Legal
Privacy Policy
Every personal detail we hold has a reason for being held, a lawful basis, and an end date. This page says what those are, and how to see or remove what is yours.
Last updated 21 August 2026
1Who is responsible for your data
SnxwFairies Innovations Private Limited, operating MSME Exchange, is the Data Fiduciary for the personal data described here, under the Digital Personal Data Protection Act 2023. You are the Data Principal.
Questions, requests and complaints about personal data go to our data-protection address — not yet published, for the attention of the person responsible for data protection — name — not yet published.
We have not been notified as a Significant Data Fiduciary and so are not required under §10 of the Act to appoint a Data Protection Officer. If that changes, this page will name the appointed officer.
2What we collect, and why each item exists
We collect less than a financial platform usually does, and every field below has a stated reason. Where a verification token or a result reference will do, we keep that instead of the underlying document.
| What | Why we need it |
|---|---|
| Name, email address, mobile number | To create and secure your account, and to reach you about your own activity. The email address is verified by a single-use link before the account can be used. |
| PAN | Statutory identification for an investment in securities, and to prevent the same person registering twice. Encrypted at rest. |
| Bank account details | So that an issuing company can identify a payment as yours, and so a repayment under Section 42(6) can reach you. Encrypted at rest. |
| Demat account number and depository participant | Securities are allotted into an account in your own name. Without this the company cannot allot to you. Encrypted at rest. |
| Identity and address documents | To meet the KYC obligation for an investor in a private placement. We prefer an offline verification result over a stored copy of a document wherever the source supports it. |
| Company information, filings, financial statements (for businesses) | To prepare and evidence a Section 42 placement, and to disclose verified facts to identified investors. |
| Verification results | Each records its source, the date obtained, what was returned, and when it stops being current. An audit asks what was known at the time, which a yes/no cannot answer. |
| Consent records | The purpose, the exact wording shown to you, the version, and the timestamp — so it is always answerable what you agreed to and when. |
| Activity and security logs | Sign-ins, approvals, transactions and compliance decisions, so that any significant action is reconstructable. Retained for the statutory record-keeping period. |
Aadhaar. We use Aadhaar-related data only where it is legally permitted and technically necessary, and our design uses offline verification rather than online Aadhaar authentication. We do not store an Aadhaar number where an offline verification result will serve.
We do not sell personal data, and we do not use it to build advertising profiles.
3The lawful basis
Most processing runs on your consent, taken for a stated purpose at the moment it becomes relevant, and recorded as described above. The rest runs on a legitimate use under §7 of the Act — chiefly compliance with a legal obligation, such as record retention under the Companies Act, or a check we are required to perform before an investment can proceed.
You can withdraw consent at any time. Withdrawal is as easy as giving it, and takes effect for the future; it does not undo processing already carried out, and it does not remove records the law requires us to keep. Withdrawing a consent that a check depends on will stop that part of the service working.
4Who else sees it
We share personal data only where the purpose requires it:
- With an issuing company, when you commit to its offer — because a private placement under Section 42 is made to identified persons, and the company must record who you are to allot to you and to file its return of allotment.
- With verification providers, to run a check you have consented to. Each provider receives only what that check needs, and the result comes back with its source and date attached.
- With professional reviewers — a chartered accountant, company secretary or compliance officer — where a check requires a qualified person to examine it.
- With infrastructure providers who host and secure the platform, under contract, and only as necessary to run it.
- Where the law requires it — a court order, a regulator, or a statutory authority acting within its powers.
Personal data processed for the platform is stored in India. Where a provider processes it elsewhere, that transfer is subject to §16 of the Act and to the restrictions the Government notifies.
5How long we keep it
Retention is set per category and applied on a schedule, not left to accumulate. Account and profile data is kept while your account is open. Records tied to an investment, a verification, a consent or a compliance decision are kept for the period the Companies Act and the record-keeping rules require, because they must remain explicable years later — a decision made under one year’s rules must still be reconstructable under the next.
When a retention period ends, the data is deleted or irreversibly anonymised. You can see the retention period for each category, in your own account, at Privacy & my data.
6How it is protected
PAN, bank account numbers and demat account numbers are encrypted at rest with AES-256-GCM. Because encryption would otherwise silently disable the duplicate and uniqueness checks that depend on those values, each is also stored as a keyed one-way index that permits a match without revealing the value.
Access is role-based and denied by default. Significant actions are written to an append-only audit record. We do not claim to be unbreachable, and we do not hold a security certification; what we can say is what the controls are and that they are enforced in the database rather than only in the application.
If a personal data breach occurs, we will notify the Data Protection Board and every affected Data Principal as §8(6) of the Act requires.
7Your rights, and where to exercise them
Under the DPDP Act you have the right to:
- Access — a summary of the personal data we hold and how it is processed;
- Correction and completion — of anything inaccurate or incomplete;
- Erasure — of data we no longer need and are not required to keep;
- Grievance redressal — an answer from us before you approach the Board;
- Nomination — to name a person to exercise these rights if you die or become incapable of exercising them.
You do not have to write to us to use most of these. Signed in, at Privacy & my data, you can see every category we hold, every consent you have given with the exact wording you were shown, every verification with its source and date — and request erasure. Before an erasure runs, the platform shows you what would be removed and what would not be, and why: telling you afterwards that your data is gone while an investment record still carries your name would be the worse failure.
If you cannot sign in — because the account has already been erased, because you never had one, or because you are acting for someone who has died — use the request form. We will write to the address the data is held under to confirm the request is yours before acting on it. That step is also what stops somebody else making a request in your name.
If you are not satisfied with our answer, our grievance process is the next step, and after that you may complain to the Data Protection Board of India.
8Cookies and similar technologies
We use only what the platform needs to work: a stored sign-in token to keep you authenticated, and preferences you set. We do not use advertising cookies and do not permit third-party tracking on the platform.
9Children
The platform is not for anyone under 18. We do not knowingly process the personal data of a child, and §9 of the Act prohibits tracking or behavioural advertising directed at children in any case. If you believe a child has registered, write to our data-protection address — not yet published and we will remove the account.
10Changes
If this policy changes materially, we will tell you in the platform and ask again for any consent that the change affects — a new purpose needs new consent, not a quiet edit to a page. The date at the top always reflects the current version.
11Contact
Data protection: our data-protection address — not yet published
SnxwFairies Innovations Private Limited, registered office address — not yet published