Privacy Policy
Last updated: March 1, 2026
Syltra ("we", "our", or "us"), operated by Adornet Labs (OPC) Pvt. Ltd., is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at syltra.in and app.syltra.in (the "Service").
By accessing or using the Service, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Mobile number, name, email address, and business details (for advisors and research analysts).
- Profile Information: SEBI registration number and type (RIA/RA), business name, logo, bio, website URL, social media links, and contact details.
- Client Data: Client names, mobile numbers, email addresses, PAN numbers (optional, encrypted at rest), city, risk profile, tags, and advisor notes as entered by advisors.
- Content: Portfolio details, stock allocations, update messages, PDF attachments, and disclaimer text uploaded to the platform.
- Payment Information: Billing details processed through our payment partner Razorpay. We do not store your credit/debit card numbers directly.
1.2 Information Collected Automatically
- Device Information: IP address, browser type, device type, operating system, and user agent string.
- Usage Data: Pages visited, features used, time spent on updates (for acknowledgement tracking), and interaction patterns.
- Audit Data: IP addresses and timestamps for all auditable actions, retained per SEBI compliance requirements.
- Cookies: Session cookies for authentication (HTTP-only, secure). We do not use third-party tracking cookies.
2. How We Use Your Information
- To provide, maintain, and improve the Service
- To authenticate users via OTP verification (SMS and email)
- To process subscription payments via Razorpay
- To send transactional notifications (update alerts, account notifications, subscription reminders)
- To maintain SEBI-compliant audit logs and acknowledgement records
- To generate compliance reports for advisors
- To provide customer support
- To detect and prevent fraud, abuse, or unauthorized access
- To analyze usage patterns and improve the platform (anonymized/aggregated data only)
We do not sell, rent, or share your personal information with third parties for marketing purposes. We do not use your data for targeted advertising.
3. Data Sharing & Third Parties
We share data only with the following service providers, strictly for operating the Service:
- MSG91: OTP delivery via SMS and transactional email delivery (receives mobile numbers and email addresses for authentication and notification purposes).
- Razorpay: Payment processing for subscription billing (receives billing information as required for payment processing). Razorpay is PCI DSS Level 1 compliant.
- Cloudflare: CDN, DNS, DDoS protection, and file storage via Cloudflare R2 (processes web requests and stores uploaded files with encryption at rest).
- Railway: Application hosting and server infrastructure (data processed and stored on servers).
- Sentry: Error monitoring and crash reporting (receives anonymized error data for debugging purposes).
- Google Analytics: Website analytics (collects anonymized usage data with IP anonymization enabled).
We do not share, sell, or transfer your personal data to any other third parties. All service providers are bound by their respective privacy policies and data processing agreements.
4. Data Security
We implement industry-standard security measures to protect your data:
- OTP codes are hashed with bcrypt before storage and automatically expire after 10 minutes
- JWT authentication with short-lived access tokens (15 minutes) and rotating refresh tokens
- HTTP-only, secure cookies for token storage
- PostgreSQL row-level security for multi-tenant data isolation
- PAN numbers encrypted at rest using industry-standard encryption
- All file uploads validated (magic byte verification) and encrypted at rest on Cloudflare R2
- HTTPS enforced on all connections with HSTS headers
- Rate limiting on all authentication endpoints (per-mobile and per-IP)
- Security headers: CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- 30-minute idle timeout with automatic session lock
5. Data Retention
- Active accounts: Data retained as long as your account is active and the subscription is maintained.
- Audit logs: Retained for up to 5 years per SEBI compliance requirements. These records are immutable and cannot be modified or deleted.
- After cancellation: Account data retained for 30 days, then permanently deleted. You may request immediate deletion by contacting support (subject to regulatory retention requirements).
- OTP codes: Automatically expired and purged after 10 minutes.
- Email logs: Delivery logs retained for operational and troubleshooting purposes.
6. Your Rights
Under applicable data protection laws, you have the right to:
- Access your personal data stored on the platform
- Request correction of inaccurate or incomplete data
- Export your data (portfolios, clients, updates, audit logs) as CSV/Excel/PDF
- Request deletion of your account and associated data (subject to regulatory retention requirements)
- Withdraw consent for non-essential data processing
- Object to automated decision-making (we do not use automated decision-making)
To exercise these rights, contact us at [email protected]. We will respond within 30 days.
7. Advisor Responsibility
Advisors and research analysts who use Syltra to manage client data are data controllers for their client information. You are responsible for obtaining appropriate consent from your clients before entering their data into the platform. Syltra acts as a data processor on behalf of advisors, processing client data solely as instructed through your use of the Service.
8. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected data from a child under 18, we will take steps to delete such information.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new policy on this page, updating the "Last updated" date, and sending an email or in-app notification for significant changes. Continued use of the Service after changes constitutes acceptance of the revised policy.
10. Governing Law
This Privacy Policy is governed by the laws of India. Any disputes arising from or in connection with this policy shall be subject to the exclusive jurisdiction of courts in India.
11. Contact
For privacy-related inquiries:
Company: Adornet Labs (OPC) Pvt. Ltd.
Email: [email protected]
General: [email protected]
Website: https://syltra.in