PPEXONIX
Template — to be reviewed by your lawyer before launch.

Privacy policy

Last updated: 22 September 2026
This policy explains how Pexonix processes personal data. It is written to meet India's Digital Personal Data Protection Act, 2023 (“DPDP Act”) and, for users in the EU/UK, the GDPR. Pexonix is the data fiduciary / controller for the data described here.

1. Data we collect

CategoryExamplesWhy
AccountName, email, phone (optional), login provider ID, countryCreate and secure your account
Company profileCompany name, logo, description, tags, location, website, founders' names, photos and LinkedInPublish your Startup Force profile (public by your choice)
EmployeesName, designation; photo and email only with the employee's consentTeam directory and digital IDs
Funding data (Fund Force)Address, revenue, prior rounds, raise amount, plansAI analysis and investor matching — never public, stored encrypted
Job applicationsName, email, LinkedIn, résumé, answersSent to the hiring company only
Messages & NDAsChat messages, signed NDAs (name, time, IP hash, document hash)Connections you accept
PaymentsPlan, amount, gateway reference (card data is handled by the gateway, not us)Billing, invoices, tax
Card-download leadsVisitor name, email and company entered to download a digital ID cardShared with that company as a lead, with your consent
TechnicalSalted hash of IP address, device/browser, pages visited, security logsSecurity, fraud and abuse prevention
Analytics (optional)Aggregated usage via Google AnalyticsOnly if you accept analytics cookies

2. Legal basis

We process data on the basis of your consent (DPDP Act s.6; GDPR Art. 6(1)(a)), to perform our contract with you (GDPR Art. 6(1)(b)), for legitimate uses permitted by law such as security and fraud prevention (DPDP Act s.7; GDPR Art. 6(1)(f)), and to meet legal obligations such as tax records. We use data only for the purpose it was collected for.

3. Funding data is never public

No funding information about any startup is ever published, indexed or shown to other startups, media or the public. Investors see a teaser (sector, stage, country, raise range, readiness) until you accept their request and, where enabled, an NDA is signed. The optional “auto-share” feature is off by default, requires your opt-in per investor, is logged and can be revoked. You can see who has access and revoke it at any time.

4. Employee consent

A company may list an employee's name and designation. The employee's photo and email are shown only after the employee consents (by clicking a consent email or via a signed consent form). Employees can edit their details or withdraw consent at any time through their personal link or by contacting us; their details are then removed.

5. Processors and sharing

We do not sell personal data. We share it with service providers who process it for us under data-processing agreements:

  • Google — Firebase Authentication (login), Gemini AI (analysis on a paid tier that does not train on customer data), Google Workspace (email), Google Analytics (only with consent)
  • Razorpay — payments in India
  • PayPal — payments outside India
  • Cloudflare — content delivery, DNS, security and bot protection (Turnstile)
  • Resend — automatic system emails
  • Our hosting provider (virtual private server) where our database and files are stored

We also share data with other users only as you direct (e.g. an investor you accept, a company you apply to) and with authorities where the law requires it.

6. International transfers

Some processors operate outside India or your country. Transfers are made under contracts with appropriate safeguards (such as the EU Standard Contractual Clauses) and in line with the DPDP Act.

7. Retention

  • Account and profile data: while your account is active, then deleted within 90 days of closure (invoices kept as tax law requires).
  • Job applications and résumés: automatically deleted after 12 months, or earlier on request.
  • Signed NDAs: kept for the life of the agreement plus the legal limitation period.
  • Security logs: up to 12 months.

8. Security

Funding data, contacts, messages and NDAs are encrypted in the database (AES-256); traffic is encrypted in transit; access is restricted, logged and audited; IP addresses are stored only as salted hashes. See our security page.

9. Your rights

Subject to law, you can: access your data and download a copy; correct or update it; delete your account and data; withdraw consent at any time (without affecting prior processing); object to or restrict processing (GDPR); nominate another person to exercise your rights if you die or become incapacitated (DPDP Act); and complain to a regulator (the Data Protection Board of India, or your EU/UK supervisory authority). Signed-in users can download or delete data from account settings; anyone can use the grievance form (choose “Privacy / my data”). We respond within 30 days.

10. Cookies

We use essential cookies only, unless you accept analytics. See the cookie policy.

11. Children

Pexonix is not intended for anyone under 18, and we do not knowingly process children's data.

12. Contact and Grievance Officer

Questions about this policy or your data: [email protected]. Our Grievance Officer's details are on the Grievance page.

13. Changes

We will post updates here and email you about material changes.