Effective Date: 1 July 2026 · Last Updated: 1 July 2026 · Governing Entity: CapitalSync Technologies Pvt. Ltd.
CapitalSync Technologies Pvt. Ltd. ("CapitalSync", "we", "us", "our") is the data controller for personal data collected through the CapitalSync platform, APIs, mobile applications, and associated services. Registered in India under the Companies Act 2013.
For EU/EEA users, we act as a data controller under GDPR Article 4(7). For UAE operations, CapitalSync is registered under DIFC Data Protection Law No. 5 of 2020. For Singapore operations, we comply with PDPA 2012 (amended 2021).
Data Protection Officer (DPO): privacy@capitalsync.net
Grievance Officer (India — DPDPA): grievance@capitalsync.net · Response within 72 hours
Identity & Contact: Full name, email, phone number, government-issued ID (for KYC), business registration numbers (PAN, GST, CIN, DIFC number, company registration).
Financial Data: Bank account details (for payment processing only), investment amounts, valuation data, funding history. We do NOT store raw card numbers — all payments are processed via PCI-DSS compliant gateways (Razorpay, Stripe, PayTabs).
Business Data: Pitch decks, financial statements, cap table entries, grant applications, compliance records — uploaded into the Virtual Data Room (VDR) or provided during onboarding.
Usage Data: IP address, browser type, pages visited, time spent, AI agent interactions, feature usage patterns. Collected via server logs and anonymised analytics.
Communications: WhatsApp messages sent through the platform, email correspondence, Telegram notifications (only if you opt-in).
AI-Generated Data: PERSIST scores, valuation models, grant eligibility results, investor match scores — generated by our AI engines based on data you provide.
You may withdraw consent at any time. Withdrawal does not affect lawfulness of processing before withdrawal.
Documents uploaded to the VDR are encrypted at rest (AES-256) and in transit (TLS 1.3). Access is controlled by NDA-gating — no investor can view documents without executing the required NDA on-platform.
All document accesses are logged with timestamp, user ID, IP address, and device fingerprint. Watermarking is applied automatically to all PDFs. AI classification of documents is performed by our models — no document content is shared with third-party AI providers.
VDR data is stored in Supabase (hosted on AWS Mumbai for India), with EU data stored in AWS Frankfurt under Standard Contractual Clauses (SCCs).
Retention: VDR documents are retained for the duration of your subscription + 7 years (Indian Companies Act requirement for financial records). You may request deletion at any time; we will comply within 30 days unless legal retention obligations apply.
CapitalSync operates 11 specialist AI agents (CapitalBot, FundRaise AI, Valuation AI, GrantFinder AI, Legal AI, KYB Verifier, DebtMatch AI, TradeSync AI, Retention AI, GrowthPath AI, Platform Health AI) that make recommendations on investment matching, valuation, grant eligibility, and compliance.
Under GDPR Article 22 and DPDPA Section 12, you have the right to not be subject to a decision based solely on automated processing that produces legal or significant effects. You may request human review of any AI-generated decision (PERSIST score, investor match, KYC result) by emailing privacy@capitalsync.net.
AI models are trained on anonymised, aggregated market data and do NOT use your personal business data to train models without explicit consent. AI outputs are recommendations only — not financial advice.
We share data only where necessary:
We do NOT sell personal data. We do NOT share data with advertisers.
Data may be processed in India, UAE, UK, EU, Singapore, and the US depending on service used. All transfers are protected by:
Depending on your jurisdiction, you have the following rights:
Exercise rights: privacy@capitalsync.net · Response within 30 days (GDPR) / 72 hours acknowledgement + 30 days resolution (DPDPA)
Supervisory Authority complaints: India — Data Protection Board of India · EU — Your local DPA · UK — ICO · UAE DIFC — DIFC Commissioner of Data Protection
We implement: AES-256 encryption at rest · TLS 1.3 in transit · ISO 27001-aligned controls · SOC 2 Type II (in progress) · Role-Based Access Control · Multi-Factor Authentication · Penetration testing (quarterly) · Intrusion detection · SIEM monitoring 24/7 · Supabase Row-Level Security on all tables.
Data breach notification: Affected users within 72 hours per GDPR Art. 34 · DPDPA Sec. 8(6) · DIFC DP Law Art. 21.
CapitalSync services are not directed to persons under 18 years of age. We do not knowingly collect personal data from minors. If we become aware of such collection, data is deleted within 72 hours. Parents/guardians: contact privacy@capitalsync.net.
We use: Essential cookies (session management — cannot be disabled) · Analytics cookies (anonymised, opt-out available) · No third-party advertising cookies. We do not use cross-site tracking. Cookie preference centre available in account settings.
We may update this policy to reflect legal changes or new features. Material changes will be notified via email 30 days in advance. Continued use after the effective date constitutes acceptance. Previous versions available at legal@capitalsync.net.
Data Protection Officer: privacy@capitalsync.net
Grievance Officer (India): grievance@capitalsync.net
Legal: legal@capitalsync.net
Postal: CapitalSync Technologies Pvt. Ltd., India