Privacy Policy
1.Introduction
MECASTART INNOVATIONS PRIVATE LIMITED, CIN: U62020DL2025PTC447410, ROC: RoC-Delhi,
Registered Office: Flat No 2 GF Shop No-3 Amichand Khand Giri Nagar Kalkaji South Delhi Delhi India 110019 ("Company," "we," "our," "us," or "InvestHind").
InvestHind is a platform facilitating connections between Indian startup founders and global investors.
We are committed to protecting your personal data in compliance with:
- India’s Digital Personal Data Protection Act, 2023 (DPDP)
- EU’s General Data Protection Regulation (GDPR)
- Other applicable data protection laws
This Privacy Policy explains how we collect, use, share, and protect your personal data.
2.Information We Collect
2.1 Information You Provide:
- Identity: Name, DOB, gender, photo
- Contact: Email, phone, address
- Professional: Resume, company, role
- Startup Data: Pitch deck, financials, documents
- Investor Data: Preferences, portfolio KYC: Government IDs, PAN, Aadhaar
2.2 Automated Collection:
- Technical: IP address, device, browser
- Usage: Clickstream, time on site
- Cookies: Essential, functional, analytics, marketing
2.3 Third-Party Sources:
- Social logins (LinkedIn)
- Public registries
- Verification services
3.How We Use Your Data
3.1 Service Delivery:
- Account creation, authentication, security
- Matchmaking between startups and investors Payment
- processing and subscription management
3.2 Platform Improvement:
- Analytics for performance optimization A/B
- testing and feature enhancements
3.3 Communication:
- Service updates, announcements
- Marketing (with consent)
- Surveys and feedback
3.4 Legal Compliance:
- KYC, AML, regulatory reporting Tax
- and audit requirements
4.Legal Basis for Processing Consent
- Contract performance
- Legal obligations
- Legitimate interests
5.Sharing and Disclosure
5.1 Service Providers:
- Cloud hosts (AWS, Azure)
- Payment gateways
- Analytics tools
5.2 Legal Requirements:
- Courts, regulators, law enforcement
5.3 Business Transfers:
- M&A, asset sales
6.International Transfers
- GDPR-standard SCCs
- DPDP-approved jurisdictions
- Data localization for critical data
7.Data Retention
|
Data Type |
Retention Period |
Basis |
|
Account data |
Account lifecycle +7y |
Business & legal |
|
Transaction records |
7 years |
Tax & audit |
|
KYC documents |
10 years post-close |
PMLA |
|
Analytics logs |
12 months |
Security & optimization |
|
Consent records |
Until withdrawal |
Consent |
8.Data Security
- Encryption in transit & at rest
- Access controls & monitoring
- Regular audits & vulnerability scans
9.Data Subject Rights
- Access, correction, deletion
- Restrict, object, portability
- Consent withdrawal
Exercise via: Account dashboard, DPO contact
10.Children’s Privacy
- Minimum age 18
- Data of minors deleted
11.Changes to this Policy
We may update this Privacy Policy with notice. Continued use implies acceptance.
This document is subject to change on a timely and/or need basis at the sole discretion of the Company’s management team.