Back to JcurveIQ

JCURVEIQ — PRIVACY POLICY

Last updated: 1 July 2025

Quick Summary

  • Who we are. "JcurveIQ" is a trade name operated by a single individual (sole proprietor) whose principal place of business is Indore, India ("JcurveIQ," "we," "us").
  • What we do. AI-powered analytics SaaS for capital-markets teams; marketing site with a "Request Demo" form.
  • Why we collect data. To run the site, deliver the software, secure our systems, and keep in touch with you.
  • We don't sell personal data. Ever.
  • Your rights. GDPR/UK-GDPR, CPRA, DPDP Act and other local laws all honoured—see § 9–§ 11.
  • How to reach us. hello@jcurveiq.com

1. Scope

This Policy explains how JcurveIQ ("JcurveIQ," "we," "us") collects, uses, discloses and protects information relating to identified or identifiable individuals ("Personal Data") when you:

  • visit jcurveiq.com (the "Site");
  • request a demo;
  • communicate with us in any way.

If a capitalised term is not defined here, it has the meaning given in our End-User License Agreement (EULA) or Data Processing Addendum (DPA). Where the EULA/DPA and this Policy conflict, the DPA controls for privacy matters.

2. Information We Collect

CategoryExamplesSource
IdentifiersName, business-email, phone, employer, roleYou (web form, onboarding, emails)
Account credentialsPassword hashes, SSO tokens, API keysYou / your employer
Commerce dataBilling contacts, PO numbers, last 4 digits of card (if paid tier)You / payment processor
Usage dataIP address, device/OS, timestamps, click-streams, feature flagsAutomatic (server logs, first-party cookies, Datadog)
DiagnosticsError traces, crash dumps, minimal model promptsAutomatic
Marketing dataNewsletter opt-in, event attendance, LinkedIn lead adsYou / B2B lead providers
Derived insightsHeat-maps, aggregate analyticsOur analytics pipeline

We do not intentionally collect special-category data (GDPR Art 9) or children's data (< 16 yo). If you believe we hold such data inadvertently, email hello@jcurveiq.com.

3. Why and How We Use Personal Data

PurposeLegal basis (GDPR)Typical data used
Provide, secure & maintain the ServiceArt 6 (1)(b) contract; Art 6 (1)(f) legitimate interest in securityIdentifiers, account, usage, diagnostics
Respond to demo requests & support ticketsContract / legitimate interestIdentifiers, diagnostics
Product analytics & feature planningLegitimate interest (Art 6 (1)(f)); opt-out availableUsage, derived insights
Marketing emails & webinarsConsent (Art 6 (1)(a)) for EEA; soft opt-in for B2B under PECRIdentifiers, marketing data
Legal & compliance (export control, AML, CPRA requests)Legal obligation (Art 6 (1)(c))Identifiers, commerce, logs
AI model improvement (optional)Consent (opt-in toggle)De-identified prompts

Under India's DPDP Act we act as a Data Fiduciary; under CPRA we are a Service Provider/Contractor; under GDPR/UK GDPR we are a Controller for Site visitors and a Processor for in-product Customer Data.

4. Cookies & Similar Tech

We use first-party, non-advertising cookies to:

  • keep you logged in;
  • remember language and dark/light theme;
  • measure aggregate traffic with privacy-centric analytics (Plausible, no third-party cookies).

A banner on your first visit lets EU/UK users refuse non-essential cookies (analytics). You can also clear cookies in your browser settings.

5. How We Share Information

We currently run every part of JcurveIQ on infrastructure we directly own or control. We do not disclose, sell, rent, trade or otherwise share Personal Data with any third-party service provider, processor, sub-processor, advertiser or analytics vendor.

We will only disclose Personal Data in the following narrow circumstances:

CircumstanceTypical safeguard
Legal or regulatory demandWe comply only with lawful requests and will notify you (unless legally prohibited).
Protect our rights or the rights of othersDisclosure limited to what is strictly necessary to investigate or prevent fraud, security incidents, or legal claims.
Business re-organisation (e.g., future incorporation or asset sale)Personal Data would transfer subject to this Privacy Policy and applicable law; you will receive prior notice and the ability to opt out if legally required.

Should we begin using any external sub-processor (for hosting, email delivery, analytics, payments, etc.), we will update this Section 5 at least 10 business days before the new provider receives Personal Data.

6. International Data Transfers

  • EU/UK → US. Secured via EU 2021 Standard Contractual Clauses + UK IDTA.
  • Brazil → US. Art 33 adequacy mechanisms or SCCs equivalents.
  • India → US. Until DPDP "whitelist" rules take effect, transfers continue under SPDI Rules adequacy + contractual safeguards; we will update once final DPDP Rules are in force.

7. Security

Technical & organisational measures (TOMs):

  • TLS 1.3 everywhere; HSTS preload;
  • AES-256-GCM at rest;
  • RBAC + mandatory MFA for privileged accounts;
  • daily encrypted backups (30-day retention, cross-region);
  • continuous vulnerability scanning; critical CVEs patched ≤ 7 days;
  • annual external penetration test; SOC 2 (Type 1) report under NDA.

Despite these controls no system is 100% secure; see § 11 for liability limits.

8. Retention

Default retention periods:

DataLiveArchived / anonymised
Demo-form submissions24 monthsDeleted
Account & billingLife of contract + 7 years (tax)Deleted
Usage & diagnostics logs18 monthsAggregated, then deleted
Marketing unsubscribesIndefinite (suppression list)

You can request earlier deletion (subject to legal holds).

9. Your Privacy Rights

RegionRightsHow to exercise
EEA / UKAccess, rectification, deletion, restriction, portability, objection, lodge complaint with DPAEmail hello@jcurveiq.com
California (CPRA)Know, access, correct, delete, opt-out of "sale/share", limit use of sensitive data, no retaliationhello@jcurveiq.com
Virginia / Colorado / Utah / ConnecticutAccess, correct, delete, data portability, opt-out of profilinghello@jcurveiq.com
Brazil (LGPD)Confirm processing, access, correct, anonymise, delete, portability, revocationhello@jcurveiq.com
India (DPDP)Access, correction, erasure, grievance redress (§ 13)hello@jcurveiq.com

We will verify your identity (email confirmation or reasonable KYC) and respond within the statutory deadline (30 – 45 days, region-specific).

10. Children

The Site and Service are business-to-business (B2B) and not directed to children under 16. We do not knowingly collect children's Personal Data. If you believe we have done so, contact hello@jcurveiq.com for deletion.

11. Disclaimers & Liability

Site-visit data is provided "as is." We make no warranties beyond those in our EULA. To the maximum extent permitted by law, our total liability for privacy-related claims is limited to USD 100 (or fees paid in the preceding 12 months for paying customers). See EULA § 10 for details.

12. Changes to this Policy

We may update this Policy from time to time. Material changes will be announced by:

  1. revising the "Last updated" date above;
  2. banner or email (if you hold an active account) 30 days before changes take effect.

Continued use after the effective date constitutes acceptance.

Annex A – California "Notice at Collection"

We collect: identifiers; professional info; internet activity (logs).

Purposes: as set out in § 3 above.

Retention: see § 8.

We do not sell or share Personal Data as "sell/share" is defined by the CPRA. You can exercise CPRA rights via hello@jcurveiq.com.