Privacy Policy
Privacy Policy
LEGAL NOTICE
This Privacy Policy is published in compliance with the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules framed thereunder, the Information Technology Act, 2000 ("IT Act"), and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), to the extent applicable. This document constitutes a Notice under Section 5 of the DPDP Act.
Veritect Pte. Ltd. (UEN: 202518753N), a company incorporated in Singapore ("Company"), is the sole owner and operator of the Platform at agent.veritect.ai and is the Data Fiduciary for all users of the Platform globally. The Company exclusively owns the Platform software, controls all data processing infrastructure, and determines the purpose and means of processing all personal data.
In India, access to the Platform's services may be made available through Veritect Pvt Ltd or other third-party merchant of record platforms, acting solely as authorised resellers and/or merchants of record for billing and payment purposes. Veritect Pvt Ltd is a separate and independent legal entity. The Company holds no equity, ownership stake, or controlling interest in Veritect Pvt Ltd, and the directors of the Company have no directorship or ownership interest in Veritect Pvt Ltd. The Authorised Reseller does not own, operate, or control the Platform, and does not have access to, custody of, or control over any personal data processed through the Platform.
1. Definitions and Interpretation
In this Privacy Policy, unless the context otherwise requires:
"Company" or "Veritect" means Veritect Pte. Ltd., a private company limited by shares incorporated in Singapore (UEN: 202518753N), with its registered office at Singapore Business Federation Center, 160 Robinson Road, #14-004, Singapore 068914.
"Authorised Reseller" means Veritect Pvt Ltd, a company incorporated in India, which operates as an independent authorised reseller and merchant of record for the Platform in India. The Authorised Reseller is a separate and independent legal entity and is not a subsidiary, affiliate, or branch of the Company. The Company holds no equity, ownership stake, or controlling interest in the Authorised Reseller.
"Data Fiduciary" means Veritect Pte. Ltd., which solely and exclusively determines the purpose and means of processing of personal data on the Platform, as defined under Section 2(i) of the DPDP Act. The Company owns the Platform, controls all software, infrastructure, and data processing operations. The Authorised Reseller does not determine the purpose or means of processing personal data and does not have access to, control over, or custody of any personal data processed through the Platform.
"Merchant of Record" means the entity responsible for processing payments, managing billing, and handling applicable tax compliance (including GST) for transactions on the Platform. The Merchant of Record may be the Authorised Reseller or a third-party merchant of record platform engaged by the Company from time to time.
"Data Principal" means you, the individual to whom the personal data relates, as defined under Section 2(j) of the DPDP Act.
"Data Processor" means any person who processes personal data on behalf of the Data Fiduciary, as defined under Section 2(k) of the DPDP Act.
"Platform" means the Veritect AI legal technology platform accessible at agent.veritect.ai, including all associated web applications, APIs, mobile applications, and services operated by the Company.
"Personal Data" means any data about an individual who is identifiable by or in relation to such data, as defined under Section 2(t) of the DPDP Act.
"Processing" means performing any operation or set of operations on personal data, including collection, recording, organisation, structuring, storage, adaptation, retrieval, use, alignment, combination, indexing, sharing, disclosure, restriction, erasure, or destruction, as defined under Section 2(x) of the DPDP Act.
"Significant Data Fiduciary" means a Data Fiduciary notified by the Central Government under Section 10 of the DPDP Act, subject to additional obligations.
Words and expressions used but not defined in this Policy shall have the meanings assigned to them under the DPDP Act and the IT Act, as applicable.
2. Personal Data We Collect
We collect and process the following categories of personal data, strictly limited to what is necessary for the specified purposes:
2.1 Account and Identity Data
Email address (used as primary account identifier); full name; profile photograph URL (received from the third-party authentication provider); account creation and last login timestamps.
2.2 Case and Document Data
Case titles, metadata (including case type, court name, jurisdiction, client name, and opposing party details); documents uploaded by you in supported formats (PDF, DOCX, and other formats); processed document content including text extracted through Optical Character Recognition ("OCR") and markdown conversion; notes, annotations, and tags you create within the Platform.
2.3 Research and Interaction Data
Research queries and chat messages submitted to the Platform; AI-generated outputs including summaries, timelines, legal analysis, and research memoranda; conversation and session history; saved research templates and preferences.
2.4 Technical and Usage Data
Authentication tokens and session identifiers; Internet Protocol ("IP") address (collected for security, rate limiting, and fraud prevention); browser user agent string (for security logging and compatibility); device identifiers; timestamps of all account activity; feature usage patterns and interaction logs; error logs and diagnostic data.
2.5 Data We Do Not Collect
We do not collect financial information (such as credit card numbers or bank account details) directly. All payment processing is handled by PCI-DSS compliant third-party payment processors. We do not collect biometric data, genetic data, or data revealing racial or ethnic origin, political opinions, religious beliefs, or trade union membership.
3. Purpose and Lawful Basis for Processing
We process your personal data only for the following specified and lawful purposes, in accordance with Sections 4 and 7 of the DPDP Act:
| Purpose | Consent Type | Description |
|---|---|---|
| Core Platform Services | Required | Account creation and management; user authentication and authorisation; case management and document storage; document retrieval and organisation; access control enforcement. |
| AI-Powered Features | Optional | AI-generated document summaries and legal analysis; document embeddings for semantic and hybrid search; research chat (large language model-based); case memory and timeline generation; document translation and OCR processing. |
| Security and Compliance | Legitimate Use (Section 7) | Fraud prevention and detection; rate limiting and abuse prevention; security incident investigation; compliance with applicable law and regulatory obligations; audit trail maintenance. |
| Service Improvement | Optional | Aggregated and anonymised usage analytics; system performance monitoring; feature development informed by usage patterns. No individual personal data is used for this purpose without separate consent. |
| Cross-Border Transfer | Disclosure | Transfer of data to Data Processors located outside India for AI processing, authentication, infrastructure, and related services. See Section 8 for full details. |
4. Consent Framework
In accordance with DPDP Act Section 6, we obtain your free, specific, informed, and unconditional consent before processing your personal data. Our consent framework operates as follows:
4.1 Required Consent (Core Services)
Consent for core platform services is required to use the Platform. Without this consent, we cannot provide case management, document storage, or basic platform functionality. This consent is obtained at the time of account registration through a clear, affirmative action.
4.2 Optional Consent (AI Features)
Consent for AI-powered features is strictly optional. You may use the Platform for document storage, case management, and basic organisation without enabling any AI features. If AI consent is withheld, the following features will be unavailable: AI-generated summaries and analysis, research chat, semantic search, document embeddings, automated timeline generation, and document translation. You may enable AI features at any time by providing consent through your account settings.
4.3 Granular Consent Controls
We provide granular consent management through your account settings, allowing you to enable or disable specific categories of data processing independently. Each consent category is presented with a clear description of the processing activities it authorises and the consequences of withholding or withdrawing consent.
4.4 Withdrawal of Consent
You may withdraw consent for any processing purpose at any time through the consent management interface in your account settings. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal (DPDP Act Section 6(6)). Upon withdrawal, we shall cease the relevant processing within a reasonable period not exceeding 72 hours, except where continued processing is required under applicable law.
4.5 Consent for Minors
Veritect AI is a professional legal technology platform intended exclusively for use by legal professionals, law firms, and authorised representatives. We do not knowingly process personal data of individuals below the age of 18 years. Should we become aware that personal data of a minor has been processed, we shall delete such data without undue delay, in accordance with Section 9 of the DPDP Act.
4.6 Trial, Demo, and Free Accounts
This Privacy Policy applies equally and in its entirety to all categories of accounts on the Platform, including but not limited to paid subscription accounts, free-tier accounts, trial accounts, demo accounts, evaluation accounts, and any other form of access granted by the Company (collectively, "Accounts"). The nature, scope, and protections afforded to personal data under this Policy do not vary based on the type of Account or whether any fees are payable.
For trial and demo accounts specifically: (a) All personal data collected during the trial or demo period is subject to the same security safeguards, consent requirements, and data processing limitations described in this Policy. (b) Upon expiry of a trial or demo period, if the Account is not converted to a paid subscription, the Account will be treated as inactive and subject to our data retention schedule in Section 6. (c) You retain the right to request erasure of all personal data at any time during or after a trial or demo period. (d) We shall not use personal data collected during a trial or demo period for marketing or promotional purposes without your separate, explicit consent. (e) Any data you upload, create, or generate during a trial or demo period remains your property and is subject to the same intellectual property protections described in Section 12.
5. Rights of the Data Principal
Under the DPDP Act (Sections 11-14), you are entitled to the following rights. We have implemented technical and organisational measures to facilitate the exercise of these rights:
5.1 Right of Access (Section 11(1)(a))
You may request a summary of your personal data being processed and the processing activities undertaken with respect to such data. The Platform provides a Data Export feature in your account settings that allows you to download all your personal data in a structured, commonly used, and machine-readable format (JSON). We shall respond to access requests within 72 hours.
5.2 Right of Correction and Completion (Section 11(1)(b))
You may correct inaccurate or misleading personal data, complete incomplete personal data, and update personal data that is no longer current. You may exercise this right directly through the Platform by editing your profile, case information, and associated metadata at any time.
5.3 Right of Erasure (Section 12)
You may request the complete and irreversible deletion of your account and all associated personal data. Upon receiving a valid erasure request through the Delete Account feature in your account settings, we shall erase, within 30 days:
(a) Your user profile, authentication credentials, and account metadata from our primary databases; (b) All cases, documents, notes, annotations, chat messages, and research history; (c) All document embeddings from our vector database systems; (d) All uploaded files from our object storage infrastructure; (e) All consent records, preference settings, and access logs (except as required for legal compliance); and (f) All processed derivatives including OCR outputs, AI-generated summaries, and translated content.
Erasure is permanent and irreversible. In accordance with DPDP Act Section 8(7), we shall provide you with a minimum of 48 hours' advance notice before executing the erasure. During this notice period, you may cancel your deletion request. Upon expiry of this period, deletion proceeds automatically and cannot be reversed.
5.4 Right to Withdraw Consent (Section 6(6))
You may withdraw consent for any category of processing at any time through your account settings. Withdrawal shall not affect the lawfulness of processing based on consent prior to withdrawal.
5.5 Right to Grievance Redressal (Section 13)
You have the right to have your grievances addressed in a timely and effective manner. Our grievance redressal procedure is detailed in Section 11 of this Policy.
5.6 Right to Nominate (Section 14)
You have the right to nominate any individual who shall, in the event of your death or incapacity, exercise your rights under the DPDP Act. Nominations may be submitted in writing to info@veritect.ai.
6. Data Retention and Erasure Policy
In accordance with DPDP Act Section 8(7), we retain personal data only for as long as it is reasonably necessary to fulfil the purpose for which it was collected, unless retention is required by law. Our retention schedule is as follows:
| Data Category | Retention Period | Basis and Notes |
|---|---|---|
| Active account data | Duration of active use | Retained while the account remains active and the Data Principal continues to use the Platform. |
| Trial and demo account data | Duration of trial period + 90 days | Upon expiry of a trial or demo period without conversion to a paid subscription, data is retained for 90 days to allow the Data Principal to resume or export data. After 90 days, the account is treated as inactive and subject to standard inactive account retention. |
| Inactive account data | 2 years from last activity | After 2 years of inactivity, the Data Principal will receive 48 hours' advance notice before data erasure is initiated. |
| Deleted account data | Erased within 30 days | Upon receipt of a valid account deletion request, all personal data is permanently erased within 30 days. |
| Security and audit logs | 1 year | Access logs and security event records are retained for 1 year for security investigations and regulatory compliance, then automatically purged. |
| Anonymised analytics | Indefinite | Fully anonymised and aggregated data that cannot be used to identify any individual may be retained indefinitely for service improvement. |
| Job application data | See "Job applications" section below | Resumes and structured application data are governed by the dedicated Applicant Privacy Notice below — 90 days post-rejection, 24 months post-hire, indefinite only with explicit talent-pool consent. |
| Legal hold data | As required by law | Data subject to a legal hold, regulatory investigation, or court order will be retained for the duration required by applicable law, notwithstanding any deletion request. |
6A. Job applications — Applicant Privacy Notice
When you apply to a role at Veritect through our careers page or via a link we have posted on LinkedIn or other channels, you are submitting personal data for the specific purpose of recruitment. This section governs how we handle that data.
What we collect
- Identity and contact details (name, email, phone, current location, LinkedIn profile URL).
- Employment and compensation details (employer, designation, years of experience, notice period, current and expected CTC where you choose to disclose).
- Role-specific structured answers (technical skills, AI / agentic tools shipped with, sales background and quota attainment, content portfolio links, etc.) that you provide on the form.
- Your resume / CV file (PDF, DOC or DOCX, up to 5 MB).
- An optional cover note you choose to write.
- Source attribution — how you found the role (LinkedIn, referral, website), UTM parameters, and the page you came from.
- IP address and User-Agent at the time of submission, retained for abuse prevention and audit only.
Where it is stored
Structured application data is stored in a dedicated Cloudflare D1 database hosted in the Asia-Pacific region. Resume files are stored in a private Cloudflare R2 bucket in the same region. The bucket has no public access — resumes can only be retrieved through our internal admin portal, which is protected by Cloudflare Access. We never index, train AI models on, or share resume content with third parties.
Who can access it
Application data is accessible only to (i) members of the Veritect hiring team for the role you applied to, (ii) the hiring manager, and (iii) authorised members of the People & Operations team. Access is enforced via Cloudflare Access on the admin portal, and every read or status change is recorded in an immutable audit log tied to the reviewer.
Retention
- If you are not selected: retained for 90 days after the application is closed, then permanently deleted.
- If you are selected and hired: the application becomes part of your employee record and is retained for 24 months from your start date, then archived per applicable labour law.
- If you opt into the talent pool (the checkbox at the end of the form): retained for up to 24 months from your application date so we can re-surface you for future relevant roles, and deleted thereafter unless you reconfirm consent.
Your rights
You may at any time email careers@veritect.ai with the application reference UUID shown on your confirmation screen to (a) request a copy of your application data, (b) correct any field, (c) withdraw your application, or (d) request immediate deletion of your application and resume. We action all such requests within 30 days.
Lawful basis
We process application data on the basis of your explicit consent at submission (you tick the consent box before you can submit) and our legitimate interest in evaluating candidates for current and (where you have opted in) future open roles.
7. Data Security Safeguards
We implement reasonable security safeguards as required under DPDP Act Section 8(5) and the SPDI Rules. Our security measures include, but are not limited to:
7.1 Encryption and Transport Security
All data in transit between the Data Principal's device and our servers is encrypted using Transport Layer Security (TLS) 1.3. Data at rest in our databases and object storage is encrypted using AES-256 encryption. Encryption keys are managed through secure key management infrastructure with automatic rotation.
7.2 Authentication and Access Control
User authentication is implemented using RS256 (RSA Signature with SHA-256) JSON Web Token (JWT) verification. Document and resource access is protected by cryptographically signed tokens with a maximum validity of 1 hour. Role-based access control ensures that users can only access data within their authorised scope. Multi-factor authentication is supported and recommended.
7.3 Application Security
Rate limiting through distributed counters prevents brute-force attacks and service abuse. Cross-site scripting (XSS) protection is enforced through content sanitisation on all user-generated and AI-generated content. Cross-Origin Resource Sharing (CORS) policies are restricted to known and trusted application domains. Security headers including HTTP Strict Transport Security (HSTS), X-Frame-Options, Content Security Policy (CSP), and X-Content-Type-Options are applied on all responses. Server-Side Request Forgery (SSRF) protection is enforced through protocol and IP blocklists on all URL inputs.
7.4 Infrastructure Security
Our infrastructure is deployed on enterprise-grade cloud platforms with SOC 2 Type II and ISO 27001 certification. Network-level protections include DDoS mitigation, Web Application Firewall (WAF), and traffic anomaly detection. Regular vulnerability assessments and penetration testing are conducted by qualified security professionals.
7.5 Organisational Measures
Access to personal data is restricted to authorised personnel on a need-to-know basis. All personnel with access to personal data are bound by contractual confidentiality obligations. Regular security awareness training is provided to all team members. Incident response procedures are documented, tested, and reviewed periodically.
7.6 Breach Notification
In the event of a personal data breach, we shall: (a) Notify the Data Protection Board of India within 72 hours of becoming aware of the breach, as required under DPDP Act Section 8(6); (b) Notify affected Data Principals without undue delay, providing details of the nature of the breach, the categories of data affected, the likely consequences, and the remediation steps being taken; (c) Document the breach in our internal breach register, including the facts relating to the breach, its effects, and the remedial action taken; and (d) Cooperate fully with the Data Protection Board of India in any investigation relating to the breach.
8. Cross-Border Data Transfers
Under DPDP Act Section 16, personal data may be transferred to any country or territory outside India, except to countries specifically restricted by the Central Government by notification. As of the effective date of this Policy, no such restriction has been notified.
8.1 Categories of External Data Processors
In the course of providing the Platform's services, personal data may be transferred to and processed by third-party Data Processors in the following jurisdictions for the purposes specified below:
| Processor Category | Jurisdiction(s) | Purpose |
|---|---|---|
| Authentication and Identity Provider | United States | User authentication, identity verification, session management, and single sign-on services. |
| AI and Language Model Providers | United States, European Union | AI-generated summaries, legal analysis, research chat, document classification, and natural language processing. |
| Document Processing Services | European Union, United States | Document chunking, text embeddings, vector representations for semantic search, and document reranking. |
| Translation Services | European Union | Machine translation of legal documents across Indian languages. |
| Search and Research Services | United States | Web search capabilities for legal research augmentation. |
| Cloud Infrastructure Provider | India (APAC region) | Primary database, object storage, compute, content delivery network (CDN), and core application hosting. |
| OCR and Document Extraction | Australia, India | Optical Character Recognition, document text extraction, and document format conversion. Self-hosted OCR infrastructure in India processes only storage references, not raw document content. |
| Payment Processing | India | Payment processing, GST compliance, and subscription management through the Authorised Reseller or other third-party merchant of record platforms. We do not receive or store full payment instrument details. |
8.2 Safeguards for Cross-Border Transfers
We ensure that all cross-border transfers of personal data are subject to appropriate safeguards, including: (a) Binding contractual arrangements with all Data Processors that include data protection obligations substantially equivalent to those imposed under the DPDP Act; (b) Data processing agreements that require processors to process data only on our documented instructions and for specified purposes; (c) Requirements for processors to implement technical and organisational security measures appropriate to the risk; (d) Restrictions on onward transfer by processors without our prior written authorisation; and (e) Periodic assessment of processor compliance with contractual obligations.
8.3 Changes to Processor Jurisdictions
If the Central Government notifies restrictions on data transfer to any country where our processors operate, we shall take immediate steps to either migrate the relevant processing to a non-restricted jurisdiction or obtain any additional authorisation required under the DPDP Act. We shall notify affected Data Principals of any material change in processor jurisdictions.
9. Obligations of the Data Principal
In accordance with DPDP Act Section 15, as a Data Principal, you shall: (a) Comply with the provisions of all applicable laws while exercising your rights under this Policy; (b) Not impersonate another individual when providing personal data for a specified purpose; (c) Not suppress any material information when providing personal data for any document, unique identifier, proof of identity, or proof of address; (d) Not register a false or frivolous grievance or complaint with the Data Fiduciary or the Data Protection Board of India; and (e) Ensure that the personal data provided to us is accurate, complete, and not misleading.
Contravention of these obligations may attract penalties under the DPDP Act.
10. Third-Party Services and Links
The Platform may contain links to or integrations with third-party websites, services, or applications that are not operated or controlled by us. This Privacy Policy does not apply to the practices of third parties. We are not responsible for the privacy practices, security measures, or content of any third-party service. We strongly recommend that you review the privacy policies of any third-party service before providing personal data to such service.
Where the Platform integrates with third-party services (for example, authentication providers or payment processors), we share only the minimum personal data necessary for the specific integration purpose.
11. Grievance Redressal Mechanism
In accordance with DPDP Act Section 13, we have established a grievance redressal mechanism to address your concerns regarding the processing of your personal data.
11.1 Grievance Officer
We have designated a Grievance Officer who is responsible for addressing all grievances relating to data processing. The Grievance Officer may be contacted at:
Designation: Grievance Officer, Veritect Pte. Ltd.
Email: info@veritect.ai
Platform: agent.veritect.ai (in-app grievance submission)
11.2 Grievance Resolution Process
(a) Acknowledgement: We shall acknowledge receipt of your grievance within 48 hours of receipt via the same channel through which the grievance was submitted. (b) Investigation: We shall investigate the grievance thoroughly and in good faith, taking into account all relevant facts and circumstances. (c) Resolution: We shall resolve your grievance within 30 days of receipt, or within such additional period as may be reasonably necessary in the case of complex grievances, with prior intimation to you. (d) Communication: We shall communicate the outcome of the grievance resolution to you in writing, together with the reasons for our decision and any remedial steps taken.
11.3 Escalation
If you are not satisfied with our resolution, or if we fail to resolve your grievance within the specified timeframe, you have the right to file a complaint with the Data Protection Board of India in accordance with Section 13(2) of the DPDP Act.
12. Attorney-Client Privilege and Confidentiality
We recognise that the Platform is used by legal professionals and that data uploaded to the Platform may be subject to attorney-client privilege, litigation privilege, legal professional privilege, or other forms of professional confidentiality.
(a) We do not claim any ownership, licence, or right over the content of documents uploaded to the Platform. All intellectual property rights in your documents remain exclusively with you or your clients, as applicable. (b) We do not access, review, or use the content of your documents for any purpose other than providing the Platform's services as described in this Policy. (c) Our AI processing systems are designed to process data solely for the purpose of generating outputs for your use and do not retain document content beyond the processing session, except where explicitly stored by you within the Platform. (d) We implement strict access controls to ensure that your documents are accessible only to authorised users within your account. (e) Our employees and contractors are bound by confidentiality obligations that extend to all data processed through the Platform.
Disclaimer: While we implement robust security measures and contractual protections, the use of cloud-based services inherently involves the transmission of data to third-party infrastructure. You are responsible for evaluating whether the use of the Platform is appropriate for your specific confidentiality obligations, professional conduct rules, and regulatory requirements.
13. Limitation of Liability
To the maximum extent permitted by applicable law: (a) We shall not be liable for any indirect, incidental, special, consequential, or punitive damages arising out of or relating to a breach of this Privacy Policy or any unauthorised access to or use of your personal data, except where such breach results from our gross negligence or wilful misconduct. (b) Our total aggregate liability for any claims arising under or in connection with this Privacy Policy shall not exceed the total amount paid by you to us in the 12 months preceding the claim. (c) We shall not be liable for any loss or damage arising from: (i) your failure to maintain the security of your account credentials; (ii) your provision of inaccurate, incomplete, or misleading personal data; (iii) force majeure events, including but not limited to acts of God, government actions, cyberattacks beyond reasonable prevention, and internet infrastructure failures; or (iv) the actions or omissions of third-party Data Processors, provided that we have exercised reasonable diligence in selecting and supervising such processors. (d) Nothing in this section shall limit or exclude our liability for any matter for which liability cannot be limited or excluded under applicable law.
14. Indemnification
You agree to indemnify, defend, and hold harmless Veritect Pte. Ltd., its Authorised Reseller(s), and their respective directors, officers, employees, agents, and affiliates from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable legal fees) arising from or in connection with: (a) your breach of this Privacy Policy or the Platform's Terms of Service; (b) your violation of any applicable law, regulation, or third-party right; (c) your provision of inaccurate, incomplete, or misleading personal data; or (d) any misuse of the Platform by you or any person accessing the Platform using your account credentials.
15. Governing Law and Jurisdiction
This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of Singapore. To the extent that the DPDP Act, the IT Act, and the SPDI Rules are applicable to the processing of personal data of Data Principals located in India, such Indian laws shall apply in addition to and shall prevail over the laws of Singapore in respect of matters specifically covered by those enactments.
Any dispute arising out of or in connection with this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of Singapore, except that: (a) Data Principals located in India may exercise their statutory rights under the DPDP Act, including the right to file a complaint before the Data Protection Board of India, without being required to submit to the jurisdiction of Singapore courts; and (b) mandatory consumer protection laws of the Data Principal's jurisdiction of residence shall apply to the extent they cannot be contractually excluded.
The Company voluntarily submits to the jurisdiction of the Data Protection Board of India in respect of matters arising under the DPDP Act relating to Data Principals located in India.
16. Amendments to This Policy
We reserve the right to amend this Privacy Policy from time to time to reflect changes in our data processing practices, legal requirements, or regulatory guidance. When we make material changes to this Policy: (a) We shall notify you through the Platform and, where practicable, via email at least 15 days prior to the changes taking effect. (b) We shall update the version number and effective date at the top of this Policy. (c) If the changes materially affect the scope of consent previously obtained, we shall request fresh, specific, informed, and unconditional consent in accordance with Section 6 of the DPDP Act before implementing the relevant changes. (d) Your continued use of the Platform after the effective date of an amended Policy constitutes your acceptance of the amendments, except where fresh consent is required.
17. Severability
If any provision of this Privacy Policy is held to be invalid, illegal, or unenforceable by a court of competent jurisdiction or the Data Protection Board of India, the remaining provisions shall continue in full force and effect. The invalid or unenforceable provision shall be modified to the minimum extent necessary to make it valid and enforceable, while preserving the original intent of the parties to the greatest extent possible.
18. Entire Agreement
This Privacy Policy, together with the Platform's Terms of Service and any consent forms presented through the Platform, constitutes the entire agreement between you and Veritect Pte. Ltd. with respect to the processing of your personal data. In the event of any conflict between this Privacy Policy and the Terms of Service, this Privacy Policy shall prevail with respect to data protection matters.
19. Contact Information
| Platform Operator | Veritect Pte. Ltd. |
| UEN | 202518753N |
| Registered Office | Singapore Business Federation Center, 160 Robinson Road, #14-004, Singapore 068914 |
| Authorised Reseller (India) | Veritect Pvt Ltd (independent entity; not a subsidiary or affiliate of Veritect Pte. Ltd.) |
| info@veritect.ai | |
| Platform | agent.veritect.ai |
— End of Privacy Policy —