Privacy policy
This policy explains what personal data we process, why we process it, and the rights available to you. Designed to align with India DPDP Act 2023 and EU GDPR principles.
Last updated: June 2025
Draft notice
This policy is an engineering draft aligned with our internal data-protection documentation. Final lawful bases, notices, and cross-border transfer mechanisms require counsel sign-off before production launch.
1. Who we are
Gennii Technologies Pvt. Ltd. ("Gennii", "we", "us") operates Gennii LaunchPad — a regulated platform for tokenized securities. For data-protection enquiries contact privacy@gennii.example.
2. Scope
This policy applies to personal data processed through:
- The investor web application (apps/web)
- Our API and authentication services
- Email and notification channels
- KYC and screening integrations operated on our behalf
On-chain data (wallet addresses, transaction hashes) is public by nature and generally cannot be erased from the blockchain.
3. Data we collect
- Account data — email address, password hash, role, two-factor authentication configuration.
- Identity & compliance — KYC verification status, tier, country, accreditation flag, and provider reference (not raw ID documents unless required by law).
- Screening — sanctions, PEP, and watchlist results.
- Wallet data — linked wallet addresses and link timestamps.
- Usage & technical — IP address, device/browser type, session logs (PII-scrubbed after retention period).
- Communications — support correspondence and notification delivery status.
4. How we use your data
- Provide and secure your account and platform access.
- Verify identity, eligibility, and ongoing AML compliance.
- Process subscriptions, allocations, vesting, and claims.
- Send transactional and service-related communications.
- Maintain audit logs and investigate fraud or abuse.
- Comply with legal and regulatory obligations.
5. Lawful bases
Depending on context and jurisdiction, we rely on contract performance, legal obligation (AML/KYC recordkeeping), legitimate interests (security, fraud prevention), and — where required — consent. Final lawful bases will be confirmed with counsel for each target market.
6. Processors & sharing
We share data with service providers who process it on our instructions:
- Identity verification (e.g. Sumsub)
- Sanctions / blockchain screening providers
- Email delivery providers
- Cloud infrastructure and database hosting
We do not sell your personal data. We may disclose data when required by law, court order, or to protect rights, safety, and platform integrity.
7. Retention
- Unverified inactive accounts — up to 12 months from last login.
- Verified investor records — life of account plus up to 7 years after closure (AML recordkeeping — confirm with counsel).
- Session and nonce tokens — minutes to hours (automatic expiry).
- Audit logs — minimum 7 years.
- Application logs — 90 days, PII-scrubbed.
Deletion may be suspended during legal hold (litigation, regulatory inquiry, or fraud investigation).
8. Security
We implement encryption at rest and in transit, role-based access controls, mandatory 2FA for privileged accounts, append-only audit logging, and regular security reviews. No method of transmission or storage is 100% secure; report concerns to security@gennii.example.
9. International transfers
Data may be processed in India and other jurisdictions where our processors operate. Cross-border transfers use appropriate safeguards (standard contractual clauses or equivalent mechanisms) as required by applicable law.
10. Your rights
Subject to applicable law, you may request:
- Access to personal data we hold about you
- Correction of inaccurate data
- Erasure (where not overridden by legal retention)
- Restriction or objection to certain processing
- Data portability in a machine-readable format
- Withdrawal of consent where processing is consent-based
Submit requests to privacy@gennii.example. We respond within statutory timeframes (typically 30 days). You may also lodge a complaint with your local data-protection authority.
11. Cookies & analytics
We use essential cookies for authentication and security. Optional analytics cookies, if enabled, will be disclosed in a separate cookie notice with consent controls where required.
12. Children
The Platform is not directed at individuals under 18. We do not knowingly collect data from children.
13. Changes
We may update this policy when our processing changes. Material updates will be communicated via email or a notice on the Platform.
14. Contact
Data Protection Officer (to be appointed): privacy@gennii.example. See also our Contact page.