Home/Guide & Trust/Trust/Privacy & Data
← All guides

Privacy & Data

Trust 5 min read

Privacy & Data Policy

Last updated: [19/05/2026] Data Fiduciary: Dealzebra Global Intelligence LLP ("DealCollab")

This policy explains what data we collect, why, who can see it, and your rights under Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP).

1. What we collect

  • Account data: name, firm, email, phone, professional role.
  • KYC data: identity documents you submit for verification.
  • Mandate data: deal information you provide — sector, geography, size, revenue ranges, structure, and descriptions. We ask for ranges and descriptors; you are never required to submit client-identifying details during intake.
  • Usage data: logins, actions on the platform, EOIs sent and received, token transactions.

2. Why we process it (purposes)

  • To verify your identity (KYC).
  • To run the matching engine on your mandates.
  • To notify you about matches and EOIs.
  • To maintain your token ledger and process payments.
  • To keep the platform secure and prevent fraud and fake mandates.
  • To comply with legal obligations.

We process this data with your consent, given when you register and submit mandates. You may withdraw consent by deleting your account, subject to data we must retain by law.

3. Who can see what — the core rule

  • Your identity, firm name, and contact details are hidden from other users by default.
  • Counterparties see only anonymised match information (sector, geography, compatibility rationale).
  • Your verified name and phone number are shared with a counterparty only when an EOI between you is approved — by you, for inbound EOIs.
  • We do not sell mandate data. We do not share your confidential deal information with advertisers or data brokers. Aggregated, anonymised statistics (e.g., sector distribution) may be used to describe the platform.

4. Third parties we use

We use service providers to run the platform: cloud hosting, database infrastructure, payment processing, and AI processing of mandate text for matching. These providers process data on our instructions under confidentiality obligations. [List named processors here — hosting provider, payment gateway, AI provider.]

5. Security

  • Sensitive fields are encrypted in transit and at rest.
  • Access to confidential data is role-restricted and logged.
  • In the event of a personal data breach, we will notify affected users and the Data Protection Board of India as required by the DPDP Act, restrict access immediately, and take corrective measures.

6. Retention

  • Active mandate data is retained while your mandate is live.
  • Deleted mandates are removed from matching immediately and from operational systems within [30] days, except records we must keep for legal, tax, or fraud-prevention purposes.
  • Token ledger and payment records are retained as required by law.

7. Your rights (DPDP)

You may, at any time:

  • Access a summary of the personal data we hold about you.
  • Correct inaccurate data — mandates are editable in-app.
  • Delete your mandates and your account.
  • Withdraw consent for processing (this ends matching for your mandates).
  • Grieve: raise a complaint with our Grievance Officer, and if unresolved, with the Data Protection Board of India.

To exercise any right, email [privacy email]. We respond within [15] days.

8. Grievance Officer

Name: [FULL NAME — DPDP requires a real, named person] Email: [email] Address: [Registered address]

9. Children

The platform is for professionals aged 18+. We do not knowingly process children's data.

10. Changes

Material changes to this policy will be notified in-app before they take effect.

Ready to submit a mandate?

Join DealCollab

Next

Terms of Service