This policy explains what personal data startuperr collects, why we collect it, how we use it, and what rights you have over it. If you are a tenant using startuperr to manage your own customers' data, Section 10 explains your responsibilities as a Data Fiduciary under the DPDP Act 2023.
Who we are
startuperr is a multi-tenant SaaS platform that provides startup operations tools — including CRM, HR, compliance, legal, and AI — to founders and small teams. References to "startuperr", "we", "us", or "our" in this policy refer to the company operating the startuperr platform.
We act as the Data Fiduciary for data collected from our registered users and platform visitors. For data that our tenants (customers) collect through startuperr — for example, their own customers' contact details entered into the People CRM — we act as the Data Processor, and the tenant is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act).
What we collect
We collect two broad categories of data: data you give us directly, and data generated by your use of the platform.
| Data type | Examples | How collected |
|---|---|---|
| Account data | Name, email address, password hash, organisation name | Registration form |
| Profile data | Role, entity type, legal details, director information | Tenant profile setup |
| CRM data | Contact names, phone numbers, emails, notes, conversation logs | Manual entry or CSV import |
| HR data | Job applicant details, resume files, application responses | Job portal applications |
| Form responses | Consent records, form field answers, purpose acknowledgements | Public forms |
| Resolution data | Director names, official emails, signatures, signed documents | Resolution module |
| Voice input | Audio recordings provided when using voice queries in the AI assistant | CoS AI voice feature |
| Usage data | Pages visited, actions taken, timestamps, IP address, browser type | Automatically via server logs |
| Lead ads data | Leads from connected Facebook/Instagram pages via Meta Graph API | Meta Lead Ads integration |
We do not collect payment card details (handled by our payment processors), government identity numbers unless you provide them voluntarily for legal documents, or sensitive personal data beyond what is strictly necessary to deliver the platform.
How we use your data
We use the data we collect only for the purposes listed below. We do not sell your data. We do not use it for advertising.
- To create and manage your account and tenant workspace
- To provide and operate all platform modules (CRM, HR, Forms, Resolutions, Workday, CoS AI)
- To authenticate users and send OTPs for director signature flows
- To deliver email notifications — signature requests, job application alerts, and system messages
- To transcribe voice input and respond to AI assistant queries on your behalf
- To sync lead data from connected Meta pages into your People CRM
- To improve platform performance, diagnose bugs, and develop new features
- To fulfil legal obligations and respond to lawful regulatory requests
- To communicate product updates, security notices, and policy changes
Legal basis for processing
Under the Digital Personal Data Protection Act, 2023, we rely on the following bases for processing personal data:
- Consent — for optional features such as voice input in the CoS AI module, and for marketing communications. You may withdraw consent at any time.
- Contract performance — processing necessary to provide the platform services you have signed up for, including your tenant workspace, CRM, HR, and compliance modules.
- Legitimate interest — for platform security, fraud prevention, and product analytics used to improve the service, where those interests are not overridden by your rights.
- Legal obligation — where we are required by law, such as retaining records for tax or regulatory purposes.
Who we share data with
We share personal data only where necessary to operate the platform. We do not sell data, and we do not share it with advertisers.
| Third party | Purpose |
|---|---|
| AI transcription service | Converting voice recordings to text when you use voice input in the AI assistant. Audio is not retained beyond the transcription request. |
| Meta (Facebook / Instagram) | Retrieving lead data from Facebook and Instagram pages you connect to startuperr. Governed by your integration settings and Meta's own policies. |
| Email delivery provider | Sending transactional emails — OTPs, signature requests, HR notifications. Provider processes email addresses only. |
| Cloud hosting provider | Hosting platform infrastructure and databases. Data is stored on servers in India or within data residency zones permitted under DPDP Act. |
| Payment processor | Processing subscription payments. We do not receive or store card details; these are handled directly by the processor. |
All third-party processors are bound by data processing agreements that prohibit them from using your data for any purpose beyond what is stated above.
Data storage & security
Your data is stored on secured servers. We use industry-standard measures to protect it, including:
- Encrypted connections (TLS) for all data in transit
- Password hashing using strong one-way algorithms
- Tenant isolation — each workspace is scoped so no tenant can access another's data
- Role-based access controls so users only see what they are authorised to see
- OTP verification for sensitive actions like resolution signing
Retention. We keep your data for as long as your account is active. If you close your account, we delete your personal data within 90 days, except where retention is required by law (such as for financial records). Tenant CRM and HR data is deleted on the same schedule unless you request earlier deletion.
No method of electronic transmission or storage is 100% secure. If we become aware of a breach affecting your data, we will notify you as required by applicable law.
Your rights
Under the DPDP Act 2023 and applicable law, you have the following rights over your personal data:
- Right to access — request a copy of the personal data we hold about you
- Right to correction — request correction of inaccurate or incomplete data
- Right to erasure — request deletion of your personal data, subject to legal retention obligations
- Right to withdraw consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- Right to grievance redressal — raise a complaint with our Grievance Officer (see Section 14)
- Right to nominate — nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
To exercise any of these rights, email us at privacy@startuperr.com. We will respond within 30 days. We may ask you to verify your identity before processing the request.
If you are a contact stored in a tenant's CRM — not a registered startuperr user — please contact that tenant directly. They are the Data Fiduciary for your data; we are only the processor.
Cookies
We use cookies and similar technologies to keep you logged in, remember your preferences, and understand how the platform is used.
| Cookie type | Purpose | Duration |
|---|---|---|
| Session cookies | Maintain your login session across page navigations | Until you log out |
| Preference cookies | Remember settings like theme, sidebar state, and filters | Up to 1 year |
| Analytics cookies | Understand which features are used most, to improve the product | Up to 6 months |
We do not use advertising or third-party tracking cookies. You can disable cookies in your browser settings, but some parts of the platform may not function correctly without session cookies.
Children
startuperr is a business operations platform intended for adults and organisations. We do not knowingly collect personal data from individuals under the age of 18. If you believe a minor has provided us with personal data, please contact us at privacy@startuperr.com and we will delete it promptly.
Tenant data responsibilities
If you are a registered tenant using startuperr to manage your own customers, employees, or contacts, you are the Data Fiduciary for that data under the DPDP Act 2023. startuperr acts as your Data Processor.
As a Data Fiduciary, you are responsible for:
- Obtaining valid consent from individuals whose data you enter into startuperr (CRM contacts, job applicants, form respondents)
- Providing a privacy notice to those individuals that meets the Act
- Responding to data principal requests (access, correction, erasure) received from your own contacts
- Ensuring data entered into startuperr is accurate and collected lawfully
- Informing your contacts that their data is processed by startuperr as your third-party service provider
Using startuperr does not transfer legal responsibility from the tenant to startuperr.
AI assistant & voice input
The Chief of Staff AI assistant lets you interact with your workspace using text or voice. Here is how we handle the data involved:
- Text queries are used solely to respond to your request — for example, finding a contact, creating a task, or summarising your day. Only the information necessary to answer your query is used.
- Voice recordings are converted to text so the assistant can understand your request. Audio is not retained once the transcription is complete.
- Conversation history is kept for the current day to provide continuity. It is not carried forward to future sessions.
- Your data is never used to train AI models. Queries and responses are used only to fulfil your request in the moment.
Meta integrations
If you connect a Facebook or Instagram Page to startuperr using the Meta Lead Ads integration, the following applies:
- startuperr retrieves lead data from your connected Facebook or Instagram page(s) and stores it in your tenant's People CRM.
- The data retrieved is determined by the lead form fields you have configured in Meta — typically name, phone number, email, and any custom fields.
- You are responsible for ensuring your Meta lead ad forms include a privacy notice pointing to your own privacy policy, as required by Meta's advertising policies and applicable law.
- You may disconnect the integration at any time from your tenant settings. Disconnecting stops future lead sync; previously synced leads remain in your CRM until you delete them.
- startuperr's use of data received from Meta complies with Meta's Platform Terms.
Changes to this policy
We may update this Privacy Policy from time to time. When we make a material change, we will notify you by email and display a notice in the platform at least 14 days before the change takes effect.
The "Last updated" date at the top of this page always reflects the most recent version. Continuing to use startuperr after the effective date of any update constitutes acceptance of the revised policy.
For minor changes (such as fixing typos or clarifying existing practices without changing their substance), we will update the date without individual notice.
Contact us
For any privacy-related queries, requests, or complaints, please reach out to our Grievance Officer:
You also have the right to lodge a complaint with the Data Protection Board of India, once constituted under the DPDP Act 2023, if you believe your rights have not been addressed to your satisfaction.