Skip to content
Inside Membership Unchartered Partnerships Contact
The Charter
Request Consideration
Inside Membership Unchartered Partnerships Contact Request Consideration

Privacy notice

What we hold, why, and how to make us stop.

Version 2026-08-26. This notice is written to be read once and understood, which is also what the law asks for.

Who is responsible

Empirilex Private Limited, trading as The Charter, decides why and how your personal data is used. Under the Digital Personal Data Protection Act, 2023 (India) we are the Data Fiduciary; under the UK and EU GDPR we are the controller.

904, Trade World C, Kamala Mills, Lower Parel, Mumbai 400013, India

Data Protection Officer: Data Protection Officer, [email protected]
Grievance Officer (DPDP s.13): Grievance Officer, [email protected]

What we collect, and only that

WhatWhyLawful basisKept for
Membership request: name, email, city, company, what you have built, who referred you To read your request, hold one conversation about it, and reply either way Your consent (DPDP s.6) and steps taken at your request before entering a relationship (GDPR Art. 6(1)(b)) 12 months
Partnership proposal: name, email, organisation, category, what you have in mind To assess the fit and reply Your consent, and our legitimate interest in ordinary business correspondence (GDPR Art. 6(1)(f)) 24 months
Cookie choice: which categories you allowed, when, and a one-way hash of your network address To honour your choice and be able to prove it was freely given Legal obligation and our legitimate interest in demonstrating compliance 5 years
Abuse control: a one-way hash of your network address and a timestamp To stop automated submissions flooding the forms Legitimate interest in keeping the site usable (GDPR Art. 6(1)(f)) 7 days

We do not ask for, and have no use for, any of the special or sensitive categories — health, beliefs, biometrics, financial account details, government identifiers. Please do not send them. We do not knowingly process the data of children, and the site is not directed at them.

How it is protected

  • Names, email addresses and free text are encrypted at rest with authenticated encryption. A stolen database file is not readable without a key held separately.
  • Network addresses are never stored. Where we need to recognise repeat traffic we store a salted one-way hash instead.
  • The site is served over TLS with HSTS, a strict Content Security Policy, and CSRF protection on every form.
  • Deletion is automatic. A scheduled job removes anything past its retention date, whether or not anyone remembers to ask.

Who else sees it

The people at The Charter who read applications and proposals, and our hosting and email providers, who process data on our written instructions and nothing else. We do not sell personal data, we do not share it for advertising, and there is no profiling or automated decision-making that produces a legal effect.

Where data moves outside India or the EEA, it is covered by the appropriate safeguard — Standard Contractual Clauses for EEA transfers, and transfers permitted under s.16 of the DPDP Act.

What you can ask for

Whichever law applies to you, the practical answer is the same: ask, and we do it.

  • See it — a copy of what we hold about you, and a summary of how it is being used.
  • Correct it — fix anything wrong, complete anything missing.
  • Erase it — delete it, unless a specific law requires us to keep it.
  • Withdraw consent — as easily as it was given, with no effect on what was lawful beforehand.
  • Take it with you — a machine-readable copy (GDPR Art. 20).
  • Object or restrict — where we rely on legitimate interest (GDPR Arts. 18, 21).
  • Nominate someone — under DPDP s.14 you may name a person to exercise these rights if you die or become incapacitated.

Make a request

If we get it wrong

Write to the Grievance Officer first — that is the route the DPDP Act asks you to take, and it is the fastest one. If you are not satisfied, you may complain to the Data Protection Board of India, or, in the EEA or UK, to your local supervisory authority or the Information Commissioner's Office.

Breach

If personal data is compromised we notify the Data Protection Board of India and every affected person without delay, and we notify the relevant supervisory authority within 72 hours where the GDPR applies.

Changes

Material changes are published here with a new version number and, where the change affects something you consented to, we ask again rather than assume.

The Charter Founders and investors. Since 2024.
Inside Membership Unchartered Partnerships Contact
MUMBAI · BENGALURU · DELHI · SINGAPORE
Privacy Cookies Your data Terms
Empirilex Private Limited © 2026

Before anything is measured.

We set the cookies that keep this site working, and nothing else, unless you say so. Audience measurement is off until you turn it on, and you can change your mind at any time. What each cookie does.