The short version
- We collect only what a curated marketplace needs: who you are, what you represent, and enough to verify it.
- Sensitive fields are never public. PAN, CIN, financials and contact details are shown to a counterparty only after both sides agree to an introduction.
- We don’t sell data and we don’t run ad trackers. Only essential cookies are in use today.
- You are in control. Export, correct, delete, or withdraw consent from the Data & privacy centre — no account needed to ask.
Who is responsible for your data
Ascend is operated from India by the company identified below. In DPDP terms that company is the Data Fiduciary; in GDPR terms the Controller for the personal data described here. Where a founder uploads information about team members or shareholders, the founder is responsible for having the right to share it.
- Operating entity
- Avyxon AI Labs
- Registered address
- Will be published here once the registered office is filed. Until then, reach us by email.
- Contact
- privacy@ascend.in
What we collect and why
Each row below is one category of data. “Kept for” is our standard retention; the retention section explains the exceptions.
Identity & sign-in
- Examples
- Mobile number (verified by one-time code), name, work email.
- Why
- To create your account, sign you in without a password and reach you about the account.
- Basis
- ContractConsent
- Kept for
- Life of the account + 90 days
Role & intent
- Examples
- Founder / investor / mentor, sectors and stages of interest.
- Why
- To show you the right side of the marketplace and match you appropriately.
- Basis
- Contract
- Kept for
- Life of the account
Startup profile
- Examples
- Company name, one-liner, sector, stage, traction, team, links, pitch materials you upload.
- Why
- To build the public profile you choose to publish and let verified counterparties evaluate it.
- Basis
- ConsentContract
- Kept for
- Until you unpublish or delete
Company verification
Never public- Examples
- CIN, DPIIT recognition number, registered name and address as returned by the MCA lookup.
- Why
- To verify the company exists and that you are entitled to represent it before the profile is published.
- Basis
- ConsentLegitimate use
- Kept for
- Life of the account; the verification decision is kept 7 years
Sensitive financial identifiers
Never public- Examples
- PAN, turnover, funding history, cap-table summary, investor cheque size / thesis.
- Why
- For due-diligence readiness and to make a meaningful introduction. Revealed only through a double-blind introduction.
- Basis
- Consent
- Kept for
- Until you remove it or delete the account
Investor & mentor profile
- Examples
- Firm / affiliation, focus areas, bio, public links.
- Why
- So founders can decide whether an introduction makes sense.
- Basis
- ConsentContract
- Kept for
- Until you unpublish or delete
Consent records
- Examples
- Which version of this notice and the Terms you agreed to, when, from which IP.
- Why
- To prove consent was given, and to honour a withdrawal precisely.
- Basis
- Legal duty
- Kept for
- 7 years after the account closes
Service & security logs
- Examples
- IP address, device/browser, timestamps, OTP attempts, admin actions.
- Why
- To keep the service secure, investigate abuse and show an audit trail of who did what.
- Basis
- Legitimate useLegal duty
- Kept for
- 12 months (security logs); 7 years (admin audit log)
Data we don’t collect: no biometrics, no precise location, no contacts from your phone, no browsing history across other sites.
Our lawful basis
Under the DPDP Act we process personal data either with your consent (section 6) or for a legitimate use listed in section 7 — for example when you voluntarily give us data for a specific purpose, or where the law requires it. Under the GDPR the matching bases are consent (Art. 6(1)(a)), performance of a contract with you (6(1)(b)), a legal obligation (6(1)(c)) and our legitimate interests in running a secure service (6(1)(f)).
- Consent is explicit and unbundled. The box is never pre-ticked; we record the version you agreed to, when, and the IP it came from; and you can withdraw as easily as you gave it.
- Withdrawal is honoured going forward. Processing that already happened lawfully stays lawful, but we stop, and we delete what we no longer need.
- Optional means optional. Fields marked optional improve matching but are never required to use the service.
How verification works
“Verified by Ascend” is earned, not bought. When a founder submits a company profile, a member of our super-admin team runs a lookup against the Ministry of Corporate Affairs (MCA) register using the CIN you provide, and compares the registered name, status and directors with what you told us. Where a DPIIT recognition number is supplied, its format and validity are checked as well.
- The lookup sends only the CIN to the MCA service; it does not send your PAN or financials.
- The admin console is IP-restricted and every decision (approve, return, reject, feature) is written to an audit log with the admin’s identity and a timestamp.
- Verification is a good-faith identity check. It is not an audit of your accounts or an endorsement — see Terms — Verification.
What is never public
Your public profile contains only the sections you choose to publish. The following are never shown on a public page, never indexed, and never included in a data export to anyone but you:
- PAN and any tax identifier
- CIN and the raw MCA record (the public page shows only a “verified” mark)
- Financials: turnover, funding history, cap table, cheque size
- Mobile number and email address
The double-blind introduction
Interest is expressed privately. Before any introduction the other side may see that interest has been expressed, but only as an anonymised card — never your name, and never your contact details. Only when both a founder and an investor (or mentor) say yes does Ascend introduce them, and only then are the private fields each side agreed to share revealed to the other. Either side can withdraw before the reveal, and a reveal is logged so you can always see who received what, and when.
How long we keep it
We keep personal data only for as long as the purpose needs it, then delete or irreversibly anonymise it. The standard periods are in the inventory above. Exceptions:
- Account deletion: the profile is unpublished immediately; personal data is erased within 30 days; backups roll off within a further 30 days.
- Inactivity: if you don’t sign in for 24 months we will write to you, then unpublish and delete the account if we hear nothing within 30 days.
- Legal holds: consent records, verification decisions and admin audit logs are kept 7 years because we may need to demonstrate them to a regulator or court.
How we protect it
We run the service to a SOC 2-style standard of controls and describe them plainly rather than promise perfection — no system is perfectly secure, and we would rather tell you exactly what we do.
- Passwordless sign-in: one-time codes expire quickly and are stored only as hashes.
- Everything travels over TLS; sensitive fields are encrypted at rest.
- Admin access is IP-restricted and every review decision is logged with who, what and when.
- How we protect your data
- In transit: TLS 1.2+ on every connection, including to our processors.
- At rest: encrypted storage; sensitive identifiers (PAN, CIN, financials) held in restricted fields with separate access control.
- Access: least-privilege roles; the admin console is IP-allow-listed; super-admin actions require an authenticated session and are audit-logged.
- Sign-in: passwordless OTP with rate limiting; codes are short-lived and stored only as hashes; you can sign out of every device from your account.
- Incident response: if a breach is likely to affect you we will notify you and the Data Protection Board of India (and, where the GDPR applies, the relevant supervisory authority within 72 hours) without undue delay.
Your rights — and how to use them
Whether you are in India, the EU/UK or elsewhere, we give everyone the same set of rights. Use the Data & privacy centre or email privacy@ascend.in. We acknowledge every request within 3 working days and aim to resolve it within 30 days.
- Access & portability
- Get a copy of the personal data we hold about you, in a machine-readable format, plus a summary of who it has been shared with (DPDP §11; GDPR Art. 15, 20).
- Correction
- Fix inaccurate or incomplete data. Most profile fields you can edit yourself; verified fields are corrected by our team after re-verification (DPDP §12; GDPR Art. 16).
- Erasure
- Delete your account and personal data, subject to the legal holds above (DPDP §12; GDPR Art. 17).
- Withdraw consent
- As easy as giving it. Withdrawal stops future processing based on consent; some features may stop working as a result (DPDP §6(4); GDPR Art. 7(3)).
- Object / restrict
- Where we rely on legitimate use or interests, object and we will stop unless we can show compelling grounds (GDPR Art. 18, 21).
- Nominate
- Under the DPDP Act you may nominate someone to exercise these rights if you are unable to (DPDP §14).
- Complain
- Raise a grievance with our grievance officer first; if unresolved, with the Data Protection Board of India or your local supervisory authority.
We will never charge for a request unless it is manifestly excessive, and we will always verify it is really you — usually by sending a one-time code to the mobile number or email on the account.
Grievance officer & data protection contact
Section 8(9) of the DPDP Act, read with Rule 9 of the DPDP Rules, requires us to publish the business contact information of someone who can answer your questions about your personal data on our behalf, and section 13 gives you the right to a readily available way to complain. Here is how to reach that person.
- Grievance contact
- Office of the Grievance Officer, Ascend
- privacy@ascend.in
- Postal address
- Will be published here once the registered office is filed. Email reaches the same desk in the meantime.
- Response time
- Acknowledgement within 3 working days; resolution within 30 days (statutory maximum: the period prescribed under the DPDP Rules — currently up to 90 days for grievances).
If we have not resolved your grievance, you may complain to the Data Protection Board of India under section 13(3) of the DPDP Act, or — if you are in the EU or UK — to your local supervisory authority. We have not been notified as a Significant Data Fiduciary, so no Data Protection Officer is appointed under section 10; if that changes, this section will name one.
International transfers
Ascend is built for India and our primary storage is in India. Some processors (for example email delivery or cloud regions) may process data outside India. Where that happens we rely on the transfer rules under the DPDP Act and, for people in the EU/UK, on adequacy decisions or Standard Contractual Clauses with the processor. Ask us for a list of locations at any time.
Age
Ascend is a professional service for adults. You must be 18 or older to create an account. We do not knowingly collect data from anyone under 18; if you believe we have, tell us and we will delete it.
Changes to this notice
When we change this notice materially we will update the version and date at the top, email account holders before the change takes effect, and — where the change needs new consent — ask for it again rather than assume it. Older versions are available on request.