This policy applies to information processed by M/s. Nexora Technologies, a sole proprietorship (“Nexora”, “we”), in the course of providing its software products — including Investra MFD and Vault Backoffice — and the capital markets platform while it is in build; software we design, build, host or support for a customer to order; the website at nexoratechnologiesnagpur.com; and any related services (collectively, the “Services”).
Where Nexora processes information on behalf of a customer (a business using one of our products, or one whose software we build or run), our customer is the controller under DPDP / GDPR vocabulary and Nexora acts as the processor. In that scenario, this policy describes Nexora’s own processing only — the controller’s own privacy notice governs end-user relationships.
We collect only what we need to provide the Services and to meet our legal obligations. The categories are:
- Account information. Names, work emails, phone numbers, employer of record, and the role each person holds within a customer organisation.
- KYC information. Where a customer uses the KYC and onboarding features of our capital-markets software, we process PAN, Aadhaar (masked at rest), name, date of birth, address, occupation, and any documents the user uploads.
- Trading metadata. In our capital-markets software: orders, fills, cancellations, and the audit trail entries those actions generate.
- Information in software we run for a customer. Where we build, host or support a system for a customer, the personal information that system holds, processed on the customer’s instructions.
- Technical telemetry. IP addresses, user agents, request IDs, and latency metrics.
We process personal information under one or more of the following bases: performance of contract; legal obligation (for capital-markets services, notably SEBI, NSDL, CDSL and bank-rail rules); legitimate interests in operating, securing, and improving the Services; and explicit consent for optional features (e.g. CKYC registry lookup).
Where consent is the basis, you can withdraw it at any time — though doing so may make some of the Services unusable, and we will say so explicitly.
Records are retained for the period required by applicable law plus a short grace window:
- Audit and order records (capital-markets services): 10 years, per SEBI requirements.
- KYC records (capital-markets services): 8 years after relationship closure, per PMLA.
- Account information: while the customer relationship is live, plus 24 months.
- Technical telemetry: 90 days for operational logs; 30 days for raw request traces.
Information held in software we build or run for a customer is retained for as long as that customer instructs, subject to the law that applies to it.
Subject to applicable law, you can request access to the personal information we hold about you, correction of inaccuracies, erasure, and a portable copy. Some rights are limited by our regulatory retention obligations — we cannot, for example, delete an order record before its statutory retention has elapsed.
Send requests to privacy@nexoratechnologiesnagpur.com. We respond within 30 calendar days.
Nexora operates a control environment designed against the ISO 27001 and SEBI CSCRF frameworks; neither attestation has been obtained yet. Across the systems Nexora operates, encryption at rest (AES-256) and in transit (TLS 1.3) is universal; access to production systems is MFA-enforced, audited, and limited to operational necessity. Full posture detail lives in the Trust Center.
Questions about this policy can go to our Data Protection Officer at dpo@nexoratechnologiesnagpur.com. For unresolved concerns, you may contact the Data Protection Board of India.