NSE closed·  :  :   IST
sandbox · v0.1
counsel review pending — non-binding. this is a plain-language draft published for transparency during the pre-launch build. it is not a legal agreement, it does not create rights or obligations, and it will be replaced by a counsel-reviewed document before public launch. see how we build.

legal · privacy

privacy

indicative effective date — 2026-08-17

data controller

vajraquant is the data fiduciary for personal data collected via the platform, in the sense of the Digital Personal Data Protection Act, 2023 (DPDP). contact for privacy matters: hello@vajraquant.com.

what we collect

  • account data. email, hashed password, display name, phone (optional), MFA secret. required to run the account.
  • trading data. strategies you create, backtests you run, orders and fills routed via the platform, positions, and the rationale trail generated by the runtime.
  • broker linkage. broker account references and API-token references. tokens are stored encrypted with envelope encryption in a KMS; the decrypted value only ever exists in the execution service's memory, is never logged, and is never returned by any API.
  • tax data. PAN, bank details, contract notes, holding statements you upload for tax computation. classified as sensitive personal data — encrypted at rest with a separate key, masked in list views, redacted from logs and error traces, and access-logged individually.
  • usage telemetry. pages viewed, features used, API call metrics. no third-party tracking on the marketing site pre-launch.

why we process it

to provide and secure the platform; to compute your tax file; to route your orders to your broker; to comply with statutory retention requirements; to communicate transactional events (order status, deployment events, security alerts); and — with consent — to send product updates.

your rights under DPDP

  • access — a copy of your personal data on request.
  • correction — request rectification of inaccurate data.
  • erasure — request deletion, subject to statutory retention (see below).
  • grievance redress — write to us and we will respond within the statutory window.

note. the right to erasure conflicts with statutory retention for financial and tax records. we will publish the exact retention schedule with counsel before launch. in the interim: tax filings, order logs, and rationale trails are retained for the statutory period regardless of an erasure request; other personal data is deleted on request.

data residency and transfer

primary storage is in India. we do not currently transfer personal data outside India for processing. if that changes, we will publish the destinations and the safeguards before it takes effect.

vendors and sub-processors

pre-launch, the platform runs on free-tier or local infrastructure and does not use paid sub-processors. before launch, we will publish the list of sub-processors (managed database, email delivery, error tracking) and update it on any change.

security

MFA is required before live deployment. all secrets encrypted at rest. row-level tenancy enforced in the data layer, not the controller. audit log write-only from the application. daily automated DR restore test on staging.

changes

we will notify you of material changes in-app and by email at least 30 days before they take effect.

← back to legal