Legal
Privacy Policy
Effective 25 August 2026 · version 1.0
Your clients' data stays in your own Google account. We process it on your instructions to run the Service, and for nothing else. This notice is written to the Digital Personal Data Protection Act, 2023.
01Our role, and yours
This notice explains how personal data is handled in Veriq AI, and it distinguishes two very different roles.
- Your firm is the Data Fiduciary for your clients' personal data. You decide what is collected and why. You hold the relationship, and the consent.
- We are a Data Processor acting on your documented instructions for that data. We do not decide its purposes and we do not use it for our own.
- We are the Data Fiduciary only for your own account data: the names, work email addresses and billing details of the people at your firm who deal with us.
This notice is written to the Digital Personal Data Protection Act, 2023.
02What is processed
| Category | Examples | Whose |
|---|---|---|
| Client register | Client name, business type, GSTIN, contact email and phone, filing profile | Your clients' |
| Compliance records | Due dates, filing status, document requests and receipts | Your clients' |
| Correspondence | Reminder text sent, replies received, questions logged | Your clients' |
| Billing records | Invoice amounts, payment status | Your clients' |
| Account data | Name, work email, sign-in record, billing contact | Your firm's staff |
We do not collect special-category data, and the Service is not designed to hold it. Do not place health, biometric or similar data in the register.
03Where it is stored
The register is a spreadsheet in your firm's own Google account. It is not copied into a database of ours. We read and write it through a token-authenticated endpoint; the token is held server-side and is never sent to a browser.
Operational by-products — execution logs, error records, message drafts in transit — exist on the infrastructure listed in the next section for as long as clause 05 provides.
04Who else processes it, and where
Some processing happens outside India. Where it does, it is on our documented instructions and under contractual terms requiring confidentiality and security.
| Provider | What it handles | Location |
|---|---|---|
| The register itself; outbound email from your own account | Per your Google account | |
| Cloudflare | Hosting, sign-in, email routing | Global edge |
| n8n | Workflow execution and scheduling | European Union |
| Groq | Generating message text. Receives the fields needed to draft a message. | United States |
| Brevo | Relaying outbound email | European Union |
| Telegram | Failure alerts to your firm. Operational only; no client records. | Global |
We do not sell personal data, and we do not use it to train AI models. Content sent to our AI provider is used to produce that one message and is not retained for training.
05How long it is kept
- The register is retained by you, in your account, for as long as you keep it. We do not control its lifetime.
- Execution and error logs are retained for up to 90 days, then deleted.
- Account and billing records are retained for as long as you are a customer and afterwards only as long as tax and company law require.
- On termination we disconnect from your register, revoke our access and delete operational copies within 30 days.
06How it is protected
- Credentials are held server-side as environment variables and are never exposed to a browser.
- Console access is per person through Cloudflare Access, with a sign-in record — not a shared password.
- Endpoints are token-authenticated, and the readable tabs are allowlisted rather than open.
- All traffic is encrypted in transit.
No system is perfectly secure. If a personal data breach occurs we will notify you and the Data Protection Board of India as the Act requires.
07Rights of the individuals in the register
Under the Act a Data Principal may ask for access to their data, correction or completion of it, erasure, and may withdraw consent or nominate someone to act for them.
Route these requests to the firm, not to us. Where the data belongs to a client of your firm, your firm is the Data Fiduciary and holds the relationship. If such a request reaches us directly we will refer it to your firm and assist you in answering it. For your own staff's account data, contact us using the next section.
08Grievance Officer
The Act requires a named point of contact for grievances. Ours is:
We will acknowledge a grievance within 7 working days and respond substantively within 30 days. If you are not satisfied, you may escalate to the Data Protection Board of India.
09This website
Our marketing site sets no advertising or analytics cookies and runs no third-party tracking scripts. It loads fonts from Google Fonts, which receives the request. Booking a demo takes you to Calendly, whose own privacy notice then applies to what you enter there.
Our transactional email is relayed by Brevo, which applies open and click tracking that we cannot disable on our current plan.
10Changes
We will post any change here and update the version and date at the top. Where a change materially affects how your data is processed, we will notify the email address on your account at least 30 days beforehand.