Privacy Policy
What we collect, why we collect it, who processes it on our behalf, how long we keep it, and what you can ask us to do with it.
Contents · 15 sections
Tyche Capital is not a company, LLP or other legal entity. It is a name used by three university graduates in Bengaluru: Kushagra Agarwal, Vedansh Mishra and Ankith Bharadwaj (“we”, “us”, “our”). The three of us jointly decide why and how personal data is processed on this site, so we are jointly the “Data Fiduciary” under the Digital Personal Data Protection Act, 2023 (“DPDP Act”). The obligations in this Policy are owed by us personally.
The DPDP Act’s detailed obligations are being brought into force in phases under the Digital Personal Data Protection Rules, 2025. Until they apply in full, Section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 continue to apply where relevant. We follow the DPDP framework now, voluntarily, and will update this Policy as further provisions commence.
This Policy covers everyone who visits tychecapital.co.in or its subdomains (the “Site”), creates an account, or contacts us. Read it with our Terms of Service and Risk Disclosure.
| Who | What we collect | How we get it |
|---|---|---|
| All visitors | IP address, browser and device type, pages requested, date and time, in server and security logs. A strictly necessary cookie recording your cookie-notice choice. | Automatically |
| Anyone who opens a research piece | One view per reader per piece per day. Signed in, the view is recorded against your account. Signed out, we keep only a one-way hash of your IP address and browser, made with a value that changes every day and is deleted after two days, so it can no longer be linked to you. The address itself is never stored. | Automatically |
| Account holders (email sign-in) | Email address; the phone number you give when you create your account, and your name if you give it; a password, which is stored only as a salted hash that no one can read, or one-time sign-in codes sent to your email; account creation and last sign-in times; your confirmation that you are 18 or older and the document versions you accepted. | From you |
| Account holders (Google sign-in) | Your name, email address and profile photo, as shared by Google when you choose “Continue with Google”. We do not receive your Google password. The phone number you give when you complete your profile. | From Google, at your request; your phone number from you |
| Account holders reading research | Where you stopped in each piece and how you set up the reader; the highlights, annotations and notes you make, which only your own account can read; research you submit to us. | From you |
| Anyone who contacts us | Your name, email address and whatever you write to us. | From you |
We do not collect Aadhaar numbers, PAN, bank account, UPI, card or other payment details, or any information about your finances or investments from visitors or account holders. We never ask for them. See “We will never ask you for money” in our Risk Disclosure.
The DPDP Act permits processing on the basis of your consent (Section 6) or for one of the “certain legitimate uses” in Section 7.
| Purpose | Basis |
|---|---|
| Creating, securing and operating your account and giving you access to the research archive | Your consent (s.6), given at sign-up |
| Sending sign-in codes, security alerts, and notices of material changes to our documents | Your consent (s.6), given at sign-up |
| Replying to messages you send us | The data you voluntarily provided for that purpose (s.7(a)) |
| Keeping the Site secure and preventing abuse, including keeping logs | Your consent (s.6), given at sign-up; for visitors without an account, the strictly necessary operation of the Site |
| Responding to a court order, or to a lawful demand from an authority in India | Compliance with a legal obligation to disclose information to the State (s.7(d)), or with a judgment, decree or order (s.7(e)) |
| Keeping records where a law requires it | Retention required by law (s.8(7)) |
We do not use your data for advertising, profiling or automated decision-making, and we do not send marketing emails. If we ever start a newsletter, it will be opt-in only, with a separate consent.
What we do:
- All traffic to the Site is encrypted in transit (HTTPS/TLS).
- Our database provider encrypts stored data by default.
- Passwords are stored only as salted hashes by our authentication provider. None of us can see your password.
- Administrative access is limited to the three of us. Our hosting and database provider accounts are protected by multi-factor authentication.
No system is completely secure, and we cannot guarantee the security of data sent over the internet.
Personal data breaches. If a personal data breach affects you, we will inform you and the Data Protection Board of India in the form and within the time required by the DPDP Act and Rules. We will tell you what happened, when, the likely consequences, what we have done, and what you can do to protect yourself.
Cyber security incidents. Where the CERT-In Directions of 28 April 2022 apply to us, we will retain logs and report cyber security incidents as those Directions require.
We take reasonable steps to keep your account data accurate and complete. You can correct your details at any time by contacting us (Section 8).
- Account data: while your account is open. If you delete your account, we delete or irreversibly anonymise your account data within 30 days. If it is inactive for 12 months, we delete it, after emailing you a week beforehand and again the day before.
- Contact messages: 12 months after our conversation ends.
- Security logs: up to 180 days.
- Legal exceptions: we keep specific data longer only where a law requires it, or where it is needed for an actual or reasonably expected legal claim, and only for as long as that requires.
You have the following rights under the DPDP Act:
- Access: a summary of the personal data we hold about you, the processing we carry out, and the identities of the Data Fiduciaries and Data Processors we have shared it with, with a description of what was shared.
- Correction and erasure: to correct, complete or update your data, or to have it erased. If we must keep something for a legal reason, we will tell you what and for how long.
- Withdraw consent: at any time, as easily as you gave it, by emailing us from your registered email address. Withdrawing consent means we will close your account. It does not affect processing before you withdrew.
- Nominate: you may nominate another individual to exercise your rights if you die or become incapable.
- Grievance redressal: to raise a grievance with us (Section 12) and, if we do not resolve it, to complain to the Data Protection Board of India.
How to exercise them: email ankith@tychecapital.co.in from your registered email address. If we cannot confirm a request comes from you, we will ask you to confirm it from that address. We respond within 30 days.
Section 15 of the DPDP Act requires you, among other things, not to impersonate anyone when providing personal data, not to register false or frivolous grievances, and to provide only verifiably authentic information when seeking correction or erasure.
You must be 18 or older to create an account, and you confirm this at sign-up. We do not knowingly process the personal data of anyone under 18, and we do not track, behaviourally monitor, or target advertising at children. If we learn that an account belongs to someone under 18, we will close it and delete its data promptly. Anyone may read the Site’s public pages, which set only strictly necessary cookies.
In accordance with the Information Technology Act, 2000, the rules made under it, and the DPDP Act, our Grievance Officer is:
Grievance Officer
Ankith Bharadwaj
ankith@tychecapital.co.in
Bengaluru, Karnataka, India (correspondence by email only)
We acknowledge grievances within five business days and resolve them within 30 days. If we need longer, we will tell you why and give you a date, and in any case we will stay within the maximum period set by the DPDP Rules, 2025.
We may update this Policy. The date at the top shows the latest version. We will email account holders about material changes before they take effect and, where the DPDP Act requires fresh consent, we will ask for it rather than assume it. We keep dated copies of all previous versions and will provide them on request.
This Policy is governed by the laws of India. Subject to your right to approach the Data Protection Board of India or any other forum available under law, the courts at Bengaluru, Karnataka have jurisdiction over any dispute arising from it.
- Data Fiduciary
- The person who, alone or with others, decides the purpose and means of processing personal data. For this Policy, that is Kushagra Agarwal, Vedansh Mishra and Ankith Bharadwaj, jointly.
- Data Principal
- The individual the personal data relates to. That is you.
- Data Processor
- A person who processes personal data on behalf of a Data Fiduciary.
- Personal data
- Any data about an individual who is identifiable by or in relation to that data.
- Personal data breach
- Any unauthorised processing of personal data, or its accidental disclosure, acquisition, sharing, use, alteration or destruction, or loss of access to it, that compromises its confidentiality, integrity or availability.
Previous versions of this Policy are available on request from ankith@tychecapital.co.in.