BITS-SPARK Angels

BITS-SPARK Angels

Privacy Policy

Effective Date: June 29, 2026  ·  Last Updated: June 29, 2026

BITS-SPARK Angels (“we,” “our,” or “us”) operates the BITS-SPARK Angels Investment Management Platform (the “Platform”) — an invite-only portal that facilitates angel investment activities for BITS alumni and associated founders. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and the rights you have over it. By using the Platform, you agree to the practices described in this Policy.


1. Who This Policy Applies To

This Policy applies to all users of the Platform, including:

  • Angel Investors — BITS alumni and other accredited investors who review deals and make commitments.
  • Founders / Startups — Company representatives who submit their startups for evaluation.
  • Committee Members — Screening and investment committee reviewers.
  • Administrators — Platform operators managing users, deals, and settings.
  • Volunteers — Supporting members with limited access.

2. Information We Collect

2.1 Information You Provide Directly

  • Account credentials: email address and hashed password (bcrypt, 12 rounds).
  • Investor profile: first, middle, and last name; city, state, and country; phone number; LinkedIn profile URL; BITS batch year and campus (Pilani, Goa, Hyderabad, Dubai); current employer and role; industry expertise and investment interests; typical investment amount and prior investment experience; investing entity (self or company) and company name.
  • Founder / startup profile: company name, sector(s), funding stage, incorporation details, product description, amount sought, LinkedIn company page, and one-pager document URL.
  • KYC & accreditation documents: uploaded files (e.g., ID proof, accreditation certificates) stored as secure URLs.
  • Tax documents: documents such as Form 16, investment summaries, and capital call notices, linked to your account.
  • Banking information: account details submitted for wire transfers and distributions.
  • Investment data: commitment amounts, wiring dates, SPV allocation amounts, ownership percentages, and subscription agreement URLs.
  • Due diligence materials: financial statements, cap tables, legal documents, and other files uploaded by founders or reviewers.
  • Event RSVPs: attendance confirmation or decline for platform events.
  • Communications: messages and notes exchanged through the platform's Q&A and DD messaging features.
  • Additional comments: any free-text information you voluntarily provide in profile fields.

2.2 Information Collected Automatically

  • Session data: JSON Web Token (JWT) stored in an HTTP-only, Secure, SameSite=Lax cookie containing your user ID, role, and session expiry.
  • Last login timestamp: recorded on each successful authentication.
  • Audit log: timestamped records of significant actions (e.g., role changes, status updates, KYC decisions) linked to your user ID.

2.3 Information from Third Parties

  • LinkedIn (OAuth 2.0 / OpenID Connect): when you connect your LinkedIn account, we receive your LinkedIn member ID, public profile data, and an access token with its expiry. We store only what is needed to identify your LinkedIn profile and do not post on your behalf.
  • WhatsApp Business API (Meta): if you opt in to WhatsApp notifications, we collect and store your WhatsApp number and process inbound/outbound messages through Meta's Cloud API. We record opt-in consent explicitly.

3. How We Use Your Information

PurposeData UsedLawful Basis
Account creation & authenticationEmail, password hash, JWT sessionContract performance
Investor profile & KYC managementPersonal, financial, and document dataContract performance / Legal obligation
Deal evaluation & committee reviewStartup data, evaluation scores, notesLegitimate interests
Commitment & SPV managementInvestment amounts, wire details, allocation dataContract performance
Portfolio updates & reportingPortfolio data, update contentContract performance / Legitimate interests
Event management & RSVPsName, email, RSVP statusConsent / Legitimate interests
WhatsApp notificationsWhatsApp number, message contentConsent
LinkedIn profile enrichmentLinkedIn ID, access token, profile dataConsent
Platform security & auditIP address, user ID, action logsLegitimate interests / Legal obligation
Tax reportingTax documents, startup linkage, notesLegal obligation

4. How We Share Your Information

We do not sell your personal information. We share it only in the following limited circumstances:

  • Within the Platform: investor deal activity (excluding personal contact details) is visible to other investors on the same deal; startup data is visible to committee members and admins as appropriate to their role.
  • Service providers:
    • Neon (PostgreSQL hosting): all application data is stored on Neon's serverless PostgreSQL service, governed by Neon's data processing agreement.
    • Amazon Web Services (ECS, ECR, ALB): infrastructure hosting. AWS acts as a data processor under our instructions.
    • LinkedIn (Microsoft): OAuth authentication and profile data retrieval.
    • Meta Platforms: WhatsApp Business Cloud API for opted-in messaging.
  • Legal compliance: we may disclose information when required by applicable law, court order, or governmental authority.
  • Business transfers: in the event of a merger, acquisition, or asset sale, your information may be transferred, subject to the same protections described here.

5. Data Security

  • Encryption in transit: all traffic is served over HTTPS with TLS 1.3 enforced by AWS ALB. HSTS is set with a 2-year max-age, includeSubDomains, and preload.
  • Encryption at rest: sensitive fields (e.g., LinkedIn access tokens) are encrypted using AES-256-GCM before storage. Neon PostgreSQL storage is encrypted at rest by the provider.
  • Password security: passwords are never stored in plain text; they are hashed with bcrypt using 12 salt rounds.
  • Session security: JWT session cookies are HTTP-only, Secure, and SameSite=Lax to mitigate XSS and CSRF risks. Security headers (X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy) are applied at the application layer.
  • Role-based access control: every API route enforces authentication and role checks via server-side middleware. Users can only access data their role is permitted to see.
  • Audit logging: significant data mutations are recorded in an immutable audit log.

Despite these measures, no system is completely secure. We encourage you to use a strong, unique password and to report any suspected security incidents to us immediately.


6. Data Retention

We retain personal data for as long as your account is active or as needed to fulfil the purposes described in this Policy, comply with legal obligations, resolve disputes, and enforce agreements.

  • Active accounts: retained for the duration of your membership.
  • Closed/inactive accounts: personal profile data is retained for a minimum of 7 years to satisfy financial record-keeping obligations under applicable law.
  • Investment & tax records: retained for 10 years from the date of the relevant transaction, in compliance with financial regulatory requirements.
  • Audit logs: retained for 5 years.
  • LinkedIn access tokens: invalidated when you disconnect your LinkedIn account or when the token expires.
  • WhatsApp messages: retained for 12 months from the date sent.

7. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access: request a copy of the personal data we hold about you.
  • Correction: request correction of inaccurate or incomplete data.
  • Deletion: request deletion of your data where we no longer have a lawful basis to retain it (subject to financial record-keeping obligations).
  • Restriction: request that we restrict processing of your data in certain circumstances.
  • Portability: receive your data in a structured, machine-readable format where technically feasible.
  • Objection: object to processing based on legitimate interests.
  • Withdraw consent: where processing is based on consent (e.g., WhatsApp opt-in, LinkedIn connection), you may withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at the address in Section 11. We will respond within 30 days. We may need to verify your identity before acting on your request.


8. Cookies & Tracking

The Platform uses a single, strictly necessary HTTP-only session cookie to maintain your authenticated session. We do not use:

  • Third-party advertising or tracking cookies.
  • Analytics cookies (e.g., Google Analytics).
  • Persistent marketing identifiers.

Because we only use a strictly necessary session cookie, a cookie consent banner is not required under most cookie laws. If our cookie practices change, we will update this Policy accordingly.


9. Children's Privacy

The Platform is intended exclusively for adults (18 years or older) who meet the eligibility criteria for angel investing or startup participation. We do not knowingly collect personal data from individuals under 18. If we become aware that a minor has provided us with personal data, we will delete it promptly.


10. International Data Transfers

The Platform is hosted on AWS infrastructure and uses Neon PostgreSQL, both of which may process and store data in data centers located in the United States. If you access the Platform from outside the United States, your data will be transferred to and processed in the United States. We take appropriate safeguards (contractual clauses, provider data processing agreements) to ensure your data is protected in accordance with this Policy regardless of where it is processed.


11. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact:

BITS-SPARK Angels

Privacy & Data Protection

Email: privacy@bitsspark.com

If you are located in the European Economic Area and believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection authority.


12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will update the “Last Updated” date at the top of this page and, where feasible, notify affected users via the Platform or email. Continued use of the Platform after the updated Policy takes effect constitutes your acceptance of the revised Policy.

© 2026 BITS-SPARK Angels. All rights reserved.