LEGAL

Privacy Policy

Detailed information about how Monamaa Ventures may collect, use, share, protect and retain personal information on its corporate website.

Effective date: 18 September 2026   |   Last updated: 18 September 2026

1. Who this Policy applies to

This Privacy Policy explains how Monamaa Ventures (“Monamaa”, “we”, “us”, “our”) may collect, use, disclose, retain and protect personal information when you visit our corporate Website, contact us, submit an enquiry, interact with our forms or otherwise communicate with us through this Website.

This policy does not replace the privacy notices of our portfolio ventures. TrustRoute and Sonar Bangla Haat operate their own digital experiences and may collect information for their own services. Please review the privacy information presented by the relevant venture when using those services.

2. Our privacy approach

We aim to collect only information that is reasonably necessary for stated purposes, use it in a transparent manner, apply appropriate security measures, retain it only as needed, and respect rights available under applicable law.

3. Information we may collect

3.1 Information you provide

  • name and contact details;
  • email address, telephone number or other contact information;
  • company, organisation, role or professional information that you choose to provide;
  • information contained in partnership, investor, media, career or general enquiries;
  • documents or attachments you voluntarily send to us; and
  • any other information you choose to include in correspondence.

3.2 Information collected automatically

Depending on our hosting, security and analytics configuration, we may receive technical information such as IP address, approximate location derived from IP, browser and operating-system type, device characteristics, pages requested, referring page, timestamps, error logs and basic interaction data.

We do not need precise device location to operate this corporate Website unless a specific feature expressly asks for it and provides an appropriate notice.

3.3 Information from other sources

We may receive business contact information from professional introductions, public business sources, service providers or other lawful sources. We will use such information consistently with applicable law and the context in which it was obtained.

4. Purposes of processing

We may process personal information for the following purposes:

  • responding to contact and business enquiries;
  • evaluating partnership, investor, media or other strategic opportunities;
  • communicating with people who have requested information;
  • operating, maintaining, troubleshooting and improving the Website;
  • protecting the Website against fraud, abuse, malicious activity and security incidents;
  • maintaining business and compliance records;
  • managing contracts and professional relationships;
  • complying with legal, regulatory, court or governmental requirements; and
  • establishing, exercising or defending legal claims where reasonably necessary.

5. Legal basis / lawful processing

Where applicable, we may process personal data based on consent, legitimate and lawful business purposes, performance of a contract or steps requested before entering into a contract, compliance with legal obligations, or other grounds recognised under applicable law.

India’s Digital Personal Data Protection Act, 2023 establishes a framework for processing digital personal data and recognising individual rights, and the Ministry of Electronics and Information Technology has published the Digital Personal Data Protection Rules, 2025. Our operational practices should be read together with the law and rules applicable to the relevant processing activity and their applicable commencement provisions. citeturn0search24turn0search15

6. Consent

Where we rely on consent, we seek to provide an appropriate notice and a clear way to give or withdraw consent where required. Withdrawal of consent may not affect processing already lawfully completed before withdrawal and may not be possible where another lawful basis or legal obligation requires continued processing.

7. Cookies and similar technologies

We may use essential cookies or similar technologies to operate the Website and, if enabled, analytics or preference technologies. Please see our Cookie Policy for more information. The exact technologies used in production should be reflected in the final cookie inventory.

8. How we share personal information

We may share personal information with carefully selected service providers where reasonably necessary to operate the Website or respond to you. Examples may include hosting, cloud infrastructure, security, email, communications, form-processing, analytics and professional-service providers.

We may also disclose information:

  • when required by law, regulation, court order or lawful government request;
  • to protect the rights, safety, property or security of Monamaa, users or others;
  • to investigate suspected fraud, abuse or security incidents;
  • as part of a corporate transaction, restructuring, merger, financing or transfer of assets, subject to applicable law; or
  • where you have asked us to share the information or have otherwise authorised the disclosure.

We do not sell personal information simply because someone visits this corporate Website.

9. International processing

Some service providers may process information from locations outside India. Where applicable, we will take steps required by law in relation to such processing, contractual safeguards, security and transfers.

10. Data retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including responding to an enquiry, maintaining business records, resolving disputes, protecting security and satisfying legal or regulatory obligations.

Retention periods vary by category. When information is no longer required, it should be securely deleted, anonymised or otherwise disposed of in accordance with applicable law and our operational retention procedures.

11. Data security

We use reasonable technical and organisational safeguards appropriate to the nature and risk of the information. Measures may include access controls, secure hosting practices, authentication controls, encryption where appropriate, logging, backups, software maintenance and restricted administrative access.

No website, network or storage system can be guaranteed completely secure. If you believe you have identified a security issue involving this Website, please contact us promptly and avoid publicly disclosing sensitive details until we have had an opportunity to investigate.

12. Your rights and choices

Subject to applicable law, you may have rights relating to your personal data, which can include requesting information about processing, correction of inaccurate data, deletion/erasure where permitted, withdrawal of consent where consent is the basis, and other rights provided by applicable data-protection law.

Requests should be sent to hello@monamaa.com. We may need to verify identity and authority before completing a request. We will handle requests within the time and manner required by applicable law.

13. Accuracy of information

Please provide accurate information and tell us if relevant details change. We may rely on information supplied by you when responding to an enquiry or maintaining a business relationship.

14. Children

This corporate Website is not intentionally directed at children. We do not knowingly seek to collect children’s personal information through ordinary corporate enquiries. If you believe a child has provided personal information to us, contact us so that we can assess and address the situation appropriately.

15. Third-party websites

The Website contains links to third-party services, including portfolio venture websites. When you follow those links, the third party becomes responsible for its own processing activities and policies. We encourage you to read the privacy notice of any external service before providing personal information.

16. Business enquiries and communications

If you contact us, we may retain your correspondence and contact details so that we can respond, manage the relationship and maintain an appropriate record. We may send service-related or enquiry-related communications where necessary. Marketing communications, if introduced, will be handled in accordance with applicable consent and communication requirements.

17. Data breach and incident response

We maintain processes intended to detect, assess and respond to security incidents. Where applicable law requires notification to individuals, authorities or other parties, we will follow the prescribed requirements.

18. Changes to this Privacy Policy

We may update this policy when our Website, technologies, business practices or applicable legal requirements change. The revised policy will be published on this page with an updated effective or revision date.

19. Data fiduciary / privacy contact details

Organisation: Monamaa Ventures
Email: hello@monamaa.com
Registered office: [Insert final registered-office address before publication]

If a statutory Data Protection Officer, grievance officer or other designated privacy contact is required for the final operating entity or processing activity, the relevant name/contact details should be inserted here before production publication.

20. Complaints and escalation

We encourage you to contact us first so that we can understand and address your concern. Nothing in this policy limits any right you may have to approach a competent authority or exercise a statutory remedy under applicable law.

Important: This document is written as a detailed corporate-website policy for Monamaa Ventures. It is not a substitute for advice from qualified Indian counsel. Before production publication, confirm the exact legal entity name, registered office, applicable jurisdiction, actual vendors/analytics tools, data flows, retention periods and any statutory grievance or data-protection contact details.