Privacy Policy

DPDP Act 2023 & SEBI Cybersecurity Compliant Data Governance

DPDP Act 2023 Active
Data Fiduciary & Platform Information

This Privacy Policy governs data processing by Crucible ("Data Fiduciary", Public Beta Edition, engineered by Priyankit Raj), acting in compliance with the Digital Personal Data Protection (DPDP) Act, 2023 and applicable SEBI guidelines.

Contact Desk: support@crucible.trade

Last Updated: August 2026 • Formulated under India's DPDP Act, 2023, IT Rules 2021, and SEBI Cybersecurity Guidelines.

1. Lawful & Consent Basis for Data Collection (DPDP Act 2023)

Crucible collects and processes personal digital data only on the following statutory grounds:

  • Explicit User Consent: When you register an account, configure strategy parameters, or link broker API tokens.
  • Performance of Contract: To execute user-initiated backtests, route orders through connected broker APIs, and maintain active subscriptions.
  • Legal & Regulatory Compliance: To satisfy mandatory exchange and SEBI audit log preservation requirements for algorithmic software vendors.

2. Broker API Key Vault & Cryptographic Architecture

Crucible implements authenticated AES-256-GCM encryption for storing broker API secrets, permanent OAuth access tokens, and TOTP secrets. Raw credentials are encrypted client-side/in-memory prior to database insertion.

  • We do NOT store, log, or request trading passwords, 6-digit MPINs, or bank account PINs.
  • All database queries enforce PostgreSQL Row-Level Security (RLS) ensuring strict multi-tenant isolation by authenticated User ID.
  • Broker communications operate strictly over TLS 1.3 encrypted secure sockets.

3. Data Retention Schedules (Non-Regulatory vs SEBI Statutory Logs)

In strict observance of data minimization principles under the DPDP Act 2023 alongside regulatory retention laws, Crucible bifurcates data retention:

Data CategorySpecific Data ElementsRetention PeriodDPDP Erasure Eligibility
Non-Regulatory User DataAccount profile, email, UI settings, session tokens, optional preference tags.Active account duration + 90-day grace period post-cancellation.100% Eligible upon verified erasure request.
SEBI Statutory Telemetry & Audit LogsSHA-256 strategy hash audit trail, Algo-ID tags, trade timestamps, order fill/rejection telemetry.5 Years Mandatory (as required by SEBI Algo Circulars & PMLA rules).Exempt from erasure until 5-year statutory period lapses.

4. Zero Data Selling & Neutrality Policy

We strictly do NOT sell, rent, monetize, or broker your trading data, strategy algorithms, order logs, or performance metrics to third-party hedge funds, high-frequency traders, brokerages, or proprietary desks.

5. Data Principal Rights (DPDP Act, 2023)

Under Chapter III of the Digital Personal Data Protection Act, 2023, you possess the following enforceable rights:

  • Right to Access Information: Request a comprehensive summary of your personal data processed by Crucible and the identities of third-party processors.
  • Right to Correction & Updating: Correct inaccurate, incomplete, or outdated credentials directly via Broker Settings or support request.
  • Right to Erasure / Deletion: Request permanent deletion of non-regulatory personal data, saved strategy code, and vaulted credentials (subject to statutory SEBI audit retention).
  • Right of Grievance Redressal: Avail readily accessible grievance redressal mechanisms before the Data Protection Board of India.
  • Right to Nominate: Nominate an individual who shall exercise your data rights in the event of death or incapacity.
How to Exercise Your DPDP Data Rights:

To exercise any of the above rights, send a written request from your registered email address to our Data Protection & Grievance Officer at support@crucible.trade. Please include your User ID and specify the right being invoked.

SLA: Receipt acknowledged within 24 to 48 business hours; completed within 15 to 30 business days.

6. Statutory Grievance Redressal Officer (IT Rules 2021 & DPDP Act 2023)

In compliance with Section 12 of the Digital Personal Data Protection Act, 2023 and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021:

Officer Name: Priyankit Raj
Designation: Platform Architect & Grievance Contact
Platform: Crucible (Public Beta)
Email: support@crucible.trade
Alternate Security Desk: support@crucible.trade
Turnaround SLA: Acknowledged within 24 to 48 business hours; resolution within 15 to 30 business days.