← Back to CapitalSync

Privacy Policy

Last updated: 6 August 2026 · CapitalSync Genesis LLP

1. What we collect

  • Account data — name, email, phone/WhatsApp number, business name, password (stored as a secure hash).
  • Business data — company details, financial documents, and other files you choose to upload.
  • Usage data — pages visited, features used, device and log information.
  • Payment data — processed by our payment providers (Razorpay, Lemon Squeezy); we do not store full card numbers.
  • Communications data — a record of emails and WhatsApp messages we send you and, where a channel supports it, delivery/open status. This lets our team see your communication history with us in one place.

2. Why we use it

  • To provide the service: business scoring, document preparation, investor matching, scheme matching.
  • AI processing: your documents are analysed to generate advice and materials for you. They are not used to train public AI models.
  • To contact you about your account, deals, and service updates.
  • To meet legal obligations, including KYC/AML checks where required.

3. AI processing, automated decisions, and AI agents that take action

This section exists because CapitalSync uses AI more directly than most platforms — for drafting, for scoring, and in a small number of cases, for taking real actions on your behalf. We think you should know exactly where, not just that "AI is used."

  • Who processes your content. Documents, messages, and business data you submit for AI analysis are sent to Anthropic (maker of the Claude models) to generate the output you asked for — a score, a draft, an answer. Some AI-generated speech/video/translation features additionally use ElevenLabs (voice), Sarvam AI (Indian-language translation and speech), and HeyGen (avatar video), only when you or your workflow actually uses those features. None of these providers use your data to train their own public models — CapitalSync's agreements with them are on that basis, and we do not opt you into anything different.
  • Automated scoring and decisions. The PERSIST Score and similar readiness/prioritisation scores are computed by an AI model from your business data, without a human reviewing every individual score before it's shown to you. It is an assessment, not a final decision about your access to funding, and it is never the sole basis for an investor's decision — investors make their own call. You can ask a human team member to review any score CapitalSync itself computed about you, at the contact below.
  • AI agents that take real actions. A small number of features go beyond generating text — for example, our Sales Autopilot feature can draft and send an outreach email to a prospective business on CapitalSync's behalf. Any such consequential, outward-facing action requires a human team member's explicit approval before it happens — the AI drafts, a person decides whether to send. We keep a real, auditable record of every step an AI agent takes and of the human approval behind any action that reaches a real person, so this isn't just a policy promise.
  • Your right to a human. If an automated score or AI-drafted output affects you and you'd like a person to look at it, email us at the address in Section 7 and say so — we will have a human team member review it.

4. Who we share it with

  • Investors — only the materials you approve for sharing, only after you ask for an introduction.
  • Service providers — hosting (Vercel, Railway), database (Supabase), payments (Razorpay, Lemon Squeezy), AI processing (Anthropic, and ElevenLabs/Sarvam AI/HeyGen where those specific features are used), communication (Resend for email, WhatsApp Business via WATI), security scanning (VirusTotal, for files you upload). Each is bound by its own security and data-processing commitments, and none may use your data for their own purposes beyond providing the service to us.
  • Authorities — where the law requires it.
  • We do not sell your personal data.

5. Where it lives and how it's protected

Data is stored in our database hosted in the Asia-Pacific region (Singapore), encrypted in transit (TLS 1.2+) and at rest (AES-256). Access inside our systems is controlled with row-level security so each tenant can only reach its own records. Files you upload are checked for known malicious content before storage; this is a real security check, not a guarantee that every possible threat is caught.

6. How long we keep it

Account and business data is kept while your account is active. After closure, we delete or anonymise personal data within 90 days, except records we must retain for legal, tax, or compliance reasons.

7. Your rights

  • Access, correct, or export the data we hold about you.
  • Delete your account and associated personal data.
  • Withdraw consent for optional processing at any time.
  • Request human review of an automated score or AI-drafted output about you (Section 3).
  • Complain to your local data protection authority (in India, under the DPDP Act 2023; in the EU/UK, under GDPR).

To exercise any right, email jai@capitalsync.net. We respond within 30 days.

8. Cookies and consent

We use essential cookies/local storage for login sessions and a consent banner for document processing. We do not run third-party advertising trackers.

9. Children

The platform is for businesses and is not directed at anyone under 18.

10. Changes

If we make material changes to this policy, we will notify you by email or an in-app notice before they take effect.

This document is a plain-language summary prepared for usability. It should be reviewed by qualified legal counsel to confirm compliance with the DPDP Act 2023, GDPR, and other applicable regulations.