Privacy Policy Consulting Division · Investment Division ·
www.emeraldandpartners.com
This Privacy Policy (“Policy”) was last updated on 10/07/2026. It applies from that date forward and replaces any earlier version published on this site.
Who This Policy Applies To
This Policy describes how JE & Co., operating under the brand name Emerald & Partners (“Emerald & Partners,” “the Firm,” “we,” “us,” or “our”), collects, uses, stores, shares, and protects personal data in connection with this website (the “Site”) and the Firm’s broader activities across its two divisions:
- The Consulting Division, which provides advisory services across strategy and growth, financial and investment readiness, operations and execution, and compliance, legal, and governance; and
- The Investment Division, which operates a dual investment vehicle deploying venture capital at the pre-seed to Series A stage and growth/private equity capital at the Series B to Series C stage, through the applicable fund, trust, or investment manager entity notified to investors from time to time (“the Fund”).
This Policy applies to all individuals whose personal data we process — including website visitors, prospective clients, prospective investors, referral contacts, and service providers — collectively referred to as “Data Principals” in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Digital Personal Data Protection Rules, 2025 (“DPDP Rules”).
We act as a Data Fiduciary under the DPDP Act in respect of personal data processed in connection with this Site and our business activities. Where we engage third-party processors to handle data on our behalf, we do so under appropriate contractual arrangements consistent with the DPDP Act.
What Personal Data We Collect and Why
We collect personal data only for lawful purposes and only to the extent necessary for those purposes. The categories below describe what we collect and why.
Identity and contact data — your name, designation, organisation, email address, and phone number — is collected to respond to enquiries, onboard consulting clients, and maintain investor communications.
Professional and business data — including your role, sector, company background, and engagement history — is used to scope mandates, assess fit, and deliver consulting services effectively.
Financial and KYC data — including PAN, identity documents, net worth declarations, bank details, and source of funds information — is collected by the Investment Division only, for the purposes of investor eligibility verification and KYC/AML compliance under SEBI and PMLA obligations.
Usage and technical data — IP address, browser type, pages visited, time on site, and referring URL — is collected automatically when you visit the Site, and is used for analytics, security monitoring, and improving user experience.
Communications data — emails, enquiry form submissions, meeting notes, and call records — is retained to deliver services, maintain accurate client records, and meet regulatory requirements.
Preferences and consent records — including marketing opt-ins, communication preferences, and consent timestamps — are maintained to ensure we contact you only in the ways you have agreed to.
We do not collect sensitive personal data as defined under the DPDP Act unless it is strictly required for a specific regulated purpose — for example, identity verification for KYC — and we have obtained your explicit consent to do so.
Legal Basis for Processing
We process personal data only where we have a valid legal basis to do so under the DPDP Act. Depending on the context, the applicable basis will be one or more of the following:
- Consent: Where you have given us clear, informed, and specific consent — for example, by submitting an enquiry form, subscribing to updates, or opting in to investor communications.
- Contractual necessity: Where processing is necessary to perform a contract with you or to take steps at your request before entering into one — for example, scoping and delivering a consulting mandate.
- Legal obligation: Where we are required to process data to comply with a law, regulation, or regulatory direction — for example, KYC, AML, and record-retention obligations under SEBI regulations, the Prevention of Money Laundering Act, 2002, and FEMA.
- Legitimate interest: Where processing is necessary for a legitimate business interest of the Firm that does not override your rights — for example, maintaining internal client records, conducting due diligence on referral sources, or securing the Site against misuse.
Where we rely on consent as the basis for processing, you may withdraw that consent at any time by contacting us at the details in Section 14. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
How We Share Personal Data
We do not sell, rent, or trade your personal data. We share it only in the following circumstances and only to the extent necessary:
- Professional advisers: Lawyers, accountants, auditors, and compliance consultants engaged by the Firm who require access to data in the course of providing their services, under confidentiality obligations.
- Regulatory and government authorities: Where disclosure is required by law, court order, or a regulatory body with jurisdiction over the Firm’s activities, including SEBI, the Financial Intelligence Unit, the Registrar of Companies, or any other competent authority.
- Co-investors and deal counterparties (Investment Division): In the context of a specific transaction or fund closing, where sharing is necessary to complete legal, KYC, or due diligence processes and where the relevant Data Principal has been informed.
- Service providers and data processors: Technology providers, cloud hosting services, and administrative platforms engaged by the Firm to support operations, each bound by a data processing agreement consistent with the DPDP Act.
- Successors and affiliated entities: In the event of a restructuring, merger, or transfer of any part of the Firm’s business, to the extent permitted by law and with appropriate safeguards.
Where we share data with parties outside India, we do so only in accordance with the cross-border transfer provisions of the DPDP Act and applicable Rules, and only where an equivalent standard of data protection is ensured.
Cookies and Site Analytics
This Site uses cookies and similar technologies to support basic functionality, analyse traffic, and improve user experience. Cookies we use fall into three categories:
- Strictly necessary cookies: Required for the Site to function. These cannot be disabled.
- Analytics cookies: Used to understand how visitors use the Site — pages visited, time spent, and navigation paths — on an aggregated and anonymised basis.
- Preference cookies: Used to remember your settings and communication preferences across visits.
You can manage or disable non-essential cookies through your browser settings or through our cookie preference panel. Disabling analytics or preference cookies will not prevent you from accessing the Site but may affect certain features.
Retention of Personal Data
We retain personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by applicable law.
- Enquiry and contact data from visitors who do not proceed to an engagement is retained for up to 12 months, after which it is deleted or anonymised.
- Consulting engagement records — including communications, deliverables, and client data — are retained for a minimum of 7 years following conclusion of the engagement, consistent with standard legal and accounting record-keeping requirements.
- Investment Division and KYC records are retained for the period required under SEBI regulations, PMLA, and FEMA — typically a minimum of 5 to 10 years from the date of the relevant transaction or the closure of the Fund, whichever is later. These obligations override shorter general retention periods.
- Site usage and technical data is retained for up to 24 months for analytics and security purposes.
On expiry of the applicable retention period, data is securely deleted or irreversibly anonymised.
Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These include access controls, encryption in transit, secure storage, and periodic security reviews of our systems and third-party processors.
No method of transmission over the internet or electronic storage is completely secure. While we take all reasonable precautions, we cannot guarantee absolute security. In the event of a personal data breach that is likely to result in harm to a Data Principal, we will notify the relevant authority and, where required by the DPDP Act and Rules, the affected individual(s), within the prescribed timeframes.
Your Rights as a Data Principal
Under the DPDP Act, you have the following rights in respect of your personal data that we hold:
- Right to access: You may request confirmation of whether we hold personal data about you and obtain a summary of the data we hold and the purposes for which it is used.
- Right to correction and erasure: You may request that we correct inaccurate or incomplete data, or erase personal data that we are no longer entitled to retain.
- Right to grievance redressal: You may raise a grievance with our Grievance Officer (see Section 14) and receive a response within the period prescribed under the DPDP Act.
- Right to nominate: You may nominate another individual to exercise your rights on your behalf in the event of your death or incapacity, in accordance with the DPDP Rules.
- Right to withdraw consent: Where processing is based on your consent, you may withdraw that consent at any time, without affecting the lawfulness of prior processing.
To exercise any of these rights, please submit a written request to our Grievance Officer using the contact details in Section 14. We will respond within the period required under the DPDP Act, and we will not charge a fee for reasonable requests.
Please note that certain rights may be subject to limitations where processing is required to comply with a legal obligation — for example, KYC and AML record-keeping requirements under SEBI regulations and PMLA.
Children's Data
This Site is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that personal data has been submitted by or on behalf of a minor without appropriate consent, we will delete it promptly.
Investment Division — Additional Privacy Terms
The following provisions apply specifically to personal data processed in connection with the Investment Division and its fund and co-investment activities.
KYC and regulatory data: Personal data collected for KYC and AML purposes — including identity documents, source of funds declarations, and financial information — is processed under legal obligation and is retained for the minimum period required by SEBI, PMLA, and FEMA, irrespective of whether an investment is ultimately made. Requests for erasure of such data cannot be fulfilled where retention is legally mandated.
Investor records and fund documents: Data contained in subscription agreements, investor questionnaires, side letters, and fund closing documents is processed and retained as part of the Fund’s legal records and is shared with the Fund’s auditors, legal counsel, and administrator as necessary for fund operations.
Co-investor and deal counterparty sharing: In connection with a co-investment or syndicated deal, limited data (name, entity, contact details) may be shared with co-investors for the purpose of completing the transaction, subject to confidentiality arrangements.
Third-Party Links
This Site may contain links to third-party websites for convenience or reference. We do not control, and are not responsible for, the privacy practices or content of any third-party site. Visiting a linked site is governed by that site’s own privacy policy.
Changes to This Policy
We may update this Policy from time to time to reflect changes in our services, structure, regulatory obligations, or applicable law. The “last updated” date at the top of this page will always reflect the current version. For material changes, we will take reasonable steps to make the update visible on this page. Continued use of the Site after an update constitutes acceptance of the revised Policy.
Regulatory Position
Where any activity of the Investment Division requires registration, licensing, or notification under Indian law — including under the SEBI (Alternative Investment Funds) Regulations, 2012 — that activity is, or will be, conducted through the appropriately registered or notified entity within the Group. This Policy does not constitute the exercise of any regulated activity. Details of the relevant registered entity are available on request and will be disclosed in full in definitive fund documentation.
Contact and Grievance Officer
For any questions about this Policy, to exercise your rights under the DPDP Act, or to raise a data-related grievance, please contact:
- Grievance Officer: Mr.Akash
- Email: akash@emeraldandparnters.com
- Registered office: 2nd Floor, Palm Heights, 22, 5th Cross Rd, Vijaya Bank Colony, Banaswadi, Bengaluru, Karnataka 560043
- General and Consulting Division enquiries: info@emeraldandparnters.com
- Investment Division enquiries: info@emeraldandparnters.com
We aim to acknowledge grievances within 48 hours and to resolve them within the period prescribed under the DPDP Act and DPDP Rules.