Legal / Privacy

Privacy Policy

Privacy Policy for Vistara Venture Holdings Pte Ltd. Effective 17 September 2026.

Operated by
Vistara Venture Holdings Pte Ltd
Website
www.vistaraventures.com
Effective date
17 September 2026

1. Purpose and scope

Vistara Venture Holdings Pte Ltd, a Singapore company trading as Vistara Ventures ("Vistara", "we", "us", "our"), respects privacy and is committed to handling personal information responsibly.

This Privacy Policy explains how we collect, use, disclose, store, analyze, transfer and otherwise process personal information in connection with:

  • www.vistaraventures.com and related webpages or forms;
  • investment, fundraising, M&A and transaction opportunities;
  • venture building, consulting, technology and operational services;
  • investor, founder, partner, mentor and business-development relationships;
  • recruitment and talent activities;
  • events, webinars and marketing;
  • meetings, calls, recordings, transcripts and correspondence;
  • CRM, analytics, advertising and website technologies; and
  • other Vistara business activities that refer to this Privacy Policy.

This policy is intended as a global core privacy notice and is designed to address applicable requirements in the United Kingdom, Australia, the United States, Sri Lanka, India and, where applicable, Singapore, together with other jurisdictions in which Vistara operates or interacts with individuals.

Different laws apply depending on where you are located, where Vistara operates and the nature of the processing. If a provision of this policy conflicts with a mandatory legal requirement, the mandatory requirement prevails.

2. Who is responsible for your information

Unless a separate notice or agreement states otherwise, Vistara Venture Holdings Pte Ltd is responsible for deciding why and how personal information covered by this policy is processed.

In some transactions or joint activities, another Vistara entity, portfolio company, co-investor, adviser, employer, client, service provider or transaction counterparty may be an independent controller, joint controller, data fiduciary, APP entity, organization or other legally responsible party under applicable law. Where required, the relevant arrangement will explain those roles.

For privacy questions, rights requests, complaints and marketing opt-outs, contact hello@vistaraventures.com.

3. Personal information we may collect

Depending on your relationship with Vistara, we may collect the following categories of information.

3.1 Identity and contact information

Name, title, employer, role, business address, residential address where necessary, email address, phone number, social-media handle, account identifiers and similar contact information.

3.2 Professional and business information

Employment history, company affiliations, board positions, professional profile, biography, education, qualifications, expertise, business interests, founder or investor profile, references, professional-network information and publicly available career information.

3.3 Company, investment and transaction information

Pitch decks, financial statements, cap tables, business plans, forecasts, valuations, ownership information, fundraising history, investor information, transaction documents, acquisition or sale information, data-room materials, due-diligence information, commercial contracts and information relating to a company, fund, asset or opportunity.

Some business documents may contain personal information about founders, directors, shareholders, employees, customers, suppliers, investors or other individuals.

3.4 Financial and compliance information

Where relevant and legally permitted, we may collect payment details, tax information, source-of-funds information, beneficial ownership information, sanctions and politically exposed person screening results, identity-verification information and other KYC/AML or compliance data.

We do not routinely seek sensitive financial or identity information through general website forms. Additional information may be requested during a transaction, employment process or regulated engagement.

3.5 Recruitment information

CVs, resumes, work history, qualifications, compensation expectations, interview notes, assessments, references, right-to-work information, immigration or visa status, background-check information, criminal-record information where lawful and relevant, and other candidate information.

3.6 Communications and meeting information

Emails, messages, contact-form submissions, call notes, meeting notes, recordings, transcripts, AI-generated summaries, correspondence, feedback and information you provide during conversations with us.

3.7 Website, device and usage information

IP address, browser type, device identifiers, operating system, referring pages, pages viewed, timestamps, approximate location derived from IP, cookie identifiers, advertising identifiers, interaction data, clicks, session information and security logs.

3.8 Marketing and preference information

Marketing permissions, communication preferences, event registrations, newsletter subscriptions, areas of interest, investor or founder interests, campaign engagement, unsubscribe requests, suppression records and advertising preferences.

3.9 Inferences and profiles

We may create business-related inferences, classifications or scores based on information available to us, such as likely relevance of an opportunity, investor or founder category, sector interest, lead priority, transaction fit, recruitment fit or engagement likelihood.

3.10 Sensitive or higher-risk information

Where necessary for a legitimate transaction, employment, compliance or legal purpose, we may process information that is treated as sensitive, special-category, criminal-offence or otherwise higher-risk under applicable law. This may include criminal background information, immigration or visa information, government identifiers, financial or tax information, health or disability information voluntarily provided for workplace accommodations, or other information required for due diligence or legal compliance.

We collect such information only where we have an appropriate legal basis, condition, consent, authorization or other legal permission.

4. How we collect information

We may collect personal information:

  • directly from you through forms, email, calls, meetings, applications, data rooms, submissions and contracts;
  • from your employer, company, fund, advisers, representatives, co-founders or colleagues;
  • from referrals and introductions;
  • from portfolio companies, controlled entities, co-investors, mentors, partners and transaction counterparties;
  • from professional advisers, recruiters, reference providers and service providers;
  • from public and professional sources, including LinkedIn and other professional networks, company websites, public filings, corporate registries, news articles, professional directories, event lists, investor and founder databases, conference information and other publicly accessible sources;
  • from reputable commercial data providers and business-information services;
  • from cookies, analytics, advertising technologies and Site interactions; and
  • from AI, research and enrichment tools that lawfully compile or analyze business information.

Where we obtain personal information indirectly, we provide notice or otherwise meet transparency requirements where applicable. For example, for UK personal data obtained from public or third-party sources, we will provide required privacy information within the legally required period and generally no later than first communication where applicable.

5. Why we use personal information

We may use personal information for the following purposes, subject to applicable law.

5.1 Deal flow, investing and transactions

To identify, source, assess, compare, diligence, structure, finance, invest in, acquire, sell, advise on or otherwise evaluate companies, funds, assets, investors, buyers, sellers and transaction opportunities.

5.2 Fundraising and investor introductions

To assess fundraising needs, identify potentially relevant investors or financing sources, make introductions, manage communications, support due diligence, coordinate transaction processes and administer related engagements.

5.3 Venture building, consulting and operations

To provide strategy, product, technology, AI, engineering, operations, growth, recruitment, transformation, board, mentor and other venture-building or business services.

5.4 CRM and relationship management

To maintain records of founders, companies, investors, advisers, mentors, partners, candidates, suppliers and other contacts; track communications; avoid duplicate outreach; manage relationships; and identify relevant future opportunities.

5.5 Marketing and business development

To market and promote Vistara's services, Vistara-controlled companies, portfolio companies and ventures, commercial partners, events, investment opportunities, acquisition opportunities and other relevant business opportunities, where permitted by law.

Marketing may occur through email, newsletters, direct outreach, telephone, SMS, WhatsApp, LinkedIn and other professional messaging, social-media advertising, retargeting, Google or other digital advertising, event or webinar invitations and physical mail.

We do not treat this policy as a substitute for consent where a law requires prior consent. We use consent, legitimate interests, existing-business-relationship permissions or other lawful mechanisms as applicable to the jurisdiction and channel.

5.6 Research, analytics and service improvement

To understand markets and sectors, conduct research, develop investment theses, measure engagement, improve the Site and services, test new products, evaluate campaigns, produce aggregated analytics, benchmark operations and improve Vistara's processes.

5.7 AI and automation

To use AI, machine learning and automated tools for research, document review, summarization, opportunity screening, due diligence support, lead prioritization, CRM enrichment, recruitment support, meeting transcription, product and software development, workflow automation, analytics and related activities.

5.8 Recruitment and workforce management

To recruit, assess and communicate with candidates, verify qualifications or references, manage interviews and offers, consider candidates for current or future roles and meet employment, immigration or compliance requirements.

5.9 Security, fraud prevention and compliance

To protect systems, detect misuse, verify identity, prevent fraud, conduct sanctions/KYC/AML checks where relevant, investigate incidents, enforce agreements, protect legal rights and comply with legal, regulatory, tax, accounting and reporting obligations.

5.10 Corporate transactions and administration

To manage accounting, finance, audits, insurance, governance, legal claims, business continuity and potential corporate transactions involving Vistara, including financing, restructuring, merger, acquisition or sale of all or part of our business or assets.

6. Legal bases and permissions

The legal basis for processing depends on the jurisdiction and context. Where a law requires a specific legal basis, we may rely on one or more of the following:

  • Contract and pre-contract steps: processing necessary to enter into or perform an agreement or to take requested steps before an agreement.
  • Legitimate interests: our or a third party's legitimate business interests, where those interests are not overridden by your rights and interests. Examples include B2B relationship management, deal sourcing, fraud prevention, security, service improvement, certain direct marketing, research and internal administration.
  • Consent: where you have freely given valid consent, including for certain marketing, cookies, recordings, sensitive information or other activities where required.
  • Legal obligation: processing necessary to comply with laws, court orders, regulatory requirements, sanctions, tax, employment, accounting or other obligations.
  • Legal claims and substantial public-interest conditions: where applicable to sensitive, criminal-offence or otherwise restricted information.
  • Other statutory permissions: including deemed consent, legitimate-use exceptions, business-purpose exceptions, permitted general situations or comparable permissions recognized by applicable law.

Where a jurisdiction does not use "lawful basis" terminology, we process information only where the relevant law permits the collection, use or disclosure.

For India, as the Digital Personal Data Protection Act 2023 and Digital Personal Data Protection Rules 2025 become applicable to the relevant processing, Vistara will use consent or other permitted "legitimate uses" and provide the notices, rights mechanisms and safeguards required by that framework.

For Sri Lanka, Vistara will align processing with the Personal Data Protection Act No. 9 of 2022, as amended, as relevant provisions become operational, including the key processing and controller/processor provisions commencing on 1 January 2027.

7. Direct marketing

Vistara wants to maintain commercially useful relationships while respecting marketing laws and individual preferences.

7.1 Our own marketing

Where lawful, Vistara may use business contact and relationship information to send relevant communications about:

  • Vistara services and activities;
  • Vistara-controlled companies;
  • portfolio companies and ventures;
  • events and webinars;
  • fundraising and investment opportunities;
  • acquisitions, company-sale opportunities and transaction activity;
  • relevant commercial partners; and
  • other business opportunities reasonably related to your professional interests or relationship with us.

7.2 Public-source and third-party lead data

Where legally permitted, we may collect professional contact information from public and commercial sources and add it to our CRM for business development. We consider factors such as your professional role, the source, the likely relevance of our communication, applicable consent rules and whether you have objected or opted out.

In jurisdictions requiring prior consent for a particular channel, including certain Australian commercial electronic messages, we will only contact you where we have the required consent or other legally recognized permission.

7.3 Marketing on behalf of or with other businesses

Vistara may market opportunities involving portfolio companies, ventures, controlled entities and commercial partners. Vistara may also share contact information with such third parties for their own direct marketing only where you have consented or another valid legal basis permits the direct contact.

7.4 Your marketing choices

You may opt out of marketing at any time by:

  • using the unsubscribe link in an email;
  • replying STOP or using the opt-out mechanism provided for SMS or messaging where available;
  • telling us during a call;
  • changing cookie or advertising preferences where available; or
  • emailing hello@vistaraventures.com.

We may retain a minimal suppression record after you opt out so that we do not accidentally add you back to marketing lists.

Opting out of marketing does not prevent us from sending non-marketing communications necessary for an active transaction, contract, security matter, legal obligation or requested service.

8. Cookies, analytics and advertising technologies

We may use cookies, pixels, tags, SDKs, local storage and similar technologies for:

  • essential Site functionality and security;
  • preferences and user experience;
  • analytics and performance measurement;
  • CRM and conversion tracking;
  • advertising, audience measurement and retargeting; and
  • fraud prevention and security.

Our technology stack may include services such as Google Analytics, Google Ads, Meta technologies, LinkedIn Insight Tag, Microsoft Clarity, scheduling tools, CRM tracking or equivalent future tools.

Where law requires consent for non-essential storage or access technologies, including applicable UK rules, we will not activate those technologies until the required consent is obtained. We will provide a cookie preference mechanism allowing users to reject or manage non-essential categories where required.

Where U.S. state law gives a right to opt out of "sale", "sharing" or targeted advertising, we will provide the required mechanism if our activities fall within those definitions and the relevant law applies to us. We will honor legally recognized opt-out preference signals such as Global Privacy Control where required.

9. AI and automated processing

Vistara may use third-party and internally developed AI or automated systems to process personal information for the purposes described in this policy.

Examples include:

  • extracting and summarizing information from pitch decks or company materials;
  • comparing business opportunities and markets;
  • generating meeting notes or transcripts;
  • prioritizing CRM leads or business-development opportunities;
  • supporting investment, diligence and transaction workflows;
  • supporting candidate screening and recruitment administration;
  • detecting security or fraud risks; and
  • improving products, software, internal tools and operating processes.

AI systems may generate inferences, rankings, classifications or recommendations. Material decisions are generally subject to human review where appropriate to the decision and risk involved, and we do not use solely automated decision-making with legal or similarly significant effects where prohibited by law.

For Australian individuals, from 10 December 2026, where Vistara is an APP entity and has arranged for a computer program to use personal information in making or substantially assisting a decision that could reasonably be expected to significantly affect an individual's rights or interests, this policy is intended to disclose the relevant categories of information and decision types. These may include professional,

employment, transaction, compliance, engagement and application data used for decisions concerning candidate progression, opportunity prioritization, eligibility or transaction/compliance review. Vistara will update this description if its material automated-decision practices change.

AI providers may act as processors, service providers or independent organizations depending on the service and context. We take reasonable steps to configure and contract with providers in a manner appropriate to the sensitivity of the information processed.

10. Meeting recordings and transcripts

We regularly use conferencing, recording, transcription and AI note-taking tools such as Zoom, Microsoft Teams, Google Meet, Granola or equivalent services.

We may record, transcribe, summarize and analyze meetings for note-taking, follow-up, diligence, training, quality, record-keeping and business purposes. Where applicable law requires consent or specific notice, we will obtain or provide it.

Participants should avoid sharing information they are not authorized to disclose. If you have concerns about recording, raise them before or at the start of the meeting.

11. Recruitment privacy

We may use candidate information to assess suitability for current or future roles, communicate with candidates, conduct interviews and assessments, verify references and qualifications, administer offers and meet legal obligations.

Where lawful and relevant, we may conduct background checks or process criminal-record, immigration or visa information. We do so only with the legal permission, consent or procedural safeguards required in the relevant jurisdiction.

We may retain unsuccessful candidate information for future opportunities for a reasonable period unless you request deletion or object and no overriding lawful reason requires retention.

12. Deal submissions and confidential business materials

Pitch decks, financial information, cap tables, business plans and data-room materials may include personal information. We process that information for opportunity evaluation, due diligence, investment, financing, transaction execution, advisory work, venture building, internal administration and related purposes.

The privacy treatment of personal information is separate from contractual confidentiality. Submission of materials does not by itself create an NDA or confidentiality obligation. The Website Terms explain Vistara's position on unsolicited or preliminary submissions. If contractual confidentiality is required, an NDA should be agreed before sensitive information is shared.

13. Who we disclose information to

We may disclose personal information, where lawful and reasonably necessary, to:

13.1 Vistara group and related businesses

Affiliates, controlled entities, special purpose vehicles, portfolio companies and ventures, subject to appropriate purpose and legal basis.

13.2 Service providers and processors

Providers of cloud hosting, CRM, email, productivity software, analytics, advertising, cybersecurity, AI, document management, scheduling, video conferencing, meeting transcription, accounting, finance, recruitment, applicant tracking, data rooms, legal technology and similar services.

Our expected tool categories include Google Workspace/Gmail/Drive, CRM systems, OpenAI/ChatGPT, Anthropic/Claude, Zoom/Microsoft Teams/Google Meet, Granola or comparable meeting tools, AWS/Google Cloud/Azure, Replit, accounting/finance software and recruitment/applicant-tracking systems.

13.3 Professional advisers

Lawyers, accountants, auditors, tax advisers, insurers, bankers, corporate finance advisers, consultants and other professional advisers.

13.4 Investors, companies and transaction counterparties

Potential or actual investors, co-investors, lenders, buyers, sellers, founders, companies, financing sources and transaction counterparties where relevant to an opportunity and lawful to disclose.

13.5 Recruitment parties

Recruiters, reference providers, background-check providers, immigration advisers and prospective employing entities where relevant.

13.6 Authorities and legal recipients

Courts, regulators, law enforcement, tax authorities, government agencies or other recipients where disclosure is legally required or reasonably necessary to protect rights, prevent fraud or respond to lawful requests.

13.7 Corporate transaction recipients

Potential purchasers, investors, lenders and advisers involved in a financing, restructuring, merger, acquisition or sale of Vistara or its assets, subject to appropriate safeguards.

14. Sale, sharing and targeted advertising under U.S. privacy laws

Vistara does not currently intend to sell personal information for money as a standalone data-broker business.

However, if we use advertising pixels, cookies or audience tools, disclosure of identifiers and online activity data to advertising or analytics partners may be treated as a "sale", "sharing" or use for targeted advertising under certain U.S. state privacy laws even where no money changes hands.

Where an applicable law requires it, we will provide a Your Privacy Choices or equivalent opt-out mechanism, honor qualifying browser-based opt-out signals and allow eligible individuals to opt out of such processing.

We do not knowingly sell or share for cross-context behavioral advertising the personal information of a person we know is under 16 without any opt-in authorization required by applicable law.

15. California notice and U.S. state privacy rights

This section applies where the California Consumer Privacy Act, as amended, or another U.S. state comprehensive privacy law applies to Vistara and to the individual or processing activity.

During the preceding 12 months, depending on our activities, we may have collected the following categories of personal information: identifiers and contact information; customer-record information; professional or employment information; commercial and transaction information; internet or network activity; approximate geolocation; audio or visual information from meetings; education information; inferences; and sensitive personal information where necessary for compliance, recruitment or transactions.

Sources include the individual, employers and companies, referrals, public and professional sources, service providers, commercial databases, transaction parties and Site technologies.

Business purposes include providing services, evaluating opportunities, investment and transaction work, recruitment, CRM, security, legal compliance, analytics, marketing, advertising and business administration.

Recipients may include the categories described in Section 13. Advertising partners may receive online identifiers and activity data where advertising technologies are enabled.

Subject to applicable law and verification, residents of certain U.S. states may have rights to:

  • know or access personal information;
  • receive a portable copy;
  • correct inaccurate information;
  • delete certain information;
  • opt out of sale, sharing or targeted advertising;
  • opt out of certain profiling or automated decision processing where provided by law;
  • limit certain uses or disclosures of sensitive personal information;
  • appeal a refusal of a request in states that provide an appeal right; and
  • exercise rights without unlawful discrimination or retaliation.

To exercise a right, email hello@vistaraventures.com and identify your state of residence and request. We may verify identity and authority. Authorized agents may submit requests where permitted by law.

Rights apply only to the extent the relevant law covers Vistara and the requested information; statutory exceptions may apply.

16. United Kingdom privacy rights

Where the UK GDPR and Data Protection Act 2018 apply, individuals may, subject to legal conditions and exceptions, have rights including access, rectification, erasure, restriction, portability, objection and rights concerning certain automated decision-making.

You have an absolute right to object to processing of your personal data for direct marketing, including profiling related to direct marketing. If you object, we will stop that marketing processing and may retain a suppression record to ensure your preference is respected.

Where we rely on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.

You may complain to the UK Information Commissioner's Office (ICO). If Vistara is required to appoint a UK representative under Article 27 because it has no relevant UK establishment, Vistara will publish the representative's contact details.

17. Australia privacy rights and direct marketing

Where the Australian Privacy Act 1988 and Australian Privacy Principles apply, you may request access to and correction of personal information and may make a privacy complaint.

Vistara will provide a simple means to opt out of direct marketing and will honor valid opt-out requests. Where personal information was obtained from another source, we will provide source information on request where required and not impracticable or unreasonable.

Commercial electronic messages to Australian recipients will be sent only where the Spam Act 2003 permits, including the required consent or other recognized permission, sender identification and a functional unsubscribe facility. Telemarketing will be conducted subject to applicable Do Not Call Register requirements and calling standards.

18. Sri Lanka privacy rights

Where Sri Lanka's Personal Data Protection Act No. 9 of 2022, as amended by the Personal Data Protection (Amendment) Act No. 22 of 2025, applies, Vistara will comply with applicable obligations as they become operational.

Sri Lanka's July 2026 Gazette appoints 1 January 2027 as the commencement date for Section 2, Section 3, Part I on processing of personal data and Part III on controllers and processors. Vistara is drafting and operating this policy to be forward-compatible with those requirements.

Where rights, consent, processing, security, cross-border-transfer, DPO, breach, direct-marketing or other provisions apply to Vistara, we will implement the required processes and regulatory guidance.

19. India privacy rights

India's Digital Personal Data Protection Act 2023 and Digital Personal Data Protection Rules 2025 are subject to staged commencement. As the relevant provisions become applicable, Vistara will provide required notices, obtain valid consent where required, enable withdrawal of consent, implement security and breach processes, and support applicable rights of Data Principals.

Where Indian law treats an individual as a child, Vistara will apply any required verifiable parental or guardian consent and child-data restrictions unless a statutory exemption applies.

Requests may be submitted to hello@vistaraventures.com. Where applicable, individuals may also use statutory grievance and Data Protection Board processes.

20. Singapore privacy rights

As a Singapore company, Vistara is subject to Singapore's Personal Data Protection Act 2012 (PDPA) to the extent applicable to the relevant processing. We comply with applicable notification, consent, purpose limitation, protection, retention, transfer, access/correction, accountability and breach-notification obligations.

Where applicable, individuals may request access to or correction of personal data, withdraw consent subject to legal consequences and contact Vistara regarding privacy concerns.

For marketing to Singapore telephone numbers, Vistara will comply with applicable Do Not Call Registry and identification/opt-out requirements, subject to statutory exceptions including relevant B2B communications where applicable.

21. International transfers

Vistara uses cloud, SaaS, AI, communication, CRM and other service providers operating in multiple countries. Personal information may therefore be processed in countries other than the country in which it was collected.

Likely locations may include the United States, United Kingdom, Australia, Singapore, Sri Lanka, India, countries in the European Economic Area and other jurisdictions in which our providers, advisers, transaction counterparties or affiliates operate.

Where cross-border transfer restrictions apply, we use appropriate measures depending on the law and context, which may include:

  • contractual data-protection clauses;
  • UK International Data Transfer Agreement or Addendum mechanisms where applicable;
  • transfer risk assessments where required;
  • providers or countries benefiting from an applicable adequacy or comparable-protection mechanism;
  • contractual obligations requiring comparable protection under Singapore law;
  • reasonable steps required for Australian overseas disclosures; and
  • other approved or prescribed transfer mechanisms under applicable Sri Lankan, Indian or other law as they become effective.

No transfer mechanism can eliminate every risk, but we take reasonable and legally required steps to protect transferred information.

22. Data security

We use administrative, technical and organizational measures appropriate to the nature of the information and our business. These may include access controls, role-based permissions, authentication, multi-factor authentication, encryption where appropriate, secure cloud services, logging and monitoring, backups, vendor diligence, confidentiality obligations, device and account security, security reviews and incident-response processes.

No system or transmission method is completely secure. We cannot guarantee absolute security, but we maintain safeguards designed to reduce unauthorized access, loss, misuse, alteration or disclosure.

23. Data breaches

We maintain processes for identifying, investigating, containing and responding to suspected personal-data breaches.

Where applicable law requires notification to a regulator, affected individual, customer or other party, we will make the required notification within the applicable timeframe and provide the information required by law.

24. Data retention

We retain personal information for as long as reasonably necessary for the purposes described in this policy and to meet legal, regulatory, tax, accounting, dispute, evidentiary, security and transaction requirements.

Retention depends on the category and context. Typical criteria and starting points include:

  • active business and CRM relationships: for the relationship and a reasonable period afterward while future opportunities remain relevant;
  • deal, investment, fundraising and transaction records: commonly for at least the applicable legal, tax, audit or limitation period, which may be seven years or longer depending on jurisdiction and transaction;
  • unsuccessful deal submissions: for a reasonable period, potentially up to five years or longer where there is an ongoing legitimate future-matching purpose and law permits;
  • recruitment records: generally for the recruitment cycle and a reasonable period afterward, often up to two years for future opportunities unless a longer period is required or agreed;
  • meeting recordings and transcripts: for as long as useful for the relevant engagement, diligence, record-keeping or dispute purpose, with shorter periods used where practical for routine recordings;
  • marketing records: until you opt out, object or the information is no longer useful, subject to periodic review; and
  • suppression records: for as long as needed to ensure an opt-out or objection continues to be respected.

We may retain information longer where a dispute, legal hold, regulatory inquiry, investigation, ongoing transaction or legal obligation requires it. We may retain de-identified or aggregated information where it no longer identifies an individual.

25. Accuracy and your responsibilities

Please provide accurate information and tell us when important information changes. Where we use public or third-party data, we take reasonable steps appropriate to the purpose to keep information accurate, but those sources may contain errors or become outdated.

26. Your privacy requests

To request access, correction, deletion, restriction, portability, objection, withdrawal of consent, marketing opt-out, information about sources, or another right available under applicable law, email:

hello@vistaraventures.com

Please describe your request and jurisdiction. We may request reasonable information to verify identity, authority and the scope of the request.

We will respond within the period required by applicable law. Some rights are subject to exceptions, including legal privilege, confidentiality owed to another person, legal claims, compliance requirements, transaction records, fraud prevention and information we must retain by law.

We will not discriminate unlawfully against you for exercising privacy rights.

27. Complaints

If you believe we have mishandled personal information, contact hello@vistaraventures.com. We will review the complaint and respond within a reasonable period and any legally required timeframe.

Depending on your location and the law that applies, you may also complain to the relevant privacy or data-protection regulator, including the UK ICO, the Australian OAIC, the Sri Lankan Data Protection Authority, the Singapore PDPC, India's Data Protection Board or an applicable U.S. state authority.

28. Children and younger users

The Site is not specifically designed as a children's service, but Vistara does not impose a blanket age restriction on access to public Site content.

If we process personal information about a person who is legally treated as a child in the relevant jurisdiction, we will apply the consent, parental authorization, transparency, advertising, profiling and other protections required by that law.

We do not knowingly use children's personal information for behavioral advertising or sell/share such information where prohibited. If you believe a child has provided personal information in circumstances that do not comply with applicable law, contact us so we can investigate and take appropriate action.

29. Third-party privacy practices

The Site and our communications may link to or integrate with third-party websites and services. Their privacy practices are governed by their own policies. We encourage you to review them.

Vistara is not responsible for independent third-party privacy practices, although we remain responsible for our own legal obligations when we select or instruct processors and service providers.

30. Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes in law, regulation, technology, services, business models, vendors or data practices.

The updated version will be posted on the Site with a revised effective date. Where law requires additional notice or consent for a material new use of personal information, we will provide it before the new use begins.

31. Contact details

Vistara Ventures

Vistara Venture Holdings Pte Ltd

Website: www.vistaraventures.com

Data Protection Officer / privacy contact: hello@vistaraventures.com

Vistara Ventures

Capital, leadership, execution and exit. Brought together.

Start here

Tell us what the company must become next. We will help design the right conversation.

Share your company or opportunity with us
© 2026 Vistara Ventures

Investment opportunities, capital introductions and transaction services are subject to eligibility, jurisdiction, due diligence and applicable regulatory requirements. Nothing on this website constitutes an offer, financial advice or a guarantee of investment or transaction completion.