Privacy Policy
Your privacy is important to us. This policy explains how we handle your data.
Last updated: 28 July 2026 · Effective: July 2026
This Privacy Policy describes how Neriq, operated by V Narendra Kumar as a sole proprietorship in India pending incorporation of Neriq Labs Private Limited ("Neriq", "we", "us"), collects, uses and shares personal data when you use our website and services. We will publish the registered entity name, identification number and registered office once the company is incorporated.
If you have any queries or concerns with this Policy, please contact our Grievance Officer (refer Section 15). If you do not agree with the Policy, we would advise you not to use the Site, the Free Tools or the Platform.
01What this policy covers
This Policy applies to three surfaces:
- The Site: neriq.ai and its subdomains.
- The Free Tools: the DPDP Readiness Check and the DPDP Penalty Calculator.
- The Platform: app.neriq.ai, our compliance platform, currently available by invitation only.
It does not apply to third-party websites linked from our Site, each of which has its own privacy practices.
02Information we process on behalf of our customers
The Platform is intended for use by business customers. As a result, for much of the personal data we process, we act as a Data Processor on behalf of our customers, who are the Data Fiduciary.
In plain terms: when your employer connects their Google Workspace or their AWS account to Neriq, we read configuration and access information from those systems on their instructions. Some of that is personal data about you, such as that a user account exists, whether two-step verification is enrolled, or when an account last signed in. Your employer decides why that happens. We act on their instructions.
If you want to know what Neriq holds about you inside your employer's account, or want it corrected or deleted, please contact your employer first. They control it, and our agreement with them requires us to direct your request to them rather than answer it ourselves. If you cannot get a response, write to us and we will tell you what we can.
For everything else, including your account with us, the emails you give us and your use of the Site and Free Tools, we are the Data Fiduciary and the rest of this Policy applies directly.
03Information we collect
3.1 Information you provide
- Account information: name, email, organisation name, job title, and the sign-in method you use, whether an emailed one-time link, Google, GitHub, Slack, or your own Okta.
- Free Tool submissions: for the Readiness Check, your email, your answers, your score and your classification, collected only if you choose to share your email after seeing your result. For the Penalty Calculator, your email address only. The Penalty Calculator runs entirely in your browser; your inputs and its output are not transmitted to us.
- Communications: when you contact us, request support, or send feedback.
- Customer Data: information you upload to the Platform, and information we read from your connected systems, governed by Schedule A of our Terms of Service.
We do not collect payment information. We do not collect government identifiers such as Aadhaar, PAN or passport numbers, and we do not collect biometric or health data.
3.2 Information collected automatically
- Usage data: features used, actions taken, time spent.
- Device information: browser type and operating system. Our hosting provider derives a two-letter country code from your IP address. We store the country code, not your full IP address, though our hosting and network providers process the full address in order to deliver the page to you.
- Referrer: the page that linked you to us.
3.3 What we read from your connected systems
When your organisation connects a system, Neriq is granted read-only access. We do not write to your systems, change your configuration, or run code inside them.
Every read is classified into one of exactly four categories, and the category is recorded on the read itself:
| Category | What it means | Example |
|---|---|---|
config_metadata | How a system is set up | Whether a storage bucket is encrypted; branch protection on a repository |
identity_metadata | Facts about accounts, not their contents | That a user account exists; whether two-step verification is enrolled |
access_evidence | Proof of who can reach what | Membership of an administrator group; an access-review record |
posture_state | The current security state of a service | Whether logging is enabled; whether a key has been rotated |
What is deliberately absent from that list is content. There is no category for the body of an email, the contents of a document, a customer record in your database, source code, or a message. Neriq reads the shape of your systems, not what is inside them.
Each read also carries a retention rule. Some data is fetched, evaluated, and nothing raw is kept. Some is kept as the snapshot an auditor will ask to see. Some is kept only as a one-way hash, for example to match a user across two systems without storing the address itself.
04How we use information, and on what basis
We use information to provide and improve the Services, send technical notices, updates and support messages, respond to your questions, monitor and analyse usage, detect and prevent fraud and security issues, and comply with legal obligations.
The Digital Personal Data Protection Act, 2023 permits processing on one of two footings: your consent under Section 6, or one of the enumerated legitimate uses in Section 7. The Act has no "legitimate interest" basis, so unlike a policy adapted from European law, this one does not claim one.
| Purpose | Basis |
|---|---|
| Deliver your readiness result and follow up on it | Consent, Section 6 |
| Waitlist signup and launch notification | Consent, Section 6 |
| Create and operate your Platform account | Consent, Section 6 |
| Improve and benchmark using aggregated, de-identified data | Consent, Section 6 |
| Process data read from your employer's connected systems | Your employer's basis, not ours. We process on their instructions as a Data Processor |
| Operate the service, prevent abuse, keep it secure | Section 7(a), voluntary provision for a specified purpose |
| Comply with a legal obligation or a lawful request from an authority | Legal obligation |
The standard consent has to meet is set by the Act itself:
"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose." DPDP Act, 2023, Section 6(1)
The last clause is the one we hold ourselves to most tightly. Consent is limited to such personal data as is necessary, which is the reason Section 3.3 lists four categories of read and no category for content.
You may withdraw consent at any time by writing to dpo@neriq.ai. Withdrawal does not affect the lawfulness of processing carried out before it.
05The record of what we read
Neriq keeps a log of every read it makes from your connected systems: which connector, which endpoint, which of the four categories above, and when. The log is append-only, and each entry is cryptographically chained to the one before it, so an entry cannot be altered or removed without breaking the chain. At the end of a scan we sign the head of that chain and issue a receipt.
You can check that receipt yourself, without trusting us to be honest about it. The signature is verified against a public key we publish separately from the receipt, so a receipt we had forged would not verify.
We built this because a compliance tool that asks to be trusted, while grading everyone else on whether they can be trusted, is a contradiction.
06How we share information
We do not sell your personal data. We may share information with:
- Service providers: third-party vendors who perform services on our behalf, such as hosting, database management, email delivery and error monitoring, to operate, support and improve our Services. These third parties process personal data only for specified purposes consistent with this Privacy Policy and applicable law.
- Professional advisors: lawyers, auditors and consultants, as needed and under confidentiality obligations.
- Legal compliance: when required by law, court order or a lawful request from an authority, including the Data Protection Board of India, or to protect our rights.
- Business transfers: in connection with incorporation, a merger, acquisition or sale of assets. We will post a prominent notice on the Site if this happens.
A current list of our service providers, with the purpose and location of each, is available on request from dpo@neriq.ai. We will give reasonable notice before engaging a new one, as set out in Schedule A of our Terms.
07International transfers
This is the most commonly misstated point in Indian data protection, so we quote the Act rather than summarise it:
"The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." DPDP Act, 2023, Section 16(1)
Transfer is therefore permitted unless a specific country or territory is restricted by notification, and no such restriction has been notified. DPDP does not require India-only hosting, and we will not claim otherwise. Section 16(2) adds that this does not displace any other Indian law imposing a higher degree of protection or a stricter transfer restriction, so if your sector carries its own localisation rules, those still bind you.
In practice:
- Scanning infrastructure, evidence storage, encryption keys and outbound email run in India, in the AWS Asia Pacific (Mumbai) region. The data we read from your connected systems, and the keys that protect it, stay in India.
- Our web application, database and error monitoring are operated by managed providers whose infrastructure runs both inside and outside India, including in the United States. Where processing occurs outside India, you authorise that transfer subject to the safeguards in Schedule A of our Terms.
08Data retention
We retain personal data for as long as necessary to provide the Services and fulfil the purposes described in this policy, unless a longer retention period is required by law. The Act puts the obligation this way:
A Data Fiduciary "shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force." DPDP Act, 2023, Section 8(7)
| Data | Retention |
|---|---|
| Readiness check submissions | 24 months from submission, or until consent is withdrawn |
| Waitlist email addresses | Until you withdraw consent |
| Platform account data | For the life of the account, then deleted within 30 days |
| Data read from connected systems | Per your organisation's instruction, and per the retention rule on each read described in Section 3.3 |
| The read record and scan receipts | Retained as the audit trail. Deleting them would destroy the evidence they exist to preserve |
| Security and service logs | Retained for one year, then erased. Rule 6(e) of the DPDP Rules sets one year for detecting, investigating and remedying unauthorised access, and Rule 8(3) sets a minimum of one year followed by erasure unless another law requires longer |
| Correspondence | Up to 24 months from last contact |
| Aggregated, de-identified data | Indefinitely, because it does not identify anyone |
Retention is currently enforced by review rather than by an automated schedule. We are building the automated mechanism, and we would rather say so than imply otherwise.
09Security
Section 8(5) of the Act obliges us to take "reasonable security safeguards to prevent personal data breach". Rule 6 of the DPDP Rules says what that phrase means at a minimum, and it is specific. Rather than paraphrase it, we set the Rule's own words beside our answer.
| What Rule 6(1) requires, verbatim | What we do |
|---|---|
| (a) "appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data" | Personal data is encrypted in transit and at rest, and keys are held in a dedicated key service. Some data we read is retained only as a one-way hash rather than in the clear. |
| (b) "appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable" | Access to systems holding personal data is restricted and authenticated, and each customer's data is isolated from every other customer's at the database layer. |
| (c) "visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence" | This is what the read record in Section 5 is. Every read we make from your systems is logged, chained so it cannot be altered, and signed. |
| (d) "reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups" | We keep backups so processing can continue after a compromise. |
| (e) "retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise" | Security and service logs are retained for one year. |
| (f) "appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards" | Our agreements with service providers carry security obligations, and Schedule A of our Terms carries ours to you. |
| (g) "appropriate technical and organisational measures to ensure effective observance of security safeguards" | The measures above are backed by written procedure and reviewed as the product changes. |
No method of transmission over the Internet is completely secure, and no security measure is absolute. We cannot guarantee protection against every threat. A fuller description of our security posture is available to customers on request, under confidentiality.
10If there is a personal data breach
If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person as the Act and the Rules require.
Two separate laws apply here and they are commonly confused, so we state both. Under Rule 7 of the DPDP Rules we must intimate affected individuals without delay, give the Board an initial intimation without delay, and give the Board a detailed report within 72 hours of becoming aware. Separately, where an incident is a reportable cybersecurity incident, the CERT-In Direction of 28 April 2022 issued under Section 70B of the Information Technology Act, 2000 requires reporting to CERT-In within 6 hours.
The 6-hour rule is CERT-In's, not DPDP's. A serious incident can trigger both.
Where a breach affects personal data we process on a customer's behalf, we will notify that customer without undue delay, as set out in Schedule A of our Terms.
11Your rights
Under the DPDP Act you have the following rights over personal data we hold as a Data Fiduciary. For data we hold as a Processor on your employer's behalf, see Section 2.
- Right to information, Section 11. A summary of the personal data we are processing and of the processing activities we undertake with it. The right also covers the identities of every other Data Fiduciary and Data Processor with whom we have shared your personal data, together with a description of the data shared, and any further information the Rules prescribe. If you ask us for that, we will give you the list rather than a summary of it.
- Right to correction and erasure, Section 12. Correction of what is inaccurate, completion of what is incomplete, updating of what is out of date, and erasure of what is no longer needed, subject to any retention the law requires.
- Right to grievance redressal, Section 13. A route to complain to us, in Section 15 below.
- Right to nominate, Section 14. In the Act's words, the right "to nominate, in such manner as may be prescribed, any other individual, who shall, in the event of death or incapacity of the Data Principal, exercise the rights of the Data Principal". This right is specific to the Indian regime.
- Right to withdraw consent, Section 6. At any time.
To exercise any of these, email dpo@neriq.ai with your name, the email address you used with us, and what you want us to do. We verify identity by confirming the email address on the record before we act.
Rule 14(3) of the DPDP Rules requires us to fix a period "not exceeding ninety days" for responding to grievances. Ours is ninety days at the outside, and we aim to be considerably quicker.
If our response does not satisfy you, you may complain to the Data Protection Board of India. The Board is being constituted and may not yet have an operating complaint route. We will publish its contact details here once they are available.
12Cookies
We set no cookies of our own on the marketing site, and our analytics provider operates without cookies and does not follow individuals between sessions. The Platform sets a session cookie, because you cannot stay signed in without one; it is strictly necessary and is not used for tracking, advertising or profiling. Our network provider may set strictly necessary security cookies.
We use no advertising cookies, no cross-site tracking pixels, and no behavioural profiling. If that changes we will update this Policy and seek consent where it is required.
13AI and data usage
Neriq describes itself as an AI-supported compliance platform, so we should be precise about what that means for your data.
- Customer data is never used to train AI models. Your data remains yours.
- We do not sell or share your data with anyone to train theirs.
- As at the date of this Policy, the scanning pipeline sends no customer data to any third-party language model. Compliance checks are evaluated by deterministic code against the data read from your systems.
- If we introduce a feature that sends your data to a model provider, we will say so here before it ships, describe what is sent, and where the feature is not essential to the service, ask first.
14Children
Our Services are intended for business use. We do not knowingly collect personal data of children, who under Section 2(f) of the DPDP Act are individuals under 18 years of age. If we become aware that we have collected such data, we will delete it without delay.
15Grievance Officer
The contact details of our Grievance Officer, whom you may contact if you have any concerns, complaints or feedback pertaining to this Policy, are as follows:
Grievance Officer
Neriq
Email: dpo@neriq.ai
This contact is published in accordance with Section 8(9) of the Act and Rule 9 of the DPDP Rules, which require a Data Fiduciary to prominently publish the business contact information of its Data Protection Officer, where one applies, or of a person able to answer questions on its behalf. Neriq is not a Significant Data Fiduciary, so a designated Data Protection Officer is not mandatory. The address above reaches the person able to answer.
For questions about our Terms, contact legal@neriq.ai. Once Neriq Labs Private Limited is incorporated, the registered office address will be published here alongside these contacts.
16Changes to this policy
We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy and revising the date at the top. Continuing to use the Services after the effective date means you acknowledge the updated Policy.
This Policy is governed by the laws of India. Disputes follow the dispute resolution provisions of our Terms of Service.
· The Neriq team