacy decisions or SCCs under DIFC DP Law
  • Singapore PDPA: Data Transfer Agreements per PDPC guidelines
  • US CCPA: Data Processing Agreements with all sub-processors

8. Your Rights

Depending on your jurisdiction, you have the following rights:

  • Access — obtain a copy of your personal data (GDPR Art. 15 / DPDPA Sec. 11)
  • Rectification — correct inaccurate data (GDPR Art. 16 / DPDPA Sec. 12)
  • Erasure — request deletion ("right to be forgotten") (GDPR Art. 17 / DPDPA Sec. 13)
  • Portability — receive your data in machine-readable format (GDPR Art. 20)
  • Restriction — limit processing in certain circumstances (GDPR Art. 18)
  • Objection — object to processing based on legitimate interests (GDPR Art. 21)
  • Opt-out of automated decisions — request human review (GDPR Art. 22 / DPDPA Sec. 12)
  • Nominate — designate a person to exercise rights on your behalf (DPDPA Sec. 14)
  • CCPA: Know, Delete, Correct, Opt-Out of Sale/Sharing, Non-Discrimination

Exercise rights: privacy@capitalsync.net · Response within 30 days (GDPR) / 72 hours acknowledgement + 30 days resolution (DPDPA)

Supervisory Authority complaints: India — Data Protection Board of India · EU — Your local DPA · UK — ICO · UAE DIFC — DIFC Commissioner of Data Protection

9. Data Retention

  • Account data: Duration of subscription + 7 years (Indian statutory requirement)
  • KYC/AML records: 5 years from last transaction (PMLA 2002)
  • Financial transaction records: 8 years (Income Tax Act 1961)
  • VDR documents: Subscription duration + 7 years (unless deletion requested)
  • Audit logs: 3 years (SEBI Intermediary Regulations)
  • Marketing consent records: 3 years from last interaction
  • Anonymised analytics: Indefinitely (no personal data)

10. Security

We implement: AES-256 encryption at rest · TLS 1.3 in transit · ISO 27001-aligned controls · SOC 2 Type II (in progress) · Role-Based Access Control · Multi-Factor Authentication · Penetration testing (quarterly) · Intrusion detection · SIEM monitoring 24/7 · Supabase Row-Level Security on all tables.

Data breach notification: Affected users within 72 hours per GDPR Art. 34 · DPDPA Sec. 8(6) · DIFC DP Law Art. 21.

11. Children's Privacy

CapitalSync services are not directed to persons under 18 years of age. We do not knowingly collect personal data from minors. If we become aware of such collection, data is deleted within 72 hours. Parents/guardians: contact privacy@capitalsync.net.

12. Cookies & Tracking

We use: Essential cookies (session management — cannot be disabled) · Analytics cookies (anonymised, opt-out available) · No third-party advertising cookies. We do not use cross-site tracking. Cookie preference centre available in account settings.

13. Changes to This Policy

We may update this policy to reflect legal changes or new features. Material changes will be notified via email 30 days in advance. Continued use after the effective date constitutes acceptance. Previous versions available at legal@capitalsync.net.

14. Contact

Data Protection Officer: privacy@capitalsync.net

Grievance Officer (India): grievance@capitalsync.net

Legal: legal@capitalsync.net

Postal: CapitalSync Technologies Pvt. Ltd., India

Terms of ServiceDisclaimerSecurityRefund Policy← Back to Home