Legal

Privacy Policy

Effective 15 May 2026 · Operated by Fundclair Technologies, A-26, Third Floor, Sector 8, Dwarka, New Delhi 110077
Version 1.1
Fundclair provides an investor-reporting and fund-administration platform to alternative investment funds ("Funds"). This Privacy Policy explains what data we handle, in what role, how we protect it, and your rights under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable Indian law.

1. Who we are, and the two roles we play

Under the DPDP Act we act in two distinct roles:
  • For investor data on the platform (everything a Fund or its investors upload or generate while using the platform): the Fund is the Data Fiduciary and Fundclair is its Data Processor. We process this data on the Fund's instructions under a written agreement. If you are an investor, your Fund decides why and how your data is processed; your rights requests are actioned through the platform or your Fund, as described in §8.
  • For data we collect for our own purposes — website visits, demo usage, sales enquiries, billing contacts, and the account details of Fund administrators: Fundclair is the Data Fiduciary, and this policy is our notice to you.

2. What we collect

Investor data (processed for your Fund): full legal name; PAN; Aadhaar number where provided during KYC; contact details (email, phone, postal address); bank account and IFSC details; demat details; FATCA/CRS declarations; nominee, joint-holder, and beneficial-ownership details; KYC documents; commitment, unit, holding, and transaction data and derived metrics (folio, unit class, commitment, drawn and uncalled amounts, NAV-based figures such as XIRR, TVPI, DPI, MOIC); documents delivered to you; queries and communications; and portal access logs.
Data we collect as fiduciary: administrator account details (name, email, phone, role); login and security records; support and enquiry messages; billing details; and technical data (IP address, device and browser information, timestamps).
We do not use personal data for advertising. We do not sell, rent, or licence personal data to anyone.

3. Why we process it

To operate the investor portal and fund-administration workflows (onboarding, statements, capital calls, distributions, documents, queries); to authenticate users and secure the platform (including fraud and abuse detection); to maintain audit trails of sensitive actions; to provide support; to invoice Funds; and to comply with law. Processing of investor data is on the instructions of your Fund; the Fund is responsible for its legal basis (including any notice or consent it must give you).

4. Where your data lives

Your data is stored in India. Our primary systems — the database, authentication, application, and all documents — run in the Mumbai region, with each fund's data kept isolated from every other fund's. The one exception is transactional email, which is delivered by a provider whose infrastructure operates outside India. Every provider that processes your data, and where each one operates, is listed in the sub-processor register in Section 5.

5. Who else touches your data (sub-processors)

Provider
Purpose
Location
Supabase
Database and authentication
India (Mumbai)
Amazon Web Services
Document storage and delivery
India (Mumbai)
Vercel
Application hosting and compute
India (Mumbai)
Resend
Transactional email delivery
Japan (Tokyo)
Cashfree
PAN verification during onboarding
India
Leegality
Electronic signing of fund documents
India
We impose contractual data-protection obligations on each sub-processor. This list is kept current at our sub-processors page; material changes are notified to Funds under our agreements with them.

6. How we protect it

  • In transit: TLS 1.2 or higher on all connections.
  • At rest: encryption at the infrastructure layer (managed-database and object-storage encryption). In addition, designated sensitive fields — PAN, Aadhaar, bank account number, and other government-identifier and financial-account fields (including passport / OCI numbers, foreign tax-identification numbers, and demat account identifiers) — are encrypted at the field level using AES-256-GCM with a server-side key; the database stores ciphertext for these fields at rest.
  • Access control: role-based access; investors can access only their own folio's data; per-fund isolation including separate document storage per fund.
  • Authentication: mandatory two-factor authentication for fund administrators using authenticator-app TOTP; TOTP two-factor is offered to investors, who may opt out.
  • Governance: consequential actions require dual control (maker-checker) with second-factor approval; sensitive operations are written to an audit log recording timestamp, user, and action.
  • Resilience: nightly backups with documented restore procedures; inactive sessions are logged out after 30 minutes.
  • Testing: periodic security assessment and risk-prioritised remediation.

7. How long we keep it

For investor data we are a processor: we retain it for as long as your Fund instructs and applicable law requires, and on termination of a Fund's agreement we make data available for export and then delete it on the contractual schedule (export window 30 days; deletion at 90 days, except where law requires longer retention). Funds are typically subject to record-keeping laws — for example, KYC records for at least five years after the relationship ends under anti-money-laundering law, and SEBI record-keeping requirements applicable to AIFs — so erasure requests may be met by anonymisation where full deletion would conflict with those obligations. For data we hold as fiduciary: audit logs of sensitive operations are retained for at least as long as applicable law requires; security and access logs are retained at least one year (and as required by CERT-In directions, at least 180 days in rolling form); enquiry and billing records as needed for the purposes above; we delete or anonymise when the purpose is served, with prior notice before scheduled deletion where the DPDP Rules require it.

8. Your rights

If you are an investor, exercise your rights through the portal or your Fund (the Data Fiduciary): a summary of your data and its purposes (access); correction of inaccurate or incomplete data (the portal's profile update-request feature); erasure (the portal's erasure-request feature runs an export-then-delete process, subject to the retention laws in §7); consent withdrawal (via your Fund); and grievance redressal. If you are a website visitor or administrator, contact us directly.
We acknowledge requests within 3 business days and resolve grievances within timelines not exceeding 90 days as prescribed under the DPDP Rules. If unresolved, you may complain to the Data Protection Board of India.

9. Cookies

The platform uses only essential session cookies required for authentication and security. No advertising cookies, no cross-site tracking. Aggregate, non-identifying statistics may be collected to operate the service.

10. Children

The platform is not directed at persons under 18. Investors are onboarded by Funds subject to their own eligibility and KYC obligations; guardian-operated accounts for minor investors, where a Fund permits them, are the Fund's responsibility as fiduciary. If we learn we hold a child's data without required safeguards, we will address it promptly with the Fund.

11. Changes

Material changes are notified by email and on-platform notice, with version and date shown. Continued use after notice is acceptance.

12. Grievance Officer

Grievance Officer — Fundclair
admin@fundclair.com
Suresh Kumar · A-26, Third Floor, Sector 8, Dwarka, New Delhi 110077 · acknowledgement within 3 business days, resolution within the timelines in §8.