Privacy Policy
This Privacy Policy describes how Velthian.com collects, uses, stores, and protects personal data you provide when you use our platform. We are committed to your privacy in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act), the Information Technology Act, 2000, and the IT (Reasonable Security Practices and Sensitive Personal Data) Rules, 2011.
By using our Service you consent to the collection and use of your information as described here. If you do not agree, please discontinue use of the platform.
1. What Data We Collect
- Account data: Name, email address, and password (stored hashed — never in plain text)
- Financial tracking data: Investment details you enter manually — asset names, quantities, purchase prices, dates — used solely to power your personal dashboard
- Usage and log data: IP address, browser type, device information, pages visited, and timestamps — collected automatically for security and performance
- Cookies: Session cookies required for authentication; optional preference cookies to remember your display settings
We do not collect Aadhaar numbers, PAN numbers, payment card details, or any government-issued ID unless a specific feature requires it — in which case you will be separately informed and asked for explicit consent.
2. How We Use Your Data
- Provide and operate the platform features you use
- Authenticate your identity and maintain session security
- Respond to your support requests or queries
- Detect and prevent fraud or unauthorised access
- Improve platform performance using aggregated, anonymised data
3. Legal Basis for Processing
Under the DPDP Act, 2023, we process your personal data based on:
- Consent: You provide consent when you register and accept this policy
- Legitimate use: Fraud prevention, security, and ensuring platform integrity
- Legal obligation: Where required to comply with applicable Indian law or a court order
You may withdraw consent at any time by deleting your account or contacting us.
4. Cookies
We use session cookies to keep you logged in during your visit — these are deleted when you close your browser. We may also use functional cookies to remember display preferences. We do not use advertising cookies or share cookie data with ad networks. You can disable cookies in your browser settings, but this will prevent login from functioning.
5. Data Storage and Security
Your data is stored on servers located in India or in jurisdictions with adequate data protection standards. Security measures include:
- Encrypted passwords (one-way hashing)
- HTTPS encryption for all data in transit
- Access controls limiting team visibility of your data
- Regular security reviews
No method of internet transmission or electronic storage is completely secure. We cannot guarantee absolute security. In the event of a breach likely to cause harm, we will notify you as required by law.
6. Service Providers
We may share limited data with trusted third-party service providers (e.g. cloud hosting, email delivery) strictly to operate the platform. These providers are given only the data necessary for their function, are contractually obligated to protect it, and are not permitted to sell or disclose it to any other party.
7. Data Retention
We retain your data for as long as your account is active. If you request account deletion, we will delete your personal data within 30 days, except where we are required to retain it under applicable law (e.g. for tax or audit purposes).
8. Links to Other Websites
Our platform may contain links to external websites governed by their own privacy policies. We are not responsible for the content or data practices of third-party sites. We strongly encourage you to review their policies before sharing any information.
9. Your Rights as a Data Principal
Under the DPDP Act, 2023, you have the right to:
- Access: Request a summary of personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Erasure: Request deletion of your personal data, subject to legal retention requirements
- Grievance redressal: Raise a complaint with our Grievance Officer (see below)
- Withdraw consent: At any time; this does not affect the lawfulness of prior processing
- Nominate: Designate another individual to exercise your rights in the event of your death or incapacity
Write to privacy@velthian.com to exercise any of these rights. We will respond within 30 days.
10. Children's Privacy
Our Service is not directed at individuals under 18. We do not knowingly collect personal data from minors. If we become aware that a minor has provided data without parental consent, we will delete it promptly. If you believe this has occurred, please contact us immediately.
11. Changes to This Policy
We may update this policy from time to time. Material changes will be notified via email or a prominent notice on the platform before they take effect. The "Last updated" date at the top reflects the most recent revision. Continued use of the platform after changes constitutes acceptance of the revised policy.
12. Grievance Officer
In accordance with the IT Act, 2000 and the DPDP Act, 2023, you may direct any grievances or complaints to our Grievance Officer:
Richa Samant
Head of Operations & Compliance, Velthian.com
Email: richa@velthian.com
Response time: Within 30 days of receipt
If unsatisfied with our response, you may escalate to the Data Protection Board of India once constituted under the DPDP Act, 2023.