Home
Who We Serve
About Contact Setup a Demo
Legal

Privacy Policy

How CapHive Private Limited handles personal data — on this website, in our marketing, and inside the platform we operate for our clients.

Last updated — [Month DD, YYYY]

Template — pending legal review. This document is a working template. It has not been reviewed or approved by counsel and does not yet reflect a legal opinion on CapHive's obligations. Every item shown in square brackets — for example [CIN], [grievance officer name] or [retention period] — is a placeholder that must be completed before publication. Do not rely on this page.

1. Who we are and what this policy covers

This policy is issued by CapHive Private Limited ("CapHive", "we", "us"), a company incorporated in India with registered office at 801, One International Center, Tower 1, Senapati Bapat Marg, Lower Parel, Mumbai 400013. Our corporate identity number is [CIN].

This policy explains how we handle personal data in three situations:

  • when you visit caphive.com or contact us through this website;
  • when you receive marketing or event communications from us, or evaluate the platform; and
  • when our clients use the CapHive platform and we process data on their instructions.

This policy does not cover websites operated by other organisations that we link to. It also does not override any data processing agreement or master services agreement signed between CapHive and a client. Where a signed agreement says something different about client data, that agreement applies.

2. The two roles we play

This distinction matters, because it decides who you should approach about your data and who is accountable for it.

2.1 CapHive as controller

For this website, our marketing, our events, our recruitment and our own business administration, CapHive decides why and how personal data is used. In that role we are the controller (in Indian law, the "data fiduciary"). Examples: a demo request form, a newsletter subscription, a job application, or analytics about how this website is used. If you want to exercise rights over that data, contact us directly using section 13.

2.2 CapHive as processor

For the fund, portfolio, deal and investor data that our clients load into the platform, the client — the fund manager, general partner, family office or fund administrator — decides why and how that data is used. CapHive acts on the client's documented instructions and is a processor (in Indian law, a "data processor" acting for the client as data fiduciary).

In that role we do not decide what investor data is collected, we do not use it for our own purposes, and we do not sell it. We do not use client data to train general-purpose artificial intelligence models. Where the platform's AI agents analyse client data, they do so within that client's environment and on that client's instructions.

If you are an investor, limited partner or portfolio company contact and your data is in the platform, the organisation that invited you is the controller. Please direct requests about that data to them. If you send such a request to us, we will refer it to the relevant client and, where the contract requires, help them respond.

3. Personal data we collect

3.1 Website visitors

  • Technical data: IP address, browser and device type, operating system, referring page, pages viewed and time spent.
  • Cookie and similar identifiers, as described in our Cookie Policy.

3.2 Prospects and other business contacts

  • Identity and contact data: name, work email address, telephone number, job title, organisation.
  • Enquiry content: what you asked us, which products you were interested in, meeting notes.
  • Communication records: emails, call records and marketing engagement such as whether a message was opened.
  • Demo request details: when you submit the form on this site we record what you typed, the page you submitted it from, and any campaign parameters in the link that brought you here. We also record your IP address and browser identifier — those two solely to detect and block automated abuse of the form, and they are deleted on the shorter clock set out in section 7.

3.3 Platform users

  • Account data: name, work email address, role and permissions, organisation.
  • Authentication data: hashed credentials, single sign-on identifiers, multi-factor authentication settings.
  • Audit and usage logs: sign-in events, IP address, actions taken in the application.
  • Support data: tickets, correspondence and, where you provide it, screenshots or files.

3.4 Investor and portfolio data processed for clients

On behalf of our clients, the platform may hold personal data about investors, their authorised representatives, portfolio company contacts and transaction counterparties. Depending on what the client configures, this can include:

  • identity and contact details, and details of the investing entity;
  • commitment, drawdown, distribution and holding records;
  • bank account and payment reference details;
  • tax identifiers and tax residency information;
  • KYC and anti-money-laundering documentation, including identity documents, proof of address, source-of-funds information and screening results; and
  • signed subscription documents and other executed agreements.

Some of this data is sensitive, and identity documents may contain government-issued identifiers. We hold it only because a client has instructed us to, and only for as long as their instructions and contract allow.

4. How we use personal data and our legal bases

The table below sets out, for the data we handle as controller, what we use it for and the legal basis we rely on. Where we act as processor, the client's legal basis applies and the client is responsible for establishing it.

Data categoryPurposeLegal basis (controller)
Technical and cookie dataOperating and securing the website; measuring and improving itLegitimate interests; consent where the cookie is not strictly necessary
Identity and contact data of prospectsResponding to enquiries and demo requests; arranging meetingsLegitimate interests; steps towards entering a contract
Enquiry and communication recordsManaging the sales relationship; keeping a record of what was agreedLegitimate interests
Marketing engagement dataSending relevant updates, insights and event invitationsConsent, or legitimate interests where permitted by local law
Platform account and authentication dataCreating accounts, authenticating users, administering accessPerformance of a contract; legitimate interests in security
Audit and usage logsSecurity monitoring, fraud prevention, incident investigation, service reliabilityLegitimate interests; legal obligation
Support dataProviding technical support and resolving issuesPerformance of a contract
Billing and supplier dataInvoicing, accounting, tax and statutory recordsLegal obligation; performance of a contract
Recruitment dataAssessing applications for roles at CapHiveConsent; steps towards entering a contract
Investor, KYC and transaction dataProviding the platform to the client that holds the dataProcessed on the client's instructions — the client determines the basis

We do not use automated decision-making that produces legal effects for you without human involvement. Platform features that analyse data, including AI agents, produce outputs for review by the client's own staff.

5. Sharing and sub-processors

We do not sell personal data. We share it only in the following ways.

  • Service providers. We use third parties to host, secure, monitor and support the platform and our own operations. They act on our instructions and are bound by written contracts.
  • Client-directed recipients. Where we act as processor, we transmit data to recipients the client configures — for example an e-signature provider, a bank, a custodian, a KYC screening service or the client's auditors.
  • Professional advisers. Our lawyers, auditors, insurers and accountants, where they need the data to advise us.
  • Authorities. Where disclosure is required by law, by a court order, or by a regulator with jurisdiction over us. Where we act as processor and the law allows, we will notify the client before disclosing their data.
  • Corporate transactions. A prospective buyer or investor in a reorganisation, merger or sale, under confidentiality obligations.

Our current sub-processors are:

Sub-processorService providedLocation
[Sub-processor name][Cloud hosting and storage][Country / region]
[Sub-processor name][Transactional email delivery][Country / region]
[Sub-processor name][Electronic signature][Country / region]
[Sub-processor name][KYC and screening][Country / region]
[Sub-processor name][Product analytics and error monitoring][Country / region]
[Sub-processor name][Customer support and ticketing][Country / region]

Clients who have signed a data processing agreement with us receive advance notice of changes to this list in accordance with that agreement, with a notice period of [notice period].

6. International transfers

CapHive is based in India and serves clients with fund structures in India and other jurisdictions. Personal data may therefore be transferred to, stored in or accessed from countries other than the one you are in, including [list of countries].

Where we transfer personal data across borders, we rely on the following safeguards:

  • for transfers out of India, compliance with the restrictions and any government notifications issued under the Digital Personal Data Protection Act, 2023;
  • for transfers out of the European Economic Area, the United Kingdom or Switzerland, the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another mechanism recognised under Article 46 of the GDPR, together with a transfer risk assessment; and
  • [any additional mechanism or certification relied on].

Where we act as processor, hosting location is a matter for the client's configuration and contract. Clients may request details of where their data is stored.

7. How long we keep personal data

We keep personal data only as long as we need it for the purposes in section 4, or as long as the law requires.

  • Website and analytics data — [retention period].
  • Demo request form submissions — 24 months after the last meaningful interaction. The IP address and browser identifier collected with a submission are kept for 90 days and then permanently erased from the record, because they serve only to detect abuse of the form; the rest of your enquiry is retained for the period above.
  • Prospect and marketing records — [retention period] after the last meaningful interaction.
  • Platform account records — for the term of the client's agreement, then [retention period].
  • Audit and security logs — [retention period].
  • Support tickets — [retention period].
  • Billing, tax and statutory records — [retention period, per applicable statutory minimum].
  • Recruitment records — [retention period] after the process closes.

For client data held under our processor role, retention is set by the client's instructions and their own regulatory obligations, which for KYC records are often long. On termination we return or delete client data in line with the signed agreement, within [period], except where we must keep a copy by law. Backups are overwritten on a rolling cycle of [period].

8. Security

We apply technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure and loss. These include encryption in transit and at rest, role-based access control, single sign-on and multi-factor authentication, audit logging, environment separation, and background checks and training for our staff.

Our controls, hosting arrangements and certifications are described in more detail on our Security & Trust page. No system can be guaranteed to be completely secure. If a personal data breach occurs, we will notify the relevant authority and affected persons where the law requires it, and — where we act as processor — notify the client without undue delay so they can meet their own obligations.

9. Your rights and how to exercise them

Subject to the law that applies to you, you may have the right to ask us to give you access to your personal data, correct it, complete it, update it, erase it, restrict how we use it, provide it in a portable form, or stop using it for direct marketing. You may also withdraw consent where we relied on consent, and object where we relied on legitimate interests.

To make a request, write to hello@caphive.com with enough detail for us to identify you. We do not charge for a first request. We will respond within the period the applicable law allows, and in any event within [number] days. We may ask you to verify your identity before we act. If your data is in the platform under a client's control, we will pass the request to that client.

9.1 Grievance officer — India

Under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made under it, you may contact our grievance officer:

  • Name: [grievance officer name]
  • Designation: [designation]
  • Email: [grievance officer email]
  • Postal address: 801, One International Center, Tower 1, Senapati Bapat Marg, Lower Parel, Mumbai 400013
  • Response time: within [number] days of receipt

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

9.2 Rights under the GDPR and UK GDPR

Where the GDPR or UK GDPR applies to our processing, you also have the right to lodge a complaint with your local supervisory authority. Our Data Protection Officer, where one is appointed, is [Data Protection Officer name and contact]. Our representative in the European Union or United Kingdom, where one is required, is [EU/UK representative name and address].

10. Cookies and similar technologies

We use cookies and similar technologies on this website to keep it working, remember your preferences and, where you allow it, to analyse how the site is used. What we set, why, and how to control it is set out in our Cookie Policy.

11. Children's data

CapHive sells to institutions. This website and the platform are not directed at children, and we do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, write to hello@caphive.com and we will delete it. Where a client's investor records include data about a minor — for example a beneficiary — that data is processed on the client's instructions and the client is responsible for obtaining any consent required.

12. Changes to this policy

We may update this policy to reflect changes in our services, our suppliers or the law. When we do, we will change the "last updated" date at the top of this page. If the change is significant, we will give notice by email or through the platform before it takes effect, at least [notice period] in advance where the law or a contract requires it. Earlier versions are available on request.

13. How to contact us

For any question about this policy or about how we handle personal data:

  • Email: hello@caphive.com
  • Post: CapHive Private Limited, 801, One International Center, Tower 1, Senapati Bapat Marg, Lower Parel, Mumbai 400013, India

You can also reach us through our contact page. Please see our Terms of Service for the terms that govern use of this website.