Privacy Policy

Version 3.0

Effective date / Last updated: 16 August 2026

1. INTRODUCTION AND SCOPE

Tradesurf Research Private Limited (“the Company”, “we”, “us”, “our”), operating the Qortle platform, respects your privacy and is committed to protecting your Personal Data. This Privacy Policy explains what Personal Data we collect, how we collect and use it, whom we share it with, how long we keep it, how we protect it, and the rights available to you. It is published in compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (“SPDI Rules”), and the Digital Personal Data Protection Act, 2023 (“DPDP Act”). By using the Qortle platform or providing your Personal Data to us, you acknowledge that you have read and understood this Policy.

2. DEFINITIONS

  • “Personal Data” means any data about an individual who is identifiable by or in relation to such data.
  • “Sensitive Personal Data or Information (SPDI)” has the meaning given under the SPDI Rules and includes passwords, financial information such as bank account, card or other payment-instrument details, and any information received for processing or storage under lawful contract.
  • “Data Principal” means the individual to whom the Personal Data relates (and, for a child, includes the parent or lawful guardian, and for a person with disability, includes the lawful guardian).
  • “Data Fiduciary” means the Company, which determines the purpose and means of processing your Personal Data.
  • “Data Protection Board” means the Data Protection Board of India established under the DPDP Act.

3. INFORMATION WE COLLECT

  • Identity and contact data name, email address, phone number, postal address.
  • KYC data where you are a fee-paying client, as mandated by SEBI, collected and verified through a KYC Registration Agency (KRA).
  • Financial information (SPDI) payment-instrument details processed through secure third-party payment gateways; we do not store full card numbers on our servers.
  • Technical and usage data device information, IP address, log data, and how you use the platform.
  • Communications records of your interactions with us, including queries and grievances.

We collect only such Personal Data as is necessary for the purposes described in this Policy (data minimisation).

4. HOW WE COLLECT INFORMATION

  • Directly from you when you register, subscribe, complete KYC, make a payment, or contact us.
  • Automatically through cookies and similar technologies and server logs when you use the platform.
  • From third parties such as KYC Registration Agencies, payment gateways, and authentication providers you choose to use.

5. LAWFUL BASIS AND PURPOSE OF PROCESSING

We process your Personal Data on the basis of your consent and to perform our contract with you: to deliver and personalise research services, complete KYC and meet SEBI and other statutory/regulatory obligations, process payments, communicate service updates and notifications, maintain records required under law, and prevent fraud and ensure security. We may use Artificial Intelligence tools to provide research services; we do not make decisions producing legal or similarly significant effects about you solely by automated means without human oversight.

6. CONSENT AND WITHDRAWAL OF CONSENT

By providing your Personal Data and using the platform, you consent to its processing in accordance with this Policy; for SPDI, consent is obtained as required under the SPDI Rules. Under the DPDP Act, we provide notice of the Personal Data sought and the purpose of processing. You may withdraw your consent at any time by contacting our Grievance Officer (Section 16). Withdrawal will not affect the lawfulness of processing carried out before withdrawal, and may limit our ability to provide certain services.

7. DISCLOSURE AND SHARING

We do not sell your Personal Data. We may share it with: (a) SEBI, RAASB, KRAs and other regulatory or statutory authorities as required by law; (b) service providers and processors (e.g. payment gateways, cloud hosting, KYC agencies) engaged under written contracts with confidentiality and data-protection obligations; and (c) courts, law-enforcement or government agencies where required to comply with legal process or to protect rights, safety and property. We may also share Personal Data with a successor entity in the event of a merger, acquisition or reorganisation, subject to this Policy.

8. CROSS-BORDER DATA TRANSFER

Some of our service providers (e.g. cloud hosting or payment processing) may store or process Personal Data on servers located outside India. Any such transfer is made only to countries or territories not restricted by the Central Government under Section 16 of the DPDP Act, and subject to appropriate contractual and security safeguards. Records required to be maintained in India under SEBI regulations are retained in India.

9. DATA SECURITY

We implement reasonable security practices and procedures as required under Section 43A of the IT Act and Rule 8 of the SPDI Rules including encryption in transit, access controls, and administrative, physical and technical safeguards commensurate with the information protected. While we take reasonable steps to protect your data, no method of transmission or storage is completely secure.

10. DATA RETENTION AND ERASURE

We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected and to comply with applicable legal, regulatory (including SEBI record-keeping) and accounting requirements, after which it is deleted or anonymised. You may request erasure of your Personal Data, subject to our legal and regulatory retention obligations.

11. YOUR RIGHTS AS A DATA PRINCIPAL

Subject to applicable law, you have the right to:

  • access a summary of your Personal Data and the processing activities;
  • seek correction, completion, updating or erasure of your Personal Data;
  • withdraw your consent at any time;
  • nominate another individual to exercise your rights in the event of your death or incapacity;
  • readily available means of grievance redressal; and
  • register a complaint with the Data Protection Board of India if your grievance is not satisfactorily resolved by us.

To exercise these rights, contact our Grievance Officer (Section 16).

12. COOKIES AND TRACKING TECHNOLOGIES

We use cookies and similar technologies for authentication, analytics and to enhance your experience. You can control cookies through your browser settings; disabling them may affect certain features.

13. CHILDREN AND PERSONS WITH DISABILITY

Our services are intended for individuals 18 years of age and above. Where we process the Personal Data of a child or of a person with disability who has a lawful guardian, we obtain the verifiable consent of the parent or lawful guardian as required under Section 9 of the DPDP Act. We do not undertake tracking, behavioural monitoring, or targeted advertising directed at children.

14. PERSONAL DATA BREACH

In the event of a personal data breach, we will take prompt remedial action and will notify the Data Protection Board of India and each affected Data Principal in accordance with Section 8(6) of the DPDP Act and the rules made thereunder.

15. THIRD-PARTY LINKS

The platform may contain links to third-party websites or services (for example SEBI, SCORES, SMART ODR, or payment gateways). This Policy does not apply to those websites; we are not responsible for their content or privacy practices, and we encourage you to review their policies.

16. GRIEVANCE OFFICER

In accordance with the SPDI Rules and the DPDP Act, we have designated a Grievance Officer to address any privacy grievance and any request to exercise your rights. This role is presently held by our Compliance Officer:

Grievance Officer (also the Company's Compliance Officer): Mahesh Pratap Singh

Email: mahesh.singh@qortle.ai

Phone: +91 99231 93724

Address: D1-501 Lunkad Zodiac, Satyam Marg, Konark Nagar, Clover Park, Viman Nagar, Pune, Maharashtra 411014, India

We will acknowledge your grievance and endeavour to resolve it within the timelines prescribed under applicable law.

17. CHANGES TO THIS POLICY

We may update this Policy from time to time. The “Last updated” date above reflects the latest revision. Material changes will be notified through the platform; continued use after an update constitutes acceptance of the revised Policy.

18. GOVERNING LAW AND JURISDICTION

This Policy is governed by and construed in accordance with the laws of India. Any dispute arising in relation to this Policy shall be subject to the exclusive jurisdiction of the courts of Maharashtra.


Tradesurf Research Private Limited

Registered Office: D1-501 Lunkad Zodiac, Satyam Marg, Konark Nagar, Clover Park, Viman Nagar, Pune, Maharashtra 411014, India