PrivacyPolicy.
Last Updated: 15 August 2026 · Effective: 15 August 2026
VentureSense Technologies LLP · Data Fiduciary under the DPDP Act, 2023 · support@zurvek.com
This Privacy Policy explains what personal data VentureSense Technologies LLP ("Zurvek", "we", "us") collects when you use the Zurvek platform, the Zurvek Engine, OriZin, CENTRA, memos, dashboards, and related APIs and emails (the "Service"); why we process it; how long we keep it; who processes it on our behalf; and the rights you hold under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and other applicable law.
1.Data We Collect
A. Account and identity. Name, email, role (Founder / Investor), organization, phone (optional), authentication metadata, and role assignments.
B. Uploaded Content. Pitch decks, financial inputs, product notes, URLs (LinkedIn, website, MCA filings), and any files you attach to support tickets.
C. Derived analytical data. Verdicts, scores, rubrics, memos, extracted metrics, idea fingerprints, and audit trails computed from your Content.
D. Usage telemetry. Pages viewed, features used, evaluation events, error reports, session identifiers, IP address, user agent, and coarse geolocation derived from IP.
E. Communications. Support tickets, replies, attachments (scanned server-side), email delivery events, and unsubscribe records.
F. Payment metadata. Transaction identifiers, plan, amount, GST status, and invoice number. Card and bank details are handled by our payment processor and never stored on Zurvek servers.
2.Why We Process (Lawful Basis)
| Data | Purpose | Lawful basis (DPDP §7) |
|---|---|---|
| Account & identity | Provide access, security, support | Contract & consent |
| Uploaded Content | Generate Verdicts you asked for | Contract |
| Derived analytical data | Deliver the Service, audit integrity | Contract & legitimate use |
| Usage telemetry | Reliability, abuse prevention, quotas | Legitimate use |
| Communications | Respond, notify, comply with §13 SLAs | Contract & legal obligation |
| Payment metadata | Invoicing, tax, fraud prevention | Contract & legal obligation |
| Anonymized derivatives | Improve models, benchmarks | Consent (opt-out available) |
3.Retention Schedule
- Account records — for the life of the account plus 24 months, then deletion or anonymization.
- Uploaded decks & files — 90 days after evaluation, or until you delete them, whichever is earlier.
- Verdicts & memos — retained while your account is active; export available for 30 days after termination.
- Anonymized derivatives — retained indefinitely unless you opt out; opt-out is prospective.
- Support tickets — 24 months, or longer where required for legal defense.
- Email delivery logs — 12 months for audit and troubleshooting.
- Payment metadata & invoices — 8 years, per Indian tax law.
- Security audit logs — 12 months for incident response.
4.Sub-processors
We rely on the following processors. Each is bound by a data-processing agreement or equivalent contractual controls.
| Provider | Data |
|---|---|
| Lovable Cloud (Supabase infra) | Application data, files, auth |
| Lovable AI Gateway (Google Gemini) | Deck excerpts, prompts, model outputs |
| Mailgun | Transactional email delivery |
| Razorpay / Paddle | Payments, tax invoices |
| Cloudflare | Edge, DNS, DDoS protection |
| Sentry / analytics | Error and usage telemetry |
Not a certification. Providers may update their own sub-processors from time to time.
5.Cross-Border Transfers
Our application database and document storage are hosted in the European Union (Ireland region). Some processors operate in other jurisdictions, including the United States. We transfer personal data outside India only where the transfer is permitted by §16 of the DPDP Act and is subject to appropriate contractual and technical safeguards. If the Indian government notifies restrictions on any destination, we will suspend or reroute the relevant flows within a reasonable period.
6.Your Rights as a Data Principal
- Access — request a summary of your personal data.
- Correction & update — request correction of inaccurate or incomplete data.
- Erasure — request deletion, subject to legal retention obligations.
- Grievance redressal — reach our Grievance Officer within 30 days.
- Nomination — nominate another person to exercise your rights on death or incapacity.
- Withdraw consent — for processing based on consent, at any time; withdrawal does not affect prior lawful processing.
- Anonymized derivatives opt-out — write to support@zurvek.com with subject "Corpus Opt-Out".
Send requests to support@zurvek.com. We respond within 30 days per DPDP §13.
7.Security
We apply defense-in-depth controls appropriate to the sensitivity of the data. Details are published on the Security page. Highlights:
- Row-Level Security enforced at the database with organization-scoped isolation.
- Encrypted at rest and in transit on our cloud provider.
- Service-role secrets stored in a managed Vault; never exposed to the browser.
- Support attachment magic-byte and signature scanning before download.
- Zero-Trust account approval flow, quota gates, and 30-second upload cooldown.
- Audit trail for admin actions and approval decisions.
No system is perfectly secure. If you believe you have found a vulnerability, contact security@zurvek.com.
8.Breach Notification
In the event of a personal data breach reasonably likely to result in harm, we will notify affected Data Principals and the Data Protection Board of India within the timelines required by law. Where CERT-In rules apply, we will report qualifying incidents within 6 hours.
9.Cookies and Similar Technologies
We use strictly necessary cookies for session, authentication, and theme, and non-essential cookies for analytics after your consent. See the Cookie Policy.
10.Children
The Service is not directed to children. We do not knowingly process personal data of anyone under 18. If you believe we have collected such data, write to support@zurvek.com and we will delete it promptly.
11.Automated Decision-Making
The Zurvek Engine produces algorithmic Verdicts. These are decision-support outputs, not automated decisions producing legal or similarly significant effects on you. You always retain human oversight over any downstream decision.
12.Changes to this Policy
Material changes will be notified in-app or by email at least 30 days before the effective date. Non-material clarifications may be published without notice.
13.Grievance Officer
In accordance with DPDP §13 and IT Rules, our Grievance Officer can be reached via the Grievance Officer page or by writing to support@zurvek.com with subject "Grievance". Response SLA: 30 days.

