GestaltArena
Data Protection & Privacy Framework

Privacy Policy

Global GDPR & CCPA Compliance Notice | Gestalt Technologies (Pvt) Ltd

Commitment to Global Data Privacy

Gestalt Technologies (Private) Limited ("GTPL", "we", "us") enforces a strict, institutional-grade data privacy framework. This policy dictates how Gestalt Arena collects, processes, and encrypts your personal, corporate, and financial data in stringent accordance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and applicable international data protection mandates.

1. Information Collection & Processing

We collect specifically categorized data streams to facilitate secure digital matchmaking: Identity Data (names, corporate affiliations, KYC/AML verification flags), Financial Metadata (anonymized ticket sizes, valuation parameters, funding goals), and Telemetry Data (IP addresses, browser signatures, session cookies). We operate on the principle of data minimization; only data strictly necessary for fulfilling contractual obligations and ensuring platform integrity is processed.

2. Public Directory vs. Encrypted Deal Rooms

Gestalt Arena bifurcates data visibility. Baseline profiles (company name, industry, investment thesis) are indexed globally for discoverability. Conversely, proprietary documents—including pitch decks, term sheets, direct messages, and capital transfer proofs—are strictly localized to authenticated, participant-restricted Deal Rooms. GTPL does not mine or expose Deal Room contents to unauthorized third parties or global search engines.

3. International Rights (GDPR & CCPA)

Regardless of your geographic jurisdiction, GTPL guarantees your statutory rights. EU/UK Residents (GDPR): You retain the absolute right to data access, rectification, portability, and erasure (the "Right to be Forgotten"). California Residents (CCPA/CPRA): We unequivocally state that GTPL does not and will not sell your personal data or corporate metadata to third-party data brokers. You have the right to request a comprehensive disclosure of data processing categories.

4. Security Architecture & Retention

All data in transit is secured via TLS 1.3, and data at rest is protected utilizing AES-256 encryption. While GTPL deploys commercial best practices to protect your data, no digital architecture is completely invulnerable. Data is retained only for the lifecycle of your active account, plus any mandatory legal archiving periods required for financial compliance and anti-fraud auditing.

5. Legal Inquiries & Data Subject Requests

To exercise your regulatory rights, execute a data export, or initiate an account deletion mandate, please submit a formal Data Subject Access Request (DSAR) to our Data Protection Officer (DPO) via encrypted channel at gestalttech.pltd@gmail.com.