Skip to main content

    PrivacyPolicy.

    Last Updated: 15 August 2026 · Effective: 15 August 2026

    VentureSense Technologies LLP · Data Fiduciary under the DPDP Act, 2023 · support@zurvek.com

    This Privacy Policy explains what personal data VentureSense Technologies LLP ("Zurvek", "we", "us") collects when you use the Zurvek platform, the Zurvek Engine, OriZin, CENTRA, memos, dashboards, and related APIs and emails (the "Service"); why we process it; how long we keep it; who processes it on our behalf; and the rights you hold under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable law.

    1.Data We Collect

    A. Account and identity. Name, email, role (Founder / Investor), organization, phone (optional), authentication metadata, and role assignments.

    B. Uploaded Content. Pitch decks, financial inputs, product notes, URLs (LinkedIn, website, MCA filings), and any files you attach to support tickets.

    C. Derived analytical data. Verdicts, scores, rubrics, memos, extracted metrics, idea fingerprints, and audit trails computed from your Content.

    D. Usage telemetry. Pages viewed, features used, evaluation events, error reports, session identifiers, IP address, user agent, and coarse geolocation derived from IP.

    E. Communications. Support tickets, replies, attachments (scanned server-side), email delivery events, and unsubscribe records.

    F. Payment metadata. Transaction identifiers, plan, amount, GST status, and invoice number. Card and bank details are handled by our payment processor and never stored on Zurvek servers.

    2.Why We Process (Lawful Basis)

    DataPurposeLawful basis (DPDP §7)
    Account & identityProvide access, security, supportContract & consent
    Uploaded ContentGenerate Verdicts you asked forContract
    Derived analytical dataDeliver the Service, audit integrityContract & legitimate use
    Usage telemetryReliability, abuse prevention, quotasLegitimate use
    CommunicationsRespond, notify, comply with §13 SLAsContract & legal obligation
    Payment metadataInvoicing, tax, fraud preventionContract & legal obligation
    Anonymized derivativesImprove models, benchmarksConsent (opt-out available)

    3.Retention Schedule

    • Account records — for the life of the account plus 24 months, then deletion or anonymization.
    • Uploaded decks & files — 90 days after evaluation, or until you delete them, whichever is earlier.
    • Verdicts & memos — retained while your account is active; export available for 30 days after termination.
    • Anonymized derivatives — retained indefinitely unless you opt out; opt-out is prospective.
    • Support tickets — 24 months, or longer where required for legal defense.
    • Email delivery logs — 12 months for audit and troubleshooting.
    • Payment metadata & invoices — 8 years, per Indian tax law.
    • Security audit logs — 12 months for incident response.

    4.Sub-processors

    We rely on the following processors. Each is bound by a data-processing agreement or equivalent contractual controls.

    ProviderData
    Lovable Cloud (Supabase infra)Application data, files, auth
    Lovable AI Gateway (Google Gemini)Deck excerpts, prompts, model outputs
    MailgunTransactional email delivery
    Razorpay / PaddlePayments, tax invoices
    CloudflareEdge, DNS, DDoS protection
    Sentry / analyticsError and usage telemetry

    Not a certification. Providers may update their own sub-processors from time to time.

    5.Cross-Border Transfers

    Our application database and document storage are hosted in the European Union (Ireland region). Some processors operate in other jurisdictions, including the United States. We transfer personal data outside India only where the transfer is permitted by §16 of the DPDP Act and is subject to appropriate contractual and technical safeguards. If the Indian government notifies restrictions on any destination, we will suspend or reroute the relevant flows within a reasonable period.

    6.Your Rights as a Data Principal

    • Access — request a summary of your personal data.
    • Correction & update — request correction of inaccurate or incomplete data.
    • Erasure — request deletion, subject to legal retention obligations.
    • Grievance redressal — reach our Grievance Officer within 30 days.
    • Nomination — nominate another person to exercise your rights on death or incapacity.
    • Withdraw consent — for processing based on consent, at any time; withdrawal does not affect prior lawful processing.
    • Anonymized derivatives opt-out — write to support@zurvek.com with subject "Corpus Opt-Out".

    Send requests to support@zurvek.com. We respond within 30 days per DPDP §13.

    7.Security

    We apply defense-in-depth controls appropriate to the sensitivity of the data. Details are published on the Security page. Highlights:

    • Row-Level Security enforced at the database with organization-scoped isolation.
    • Encrypted at rest and in transit on our cloud provider.
    • Service-role secrets stored in a managed Vault; never exposed to the browser.
    • Support attachment magic-byte and signature scanning before download.
    • Zero-Trust account approval flow, quota gates, and 30-second upload cooldown.
    • Audit trail for admin actions and approval decisions.

    No system is perfectly secure. If you believe you have found a vulnerability, contact security@zurvek.com.

    8.Breach Notification

    In the event of a personal data breach reasonably likely to result in harm, we will notify affected Data Principals and the Data Protection Board of India within the timelines required by law. Where CERT-In rules apply, we will report qualifying incidents within 6 hours.

    9.Cookies and Similar Technologies

    We use strictly necessary cookies for session, authentication, and theme, and non-essential cookies for analytics after your consent. See the Cookie Policy.

    10.Children

    The Service is not directed to children. We do not knowingly process personal data of anyone under 18. If you believe we have collected such data, write to support@zurvek.com and we will delete it promptly.

    11.Automated Decision-Making

    The Zurvek Engine produces algorithmic Verdicts. These are decision-support outputs, not automated decisions producing legal or similarly significant effects on you. You always retain human oversight over any downstream decision.

    12.Changes to this Policy

    Material changes will be notified in-app or by email at least 30 days before the effective date. Non-material clarifications may be published without notice.

    13.Grievance Officer

    In accordance with DPDP §13 and IT Rules, our Grievance Officer can be reached via the Grievance Officer page or by writing to support@zurvek.com with subject "Grievance". Response SLA: 30 days.