Skip to content
nitiqo
Legal

Privacy Policy

Last updated: 27 June 2026

Vedasva Systems (“Nitiqo”, “we”, “us” or “our”) respects your privacy and is committed to protecting your personal data. This Privacy Policy explains what information we collect about you, how and why we use it, who we share it with, and the rights and choices available to you.

For security, privacy & procurement teams

Evaluating Nitiqo for your organisation? Our Trust Center holds our security posture, certifications and responsible-disclosure policy; our Data Processing Addendum governs personal data processed within the platform and includes our security commitments, audit rights and sub-processor terms. A current sub-processor list and completed security questionnaires are available on request at hello@nitiqo.com.

1. Scope of this policy

This policy applies to personal data we process as a controller when you visit nitiqo.com and our related web properties, request a demo or contact us, subscribe to communications, apply to or use our partner programme, or otherwise interact with Vedasva Systems (together, the “Services”). Personal data that a customer uploads to or processes within theNitiqo platform is covered by Section 3 and our Data Processing Addendum, not by this policy.

2. Who we are

For personal data covered by this policy, the controller is Vedasva Systems, the company behind Nitiqo. You can reach us at hello@nitiqo.com for any privacy-related query, including to identify the relevant contracting entity and registered address for your jurisdiction.

3. Enterprise and customer data

When we provide the Nitiqo platform to an organisation, that organisation (our customer) is the controller of the personal data it uploads or processes within the platform, and Vedasva Systems acts as its processor. In that role we process customer personal data only on the customer's documented instructions and as described in the agreement and our Data Processing Addendum (DPA), which addresses:

  • the subject matter, duration, nature and purpose of processing;
  • confidentiality obligations on personnel with access to data;
  • technical and organisational security measures;
  • use of sub-processors, with notice of changes and a right to object;
  • assistance with data-subject requests, impact assessments and regulator engagement;
  • personal-data breach notification within the timeframes set out in the DPA;
  • audit and information rights to verify our compliance; and
  • return or deletion of customer data on termination.

Enterprise customers can execute our DPA, including Standard Contractual Clauses where relevant, as part of their agreement. Where our processing of customer data conflicts with this policy, the DPA and the customer agreement control.

4. Information we collect

We collect personal data in three ways.

Information you provide to us

  • Identity and contact data — such as your name, work email address, telephone number, job title, company name and country.
  • Enquiry content — the message, demo request, support question or other information you choose to send us through forms or email.
  • Partner data — information you submit when you apply to, or operate within, our partner programme, including business details and credentials for the partner portal.
  • Recruitment data — where you apply for a role, the contents of your application and any information you choose to share with us.

Information we collect automatically

  • Device and technical data — IP address, browser type and version, operating system, language settings and similar diagnostic data.
  • Usage data — pages viewed, referring and exit pages, approximate location derived from IP, and aggregate, privacy-respecting analytics about how the website is used.

Information from third parties

We may receive limited information about you from business-information providers, event partners, our service providers, and publicly available sources, used to validate enquiries, prevent fraud and keep our records accurate.

We do not intentionally collect special categories of personal data (such as health, racial or ethnic origin, or political opinions) through the website, and we ask that you do not submit such data to us.

5. Cookies and similar technologies

Our website is designed to be lightweight and static by default. We use only the cookies and local-storage entries that are strictly necessary to operate the site and a minimal set of privacy-respecting analytics that do not track you across other websites. Where required by law, we ask for your consent before setting non-essential cookies, and you can withdraw consent at any time through your browser settings or any cookie control we provide.

6. How we use information

We use personal data to:

  • respond to your enquiries, schedule and run demos, and provide the Services you request;
  • operate, maintain, secure and improve our website and our partner programme;
  • send you administrative messages and, where permitted, relevant marketing communications;
  • understand how our website is used so we can improve content and performance;
  • detect, prevent and investigate fraud, abuse and security incidents; and
  • comply with our legal obligations and enforce our terms and agreements.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising.

7. Legal bases for processing

Where the EU or UK General Data Protection Regulation (GDPR) applies, we rely on the following legal bases:

  • Consent — for example, for non-essential cookies and certain marketing, which you may withdraw at any time;
  • Performance of a contract — or steps taken at your request before entering a contract, such as responding to a demo request;
  • Legitimate interests — to operate and secure our business, develop our Services and engage in business-to-business marketing, balanced against your rights; and
  • Legal obligation — where processing is necessary to comply with applicable law.

Where India's Digital Personal Data Protection Act, 2023 (DPDP Act) applies, we process personal data on the basis of your consent or other lawful grounds permitted under that Act.

8. Artificial intelligence and machine learning

Nitiqo is an AI-native platform, and we are deliberate about how personal data interacts with our AI features. For personal data covered by this policy, we apply the following principles:

  • No training of shared models on customer data. We do not use personal data that customers process within the platform to train, fine-tune or improve foundation models that are shared across customers, except where the customer has explicitly instructed us to do so for their own benefit.
  • Customer control and isolation. AI processing of customer data takes place under the customer's instructions and within their tenant boundary, subject to the DPA.
  • Human oversight. AI outputs are intended to assist, not replace, human judgement; we do not make decisions producing legal or similarly significant effects about you solely by automated means (see Section 23).
  • Sub-processor transparency. Any third-party AI providers we rely on appear on our sub-processor list and are bound by confidentiality and data-protection terms, including restrictions on using data to train their own models.

9. Marketing communications

We may send you information about Nitiqo that we think is relevant to your role. You can opt out at any time by using the unsubscribe link in our emails or by contacting us at hello@nitiqo.com. Opting out of marketing does not stop service or transactional messages necessary to respond to your requests.

10. How we share information

We share personal data only in the following circumstances:

  • Service providers — who process data on our behalf under written contracts (see below);
  • Professional advisers — such as auditors, lawyers and insurers, where necessary;
  • Corporate transactions — in connection with a merger, acquisition, financing or sale of assets, subject to appropriate confidentiality; and
  • Legal and safety — where required to comply with law, respond to lawful requests, or protect the rights, property and safety of Vedasva Systems, our users and others (see Section 20).

11. Service providers and sub-processors

We rely on carefully selected providers for hosting, content delivery, email, customer relationship management, analytics and AI capabilities. Each is bound by contractual obligations to protect personal data, to process it only on our instructions, and to maintain appropriate security. We maintain a current list of sub-processors used to deliver the Nitiqo platform, available to customers, and we provide advance notice of material changes so customers can exercise any right to object set out in the DPA.

12. International transfers and data residency

We may process personal data in countries other than the one in which you are located. Where we transfer personal data across borders, we rely on lawful transfer mechanisms — such as the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or adequacy decisions — and we apply additional safeguards where appropriate. For enterprise, regulated and sovereign deployments, regional hosting and data-residency options may be available so that customer data is stored and processed in a chosen region; contact us to discuss options for your jurisdiction.

13. Data retention

We keep personal data only for as long as necessary to fulfil the purposes described in this policy, including to meet legal, accounting, tax or reporting requirements. Retention periods vary according to the type of data and the reason we hold it; when data is no longer needed, we securely delete or anonymise it. Customer data within the platform is retained, returned and deleted in accordance with the customer agreement and DPA.

14. How we protect information

We maintain technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure or destruction. These include encryption in transit and at rest, access controls on a least-privilege basis, tenant isolation, network and application hardening, monitoring and logging, secure development practices, and a static-by-design public website that minimises attack surface. You can read more, including our certifications and audits, in our Trust Center. No method of transmission or storage is completely secure, so while we work hard to protect your data we cannot guarantee absolute security.

15. Personal data breaches

We maintain an incident-response process to detect, investigate and respond to security incidents. Where a personal-data breach affects data for which we are the controller, we will notify affected individuals and the relevant authorities where and within the timeframes required by applicable law. Where we act as a processor for a customer, we notify the customer without undue delay in accordance with the DPA so they can meet their own obligations.

16. Your privacy rights

Depending on where you live and the applicable law, you may have some or all of the following rights in relation to your personal data:

  • to access a copy of the personal data we hold about you;
  • to correct inaccurate or incomplete data;
  • to delete your data in certain circumstances;
  • to restrict or object to certain processing, including direct marketing;
  • to data portability, where applicable;
  • to withdraw consent at any time, without affecting prior processing;
  • to nominate another person to exercise your rights, where the DPDP Act applies; and
  • to lodge a complaint with a supervisory or data-protection authority.

If your personal data is processed within the Nitiqo platform on behalf of a customer, please direct your request to that customer as controller; we will assist them in responding as required by the DPA.

17. California privacy rights

If you are a California resident, the California Consumer Privacy Act, as amended by the CPRA, gives you rights to know, access, correct and delete your personal information, to opt out of the “sale” or “sharing” of personal information, and to limit the use of sensitive personal information, without discrimination for exercising those rights. We do not sell or share personal information as those terms are defined, and we honour recognised opt-out preference signals such as the Global Privacy Control (GPC) where applicable. You may use an authorised agent to submit a request. To exercise these rights, contact us as described below.

18. Exercising your rights

To exercise any of these rights, contact us at hello@nitiqo.com marked for the attention of our Privacy Team. We may need to verify your identity before acting on your request. We will respond within the timeframe required by applicable law and free of charge in most cases. If you are in the EU or UK and believe we have not handled your data properly, you may complain to your local data-protection authority. If the DPDP Act applies, you may also raise a grievance with us and, where unresolved, with the Data Protection Board of India.

19. Representative and Data Protection Officer

Where we are required to appoint a representative in the EU or UK under Article 27 of the GDPR, or a Data Protection Officer under Article 37, their contact details are available on request at hello@nitiqo.com. You may contact them on any matter relating to our processing of your personal data or to exercise your rights.

20. Government and law-enforcement requests

We disclose personal data to government, law-enforcement or regulatory bodies only where we have a good-faith belief that we are legally required to do so. We review each request for validity, push back on requests that are overbroad or legally deficient, and disclose only the minimum necessary. Where we act as a processor and are legally permitted, we will redirect the request to the relevant customer and notify them before responding, so they can seek to protect their data.

21. Children's privacy

Our Services are intended for business users and are not directed to children. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take appropriate steps to delete it.

Our website may contain links to third-party websites and services that we do not control. This policy does not apply to those third parties, and we encourage you to review their privacy notices. We are not responsible for the content or privacy practices of third-party sites.

23. Automated decision-making

We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing of the personal data covered by this policy. Where this changes, we will update this policy and provide any information required by law, including meaningful information about the logic involved and your right to obtain human review.

24. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, our Services or the law. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Please review this page periodically.

25. How to contact us

If you have any questions, concerns or requests regarding this policy or your personal data, contact our Privacy Team at hello@nitiqo.com. We will be glad to help.