1. Overview
Cognitosphere("we") respects your privacy. This Privacy Policy explains what information we process when you use Nerve, why we process it, how long we retain it, and your rights. This policy applies to our website, authenticated dashboard, APIs, and connected hardware devices.
For privacy enquiries or data-subject requests, contact legal@hmct.in.
2. Information we collect
Account data. Name, email address, authentication identifiers, and profile metadata supplied when you register or sign in.
Broker & portfolio data. Holdings, positions, cash balances, symbols, quantities, prices, and sync timestamps retrieved from broker APIs (e.g. Zerodha Kite) after you authorise access. Access tokens are encrypted at rest.
Device data. Hardware identifiers, pairing codes, session tokens, last-seen timestamps, Wi-Fi configuration entered on devices (stored locally on device firmware; not retained on our servers except as needed for provisioning logs), and notification delivery state.
Usage & technical data. IP address, browser type, request logs, error diagnostics, and timestamps generated by our application and database infrastructure.
3. How we use information
- Authenticate users and maintain secure sessions
- Sync and display portfolio data in the dashboard and on linked devices
- Deliver trade notifications you or your organisation configure
- Operate, secure, and improve the Service
- Comply with legal obligations and respond to lawful requests
- Communicate service updates, security notices, and support responses
We do not sell personal information. We do not use portfolio data for third-party advertising.
4. Legal bases (where applicable)
Where the Digital Personal Data Protection Act, 2023 (India) or similar laws apply, we process data based on: (a) your consent (broker linking, device pairing); (b) performance of our contract with you (providing the Service); (c) legitimate interests (security, fraud prevention, product improvement), balanced against your rights; and (d) legal obligation.
5. Sub-processors & data sharing
We use trusted infrastructure providers, including:
- Identity services — authentication and user identity
- PostgreSQL — encrypted database storage (portfolio snapshots, device registry, notification state)
- Application infrastructure — secure server-side API execution
- Zerodha Kite Connect — broker data retrieval when you connect your account
We share data only with subprocessors necessary to deliver the Service, under contractual confidentiality and security obligations, or when required by law.
6. International transfers
Sub-processors may process data in jurisdictions outside your country (including the United States and European Union). Where required, we implement appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by our vendors.
7. Retention
We retain account and portfolio data while your account is active and for a reasonable period thereafter to comply with law, resolve disputes, and maintain backups. Broker tokens are removed or invalidated when you disconnect or when tokens expire. Device session records may be retained for security auditing. You may request deletion subject to Section 8.
8. Your rights
Depending on applicable law, you may have the right to access, correct, delete, restrict, or port your personal data, and to withdraw consent where processing is consent-based. Submit requests to legal@hmct.in. We will verify your identity before fulfilling requests.
You may disconnect broker integrations and unlink devices at any time through the dashboard. Account deletion requests will be processed within 30 days unless retention is legally required.
9. Security
We employ encryption for broker tokens, HTTPS for data in transit, role-based access controls, and server-side validation for device APIs. No method of transmission or storage is 100% secure; you share information at your own risk and should protect devices and credentials.
10. Children
The Service is not directed to individuals under 18. We do not knowingly collect data from minors. Contact us if you believe a minor has provided information.
11. Changes
We may update this Privacy Policy periodically. The "Last updated" date at the top reflects the current version. Material changes will be communicated through the Service or email where appropriate.