What you are actually holding
A fundraise generates a quiet pile of personal data about identifiable people who are not your customers:
- A target list of partners with names, work emails, phone numbers, sometimes personal numbers
- Notes on individuals, such as “met at a conference, warm, decides with his partner”
- A CRM or spreadsheet tracking every conversation and its status
- Email threads, calendar invites, call recordings or transcripts
- Names and contact details of associates and analysts who never agreed to anything
- Notes on why someone passed, often including opinions about them
All of that is personal data about identifiable individuals, held by you, for your purpose.
Why it is easy to miss
Because it does not feel like data processing. It feels like keeping track of a conversation. But there is no exemption for being a small company doing something reasonable, and the material is often more sensitive than it looks, a note recording someone’s opinion of a colleague, or a recording made without a clear basis, is the kind of thing that reads badly if it ever surfaces.
The three practical exposures
- Call recordings and transcripts. The highest-risk item by a distance. If you record investor calls, including with an AI note-taker, you are processing the voice and words of identifiable people. Say so at the start and get agreement. Doing it silently is the single worst habit in this list.
- Subjective notes. “Seemed disengaged”, “his partner is the blocker”. If an individual ever exercised a right of access, these are the records you would least want to produce. Write notes you would be willing to show the person they are about.
- Retention after the round. Most founders keep the whole CRM indefinitely. There is no purpose being served two years later for investors who passed, and holding it is pure downside.
What this costs to do properly: very little
- Announce recording. One sentence at the top of the call, and stop if asked. This also just makes you easier to deal with.
- Keep notes factual. What was said and what was agreed. Opinions about people age badly and serve no purpose you cannot serve otherwise.
- Delete the pipeline after the round. Keep the relationships you actually have; delete the notes on everyone who passed. Set a date and do it.
- Do not put the investor CRM in the data room. Obvious when stated and it happens, a “fundraising” folder gets shared wholesale, and now one investor can read your notes on their competitors. That is a commercial disaster before it is a compliance one.
- Mind forwarded decks. If a partner forwards your deck internally, you may end up holding contact details of people you never spoke to. There is nothing wrong with that; there is something wrong with cold-marketing to them later on that basis.
Why a data room helps here, narrowly
The honest claim is small. A room does not manage your investor CRM, and nothing here should suggest it does.
What it changes is the fourth item above. When access is granted per person and per document, there is no “fundraising folder” that can be shared wholesale by accident, the thing you grant is the thing you chose. The mistake becomes harder to make rather than easier to recover from, which is the only kind of help worth claiming.
The other direction, the personal data inside the documents you share, is covered in DPDP and your investor data room, and how the platform maps to the Act is on the DPDP page.
A practical summary, not legal advice. Your obligations as a Data Fiduciary depend on what you process and why; take advice on your own facts.
XDrop AI is a data room for Indian fundraising, with an AI that answers investor questions and cannot read what you have not shared.
Start free