Your rights
Pick a right to pre-fill the request form, or read what each one means first.
Access & export
A copy of everything we hold about you — profile, verification record, consent history, and who your private fields were revealed to — as JSON and a readable PDF.
DPDP §11 · GDPR Art. 15, 20RequestCorrect
Most fields you can edit yourself from your profile. Verified fields (company name, CIN, DPIIT) are corrected by our team after a fresh MCA check.
DPDP §12 · GDPR Art. 16RequestDelete / erase
Close the account: the profile is unpublished immediately, personal data erased within 30 days, backups within a further 30. Consent and audit records are kept as the law requires.
DPDP §12 · GDPR Art. 17RequestWithdraw consent
For one purpose (say, being shown to investors) or for everything. As easy as giving it; takes effect going forward.
DPDP §6(4) · GDPR Art. 7(3)RequestObject / restrict
Where we rely on legitimate use rather than consent — security logs, for example — you can object, and we stop unless we can show compelling grounds.
GDPR Art. 18, 21RequestRaise a grievance
Something we got wrong, a request we didn't handle well, or a concern about how your data was used. Goes straight to the grievance officer.
DPDP §13Request
Make a request
Make a request
No account needed. We verify it’s you by sending a one-time code to the mobile number or email on the account before we release, change or delete anything.
What happens next
- 1
Acknowledged
You get a reference and an acknowledgement within 3 working days.
- 2
Verified
We send a one-time code to the mobile number or email on the account. Nothing moves until it's confirmed.
- 3
Actioned
Export delivered, field corrected, consent withdrawn or account erased — within 30 days.
- 4
Recorded
The request, the decision and who made it are written to the audit log, so you can ask us to show our working.
How we verify it's you
Releasing or deleting data to the wrong person would be a breach, so every request is verified against the account: a one-time code to the registered mobile number or email, and for erasure a second confirmation. Nominees under the DPDP Act should attach the nomination or authority they hold. We never ask for PAN or documents by email.
- Passwordless sign-in: one-time codes expire quickly and are stored only as hashes.
- Admin access is IP-restricted and every review decision is logged with who, what and when.
- How we protect your data
Do it yourself, right now
If you have an account, most of this is a few taps away:
- Edit or unpublish
- Your profile — every section can be edited or hidden individually.
- Cookie choices
- Cookie policy — change your preference at any time.
If you're not satisfied
Start with the Office of the Grievance Officer, at privacy@ascend.in — a staffed desk rather than a named individual, because no officer has been appointed yet (why). If we don’t resolve it within the statutory period, or you disagree with our answer, you can complain to the Data Protection Board of India (DPDP Act §18) or, if you are in the EU/UK, to your local supervisory authority. Doing so never affects your account.