PRIVACY POLICY
Polaris — Founder, Investor and Trusted Partner Platform
Effective Date: 25 August 2026
Last Updated: 25 August 2026
This Privacy Policy explains how Anjanajyoti Healthtech Private Limited (“Polaris”, “we”, “us” or “our”) collects, uses, stores, discloses and protects information in connection with the Polaris platform, including www.inpolaris.com, inpolaris.com, the web application and associated routes, including the administrator portal at /admin.
1. Who We Are
The Polaris platform is operated by Anjanajyoti Healthtech Private Limited, a private limited company incorporated in Delhi, India.
Registered office: A-3, Ground Floor, Greater Kailash Enclave 1, New Delhi 110048, India.
CIN: U62013DL2023PTC421923. PAN: AAZCA6036A.
For privacy, legal and grievance matters, contact: support@anjanajyoti.org.
2. Scope of This Policy
This Policy applies to information processed through the Polaris website, web application and related platform services. It covers Founders, Investors and Trusted Partners, as well as visitors and persons who interact with Polaris in connection with those services.
At launch, India is the active commercial market. EEA, UK and US users are not intended to be accepted as commercial users at launch. International expansion will be accompanied by jurisdiction-specific privacy notices and terms where legally necessary.
3. Information We Collect
3.1 Identity and Contact Information
Name and other identity information you provide.
Mobile or WhatsApp number and email address.
Information needed to authenticate your account and communicate with you.
3.2 Authentication and Consent Information
OTP and session identifiers, verification status, consent versions, timestamps and related authentication records.
OTP codes are stored as hashes and are not retained in plaintext.
3.3 Founder Information
LinkedIn/profile information.
Startup name and company formation/incorporation documents.
Sector, stage, geography, team information and fundraising ask.
Financial and fundraising information.
Pitch decks and other documents uploaded through relevant workflows.
3.4 Investor Information
Individual or entity details and LinkedIn/profile information.
Investment sectors, stages and geographies.
Typical cheque size and investment preferences.
Verification information.
3.5 Trusted Partner Information
Individual or entity details and firm information.
Service category, credentials and verification documents.
Subscription/listing information and lead activity.
3.6 Transaction and Payment Information
Plans, credits, payment/order identifiers, amounts, currency, invoices/receipts and payment status.
Payment card and bank credentials should remain with the applicable payment provider and are not intended to be stored by Polaris.
3.7 Platform, Usage, Support and Technical Information
Introductions, bookmarks, notifications, audit/security logs and timestamps.
Support, complaint and dispute information.
Technical information reasonably necessary for platform operation and security.
4. How We Use Information
Depending on the role, service and applicable law, Polaris may use information to:
Create and administer accounts and provide platform services.
Authenticate users and maintain account and platform security.
Review and manually verify profiles before publication.
Operate Founder, Investor and Trusted Partner discovery and matching workflows.
Facilitate approved introductions and, where the workflow permits, share additional contact or profile information after the relevant event or consent.
Display profile information to the categories of users permitted by the applicable visibility rules.
Process subscriptions, credits, payments, invoices, refunds and payment disputes.
Prevent fraud, abuse, scraping, circumvention, security incidents and other prohibited activity.
Respond to support requests, complaints, appeals and legal requests.
Maintain audit, security, compliance and operational records.
Comply with applicable law and enforce our agreements and policies.
5. Automated Matching and AI Transparency
At the current launch state reflected in the completed legal intake, Polaris does not have an external generative-AI provider wired into the production application. The current discovery/ranking function is a deterministic, rules-based relevance system.
The current ranking materially considers sector overlap, then investment-stage overlap and geography overlap, with recently updated profiles used as a tie-breaker.
A ranking is an automated platform relevance output. It is not an investment recommendation, prediction of success, guarantee of compatibility, guarantee of funding, or professional advice.
At launch, automated matching/ranking does not by itself approve or reject profiles, determine verification, suspend accounts, set pricing or make investment-suitability decisions. Verification and enforcement decisions remain subject to human review.
No user content is currently used to train or improve a Polaris model or a third-party model based on the production position described in the intake. If an external AI provider or materially different AI functionality is introduced, Polaris will update its privacy and AI transparency disclosures and implement appropriate legal and contractual safeguards.
6. Legal Bases and Consent
Polaris will process information on the legal basis applicable to the relevant processing and jurisdiction. For India, processing will be carried out in accordance with applicable data-protection law, including the Digital Personal Data Protection Act and Rules in force at the relevant time.
Transactional and service communications may be processed as necessary for the account and service relationship, with consent recorded where required, including where required for WhatsApp authentication.
Marketing communications, newsletters and partner promotions will use separate affirmative opt-in consent where required by applicable law. Users may withdraw marketing consent through the available unsubscribe or preference mechanism.
7. Profile Visibility and Disclosure
Polaris does not make all information available to all users. Visibility depends on the user's role, the relevant workflow and the applicable consent or access state.
Public information consists only of information intentionally published in a public directory or profile and designated as public in the product.
Founders cannot discover other Founders through the platform.
Investors are not generally visible to other Investors.
Matched/discoverable users see only the fields permitted by the applicable role and visibility state.
After an approved introduction, additional contact or profile information may be shared according to the workflow and applicable consent.
Pitch decks, financials and confidential documents are restricted to authorised/matched Investors and Polaris Super Admins as applicable.
KYC/verification evidence, private documents, payment records, OTP/session data, consent records, audit/security logs, moderation notes and administrative data are internal.
8. Verification Information
Polaris may manually verify information before a profile is published. Verification may use government and public internet sources and information supplied by the user.
A Verified badge means that specified information submitted at profile creation or during the applicable verification process was reviewed or checked by Polaris. It does not guarantee that every item of information is complete, current or accurate, and it is not a guarantee of suitability, professional quality, funding, investment interest or any commercial outcome.
Polaris may reject, suspend, revoke or require renewed verification where information is inaccurate or misleading, verification is no longer reliable, or the user breaches applicable guidelines or policies.
9. Confidential and Uploaded Information
Users may upload confidential business information and supporting materials where the relevant workflow permits. Users must have the right and authority to provide that information and must obtain any permissions required for personal data or third-party intellectual-property material.
Polaris processes uploaded information to provide the service, including account operation, matching, verification, security and service delivery. Non-public confidential documents are not intended for public marketing.
Users should not upload information they are prohibited from disclosing and should minimise unnecessary sensitive personal data.
10. Third-Party Service Providers
Polaris uses or may use third-party providers to operate the platform. The launch intake identifies AWS Amplify for hosting/deployment, MongoDB Atlas for the production database, Google Workspace/Gmail for business email, and Twilio WhatsApp infrastructure for authentication once production activation is completed.
Razorpay is the intended first live payment provider once approved and configured. Cashfree is a stated commercial option but was not wired into the production code reviewed for the intake. Payment providers process payment information in their own systems.
The exact MongoDB Atlas production region and current vendor subprocessor/data-transfer arrangements must be confirmed from the applicable vendor documentation before final publication. Where third parties process personal information on Polaris's behalf, Polaris will use appropriate contractual and organisational safeguards as required by applicable law.
11. International Transfers and Access
At launch, India is the active commercial market. Polaris staff and authorised service providers may access information from India and other locations as necessary for authorised operations.
International data hosting, access and transfers may occur through vendors depending on their infrastructure and configuration. Applicable transfer requirements and safeguards will be assessed based on the relevant jurisdiction and vendor arrangements. Jurisdiction-specific notices or contractual terms may be introduced when Polaris expands internationally.
12. Cookies and Similar Technologies
Polaris may use essential cookies and similar technologies necessary for authentication, session management, security and operation of the platform. The launch intake does not approve advertising pixels or third-party advertising trackers, and no separate third-party analytics provider is currently approved in the reviewed production code.
If analytics, advertising or other non-essential tracking technologies are introduced, Polaris will update its Cookie Policy and obtain consent where legally required.
13. Data Sharing and Disclosure
Polaris may disclose information:
To authorised users where permitted by the applicable role and platform workflow.
To service providers that process information for hosting, database, authentication, communications, payments, security or related operations.
Where necessary to verify information using public or government sources.
Where required by law, court order, regulatory request or lawful process.
Where reasonably necessary to detect, prevent or address fraud, security incidents, abuse, unlawful conduct or other material risks.
To professional advisers, auditors or other authorised persons where reasonably necessary and subject to appropriate confidentiality obligations.
In connection with a corporate transaction, restructuring or transfer of relevant business assets, subject to applicable law and appropriate safeguards.
14. Data Security
Polaris maintains technical and organisational controls appropriate to the nature of the information and the risks involved. The launch controls identified in the intake include:
TLS/HTTPS for information in transit.
Encryption at rest through AWS, MongoDB and other vendor-managed infrastructure where provided.
Passwordless OTP authentication.
Hashed OTP storage, OTP expiry, cooldown and lockout controls.
Role-based access control and administrative permissions.
Least-privilege access to production systems.
Administrative audit logging.
Database indexes and TTL cleanup for OTP/session records.
Secure secret storage rather than storing secrets in source code.
Backups and restoration capability through the production database/provider.
Monitoring and incident-response procedures.
Vendor access controls and periodic security/dependency updates.
No method of transmission or storage can be guaranteed to be completely secure. Users should also protect access to their devices, email accounts and mobile/WhatsApp accounts.
15. Data Retention
Polaris retains information only for as long as reasonably necessary for the purposes described in this Policy, to provide services, maintain security, resolve disputes, comply with legal obligations and enforce agreements.
Account/profile information should generally be deleted or anonymised after closure when no longer necessary, subject to applicable exceptions.
KYC/verification records, invoices, tax records, payment records, disputes/refunds and statutory accounting records may be retained for legally required periods.
Security/audit logs, introductions and consent records may be retained for defined security or compliance periods.
Backups may persist until their normal rotation or expiry period.
Specific retention periods may vary by data category and applicable law.
16. Your Privacy Rights and Requests
Subject to applicable law and legitimate exceptions, users may request access to, correction of, deletion/erasure of, restriction of or a copy of their personal information.
Requests should be sent to support@anjanajyoti.org and may require reasonable identity verification.
Polaris will acknowledge requests promptly and ordinarily respond within the statutory period applicable to the request and jurisdiction. For India, the process will be aligned with the Digital Personal Data Protection Act and Rules in force at the time of the request.
17. Data and Security Incident Response
Suspected personal-data or security incidents are to be escalated internally to the designated security/privacy owner and authorised management/legal contact. Polaris's incident process is intended to include containment, evidence preservation, assessment of scope and affected information, credential revocation or rotation, remediation, documentation, determination of notification obligations and corrective action.
Where legally required, Polaris will notify affected users, regulators or other relevant parties within applicable timelines.
18. Marketing Communications
Providing a mobile number, WhatsApp number or email address for account creation does not by itself constitute consent to marketing. These channels may be used for authentication, transactional/service notifications, security notices and account communications. Marketing, newsletters and partner promotions require separate consent where required by law and must provide an appropriate withdrawal mechanism.
19. Children's Privacy
Polaris is intended for users who are at least 18 years old and legally capable of entering into the relevant agreement, or such higher minimum age as may apply under the law of the user's country. Polaris does not knowingly seek to provide commercial services to persons who do not meet the applicable age and legal-capacity requirements.
20. Changes to This Privacy Policy
Polaris may update this Policy when its services, processing activities, vendors, legal requirements or privacy practices change. Material changes will be notified in advance where reasonably practicable and where required by law. Immediate notice may be provided where necessary for security, legal compliance or urgent operational reasons.
The English version is the launch version. Future translations may be provided for international markets. Where a translation conflicts with the English version, the English version will control unless applicable local law requires otherwise.
21. Contact and Grievance Details
Privacy, legal and formal grievance contact:
Anjanajyoti Healthtech Private Limited
A-3, Ground Floor, Greater Kailash Enclave 1
New Delhi 110048, India
Email: support@anjanajyoti.org
Operational/platform support is available at support@inpolaris.com. A formally designated Privacy/Data Protection/Grievance Officer should be appointed before publication where applicable law requires a specific named officer.
22. Important Launch Dependencies
This Policy is based on the completed Polaris Legal Launch Intake Questionnaire. Before public commercial launch, Polaris should confirm the following matters identified in that intake:
Final production payment provider(s) and their approval/configuration status.
Twilio WhatsApp production approval, sender/template and production credentials.
Exact MongoDB Atlas production region and vendor subprocessor/data-transfer terms.
Formal appointment and name of the Privacy/Data Protection/Grievance Officer where required.
Final legal review of Indian data-protection, consumer, payment, advertising and platform-regulation requirements.
Local counsel review before international commercial expansion.
This Privacy Policy is intended to form part of Polaris's launch legal framework and should be read together with the Polaris Terms of Service, Cookies Policy and Payments and Refund Policy.
— End of Privacy Policy —
Legal
Privacy Policy
Version v1.0·Effective from 25 Aug 2026·Published 25 Aug 2026