Privacy Policy

Privacy Policy

Your privacy is important to us. This policy explains how we handle your data.

Last updated: 28 July 2026 · Effective: July 2026

The short version. We read the shape of your systems, never the contents of your files, emails, messages, databases or code. Access is read-only. We keep a tamper-evident record of every read we make, and you can verify it without trusting us. We do not train any model on your data, and we do not sell data to anyone.

This Privacy Policy describes how Neriq, operated by V Narendra Kumar as a sole proprietorship in India pending incorporation of Neriq Labs Private Limited ("Neriq", "we", "us"), collects, uses and shares personal data when you use our website and services. We will publish the registered entity name, identification number and registered office once the company is incorporated.

If you have any queries or concerns with this Policy, please contact our Grievance Officer (refer Section 15). If you do not agree with the Policy, we would advise you not to use the Site, the Free Tools or the Platform.

01What this policy covers

This Policy applies to three surfaces:

It does not apply to third-party websites linked from our Site, each of which has its own privacy practices.

02Information we process on behalf of our customers

The Platform is intended for use by business customers. As a result, for much of the personal data we process, we act as a Data Processor on behalf of our customers, who are the Data Fiduciary.

In plain terms: when your employer connects their Google Workspace or their AWS account to Neriq, we read configuration and access information from those systems on their instructions. Some of that is personal data about you, such as that a user account exists, whether two-step verification is enrolled, or when an account last signed in. Your employer decides why that happens. We act on their instructions.

If you want to know what Neriq holds about you inside your employer's account, or want it corrected or deleted, please contact your employer first. They control it, and our agreement with them requires us to direct your request to them rather than answer it ourselves. If you cannot get a response, write to us and we will tell you what we can.

For everything else, including your account with us, the emails you give us and your use of the Site and Free Tools, we are the Data Fiduciary and the rest of this Policy applies directly.

03Information we collect

3.1 Information you provide

We do not collect payment information. We do not collect government identifiers such as Aadhaar, PAN or passport numbers, and we do not collect biometric or health data.

3.2 Information collected automatically

3.3 What we read from your connected systems

When your organisation connects a system, Neriq is granted read-only access. We do not write to your systems, change your configuration, or run code inside them.

Every read is classified into one of exactly four categories, and the category is recorded on the read itself:

CategoryWhat it meansExample
config_metadataHow a system is set upWhether a storage bucket is encrypted; branch protection on a repository
identity_metadataFacts about accounts, not their contentsThat a user account exists; whether two-step verification is enrolled
access_evidenceProof of who can reach whatMembership of an administrator group; an access-review record
posture_stateThe current security state of a serviceWhether logging is enabled; whether a key has been rotated

What is deliberately absent from that list is content. There is no category for the body of an email, the contents of a document, a customer record in your database, source code, or a message. Neriq reads the shape of your systems, not what is inside them.

Each read also carries a retention rule. Some data is fetched, evaluated, and nothing raw is kept. Some is kept as the snapshot an auditor will ask to see. Some is kept only as a one-way hash, for example to match a user across two systems without storing the address itself.

04How we use information, and on what basis

We use information to provide and improve the Services, send technical notices, updates and support messages, respond to your questions, monitor and analyse usage, detect and prevent fraud and security issues, and comply with legal obligations.

The Digital Personal Data Protection Act, 2023 permits processing on one of two footings: your consent under Section 6, or one of the enumerated legitimate uses in Section 7. The Act has no "legitimate interest" basis, so unlike a policy adapted from European law, this one does not claim one.

PurposeBasis
Deliver your readiness result and follow up on itConsent, Section 6
Waitlist signup and launch notificationConsent, Section 6
Create and operate your Platform accountConsent, Section 6
Improve and benchmark using aggregated, de-identified dataConsent, Section 6
Process data read from your employer's connected systemsYour employer's basis, not ours. We process on their instructions as a Data Processor
Operate the service, prevent abuse, keep it secureSection 7(a), voluntary provision for a specified purpose
Comply with a legal obligation or a lawful request from an authorityLegal obligation

The standard consent has to meet is set by the Act itself:

"The consent given by the Data Principal shall be free, specific, informed, unconditional and unambiguous with a clear affirmative action, and shall signify an agreement to the processing of her personal data for the specified purpose and be limited to such personal data as is necessary for such specified purpose." DPDP Act, 2023, Section 6(1)

The last clause is the one we hold ourselves to most tightly. Consent is limited to such personal data as is necessary, which is the reason Section 3.3 lists four categories of read and no category for content.

You may withdraw consent at any time by writing to dpo@neriq.ai. Withdrawal does not affect the lawfulness of processing carried out before it.

05The record of what we read

Neriq keeps a log of every read it makes from your connected systems: which connector, which endpoint, which of the four categories above, and when. The log is append-only, and each entry is cryptographically chained to the one before it, so an entry cannot be altered or removed without breaking the chain. At the end of a scan we sign the head of that chain and issue a receipt.

You can check that receipt yourself, without trusting us to be honest about it. The signature is verified against a public key we publish separately from the receipt, so a receipt we had forged would not verify.

We built this because a compliance tool that asks to be trusted, while grading everyone else on whether they can be trusted, is a contradiction.

06How we share information

We do not sell your personal data. We may share information with:

A current list of our service providers, with the purpose and location of each, is available on request from dpo@neriq.ai. We will give reasonable notice before engaging a new one, as set out in Schedule A of our Terms.

07International transfers

This is the most commonly misstated point in Indian data protection, so we quote the Act rather than summarise it:

"The Central Government may, by notification, restrict the transfer of personal data by a Data Fiduciary for processing to such country or territory outside India as may be so notified." DPDP Act, 2023, Section 16(1)

Transfer is therefore permitted unless a specific country or territory is restricted by notification, and no such restriction has been notified. DPDP does not require India-only hosting, and we will not claim otherwise. Section 16(2) adds that this does not displace any other Indian law imposing a higher degree of protection or a stricter transfer restriction, so if your sector carries its own localisation rules, those still bind you.

In practice:

08Data retention

We retain personal data for as long as necessary to provide the Services and fulfil the purposes described in this policy, unless a longer retention period is required by law. The Act puts the obligation this way:

A Data Fiduciary "shall erase her personal data unless retention of the same is necessary for the specified purpose or for compliance with any law for the time being in force." DPDP Act, 2023, Section 8(7)
DataRetention
Readiness check submissions24 months from submission, or until consent is withdrawn
Waitlist email addressesUntil you withdraw consent
Platform account dataFor the life of the account, then deleted within 30 days
Data read from connected systemsPer your organisation's instruction, and per the retention rule on each read described in Section 3.3
The read record and scan receiptsRetained as the audit trail. Deleting them would destroy the evidence they exist to preserve
Security and service logsRetained for one year, then erased. Rule 6(e) of the DPDP Rules sets one year for detecting, investigating and remedying unauthorised access, and Rule 8(3) sets a minimum of one year followed by erasure unless another law requires longer
CorrespondenceUp to 24 months from last contact
Aggregated, de-identified dataIndefinitely, because it does not identify anyone

Retention is currently enforced by review rather than by an automated schedule. We are building the automated mechanism, and we would rather say so than imply otherwise.

09Security

Section 8(5) of the Act obliges us to take "reasonable security safeguards to prevent personal data breach". Rule 6 of the DPDP Rules says what that phrase means at a minimum, and it is specific. Rather than paraphrase it, we set the Rule's own words beside our answer.

What Rule 6(1) requires, verbatimWhat we do
(a) "appropriate data security measures, such as securing of personal data through encryption, obfuscation, masking or the use of virtual tokens mapped to that personal data"Personal data is encrypted in transit and at rest, and keys are held in a dedicated key service. Some data we read is retained only as a one-way hash rather than in the clear.
(b) "appropriate measures to control access to the computer resources used by such Data Fiduciary or such a Data Processor, wherever applicable"Access to systems holding personal data is restricted and authenticated, and each customer's data is isolated from every other customer's at the database layer.
(c) "visibility on the accessing of such personal data, through appropriate logs, monitoring and review, for enabling detection of unauthorised access, its investigation and remediation to prevent recurrence"This is what the read record in Section 5 is. Every read we make from your systems is logged, chained so it cannot be altered, and signed.
(d) "reasonable measures for continued processing in the event of confidentiality, integrity or availability of such personal data being compromised as a result of destruction or loss of access to personal data or otherwise, such as by way of data-backups"We keep backups so processing can continue after a compromise.
(e) "retain such logs and personal data for a period of one year, unless compliance with any law for the time being in force requires otherwise"Security and service logs are retained for one year.
(f) "appropriate provision in the contract entered into between such Data Fiduciary and such a Data Processor, wherever applicable, for taking reasonable security safeguards"Our agreements with service providers carry security obligations, and Schedule A of our Terms carries ours to you.
(g) "appropriate technical and organisational measures to ensure effective observance of security safeguards"The measures above are backed by written procedure and reviewed as the product changes.

No method of transmission over the Internet is completely secure, and no security measure is absolute. We cannot guarantee protection against every threat. A fuller description of our security posture is available to customers on request, under confidentiality.

10If there is a personal data breach

If a personal data breach occurs, we will notify the Data Protection Board of India and every affected person as the Act and the Rules require.

Two separate laws apply here and they are commonly confused, so we state both. Under Rule 7 of the DPDP Rules we must intimate affected individuals without delay, give the Board an initial intimation without delay, and give the Board a detailed report within 72 hours of becoming aware. Separately, where an incident is a reportable cybersecurity incident, the CERT-In Direction of 28 April 2022 issued under Section 70B of the Information Technology Act, 2000 requires reporting to CERT-In within 6 hours.

The 6-hour rule is CERT-In's, not DPDP's. A serious incident can trigger both.

Where a breach affects personal data we process on a customer's behalf, we will notify that customer without undue delay, as set out in Schedule A of our Terms.

11Your rights

Under the DPDP Act you have the following rights over personal data we hold as a Data Fiduciary. For data we hold as a Processor on your employer's behalf, see Section 2.

To exercise any of these, email dpo@neriq.ai with your name, the email address you used with us, and what you want us to do. We verify identity by confirming the email address on the record before we act.

Rule 14(3) of the DPDP Rules requires us to fix a period "not exceeding ninety days" for responding to grievances. Ours is ninety days at the outside, and we aim to be considerably quicker.

If our response does not satisfy you, you may complain to the Data Protection Board of India. The Board is being constituted and may not yet have an operating complaint route. We will publish its contact details here once they are available.

12Cookies

We set no cookies of our own on the marketing site, and our analytics provider operates without cookies and does not follow individuals between sessions. The Platform sets a session cookie, because you cannot stay signed in without one; it is strictly necessary and is not used for tracking, advertising or profiling. Our network provider may set strictly necessary security cookies.

We use no advertising cookies, no cross-site tracking pixels, and no behavioural profiling. If that changes we will update this Policy and seek consent where it is required.

13AI and data usage

Neriq describes itself as an AI-supported compliance platform, so we should be precise about what that means for your data.

14Children

Our Services are intended for business use. We do not knowingly collect personal data of children, who under Section 2(f) of the DPDP Act are individuals under 18 years of age. If we become aware that we have collected such data, we will delete it without delay.

15Grievance Officer

The contact details of our Grievance Officer, whom you may contact if you have any concerns, complaints or feedback pertaining to this Policy, are as follows:

Grievance Officer
Neriq

Email: dpo@neriq.ai

This contact is published in accordance with Section 8(9) of the Act and Rule 9 of the DPDP Rules, which require a Data Fiduciary to prominently publish the business contact information of its Data Protection Officer, where one applies, or of a person able to answer questions on its behalf. Neriq is not a Significant Data Fiduciary, so a designated Data Protection Officer is not mandatory. The address above reaches the person able to answer.

For questions about our Terms, contact legal@neriq.ai. Once Neriq Labs Private Limited is incorporated, the registered office address will be published here alongside these contacts.

16Changes to this policy

We may update this Privacy Policy from time to time. We will notify users of material changes by posting the updated policy and revising the date at the top. Continuing to use the Services after the effective date means you acknowledge the updated Policy.

This Policy is governed by the laws of India. Disputes follow the dispute resolution provisions of our Terms of Service.

A note on timing. The substantive obligations of the DPDP Act, including notice, consent, security, breach reporting and Data Principal rights, commence approximately 13 May 2027, being eighteen months after the Rules were notified on 13 November 2025, under Rule 1(4). We have chosen to work to these standards now rather than in 2027. We would find it hard to sell a compliance product while waiting for our own deadline.

· The Neriq team