Any origin. Any destination. One workflow. Located in United States Support Sign in
Veloque
Sign in Start 3-day free trial
Sign in Start 3-day free trial
Legal

Privacy policy

Last updated 1 September 2026

The short version, in plain words

  • We keep your name, email, company details and whatever you type into the tools.
  • What you type into the AI tools and the chat box is sent to Google's AI to get an answer. Don't paste customer names, contract prices or anyone's personal details there.
  • Your password, bank details and registration numbers are scrambled before they are stored.
  • Nothing is counted until you say yes. Analytics cookies stay off until you accept them, and you can change your mind from “Cookie settings” in the footer.
  • We never sell your data, never give it to advertisers, and never let it train an AI model.
  • You can ask us to show, correct, export or delete your data. Write to the address at the bottom — we answer within 30 days, or one month if the GDPR applies to you.

1. Who we are, and which law applies to you

Chetty Exports Private Limited ("we", "us", "CEPL"), of #1, Chendhur Plaza, Chendhur Garden, Soriyampatti, Harur 636903, Tamil Nadu, India, operates Veloque at veloque.in. We are the Data Fiduciary under India's Digital Personal Data Protection Act, 2023 and the controller under the EU General Data Protection Regulation and the UK GDPR, for the personal data described here.

Veloque is sold to businesses in many countries, so more than one privacy law can apply at once. Rather than publish several policies that would slowly disagree with each other, this one covers all of them and says where they differ:

2. Where we are the controller, and where we are only the processor

This distinction matters and is easy to blur, so it comes first.

We are the controller for data about you: your name, work email, phone, country, company, password hash, billing details, support tickets, and the technical records our servers keep of your requests. We decided to collect those and why, so they are ours to answer for, and this policy governs them.

We are only the processor for the business records you put into the platform — your customers and suppliers, their contact people, your quotations, shipments and invoices. You decided to put those there; we hold them and act on your instructions. Where those records contain personal data about somebody else, you are that person's controller and we are your processor. The terms governing that — instructions, confidentiality, sub-processors, assistance, deletion on termination — are in our Data Processing Addendum, which applies automatically to every account. You do not have to ask us to sign one.

3. What we collect

Account details you give us: name, email, company, phone, country, and password (stored only as a bcrypt hash, never in plain text).

Business and registration details you enter in your company profile: your tax number, customs number, national number and bank identifiers — which are called different things in different countries, and are asked for by whichever names apply where you trade — plus registered address and bank name. These are the fields we treat as most sensitive and encrypt at rest (see Security).

What you put into the tools: product descriptions, costing inputs, saved quotes, shipments, documents and the master data behind them.

Support: messages you type into the on-site chat assistant, and the subject, description and replies on any ticket you raise — including the name and email you give if you raise one without signing in.

Billing: your organisation's billing address, billing email and tax registration number if you make a purchase. We never see or store your card number. The card is entered on our payment provider's own form and stays with them; we receive a token, the last four digits, and whether the charge succeeded.

Technical data, collected automatically: IP address, browser user agent and timestamps, for security, fraud prevention and rate limiting. A coarse country is derived from the IP address to pick your currency and the right tax rules for your calculators; that derivation is cached in a cookie so it need not be repeated on every page.

What we do not collect: we ask for no special-category data — health, race, religion, politics, biometrics, trade-union membership, sexual orientation — and none of it is needed to use Veloque. Please do not put any into the tools. We do not knowingly collect data from anyone under 18; the service is for business use by adults acting for their company, and we do not offer accounts to children. Where the DPDP Act requires verifiable parental consent for a child's data, we meet that requirement by not processing children's data at all.

4. Why we process it, and on what legal basis

GDPR Article 6 requires a named lawful basis for every purpose. The DPDP Act works from consent plus a set of "legitimate uses". This table is the same answer for both.

PurposeWhat that meansLawful basis
Running your account Creating it, signing you in, keeping your organisation and team, sending service email you cannot opt out of (password resets, receipts, security notices). Performance of a contract
The trade tools Turning what you type into a product code, a cost sheet, a compliance answer or a document. Performance of a contract
Billing and tax records Taking payment, issuing invoices, keeping the statutory accounting record. Legal obligation, and performance of a contract
Support Answering a ticket or a chat message, and escalating it if it stalls. Performance of a contract, and our legitimate interest in running a support desk
Security and abuse prevention Rate limiting, blocking credential-guessing, keeping short-lived access logs. Our legitimate interest in keeping the service and its users safe
Analytics Counting visits and page views in aggregate — only after you have said yes. Consent, which you can withdraw at any time
Product email Product news, if you asked for it. We do not add you to a list because you signed up. Consent, which you can withdraw at any time

Where we rely on legitimate interests, we have weighed ours against your rights and concluded they do not override them: rate limiting and short-lived security logs are the minimum needed to stop accounts being broken into, and a support desk cannot answer a question without reading it. You can object to either — see section 9.

Where we rely on consent, nothing happens until you give it, and withdrawing it is as easy as giving it. Withdrawal does not make the processing before it unlawful.

5. The AI features, and what is not a decision about you

Product descriptions and the standing business context from your profile (company name, role, tax and customs numbers, products, markets, certifications — never your address, bank details or password) are sent to Google's Gemini API to generate a classification, compliance, market-shortlist, trade-plan or diagnosis result. The same applies to messages you type into the on-site chat assistant, which go to the same API together with a knowledge base built only from our own public pages.

Do not paste confidential buyer names, contract pricing, or another individual's personal data into the AI boxes. Treat them as you would any third-party AI tool. The tools work perfectly well on a product description with no names in it.

Your data does not train anyone's model. We use Google's paid API tier, under terms providing that submitted content is not used to train Google's generative models, and we train no model of our own on your content. The mirror-image commitment — that nobody may train a model on our content either — is in our copyright notice.

Automated decision-making (GDPR Article 22). Veloque produces estimates and suggestions. It makes no decision producing a legal effect concerning you, or similarly significantly affecting you: it does not decide whether you get an account, a price, credit, or a shipment. Every output is a draft for you to check — which is the entire point of the disclaimer. There is no profiling and no automated decision-making within the meaning of Article 22.

6. Who else touches it

The full register — every sub-processor, what it does, where it is, and on what basis data reaches it — is published and kept current at Security → sub-processors, so it can be updated without republishing this policy. In summary: our hosting and outbound-email provider; Google's Gemini API for the AI features; our payment provider for taking money; Google Analytics if and only if you accepted analytics cookies; the two public asset services your browser fetches the display typeface and one graphics library from, which see your IP address and browser user agent; and a central-bank exchange-rate feed, which receives no personal data at all.

We may also disclose data where legally compelled — a valid order from a court or a regulator with jurisdiction over us — and in a merger or sale of the business, in which case the buyer takes on this policy and you are told before anything changes. We do not sell personal data, we do not share it with advertisers or data brokers, and we do no cross-context behavioural advertising.

7. Sending data abroad

We are in India and some of the services above are elsewhere, so data crosses borders. That is lawful, and here is on what footing.

Out of the EEA or the UK. Where you are in the EEA or the UK, transfers to us in India and to sub-processors outside those areas are made under the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK International Data Transfer Addendum where the UK GDPR applies, supported by a transfer risk assessment and the technical measures in Security — encryption in transit, encryption at rest for the sensitive fields, and no routine access to customer content by our staff. India has not been the subject of an EU adequacy decision, which is precisely why the clauses, rather than adequacy, are the mechanism. They are incorporated into our Data Processing Addendum; a copy is available on request.

Out of India. The DPDP Act permits transfer to any country the Central Government has not restricted. We monitor that list and will say so here if it ever affects a service we use.

8. Cookies

Only the cookies that sign you in, protect the forms, and remember your currency and your consent choice are set automatically. Analytics cookies are set only after you accept them — and until you do, no analytics script is requested from Google at all. Two asset requests that set no cookie are made regardless; the cookie policy section 5 explains them. The complete table, and the button to change your mind, are on the cookie policy.

9. Your rights

You have all of these, whichever law applies to you. Where only one regime grants a right, it is marked.

How to use them: write to the contact in section 12 from the email address on the account, or from inside the account. We do not charge. We answer within 30 days under the DPDP Act and within one month under the GDPR — extendable by two further months for a genuinely complex request, in which case we tell you inside the first month and say why. If we must refuse part of a request, we say which part and on what ground.

We may ask you to confirm who you are before acting, but only so far as needed to be sure — we will not use your request as an excuse to collect more data than we already hold.

10. Deleting your account

Write to us and we will close it. Personal data goes within 30 days, except the invoices and payment records we are legally required to keep (see the table below) — we tell you exactly what is being kept and why, rather than quietly retaining it. Backups roll off on their own cycle and are never restored to serve a deleted account.

11. How long we keep it

WhatHow longWhy
Account and profile While the account is open, then 30 days after you close it. So an account closed by mistake can be restored, and so a departing colleague cannot silently erase an organisation.
Saved quotes, cost sheets, shipments and documents While the account is open, then 30 days after closure. They are your working records; they go when the account does.
Invoices and payment records 8 years from the end of the financial year. Required by Indian company and GST law. These survive account closure and are not deleted on request — we tell you so when you ask.
Support tickets and chat transcripts 24 months from closure of the ticket. So a recurring problem can be traced, and so a billing dispute has a record.
Security and rate-limit logs (IP, timestamps) 90 days, rolling. Long enough to investigate an incident, short enough not to be a standing archive of who visited when.
Consent records While the consent stands, then 3 years. To evidence that consent was given, which is itself a legal requirement.

12. Contact — Grievance Officer and data protection

One person holds both roles: Grievance Officer under the Information Technology Act 2000 and the DPDP Act 2023, and our contact point for data protection under the GDPR and UK GDPR.
Elavarasan Raja
Chetty Exports Private Limited, #1, Chendhur Plaza, Chendhur Garden, Soriyampatti, Harur 636903, Tamil Nadu, India
support@veloque.in

We have not appointed a Data Protection Officer. Article 37 requires one only where processing is on a large scale, involves regular and systematic monitoring, or concerns special-category data. Veloque does none of those: it is a business tool, we do no behavioural monitoring, and we ask for no special-category data at all. If that changes we will appoint one and name them here.

We have not yet appointed an EU representative under Article 27. We would rather say so than name one that does not exist. Until we do, EEA and UK residents should use the contact above, which is monitored and answered to the same deadlines. This is an open item we are working through, not a position we intend to keep.

13. Complaining to a regulator

Come to us first if you can — it is usually faster. But you never have to, and none of the following needs our involvement:

14. If there is a breach

If personal data is breached we will notify the relevant supervisory authority without undue delay and within 72 hours of becoming aware of it, where the GDPR or UK GDPR applies and the breach is likely to present a risk, and we will notify the Data Protection Board of India as the DPDP Act requires. Where the breach is likely to result in a high risk to you, we tell you directly and in plain language: what happened, what data, what we have done, and what you should do. Our incident handling — including that a suspected security issue is treated as Critical from the moment it is reported — is in the escalation policy, and researchers can reach us through /.well-known/security.txt.

15. Changes to this policy

We may update this policy as the product or the law changes. Material changes will be reflected by the "Last updated" date above; where a change materially reduces your rights or widens what we do with your data, we will tell account holders by email before it takes effect rather than relying on you to re-read the page.

This page goes with our Terms of use, Cookie policy, Data Processing Addendum and Security page. Chetty Exports Private Limited, #1, Chendhur Plaza, Chendhur Garden, Soriyampatti, Harur 636903, Tamil Nadu, India — support@veloque.in