PRIVACY POLICY
1. Introduction and Overview
Graviti Exchange is a Virtual Digital Asset (VDA) trading platform operated by AlphaQuest Technovations Private Limited (hereinafter "Graviti Exchange", "Company", "We", "Us", or "Our"). The Platform is accessible via the website graviti.exchange and any associated mobile applications or web-based interfaces (collectively, the "Platform").
This Privacy Policy ("Policy") governs the collection, receipt, storage, processing, disclosure, transfer, and all other forms of handling of your Personal Data when you access or use the Platform. This Policy is prepared in compliance with the following applicable Indian laws and regulatory frameworks:
a. Digital Personal Data Protection Act, 2023 ("DPDPA") and rules made thereunder;
b. Information Technology Act, 2000 and the IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("IT-SPDI Rules");
c. Prevention of Money Laundering Act, 2002 ("PMLA") and the Prevention of Money Laundering (Maintenance of Records) Rules, 2005;
d. Financial Intelligence Unit – India ("FIU-IND") Master Directions applicable to Reporting Entities;
e. Goods and Services Tax Act 2017, Income Tax Act, 1961, including Section 194S (TDS on VDA transactions) and Section 285BAA reporting obligations;
f. Foreign Exchange Management Act, 1999 and applicable Reserve Bank of India ("RBI") directions.
g. Companies Act 2013 and rules made thereunder.
We reserve the right to update or amend this Policy at any time. Material changes will be communicated via email or a prominent Platform notice at least 15 (fifteen) days before taking effect. Your continued use of the Platform after that date constitutes acceptance of the revised Policy. All prior versions remain archived and are available upon written request.
2. Definitions
For the purposes of this Policy, the following terms shall have the meanings ascribed below:
a. "AML/CFT" – Anti-Money Laundering and Combating the Financing of Terrorism, as governed by the PMLA, FIU-IND directions, and FATF recommendations.
b. "Consent" – A freely given, specific, informed, and unambiguous indication of your agreement to the processing of your Personal Data, whether by a statement or a clear affirmative action.
c. "Data Fiduciary" – The Company, being the entity that determines the purpose and means of processing of Personal Data, as defined under the DPDPA.
d. "Data Principal" – You, the individual to whom the Personal Data relates, as defined under the DPDPA.
e. "Data Processor" – Any third-party entity that processes Personal Data on behalf of the Company pursuant to a written contract.
f. "KYC" – Know Your Customer – the mandatory customer identification, due diligence, and verification process required under applicable AML/CFT laws and FIU-IND obligations.
g. "Personal Data" – Any data about an individual who is identifiable by or in relation to such data, as defined under the DPDPA, including Sensitive Personal Data or Information ("SPDI") as defined under the IT-SPDI Rules.
h. "Platform" – The Graviti Exchange website (graviti.exchange), mobile applications, APIs, and all associated digital products and services.
i. "Virtual Digital Asset (VDA)" – A virtual digital asset as defined under Section 2(47A) of the Income Tax Act, 1961, including cryptocurrencies, tokens, and any digital representation of value.
3. Personal Data We Collect
We collect the following categories of Personal Data in connection with your use of the Platform and in fulfilment of our legal, regulatory, and contractual obligations:
3.1 Identity and Contact Information
a. Full legal name, date of birth, gender, and nationality;
b. Email address, registered mobile number, and residential/correspondence address;
c. Username and encrypted account credentials.
3.2 KYC and AML/CFT Verification Data
Collection of KYC data is mandatory and is required pursuant to our obligations as a Reporting Entity under the PMLA and FIU-IND Master Directions. This includes:
a. Government-issued identity documents – Aadhaar (UID), PAN Card, Passport, Driving Licence, or Voter ID;
b. Address proof documents and recent photograph;
c. Live liveness verification data and in-person verification (IPV) video recordings;
d. Bank account details, including account number and IFSC code;
e. Source of funds and source of wealth declarations;
f. Politically Exposed Person (PEP) status and sanctions screening data;
g. Enhanced due diligence (EDD) documentation for high-risk users, as required.
3.3 Financial and Transaction Data
a. Details of all deposits, withdrawals, and VDA transactions, including amounts, timestamps, and transaction IDs;
b. Linked bank account and payment instrument information;
c. Profit and loss records and tax-related information, including details required for TDS deduction under Section 194S of the Income Tax Act, 1961.
3.4 Blockchain and Wallet Data
Disclaimer: Certain data recorded on a blockchain is inherently public and immutable. Once a transaction is confirmed on a public blockchain, it cannot be deleted, altered, or restricted regardless of any request made under this Policy or applicable law. We have no ability to modify or remove on-chain data.
a. Public wallet addresses and associated on-chain transaction records;
b. Smart contract interaction data involving your wallet addresses;
c. Transaction metadata visible on public block explorers;
d. Internal custodial wallet data generated by the Platform for your account.
3.5 Device, Network, and Technical Data
a. IP address, device identifiers (device ID, IMEI where accessible), and MAC address;
b. Browser type and version, operating system, and device hardware model;
c. Geolocation data (IP-based or GPS-based, where device permissions are granted), used for jurisdiction verification and fraud prevention;
d. Session data, login timestamps, and access logs.
3.6 Cookies and Tracking Data
We collect data through cookies, web beacons, pixel tags, and local storage objects. Please refer to Section 7 for full details on our Cookie Policy.
3.7 Communications and Support Data
a. Records of support queries, complaints, and grievance communications;
b. Call recordings and chat transcripts for customer support interactions;
c. Survey and feedback responses;
d. Marketing communication preferences and opt-in/opt-out records.
3.8 Usage and Analytics Data
a. Platform navigation patterns, feature usage, session duration, and page views;
b. Trading behaviour and activity patterns, used for personalisation and fraud detection;
c. Referral source and affiliate tracking parameters.
Where Personal Data is not provided or Consent is withdrawn for mandatory processing, we may be wholly or partially unable to provide services on the Platform.
4. How We Collect Your Personal Data
We collect your Personal Data through the following means:
4.1 Data Provided Directly by You
a. At the time of account registration and onboarding;
b. During KYC/AML verification processes and periodic re-KYC exercises;
c. When you place orders or transact on the Platform;
d. When you correspond with us via email, chat, telephone, or any other channel;
e. When you participate in surveys, promotions, referral programmes, or feedback forms;
f. When you submit grievance or support requests.
4.2 Data Collected Automatically
a. Through cookies and tracking technologies when you visit or use the Platform (see Section 7);
b. Through server logs, API call records, and application telemetry;
c. Through device SDKs embedded in our mobile applications;
d. Through geolocation services activated on your device, subject to device-level permissions granted by you.
4.3 Data Received from Third Parties
a. KYC verification service providers, identity verification bureaus, and eKYC platforms;
b. Financial institutions, payment gateways, and banking partners, for transaction verification;
c. Sanctions and PEP screening databases maintained by authorised vendors;
d. Public blockchain networks and on-chain data analytics platforms;
e. Fraud detection and risk intelligence providers;
f. Regulatory authorities and law enforcement agencies, pursuant to lawful requests;
g. Referral partners and affiliates, limited to information necessary to process referrals.
All Personal Data you provide must be accurate, complete, and kept up to date. You must promptly notify us of any changes to your information that may affect service delivery. We shall not be liable for any loss or adverse consequence arising from inaccurate or outdated information provided by you.
5. Purposes and Legal Bases for Processing
We process your Personal Data only for lawful purposes, each grounded in one or more of the following legal bases: (a) your freely given, specific, and informed Consent; (b) necessity for the performance of a contract to which you are a party; (c) compliance with a legal obligation to which we are subject; or (d) our legitimate interests, to the extent not overridden by your rights and interests.
5.1 Account Creation and Service Delivery
a. Verifying your identity and eligibility to use the Platform;
b. Creating, maintaining, and administering your account;
c. Processing, settling, and confirming transactions and orders placed by you;
d. Sending service notifications, account alerts, and administrative communications.
5.2 KYC, AML/CFT, and Regulatory Compliance
a. Conducting customer identification, due diligence, and enhanced due diligence as required under PMLA and FIU-IND Master Directions;
b. Screening against applicable sanctions lists, PEP databases, and adverse media sources;
c. Transaction monitoring and filing of Suspicious Transaction Reports (STRs) and Cash Transaction Reports (CTRs) with FIU-IND, as required;
d. Complying with tax reporting obligations, including TDS deduction under Section 194S and reporting under Section 285BAA of the Income Tax Act, 1961;
e. Responding to lawful requests, summons, orders, or directions from regulatory authorities, courts, or law enforcement;
f. Maintaining records for the minimum periods prescribed under PMLA and FIU-IND directions.
5.3 Platform Security and Fraud Prevention
a. Detecting, investigating, and preventing fraudulent, unauthorised, or illegal activities;
b. Monitoring for cybersecurity threats, account takeovers, and suspicious access patterns;
c. Enforcing our Terms of Use and other platform policies;
d. Conducting internal audits, risk assessments, and compliance reviews.
5.4 Personalisation and Platform Improvement
a. Personalising your experience, including product and content recommendations;
b. Analysing usage patterns to improve Platform features, functionality, and performance;
c. Conducting research, A/B testing, and analytics for product development.
5.5 Marketing and Communications
a. Sending marketing communications, newsletters, and promotional offers where you have provided explicit Consent or have not opted out, in accordance with applicable law;
b. Understanding the effectiveness of marketing campaigns.
You may withdraw Consent for marketing communications at any time by clicking the unsubscribe link in any marketing email or by contacting us at the details in Section 12. Withdrawal of Consent for mandatory processing may result in account termination and cessation of services.
5.6 Legal and Dispute Resolution
a. Establishing, exercising, or defending legal claims before courts, tribunals, or arbitral bodies;
b. Complying with court orders, arbitral awards, and regulatory directions;
c. Preventing abuse of the Platform and protecting third-party rights.
6. Disclosure and Sharing of Personal Data
We do not sell, rent, or trade your Personal Data to third parties for commercial gain other than using it to develop, enhance and market our products and services either from ourselves, partners or group companies. We may share your Personal Data with the following categories of recipients on a need-to-know basis, subject to confidentiality and data protection obligations:
6.1 Regulatory and Law Enforcement Authorities
We are required by law to disclose your Personal Data to certain governmental and regulatory bodies. This includes:
a. FIU-IND, for filing of STRs, CTRs, and cross-border wire transfer reports under the PMLA;
b. The Income Tax Department, for TDS filings under Section 194S and other statutory reporting;
c. The Enforcement Directorate, Central Bureau of Investigation, State Police, and other agencies, pursuant to lawful summons, search warrants, or directions;
d. SEBI, RBI, or any other competent financial sector regulator;
e. Courts and arbitral tribunals pursuant to orders or processes issued by them.
6.2 KYC and Verification Partners
a. UIDAI-authorised KYC User Agencies and eKYC providers for Aadhaar-based verification;
b. Video KYC, face-matching, and liveness verification service providers;
c. PAN verification and income tax portal integration partners.
6.3 Financial and Payment Partners
a. Banking partners, payment aggregators, and settlement banks for processing deposits and withdrawals;
b. Payment gateway providers and beneficiary account verification services.
6.4 Technology, Cloud, and Analytics Partners
a. Cloud service providers including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure, for hosting, storage, and computing;
b. Blockchain analytics and AML screening platforms for VDA transaction risk scoring;
c. Web analytics platforms and fraud detection providers, subject to applicable data processing agreements.
6.5 Legal, Audit, and Advisory Partners
a. Legal advisors and law firms retained for disputes, regulatory proceedings, or legal advice;
b. Chartered accountants, statutory auditors, and tax advisors for compliance reviews.
6.6 Business Transfers
In the event of a merger, acquisition, corporate restructuring, or sale of all or a substantial portion of our assets, your Personal Data may be transferred to the acquiring entity, subject to applicable law. Such transfer may occur without any further consent from you to the extent permitted by applicable law. Following completion of the transaction, we shall not be responsible or liable for the privacy practices, acts, omissions, or processing activities of the acquiring entity with respect to the transferred Personal Data. We may provide notice of such transfer as required under applicable law.
All third-party recipients of your Personal Data are required to execute data processing agreements incorporating confidentiality obligations, adequate security standards, and restrictions on use. We conduct periodic due diligence of our Data Processors to verify ongoing compliance.
7. Cookies and Tracking Technologies
7.1 What Are Cookies?
Cookies are small text files stored on your device when you visit our Platform. They allow us to recognise your device, maintain your session, and provide a personalised experience. We also use related tracking technologies including web beacons, pixel tags, and local storage objects.
7.2 Types of Cookies We Use
a. Strictly Necessary Cookies – essential for Platform security and session functionality; cannot be disabled without impairing core Platform features. No Consent is required for these cookies.
b. Performance and Analytics Cookies – collect anonymised information about Platform usage patterns and errors, helping us improve the user experience.
c. Functionality Cookies – remember your preferences (such as language and interface settings) to deliver a personalised experience.
d. Targeting and Marketing Cookies – used to deliver relevant advertisements and track campaign effectiveness. These cookies are deployed only with your explicit Consent, which you may withdraw at any time.
7.3 Managing Your Cookie Preferences
You may manage or withdraw cookie preferences at any time through our Cookie Consent Manager on the Platform, or by adjusting your browser settings to reject or delete cookies. Please note that disabling certain cookies may impair the availability or functionality of Platform features. For guidance on cookie management, please refer to your browser's help documentation.
8. Cross-Border Data Transfers
Your Personal Data will primarily be stored and processed on servers located within the territory of India. However, in the course of providing certain services, operations or any other business measures it may be necessary to transfer your Personal Data to jurisdictions outside India.
Where such transfers occur, we ensure they are undertaken in compliance with the DPDPA and applicable rules, including:
a. Execution of standard contractual clauses or data processing agreements incorporating adequate data protection obligations with the recipient;
b. Transfers to jurisdictions notified by the Central Government of India under Section 16 of the DPDPA as providing an adequate level of data protection;
c. Any other mechanism or safeguard prescribed by the Data Protection Board of India or the Central Government from time to time.
By using the Platform, you acknowledge and consent to the transfer of your Personal Data to such jurisdictions, subject to the safeguards described above.
9. Data Retention
We retain your Personal Data only for as long as necessary to fulfil the purposes described in this Policy and to satisfy our legal, regulatory, audit, and reporting obligations. Upon expiry of the applicable retention period, Personal Data will be securely deleted, anonymised, or archived in a manner that prevents further processing, subject to any legal hold obligations in force. Anonymised or aggregated data that cannot be used to identify you may be retained for statistical or research purposes without time limitation. Please note that data recorded on public blockchains cannot be deleted and will remain on-chain permanently.
10. Cybersecurity and Data Security Safeguards
We implement a comprehensive, risk-based information security programme designed to protect your Personal Data from unauthorised access, disclosure, alteration, destruction, or loss. Our safeguards include both technical and organisational measures:
10.1 Technical Safeguards
The Company implements appropriate technical and organizational security measures to protect personal data and digital assets from unauthorized access, use, disclosure, alteration, loss, or destruction. Such measures include access controls, authentication mechanisms, secure data handling practices, system monitoring, periodic security assessments, and other industry-standard safeguards appropriate to the nature and sensitivity of the information processed.
10.2 Organisational Safeguards
a. Designation of a Data Protection Officer (DPO) responsible for overseeing compliance with this Policy and applicable data protection laws;
b. Mandatory privacy and security training for all employees who handle Personal Data;
c. Strict need-to-know access controls limiting employee access to Personal Data;
d. Non-disclosure and confidentiality agreements binding on all employees, contractors, and vendors with access to Personal Data.
10.3 Data Breach Response
In the event of a Personal Data breach likely to affect your rights and interests, we will notify you and the Data Protection Board of India within the timelines prescribed under the DPDPA and applicable rules. Notification will include the nature of the breach, categories of data affected, likely consequences, and measures taken or proposed to address the breach.
Disclaimer: Notwithstanding the security measures described above, no method of electronic transmission or storage is 100% secure. While we employ commercially reasonable and legally compliant safeguards, we cannot guarantee absolute security against all threats. You acknowledge and accept the inherent risks of transmitting information over the internet.
11. Your Rights as a Data Principal
Subject to applicable law, including the DPDPA, you have the following rights in relation to your Personal Data processed by us. Certain rights may be limited where compliance with legal obligations or overriding interests so require.
11.1 Right to Access
You may obtain confirmation of whether we process your Personal Data and, if so, receive a summary of the Personal Data held and the processing activities carried out in respect thereof.
11.2 Right to Correction
You may request correction of inaccurate or incomplete Personal Data that we hold about you. We will act on your request within a reasonable period after verification.
11.3 Right to Erasure
You may request deletion of Personal Data that is no longer necessary for the purposes for which it was collected. Please note that this right is subject to overriding legal retention obligations – particularly under the PMLA and FIU-IND directions – which require us to retain certain records for mandated periods regardless of your request. Data recorded immutably on a public blockchain cannot be erased under any circumstances.
11.4 Right to Withdraw Consent
Where processing is based on your Consent, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal. Withdrawal of Consent for mandatory processing will result in termination of your account and cessation of services.
11.5 Right to Nominate
You may nominate another individual to exercise your rights under this Policy in the event of your death or incapacity, in accordance with the DPDPA.
11.6 Right to Grievance Redressal
You have the right to have your grievances regarding our data processing practices addressed promptly through the mechanism set out in Section 13.
11.7 Right to Data Portability
Where mandated by applicable rules under the DPDPA, you may receive your Personal Data in a structured, commonly used, and machine-readable format, and transmit it to another Data Fiduciary.
To exercise any of your rights, please submit a written request to our Grievance Officer at the details in Section 12. We will respond within 30 (thirty) days of receipt of a complete and verifiable request. We may require identity verification before processing your request.
12. Grievance Redressal
In accordance with the IT Act, 2000 and rules made thereunder, and in anticipation of obligations under the DPDPA, we have designated a Grievance Officer to address any complaints, concerns, or requests arising from this Policy or our data processing practices:
Grievance Officer: [Name to be designated]
Organisation: AlphaQuest Technovations Private Limited
Address: WeWork Oberoi Commerz II, 20th Floor, CTS 95 HD-338, Goregaon East, Mumbai – 400063, Maharashtra, India
Grievance Email: support@graviti.exchange
Response Time: Within 30 (thirty) days of receipt of a complete complaint
If your grievance is not satisfactorily resolved by our Grievance Officer within the stipulated period, you may escalate the matter to the Data Protection Board of India upon its operationalisation under the DPDPA. We are fully committed to cooperating with the Board in the resolution of any complaints filed against us.
13. Children's Privacy and Age Restriction
The Platform is not intended for, nor directed at, individuals below 18 (eighteen) years of age. We do not knowingly collect Personal Data from minors. Account registration and use of Platform services is strictly limited to adults who are legally competent to contract under Indian law.
If you are a parent or guardian and believe that a minor has provided us with Personal Data without your consent, please contact our Grievance Officer immediately at support@graviti.exchange. We will take prompt steps to delete such information upon verification. We reserve the right to suspend or terminate any account where we have reasonable grounds to believe that the account holder does not meet the minimum age requirement.
14. Third-Party Links and Integrated Services
The Platform may contain hyperlinks to third-party websites, applications, and services that are not operated or controlled by us. This Policy does not apply to such third-party platforms. We strongly encourage you to review the privacy policies of any third-party service you access. We bear no responsibility or liability for the privacy practices, security standards, or content of any third-party website or service linked from our Platform.
Where we integrate third-party services into the Platform – such as payment gateways, analytics tools, or identity verification services – such integrations are governed by data processing agreements. We are not liable for the independent privacy practices of integrated third parties beyond our contractual arrangements with them.
15. Governing Law and Dispute Resolution
This Privacy Policy and any dispute arising out of or in connection with it – including questions regarding its existence, validity, or termination – shall be governed by and construed in accordance with the laws of the Republic of India, without regard to its conflict of law provisions.
Any dispute, controversy, or claim arising out of or relating to this Policy shall first be subject to good-faith negotiation between the parties for a period of 30 (thirty) days from the date of written notice of the dispute. If unresolved within that period, the dispute shall be referred to and finally resolved by arbitration in accordance with the Arbitration and Conciliation Act, 1996, as amended from time to time. The seat and venue of arbitration shall be Mumbai, Maharashtra, India. The arbitration shall be conducted in the English language, and the award shall be final and binding on the parties.
Notwithstanding the above, each party retains the right to seek interim or injunctive relief from a court of competent jurisdiction. The courts at Mumbai, Maharashtra shall have exclusive jurisdiction to entertain any application for such interim relief, and both parties irrevocably submit to the jurisdiction of those courts for this limited purpose.
16. General Provisions
16.1 Force Majeure
We shall not be liable for any delay or failure in the performance of our obligations under this Policy arising from causes beyond our reasonable control, including acts of God, fire, flood, earthquake, epidemic, pandemic, war, terrorism, civil commotion, strikes, government restrictions, regulatory interventions, failure of telecommunications or internet infrastructure, power outages, cyberattacks targeting systems maintained with industry-standard security, or failure of third-party service providers.
16.2 Limitation of Liability
To the maximum extent permitted by applicable law, the Company and its affiliates, officers, directors, employees, and service providers shall not be liable to you for any loss, damage, cost, or expense (including any indirect, consequential, incidental, punitive, or special loss) arising from or in connection with your use of the Platform or the Services, including losses arising from Order execution, market movements, liquidation of positions, system outages, or security incidents. We shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising from unauthorised third-party access to systems maintained with industry-standard security, immutability of blockchain data, or events of Force Majeure.
16.3 Consent Framework and Audit Trail
Your Consent to this Policy is obtained at account creation and recorded in our systems with a timestamp and version reference. We maintain a detailed Consent audit trail in compliance with the DPDPA. Where possible, Consent is granular – you may provide separate Consent for mandatory processing (required for service delivery and legal compliance) and optional processing (such as marketing). Consent withdrawal requests may be submitted through in-app settings or by writing to our Grievance Officer.
16.4 Severability
If any provision of this Policy is found to be unlawful, void, or unenforceable, such provision shall be deemed severable and shall not affect the validity or enforceability of the remaining provisions, which shall continue in full force and effect.
16.5 Entire Agreement
This Policy, together with our Terms of Use and any other terms incorporated herein by reference, constitutes the entire agreement between you and us regarding the subject matter hereof and supersedes all prior agreements, representations, and understandings of any nature.
16.6 Waiver
No failure or delay by us in exercising any right under this Policy shall be construed as a waiver of that right, nor shall any single or partial exercise prevent any further exercise of the same or any other right.
16.7 Language
This Policy is drafted in the English language. In the event of any conflict between a translated version and the English version, the English version shall prevail in all respects.
17. Contact Information
For any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us at:
Company: AlphaQuest Technovations Private Limited
Address: WeWork Oberoi Commerz II, 20th Floor, CTS 95 HD-338, Goregaon East, Mumbai – 400063, Maharashtra, India
CIN: U62099MH2024PTC435645
Grievance Email: support@graviti.exchange

