Privacy Policy
How Pentragrid Holdings collects, uses, and protects your personal data — including investor contact information — in compliance with GDPR and applicable data protection laws.
Last updated: 1 August 2026
Contents
1. Overview & Data Controller
Pentragrid Holdings Inc. ("Pentragrid", "we", "us", or "our") is committed to protecting the privacy and personal data of all individuals who interact with us, including prospective and existing investors, institutional partners, and website visitors.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data in accordance with the General Data Protection Regulation (GDPR), the Indian Personal Data Protection Act, the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection, and other applicable data protection laws.
Data Controller: Pentragrid Holdings Inc., Global Headquarters, Gurgaon, India. For data protection enquiries, contact: privacy@pentragrid.com
2. Personal Data We Collect
We collect the following categories of personal data:
• Identity Data: Full name, job title, company name, professional designation, and accreditation status (e.g., qualified/institutional investor status).
• Contact Data: Email address, telephone number, postal address, and country of residence.
• Financial & Investment Data: Investment preferences, ticket size ranges, portfolio interests, accreditation documentation, and KYC/AML verification materials where required.
• Communication Data: Records of correspondence, meeting notes, investor inquiry submissions, and responses to our investor relations communications.
• Technical Data: IP address, browser type, device identifiers, pages visited, and time spent on our website, collected via cookies and analytics tools.
• Usage Data: Information about how you use our website, download our materials, and interact with our investor portal.
3. Legal Basis for Processing
We process your personal data on the following legal grounds under GDPR Article 6:
• Legitimate Interests (Art. 6(1)(f)): Processing investor contact data to evaluate investment opportunities, conduct due diligence, and maintain investor relations. We have assessed that our legitimate interests do not override your fundamental rights.
• Contractual Necessity (Art. 6(1)(b)): Where processing is necessary to perform a contract with you or take pre-contractual steps at your request.
• Legal Obligation (Art. 6(1)(c)): To comply with KYC, AML, and financial regulatory requirements applicable in India, UAE, Singapore, and other jurisdictions where we operate.
• Consent (Art. 6(1)(a)): Where you have explicitly consented to receiving investor updates, newsletters, or marketing communications. You may withdraw consent at any time.
4. How We Use Your Data
We use your personal data for the following purposes:
• Investor Relations: To respond to investment inquiries, share investment decks, term sheets, and SPV documentation with qualified investors.
• Due Diligence & Compliance: To verify investor accreditation, conduct KYC/AML checks, and meet regulatory obligations across our operating jurisdictions.
• Communications: To send you relevant updates about our investment rounds, portfolio performance, and corporate developments where you have opted in or where we have a legitimate interest.
• Website Analytics: To understand how visitors use our website and improve user experience. Analytics data is aggregated and does not identify individuals.
• Legal & Regulatory: To comply with court orders, regulatory requests, or legal obligations in any jurisdiction where Pentragrid operates.
5. Data Sharing & Third Parties
We do not sell your personal data. We may share your data with:
• Professional Advisors: Legal counsel, auditors, and compliance consultants bound by confidentiality obligations.
• Regulatory Authorities: Financial regulators, tax authorities, and law enforcement agencies where legally required.
• Service Providers: Technology vendors (CRM, email platforms, analytics) who process data on our behalf under data processing agreements with appropriate safeguards.
• Co-Investors & Partners: Only with your explicit consent or where required to complete a transaction you have initiated.
International Transfers: Where data is transferred outside the EEA or your home jurisdiction, we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions.
6. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy:
• Investor inquiry data: 7 years from last contact, in line with financial record-keeping requirements.
• KYC/AML documentation: As required by applicable financial regulations (typically 5–10 years).
• Website analytics data: 26 months from collection.
• Marketing consent records: Until consent is withdrawn plus 3 years.
After the applicable retention period, data is securely deleted or anonymised.
7. Your Rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
• Right of Access (Art. 15 GDPR): Request a copy of the personal data we hold about you.
• Right to Rectification (Art. 16): Request correction of inaccurate or incomplete data.
• Right to Erasure (Art. 17): Request deletion of your data where there is no compelling reason for continued processing.
• Right to Restrict Processing (Art. 18): Request that we limit how we use your data.
• Right to Data Portability (Art. 20): Receive your data in a structured, machine-readable format.
• Right to Object (Art. 21): Object to processing based on legitimate interests, including direct marketing.
• Right to Withdraw Consent: Where processing is based on consent, withdraw it at any time without affecting prior lawful processing.
To exercise any of these rights, contact us at privacy@pentragrid.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
9. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, destruction, or alteration. These include:
• Encryption of data in transit (TLS/SSL) and at rest.
• Access controls limiting data access to authorised personnel only.
• Regular security assessments and staff training.
• Incident response procedures to address data breaches promptly.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours and inform affected individuals without undue delay.
10. Contact & Updates
For any questions, requests, or concerns regarding this Privacy Policy or our data practices, please contact:
Data Protection Officer (DPO): privacy@pentragrid.com
Postal Address: Pentragrid Holdings Inc., Global Headquarters, Gurgaon, Haryana, India
This Privacy Policy was last updated on 1 August 2026. We may update this policy periodically to reflect changes in our practices or applicable law. Material changes will be communicated via email to registered contacts or prominently on our website.
Questions about your data?
Contact our Data Protection Officer directly.