◆
MyFundedDesk
Digital Personal Data Protection (DPDP) Act 2023 Compliant

Privacy Policy & Data Protection

Effective Date: September 1, 2026 • Version 2.4 • Entity: FundedDesk Technologies Pvt. Ltd.

Our Privacy Commitment: FundedDesk respects your digital sovereignty. We do not sell, license, or monetize your personal information or proprietary trading strategies to third-party hedge funds, brokers, or data aggregators.

1. Identity of the Data Fiduciary

This Privacy Policy governs the processing of personal data by FundedDesk Technologies Private Limited (hereinafter referred to as "FundedDesk", "we", "us", or "our"), incorporated under the Companies Act, 2013, with its principal corporate address at Level 8, Platina Tower, G-Block, Bandra Kurla Complex (BKC), Mumbai 400051, Maharashtra, India.

Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), FundedDesk serves as the "Data Fiduciary" responsible for determining the purpose and means of personal data processing.

2. Categories of Personal Data Collected

We collect and process the following classifications of user information:

  • Identity & Contact Information: Full legal name, verified email address, mobile phone number, billing address, and username.
  • KYC & Payout Verification: Government identification (Permanent Account Number - PAN, Aadhaar / Passport), banking account details (Bank Name, Account Number, IFSC Code), and UPI Virtual Payment Address (VPA) required for legitimate payout disbursement and tax reporting.
  • Billing & Transaction Records: Challenge package tier purchased, transaction IDs, payment method tokens, invoice receipts, and currency. (Note: Credit/debit card numbers are tokenized directly via PCI-DSS Level 1 payment processors; FundedDesk never stores raw CVV numbers).
  • Simulated Trading Data: Order tickets, execution timestamps, lots traded, instrument tickers (NIFTY, BANKNIFTY), stop-loss levels, drawdown watermarks, and P&L trajectories.
  • Device & Telemetry Data: IP address, device hardware fingerprints, browser user-agent, operating system details, session cookies, and network latency logs.

3. Purpose and Legal Basis for Processing

We process your data strictly under the following lawful legal grounds:

  • Performance of Contract: To provision trading evaluation credentials, match simulated orders against live exchange tick feeds, evaluate compliance with rulebook parameters, and calculate profit splits.
  • Compliance with Legal Obligations: Fulfilling tax obligations under the Indian Goods and Services Tax (GST) Act, 2017, Prevention of Money Laundering Act (PMLA), and relevant financial record retention mandates.
  • Legitimate Interests & Risk Mitigation: Monitoring matching engine telemetry to identify latency exploitation, automated signal spoofing, multi-account collusion, and reverse-hedging attacks that breach platform terms.
  • Consent: Sending transactional product announcements, system maintenance bulletins, and customer satisfaction surveys (with immediate opt-out available).

4. Trading Telemetry & Forensic Snapshots

To maintain complete transparency during account breaches and evaluation pass certifications, our risk engine records a cryptographic snapshot of every order execution. This snapshot includes:

  • Sub-second timestamp of order placement and simulated fill.
  • Underlying spot tick at time of fill from the National Stock Exchange (NSE) feed.
  • Account equity watermark and remaining daily drawdown buffer.

These forensic logs are accessible to the trader inside their dashboard and are retained to resolve dispute inquiries without ambiguity.

5. Cryptographic Security Standards

FundedDesk maintains state-of-the-art security architectures designed to safeguard sensitive personal data:

  • Encryption at Rest: Database tables and user credentials are encrypted using Advanced Encryption Standard (AES-256). User passwords undergo cryptographic salting and hashing via bcrypt.
  • Encryption in Transit: All HTTP and WebSocket connections are strictly enforced through Transport Layer Security (TLS 1.3) with HSTS headers.
  • Infrastructure Isolation: Hosted in SOC 2 Type II and ISO 27001 certified AWS Mumbai (ap-south-1) data center clusters with strict VPC isolation, rate limiting, and DDoS mitigation shields.

6. Cookies and Local Storage

We employ session cookies and browser LocalStorage strictly for technical functionality:

  • Essential Authentication Cookies: Used to maintain secure active sessions on the trader terminal and dashboard.
  • Preference Storage: Saves your charting layout, indicator configurations, dark/light theme, and watchlist groupings.
  • Telemetry Cookies: Measures sub-second WebSocket ping to automatically switch between primary and fallback streaming endpoints.

7. Authorized Third-Party Processors

We partner only with vetted industry leaders that adhere to rigorous data privacy frameworks:

  • Payment Processors: Direct UPI Banking & Institutional Payment Partners (for challenge purchases and IMPS/UPI payouts).
  • Cloud & Computing Infrastructure: Amazon Web Services (AWS) Mumbai region.
  • Transactional Communications: Resend / SendGrid / AWS SES for encrypted system notifications and receipt dispatches.

8. Data Retention Schedules

We retain personal data only for as long as necessary to fulfill the purposes for which it was gathered. Specifically:

  • Financial, invoice, and KYC records are preserved for a period of seven (7) years in compliance with statutory Indian taxation and audit requirements.
  • Active account profile data is stored until account closure or an explicit erasure request under the DPDP Act.
  • High-frequency WebSocket tick logs and browser telemetry are purged on a rolling 180-day cycle.

9. Your Rights under the DPDP Act 2023

As a Data Principal in India, you enjoy statutory rights:

  • Right to Access Information: Request a summary of personal data being processed and third parties with whom it has been shared.
  • Right to Correction & Erasure: Rectify inaccurate personal details or request deletion of data that is no longer required for statutory purposes.
  • Right of Grievance Redressal: Direct complaints to our dedicated Grievance Officer for prompt investigation and resolution.
  • Right to Nominate: Nominate another individual to exercise your rights in the event of death or incapacity.

10. Grievance Officer & Redressal Mechanism

In compliance with the DPDP Act 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, the designated Grievance Officer is:

Data Protection & Grievance Officer
FundedDesk Technologies Private Limited
Level 8, Platina Tower, G-Block, Bandra Kurla Complex (BKC)
Mumbai, Maharashtra 400051, India
Response Resolution SLA: Within 30 business days