Legal / privacy

Privacy Policy

What Maitro collects, why it is used, how long it is retained, who processes it, and how applicants or members can exercise rights.

DPDP-awareGDPR-awareNo data saleNo AI training on application contentRetention scheduleSub-processors listed

Claim discipline

Premium does not mean reckless.

This page separates current controls, roadmap targets, illustrative tools, gated economics, and agreement-controlled terms so senior leaders can evaluate Maitro without mistaking posture for guarantee.

Policy

Minimum necessary data

Maitro collects identity, application, membership, payment, communication, and security telemetry needed to run the site and tiers.

Current wording

No sale or model training

Public policy states no data sale and no AI model training on application content.

Careful residency

Primary India posture

Primary hosting is described as India/Mumbai posture, with limited global sub-processors listed plainly.

Version

Policy version

28 April 2026 / Version 2.0 / presentation refreshed 26 May 2026

Presentation has been upgraded for readability. Legal meaning should remain subject to founder/legal review before being treated as final advice.

1. Who we are

Maitro is operated by Talpro India Private Limited. Talpro India Private Limited is the Data Fiduciary under India privacy framing and the controller for personal data processed through maitro.tech where applicable.

Privacy and grievance requests should be sent to privacy@maitro.tech.

2. What we collect

GroupExamplesPurpose
VisitorsIP, user agent, page path, referrerSecurity, abuse prevention, aggregate analytics
ApplicantsName, work email, role, LinkedIn, venture brief, references, conflict disclosuresEligibility, review, conflict scan, communication
MembersTier, posts, comments, attendance, preferencesOperate Society, Boardroom, Spotlight, and related services
Paid usersBilling email, GSTIN where provided, payment confirmation tokensInvoicing, payment, statutory records
CommunicationsEmail threads, form messages, booking metadataSupport, scheduling, records, legal hold where needed

3. Purpose and lawful basis

Maitro processes personal data for application review, tier operation, requested materials, conflict review, invoices, royalty administration where applicable, fraud prevention, security, and legal obligations. Statutory references should be reviewed by counsel before being treated as legal advice.

4. Retention schedule

RecordRetentionNote
Server logs and security telemetryShort operational period, currently stated as 30 daysSubject to security/legal hold.
Unsuccessful applicationsUp to 90 days, then deletion/purge cycle where implementedUsed for review and conflict scanning.
Active membersMembership plus policy retention periodNeeded for service continuity and records.
Build Lab recordsAgreement and statutory periodsRoyalty/tax/company records may need longer retention.
Invoices and tax recordsStatutory record periodTypically aligned to Indian tax/company law.

5. Sub-processors and transfers

Maitro does not sell personal data. Limited sub-processors support hosting, email, payments, authentication, anti-bot, analytics, scheduling, error telemetry, and selected AI-assisted workflows.

VendorPurposeData categoryRegionStatusNotes
Hostinger KVMApplication hostingApplication, member, and operational recordsMumbai / India postureCurrentPrimary production hosting. Exact backup region should be founder/security-confirmed.
CloudflareDNS, CDN, DDoS protection, Turnstile anti-botNetwork metadata, anti-bot tokens, request metadataGlobal edgeCurrentDo not claim absolute India-only residency while global edge services are used.
BrevoTransactional and newsletter emailEmail address, message metadata, transactional contentEU / vendor-controlledCurrentEmail implementation imports Brevo client.
RazorpayPayment processingCheckout, payment, invoice, and payment confirmation dataIndia / vendor-controlledCurrentMaitro does not receive full card numbers.
ClerkAuthentication and session managementIdentity, email, session tokensUS / vendor-controlledCurrentUsed on authenticated surfaces. Public pages may set no cookies before sign-in.
Cal.com or CalendlyOffice-hours schedulingCalendar metadata and booking detailsVendor-controlledConfigured path variesBook route supports provider-aware embeds. Avoid naming one exclusive provider in policy copy.
Sentry-compatible telemetry / GlitchTipError and performance telemetryError metadata, route, runtime contextConfigured environmentCurrent when DSN configuredTelemetry should be scrubbed for personal data where practical.
Anthropic via internal AI proxySpotlight content assistance and internal drafting workflowsLimited non-PII content artifacts where configuredExternal dependencyCurrent for selected pipelinesDo not claim application content is used for model training. Do not send secrets or unnecessary PII.

6. Your rights

Depending on residence and applicable law, you may request access, correction, erasure, withdrawal of consent, restriction, portability, grievance redressal, or nomination. Maitro may verify identity and may refuse or limit requests where law, security, contracts, or statutory records require it.

7. Cookies, breach handling, automated decisions, and children

Maitro uses strictly necessary session/security cookies on authenticated surfaces and cookieless aggregate analytics on public pages. Breach notifications follow applicable law, contract, and policy; public pages should avoid universal deadlines beyond legal requirements. Maitro does not knowingly serve children under 18 and does not make solely automated decisions that produce legal or similarly significant effects.

FAQ

Privacy Policy FAQ

Does Maitro sell personal data?

No. Maitro policy states no data sale. Limited sub-processors may process data on Maitro's instruction.

Does Maitro train AI models on application content?

No public policy should say application content is used for model training. Selected AI drafting workflows must remain minimized and non-PII where configured.

Does all data stay in India?

Primary hosting has an India/Mumbai posture, but some sub-processors operate globally. The policy should not say every byte stays in India.

Policy route

Need this reviewed for your situation?

Use the correct Maitro lane for billing, privacy, legal, or security questions. Do not send confidential idea/IP content through open email.

Maitro uses only strictly necessary session cookies and privacy-first, cookieless analytics. No advertising cookies are set. See our Cookie Policy.