Legal
Privacy notice
Last updated 28 September 2026
Who we are
Deal Network Private Limited ("Deal Network", "we") operates The Deal Network at dealnetwork.in, app.dealnetwork.in, admin.dealnetwork.in and api.dealnetwork.in. This notice describes the data the product actually handles today. For rights requests write to admin@dealnetwork.in from the email on the account, or use account closure in member Settings.
What we collect
We collect only what the product needs to run a private professional network and deal workspace:
- Waitlist data: your name, work email, WhatsApp number and the profession you select (including any description you give under Other), together with when you agreed to receive a confirmation and launch updates. Joining the waitlist does not create a member account. We use these details to manage launch access and contact you on WhatsApp; reply STOP to opt out, or email admin@dealnetwork.in for a data request. Messages sent during the waitlist period are retained, but the assistant does not reply.
- Account data: name, verified WhatsApp mobile number, email where one is provided, password hash where a password was set, referral attribution and account status.
- WhatsApp conversations with Deal Network: one-time sign-in codes and links, messages you send to our AI assistant and its replies, replies from our team, and the news updates we send you, with a record of why each update was sent, held back or not sent. Message content, including the text of each news update, is encrypted at rest and every staff read is audited.
- Professional identity: ICAI or ICSI membership evidence for chartered accountants and company secretaries; for institutional professionals, a work email address verified by a one-time code, a LinkedIn profile link, the institution, role and short description given, and the short advisory screening summary our review team reads; where a member gives a LinkedIn profile link (required for institutional professionals, optional for chartered accountants and company secretaries), the public profile data we read once to draft a summary and starting profile for the member to review, kept encrypted until the member uses or dismisses the draft; where that lookup also returns the industry, interests, date of birth or gender the provider holds, industry and interests inform the draft, and date of birth and gender fill only the matching optional profile fields the member has not set, kept encrypted, visible to the member to correct or clear and to our review team, never shown to other members or sent to an AI model, and erased when the member closes their account; we do not request personal email addresses or phone numbers from that provider; profile details; and DigiLocker Aadhaar document bytes which are encrypted at rest. We do not store Aadhaar numbers, OTPs, photos, date of birth, gender or address from that flow.
- Companies you tell us about, such as your clients: a company's name where you give one, what it does, where it is, its financial bands, whether it wants to sell, raise or acquire, and what you say about its owners' openness to a deal, in your own words and as the stance you confirm. You may tell us about a company without its consent; see Company information you share in our terms. Names, openness notes and free-text details are encrypted at rest and shown only to you. Other members see only a masked description until you choose to share more. Once the MCA register confirms a company's name, we also note what a web search says the company does, such as its industry, products and website; where that differs from what you told us, we ask you which is right, and what you say always wins.
- Asks and introductions: for an institution, what it is looking for (the kind of capital, industry, places and size, and up to three specifics in its own words), whether it chooses to show its name, and any fund or mandate deck it sends us; for a member who knows a company, their answers to our questions about it and whether they put it forward; the questions and answers relayed between the two sides and what each chose to share; the introductions made; and how each side later says an introduction went. Specifics, relayed words, shared details and everything read from a deck are encrypted at rest.
- Files you send us about a company or a listing, such as financial statements, annual reports, decks and GST returns: we store them privately, read them to propose details you confirm one at a time, and never show a file to another member. What a file about a company in your book says, including the names and numbers it shows, is encrypted at rest. Our team does not open Word, PowerPoint or Excel originals; where it needs to, it reads the text we extracted, and every such read is audited.
- Listings, matches, Deal Workspace records, diligence files, call recordings, transcripts, meeting summaries and legal signing artifacts.
- Provider evidence needed to reconcile email, signing, KYC, company intelligence and object storage — stored as bounded status, identifiers and encrypted snapshots, not as credentials or raw secrets.
- Product analytics on marketing and member surfaces only (PostHog). Admin never initializes analytics.
Processors
Depending on the enabled environment profile, Deal Network uses these processors to provide the service. A runtime “enabled” flag is not by itself proof that a capability has passed acceptance.
- Google Cloud (Cloud Run, Cloud SQL, Cloud Storage, logging and monitoring) for hosting, database, private objects and operations.
- Google Cloud Document AI (Layout Parser), processing in the European Union, to read the PDFs and Word, PowerPoint and Excel files you send. Each file is copied to a private storage bucket in the European Union for the read, and the copy and what was read are deleted as soon as we have the text, and within a day at the latest. Google does not use the files for any other purpose.
- Resend for transactional email.
- Meta Platforms (WhatsApp Business Platform) for WhatsApp messages: one-time sign-in codes, conversations with our AI assistant, one-time sign-in links, signing reminders and occasional news about your listings, matches, asks and the companies you know.
- Daily for private call rooms, recording and transcripts.
- OpenRouter for structured generation inside the intelligence boundary. For WhatsApp news updates, OpenRouter sends each request only to Google Cloud Vertex AI, under zero data retention. The model that decides on and writes the news reads masked listing, ask and company labels, the kind and age of each piece of news, verification status and fit tiers, and never names, phone numbers, message text or company identifiers. Before written news is sent, a check on the same route reads the draft with the other side's company names, director names and locality, only to confirm the draft does not reveal them. For the judgement calls in matching an institution's ask to the companies members know, OpenRouter likewise sends each request only to Google Cloud Vertex AI under zero data retention; that model reads the ask's structured fields and specifics, a company's industry, place, size bands and the facts its holder gave or accepted from a file, and the holder's own note on its owners' openness.
- LiveKit Cloud with Sarvam and an OpenAI Realtime fallback for voice conversations.
- Zoho Sign India for listing-party consent and pre-signing envelopes.
- FileSure for company profile, filings and Pre-DD.
- Sandbox for DigiLocker-based professional Aadhaar verification and, where enabled, for searching the MCA company register by name to confirm the name of a company you tell us about.
- Parallel Web Systems, where enabled, to search the web for what a company does once the MCA register has confirmed its name. We send only the company's registered name and city, never who you are, what you told us about it or whether it wants a deal. Under Parallel's standard terms it may keep what we send and what it finds, and use them to improve and train its services. What it finds helps us place the company in the right industry; the description itself is shown only to you, never to other members. A description is deleted 30 days after no one on Deal Network has the company in their book.
- PostHog EU for product analytics, replay and browser exceptions on marketing and member only. When you join the waitlist, your name, work email, phone number, LinkedIn link and role go to PostHog so our team is notified of the signup in Slack (Slack, Inc.), our internal messaging tool.
- ICSI public membership lookup and a source-controlled ICAI List of Firms index. For institutional applications, a zero-data-retention model provider that reads only the name, email domain, LinkedIn link, institution, role and description supplied, to produce an advisory summary for our reviewers. Where a member gives a LinkedIn profile link, EnrichLayer supplies that public profile's data (and any industry, interests, date of birth or gender it holds), and the same zero-data-retention model provider drafts a career summary and starting profile from it.
Why we use the data
We use this data to create and authenticate accounts, verify professional identity, operate listings and matching, execute pre-signing, run assigned Deal Workspaces, deliver mandatory account-security and deal messages, detect abuse, and keep an audit trail of sensitive reads and mutations. We do not sell personal data. PostHog events are best-effort product telemetry and are never audit evidence or an authorization source.
We also use it to tell you about your network on WhatsApp: when someone is interested in your listing, when a match becomes a connection, when a strong new match appears, and what is happening on your asks and with the companies you know. We raise this in conversation, in one last message before a conversation closes, or in an occasional update, no more than one every two days apart from news of a new connection, and we send nothing unprompted outside 9 a.m. to 8 p.m. India time. An AI model decides whether each such message is worth sending and writes it from masked facts; our code checks every statement it makes against our records, and a message that fails those checks is not sent. Reply Not now to dismiss an update, or STOP to stop all messages.
When an institution tells us what it is looking for, we use the companies members have told us about to find ones that may fit. Code decides what fits; where a judgement call remains, such as whether a company's holder should be asked before the institution hears of it, or whether a company meets one of the institution's specifics, an AI model makes it and our code checks its answer. The institution sees only a masked description until the holder chooses to put the company forward or share who they are. We may occasionally ask you on WhatsApp whether a company you know might suit an institution or about a detail it is missing, pass on a question or answer from the other side word for word, ask you to confirm what you said about a company's owners, and, about two weeks and again two months after an introduction, ask whether you have spoken. An institution's own deck is read only to propose updates to its own mandate and a possible ask, which it confirms. Our founders review this activity, including how often a member's companies draw interest, to keep the network fair; they see a company's name or relayed words only through an audited view.
Retention
Deals are never hard-deleted. A closed or soft-deleted deal stays absent from member paths while its evidence remains attached and admin-inspectable. Account closure ends future access and replaces contact details with a tombstone; it does not erase executed agreements, disclosed identities, downloaded files, audit evidence or deal records that already exist.
Private objects in production Google Cloud Storage have a 30-day soft-delete window. Production Cloud SQL uses backups and point-in-time recovery. Discarding an individual-buy listing draft is a soft state change and does not currently sweep the related net-worth statement; treat that statement as retained restricted data.
Password-reset and email-confirmation links expire after 60 minutes. Verification JWTs cannot be reused as password-reset tokens. WhatsApp sign-in codes expire after 5 minutes and one-time WhatsApp sign-in links after 10 minutes.
Your rights
You may request access, correction, or account closure. We will ask you to prove control of the account email before acting. Some records cannot be erased because they are another party’s transaction evidence or are required for audit, security or legal retention.
Use Settings → Close account in the member application, or email admin@dealnetwork.in. Operators record the request, verify identity, close access, and keep a bounded audit entry. Repeated requests against an already closed account receive the same outcome.
Privacy contact: admin@dealnetwork.in. Privacy notice · Terms of use.
