Data Processing Addendum
Last updated 1 September 2026
The short version, in plain words
- This is already in force. You do not have to ask us to sign one, and there is no different version we give to bigger customers.
- Where you put other people's details into Veloque — your customers, your suppliers, their staff — those are yours. We only hold and process them for you.
- We follow your instructions, we keep them confidential, we do not use them for anything of our own, and we never train an AI model on them.
- You get told before we add anyone new to the list of companies that help us run the service.
- If a regulator or one of your customers asks you a question about this, we help you answer it.
- When you leave, we delete it.
The numbered clauses below are the version that legally applies.
1. Parties, and when this applies
This Addendum is between the customer organisation that holds a Veloque account ("you", the controller) and Chetty Exports Private Limited, #1, Chendhur Plaza, Chendhur Garden, Soriyampatti, Harur 636903, Tamil Nadu, India ("we", the processor). It forms part of the Terms of use and takes effect when you accept them or open an account, whichever is earlier. No signature is required for it to bind us.
It applies whenever we process personal data on your behalf. It does not apply to data for which we are ourselves the controller — your account details, your billing records, your support tickets — which are governed by the privacy policy instead. Section 2 of that policy explains the split.
2. What we process for you
| Item | Detail |
| Subject matter | Providing the Veloque platform: classification, costing, compliance, document generation and the trade back-office records that go with them. |
| Duration | For as long as your account is open, plus the deletion window in clause 10. |
| Nature and purpose | Storage, organisation, retrieval, calculation, generation of documents, and transmission to the sub-processors in clause 6 — all only to deliver the service to you. |
| Types of personal data | Business contact details of the people at your customers and suppliers (name, role, company, email, phone, address), and anything else you choose to type into a free-text field. You decide what goes in; we ask for none of it. |
| Categories of data subject | Your customers, suppliers, agents, brokers and their staff — and your own staff, in their capacity as users of your account. |
| Special-category data | None. The platform asks for none, is not designed to hold any, and you must not put any in. |
3. Our obligations
We will:
- process personal data only on your documented instructions — which, for ordinary use, are your use of the platform's own features and this Addendum — including as to transfers, unless we are required by law to do otherwise, in which case we tell you first unless the law forbids it;
- ensure that everyone we authorise to process it is bound by confidentiality;
- keep the technical and organisational measures described in clause 5 and on the Security page;
- use no sub-processor except as clause 6 permits;
- assist you, so far as is reasonable, in answering data subject requests, in your security and breach obligations, and in any data protection impact assessment or prior consultation you have to carry out;
- delete or return the data at the end, as clause 10 sets out;
- make available the information you reasonably need to demonstrate compliance with Article 28, and allow the audits described in clause 9;
- tell you immediately if we think an instruction of yours infringes data protection law.
We will not sell your data, use it for our own purposes, use it to build or improve any product other than the service we provide to you, or use it — or allow anyone else to use it — to train, fine-tune or evaluate any machine-learning model.
4. Your obligations
You warrant that you have a lawful basis for the personal data you put into the platform, that you have given the people concerned whatever notice their law requires, and that your instructions to us are lawful. You are responsible for what your own users do inside your organisation's account, including who you invite and what access you give them. Please do not put personal data into a field that does not need it — in particular, do not paste it into the AI boxes (see clause 7).
5. Security measures
The current measures are described in full and kept up to date on the Security page, which is incorporated here by reference. In outline: TLS on every connection; passwords stored only as bcrypt hashes; AES-256-GCM encryption at rest for the sensitive registration and bank fields; server-side session tokens that expire and can be revoked; rate limiting against credential guessing; strict organisation-level data separation so one account cannot read another's records; a content security policy and the other hardening headers; least-privilege administrative access held by a single named account. We may change a measure for an equivalent or better one; we will not materially reduce the overall level of protection.
6. Sub-processors
You give general authorisation for us to appoint sub-processors. The current list — each one's name, what it does, and where it is — is published at Security → sub-processors. Before we add or replace one, we will publish the change there and notify the account's admin contact by email at least 30 days in advance. If you object on reasonable data-protection grounds within those 30 days, tell us and we will work with you to find an alternative; if none is possible, you may terminate the affected part of the service and we will refund the unused portion of what you have paid for it.
We remain fully liable to you for a sub-processor's performance of its data protection obligations, and we impose on each of them terms no less protective than these.
7. The AI features
When a user of your account runs a classification, compliance check, market shortlist, trade plan or diagnosis, the product description and the standing business context from the company profile are sent to our AI sub-processor to generate the answer. Address, bank details and passwords are never sent. We use the provider's paid API tier, whose terms provide that submitted content is not used to train its generative models.
Whether personal data reaches the AI provider is therefore within your control: it does so only if one of your users types it into a free-text box. The platform warns against this at the point of entry, and you should tell your users the same. This is the single most useful instruction you can give them.
8. International transfers
We are established in India, which is not the subject of an EU adequacy decision. Where you are established in the EEA or the UK, or the data you put in is protected by the EU or UK GDPR, the transfer to us and onward to the sub-processors in clause 6 is made under the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914), Module Two (controller to processor), which are incorporated into this Addendum by reference and completed as follows:
- Clause 7 (docking): applies.
- Clause 9 (sub-processors): Option 2, general written authorisation, with the 30-day notice period in clause 6 above.
- Clause 11 (redress): the optional independent dispute resolution language does not apply.
- Clause 17 (governing law): the law of Ireland.
- Clause 18 (forum): the courts of Ireland.
- Annex I: the parties in clause 1, and the description of processing in clause 2, of this Addendum.
- Annex II: the measures in clause 5 and on the Security page.
- Annex III: the register at Security → sub-processors.
Where the UK GDPR applies, the SCCs are read with the ICO's International Data Transfer Addendum (version B1.0), with the tables completed from the equivalent clauses above, Part 2 Mandatory Clauses applying, and neither party able to end it under section 19 other than as that document provides. Where Swiss law applies, references to the GDPR and to supervisory authorities are read as including the Swiss FADP and the FDPIC.
We have carried out a transfer risk assessment and will provide a summary on request. If we are ever served with a government or law-enforcement demand for data you have put into the platform, we will challenge it where there are reasonable grounds, disclose only the minimum lawfully required, and tell you unless legally prohibited from doing so.
9. Audit
On reasonable written notice, and not more than once in any twelve months unless a regulator requires otherwise or there has been a breach affecting you, we will answer a reasonable security questionnaire and give you the information you need to verify our compliance with this Addendum. Where that is genuinely not enough for your regulator, we will discuss an on-site or independent audit, at your cost, on terms that protect the confidentiality and security of our other customers' data. We are a small company and we would rather tell you plainly what we do than produce a certification we do not hold.
10. Breach, and what happens at the end
Breach. We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and in any event in time for you to meet your own 72-hour obligation. The notice will describe what happened, the categories and approximate number of records, the likely consequences, and what we have done and are doing. We will not ask you to keep it quiet, and we will not charge you for our assistance with it.
Termination. On closure of your account you may export your data through the platform's own export and PDF features. We delete the personal data we process for you within 30 days of closure, except where we are required by law to keep something — principally invoices and payment records — in which case we keep only that, tell you what it is, and continue to protect it under this Addendum for as long as we hold it. Backups roll off on their own cycle and are never restored to serve a closed account.
11. Liability, and how this fits with the rest
Each party's liability under this Addendum is subject to the limitations in section 14 of the Terms of use, except where the GDPR or applicable law does not permit that. Where the Standard Contractual Clauses conflict with this Addendum or with the Terms, the Clauses prevail. Where this Addendum conflicts with the Terms on anything else about processing personal data, this Addendum prevails.
12. Signed copies, and changes
If your own compliance process needs a countersigned copy, write to support@veloque.in with the entity name and address to be named and we will return one. It will say the same thing as this page.
We may update this Addendum where the law changes or the service does. Material changes are signalled by the "Last updated" date and notified to account admins by email before they take effect. We will not use an update to reduce the protections in clause 3.
This page goes with our Terms of use, Privacy policy and Security page. Data protection contact: support@veloque.in.
