Privacy Policy

This Privacy Policy describes how Fortyglyph Private Limited ("Company", "we", "us", or "our") collects, uses, shares, retains, and protects your personal data when you access or use the website https://thebondproject.in and any associated services operated under the brand name "The Bond Project" (collectively, the "Platform").

This Privacy Policy is published in accordance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the Digital Personal Data Protection Act, 2023 ("DPDP Act"), as applicable.

By using the Platform, you acknowledge that you have read and understood this Privacy Policy. Please read it carefully along with our Terms of Use and Cookie Policy.


1. Who We Are (Data Fiduciary)

For the purposes of the DPDP Act, the Data Fiduciary in respect of your personal data is:

Fortyglyph Private Limited
CIN: U66190MH2026PTC471341
Registered Office: G-20, Floor 1, Plot G17/24, Electric House, Colaba, Mumbai G.P.O., Mumbai – 400001, Maharashtra, India
Contact: rubin@thebondproject.in

2. Personal Data We Collect

We collect the following categories of personal data:

2.1 Account information

2.2 Authentication and security data

2.3 Usage data

2.4 Server logs and technical information

2.5 Payment data

We do not receive or store your full card number, CVV, expiry date, UPI PIN, net banking credentials, or any other complete payment instrument credentials. Such information is collected and processed directly by our payment gateway provider, Razorpay.

2.6 Broker-fetched data

When you connect your Broker account via OAuth and grant the relevant permissions, the Platform may access the following from your Broker account:

This data is accessed only to the extent that you have authorised via the Broker's OAuth consent screen, and only for the purpose of providing portfolio tracking, analytics, and order routing features within the Platform.

2.7 Communications

2.8 Derived data

We do not collect: PAN, Aadhaar number, bank account number, passport number, biometric information, or other sensitive identity data. KYC information is held by your Broker, not by us.


3. How We Collect Personal Data

We collect personal data:

(a) Directly from you — when you register, subscribe, communicate with us, or interact with the Platform;

(b) From your Broker via OAuth — only with your authorisation, and only to the extent permitted by the OAuth scope you consent to with the Broker;

(c) Automatically — through cookies, analytics tools, and server logs as you use the Platform; and

(d) From publicly available sources — in limited cases, such as where bond ISINs you add to your watchlist correspond to public reference data.


4. Purposes for Which We Use Personal Data

We use your personal data for the following purposes:

(a) Service delivery — to create and manage your User Account, provide the Services, display your portfolio and analytics, and operate the Platform;

(b) Authentication and security — to authenticate you, protect your Account, detect and prevent fraud or abuse, and ensure the security of the Platform;

(c) Subscription and billing — to process Subscription payments, issue receipts, manage renewals (where you opt in), and handle refunds;

(d) Customer support — to respond to your queries, complaints, and grievances;

(e) Product analytics — to understand how the Platform is used and to improve features and user experience;

(f) Communication — to send service-related notifications (which are necessary for the operation of your Account), and, only with your explicit consent, marketing communications;

(g) Legal and regulatory compliance — to comply with applicable law, respond to lawful requests from authorities, enforce our Terms, and protect the rights, safety, and property of the Company, our Users, or others.


5. Legal Basis for Processing

Under the DPDP Act, we process your personal data primarily on the basis of:

(a) your consent, which you provide by registering on the Platform, subscribing to the Services, connecting your Broker, and opting in to specific data collection or use; and

(b) certain legitimate uses permitted under the DPDP Act, including processing necessary for compliance with applicable law, prevention or detection of fraud, and where consent has been voluntarily provided in the context of the relationship.

You may withdraw your consent at any time as described in Section 9.


6. Sharing of Personal Data

We do not sell your personal data. We may share your personal data only with:

6.1 Your Broker

When you connect a Broker via OAuth and place orders through the Platform, relevant order instructions are transmitted to your Broker for execution.

6.2 Service providers

We use the following third-party service providers to operate the Platform. Each is engaged under contractual obligations of confidentiality and security, processes personal data only on our instructions in the capacity of a data processor (not as an independent controller of your personal data), and is responsible for its own onward sub-processor relationships under appropriate contractual safeguards.

(a) Cloud database and authentication — Supabase

(b) Application hosting — Railway

(c) Payment processing — Razorpay

(d) Your Broker

(e) Other service providers

These providers process personal data only on our instructions, only for the purposes set out in this Privacy Policy, and under contractual obligations of confidentiality and security. Each provider may engage its own sub-processors under appropriate contractual safeguards; please refer to each provider's privacy notice for details.

6.3 Regulators, courts, and law enforcement

We may disclose personal data when required to comply with a valid legal process, court order, or request from a regulator or law enforcement authority, or where necessary to protect the rights, safety, or property of the Company, our Users, or others.

6.4 Business transfers

In the event of a merger, acquisition, restructuring, sale of assets, or insolvency, personal data may be transferred to the relevant counterparty, subject to the protections of this Privacy Policy.


7. Cross-Border Data Transfers

7.1 The Platform's primary database and authentication infrastructure is hosted in India (Supabase's ap-south-1 / Mumbai region, operated on AWS infrastructure). Persistent personal data — including your account information, watchlists, alerts, and other application data — is stored in India.

7.2 Application hosting infrastructure is provided by Railway in Singapore. As a result, personal data in transit may temporarily transit through or be processed in Singapore during routine application operation. Persistent storage of personal data does not occur on Railway infrastructure.

7.3 Service providers used by the Company, including Supabase, Inc. and Railway Corp., are companies headquartered outside India (in the United States). Although your personal data is stored in India, personnel of these service providers based outside India may, in limited operational and support scenarios and subject to contractual safeguards, have access to systems hosting your personal data.

7.4 The Company has put in place commercially reasonable measures, including contractual safeguards under each service provider's data processing agreement, to ensure that personal data is processed in a manner consistent with this Privacy Policy and applicable law.

7.5 Such transfers comply with the requirements of the Digital Personal Data Protection Act, 2023, and any rules notified thereunder. The Company does not transfer personal data to any country or territory that has been notified by the Central Government as restricted under Section 16 of the DPDP Act.


8. Data Retention

8.1 We retain your personal data only for as long as is necessary for the purposes for which it was collected, or for such longer periods as may be required by applicable law.

8.2 General retention periods:

(a) Account data — for the duration of your Account, plus an additional period of up to twenty-four (24) months after Account closure for legal, regulatory, and dispute-resolution purposes;

(b) Payment and Subscription records — for at least eight (8) years from the end of the relevant financial year, in compliance with applicable tax, accounting, and audit requirements;

(c) Audit logs and security records — for up to twenty-four (24) months;

(d) Grievance records — for at least three (3) years from the date of resolution;

(e) Broker-fetched data — only for as long as your OAuth consent with the Broker remains active; revocation of OAuth consent will result in deletion of cached Broker-fetched data within a reasonable period.

8.3 Where personal data is no longer required, we will delete or anonymise it.


9. Your Rights Under the DPDP Act

Subject to applicable law and verification of your identity, you have the following rights in respect of your personal data:

9.1 Right to access

You have the right to obtain a summary of the personal data we hold about you, the processing activities undertaken, and the identities of third parties with whom we have shared your personal data.

9.2 Right to correction and erasure

You have the right to request correction of inaccurate or incomplete personal data, and erasure of personal data that is no longer necessary for the purposes for which it was processed, subject to retention obligations under applicable law.

9.3 Right to withdraw consent

You may withdraw your consent to the processing of your personal data at any time. Withdrawal of consent will not affect the lawfulness of processing carried out prior to such withdrawal. Withdrawal of consent may result in our being unable to provide some or all of the Services to you.

9.4 Right of grievance redressal

You have the right to readily available means of grievance redressal as described in Section 13.

9.5 Right to nominate

You have the right to nominate any other individual, who shall, in the event of your death or incapacity, exercise your rights under the DPDP Act in accordance with applicable rules.

To exercise any of these rights, please contact us at rubin@thebondproject.in. We will respond to your request within the timelines prescribed under applicable law.


10. Children

10.1 The Platform is not intended for, and may not be used by, individuals under 18 (eighteen) years of age. We do not knowingly collect personal data from any person under 18.

10.2 If we become aware that we have inadvertently collected personal data from an individual under 18, we will delete such data promptly.


11. Cookies and Similar Technologies

11.1 We use cookies and similar tracking technologies to operate the Platform, authenticate Users, maintain sessions, remember preferences, and analyse usage.

11.2 For details, please refer to our Cookie Policy at /cookie-policy.


12. Security

12.1 We implement reasonable security practices and procedures, in accordance with applicable law, to protect personal data from unauthorised access, use, disclosure, alteration, or destruction. Such measures include:

(a) HTTPS / TLS encryption for data in transit;

(b) Encryption of sensitive data at rest where applicable;

(c) Use of OAuth authentication with Brokers, so that Broker passwords are never received or stored by us;

(d) Role-based access controls within the Company's systems;

(e) Audit logging of access to sensitive systems;

(f) Periodic review of security practices.

12.2 Despite these measures, no method of transmission over the internet or storage system is completely secure. We cannot guarantee absolute security and you acknowledge that you provide personal data at your own risk.


13. Personal Data Breach Notification

In the event of a personal data breach affecting your personal data, we will notify you and the Data Protection Board of India in the manner and within the timelines required under the DPDP Act and rules made thereunder.


14. Grievance Officer and Data Protection Contact

14.1 In compliance with the Information Technology Act, 2000, the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, and the DPDP Act, the Grievance Officer for the Platform is:

Name: Rubin Talati
Designation: Founder and Grievance Officer / Data Protection Contact
Email: rubin@thebondproject.in
Postal address: G-20, Floor 1, Plot G17/24, Electric House, Colaba, Mumbai G.P.O., Mumbai – 400001, Maharashtra, India

14.2 You may write to the Grievance Officer with any grievance, query, or request relating to your personal data or the operation of this Privacy Policy. Grievances will be acknowledged within twenty-four (24) hours and resolved within fifteen (15) days, in accordance with applicable law.

14.3 Full details of the grievance redressal process are available at /grievance.


15. Changes to This Privacy Policy

15.1 We may update this Privacy Policy from time to time. The updated Policy will be posted on the Platform with a revised "Last updated" date.

15.2 Material changes will be notified to you via email or through a prominent notice on the Platform.

15.3 Your continued use of the Platform after the effective date of the updated Privacy Policy constitutes your acceptance of the updated Policy.


For questions or to exercise your rights, contact us at rubin@thebondproject.in.