Data Governance

Privacy Policy

Last Updated: August 8, 2026

At The Catalyst Collective (“we,” “us,” or “our”), we are committed to protecting the privacy, confidentiality, and security of the personal data of our applicants, guests, partners, and visitors. This Privacy Policy describes how we collect, use, disclose, and safeguard your personal data in connection with our website, our invitation and partnership processes, and our events. We process personal data in accordance with the Indian Digital Personal Data Protection Act, 2023 (“DPDPA”), and other applicable global data privacy standards (such as the GDPR).

01Personal Data We Collect

We collect personal data directly from you when you interact with our website, submit an invitation or partnership request, or contact us. This includes:

  • Invitation Requests: Full name, professional email address, current organization/company, job title or role, LinkedIn profile URL, and information regarding your professional background or reasons for wanting to attend.
  • Partnership Enquiries: Name, work email, company, role, phone number, website, requested category, message, and campaign attribution parameters included in the link you used.
  • Contact Enquiries: Name, email address, subject, and the content of any correspondence or messages you send us.
  • Technical & Usage Data: IP addresses, browser type, device identifiers, operating system, page views, referral URLs, and session logs collected automatically as you navigate the website.
  • Security and Spam Verification: To protect our forms from automated abuse, we employ Google reCAPTCHA. Google collects hardware, software, and user interaction data in accordance with its own privacy policies.

02Purpose & Legal Basis of Processing

We process your personal data for the following legitimate business purposes:

  • Curation and Selection: Evaluating application requests to ensure the event is limited to its target audience of founders, investors, family office principals, and business leaders.
  • Partnership Follow-up: Assessing category availability, sharing the brochure, and discussing a potential collaboration.
  • Event Communication & Operations: Facilitating registrations, issuing personalized invitations, sending RSVP updates, coordinating access to DLF Camellias, and providing event details (such as dress code and agenda guidelines).
  • Security and Protection: Preventing spam, fraud, and unauthorized form submissions, and securing our digital infrastructure.
  • Legal and Compliance: Complying with regulatory obligations and venue requirements.

The legal bases for processing your data include: your express consent (granted when submitting the forms), our legitimate interest in curating a safe and high-quality private event, and compliance with our legal obligations.

03Strict Data Protection & Sharing Restraints

We value the privacy of our network and adhere to strict disclosure restrictions:

No Sale of Personal Data: We will never sell, lease, rent, or license your personal data to any third party for marketing or secondary commercial purposes.

Service Providers: We share your data only with trusted third-party service providers (such as hosting, database management, and email transmission services) under strict written confidentiality agreements, and only to the extent necessary to perform their services.

Venue Coordination: For security and access clearance at DLF Camellias, we may share list information of approved guests (such as name and company affiliation) with the venue security team.

Legal Mandates: We may disclose data if required by law, court order, or a government authority, or if we believe in good faith that disclosure is necessary to protect our rights, safety, or the security of our guests.

04Data Security & Retention

We implement industry-standard physical, technical, and administrative security measures (such as SSL/TLS encryption for data in transit, firewall configurations, and strictly controlled administrative access keys) to safeguard your personal data from unauthorized access, loss, misuse, or alteration.

We retain your personal data only as long as necessary to manage our events, invitations, and partnership conversations, or as required by applicable law. Data that is no longer needed will be deleted or permanently anonymized within a reasonable period. The next gathering is planned for December 2026.

05Cookies and Analytics

Our website uses basic functional cookies and analytic technologies to maintain site performance, verify that you are a human user (reCAPTCHA), and track aggregate traffic patterns. These do not construct detailed demographic profiles. You can configure your browser settings to reject cookies; however, some sections of our forms may fail to load or function correctly without cookies enabled.

06Your Rights as a Data Subject

Depending on your location and jurisdiction (including provisions under India's DPDPA and the European Union's GDPR), you hold specific rights regarding your personal data:

  • Right of Access: Obtain confirmation of processing and a copy of the data we hold about you.
  • Right to Rectification: Request correction or update of inaccurate or incomplete details.
  • Right of Erasure (“Right to be Forgotten”): Request that we permanently delete your personal data.
  • Right to Withdraw Consent: Revoke consent to process your data, where processing was based on consent. Note that withdrawing consent may mean we can no longer evaluate or issue your event invitation.
  • Right to File Grievance: Register concerns or complaints regarding how we process your personal data.

To exercise any of these rights, please contact our data controller through the contact options available on our Contact page.

07Contact and Inquiries

If you have any questions or complaints regarding this Privacy Policy or our data management practices, please reach out to us by submitting an inquiry via the Contact page. We will review and respond to your request within standard statutory timelines.