Legal Policy

Privacy Policy

This Privacy Policy explains how Complimate Technologies LLP collects, processes, stores, transfers, and protects information — including Personal Data and Client Data — in connection with your access to and use of the Complimate platform, in accordance with the Digital Personal Data Protection Act, 2023 and other applicable Indian law.

Last updated: June 11, 2026Jurisdiction: IndiaApplies to: Complimate platform
1

Introduction

Welcome to Complimate ("Platform"), a cloud-based compliance management and compliance tracking Software-as-a-Service ("SaaS") platform developed and operated by Complimate Technologies LLP ("Complimate", "we", "our", or "us"), a company incorporated under the laws of India, having its registered office at 21 K1, Gumasta Nagar, Indore, Madhya Pradesh, 452009.

Complimate is designed to assist law firms, corporate entities, compliance consultants, chartered accountants, company secretaries, and other compliance professionals (collectively, "Users") in managing regulatory compliance obligations, filing requirements, statutory reminders, client records, internal compliance workflows, and related documentation through a secure digital interface.

This Privacy Policy ("Policy") describes how Complimate collects, receives, stores, processes, transfers, and protects information in connection with your access to and use of the Platform. This Policy applies to all visitors, registered users, account holders, and any persons whose data is uploaded, entered, or otherwise processed through the Platform.

BY ACCESSING OR USING THE PLATFORM IN ANY MANNER, INCLUDING BUT NOT LIMITED TO REGISTERING AN ACCOUNT, UPLOADING DATA, ACCESSING FEATURES, OR BROWSING THE PLATFORM, YOU ACKNOWLEDGE THAT YOU HAVE READ, UNDERSTOOD, AND UNCONDITIONALLY AGREE TO BE BOUND BY THIS PRIVACY POLICY IN ITS ENTIRETY. IF YOU DO NOT AGREE TO ANY PART OF THIS POLICY, YOU MUST IMMEDIATELY DISCONTINUE YOUR USE OF THE PLATFORM.

This Policy is incorporated into and forms an integral part of the Terms of Service and any other agreement you may have with Complimate. In the event of any conflict between this Policy and any specific data processing agreement, the terms of the data processing agreement shall prevail to the extent of such conflict.

Complimate reserves the right to amend, modify, or update this Policy from time to time in accordance with applicable law and operational requirements. Users are encouraged to review this Policy periodically. Your continued use of the Platform following the posting of any amendments shall constitute your acceptance of such amended Policy.

2

Definitions

  • "Account Information" means the registration details and profile data voluntarily provided by a User at the time of creating an account on the Platform, including but not limited to the User's name, email address, mobile number, organization name, designation, and login credentials.
  • "Applicable Law" means all applicable statutes, regulations, rules, orders, and judicial or regulatory interpretations in force, including but not limited to the Information Technology Act, 2000 and the rules made thereunder, the Digital Personal Data Protection Act, 2023 ("DPDP Act") and regulations issued thereunder, and any other law, regulation, or directive applicable to the collection, processing, storage, or transfer of personal data in India.
  • "Client Data" means any data, documents, records, filings, or information relating to the end-clients of a User that is uploaded, entered, stored, or otherwise processed on the Platform by or on behalf of such User, including client names, identification details, company details, regulatory filings, agreements, and similar records.
  • "Compliance Entity" means any legal entity, organization, firm, or individual that is registered on the Platform, either as a User directly or as a client whose compliance matters are managed by a User on the Platform, for the purpose of regulatory compliance tracking, filings, and related workflow management.
  • "Data Fiduciary" refers to the person or entity that, alone or in conjunction with others, determines the purpose and means of processing Personal Data. For the purposes of this Policy, Users who upload, enter, or process Client Data on the Platform shall be regarded as Data Fiduciaries with respect to such Client Data under the DPDP Act.
  • "Data Principal" means the natural person to whom Personal Data relates.
  • "Data Processor" means the person who processes Personal Data on behalf of a Data Fiduciary. Complimate acts as a Data Processor with respect to Client Data uploaded by Users onto the Platform.
  • "Personal Data" has the meaning ascribed to it under the DPDP Act and broadly refers to any data about an individual who is identifiable by or in relation to such data. For the purposes of this Policy, Personal Data includes information such as names, contact details, identification numbers, login credentials, IP addresses, and similar information relating to identifiable individuals.
  • "Platform" refers to the Complimate web application, mobile application (if any), application programming interfaces (APIs), and all related services, tools, and functionalities made available by Complimate, collectively accessible at Complimate.in and associated subdomains.
  • "Processing" means any operation or set of operations performed on Personal Data or compliance data, whether automated or manual, including collection, recording, storage, organization, structuring, adaptation, retrieval, use, disclosure, transmission, dissemination, alignment, combination, restriction, erasure, or destruction.
  • "Third-Party Services" means external service providers, vendors, technology platforms, and partners that Complimate engages to support the operation, maintenance, and functionality of the Platform, including but not limited to cloud infrastructure providers, payment gateway operators, authentication service providers, email and SMS notification providers, and analytics tool providers.
  • "Uploaded Data" means all data, content, documents, records, and files of any nature that are uploaded, transmitted, entered, or stored on the Platform by a User or by any authorized person acting on behalf of a User.
  • "User" means any individual, firm, company, or legal entity that accesses the Platform, creates an account, subscribes to any plan offered by Complimate, or otherwise uses any part of the Platform, including compliance professionals, law firms, corporate entities, consultants, and their authorized personnel.
3

Information Collected

Complimate collects information from Users in the following categories, depending on the nature of their use of the Platform.

4

Account Information

When a User registers for an account on the Platform or updates their profile, Complimate collects the following information voluntarily provided by the User, for the purpose of account creation, identity verification, communication, billing, and provision of platform services:

  • Full legal name of the User and/or the authorized representative
  • Business or personal email address
  • Mobile or telephone number
  • Name of the company, firm, or organization
  • Designation or professional role
  • Username and securely hashed password (login credentials)
  • Subscription plan and billing details, at a summary level — full payment card details are processed only by third-party payment gateways and are not stored by Complimate
5

Verification and Security Information

To protect the integrity of User accounts and the Platform, Complimate may collect and process the following security-related information, for purposes of fraud prevention, account security, unauthorized access detection, and maintaining audit trails as required by applicable law:

  • One-time passwords (OTPs) generated and transmitted for the purpose of verifying User identity during registration, login, or sensitive operations
  • Two-factor authentication ("2FA") data, including device identifiers used for authentication purposes
  • Internet Protocol (IP) address of the device used to access the Platform
  • Browser type, version, and device type (including operating system details) obtained through standard server logs or browser fingerprinting techniques
  • Login timestamps and session duration records
  • Authentication logs, including records of successful and unsuccessful login attempts, password change events, and session terminations
  • Geographic location data at a broad level derived from IP address, where relevant for security or compliance purposes
6

Uploaded Compliance and Client Data

The core functionality of the Platform enables Users to upload, store, manage, and process a wide range of compliance-related data and client records. Such Uploaded Data may include: records and identification details of the User's end-clients (individuals, companies, or entities); company incorporation documents, memoranda and articles of association, and constitutional documents; regulatory filings, statutory returns, annual reports, and compliance certificates; employee records, director details, and other HR or governance-related information; internal business records, licenses, permits, and authorization documents; correspondence, notices, orders, and communications received from regulatory or governmental bodies; contact information of clients or counterparties, including names, email addresses, phone numbers, and addresses; and any other document, file, or data set uploaded by the User or their authorized personnel for the purpose of compliance management.

In relation to Uploaded Data, Users expressly acknowledge and agree to the following:

User Responsibility: Users are solely and exclusively responsible for ensuring that they possess the requisite legal authority, authorization, and lawful basis (including, where applicable, the consent of the relevant Data Principal) to upload, store, and process any personal data or Client Data on the Platform. Complimate does not independently verify the lawfulness of data uploaded by Users and bears no responsibility for data uploaded without proper authorization.

Complimate as Intermediary and Data Processor: With respect to Uploaded Data and Client Data, Complimate acts solely as a technology platform and an Intermediary as defined under the Information Technology Act, 2000, and as a Data Processor as contemplated under the DPDP Act and applicable data protection principles. Complimate processes such data only on the instructions of Users and does not independently determine the purposes or means of processing such data.

Ownership of Uploaded Data: The ownership of all Uploaded Data, including Client Data, shall at all times vest exclusively in the User or the respective client to whom such data belongs. Complimate claims no proprietary interest in, and shall not commercially exploit, sell, license, or otherwise deal with, Uploaded Data beyond what is strictly necessary for the provision of Platform services.

7

Purpose of Data Collection and Processing

Complimate collects and processes information for the following specific, defined, and legitimate purposes:

  • Account Creation and Management: To register Users on the Platform, authenticate their identity, manage their accounts, process subscription plans, and provide account-related communications and notifications.
  • Provision of Compliance Services: To enable Users to track, manage, and fulfill their compliance obligations and those of their clients through the Platform's core features, including compliance calendars, regulatory reminders, filing status trackers, and workflow management tools.
  • Notifications and Reminders: To send compliance reminders, deadline alerts, filing notifications, and other automated communications to Users and their designated contacts through email, SMS, or in-platform notifications.
  • Document Storage and Management: To receive, store, organize, retrieve, and display compliance documents and records uploaded by Users in accordance with the Platform's functionality.
  • Platform Security and Fraud Prevention: To monitor, detect, investigate, and prevent unauthorized access, fraudulent activity, security breaches, and other threats to the Platform and its Users. This includes analyzing access logs, authentication data, and device fingerprints.
  • Customer Support: To respond to support requests, queries, grievances, and complaints raised by Users, and to maintain records of such interactions to the extent necessary for quality assurance and legal compliance.
  • Platform Improvement and Analytics: To analyze aggregated and anonymized usage patterns, feature utilization data, and technical performance metrics for the purpose of improving Platform functionality, user experience, and product development. Complimate does not use Uploaded Data or Client Data for this purpose without anonymization.
  • Billing and Payment Processing: To manage subscriptions, process payments through authorized third-party payment gateways, generate invoices, maintain financial records, and handle disputes or refunds.
  • Legal and Regulatory Compliance: To comply with applicable legal obligations, respond to lawful requests from regulatory authorities, courts, or enforcement agencies, and fulfill any reporting or record-keeping requirements under Applicable Law.
  • Communication and Marketing (with Consent): To send informational, promotional, or product-related communications to Users who have consented to receive such communications. Users may opt out of marketing communications at any time.
8

Encryption, Security, and Data Protection

Complimate considers the security of User data to be a matter of paramount importance. We have implemented, and continue to maintain, a range of technical, organizational, and administrative measures designed to protect data against unauthorized access, disclosure, alteration, or destruction.

Encryption During Transmission: All data transmitted between Users' devices and the Platform's servers is protected using industry-standard Transport Layer Security (TLS) encryption protocols (TLS 1.2 or higher), so that data exchanged during browsing, login, file upload, and other interactions cannot be intercepted in a readable format during transmission. We do not represent or warrant that end-to-end encryption is applied to all communications between Users and third-party integrations (such as email notification providers or external APIs), as the encryption standards of such third parties are governed by their own policies.

Encryption at Rest: Data stored on Complimate's servers and cloud infrastructure, including Uploaded Data, Account Information, and compliance records, is protected using encryption-at-rest mechanisms where technically feasible, in accordance with the practices of our cloud infrastructure providers. Encryption keys are managed using industry-standard key management practices.

Secure Cloud Infrastructure: The Platform is hosted on reputable, industry-recognized cloud infrastructure provider(s) that maintain relevant security certifications and comply with internationally recognized data security standards. Our infrastructure providers are required, by contract, to maintain appropriate physical and logical security controls, including but not limited to data center security, network security, and redundancy measures.

Access Control and Authentication: Access to the Platform's backend systems and databases is restricted on a strict need-to-know and role-based access control basis: unique user credentials are assigned to each employee or contractor requiring system access; privileged access to production systems is limited to a defined and minimal set of authorized personnel; multi-factor authentication is required for administrative access to core infrastructure; access rights are reviewed periodically and revoked promptly upon termination or role change; and Users on the Platform are required to authenticate using secure credentials and, where enabled, two-factor authentication.

Monitoring and Incident Management: Complimate maintains system monitoring mechanisms to detect unusual activity, potential security incidents, and unauthorized access attempts. In the event of a data breach or security incident affecting User data, Complimate shall take appropriate remedial action and notify affected Users and relevant authorities as required under Applicable Law.

Employee Security Obligations: All employees, contractors, and vendors with access to User data are subject to confidentiality obligations and undergo data security awareness training. Access to Personal Data and Uploaded Data by Complimate personnel is strictly limited to what is necessary for performing authorized functions such as platform maintenance, technical support, or security operations.

LIMITATION OF SECURITY GUARANTEE: NOTWITHSTANDING THE FOREGOING, NO METHOD OF ELECTRONIC STORAGE, TRANSMISSION, OR DATA PROCESSING IS COMPLETELY SECURE OR FREE FROM THE RISK OF INTERCEPTION, UNAUTHORIZED ACCESS, HACKING, CYBERATTACK, MALWARE, RANSOMWARE, OR OTHER FORMS OF COMPROMISE. COMPLIMATE DOES NOT WARRANT, GUARANTEE, OR REPRESENT THAT THE PLATFORM OR ANY DATA STORED THEREON IS IMMUNE TO ALL FORMS OF SECURITY THREATS OR THAT ABSOLUTE DATA SECURITY CAN BE GUARANTEED.

COMPLIMATE IMPLEMENTS COMMERCIALLY REASONABLE SECURITY MEASURES AND UNDERTAKES REASONABLE EFFORTS TO PROTECT PERSONAL DATA AND UPLOADED DATA. HOWEVER, USERS ACKNOWLEDGE THAT THEY UPLOAD, STORE, AND PROCESS DATA ON THE PLATFORM AT THEIR OWN RISK WITH RESPECT TO UNFORESEEN SECURITY INCIDENTS BEYOND COMPLIMATE'S REASONABLE CONTROL.

Users are strongly encouraged to maintain the confidentiality of their login credentials, avoid sharing account access with unauthorized persons, and report any suspected unauthorized access or security vulnerability to Complimate immediately at support@complimate.in.

9

Confidentiality and Access Restrictions

Treatment of Uploaded Data as Confidential: All Uploaded Data and Client Data processed on the Platform is treated by Complimate as strictly confidential information of the User. Complimate recognizes that such data may include sensitive business information, client records, and legally privileged material, and shall handle it with a commensurate level of care and discretion.

Restriction on Commercial Exploitation: Complimate shall not sell, rent, trade, commercially exploit, or otherwise deal in Uploaded Data or Client Data for any commercial purpose whatsoever. Complimate shall not use Uploaded Data or Client Data to train machine learning models, conduct market research, or derive commercial insights beyond what is strictly necessary for delivering the Platform's core services.

Permitted Access: Complimate personnel may access Uploaded Data or Client Data only in strictly limited and authorised circumstances: to provide technical support or perform platform maintenance tasks, where access is specifically requested or authorised by the User; to investigate security incidents, suspected breaches, or fraudulent activity affecting the Platform; as required by a court order, statutory obligation, or lawful direction from a government or regulatory authority under Applicable Law; to perform internal audits or security reviews to the minimum extent necessary; or as otherwise consented to by the User in writing. Any access by Complimate personnel for the above permitted purposes shall be conducted in accordance with applicable confidentiality obligations and limited to the minimum information necessary.

No Unauthorized Third-Party Disclosure: Complimate shall not disclose Uploaded Data or Client Data to any third party except as expressly provided in this Policy, required by Applicable Law, or consented to by the User.

10

Third-Party Services and Integrations

In order to deliver, operate, and enhance the Platform's functionality, Complimate may engage the services of trusted Third-Party Service providers. The categories of such providers include, but are not limited to, the following:

Cloud Hosting and Infrastructure Providers: The Platform is hosted on cloud infrastructure operated by recognized providers such as AWS and Azure. Such providers may process and store data, including Personal Data, on servers located within or outside the territory of India. Complimate ensures that its agreements with cloud providers include appropriate data protection obligations.

Payment Gateway Operators: Subscription fees and other payments processed through the Platform are handled by authorised third-party payment aggregators and payment gateways. Complimate does not directly collect, store, or process full payment card numbers, CVV data, or bank account credentials — such financial data is collected and processed directly by the payment gateway operators, who are responsible for securing it in accordance with applicable payment industry standards (including PCI-DSS).

Authentication and Security Providers: Complimate may use third-party services for OTP delivery, two-factor authentication, and identity verification purposes. These providers process limited authentication data solely for the purpose of verifying User identity.

Email and SMS Notification Providers: To facilitate compliance reminders, deadline alerts, and transactional communications, Complimate uses third-party email delivery and SMS service providers. These providers may process User contact information (email addresses and mobile numbers) for the purpose of delivering authorized communications.

Analytics and Performance Tools: Complimate may use analytics tools to collect aggregate, anonymized data about Platform usage, feature engagement, and performance. These tools may use cookies or similar tracking technologies. Complimate takes reasonable steps to ensure that analytics tools process only anonymized or pseudonymized data and do not receive Uploaded Data or Client Data.

Complimate enters into appropriate data processing agreements or contractual arrangements with all material Third-Party Service providers to ensure that they maintain reasonable data protection standards. However, Complimate does not control the internal privacy practices of such providers and shall not be liable for data processing activities conducted by them in contravention of their stated policies or contractual obligations.

Users acknowledge that their use of certain features of the Platform may involve the engagement of Third-Party Services and that information may be shared with such providers only to the extent strictly necessary for delivering the relevant functionality.

11

Cookies and Tracking Technologies

Use of Cookies: The Platform uses cookies and similar tracking technologies to enhance user experience, maintain session integrity, and collect aggregate usage data. Cookies are small data files placed on the User's browser or device by the Platform. The types of cookies used by Complimate include Essential/Functional Cookies (necessary for the Platform to function properly, including session management cookies that maintain the User's login state and preferences across pages); Performance and Analytics Cookies (used to collect anonymized information about how Users interact with the Platform, such as pages visited, time spent, and navigation paths, to improve Platform performance); and Security Cookies (used to detect and prevent fraudulent activity, unauthorized access, and security threats).

Session Management: Session cookies are used to maintain the authenticated state of Users during their active session on the Platform. These cookies are temporary and are deleted upon the closure of the browser session unless the User has selected a persistent login option.

Third-Party Analytics: Complimate may use third-party analytics tools that place cookies on Users' browsers to collect anonymized data about usage patterns. Such data is used only in an aggregated form and is not linked to specific individual User identities.

User Control: Most browsers allow Users to control and manage cookies through browser settings, including the option to block or delete cookies. However, disabling essential cookies may impair the functionality of the Platform, including the ability to log in or maintain sessions. Users may refer to their browser's help documentation for guidance on managing cookie preferences.

By continuing to use the Platform after being notified of the use of cookies, Users consent to the use of cookies as described in this section.

12

Data Retention

General Retention Period: Complimate retains Personal Data and Account Information for as long as a User's account remains active and for a reasonable period thereafter as necessary to fulfill the purposes described in this Policy, comply with applicable legal obligations, resolve disputes, and enforce agreements.

Uploaded Data Retention: Uploaded Data and Client Data are retained on the Platform for the duration of the User's subscription period and, following termination or cancellation of the subscription, for a post-termination period as specified in the Terms of Service or as required by Applicable Law. During this post-termination period, Complimate may retain data in a restricted state to facilitate retrieval or export by the User before permanent deletion.

Account Closure and Data Deletion: Upon a User's request for account closure or termination of subscription, Complimate will initiate the process of deleting or anonymizing the User's Account Information and Uploaded Data, subject to any legal retention obligations. Requests for data deletion should be submitted to Complimate in writing at the contact details provided in the Contact Information section below. Complimate shall make reasonable efforts to process such requests within thirty (30) days of receipt, subject to any applicable legal obligations that necessitate the retention of certain data.

Backup and Archival: Complimate may retain encrypted backups of data for business continuity and disaster recovery purposes for a limited period after deletion from active systems. Such backup copies will be deleted in accordance with Complimate's data lifecycle management practices.

Legal Retention Obligations: Notwithstanding the foregoing, Complimate may retain certain data for such longer period as may be required under Applicable Law, including financial records, security audit logs, and records required for regulatory compliance. In such cases, retained data will be stored securely, access will be restricted, and it will be used solely for the purpose for which it is retained.

13

Rights of Users and Data Principals

Subject to Applicable Law and the terms of this Policy, Users and, where applicable, Data Principals whose Personal Data is processed through the Platform, have the following rights:

  • Right to Access: Users have the right to request access to Personal Data held by Complimate in relation to their account. Upon a verified request, Complimate shall provide a summary of the Personal Data processed, subject to applicable limitations.
  • Right to Correction: Users may request the correction or updating of inaccurate, outdated, or incomplete Personal Data held by Complimate. Minor corrections (such as name, email, or phone number) may typically be made directly through the User's account settings on the Platform.
  • Right to Erasure/Deletion: Users may request the deletion of their Personal Data from Complimate's systems, subject to any legal obligations requiring retention of specific data and any contractual obligations. Note that deletion of Account Information will result in termination of the User's account and loss of access to the Platform.
  • Right to Withdraw Consent: Where the processing of Personal Data is based on the User's consent, the User has the right to withdraw such consent at any time, without affecting the lawfulness of processing conducted prior to withdrawal. Users may withdraw consent by adjusting their account settings or by submitting a written request to the Grievance Officer.
  • Right to Account Closure: Users have the right to request the closure of their Complimate account at any time, through the Platform's account settings or by written communication to the support team, subject to Complimate's right to retain certain data post-closure as required by Applicable Law.
  • Right to Grievance Redressal: Users have the right to raise complaints and grievances regarding the processing of their Personal Data with the designated Grievance Officer of Complimate. Complimate shall acknowledge grievances within forty-eight (48) hours and endeavor to resolve them within thirty (30) days of receipt, in accordance with Applicable Law.
14

Exercising Your Rights

Users are advised that rights exercised in relation to Client Data uploaded on behalf of third-party clients are the responsibility of the User as the Data Fiduciary, and Complimate's obligations in respect of such rights are limited to its role as Data Processor.

To exercise any of the rights described above, Users may contact Complimate using the details provided in the Contact Information and Grievance Officer section below.

15

Cross-Border Data Transfers

Complimate primarily processes and stores data within the territory of India. However, in connection with the use of Third-Party Services such as cloud infrastructure providers, email delivery services, or analytics tools, Personal Data and Uploaded Data may be stored on or accessed from servers located outside the territory of India.

Any cross-border transfer of Personal Data by Complimate shall be conducted in accordance with the requirements of Applicable Law, including any conditions or restrictions imposed by the DPDP Act and rules made thereunder regarding the transfer of personal data to countries or territories outside India. Where required, Complimate shall ensure that appropriate contractual or other safeguards are in place with the recipient of such data.

Users acknowledge that the use of global cloud infrastructure may result in their data being processed in jurisdictions with data protection laws that may differ from those applicable in India. By using the Platform, Users consent to such cross-border processing to the extent it occurs in connection with Complimate's Third-Party Services, subject to the safeguards described in this Policy.

17

Limitation of Liability

TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, COMPLIMATE'S LIABILITY ARISING OUT OF OR IN CONNECTION WITH THIS PRIVACY POLICY OR THE PROCESSING OF DATA ON THE PLATFORM SHALL BE SUBJECT TO THE FOLLOWING LIMITATIONS:

Cyberattacks and Unauthorized Access: COMPLIMATE SHALL NOT BE LIABLE FOR ANY LOSS, DAMAGE, DISCLOSURE, OR CORRUPTION OF DATA ARISING OUT OF CYBERATTACKS, HACKING, UNAUTHORIZED ACCESS, DATA BREACHES, RANSOMWARE, MALWARE, PHISHING, OR OTHER FORMS OF CYBERCRIME THAT OCCUR DESPITE COMPLIMATE HAVING IMPLEMENTED COMMERCIALLY REASONABLE SECURITY MEASURES.

Third-Party Failures: COMPLIMATE SHALL NOT BE RESPONSIBLE OR LIABLE FOR THE ACTS, OMISSIONS, SECURITY FAILURES, OR DATA BREACHES OF THIRD-PARTY SERVICE PROVIDERS, INCLUDING CLOUD PROVIDERS, PAYMENT GATEWAYS, AUTHENTICATION PROVIDERS, OR COMMUNICATION SERVICE PROVIDERS, WHERE SUCH FAILURES OCCUR WITHIN THE CONTROL OF SUCH THIRD PARTIES AND OUTSIDE THE REASONABLE CONTROL OF COMPLIMATE.

User Negligence and Credential Sharing: COMPLIMATE SHALL NOT BE LIABLE FOR ANY LOSS OR DAMAGE RESULTING FROM A USER'S FAILURE TO MAINTAIN THE SECURITY AND CONFIDENTIALITY OF THEIR LOGIN CREDENTIALS, UNAUTHORIZED SHARING OF ACCOUNT ACCESS, WEAK OR COMPROMISED PASSWORDS, OR ANY OTHER NEGLIGENT OR INTENTIONAL ACT OR OMISSION OF THE USER THAT RESULTS IN UNAUTHORIZED ACCESS TO THEIR ACCOUNT.

Data Uploaded Without Authorization: COMPLIMATE SHALL NOT BE LIABLE FOR ANY LEGAL CLAIMS, REGULATORY ACTION, OR THIRD-PARTY DISPUTES ARISING FROM A USER'S UPLOAD OF DATA WITHOUT PROPER LEGAL AUTHORITY OR WITHOUT THE REQUISITE CONSENT OF THE RELEVANT DATA PRINCIPALS. USERS INDEMNIFY COMPLIMATE AGAINST ALL SUCH CLAIMS, COSTS, AND LIABILITIES.

Force Majeure: COMPLIMATE SHALL NOT BE LIABLE FOR ANY FAILURE, DELAY, OR INTERRUPTION IN THE PROVISION OF SERVICES, OR ANY LOSS OR DAMAGE TO DATA, ARISING FROM CAUSES BEYOND COMPLIMATE'S REASONABLE CONTROL, INCLUDING NATURAL DISASTERS, FLOODS, EARTHQUAKES, PANDEMICS, ACTS OF GOD, ACTS OF WAR, TERRORISM, GOVERNMENT ACTIONS, INTERNET INFRASTRUCTURE FAILURES, POWER OUTAGES, OR OTHER FORCE MAJEURE EVENTS.

Aggregate Liability Cap: TO THE EXTENT PERMITTED BY APPLICABLE LAW, THE TOTAL AGGREGATE LIABILITY OF COMPLIMATE TO ANY USER ARISING OUT OF OR IN CONNECTION WITH THIS POLICY OR ANY DATA PROCESSING ACTIVITY CONDUCTED ON THE PLATFORM SHALL NOT EXCEED THE TOTAL SUBSCRIPTION FEES PAID BY SUCH USER TO COMPLIMATE IN THE THREE (3) MONTHS IMMEDIATELY PRECEDING THE EVENT GIVING RISE TO THE CLAIM.

Nothing in this section shall limit or exclude liability for fraud, gross negligence, or willful misconduct by Complimate, or any liability that cannot be excluded or limited under Applicable Law.

18

Children's Privacy

The Platform is intended exclusively for use by professionals, businesses, and adults who are legally competent to enter into binding agreements. Complimate does not knowingly collect, solicit, or process Personal Data from any individual who is below the age of eighteen (18) years.

By registering for or using the Platform, Users represent and warrant that they are at least eighteen (18) years of age. If Complimate becomes aware that it has inadvertently collected Personal Data from a person below the age of eighteen (18) years, Complimate shall take prompt steps to delete such information from its records.

Complimate strongly encourages parents and guardians to supervise the internet usage of minors and to ensure that minors do not access or register on the Platform.

19

Policy Updates and Modifications

Complimate reserves the right, at its sole discretion, to modify, amend, update, or replace this Privacy Policy at any time in response to changes in Applicable Law, regulatory requirements, business practices, or technological developments.

When material changes are made to this Policy, Complimate shall notify Users through one or more of the following means: posting an updated version of the Policy on the Platform with a revised "Last Updated" date; sending an email notification to registered Users at their recorded email address; or displaying a prominent in-platform notification.

The revised Policy shall take effect from the date of its publication on the Platform unless a later effective date is expressly stated. Your continued use of the Platform following the effective date of any such modification constitutes your acceptance of the revised Privacy Policy. If you do not agree to the modified Policy, you must cease using the Platform and may request account closure as described in the Data Retention section above.

Complimate recommends that Users review this Policy periodically to remain informed about how their information is being protected. The most current version of the Policy shall always be available on the Platform at Complimate.in/privacy.

20

Contact Information and Grievance Officer

If you have any questions, concerns, complaints, or requests relating to this Privacy Policy or the processing of your Personal Data, you may contact us using the following details.

General Support and Privacy Queries — Company Name: Complimate Technologies LLP; Support Email: support@complimate.in; Website: www.complimate.in; Business Hours: Monday to Friday, 10:00 AM to 6:00 PM IST, excluding public holidays.

Grievance Officer — In accordance with the Information Technology Act, 2000, the rules made thereunder (including the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021), and the Digital Personal Data Protection Act, 2023, Complimate has appointed a Grievance Officer for the purpose of addressing complaints and grievances from Users and Data Principals in respect of the processing of their Personal Data. Name of Grievance Officer: Angad Singh Hora; Designation: Grievance Officer; Email Address: grievance@complimate.in.

Grievances may be submitted to the Grievance Officer by email or by written communication sent by registered post to the postal address above. The Grievance Officer shall acknowledge receipt of your complaint within forty-eight (48) hours of receipt and shall endeavor to resolve and respond to the complaint within thirty (30) days of the date of receipt, or within such timeframe as may be prescribed under Applicable Law.

If you are not satisfied with the resolution provided by the Grievance Officer, you may escalate your grievance to the appropriate regulatory authority under Applicable Law, including the Data Protection Board of India once constituted under the DPDP Act.

21

Governing Law and Jurisdiction

This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of India. Any disputes arising out of or in connection with this Policy that cannot be resolved through the grievance mechanism provided herein shall be subject to the exclusive jurisdiction of the courts located at New Delhi, India.

Questions about this document?

Contact support for help with policy or account questions.

Contact support