Privacy Policy
Last updated: 11 June 2026 · Drafted for the Digital Personal Data Protection Act, 2023 (DPDP)
1. Who we are
Vriddhix Quant Technologies (“Vriddhix”, “we”) is the data fiduciary for the personal data processed on this platform. All our data and infrastructure are hosted in India (AWS region ap-south-1, Mumbai, and Supabase’s Mumbai region).
2. What we collect
- Account data: email address and name (stored encrypted, AES-256-GCM), phone number (stored as a one-way hash only).
- KYC data (paid plans, where required): PAN is hashed immediately; the original PAN is never stored.
- Usage data: the strategies you create, backtests you run, and standard technical logs (IP address, timestamps) for security and rate limiting.
- Payment data: handled by our payment processor; we never store card numbers.
3. What we use it for
- Providing the service: running backtests, storing your strategies, showing your results.
- Security: authentication, session management, fraud and abuse prevention.
- Legal compliance: maintaining the audit trail required of us (retained 8 years), tax records.
- Service communication: transactional emails (results, billing). Marketing email only with consent, with one-click opt-out.
4. AI processing — no PII leaves India, none reaches the model
Your strategy descriptions are processed by an AI model (Anthropic Claude) to build strategy configurations. We send only the strategy text and an anonymised identifier (a one-way hash) — never your name, email, phone or PAN.
5. Who we share with
Processors under contract, limited to what the service needs: cloud hosting (AWS India, Supabase), the AI provider above, our market-data vendor, and our payment processor. We do not sell personal data, ever.
6. Your rights (DPDP Act, 2023)
- Access a summary of your personal data and how it is processed.
- Correct or complete your data.
- Erase your data, where we are not legally required to retain it (the statutory audit trail and tax records survive erasure for their retention period).
- Withdraw consent at any time, as easily as you gave it.
- Nominate another person to exercise these rights for you.
- Escalate to the Data Protection Board of India if unsatisfied with our response.
7. Retention
- Account and strategy data: while your account is active, then deleted within 90 days of account closure.
- Compliance audit trail: 8 years (regulatory requirement), in immutable storage.
- Security logs: 12 months.
8. Cookies
We use strictly necessary cookies for login sessions. No third-party advertising trackers.
9. Grievance officer
Grievance Officer, Vriddhix Quant Technologies — privacy@vriddhix.example. We acknowledge complaints within 72 hours and resolve them within the timelines prescribed under the DPDP Act.