Veloque
Sign in Start 3-day free trial
Sign in Start 3-day free trial
Legal

Data Processing Addendum

Last updated 1 September 2026

The short version, in plain words

  • This is already in force. You do not have to ask us to sign one, and there is no different version we give to bigger customers.
  • Where you put other people's details into Veloque — your customers, your suppliers, their staff — those are yours. We only hold and process them for you.
  • We follow your instructions, we keep them confidential, we do not use them for anything of our own, and we never train an AI model on them.
  • You get told before we add anyone new to the list of companies that help us run the service.
  • If a regulator or one of your customers asks you a question about this, we help you answer it.
  • When you leave, we delete it.

The numbered clauses below are the version that legally applies.

1. Parties, and when this applies

This Addendum is between the customer organisation that holds a Veloque account ("you", the controller) and Chetty Exports Private Limited, #1, Chendhur Plaza, Chendhur Garden, Soriyampatti, Harur 636903, Tamil Nadu, India ("we", the processor). It forms part of the Terms of use and takes effect when you accept them or open an account, whichever is earlier. No signature is required for it to bind us.

It applies whenever we process personal data on your behalf. It does not apply to data for which we are ourselves the controller — your account details, your billing records, your support tickets — which are governed by the privacy policy instead. Section 2 of that policy explains the split.

2. What we process for you

ItemDetail
Subject matterProviding the Veloque platform: classification, costing, compliance, document generation and the trade back-office records that go with them.
DurationFor as long as your account is open, plus the deletion window in clause 10.
Nature and purposeStorage, organisation, retrieval, calculation, generation of documents, and transmission to the sub-processors in clause 6 — all only to deliver the service to you.
Types of personal dataBusiness contact details of the people at your customers and suppliers (name, role, company, email, phone, address), and anything else you choose to type into a free-text field. You decide what goes in; we ask for none of it.
Categories of data subjectYour customers, suppliers, agents, brokers and their staff — and your own staff, in their capacity as users of your account.
Special-category dataNone. The platform asks for none, is not designed to hold any, and you must not put any in.

3. Our obligations

We will:

We will not sell your data, use it for our own purposes, use it to build or improve any product other than the service we provide to you, or use it — or allow anyone else to use it — to train, fine-tune or evaluate any machine-learning model.

4. Your obligations

You warrant that you have a lawful basis for the personal data you put into the platform, that you have given the people concerned whatever notice their law requires, and that your instructions to us are lawful. You are responsible for what your own users do inside your organisation's account, including who you invite and what access you give them. Please do not put personal data into a field that does not need it — in particular, do not paste it into the AI boxes (see clause 7).

5. Security measures

The current measures are described in full and kept up to date on the Security page, which is incorporated here by reference. In outline: TLS on every connection; passwords stored only as bcrypt hashes; AES-256-GCM encryption at rest for the sensitive registration and bank fields; server-side session tokens that expire and can be revoked; rate limiting against credential guessing; strict organisation-level data separation so one account cannot read another's records; a content security policy and the other hardening headers; least-privilege administrative access held by a single named account. We may change a measure for an equivalent or better one; we will not materially reduce the overall level of protection.

6. Sub-processors

You give general authorisation for us to appoint sub-processors. The current list — each one's name, what it does, and where it is — is published at Security → sub-processors. Before we add or replace one, we will publish the change there and notify the account's admin contact by email at least 30 days in advance. If you object on reasonable data-protection grounds within those 30 days, tell us and we will work with you to find an alternative; if none is possible, you may terminate the affected part of the service and we will refund the unused portion of what you have paid for it.

We remain fully liable to you for a sub-processor's performance of its data protection obligations, and we impose on each of them terms no less protective than these.

7. The AI features

When a user of your account runs a classification, compliance check, market shortlist, trade plan or diagnosis, the product description and the standing business context from the company profile are sent to our AI sub-processor to generate the answer. Address, bank details and passwords are never sent. We use the provider's paid API tier, whose terms provide that submitted content is not used to train its generative models.

Whether personal data reaches the AI provider is therefore within your control: it does so only if one of your users types it into a free-text box. The platform warns against this at the point of entry, and you should tell your users the same. This is the single most useful instruction you can give them.

8. International transfers

We are established in India, which is not the subject of an EU adequacy decision. Where you are established in the EEA or the UK, or the data you put in is protected by the EU or UK GDPR, the transfer to us and onward to the sub-processors in clause 6 is made under the European Commission's Standard Contractual Clauses of 4 June 2021 (Decision (EU) 2021/914), Module Two (controller to processor), which are incorporated into this Addendum by reference and completed as follows:

Where the UK GDPR applies, the SCCs are read with the ICO's International Data Transfer Addendum (version B1.0), with the tables completed from the equivalent clauses above, Part 2 Mandatory Clauses applying, and neither party able to end it under section 19 other than as that document provides. Where Swiss law applies, references to the GDPR and to supervisory authorities are read as including the Swiss FADP and the FDPIC.

We have carried out a transfer risk assessment and will provide a summary on request. If we are ever served with a government or law-enforcement demand for data you have put into the platform, we will challenge it where there are reasonable grounds, disclose only the minimum lawfully required, and tell you unless legally prohibited from doing so.

9. Audit

On reasonable written notice, and not more than once in any twelve months unless a regulator requires otherwise or there has been a breach affecting you, we will answer a reasonable security questionnaire and give you the information you need to verify our compliance with this Addendum. Where that is genuinely not enough for your regulator, we will discuss an on-site or independent audit, at your cost, on terms that protect the confidentiality and security of our other customers' data. We are a small company and we would rather tell you plainly what we do than produce a certification we do not hold.

10. Breach, and what happens at the end

Breach. We will notify you without undue delay after becoming aware of a personal data breach affecting data we process for you, and in any event in time for you to meet your own 72-hour obligation. The notice will describe what happened, the categories and approximate number of records, the likely consequences, and what we have done and are doing. We will not ask you to keep it quiet, and we will not charge you for our assistance with it.

Termination. On closure of your account you may export your data through the platform's own export and PDF features. We delete the personal data we process for you within 30 days of closure, except where we are required by law to keep something — principally invoices and payment records — in which case we keep only that, tell you what it is, and continue to protect it under this Addendum for as long as we hold it. Backups roll off on their own cycle and are never restored to serve a closed account.

11. Liability, and how this fits with the rest

Each party's liability under this Addendum is subject to the limitations in section 14 of the Terms of use, except where the GDPR or applicable law does not permit that. Where the Standard Contractual Clauses conflict with this Addendum or with the Terms, the Clauses prevail. Where this Addendum conflicts with the Terms on anything else about processing personal data, this Addendum prevails.

12. Signed copies, and changes

If your own compliance process needs a countersigned copy, write to support@veloque.in with the entity name and address to be named and we will return one. It will say the same thing as this page.

We may update this Addendum where the law changes or the service does. Material changes are signalled by the "Last updated" date and notified to account admins by email before they take effect. We will not use an update to reduce the protections in clause 3.

This page goes with our Terms of use, Privacy policy and Security page. Data protection contact: support@veloque.in.