Version 1.0 · Effective 15 August 2026
Varshney Projects LLP, LLPIN ACG-9878, registered office A 101, Gundecha Garden, Lalbaug, Mumbai 400012, Maharashtra, India. GSTIN: 27AAYFV4317P1Z4.
For the purposes of the Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the Data Fiduciary for the personal data described in this policy.
This policy explains how we handle personal data of:
It applies equally across all three surfaces — the website, the MCP server and the API. Where this policy refers to the Service, it means all of them.
Our commercial product supplies entity-level information extracted from public regulatory filings and disclosures — information about companies, not about individuals.
We do not extract, hold or supply personal data of individuals as part of our product. Fields identifying natural persons are outside the defined scope of the service.
This matters to you because it means our product does not process your or anyone else's personal data. If we ever change this, we will amend this policy and notify account holders before the change takes effect.
| When | What we collect |
|---|---|
| You contact us or request a demonstration | Name, business email, organisation name, phone number if you provide it, and the content of your message |
| You create an account | Name, business email, organisation name, role |
| You purchase a subscription | Billing name, billing address, GSTIN, and the invoice record |
| You contact support | Your correspondence with us |
| Category | What it is |
|---|---|
| Technical data | IP address, browser type and version, device and operating system, referring page, pages viewed, timestamps |
| Service usage data | Records of calls made to our MCP server or API, including the account and access token used, the request made, the time, and the volume of data returned |
| Cookie data | See clause 6 |
Why we log service usage. Access logs let us bill accurately, enforce plan limits, investigate misuse or unauthorised redistribution, and diagnose faults. These logs are tied to an account, and where the account is operated by a named individual, to that individual. We keep them because they are the primary record of how the service was used.
We do not collect payment card details. Payments are processed by Razorpay, which is PCI-DSS compliant. Card, UPI and bank credentials are entered directly with Razorpay and never reach our systems. We receive only a transaction reference, the amount, the status, and the billing details you provide for invoicing.
We do not collect sensitive personal data. Do not send us health, biometric, or financial account information — we have no need for it.
The Digital Personal Data Protection Act, 2023 permits processing either with your consent, or for one of a specific list of legitimate uses set out in the Act. The Act contains no general "legitimate interests" basis, and we do not rely on one.
| Purpose | Basis |
|---|---|
| Responding to your enquiry or demonstration request | You voluntarily provided the data for this purpose and have not indicated that you object to it being used for it |
| Creating and administering your account, authenticating access, applying plan limits | Your consent, given when you create the account |
| Support and service communications | Your consent, given when you create the account |
| Billing, invoicing, GST and other tax records | Compliance with our legal obligations under Indian law |
| Records of your usage of the Service | Compliance with our legal obligations. These records determine what you are charged and what any refund is calculated against, so they form part of our accounting records and are kept as such |
| Detecting and investigating misuse, unauthorised access or unauthorised redistribution | Your consent, given when you accept the Data Licence Agreement, together with our obligation to keep accurate accounting records |
| Understanding how the website is used, and improving it | Your consent, through your cookie choices |
| Marketing communications | Your consent, which you may withdraw at any time |
We do not sell personal data. We do not use personal data for automated decision-making that produces legal or similarly significant effects.
Where we rely on your consent, you may withdraw it at any time by writing to compliance@bullpen.in. Withdrawal does not affect the lawfulness of processing before withdrawal.
If you withdraw consent for processing that is necessary to provide the service, we may be unable to continue providing it, and your subscription may be affected. Withdrawal does not release you from payment obligations already incurred.
Withdrawal also does not affect processing we carry out to comply with a legal obligation. In particular, billing records and records of your usage of the Service form part of our accounting records and are retained for the periods set out in clause 9, regardless of any withdrawal of consent.
We use cookies and similar technologies on our website.
| Category | Purpose | Can you refuse? |
|---|---|---|
| Essential | Security, session management, load balancing, remembering your cookie choices | No — the site will not function without them |
| Analytics | Understanding which pages are visited and how the site performs | Yes |
| Advertising | Measuring our advertising and showing you relevant advertising on other platforms | Yes |
Tools currently in use:
| Tool | Category | Provider | Purpose |
|---|---|---|---|
| Google Analytics 4 | Analytics | Google LLC | Site usage measurement |
| Google Ads tag | Advertising | Google LLC | Advertising measurement and remarketing |
| Meta Pixel | Advertising | Meta Platforms, Inc. | Advertising measurement and remarketing audiences |
What advertising cookies do. With your consent, these tools collect information about your visit — pages viewed, an identifier for your browser or device, and limited technical data — and share it with the named provider. The provider uses it to measure our advertising and to include you in audiences that may be shown our advertising on their platforms. The provider processes this data under its own privacy policy, and may do so outside India.
Consent comes first. No analytics or advertising cookie is set until you accept it through the consent banner. Declining changes nothing about how the website works for you. You can change or withdraw your choice at any time through the cookie settings link on our website, and you can clear or block cookies through your browser. Withdrawing consent stops future collection; it does not retrieve data already shared, though you can exercise your rights directly with the provider.
We do not sell personal data.
We share personal data only with service providers who process it on our instructions, and only as far as needed:
| Recipient | Purpose |
|---|---|
| Razorpay Software Private Limited | Payment processing |
| Cloud hosting provider | Hosting the website and service — Google Cloud Platform, Mumbai region (asia-south1), India |
| Google Workspace (Google LLC) | Mailboxes and service email, including grievance correspondence |
| Google LLC | Website analytics and advertising measurement, subject to your cookie consent |
| Meta Platforms, Inc. | Advertising measurement and remarketing, subject to your cookie consent |
| Professional advisers — accountants, auditors, lawyers | Where reasonably required, under duties of confidentiality |
We also disclose personal data where we are required to by law, court order, or a lawful request from a government authority; and where necessary to establish, exercise or defend legal claims.
If our business or its assets are transferred, personal data may transfer as part of that transaction. We will notify account holders before it takes effect.
We do not sell, rent or trade personal data.
We offer the Service to business and professional users in India and in other countries, but not in the European Union or the United Kingdom. We do not market the Service there and do not direct it at persons there.
As an Indian entity, we handle personal data in accordance with the Digital Personal Data Protection Act, 2023, wherever our customers are located.
Our website and service are hosted on Google Cloud Platform, Mumbai region (asia-south1), India. Some of our service providers — such as our payment gateway or email provider — may process limited personal data outside India in the course of providing their service. Where that happens, the transfer is made in accordance with the DPDP Act and any restrictions notified by the Central Government, and we take reasonable steps to ensure recipients are bound by appropriate confidentiality and security obligations.
| Data | Retention |
|---|---|
| Enquiry and demonstration requests | 24 months from last contact |
| Account data | For the life of the account, then 12 months |
| Invoices, billing and tax records | 8 years, as required of an LLP under the LLP Act |
| Usage totals that support an invoice (part of our accounting records) | 8 years, as required of an LLP |
| Detailed request-level access logs | 36 months, matching the limitation period for a contract claim |
| Support correspondence | 36 months |
| Marketing and cookie consent records | Until consent is withdrawn, then 24 months as proof of the withdrawal |
We keep data longer where required by law, or where it is needed for an ongoing or reasonably anticipated legal claim. When retention ends, we delete or irreversibly anonymise the data.
We take reasonable security safeguards to prevent personal data breaches, including:
No system is perfectly secure, and we do not guarantee absolute security. In the event of a personal data breach, we will notify the Data Protection Board of India and affected individuals as required by the DPDP Act.
Under the DPDP Act, you have the right to:
| Right | What it means |
|---|---|
| Access | Obtain a summary of the personal data we hold about you, how we process it, and who we have shared it with |
| Correction and completion | Have inaccurate or incomplete data corrected or completed |
| Erasure | Have your personal data erased, unless we are required to retain it by law or for a legal claim |
| Grievance redressal | Have a complaint heard and answered by our Grievance Officer |
| Nomination | Nominate another individual to exercise your rights in the event of your death or incapacity |
To exercise any of these, write to compliance@bullpen.in. We may ask you to verify your identity before we act.
We respond within the period prescribed under the Digital Personal Data Protection Act, 2023 and the rules made under it, and in any event no later than 30 days from receipt. If we need longer, we will tell you why and when we will respond.
If you are not satisfied with our response, you may complain to the Data Protection Board of India.
The DPDP Act also places duties on you: to provide accurate information, not to impersonate anyone, and not to file false or frivolous complaints.
Our website and services are for business use and are not directed at children. We do not knowingly collect personal data of anyone under 18. If you believe a child has provided us with personal data, write to compliance@bullpen.in and we will delete it.
Grievance Officer: Gunjan Chheda Email: compliance@bullpen.in Address: Varshney Projects LLP, A 101, Gundecha Garden, Lalbaug, Mumbai 400012, Maharashtra, India
We acknowledge receipt of a grievance within 48 hours, issuing a ticket number, and respond within the period required by the Digital Personal Data Protection Act, 2023 and the rules made under it, and in any event no later than 30 days from receipt.
We may update this policy. The updated version takes effect when published with a new effective date and version number.
Where a change materially affects how we handle your personal data, we will notify account holders by email before it takes effect. We retain every prior version. To obtain the version in force on a given date, write to compliance@bullpen.in and we will supply it.
Varshney Projects LLP A 101, Gundecha Garden, Lalbaug, Mumbai 400012, Maharashtra, India All support, legal and grievance matters: compliance@bullpen.in
Version 1.0 — 15 August 2026