Privacy & Data Protection

Privacy Policy

Your privacy matters to us. This policy explains what personal data we collect, how we use it, and the rights you have over it under India's Digital Personal Data Protection Act, 2023.

Effective date: 29 May 2026Governed by: DPDP Act, 2023 & IT Act, 2000

1. Introduction

Welcome to Founding Legals, a product of Arvya Tech Pvt. Ltd. (CIN: U62011AP2025PTC121416) (“Company”, “we”, “us”, or “our”), a company incorporated under the Companies Act, 2013, having its registered office at 5th Floor, The Herbt's Square Building, Autonagar, APIIC IT Park, Mangalagiri, Amaravati, Andhra Pradesh 522503, India.

This Privacy Policy (“Policy”) describes how we collect, use, store, disclose and protect personal data about you when you access or use our website at www.foundinglegals.com and our web application at app.foundinglegals.com (collectively, the “Platform”).

This Policy is issued in compliance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), read with the rules and notifications framed thereunder, the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (to the extent in force during the transition), and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021. By accessing or using the Platform you acknowledge that you have read and understood this Policy. Where the law requires your consent for specific processing, that consent will be sought separately at the appropriate point in your user journey and is not implied by mere use of the Platform.

2. Who this Policy Applies To

This Policy applies to data principals located in India whose personal data we process in connection with the Platform. The Platform is intended for users in India; we do not actively offer the Platform to data subjects outside India.

For the purposes of the DPDP Act, the Company is a Data Fiduciary in respect of personal data we determine the purpose and means of processing for, and a Data Processor where we process personal data on instructions of another fiduciary (for example, where you are a founder uploading personal data of co-founders, employees or shareholders).

3. Personal Data We Collect

We collect the following categories of personal data:

3.1 Information you provide directly

  • Account information: name, email address, mobile number, password (stored only in salted, hashed form).
  • Business information:company name, PAN, CIN, GST number, registered address, and directors' / officers' details required to operate compliance workflows.
  • Identity documents (KYC): PAN card, passport, and other government-issued IDs submitted for KYC or statutory filings.Aadhaar: Where Aadhaar is required for a statutory filing (such as SPICe+ incorporation), we collect the Aadhaar number only with your explicit consent, use it only for the specific filing for which it is collected, and do not use it for authentication or any unrelated purpose. We are progressively migrating Aadhaar handling to DigiLocker / offline e-KYC XML so that the raw Aadhaar number is no longer stored.
  • Financial information: bank account details (where you provide them for fund-raising or compliance services), invoices and payment records. We do not collect or store card numbers, CVVs or full banking credentials; these are handled by our payment processor (Razorpay) directly.
  • Communications: messages, queries or feedback you send us by email, contact forms or in-app support.
  • Documents you upload to the document vault, data room or other Platform features.

3.2 Information collected automatically

  • Usage data: pages visited, features used, time spent, clicks, and navigation patterns.
  • Device and technical data: IP address, browser type and version, operating system, device identifiers.
  • Cookies and similar technologies: see our Cookie Policy.
  • Log data: server logs, access timestamps, error logs, referral URLs.

3.3 Information from third parties

  • Authentication data from Google OAuth when you use “Continue with Google”.
  • Payment status and transaction identifiers from payment processors (e.g., Razorpay).
  • Public business-registry information from MCA, GSTN or other government portals used to verify your entity.

4. Why We Process Your Personal Data & Our Lawful Basis

Under the DPDP Act, the Company processes personal data either (i) on the basis of your consent, or (ii) for certain legitimate usesrecognised under Section 7 of the DPDP Act (such as compliance with law, fulfilling a function under law, or responding to a medical emergency). We do not rely on a generalised “legitimate interest” basis.

PurposeLawful Basis (DPDP Act)
Create and manage your accountConsent
Deliver the incorporation, compliance and document services you specifically requestConsent
Process payments and issue tax invoicesConsent + compliance with law (GST, Income Tax)
Send service-related transactional messages (deadline alerts, reminders, security notices)Consent (provided at signup as necessary for service delivery)
Verify identity for KYC / statutory filingsCompliance with law (legitimate use under s.7, DPDP Act)
Detect, prevent and investigate fraud, abuse or security incidentsLegitimate use under s.7, DPDP Act
Respond to your support queriesConsent
Improve and secure the Platform (in an aggregated / de-identified form wherever feasible)Consent
Send marketing communications about our products and servicesSeparate, optional consent (which you may withdraw at any time)
Comply with court orders, regulatory or government directionsCompliance with law

You may withdraw any consent at any time, with effect for the future, by writing to info@foundinglegals.com. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal and may affect our ability to deliver certain services.

5. Sensitive & Identity Information

Where we collect identity documents, financial information, Aadhaar-linked information or other data treated as sensitive under applicable law:

  • We collect such information only with your explicit consent, only to the extent necessary for the specific filing or service, and we retain it only for as long as legally required.
  • Passwords are stored in salted, hashed form and are never visible to our personnel.
  • Aadhaar numbers, where collected, are not used for authentication, are access-restricted, and are scheduled to be migrated to DigiLocker / offline e-KYC artefacts so that the raw Aadhaar number is no longer retained on our systems.

6. How We Share Your Personal Data

We do not sell your personal data. We share it only in the following limited circumstances:

6.1 Service providers (Data Processors)

We engage third-party service providers to operate the Platform. These include:

  • Cloud hosting: DigitalOcean (production environment, India region); and, where applicable, Amazon Web Services / Google Cloud Platform for ancillary services.
  • Payment processing: Razorpay Software Pvt. Ltd.
  • Authentication: Google Identity Services.
  • Analytics: Google Analytics.
  • Customer support: Intercom, Inc.
  • Transactional email: SendGrid.
  • E-signature: Zoho Sign.

Each such provider is bound to process personal data only on our instructions and to maintain reasonable security safeguards.

6.2 Independent professionals

To deliver requested professional services, we facilitate the sharing of the minimum necessary personal data with empanelled, independent Chartered Accountants, Company Secretaries and advocates. The professional-client relationship in such cases is between you and that independent professional; the Company does not direct professional advice or share in advocates' legal fees.

6.3 Government, regulatory and judicial authorities

We may disclose personal data to authorities such as the MCA, GSTN, DPIIT, Income Tax Department, the Data Protection Board of India, or any court or competent authority, where required by law or pursuant to a valid legal order.

6.4 Business transfers

In the event of a merger, acquisition, restructuring or sale of assets, personal data may be transferred to the successor entity, which will be bound by this Policy or by a successor policy providing equivalent protections.

6.5 With your consent

We may share your personal data with other parties where you have provided explicit consent for such sharing.

7. Data Retention

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, and in any case for the minimum period required by applicable Indian law:

  • Account data: for the duration of your account and up to three (3) years after account closure (for dispute resolution).
  • Financial records and tax invoices: at least eight (8) years, as required by the Income Tax Act, 1961 and GST law.
  • Incorporation and statutory filing records: at least eight (8) years or as required by the Companies Act, 2013.
  • KYC documents: for the period required by applicable KYC / AML regulations.
  • Log data: at least one hundred and eighty (180) days, as required by Rule 3(1)(h) of the IT (Intermediary Guidelines) Rules, 2021. This is a regulatory minimum; we may retain logs for longer where required for security or legal reasons.
  • Marketing consent records: until consent is withdrawn, plus one (1) year for evidentiary purposes.

On expiry of the applicable retention period, personal data is securely deleted or anonymised.

8. Data Security

We take reasonable security safeguards proportionate to the nature and sensitivity of the personal data we process, including:

  • Hosting in India: the Platform is hosted on DigitalOcean infrastructure located in Bangalore, India. Customer data is stored within India.
  • Encryption in transit: data transmitted between your device and our Platform is protected using HTTPS / TLS.
  • Encryption at rest: application data and uploaded documents are encrypted at rest within the hosting environment.
  • Password protection: passwords are stored in salted, hashed form; we never store plain-text passwords.
  • Access controls: access to personal data is restricted to authorised personnel on a need-to-know basis.
  • Incident response: we maintain procedures to detect, investigate and respond to security incidents and to notify the Data Protection Board and affected data principals as required by law.

No system can be guaranteed to be completely secure. You are responsible for keeping your account credentials confidential and for notifying us promptly if you suspect any unauthorised use of your account.

9. Your Rights as a Data Principal

Subject to the conditions and exemptions under the DPDP Act, you have the following rights in respect of your personal data:

Right to information

Obtain a summary of the personal data being processed about you and the processing activities undertaken.

Right to correction and erasure

Request correction of inaccurate or incomplete personal data, completion of incomplete data, updating of out-of-date data, or erasure of personal data that is no longer necessary, subject to legal retention obligations.

Right to withdraw consent

Withdraw any consent previously given, with effect for the future.

Right to grievance redressal

Raise a grievance with our Grievance Officer; if unresolved, escalate to the Data Protection Board of India.

Right to nominate

Nominate another individual to exercise your rights in the event of your death or incapacity.

To exercise any of these rights, please write to our Grievance Officer at info@foundinglegals.com. We will respond to verifiable requests within the timelines prescribed under applicable law.

You also owe certain duties under Section 15 of the DPDP Act, including not impersonating another person and not furnishing materially false particulars when raising grievances or exercising rights.

10. Cookies

We use cookies and similar tracking technologies on the Platform. For the categories of cookies we use and how to manage them, see our Cookie Policy.

12. Children's Personal Data

Our Platform is intended for use by adults (18 years or older). Consistent with Section 9 of the DPDP Act, we do not knowingly process the personal data of children (individuals under 18) without verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring or targeted advertising directed at children. If you believe we may have inadvertently collected the personal data of a child, please contact info@foundinglegals.com and we will take steps to delete that data.

13. Cross-Border Transfers

Customer data is stored within India. To the extent any incidental processing occurs outside India through our service providers, such transfers are made only to jurisdictions that are not restricted by the Central Government of India under Section 16 of the DPDP Act, and subject to contractual safeguards requiring the recipient to maintain appropriate protections. We do not target users outside India.

14. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, or applicable law. Where the changes are material, we will notify you by email (using the address associated with your account) and/or by a prominent notice on the Platform a reasonable period in advance of the changes taking effect. Your continued use of the Platform after the effective date constitutes acceptance of the revised Policy.

15. Grievance Officer & Escalation

In accordance with the DPDP Act and the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, our Grievance Officer may be contacted for any complaint regarding the processing of your personal data or content on the Platform:

Grievance Officer: Arvya Tech Pvt. Ltd.

Name: Mr. Manoj Kumar Thota

Designation: Grievance Officer

Email: info@foundinglegals.com

Address: Arvya Tech Pvt. Ltd., 5th Floor, The Herbt's Square Building, Autonagar, APIIC IT Park, Mangalagiri, Amaravati, Andhra Pradesh 522503, India.

Acknowledgement & resolution: We will acknowledge complaints within seventy-two (72) hours and endeavour to resolve them within the timelines prescribed under applicable law.

If you are not satisfied with the resolution provided by our Grievance Officer, you may approach the Data Protection Board of India under the DPDP Act, or seek any other remedy available to you under law.

Disclaimer: Founding Legals is a technology platform operated by Arvya Tech Pvt. Ltd. It is not a law firm, chartered accountancy firm or company secretarial firm. Information and computer-generated drafts provided on the Platform do not constitute legal, tax or professional advice. For specific legal matters, please consult a qualified professional.

Chat on WhatsApp