OpenI
Back to home
Legal

Privacy Policy

Version 1.0 · Effective 5 May 2026

1. Who We Are

OpenI Partners LLP (“OpenI”, “we”, or “us”) operates the OpenI Hub platform (the “Platform”). This Privacy Policy explains what personal data we collect, how we use it, who we share it with, and the rights you have over it. It applies to all users of the Platform, including visitors, registered users, and recipients of our communications.

For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDPA”), OpenI Partners LLP is the Data Fiduciary for personal data submitted to the Platform.

2. Data We Collect

We collect personal data in three ways:

  • You provide it directly. Account details (name, email, password hash, organisation, role), profile information for the persona(s) you hold, content you post (challenges, applications, evaluations, messages), and payment details collected through our payment processor.
  • Automatically while you use the Platform. Log entries (IP address, browser, device type, timestamps), cookies and similar technologies, page-view and click telemetry to improve the product.
  • From third parties. Public sources for imported startup profiles, payment confirmations from Razorpay, email-deliverability signals from our email provider, and OAuth profile data if you sign in via a third-party identity provider.

3. Why We Process Your Data

We use your data to:

  • provide, secure, and improve the Platform and its features;
  • authenticate you and protect your account (including via multi-factor authentication);
  • match you with relevant startups, challenges, mentors, investors, and other users using AI-driven recommendations;
  • process subscriptions, payments, and refunds;
  • send transactional and (with consent) marketing communications;
  • detect and prevent fraud, abuse, and security incidents;
  • comply with legal obligations and enforce our Terms of Use.

Our legal basis under DPDPA is your consent for non-essential processing, and legitimate use (including contractual necessity and legal obligation) for processing required to deliver the service you signed up for.

4. Imported Startup Profiles

The Platform contains startup profiles imported from public sources (the “Imported Profiles”). If you are a founder or authorised representative of an imported startup and wish to claim, correct, or remove the listing, please use the Claim flow inside the Platform or email info@openi.ai.

5. AI Processing

We use AI models (including OpenAI’s embedding and language models) to generate recommendations, narrate evaluations, and translate natural-language search queries into structured filters. Profile data and challenge text may be transmitted to these third-party AI providers under contractual data-processing terms. We do not use your personal data to train public foundation models.

6. Cookies and Similar Technologies

We use cookies and local-storage entries to keep you signed in, remember your active role, persist UI preferences, and measure aggregate platform usage. Essential cookies do not require consent; optional analytics cookies are set only after you opt in via the cookie banner where applicable.

7. Sharing of Your Data

We share personal data only as follows:

  • Other Platform users can view profile fields you mark as public (e.g. your name, organisation, sectors, bio). You control which fields are visible; private fields are visible only to you and to OpenI administrators.
  • Service providers we use to run the Platform (cloud hosting, email delivery, payment processing, AI inference, error monitoring, customer support tooling). All providers are bound by contractual confidentiality and data-protection terms.
  • Legal authorities when required by valid legal process or to protect our rights, users, or the public from harm.
  • Successors in the event of a merger, acquisition, or asset sale; you will be notified before your data is transferred to a different Data Fiduciary.

We do not sell your personal data.

8. International Transfers

Some of our service providers operate outside India (notably AI inference endpoints and email infrastructure). When we transfer your data outside India we rely on contractual safeguards approved under the DPDPA and applicable foreign privacy laws.

9. Data Retention

We retain your account and profile data for as long as your account is active and as long as needed to provide the Platform. Audit logs, payment records, and tax documents are retained for the period required by Indian law (typically up to seven years). On account deletion we anonymise or delete personal data not subject to legal-retention requirements within ninety (90) days.

10. Your Rights

Subject to applicable law, you have the right to:

  • access the personal data we hold about you;
  • correct inaccurate personal data and update your profile;
  • erase your data, subject to legal-retention exceptions;
  • port your data to another service in a machine-readable format;
  • withdraw consent for non-essential processing at any time;
  • nominate a representative under DPDPA Section 14 to exercise these rights on your behalf;
  • file a complaint with the Data Protection Board of India.

To exercise any of these rights, email info@openi.ai with the subject line “Privacy Request”. We will respond within thirty (30) days.

11. Security

OpenI Partners LLP is ISO/IEC 27001:2022 certified (Bureau Veritas Certificate No. IND.25.7578/IS/U). We use encryption in transit (TLS 1.2+), encryption at rest for production databases and backups, role-based access controls, multi-factor authentication for staff, and continuous security monitoring. Backups are encrypted and stored across geographically separated locations. Despite our safeguards, no system can guarantee absolute security; please notify us immediately if you suspect any unauthorised access.

12. Children

The Platform is intended for users aged 18 and above. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will remove it promptly.

13. Changes to This Policy

We may update this Privacy Policy from time to time. The version number and effective date at the top of this page reflect the latest revision. Material changes will be communicated via email or in-app banner before they take effect.

14. Grievance Officer / Data Protection Officer

In compliance with the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 and the DPDPA:

Grievance Officer / DPO
OpenI Partners LLP
121 Beach Towers, P. Balu Marg, New Prabhadevi Road,
Mumbai – 400 025, Maharashtra, India
Email: info@openi.ai

We aim to acknowledge grievances within forty-eight (48) hours and resolve them within thirty (30) days.

See also our Terms of Use (Version 1.0). By using the Platform you confirm acceptance of Version 1.0 of this Privacy Policy, effective 5 May 2026.