How CapHive Private Limited handles personal data — on this website, in our marketing, and inside the platform we operate for our clients.
Last updated — [Month DD, YYYY]
Template — pending legal review. This document is a working template. It has not been reviewed or approved by counsel and does not yet reflect a legal opinion on CapHive's obligations. Every item shown in square brackets — for example [CIN], [grievance officer name] or [retention period] — is a placeholder that must be completed before publication. Do not rely on this page.
This policy is issued by CapHive Private Limited ("CapHive", "we", "us"), a company incorporated in India with registered office at 801, One International Center, Tower 1, Senapati Bapat Marg, Lower Parel, Mumbai 400013. Our corporate identity number is [CIN].
This policy explains how we handle personal data in three situations:
This policy does not cover websites operated by other organisations that we link to. It also does not override any data processing agreement or master services agreement signed between CapHive and a client. Where a signed agreement says something different about client data, that agreement applies.
This distinction matters, because it decides who you should approach about your data and who is accountable for it.
For this website, our marketing, our events, our recruitment and our own business administration, CapHive decides why and how personal data is used. In that role we are the controller (in Indian law, the "data fiduciary"). Examples: a demo request form, a newsletter subscription, a job application, or analytics about how this website is used. If you want to exercise rights over that data, contact us directly using section 13.
For the fund, portfolio, deal and investor data that our clients load into the platform, the client — the fund manager, general partner, family office or fund administrator — decides why and how that data is used. CapHive acts on the client's documented instructions and is a processor (in Indian law, a "data processor" acting for the client as data fiduciary).
In that role we do not decide what investor data is collected, we do not use it for our own purposes, and we do not sell it. We do not use client data to train general-purpose artificial intelligence models. Where the platform's AI agents analyse client data, they do so within that client's environment and on that client's instructions.
If you are an investor, limited partner or portfolio company contact and your data is in the platform, the organisation that invited you is the controller. Please direct requests about that data to them. If you send such a request to us, we will refer it to the relevant client and, where the contract requires, help them respond.
On behalf of our clients, the platform may hold personal data about investors, their authorised representatives, portfolio company contacts and transaction counterparties. Depending on what the client configures, this can include:
Some of this data is sensitive, and identity documents may contain government-issued identifiers. We hold it only because a client has instructed us to, and only for as long as their instructions and contract allow.
The table below sets out, for the data we handle as controller, what we use it for and the legal basis we rely on. Where we act as processor, the client's legal basis applies and the client is responsible for establishing it.
| Data category | Purpose | Legal basis (controller) |
|---|---|---|
| Technical and cookie data | Operating and securing the website; measuring and improving it | Legitimate interests; consent where the cookie is not strictly necessary |
| Identity and contact data of prospects | Responding to enquiries and demo requests; arranging meetings | Legitimate interests; steps towards entering a contract |
| Enquiry and communication records | Managing the sales relationship; keeping a record of what was agreed | Legitimate interests |
| Marketing engagement data | Sending relevant updates, insights and event invitations | Consent, or legitimate interests where permitted by local law |
| Platform account and authentication data | Creating accounts, authenticating users, administering access | Performance of a contract; legitimate interests in security |
| Audit and usage logs | Security monitoring, fraud prevention, incident investigation, service reliability | Legitimate interests; legal obligation |
| Support data | Providing technical support and resolving issues | Performance of a contract |
| Billing and supplier data | Invoicing, accounting, tax and statutory records | Legal obligation; performance of a contract |
| Recruitment data | Assessing applications for roles at CapHive | Consent; steps towards entering a contract |
| Investor, KYC and transaction data | Providing the platform to the client that holds the data | Processed on the client's instructions — the client determines the basis |
We do not use automated decision-making that produces legal effects for you without human involvement. Platform features that analyse data, including AI agents, produce outputs for review by the client's own staff.
We do not sell personal data. We share it only in the following ways.
Our current sub-processors are:
| Sub-processor | Service provided | Location |
|---|---|---|
| [Sub-processor name] | [Cloud hosting and storage] | [Country / region] |
| [Sub-processor name] | [Transactional email delivery] | [Country / region] |
| [Sub-processor name] | [Electronic signature] | [Country / region] |
| [Sub-processor name] | [KYC and screening] | [Country / region] |
| [Sub-processor name] | [Product analytics and error monitoring] | [Country / region] |
| [Sub-processor name] | [Customer support and ticketing] | [Country / region] |
Clients who have signed a data processing agreement with us receive advance notice of changes to this list in accordance with that agreement, with a notice period of [notice period].
CapHive is based in India and serves clients with fund structures in India and other jurisdictions. Personal data may therefore be transferred to, stored in or accessed from countries other than the one you are in, including [list of countries].
Where we transfer personal data across borders, we rely on the following safeguards:
Where we act as processor, hosting location is a matter for the client's configuration and contract. Clients may request details of where their data is stored.
We keep personal data only as long as we need it for the purposes in section 4, or as long as the law requires.
For client data held under our processor role, retention is set by the client's instructions and their own regulatory obligations, which for KYC records are often long. On termination we return or delete client data in line with the signed agreement, within [period], except where we must keep a copy by law. Backups are overwritten on a rolling cycle of [period].
We apply technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure and loss. These include encryption in transit and at rest, role-based access control, single sign-on and multi-factor authentication, audit logging, environment separation, and background checks and training for our staff.
Our controls, hosting arrangements and certifications are described in more detail on our Security & Trust page. No system can be guaranteed to be completely secure. If a personal data breach occurs, we will notify the relevant authority and affected persons where the law requires it, and — where we act as processor — notify the client without undue delay so they can meet their own obligations.
Subject to the law that applies to you, you may have the right to ask us to give you access to your personal data, correct it, complete it, update it, erase it, restrict how we use it, provide it in a portable form, or stop using it for direct marketing. You may also withdraw consent where we relied on consent, and object where we relied on legitimate interests.
To make a request, write to hello@caphive.com with enough detail for us to identify you. We do not charge for a first request. We will respond within the period the applicable law allows, and in any event within [number] days. We may ask you to verify your identity before we act. If your data is in the platform under a client's control, we will pass the request to that client.
Under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 and rules made under it, you may contact our grievance officer:
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
Where the GDPR or UK GDPR applies to our processing, you also have the right to lodge a complaint with your local supervisory authority. Our Data Protection Officer, where one is appointed, is [Data Protection Officer name and contact]. Our representative in the European Union or United Kingdom, where one is required, is [EU/UK representative name and address].
We use cookies and similar technologies on this website to keep it working, remember your preferences and, where you allow it, to analyse how the site is used. What we set, why, and how to control it is set out in our Cookie Policy.
CapHive sells to institutions. This website and the platform are not directed at children, and we do not knowingly collect personal data from anyone under the age of 18. If you believe a child has provided us with personal data, write to hello@caphive.com and we will delete it. Where a client's investor records include data about a minor — for example a beneficiary — that data is processed on the client's instructions and the client is responsible for obtaining any consent required.
We may update this policy to reflect changes in our services, our suppliers or the law. When we do, we will change the "last updated" date at the top of this page. If the change is significant, we will give notice by email or through the platform before it takes effect, at least [notice period] in advance where the law or a contract requires it. Earlier versions are available on request.
For any question about this policy or about how we handle personal data:
You can also reach us through our contact page. Please see our Terms of Service for the terms that govern use of this website.