Privacy Policy

The page you're looking for no longer exists. Let us take you back.

The page you're looking for no longer exists. Let us take you back.

Scaalex Consulting

Effective Date: 20/09/2026 Applies to: www.scaalex.com and app.scaalex.com (the "Scaalex Project Intelligence & Documentation Agent")

1. Introduction

Scaalex Consulting ("Scaalex," "we," "us," "our") is an India-based M&A and capital advisory consulting firm. This Privacy Policy explains how we collect, use, store, share, and protect personal data through our marketing website (scaalex.com) and our client engagement platform (app.scaalex.com), including its client portal.

This Policy is issued in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and related rules. Where our clients or data principals are located outside India, or where a client's own compliance obligations require it, we also reference principles consistent with the EU General Data Protection Regulation ("GDPR") as a matter of good practice, without claiming direct applicability unless required by law.

Under the DPDP Act, Scaalex acts as a "Data Fiduciary" in respect of personal data it processes, and in many engagements our clients are themselves Data Fiduciaries with respect to their own stakeholders' data, with Scaalex acting as a processor/data processor on their instructions. Where relevant, this relationship is governed additionally by the data processing terms in our client engagement agreements.

2. Who This Policy Covers

  • Website visitors to scaalex.com.

  • Staff users: Scaalex employees, partners, and authorized personnel who access app.scaalex.com to manage client engagements.

  • Client portal contacts: individuals designated by our clients to access the client portal within app.scaalex.com to view engagement progress, respond to information requests, and upload/download documents.

  • Third parties named or referenced within engagement materials, such as individuals mentioned in meeting transcripts, board resolutions, cap tables, or other client documents, whose data we process solely on behalf of, and under instruction from, our clients.

3. Data We Collect

3.1 From website visitors (scaalex.com)

  • Contact form submissions (name, email, phone number, company, message content).

  • Basic technical and usage data (IP address, browser type, pages visited, referring URL) if analytics or similar tools are enabled. See Section 10 (Cookies) for detail.

3.2 From staff users (app.scaalex.com)

  • Account information: name, work email, role/designation, authentication credentials.

  • Activity data: sign-in timestamps, actions taken within the platform (uploads, edits, access changes), and system audit logs.

  • Content created or handled in the ordinary course of engagement work, including meeting notes, task assignments, and internal comments.

3.3 From client portal contacts

  • Contact and identity information: name, email, mobile number, designation, and employer/company name.

  • Session-based login credentials for the client portal (a lighter-weight, separate authentication mechanism from staff login).

  • Activity data: sign-ins, document uploads/downloads, and responses to information requests, all captured in audit logs.

3.4 Client company and engagement data

  • Client company details: legal/registered name, trading name, registered address, GST number, and website.

  • Uploaded documents and files, which may include contracts, financial statements, term sheets, capitalization tables, board resolutions, due diligence materials, and other engagement-related records. These may contain commercially sensitive and, in some cases, personal data of individuals named within them (e.g., signatories, directors, employees of the client or counterparties).

  • Meeting recordings and transcripts synced from Fireflies.ai, and AI-generated summaries, decision logs, and action-item extractions derived from that content using Anthropic's Claude API.

  • Milestones, decisions, and task/team management records associated with each engagement.

3.5 What we do not collect

We do not knowingly collect special category or sensitive personal data (such as health, biometric, or genetic data) as a matter of our standard service offering. If such data is incidentally present within client-uploaded documents or transcripts, it is processed solely as part of the underlying engagement content, under the client's instructions and responsibility, and is subject to the same security controls described in Section 8.

4. How We Use Data

We use personal data for the following purposes:

  1. Service delivery: to provide, operate, and maintain the platform, manage engagements, track milestones and decisions, and enable collaboration between staff and client portal contacts.

  2. AI-assisted processing: to generate summaries, extract decisions and action items from meeting transcripts and conversation content, using Anthropic's Claude API. This processing is engagement-specific and is used to support, not replace, the professional judgment of Scaalex advisors.

  3. Meeting transcription and scheduling: to record, transcribe, and sync meeting content via Fireflies.ai, and to schedule meetings via Google Calendar integration (OAuth-based).

  4. Account and access management: to authenticate users, manage roles and permissions, and maintain audit logs of activity for security and accountability purposes.

  5. Client communication: to respond to information requests, share engagement updates, and enable document exchange.

  6. Legal, regulatory, and compliance purposes: to meet our obligations under applicable law, including anti-money laundering, tax, and professional conduct requirements applicable to advisory firms, and to respond to lawful requests from regulators or courts.

  7. Backup and business continuity: to maintain daily backups of platform data for disaster recovery.

  8. Website and marketing: to respond to inquiries submitted through scaalex.com and, where consented to, to send updates about our services.

We do not sell personal data to third parties, and we do not use client engagement content (transcripts, documents, financial data) to train any third-party AI model beyond the processing necessary to deliver the requested output within that engagement, except where a subprocessor's own terms (e.g., Anthropic's API terms) govern such processing and we have confirmed those terms are consistent with this commitment at the time of engagement.

5. Legal Basis for Processing

Under the DPDP Act, 2023, our processing of personal data is based on one or more of the following grounds:

  • Consent: for website visitors submitting contact forms, and for client portal contacts at the time of onboarding, where explicit consent is obtained for processing of their personal data for engagement purposes.

  • Legitimate use (as recognized under the DPDP Act for specified purposes such as employer-employee relationships, and for purposes for which the data principal has voluntarily provided data and not indicated non-consent), including staff user account data processed in an employment context.

  • Contractual necessity: processing necessary to perform our engagement agreement with the client, including managing the client's data on their instructions.

  • Compliance with law: processing required under applicable Indian law, including tax, corporate, and regulatory obligations.

Where GDPR-equivalent standards are relevant (for clients or data subjects with EU/UK nexus), we additionally align our practices with the principles of lawfulness, purpose limitation, data minimization, and accountability, and rely on legitimate interest, contractual necessity, or consent as the applicable basis, consistent with GDPR Article 6.

6. Third-Party Subprocessors and Data Sharing

We engage the following subprocessors to help us deliver the platform. This list reflects our subprocessors as of the effective date of this Policy and will be kept current; clients may request an updated list at any time by contacting us using the details in Section 13.

SubprocessorRoleNature of Data ProcessedRender.comApplication hosting (web service with persistent disk)All platform data, including database records and uploaded files, as hosted infrastructureCloudflare (R2)Backup storage (S3-compatible object storage)Encrypted daily backups of platform data and filesAnthropicAI processing (Claude API)Meeting transcripts and conversation content, for the purpose of generating summaries and extracting decisions/action itemsFireflies.aiMeeting recording and transcriptionAudio/video recordings and transcripts of client and internal meetingsGoogleCalendar integration (OAuth)Calendar metadata (meeting times, participant emails) for scheduling purposes

We do not share personal data with any other third party except: (a) as required by law, regulation, or valid legal process; (b) with our professional advisors (auditors, lawyers) under confidentiality obligations, where necessary; (c) in connection with a corporate transaction (merger, acquisition, financing) involving Scaalex, subject to confidentiality safeguards; or (d) with the data principal's consent.

Each subprocessor is engaged under terms that require appropriate confidentiality and security commitments. We select subprocessors that provide industry-standard security practices, but clients should note that no subprocessor arrangement eliminates all risk, and clients remain responsible for determining, before uploading any document, whether its use of these subprocessors (particularly cross-border AI and cloud providers) is consistent with the client's own regulatory or contractual obligations, including any restrictions on offshore data processing applicable to the client's own business.

7. Cross-Border Data Transfer

Render, Cloudflare, and Anthropic may process or store data on infrastructure located outside India. Scaalex takes reasonable steps to ensure such transfers are made only to jurisdictions and service providers offering an adequate standard of protection, consistent with the DPDP Act's framework for cross-border transfers (which currently permits transfers except to countries specifically restricted by the Central Government). Where a client requires data residency restricted to India or a specific jurisdiction, this must be flagged in writing before onboarding, as it may affect the availability of certain features (e.g., AI summarization, backup redundancy).

8. Data Retention

  • Active engagement data (documents, transcripts, summaries, decisions, milestones): retained for the duration of the client engagement and thereafter for such period as is necessary for legal, regulatory, tax, or dispute-related purposes, or as otherwise agreed in the applicable engagement letter, typically not exceeding [RETENTION PERIOD, e.g., 7 years] post-engagement unless a longer period is required by law or requested by the client in writing.

  • Backups: daily backups are retained on Cloudflare R2 for 30 days on a rolling basis, with monthly backups retained for a longer period as part of our disaster recovery program. Data deleted from the live platform may persist in backups until the applicable backup retention period lapses, after which it is permanently purged.

  • Client portal contact accounts: retained while the individual has an active role in the engagement, and deactivated (with underlying activity logs retained per the audit log policy below) upon the client's confirmation that the contact no longer requires access.

  • Staff user accounts: retained for the duration of employment/engagement with Scaalex, and thereafter as required for employment record-keeping and audit purposes.

  • Audit logs (sign-ins, uploads, downloads, access changes): retained for a minimum period sufficient to support security investigations and compliance obligations, typically [AUDIT LOG RETENTION PERIOD, e.g., 3 years], after which they are archived or deleted in accordance with our internal data retention schedule.

On expiry of the applicable retention period, or upon a valid erasure request under Section 11 (subject to the exceptions described there), we will delete or anonymize the relevant personal data, including from active systems, within a reasonable period, recognizing that complete removal from backup media occurs upon the natural expiry of the backup retention cycle described above.

9. Data Security

We implement security measures that are reasonable and appropriate for the nature of the data we handle, including:

  • Encryption of data in transit (TLS) and of backup data at rest.

  • Role-based access controls, so that staff and client portal users can access only the engagements and data relevant to their role.

  • Separate, session-based authentication for the client portal, distinct from staff authentication, to limit the scope of any single credential compromise.

  • Audit logging of sign-ins, uploads, downloads, and access changes to support monitoring and post-incident investigation.

  • Daily encrypted backups to a geographically separate storage provider (Cloudflare R2), providing a recovery path in the event of primary infrastructure failure.

  • Periodic review of access permissions and prompt deactivation of accounts upon offboarding.

No system can be guaranteed to be completely secure, and we do not represent that our security measures will prevent every possible unauthorized access, loss, or breach. We continuously review and improve these measures as our platform and threat landscape evolve.

10. Cookies and Tracking (scaalex.com)

Our marketing website may use cookies and similar technologies for the following purposes: essential site functionality, basic analytics to understand site usage, and, where applicable, marketing/retargeting if such tools are enabled. [If analytics/marketing tools such as Google Analytics are in use, they should be specifically named here, together with a cookie consent banner offering visitors the ability to accept or reject non-essential cookies, in line with best practice and applicable law.] The application (app.scaalex.com) does not use marketing or advertising cookies; it uses only strictly necessary session cookies required for authentication and platform functionality.

11. Rights of Data Principals

Under the DPDP Act, 2023, individuals whose personal data we process (data principals) have the following rights, which may be exercised by contacting our Grievance Officer (Section 13):

  • Right to access: to obtain a summary of the personal data we hold and the processing activities undertaken.

  • Right to correction and completion: to request correction of inaccurate or incomplete personal data.

  • Right to erasure: to request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to our right to retain data where required by law, for legal claims, or under legitimate retention obligations (including the backup retention cycle described in Section 8).

  • Right to grievance redressal: to raise a complaint regarding our processing of personal data, which we will address within a reasonable time.

  • Right to nominate: to nominate another individual to exercise these rights on their behalf in the event of death or incapacity.

  • Right to withdraw consent: where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out prior to withdrawal.

Where a data principal's personal data forms part of client engagement documents (e.g., they are named in a contract or cap table uploaded by our client), requests concerning that data should generally be directed to the relevant client, as the Data Fiduciary responsible for that data; we will support our client in responding to such requests as required under our engagement terms.

Individuals dissatisfied with our response may escalate a complaint to the Data Protection Board of India, once constituted and operational under the DPDP Act.

12. Data Breach Notification

In the event of a personal data breach that Scaalex determines, in accordance with the DPDP Act, requires notification, we will: (a) notify the Data Protection Board of India in the manner and timeframe prescribed under applicable rules; (b) notify affected data principals and, where the affected data was processed on a client's instructions, notify the relevant client without undue delay, describing the nature of the breach, the likely consequences, and the measures taken or proposed to address it; and (c) take reasonable steps to contain, investigate, and remediate the breach. This obligation exists regardless of any contrary term in our client agreements and cannot be waived or limited by contract.

13. Children's Data

Scaalex's website and platform are intended for business and professional use and are not directed at, nor knowingly used by, individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.

14. Grievance Officer / Contact

For any questions, requests, or complaints regarding this Privacy Policy or our data practices, please contact our Grievance Officer, appointed in accordance with the DPDP Act, 2023:

Grievance Officer: Anand Pv Email: anand@scaalex.com Address: 1178, Kalyan Nagar, Bangalore, 560043

We aim to acknowledge grievances within a reasonable period and resolve them as promptly as possible.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, subprocessors, or applicable law. We will post the updated version on scaalex.com and app.scaalex.com with a revised effective date, and, for material changes affecting client data, we will provide additional notice to affected clients where practicable.



Scaalex Consulting

Effective Date: 20/09/2026 Applies to: www.scaalex.com and app.scaalex.com (the "Scaalex Project Intelligence & Documentation Agent")

1. Introduction

Scaalex Consulting ("Scaalex," "we," "us," "our") is an India-based M&A and capital advisory consulting firm. This Privacy Policy explains how we collect, use, store, share, and protect personal data through our marketing website (scaalex.com) and our client engagement platform (app.scaalex.com), including its client portal.

This Policy is issued in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and related rules. Where our clients or data principals are located outside India, or where a client's own compliance obligations require it, we also reference principles consistent with the EU General Data Protection Regulation ("GDPR") as a matter of good practice, without claiming direct applicability unless required by law.

Under the DPDP Act, Scaalex acts as a "Data Fiduciary" in respect of personal data it processes, and in many engagements our clients are themselves Data Fiduciaries with respect to their own stakeholders' data, with Scaalex acting as a processor/data processor on their instructions. Where relevant, this relationship is governed additionally by the data processing terms in our client engagement agreements.

2. Who This Policy Covers

  • Website visitors to scaalex.com.

  • Staff users: Scaalex employees, partners, and authorized personnel who access app.scaalex.com to manage client engagements.

  • Client portal contacts: individuals designated by our clients to access the client portal within app.scaalex.com to view engagement progress, respond to information requests, and upload/download documents.

  • Third parties named or referenced within engagement materials, such as individuals mentioned in meeting transcripts, board resolutions, cap tables, or other client documents, whose data we process solely on behalf of, and under instruction from, our clients.

3. Data We Collect

3.1 From website visitors (scaalex.com)

  • Contact form submissions (name, email, phone number, company, message content).

  • Basic technical and usage data (IP address, browser type, pages visited, referring URL) if analytics or similar tools are enabled. See Section 10 (Cookies) for detail.

3.2 From staff users (app.scaalex.com)

  • Account information: name, work email, role/designation, authentication credentials.

  • Activity data: sign-in timestamps, actions taken within the platform (uploads, edits, access changes), and system audit logs.

  • Content created or handled in the ordinary course of engagement work, including meeting notes, task assignments, and internal comments.

3.3 From client portal contacts

  • Contact and identity information: name, email, mobile number, designation, and employer/company name.

  • Session-based login credentials for the client portal (a lighter-weight, separate authentication mechanism from staff login).

  • Activity data: sign-ins, document uploads/downloads, and responses to information requests, all captured in audit logs.

3.4 Client company and engagement data

  • Client company details: legal/registered name, trading name, registered address, GST number, and website.

  • Uploaded documents and files, which may include contracts, financial statements, term sheets, capitalization tables, board resolutions, due diligence materials, and other engagement-related records. These may contain commercially sensitive and, in some cases, personal data of individuals named within them (e.g., signatories, directors, employees of the client or counterparties).

  • Meeting recordings and transcripts synced from Fireflies.ai, and AI-generated summaries, decision logs, and action-item extractions derived from that content using Anthropic's Claude API.

  • Milestones, decisions, and task/team management records associated with each engagement.

3.5 What we do not collect

We do not knowingly collect special category or sensitive personal data (such as health, biometric, or genetic data) as a matter of our standard service offering. If such data is incidentally present within client-uploaded documents or transcripts, it is processed solely as part of the underlying engagement content, under the client's instructions and responsibility, and is subject to the same security controls described in Section 8.

4. How We Use Data

We use personal data for the following purposes:

  1. Service delivery: to provide, operate, and maintain the platform, manage engagements, track milestones and decisions, and enable collaboration between staff and client portal contacts.

  2. AI-assisted processing: to generate summaries, extract decisions and action items from meeting transcripts and conversation content, using Anthropic's Claude API. This processing is engagement-specific and is used to support, not replace, the professional judgment of Scaalex advisors.

  3. Meeting transcription and scheduling: to record, transcribe, and sync meeting content via Fireflies.ai, and to schedule meetings via Google Calendar integration (OAuth-based).

  4. Account and access management: to authenticate users, manage roles and permissions, and maintain audit logs of activity for security and accountability purposes.

  5. Client communication: to respond to information requests, share engagement updates, and enable document exchange.

  6. Legal, regulatory, and compliance purposes: to meet our obligations under applicable law, including anti-money laundering, tax, and professional conduct requirements applicable to advisory firms, and to respond to lawful requests from regulators or courts.

  7. Backup and business continuity: to maintain daily backups of platform data for disaster recovery.

  8. Website and marketing: to respond to inquiries submitted through scaalex.com and, where consented to, to send updates about our services.

We do not sell personal data to third parties, and we do not use client engagement content (transcripts, documents, financial data) to train any third-party AI model beyond the processing necessary to deliver the requested output within that engagement, except where a subprocessor's own terms (e.g., Anthropic's API terms) govern such processing and we have confirmed those terms are consistent with this commitment at the time of engagement.

5. Legal Basis for Processing

Under the DPDP Act, 2023, our processing of personal data is based on one or more of the following grounds:

  • Consent: for website visitors submitting contact forms, and for client portal contacts at the time of onboarding, where explicit consent is obtained for processing of their personal data for engagement purposes.

  • Legitimate use (as recognized under the DPDP Act for specified purposes such as employer-employee relationships, and for purposes for which the data principal has voluntarily provided data and not indicated non-consent), including staff user account data processed in an employment context.

  • Contractual necessity: processing necessary to perform our engagement agreement with the client, including managing the client's data on their instructions.

  • Compliance with law: processing required under applicable Indian law, including tax, corporate, and regulatory obligations.

Where GDPR-equivalent standards are relevant (for clients or data subjects with EU/UK nexus), we additionally align our practices with the principles of lawfulness, purpose limitation, data minimization, and accountability, and rely on legitimate interest, contractual necessity, or consent as the applicable basis, consistent with GDPR Article 6.

6. Third-Party Subprocessors and Data Sharing

We engage the following subprocessors to help us deliver the platform. This list reflects our subprocessors as of the effective date of this Policy and will be kept current; clients may request an updated list at any time by contacting us using the details in Section 13.

SubprocessorRoleNature of Data ProcessedRender.comApplication hosting (web service with persistent disk)All platform data, including database records and uploaded files, as hosted infrastructureCloudflare (R2)Backup storage (S3-compatible object storage)Encrypted daily backups of platform data and filesAnthropicAI processing (Claude API)Meeting transcripts and conversation content, for the purpose of generating summaries and extracting decisions/action itemsFireflies.aiMeeting recording and transcriptionAudio/video recordings and transcripts of client and internal meetingsGoogleCalendar integration (OAuth)Calendar metadata (meeting times, participant emails) for scheduling purposes

We do not share personal data with any other third party except: (a) as required by law, regulation, or valid legal process; (b) with our professional advisors (auditors, lawyers) under confidentiality obligations, where necessary; (c) in connection with a corporate transaction (merger, acquisition, financing) involving Scaalex, subject to confidentiality safeguards; or (d) with the data principal's consent.

Each subprocessor is engaged under terms that require appropriate confidentiality and security commitments. We select subprocessors that provide industry-standard security practices, but clients should note that no subprocessor arrangement eliminates all risk, and clients remain responsible for determining, before uploading any document, whether its use of these subprocessors (particularly cross-border AI and cloud providers) is consistent with the client's own regulatory or contractual obligations, including any restrictions on offshore data processing applicable to the client's own business.

7. Cross-Border Data Transfer

Render, Cloudflare, and Anthropic may process or store data on infrastructure located outside India. Scaalex takes reasonable steps to ensure such transfers are made only to jurisdictions and service providers offering an adequate standard of protection, consistent with the DPDP Act's framework for cross-border transfers (which currently permits transfers except to countries specifically restricted by the Central Government). Where a client requires data residency restricted to India or a specific jurisdiction, this must be flagged in writing before onboarding, as it may affect the availability of certain features (e.g., AI summarization, backup redundancy).

8. Data Retention

  • Active engagement data (documents, transcripts, summaries, decisions, milestones): retained for the duration of the client engagement and thereafter for such period as is necessary for legal, regulatory, tax, or dispute-related purposes, or as otherwise agreed in the applicable engagement letter, typically not exceeding [RETENTION PERIOD, e.g., 7 years] post-engagement unless a longer period is required by law or requested by the client in writing.

  • Backups: daily backups are retained on Cloudflare R2 for 30 days on a rolling basis, with monthly backups retained for a longer period as part of our disaster recovery program. Data deleted from the live platform may persist in backups until the applicable backup retention period lapses, after which it is permanently purged.

  • Client portal contact accounts: retained while the individual has an active role in the engagement, and deactivated (with underlying activity logs retained per the audit log policy below) upon the client's confirmation that the contact no longer requires access.

  • Staff user accounts: retained for the duration of employment/engagement with Scaalex, and thereafter as required for employment record-keeping and audit purposes.

  • Audit logs (sign-ins, uploads, downloads, access changes): retained for a minimum period sufficient to support security investigations and compliance obligations, typically [AUDIT LOG RETENTION PERIOD, e.g., 3 years], after which they are archived or deleted in accordance with our internal data retention schedule.

On expiry of the applicable retention period, or upon a valid erasure request under Section 11 (subject to the exceptions described there), we will delete or anonymize the relevant personal data, including from active systems, within a reasonable period, recognizing that complete removal from backup media occurs upon the natural expiry of the backup retention cycle described above.

9. Data Security

We implement security measures that are reasonable and appropriate for the nature of the data we handle, including:

  • Encryption of data in transit (TLS) and of backup data at rest.

  • Role-based access controls, so that staff and client portal users can access only the engagements and data relevant to their role.

  • Separate, session-based authentication for the client portal, distinct from staff authentication, to limit the scope of any single credential compromise.

  • Audit logging of sign-ins, uploads, downloads, and access changes to support monitoring and post-incident investigation.

  • Daily encrypted backups to a geographically separate storage provider (Cloudflare R2), providing a recovery path in the event of primary infrastructure failure.

  • Periodic review of access permissions and prompt deactivation of accounts upon offboarding.

No system can be guaranteed to be completely secure, and we do not represent that our security measures will prevent every possible unauthorized access, loss, or breach. We continuously review and improve these measures as our platform and threat landscape evolve.

10. Cookies and Tracking (scaalex.com)

Our marketing website may use cookies and similar technologies for the following purposes: essential site functionality, basic analytics to understand site usage, and, where applicable, marketing/retargeting if such tools are enabled. [If analytics/marketing tools such as Google Analytics are in use, they should be specifically named here, together with a cookie consent banner offering visitors the ability to accept or reject non-essential cookies, in line with best practice and applicable law.] The application (app.scaalex.com) does not use marketing or advertising cookies; it uses only strictly necessary session cookies required for authentication and platform functionality.

11. Rights of Data Principals

Under the DPDP Act, 2023, individuals whose personal data we process (data principals) have the following rights, which may be exercised by contacting our Grievance Officer (Section 13):

  • Right to access: to obtain a summary of the personal data we hold and the processing activities undertaken.

  • Right to correction and completion: to request correction of inaccurate or incomplete personal data.

  • Right to erasure: to request deletion of personal data that is no longer necessary for the purpose for which it was collected, subject to our right to retain data where required by law, for legal claims, or under legitimate retention obligations (including the backup retention cycle described in Section 8).

  • Right to grievance redressal: to raise a complaint regarding our processing of personal data, which we will address within a reasonable time.

  • Right to nominate: to nominate another individual to exercise these rights on their behalf in the event of death or incapacity.

  • Right to withdraw consent: where processing is based on consent, to withdraw it at any time, without affecting the lawfulness of processing carried out prior to withdrawal.

Where a data principal's personal data forms part of client engagement documents (e.g., they are named in a contract or cap table uploaded by our client), requests concerning that data should generally be directed to the relevant client, as the Data Fiduciary responsible for that data; we will support our client in responding to such requests as required under our engagement terms.

Individuals dissatisfied with our response may escalate a complaint to the Data Protection Board of India, once constituted and operational under the DPDP Act.

12. Data Breach Notification

In the event of a personal data breach that Scaalex determines, in accordance with the DPDP Act, requires notification, we will: (a) notify the Data Protection Board of India in the manner and timeframe prescribed under applicable rules; (b) notify affected data principals and, where the affected data was processed on a client's instructions, notify the relevant client without undue delay, describing the nature of the breach, the likely consequences, and the measures taken or proposed to address it; and (c) take reasonable steps to contain, investigate, and remediate the breach. This obligation exists regardless of any contrary term in our client agreements and cannot be waived or limited by contract.

13. Children's Data

Scaalex's website and platform are intended for business and professional use and are not directed at, nor knowingly used by, individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.

14. Grievance Officer / Contact

For any questions, requests, or complaints regarding this Privacy Policy or our data practices, please contact our Grievance Officer, appointed in accordance with the DPDP Act, 2023:

Grievance Officer: Anand Pv Email: anand@scaalex.com Address: 1178, Kalyan Nagar, Bangalore, 560043

We aim to acknowledge grievances within a reasonable period and resolve them as promptly as possible.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, subprocessors, or applicable law. We will post the updated version on scaalex.com and app.scaalex.com with a revised effective date, and, for material changes affecting client data, we will provide additional notice to affected clients where practicable.



Founder Story

Founder Story

A consulting practice shaped by experience

Over the years, this work revealed a consistent pattern: most businesses aren’t held back by lack of talent or ambition—they’re slowed down by unclear priorities, inefficient processes, and fragmented decision-making. This practice was built to solve those problems directly.
Every engagement is grounded in deep analysis, honest conversations, and a commitment to helping teams operate with sharper focus and stronger execution.

Founded in

2022

Serving worldwide from

London, UK

Get started

Considering a transaction, or a year from one?

We help leaders navigate complexity, solve critical challenges, and build stronger, more resilient organizations for the future.

Stay updated

Perspectives on deals, capital and judgment - occasionally, not often.
By subscribing you agree to our Privacy Policy and provide consent to receive updates.

Copyright© Scaalex Consulting

Independent M&A and capital advisory

Get started

Considering a transaction, or a year from one?

We help leaders navigate complexity, solve critical challenges, and build stronger, more resilient organizations for the future.

Stay updated

Perspectives on deals, capital and judgment - occasionally, not often.
By subscribing you agree to our Privacy Policy and provide consent to receive updates.

Copyright© Scaalex Consulting

Independent M&A and capital advisory

Get started

Considering a transaction, or a year from one?

We help leaders navigate complexity, solve critical challenges, and build stronger, more resilient organizations for the future.

Stay updated

Perspectives on deals, capital and judgment - occasionally, not often.
By subscribing you agree to our Privacy Policy and provide consent to receive updates.

Copyright© Scaalex Consulting

Independent M&A and capital advisory