PRIVACY NOTICE
Who we are
Axilor Investment Advisors LLP (LLPIN-AAK-7787), having its registered office at 58,15th Cross,J.P Nagar,2nd Phase,Bangalore 560078 (“Axilor“, “we“, “us” or “our“), issues this Notice.
We are registered with the Securities and Exchange Board of India as the manager of Axilor Technology Fund I (IN/AIF1/17-18/0518), Axilor Technology Fund II (IN/AIF2/22-23/1176) and Micelio Technology Fund I (IN/AIF1/19-20/0748) (each, a “Fund“), and this Notice is published at www.axilor.com (the “Website“).
In respect of the personal data described in this Notice, we are the Data Fiduciary. This means that we determine the purpose and means of processing that personal data, and we are accountable for it under the Digital Personal Data Protection Act, 2023 (the “DPDP Act“) and the Digital Personal Data Protection Rules, 2025 (the “DPDP Rules“). Where another entity determines the purpose and means of a processing activity, that entity is the Data Fiduciary in respect of it and this Notice does not apply to that processing.
This Notice explains what personal data we collect, why we collect it, the basis on which we process it, who we share it with, how long we keep it, and the rights available to you as a Data Principal.
We have written this Notice to be read on its own. It does not depend on any other document, and nothing in our terms of use, subscription documents, transaction documents or employment documentation limits the rights described here.
Who and what this Notice covers
This Notice applies to all personal data processed by Axilor in the course of its activities, whether collected through the Website or otherwise. It applies to you if you are:
- a visitor to the Website, or a person who contacts us through it or in response to it;
- a founder or team member of a start-up that applies to us for funding or for a programme;
- an employee, intern, contractor or consultant of ours, or a candidate who applies to work with us;
- an investor or prospective investor in a Fund, or an authorised representative, nominee or beneficial owner of such an investor;
- a founder, director, key managerial person, employee or shareholder of a company in which a Fund has invested or is evaluating an investment; or
- a business partner, vendor, service provider, adviser or mentor, or a member of their personnel.
Where you are an employee, intern, contractor or consultant, this Notice is supplemented by the internal policies issued to you, including our information technology and acceptable use policies. Those policies explain how this Notice is applied in a working environment. They do not reduce the rights described here, and in the event of any inconsistency this Notice prevails.
Where you are an investor in a Fund, this Notice is supplemented by the private placement memorandum, contribution agreement and other subscription documentation of the relevant Fund. Those documents may describe further disclosures required of the Fund or its manager under law.
What this Notice does not cover
Where the Website or any of our communications links to a portfolio company, a social media platform or any other external site, that site is operated by a third party under its own privacy policy. We do not control, and are not responsible for, how those third parties handle your personal data. We encourage you to read their notices before providing information to them.
Where an Axilor entity processes personal data as a Data Processor on the instructions of another Data Fiduciary, that other Data Fiduciary determines the purpose and means of the processing and its own notice governs it. This Notice does not apply to that processing.
If you are not sure whether or how this Notice applies to you, please contact our Grievance Officer using the details in Clause 16 and we will tell you.
The personal data we collect, and why
The table below sets out, for each category of person whose data we process, the personal data concerned, the purpose for which it is processed, the basis on which we process it, and how long we keep it. We collect only the personal data that is necessary for the purpose stated against it.
| Who you are | Personal data we collect | Purpose for which it is processed | Basis under the DPDP Act | Retention |
| Website visitor | IP address, browser and device type, operating system, approximate location derived from IP, pages viewed, date and time of visit, and referring URL, collected automatically when you use the Website | Operating and securing the Website, measuring traffic and page performance, diagnosing faults, and detecting and preventing misuse | Section 7(a) (voluntary provision) for what is strictly necessary to operate and secure the Website; consent under Section 6 for analytics and other non-essential tracking | Server and security logs: [12 months]. Analytics data: [26 months], or such shorter period as configured in the analytics tool |
| Person who contacts us | Name, email address, telephone number, organisation, and the content of your message and our correspondence with you | Responding to your enquiry, maintaining a record of the correspondence, and following up where you have asked us to | Section 7(a), as the data is voluntarily provided to us for a specified purpose | [24 months] from the date of the last substantive communication, unless a longer period is required for the purposes described in Clause 12 |
| Founder or start-up applying for funding or a programme | Founder and co-founder names, contact details, professional and educational background, LinkedIn or other profile links, and the contents of the pitch materials, business plan and any supporting documents you submit | Assessing the application, conducting internal evaluation and screening, communicating with you about the outcome, and maintaining a record of applications received | Section 7(a); consent under Section 6 where we wish to retain your materials beyond the evaluation of the specific application, or share them with a third party evaluator | Unsuccessful applications: [12 months] from the decision. Successful applications: for the duration of the investment relationship and thereafter in accordance with Clause 12 |
| Business partner, vendor or service provider (and your personnel) | Name, designation, business contact details, organisation details, bank account and tax registration details, and correspondence records | Negotiating, entering into and administering the engagement, making and receiving payments, and meeting tax, accounting and audit obligations | Section 7(a) and Section 7(b) (performance of a legal obligation) in respect of tax, accounting and statutory record-keeping | Eight years from the end of the relevant financial year, in line with Section 128(5) of the Companies Act, 2013, and any longer period required under tax law |
| Person who reports an impersonation or fraud concern | Your name and contact details, and the details, screenshots and other material you provide about the suspected impersonation | Investigating the report, protecting the Company, its stakeholders and the public, and pursuing legal or regulatory action where appropriate | Section 7(a); Section 7(b) where disclosure to an authority is legally required | For the duration of the investigation and any resulting proceedings, and thereafter as required to establish, exercise or defend a legal claim |
| Employee, intern, contractor or consultant | Name, contact details, date of birth, photograph, PAN and other identification and tax details, employment and educational history, references, offer and engagement documentation, bank account details, remuneration, payroll and benefits records, statutory contribution details, attendance and leave records, performance and disciplinary records, emergency contact and nominee details, and records generated by our systems in the course of your work | Administering your employment or engagement, paying remuneration and benefits, managing attendance, leave and performance, providing access to our systems and premises, protecting the confidentiality and security of our information, and meeting our employment, tax and social security obligations | Section 7(i) (employment purposes, including the provision of a service or benefit to an employee and safeguarding the employer from loss or liability); Section 7(b) for tax and social security obligations | For the duration of your employment or engagement and thereafter for eight years from the end of the relevant financial year, or such longer period as is required under labour, tax or social security legislation or to defend a legal claim |
| Candidate for employment or engagement | Name, contact details, curriculum vitae, employment and educational history, references, identification documents, interview notes and assessment records, and the outcome of any background verification | Assessing your suitability for the role, conducting interviews and verification, communicating with you about the outcome, and, where you agree, considering you for future roles | Section 7(a); Section 7(i) in respect of verification connected with prospective employment; consent under Section 6 for retention beyond the recruitment process | [12 months] from the conclusion of the recruitment process, unless you consent to a longer period. Where you are appointed, retained as part of your employment record |
| Investor or prospective investor in a Fund, and your authorised representatives, nominees and beneficial owners | Name, contact details, date of birth, nationality, photograph and specimen signature, PAN and other identification documents, passport and tax residency details, bank account and depository participant details, details of authorised signatories, nominees and beneficial owners, source of funds and source of wealth declarations, commitment, drawdown, capital account and distribution records, and correspondence | Accepting and administering your commitment to a Fund, maintaining unit and capital account records, making drawdowns and distributions, carrying out know-your-customer, anti-money laundering, sanctions and politically exposed person screening, and making the filings and reports required of the Fund or its manager | Section 7(b) (compliance with a legal obligation) in respect of know-your-customer, anti-money laundering, tax and securities law requirements; Section 7(a) for information you provide voluntarily in the course of the relationship | Five years from the completion of the transaction or the cessation of the business relationship, whichever is later, under the Prevention of Money-Laundering Act, 2002, and such longer period as is required under the SEBI (Alternative Investment Funds) Regulations, 2012 or directed by an authority |
| Founder, director, key managerial person or shareholder of a portfolio company or a company under evaluation | Name, contact details, identification and tax details, director identification number, designation and shareholding, professional and educational background, information gathered in due diligence including reference and background checks, transaction documents to which you are a party, board and shareholder records, and correspondence | Evaluating, making, administering, monitoring and exiting an investment, exercising and enforcing rights under transaction documents, meeting the valuation, audit and reporting requirements of the relevant Fund, and establishing, exercising or defending a legal claim | Section 7(a); Section 7(b) for reporting and record-keeping obligations; Section 7(c) where processing is necessary to comply with a judgment, decree or order | For the duration of the investment and thereafter for eight years from the end of the financial year in which it is fully exited, and longer where required by law or where a claim is contemplated or pending |
We do not knowingly collect special category or sensitive data through the Website, and we ask you not to submit it. Please do not include personal data in a pitch deck, application or message beyond what is necessary for us to assess it or respond to you. If you send us personal data relating to another person, such as a co-founder or a referee, you confirm that you have that person’s authority to do so and that you have informed them of this Notice.
How we collect your personal data
We collect personal data in the following ways.
Directly from you
When you complete a form on the Website, send us an email, apply for funding or a programme, apply to work with us, subscribe to updates, complete subscription or onboarding documentation for a Fund, or otherwise correspond with us.
Through the application form hosted by a third party
The “Apply” link on the Website takes you to an application form hosted on Google Forms, a service provided by Google LLC and its affiliates. When you use that form, the information you enter is collected and stored on Google’s infrastructure and is then made available to us. Google processes that information as our data processor under our agreement with it, and also processes technical data about your use of the form under its own privacy policy.
Automatically as you use the Website
Through our web server logs and our content delivery and security infrastructure, and through analytics and similar technologies, as you browse the Website. The technologies used for this purpose, and the choices available to you in relation to them, are described in our Cookie Policy referred to in Clause 6.
From third parties and public sources
Where we receive an introduction or a referral, or where we look at publicly available information such as a company registry filing, a professional networking profile or a published article in the course of evaluating an opportunity. Where we do this, we process only what is relevant to the evaluation.
We also receive personal data from the entity you represent or are associated with. This includes personal data about founders, directors, key managerial personnel and shareholders provided to us by a portfolio company or a company under evaluation, and personal data about authorised signatories and beneficial owners provided to us by an investor. Where personal data about you reaches us in this way, the entity that provided it is responsible for having a lawful basis for doing so and for informing you.
For investors, we obtain and verify personal data through the Central KYC Records Registry, KYC registration agencies, depositories and depository participants, and through sanctions, adverse media and politically exposed person screening databases, as required by applicable law.
In the course of your employment or engagement
Where you work for us, we collect personal data from you during onboarding and throughout your engagement, from referees and background verification agencies where verification is carried out, and from the records generated by our systems, networks, devices and premises access controls in the ordinary course of your work.
The basis on which we process personal data
Under the DPDP Act, personal data may be processed only on the basis of your consent under Section 6, or for one of the specific legitimate uses listed in Section 7. There is no general “legitimate interests” basis in India. We rely on the following.
Consent under Section 6
Where we rely on consent, we ask for it separately and in plain terms, we tell you what personal data we need and why, and we take it only for the purpose we have stated. Your consent is limited to that purpose. We rely on consent for analytics and other non-essential tracking on the Website, for marketing and subscription communications, and for retaining application materials beyond the evaluation of a specific application.
Merely visiting the Website, or clicking through an advisory or banner, is not treated by us as consent to processing that requires consent. Where consent is required, we ask for it by a clear affirmative action.
Certain legitimate uses under Section 7
We rely on Section 7(a) where you voluntarily provide personal data to us for a specified purpose and have not indicated that you object to its use for that purpose, for example when you write to us with an enquiry or submit an application. We rely on Section 7(b) where processing is necessary for us to comply with a legal obligation, and on Section 7(c) where processing is necessary to comply with a judgment, decree or order.
We rely on Section 7(i) where processing is necessary for employment purposes, including to safeguard us from loss or liability, to prevent corporate espionage, to maintain the confidentiality of trade secrets, intellectual property and classified information, and to provide a service or benefit to an employee.
Where we process personal data to meet a know-your-customer, anti-money laundering, tax, securities law or other statutory obligation, that processing is required by law. It is not based on your consent and it cannot be withdrawn. If the information required for it is not provided to us, we may be unable to establish or continue the relationship.
Withdrawing your consent
Where we process on the basis of your consent, you may withdraw that consent at any time, and it will be as easy to withdraw as it was to give. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. Following withdrawal we will cease the relevant processing and will erase the personal data unless we are required to retain it under a law in force, in which case we will tell you what we are retaining and why. Where consent supported a service you had asked for, withdrawal may mean we can no longer provide it, and we will tell you if that is the case.
Cookies and similar technologies
Our use of cookies and similar tracking technologies on the Website is dealt with separately in our Cookie Policy, available at Cookie Policy. That policy sets out the categories of cookies in use, what each of them does, how long they persist, and how you may give, refuse and later withdraw your consent to those that are not strictly necessary. It is issued alongside this Notice and should be read together with it.
Where a cookie or similar technology is used to collect personal data about you, the purpose for which that data is processed and the basis on which we process it are as set out in this Notice.
Additional information for particular relationships
Employees, contractors and candidates
We monitor the use of our systems, networks, devices, email accounts and premises access to the extent necessary to keep them secure, to protect confidential information and personal data, and to safeguard us from loss or liability. Monitoring is proportionate to that purpose, is not directed at the content of personal communications except where an investigation makes it necessary and is authorised internally, and is carried out in accordance with our information technology and acceptable use policies. We rely on Section 7(i) of the DPDP Act for this processing.
Where background verification is carried out before or during your engagement, it is limited to what is relevant to the role. We will tell you before verification is carried out, and you may ask us for its outcome.
Providing the personal data described against your category in the table in Clause 3 is a requirement of your employment or engagement. We cannot employ or engage you, pay you, or meet our statutory obligations in respect of you without it.
Investors in the Funds
Personal data described against the investor category in the table in Clause 3 is processed by us in our capacity as manager of the relevant Fund.
In the course of that processing we are required by law to disclose personal data to, among others, the Central KYC Records Registry and KYC registration agencies, the Financial Intelligence Unit – India, the Securities and Exchange Board of India, the trustee and the service providers of the relevant Fund, and the income tax authorities, including in connection with reporting under the Foreign Account Tax Compliance Act and the Common Reporting Standard. These disclosures are mandatory, are not subject to your consent, and continue after the relationship ends for as long as the law requires.
Portfolio companies and companies under evaluation
Where a Fund invests in or evaluates a company, we process personal data relating to its founders, directors, key managerial personnel and shareholders for the purposes set out against that category in the table in Clause 3. Where that personal data is given to us by the company rather than by you, the company is responsible for informing you and for having a lawful basis for providing it.
Personal data forming part of transaction documents, board and shareholder records, and Fund valuation and reporting records is retained for the periods described in Clause 12, because those records evidence the Fund’s investment and are subject to statutory record-keeping requirements.
Who we share personal data with
We share personal data only where there is a reason to, and only to the extent necessary. The categories of recipient are:
- Data processors engaged by us, including our website hosting and content delivery providers, email and productivity providers, form and survey providers, and analytics providers. We engage processors only under a valid written contract that restricts them to processing on our instructions, requires appropriate security safeguards, and prohibits use of the data for their own purposes.
- Group entities, including Axilor Ventures Private Limited, where an enquiry, application or engagement relates to a matter handled by that entity, and to the extent necessary for that purpose.
- Professional advisers, including our legal advisers, auditors, tax advisers and bankers, where necessary for the purpose for which we hold the data.
- Fund service providers, including the trustee of each Fund, the fund administrator, the registrar and transfer agent, the custodian and depository participant, the valuer and the statutory auditor of each Fund, where necessary to administer the Fund and maintain its records.
- Know-your-customer and screening infrastructure, including the Central KYC Records Registry, KYC registration agencies, depositories, and sanctions, adverse media and politically exposed person screening databases.
- Human resources service providers, including payroll, benefits and insurance providers and background verification agencies, in respect of our personnel and candidates.
- Third party evaluators, where an application is reviewed with the assistance of an external expert or mentor. Where we do this, we will have obtained your consent.
- Governmental, regulatory and law enforcement authorities, including the Securities and Exchange Board of India, the Reserve Bank of India, the Financial Intelligence Unit – India, the Registrar of Companies, the Indian Computer Emergency Response Team, the Employees’ Provident Fund Organisation and the Employees’ State Insurance Corporation, tax authorities and the Data Protection Board of India, where we are required to disclose by law or to comply with a lawful order, or where disclosure is necessary to establish, exercise or defend a legal claim.
- An acquirer or successor, in connection with a corporate reorganisation, merger or transfer of all or part of our business, subject to the recipient being bound to treat the data consistently with this Notice.
We do not sell personal data, and we do not share it with third parties for their own marketing purposes.
Transfers outside India
Some of the service providers we use store or process personal data on infrastructure located outside India. In particular, the application form referred to in Clause 4.2, our email and productivity tools, certain Fund service providers, and the sanctions and screening databases used for investor due diligence are provided by vendors that may process data outside India.
Section 16 of the DPDP Act permits the transfer of personal data outside India except to a country or territory that the Central Government has restricted by notification. We do not transfer personal data to any restricted country or territory, and we monitor any notification issued under Section 16. Where personal data is transferred outside India, our contract with the recipient requires it to apply security safeguards no less protective than those we apply ourselves, and the transfer does not reduce our accountability to you as Data Fiduciary.
Where a sectoral law or regulation applicable to us requires a category of data to be stored within India, that requirement prevails and the data is not transferred.
How we protect personal data
We implement reasonable security safeguards to prevent a personal data breach, including:
- encryption of personal data in transit and at rest, and masking or obfuscation where appropriate;
- access controls on a least-privilege basis, with multi-factor authentication on administrative and remote access;
- logging and monitoring of access to and activity on our systems, with logs retained for at least one year to enable detection, investigation and remediation of unauthorised access;
- endpoint protection, patch and vulnerability management, and hardening of our website and hosting environment;
- contractual security obligations on every processor we engage, together with periodic review of their performance;
- backup and business continuity arrangements enabling the restoration of data following an incident; and
- training and awareness for personnel who handle personal data, and a defined incident response procedure.
No system can be guaranteed to be entirely secure. Where an incident occurs, we respond in accordance with Clause 13.
Your rights
As a Data Principal you have the following rights under the DPDP Act in respect of personal data processed on the basis of your consent, and, to the extent applicable, personal data processed under Section 7(a).
Right to access information about processing
You may ask us for a summary of the personal data we are processing about you and the processing activities we are undertaking, the identities of the other Data Fiduciaries and Data Processors with whom we have shared it and a description of what was shared, and any other information prescribed in relation to that data.
Right to correction, completion, updating and erasure
You may ask us to correct inaccurate or misleading personal data, complete incomplete personal data, update personal data, and erase personal data. We will erase personal data on request unless retention is necessary for the specified purpose for which it was collected, or is required by a law in force. Where we decline to erase, we will tell you the reason.
Right of grievance redressal
You may raise a grievance with us about any act or omission of ours in relation to your personal data or the exercise of your rights, through the mechanism in Clause 16. You must exhaust that mechanism before approaching the Data Protection Board of India.
Right to nominate
You may nominate another individual to exercise your rights under the DPDP Act on your behalf in the event of your death or your incapacity by reason of unsoundness of mind or infirmity of body. To make, change or revoke a nomination, please write to our Grievance Officer.
How to exercise your rights, and our response
Please send your request to Mail ID: contactprivacy@axilor.com with enough information for us to identify you and the personal data concerned. We may ask you to verify your identity before we act, and we will not use the information you give us for verification for any other purpose. We will respond to a rights request within thirty (30) days of receiving it. There is no charge for exercising your rights.
Your duties
The DPDP Act also places duties on Data Principals. You must not impersonate another person when providing personal data, must not suppress material information when providing personal data where it is required by law, must not register a false or frivolous grievance or complaint, and must furnish only information that is verifiably authentic when exercising the right to correction or erasure. The Act provides for a penalty for breach of these duties.
How long we keep personal data
We keep personal data only for as long as it is necessary for the purpose for which it was collected, and we erase it once that purpose is no longer being served and retention is no longer necessary for a legal or business purpose. The retention period applicable to each category of personal data is set out in the final column of the table in Clause 3, and that table governs unless a longer period is required under this Clause.
Some personal data must be retained for longer because a law requires it. In particular:
- books of account and related records are retained for eight years from the end of the relevant financial year under Section 128(5) of the Companies Act, 2013;
- records relating to a transaction or a business relationship are retained for five years under the Prevention of Money-Laundering Act, 2002 and the rules made under it;
- records prescribed under the SEBI (Alternative Investment Funds) Regulations, 2012 are retained for the periods specified in those regulations, where applicable;
- records relating to employment, wages, working hours and social security contributions are retained for the periods prescribed under the applicable labour and social security legislation;
- records required for income tax purposes are retained for the periods prescribed under the Income-tax Act, 1961; and
- personal data relevant to an actual or reasonably anticipated legal proceeding, investigation or regulatory inquiry is retained until that matter is concluded and any limitation period has expired.
At the end of the applicable period, personal data is securely deleted, destroyed or irreversibly anonymised, and we instruct our processors to do the same. Our detailed retention schedule is maintained as part of our record of processing activities.
Personal data breaches
If a personal data breach occurs, we will, without delay, intimate each affected Data Principal in plain language, describing the nature, extent and timing of the breach, its likely consequences, the measures we are taking to mitigate risk, the safety measures you may take, and the contact details of the person able to answer questions on our behalf.
We will also, without delay, intimate the Data Protection Board of India of the nature, extent, timing and location of the breach, and will furnish the detailed particulars required under the DPDP Rules within seventy-two hours of becoming aware of the breach, or within such longer period as the Board may allow on request.
These obligations apply to every personal data breach; they are not limited to breaches we assess as serious. Separately, and in addition, we report cyber security incidents to the Indian Computer Emergency Response Team within six hours of noticing them or being brought to notice, as required by the CERT-In Directions of 28 April 2022, and we comply with the incident reporting obligations applicable to us as a SEBI regulated entity.
Children and persons with a disability
The Website is intended for adults and we do not direct it at children. We do not knowingly process the personal data of a child, meaning an individual who has not completed eighteen years of age, without the verifiable consent of a parent or lawful guardian, and we do not undertake tracking or behavioural monitoring of children or direct advertising at children.
We process the personal data of an individual with a disability who has a lawful guardian only with the verifiable consent of that guardian.
If you believe that we hold personal data of a child that was provided without the required consent, please contact our Grievance Officer and we will delete it.
Language and accessibility
This Notice is published in English. On request, we will make it available in any language specified in the Eighth Schedule to the Constitution of India. Please contact our Grievance Officer if you would like a copy in another language.
Grievance redressal and how to contact us
If you have a question about this Notice, wish to exercise a right, or wish to raise a grievance about how we have handled your personal data, please contact:
| Contact point | Details |
| Grievance Officer | Ms. Maggi Pouline, Head Administration Axilor Investment Advisors LLP Registered office at 58,15th Cross J.P Nagar,2nd Phase, Bangalore 560078 Email: contactprivacy@axilor.com Telephone: +91-9880834400 |
| Response timeline | We will acknowledge your grievance promptly and will respond to it within 72hours of receipt. We maintain a record of every grievance received and of how it was resolved. |
| Escalation | If you are not satisfied with our response, or if we do not respond within the stated period, you may make a complaint to the Data Protection Board of India in the manner prescribed under the DPDP Act. You must first have exhausted the mechanism described above. |
The Grievance Officer is the person able to answer questions on our behalf about the processing of your personal data for the purposes of Section 5 of the DPDP Act. Axilor has not been designated a Significant Data Fiduciary, and accordingly the Grievance Officer is not a Data Protection Officer appointed under Section 10 of the DPDP Act.
Changes to this Notice
We review this Notice at least once a year and update it when our processing changes. The current version is always available at www.axilor.com/privacy.
Where a change materially affects how we use your personal data, or where a change requires it, we will bring the change to your attention by a prominent notice on the Website and, where we hold your contact details and the change affects you, by direct communication. Where a change requires fresh consent, we will ask for it before the change takes effect. We will not apply a change retrospectively to reduce the protections that applied when your personal data was collected.
Version Detail: Ver 2.0 Dated on 01-10-2026.