BITS-SPARK Angels (“we,” “our,” or “us”) operates the BITS-SPARK Angels Investment Management Platform (the “Platform”) — an invite-only portal that facilitates angel investment activities for BITS alumni and associated founders. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights you have over it. By using the Platform, you agree to the practices described in this Policy.
1. Who This Policy Applies To
This Policy applies to all users of the Platform, including:
- Angel Investors — BITS alumni and other accredited investors who review deals and make commitments.
- Founders / Startups — Company representatives who submit their startups for evaluation.
- Committee Members — Screening and investment committee reviewers.
- Administrators — Platform operators managing users, deals, and settings.
- Volunteers — Supporting members with limited access.
2. Information We Collect
2.1 Information You Provide Directly
- Account credentials: email address and hashed password (bcrypt, 12 rounds).
- Investor profile: first, middle, and last name; city, state, and country; phone number; LinkedIn profile URL; BITS batch year and campus (Pilani, Goa, Hyderabad, Dubai); current employer and role; industry expertise and investment interests; typical investment amount and prior investment experience; investing entity (self or company) and company name.
- Founder / startup profile: company name, sector(s), funding stage, incorporation details, product description, amount sought, LinkedIn company page, and one-pager document URL.
- KYC & accreditation documents: uploaded files (e.g., ID proof, accreditation certificates) stored as secure URLs.
- Tax documents: documents such as Form 16, investment summaries, and capital call notices, linked to your account.
- Banking information: account details submitted for wire transfers and distributions.
- Investment data: commitment amounts, wiring dates, SPV allocation amounts, ownership percentages, and subscription agreement URLs.
- Due diligence materials: financial statements, cap tables, legal documents, and other files uploaded by founders or reviewers.
- Event RSVPs: attendance confirmation or decline for platform events.
- Communications: messages and notes exchanged through the platform's Q&A and DD messaging features.
- Additional comments: any free-text information you voluntarily provide in profile fields.
2.2 Information Collected Automatically
- Session data: JSON Web Token (JWT) stored in an HTTP-only, Secure, SameSite=Lax cookie containing your user ID, role, and session expiry.
- Last login timestamp: recorded on each successful authentication.
- Audit log: timestamped records of significant actions (e.g., role changes, status updates, KYC decisions) linked to your user ID.
2.3 Information from Third Parties
- LinkedIn (OAuth 2.0 / OpenID Connect): when you connect your LinkedIn account, we receive your LinkedIn member ID, public profile data, and an access token with its expiry. We store only what is needed to identify your LinkedIn profile and do not post on your behalf.
- WhatsApp Business API (Meta): if you opt in to WhatsApp notifications, we collect and store your WhatsApp number and process inbound/outbound messages through Meta's Cloud API. We record opt-in consent explicitly.
3. How We Use Your Information
| Purpose | Data Used | Lawful Basis |
|---|---|---|
| Account creation & authentication | Email, password hash, JWT session | Contract performance |
| Investor profile & KYC management | Personal, financial, and document data | Contract performance / Legal obligation |
| Deal evaluation & committee review | Startup data, evaluation scores, notes | Legitimate interests |
| Commitment & SPV management | Investment amounts, wire details, allocation data | Contract performance |
| Portfolio updates & reporting | Portfolio data, update content | Contract performance / Legitimate interests |
| Event management & RSVPs | Name, email, RSVP status | Consent / Legitimate interests |
| WhatsApp notifications | WhatsApp number, message content | Consent |
| LinkedIn profile enrichment | LinkedIn ID, access token, profile data | Consent |
| Platform security & audit | IP address, user ID, action logs | Legitimate interests / Legal obligation |
| Tax reporting | Tax documents, startup linkage, notes | Legal obligation |
4. How We Share Your Information
We do not sell your personal information. We share it only in the following limited circumstances:
- Within the Platform: investor deal activity (excluding personal contact details) is visible to other investors on the same deal; startup data is visible to committee members and admins as appropriate to their role.
- Service providers:
- Neon (PostgreSQL hosting): all application data is stored on Neon's serverless PostgreSQL service, governed by Neon's data processing agreement.
- Amazon Web Services (ECS, ECR, ALB): infrastructure hosting. AWS acts as a data processor under our instructions.
- LinkedIn (Microsoft): OAuth authentication and profile data retrieval.
- Meta Platforms: WhatsApp Business Cloud API for opted-in messaging.
- Legal compliance: we may disclose information when required by applicable law, court order, or governmental authority.
- Business transfers: in the event of a merger, acquisition, or asset sale, your information may be transferred, subject to the same protections described here.
5. Data Security
- Encryption in transit: all traffic is served over HTTPS with TLS 1.3 enforced by AWS ALB. HSTS is set with a 2-year max-age, includeSubDomains, and preload.
- Encryption at rest: sensitive fields (e.g., LinkedIn access tokens) are encrypted using AES-256-GCM before storage. Neon PostgreSQL storage is encrypted at rest by the provider.
- Password security: passwords are never stored in plain text; they are hashed with bcrypt using 12 salt rounds.
- Session security: JWT session cookies are HTTP-only, Secure, and SameSite=Lax to mitigate XSS and CSRF risks. Security headers (X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy) are applied at the application layer.
- Role-based access control: every API route enforces authentication and role checks via server-side middleware. Users can only access data their role is permitted to see.
- Audit logging: significant data mutations are recorded in an immutable audit log.
Despite these measures, no system is completely secure. We encourage you to use a strong, unique password and to report any suspected security incidents to us immediately.
6. Data Retention
We retain personal data for as long as your account is active or as needed to fulfil the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce agreements.
- Active accounts: retained for the duration of your membership.
- Closed/inactive accounts: personal profile data is retained for a minimum of 7 years to satisfy financial record-keeping obligations under applicable law.
- Investment & tax records: retained for 10 years from the date of the relevant transaction, in compliance with financial regulatory requirements.
- Audit logs: retained for 5 years.
- LinkedIn access tokens: invalidated when you disconnect your LinkedIn account or when the token expires.
- WhatsApp messages: retained for 12 months from the date sent.
7. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: request a copy of the personal data we hold about you.
- Correction: request correction of inaccurate or incomplete data.
- Deletion: request deletion of your data where we no longer have a lawful basis to retain it (subject to financial record-keeping obligations).
- Restriction: request that we restrict processing of your data in certain circumstances.
- Portability: receive your data in a structured, machine-readable format where technically feasible.
- Objection: object to processing based on legitimate interests.
- Withdraw consent: where processing is based on consent (e.g., WhatsApp opt-in, LinkedIn connection), you may withdraw consent at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at the address in Section 11. We will respond within 30 days. We may need to verify your identity before acting on your request.
8. Cookies & Tracking
The Platform uses a single, strictly necessary HTTP-only session cookie to maintain your authenticated session. We do not use:
- Third-party advertising or tracking cookies.
- Analytics cookies (e.g., Google Analytics).
- Persistent marketing identifiers.
Because we only use a strictly necessary session cookie, a cookie consent banner is not required under most cookie laws. If our cookie practices change, we will update this Policy accordingly.
9. Children's Privacy
The Platform is intended exclusively for adults (18 years or older) who meet the eligibility criteria for angel investing or startup participation. We do not knowingly collect personal data from individuals under 18. If we become aware that a minor has provided us with personal data, we will delete it promptly.
10. International Data Transfers
The Platform is hosted on AWS infrastructure and uses Neon PostgreSQL, both of which may process and store data in data centers located in the United States. If you access the Platform from outside the United States, your data will be transferred to and processed in the United States. We take appropriate safeguards (contractual clauses, provider data processing agreements) to ensure your data is protected in accordance with this Policy regardless of where it is processed.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:
If you are located in the European Economic Area and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the “Last Updated” date at the top of this page and, where feasible, notify affected users via the Platform or email. Continued use of the Platform after the updated Policy takes effect constitutes your acceptance of the revised Policy.
