Legal Β· Effective 2026

Privacy Policy

Manalang Ventures LLP, trading as First500days
Last updated: 1st September, 2026

1. Who we are

Manalang Ventures LLP (β€œwe”, β€œus”, β€œour”), a limited liability partnership registered in India under LLPIN ACJ-6750, trading as First500days, is the controller of the personal data described in this policy. Our registered office is New Delhi, India, 110015.

We are a venture-building and business consulting firm. We work with founders in India, the United Kingdom, the European Union, the UAE, Singapore, Canada and elsewhere, which means we handle personal data across borders and under more than one privacy law. This policy explains what we collect, why, who we share it with, how long we keep it, and what you can do about it.

2. Who this policy covers

  • Website visitors β€” anyone browsing first500days.com
  • Enquirers β€” people who contact us, book a consultation, or request an assessment
  • Clients and prospective clients β€” founders and businesses we work with, and their team members
  • Applicants for our Academy programmes
  • Mentors, advisers, contractors and suppliers
  • Job applicants

3. What personal data we collect

3.1 Information you give us

Enquiry and consultation data. Name, email address, phone number, country, company name, website, your role, your idea or business, sector, stage, and what you want help with.

Client engagement data. Everything needed to deliver the services: business and financial information, market and customer data, product plans, team details, and correspondence with us.

Founder visa engagement data. Where we support a founder or startup visa case, this is more extensive and more sensitive. It can include: your full name and any former names, date and place of birth, nationality and citizenship, passport and travel document details, current and past visa and immigration history including any refusals, addresses and residence history, education and employment history, qualifications, professional memberships, marital status and details of your partner and children where they are part of your plans, financial information including bank statements, funding, savings and evidence of maintenance, and tax residence.

Special category and equivalent data. Some of the above may reveal, or include, information treated as sensitive under privacy law β€” for example information revealing racial or ethnic origin, religious belief, health information where a route or application requires it, and information about criminal convictions or offences where a route requires a declaration. We collect this only where it is genuinely necessary for the engagement you have asked us to carry out, and we ask you not to send us sensitive information we have not requested.

Programme and event data. Registration details, attendance, and submissions for Academy cohorts, workshops and webinars.

Recruitment data. CV, work history, education, right-to-work information and interview notes.

3.2 Information we collect automatically

IP address, approximate location derived from it, device and browser type, operating system, referring URL, pages viewed, time on page, links clicked, and similar analytics β€” collected through cookies and comparable technologies where you have consented. See our Cookie Policy.

3.3 Information from other sources

Publicly available sources such as LinkedIn, company registries and company websites; referrals from clients, partners or mentors; and information from advisers you have asked to work with us.

4. Why we use your data, and our legal basis

Where UK or EU data protection law applies, we rely on the bases below. Where Indian law applies, we rely principally on your consent, or on legitimate uses permitted by the Digital Personal Data Protection Act 2023.

  • Respond to enquiries and hold consultation calls: To answer you and assess fit. Legal basis: legitimate interests β€” responding to a request you made.
  • Prepare proposals and engagement letters: To agree terms. Legal basis: steps prior to entering a contract.
  • Deliver our services: To do the work you engaged us for. Legal basis: performance of a contract.
  • Prepare founder visa business cases and endorsement documentation: To deliver the engagement. Legal basis: performance of a contract.
  • Process special category data within a visa engagement: Because the route requires it. Legal basis: your explicit consent, and where applicable establishment or defence of legal claims.
  • Process criminal offence information where a route requires a declaration: Because the route requires it. Legal basis: your explicit consent, under appropriate safeguards.
  • Invoice, take payment and keep accounts: To run the business and meet tax law. Legal basis: legal obligation; legitimate interests.
  • Send service and account communications: To keep you informed about live work. Legal basis: performance of a contract.
  • Send marketing emails and newsletters: To tell you about our services. Legal basis: consent, or legitimate interests for existing clients on comparable services.
  • Website analytics: To improve the site. Legal basis: consent.
  • Advertising and campaign measurement: To reach relevant founders. Legal basis: consent.
  • Publish testimonials, case studies and client names: To show our work. Legal basis: consent β€” always asked for separately and in writing.
  • Security, fraud prevention and IT administration: To protect the business and your data. Legal basis: legitimate interests; legal obligation.
  • Recruitment: To assess applicants. Legal basis: steps prior to a contract; legitimate interests.
  • Establish, exercise or defend legal claims: To protect our position. Legal basis: legitimate interests; legal obligation.

Where we rely on legitimate interests, we have considered whether those interests are overridden by your rights, and you may object at any time β€” see clause 10.

5. What we do not do

  • We do not sell your personal data.
  • We do not share your data with third parties for their own marketing.
  • We do not make decisions with legal or similarly significant effects about you by automated means alone.
  • We do not require sensitive personal data beyond what an engagement genuinely needs.
  • We do not submit information about you to any authority without your knowledge and instruction.

6. Who we share your data with

Immigration advisers and lawyers. Where you ask us to, or where you engage an adviser we introduce you to, we share what is needed for them to advise and act. They are independent controllers of the data you give them.

Endorsing bodies, designated organisations and authorities. Where an engagement involves preparing an endorsement or support application, documentation containing your personal data is submitted to the relevant body β€” by you, or by your adviser, or by us on your written instruction.

Professional and commercial partners. Accountants, company formation agents, banks, trademark and IP agents, and similar, where an engagement requires it.

Professional advisers and authorities. Our own lawyers, accountants and insurers; and regulators, courts or law enforcement where we are legally required to disclose.

Business transfer. If our business or part of it is reorganised, sold or merged, data may transfer to the acquirer under confidentiality obligations.

7. Use of AI tools

We use AI-assisted software in parts of our work β€” for example in research, drafting and analysis. Where we do, we use business or enterprise arrangements that do not permit the provider to train public models on client content, and we do not put client-identifying or sensitive personal data into consumer AI tools. Human review sits behind every deliverable. If you would prefer we did not use AI tools in your engagement, tell us and we will accommodate it where practicable.

8. International transfers

We are established in India, with teams and offices in India, the UAE and Singapore. If you are in the UK or the EU, your personal data will be transferred outside your country β€” including to India β€” and accessed by our teams there.

India, the UAE and Singapore have not been the subject of a UK or EU adequacy decision. Where we transfer personal data from the UK or the EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and, for UK transfers, the UK International Data Transfer Agreement or the UK Addendum, together with a transfer risk assessment and additional technical and organisational measures where required.

You can request a copy of the safeguards we use by emailing [email protected].

9. How long we keep it

  • Website analytics: Up to 14 months, or as set in the tool.
  • Enquiries that do not become engagements: 24 months from last contact.
  • Client engagement records and deliverables: 7 years from the end of the engagement.
  • Founder visa engagement files, including sensitive data: 7 years from the end of the engagement, unless you ask us to delete sooner and we are not required to keep it.
  • Invoices and accounting records: 8 years, or as required by Indian tax law.
  • Marketing contacts: Until you unsubscribe, plus 12 months.
  • Consent records for cookies: 6 months, then re-asked.
  • Recruitment β€” unsuccessful applicants: 12 months.
  • Contracts and signed terms: 7 years from expiry.

We review retention periodically and delete or anonymise data that is no longer needed. Where you ask us to delete sensitive visa data earlier and we have no legal reason to keep it, we will.

10. Your rights

Depending on where you are, you may have the right to:

  • Be informed about how we use your data β€” this policy
  • Access the personal data we hold about you
  • Correct data that is inaccurate or incomplete
  • Erase data where there is no good reason for us to keep it
  • Restrict processing in certain circumstances
  • Object to processing based on legitimate interests, and to direct marketing at any time
  • Portability β€” receive data you gave us in a machine-readable format
  • Withdraw consent at any time, without affecting processing already carried out
  • Nominate another person to exercise your rights if you die or become incapacitated (under Indian law)
  • Complain to a regulator

To exercise any of these, email [email protected]. We may need to verify your identity. We respond within 30 days, and will tell you if we need longer. There is no charge unless a request is manifestly unfounded or excessive.

Complaints. You can complain to us first β€” we would prefer that β€” via the Grievance Officer above. You may also complain to:

  • India β€” the Data Protection Board of India
  • United Kingdom β€” the Information Commissioner's Office, ico.org.uk
  • EU/EEA β€” your national supervisory authority
  • Singapore β€” the Personal Data Protection Commission
  • UAE β€” the relevant data protection authority for your emirate or free zone

11. Marketing

We send marketing only where we are permitted to. Every marketing email carries an unsubscribe link, and you can opt out of WhatsApp or SMS by replying STOP or writing to us. Opting out of marketing does not stop necessary communications about a live engagement or an application in progress.

12. Cookies

We use cookies and similar technologies. Non-essential cookies are set only with your consent, which you can change at any time via Cookie settings in the footer. See our Cookie Policy for the full list.

13. Security

We use access controls, encryption in transit, role-based permissions, confidentiality obligations for staff and contractors, and vetted providers. Visa engagement files, which contain identity and financial documents, are held in restricted-access storage available only to the team working on that engagement.

No system is completely secure. If a breach occurs that is likely to result in a risk to you, we will notify you and the relevant regulators within the timeframes the applicable law requires.

Please do not send passports, bank statements or other identity documents by ordinary email or WhatsApp. We will give you a secure upload method.

14. Children

Our services are for adults and our website is not directed at children. We do not knowingly collect data from anyone under 18. Where a founder visa engagement involves dependent children, we process only what the route requires, on the instruction of their parent or guardian, and we apply the verifiable parental consent requirements of applicable law. If you believe a child has given us data, contact us and we will delete it.

15. Third-party sites

Our website links to third-party sites and platforms, including LinkedIn, Instagram, YouTube and WhatsApp. Their privacy practices are their own and this policy does not cover them.

16. Changes to this policy

We update this policy as our services, tools and obligations change. The β€œlast updated” date shows when it last changed. Where changes are significant, we will tell clients with an active engagement directly.