Terms of Service

Terms of Service

Please read these terms carefully before using our services.

Last updated: 28 July 2026 · Effective: July 2026

The short version. Neriq gives you analysis and evidence. It is not legal advice and it does not certify your compliance with anything. The platform is a free private beta with no uptime commitment. Access to your systems is read-only. You own your data, you can export it, and we delete it when you leave.

This agreement ("Agreement") is between Neriq, operated by V Narendra Kumar as a sole proprietorship in India pending incorporation of Neriq Labs Private Limited ("Neriq", "we", "us"), and the entity or person agreeing to these terms ("Customer", "you"). By using our services, you agree to these terms.

We will publish the registered entity name, identification number and registered office here once the company is incorporated.

01Services

1.1 What the Services are

Neriq provides a compliance platform, together with the website at neriq.ai and free tools published on it. Collectively these are the "Services":

We grant you a non-exclusive, non-transferable licence to access and use the Services for your internal business purposes, subject to this Agreement.

1.2 Service level

The Platform is currently a free private beta, available by invitation only. It carries no uptime commitment and no service level agreement, and none is implied. Features may be added, altered or removed with little notice, and the Platform may be discontinued in whole or in part. You should not make it a dependency of a process you cannot run without.

Except where we must act immediately for security or legal reasons, we will give you reasonable notice before withdrawing access, and a reasonable opportunity to export your data.

1.3 Support

We provide commercially reasonable support by email at support@neriq.ai.

02The Services are not legal advice

The Services are tools to assist with your compliance programme. We do not guarantee that you will achieve any particular certification or compliance outcome. You remain solely responsible for your compliance obligations.

Neriq is not a law firm, an audit firm or a certification body, and using the Services creates no advisor relationship between us. Readiness scores, penalty estimates, findings, control statuses, framework mappings and evidence packages are general in nature and may not reflect the facts, sector or regulatory position of your organisation. Obtain independent professional advice before acting on any output of the Services.

Penalties under the Digital Personal Data Protection Act, 2023 are determined case by case by the Data Protection Board of India on the factors set out in the Act. No tool can predict the outcome of a regulatory proceeding, and ours does not claim to.

03Customer responsibilities

3.1 Account security

You are responsible for maintaining the confidentiality of your account credentials and for all activities under your account. Notify us immediately of any unauthorised access.

3.2 Authorised users

You may permit your employees, contractors and agents to access the Services. You are responsible for their compliance with this Agreement. Account sharing between users is prohibited. Your administrators can add, remove and change the permissions of users in your organisation.

3.3 Acceptable use

You agree not to:

We may suspend access for violations.

3.4 Your Data

You retain ownership of all data you upload to the Services, and of the data we read from your connected systems, the evidence we collect for you and the findings we produce from it ("Customer Data"). You grant us a licence to use Customer Data solely to provide the Services. You represent that you have the rights to provide this data and that it does not infringe third-party rights.

04Connected systems

4.1 Your authority to connect

When you connect a system, you represent that you are authorised by your organisation to grant that access, that granting it does not breach your agreement with the provider of that system, and that where the connected data includes personal data of your employees or customers, you have a lawful basis for us to process it.

4.2 Scope of access

You authorise us to make read-only calls to the connected system, evaluate the results against compliance requirements, store what is needed as evidence, and display it to users in your organisation.

We will not write to, modify or delete anything in your connected systems, run code inside your infrastructure, or act on your behalf in any system. Access is read-only in every connector, without exception. We will not read the contents of your files, emails, messages, databases or source code.

4.3 Withdrawing access

You may disconnect any system at any time from within the Platform. Disconnecting stops further reads. It does not by itself delete evidence already collected; Section 6.3 governs deletion.

4.4 Record of access

We maintain a tamper-evident, cryptographically chained record of every read we make from your systems, and sign it at the end of each scan. You can verify that signature independently, without relying on us. That record is the audit mechanism referred to in Schedule A.

05Fees

The Platform is provided free of charge during the private beta. No fees are payable and no subscription term applies.

If we introduce paid plans, the applicable fees, billing, renewal and cancellation terms will be presented to you before you purchase, and this Agreement will continue to apply underneath them.

06Term and termination

6.1 Term

This Agreement applies from the moment you first use the Services and continues until terminated.

6.2 Termination

You may stop using the Services at any time and may close your account by writing to legal@neriq.ai. We may suspend or terminate your access if you materially breach this Agreement, if the law or a regulatory authority requires it, if we discontinue the Services, or if we reasonably believe your continued use poses a security, legal or reputational risk. Except where we must act immediately, we will give you notice first.

6.3 Effect of termination

Upon termination your access ends. Before it does, you may export Customer Data, including your evidence and scan receipts, and we will allow a reasonable period to do so. We will delete Customer Data within 30 days unless you request its return or earlier deletion, or applicable law requires retention. Backups may retain copies for a short period and expire on their normal cycle.

Your scan receipts remain independently verifiable after you leave, because the key against which they are checked is published separately from the receipt. Evidence you have already given an auditor does not stop being checkable because you stopped being a customer.

6.4 Survival

Provisions which by their nature should survive termination do so, including intellectual property, confidentiality, disclaimers, limitation of liability, indemnification and governing law.

07Intellectual property

7.1 Our IP

We own all rights to the Services, including the software, interface, check definitions, framework mappings, scoring methodology, documentation and improvements. Nothing in this Agreement transfers ownership of our intellectual property to you.

Certain frameworks we work with are published by standards bodies which own their text and license it on their own terms. Our mappings and paraphrases are our own work, produced from primary sources. Nothing in the Services grants you a licence to any third party's standard.

7.2 Feedback

If you provide suggestions or feedback, we may use it without obligation to you.

7.3 Aggregated data

We may collect and use aggregated, anonymised data derived from your use of the Services to improve our products. This data will not identify you, your organisation or your users. We will not publish or share statistics identifying your organisation without your written permission.

08Confidentiality

Each party agrees to protect the other's confidential information with reasonable care and not to disclose it except as necessary to perform this Agreement or as required by law, with notice where permitted.

Customer Data, your findings and your compliance posture are your confidential information. This obligation does not apply to information which is public through no fault of the receiving party, which the receiving party already held, or which it develops independently.

09Data protection

We process personal data in accordance with Schedule A to this Agreement and our Privacy Policy. Schedule A applies whenever we process personal data on your behalf. The Privacy Policy applies where we act as a Data Fiduciary in our own right, and Section 2 of that policy explains which is which.

10Warranties and disclaimers

10.1 Your warranty

You warrant that you have the authority to enter this Agreement and that your use of the Services will comply with applicable laws.

10.2 Disclaimer

The Services are provided "as is" and "as available". We disclaim all warranties, express, implied or statutory, including implied warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, completeness, reliability, security and uninterrupted availability.

We do not warrant that the Services will meet your compliance requirements, that they will be uninterrupted, error-free or secure, that any finding, score, mapping or evidence package will be accurate, current or complete, that the Services will protect you from enforcement action, a fine, a lawsuit, a failed audit or a breach, or that any defect will be corrected.

Because the Platform is a free beta, we give no warranty that it will perform as documented.

10.3 Automated analysis

Certain features of the Services apply automated analysis to the data read from your systems. We do not warrant the accuracy, completeness or reliability of automated output, recommendations or findings. You are responsible for reviewing and validating any output before relying on it.

As at the effective date of this Agreement, the scanning pipeline does not send Customer Data to any third-party language model, and we do not use Customer Data to train any model, ours or a third party's. If that changes we will update our Privacy Policy before the feature ships.

11Indemnification

11.1 By you

You will defend us against third-party claims arising from Customer Data, from your breach of this Agreement, from your connecting a system you were not authorised to connect, or from any action you take based on the output of the Services, including any regulatory, legal or financial consequence of treating that output as professional advice, and pay damages finally awarded.

11.2 Conditions

Indemnification requires prompt notice, sole control of the defence, and reasonable cooperation.

12Limitation of liability

12.1 Exclusion of damages

Neither party will be liable for indirect, incidental, special, consequential or punitive damages, including lost profits, lost data or business interruption.

12.2 Liability cap

Each party's total liability arising out of or related to this Agreement, whether in contract or under any other theory of liability, will not exceed the total amount paid by you under this Agreement in the twelve months preceding the event giving rise to the liability ("Standard Cap").

The Platform is currently provided free of charge, so no amount is payable and the Standard Cap is nil. Our liability during the free beta is limited to the maximum extent permitted by applicable law. When paid plans are introduced, the Standard Cap will operate on the fees you have paid.

12.3 Exceptions

Our aggregate liability arising from a breach by us of our confidentiality or intellectual property obligations under this Agreement shall not exceed, in the aggregate, three times the Standard Cap.

These limitations do not apply to your indemnification obligations or to violations of Section 3.3 (Acceptable Use). Nothing in this Agreement limits liability that cannot lawfully be limited, including for fraud or wilful misconduct.

13General

13.1 Force majeure

Neither party is liable for delays or failures due to causes beyond reasonable control, including natural disasters, war, terrorism, labour disputes, government actions or infrastructure failures.

13.2 Assignment

You may not assign this Agreement without our consent, except to an affiliate or in connection with a merger or acquisition. We may assign freely, including on incorporation of Neriq Labs Private Limited.

13.3 Governing law and dispute resolution

This Agreement shall be governed by the laws of India without regard to its conflict of laws provisions. If a dispute arises under this Agreement that cannot be resolved first through good faith negotiations between the parties, such dispute shall be referred to arbitration to be conducted and resolved by a single arbitrator in accordance with the provisions of the (Indian) Arbitration and Conciliation Act, 1996 then in effect as modified herein. All such arbitration shall be confidential and shall take place in New Delhi, or such other location that is mutually agreed to by the parties in writing, which will also be regarded as the seat of arbitration. Subject to the arbitration clause, the Courts in New Delhi shall have exclusive supervisory jurisdiction over any disputes under this Agreement.

13.4 Entire agreement

This Agreement, including Schedule A and the referenced policies, constitutes the entire agreement between us and supersedes all prior agreements on this subject.

13.5 Amendments

We may update these terms by posting a revised version. Material changes will be communicated with at least 30 days' notice. Continued use after the effective date constitutes acceptance.

13.6 Notices

Notices to us should be sent to legal@neriq.ai. We may send notices to the email address on your account.

13.7 Severability

If any provision is unenforceable, the remaining provisions remain in effect.

13.8 Waiver

Our failure to enforce a provision is not a waiver of our right to enforce it later.

ASchedule A: Data Processing

This Schedule forms part of the Agreement between Neriq and Customer for the Neriq platform, and governs the processing of personal data. It exists because the Act is explicit that the engagement must be contractual:

"A Data Fiduciary may engage, appoint, use or otherwise involve a Data Processor to process personal data on its behalf for any activity related to offering of goods or services to Data Principals only under a valid contract." DPDP Act, 2023, Section 8(2)

A1. Definitions

"Personal Data" means any information relating to an identified or identifiable individual that Customer uploads to, or that Neriq reads from Customer's connected systems through, the Services.

"Data Protection Laws" means the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025, together with any other applicable privacy laws.

"Sub-processor" means any third party engaged by Neriq to process Personal Data on behalf of Customer.

"Data Principal" means the individual to whom Personal Data relates.

A2. Roles and responsibilities

Customer as Data Fiduciary. Customer determines the purposes and means of processing Personal Data. Customer is responsible for ensuring a lawful basis for processing and for the accuracy of data provided.

Neriq as Data Processor. Neriq processes Personal Data only on Customer's documented instructions and in accordance with this Schedule and applicable Data Protection Laws. Configuring a connector is an instruction. If we believe an instruction breaches the law, we will tell you rather than follow it silently.

A3. Processing details

ElementDescription
PurposeProviding the Neriq compliance platform
DurationFor as long as the account is open, plus the deletion window in Section 6.3
Data PrincipalsCustomer's employees, contractors and agents
Data categoriesNames, work email addresses, job titles, account status, group and role membership, authentication and multi-factor enrolment status, access and activity metadata, and compliance-related records. Restricted by design to the four read categories described at Section 3.3 of the Privacy Policy, none of which is content.
Sensitive dataCustomer shall not submit health, biometric, financial-account or government-identifier data. No connector is built to read it.

A4. Neriq obligations

Neriq shall:

A5. Security measures

Neriq maintains security measures appropriate to the risk, including encryption of data in transit and at rest, access controls and authentication, multi-tenant isolation, logging and monitoring of access, backups, and incident response procedures.

Section 9 of the Privacy Policy sets each of the seven minimum measures required by Rule 6 of the DPDP Rules, 2025 beside what we do about it, in the Rule's own words. A fuller description is available on request under confidentiality.

A6. Sub-processors

Authorisation. Customer authorises Neriq to engage Sub-processors to assist in providing the Services.

Current Sub-processors. A list of current Sub-processors, with the purpose and location of each, is available from dpo@neriq.ai.

Changes. Neriq will notify Customer at least 10 days before engaging a new Sub-processor. Customer may object on reasonable data protection grounds within that period.

Liability. Neriq remains liable for Sub-processor compliance with this Schedule.

A7. Data Principal rights

Neriq will assist Customer in fulfilling its obligations to respond to Data Principal requests under Sections 11 to 14 of the Act, being the rights to information, to correction and erasure, to grievance redressal and to nominate.

Customer is responsible for responding to requests. If a request reaches us directly for data we hold on Customer's behalf, we will redirect it to Customer rather than answer it, and notify Customer promptly.

A8. Data breach notification

Neriq will notify Customer without undue delay after becoming aware of a personal data breach affecting Customer's Personal Data. Notification will include the nature of the breach, the categories and approximate number of Data Principals affected, the likely consequences, and the measures taken or proposed to address it.

The statutory timelines under Rule 7 of the DPDP Rules, and the separate six-hour CERT-In obligation which is commonly confused with them, are set out at Section 10 of the Privacy Policy.

A9. Cross-border transfers

Section 16(1) of the Act permits transfer of Personal Data outside India unless the Central Government restricts a specific country or territory by notification. No such restriction has been notified. Where processing occurs outside India, Customer authorises that transfer subject to the safeguards in this Schedule. Section 7 of the Privacy Policy states where data is held.

A10. Records and audit

Upon reasonable notice, Customer may request information necessary to verify Neriq's compliance with this Schedule.

For the part of our processing that reads from Customer's systems, the tamper-evident record described at Section 4.4 is itself the audit mechanism. It records every call made, the category of data returned, and when, in a form Customer can verify independently rather than take on our word.

A11. Term and deletion

This Schedule remains in effect for the duration of the Agreement. Upon termination Neriq will delete or return all Personal Data within 30 days at Customer's written request, may retain data as required by applicable law, and will certify deletion upon request.

A12. Liability

Each party's liability under this Schedule is subject to the limitations set out in Section 12.

If you need your own paper. These terms carry the data processing terms inline because that is the smallest thing that satisfies Section 8(2) of the Act. If your organisation requires a standalone Data Processing Agreement on your own template, write to legal@neriq.ai and we will work from it.

Contact

Questions about these terms? Contact us at legal@neriq.ai.

For privacy and data protection matters, including data access, correction, erasure and consent withdrawal, contact dpo@neriq.ai as described in our Privacy Policy.

· The Neriq team