VapusData logoVapusData logo

Privacy Policy – 2026

Privacy Policy – 2026

Last updated 4 September 2026

Anekam Datanet Technologies Pvt Ltd is committed to protecting your privacy. Please read this Privacy Policy carefully to learn more about how we collect and use your information. This Privacy Policy, when read together with the Terms of Use, governs your interactions with the Vapusdata Platform and/or the Anekam Datanet Technologies Pvt Ltd, as well as your professional interactions with Anekam Datanet Technologies Pvt Ltd.

1. Introduction

Anekam Datanet Technologies Pvt Ltd is committed to protecting your privacy. Please read this Privacy Policy carefully to learn more about how we collect and use your information. This Privacy Policy, when read together with the Terms of Use, governs your interactions with the Vapusdata Platform and/or the Anekam Datanet Technologies Pvt Ltd, as well as your professional interactions with Anekam Datanet Technologies Pvt Ltd.

By interacting with the Vapusdata Platform and/or the Anekam Datanet Technologies Pvt Ltd, submitting information to Us or signing up for any services offered by Us, you agree and consent to Anekam Datanet Technologies Pvt Ltd, as well as our respective representatives collecting, using, disclosing and sharing amongst themselves your Data, Personal Data, non-PII and disclosing such Data, Personal Data and non-PII to our authorised service providers and relevant third parties in the manner set forth in this Privacy Policy.

2. Definitions

The following expressions shall, unless otherwise expressly stated, bear the following meaning:

  • Data means any data you may provide to us via the Vapusdata Platform or as part of Anekam Datanet Technologies Pvt Ltd and includes any data we may access from you such as ad campaign data, device data and location data (which is set out in further detail below).
  • Vapusdata Platform means a platform known as vapusdata.com which, among other things, (i) gives customers recommendations on content, product pricing, inventory, advertising, and supply chain optimization; (ii) allows customers to manage eCommerce orders; and (iii) allows customers to execute and manage marketing campaigns.
  • Non-PII means any information that cannot be used to identify a particular individual and, for the avoidance of doubt, includes Data which is not personal Data.
  • Personal Data means any data or information that, either jointly with other data or on its own can be relating directly or indirectly about you (or any person) from which you (or such person) can be identified, either (a) from that data; or (b) from that data and other information to which we have or are likely to have access including any sensitive personal data and expression of opinion about you. For the avoidance of doubt Data may also be Personal Data.
  • Privacy Policy shall mean this policy and shall include all such further and future amendments.
  • Process, Processing shall mean any dealings by Us with the Data, Personal Data and Non-PII including but without limitation to the collection, recording, holding, storing, use and disclosure of the Data, Personal Data and non-PII and shall further include, but not be limited to, the organisation, adaptation, alteration of the Data, Personal Data and Non-PII, the access to, retrieval, consultation or use of the Data, Personal Data and Non-PII, the disclosure of the Data, Personal Data and Non-PII by transmission, transfer, dissemination or otherwise making available or the alignment, combination, correction, erasure or the destruction of the Data, Personal Data and Non-PII.
  • Related Corporation means any subsidiary or holding/parent company of that corporation or any subsidiary of that holding/parent company, or any other affiliated legal entity with whom we are under common corporate control, which has agreed to comply with the terms of this Privacy Policy.
  • Anekam Datanet Technologies Pvt Ltd, Our, Us, We refers to Anekam Datanet Technologies Pvt Ltd and its Related Corporation(s).
  • Anekam Datanet Technologies Pvt Ltd means any services and/or products and/or a combination of both provided by Anekam Datanet Technologies Pvt Ltd, our Related Corporation(s), authorised agents, authorised affiliated partners or associates and shall include the Vapusdata Platform. Any references to Anekam Datanet Technologies Pvt Ltd shall include the Vapusdata Platform.

3. Information we collect

We collect the minimum needed to operate an enterprise platform and to run the commercial relationship behind it. We do not sell personal data, and we do not run advertising networks on the platform.

Account data

  • Name, corporate email address, job title, employer and country, supplied at sign-up or by an account administrator.
  • Authentication data — hashed credentials, SSO identifiers, multi-factor enrolment and session records.
  • Billing and contracting details: entity name, registered address, tax identifiers, purchase orders and payment references.
  • Correspondence with sales and support, including demo requests, tickets and the contact forms on this site.

Operational & telemetry data

  • API request logs, timestamps, endpoints, response codes and error traces.
  • Token consumption, agent execution metrics, workflow run history, queue depth and latency.
  • Security and audit events: sign-ins, permission changes, key issuance and configuration changes.
  • Device and browser metadata, and IP address, used for security, abuse prevention and diagnostics.

Customer-connected SaaS data

Where a customer connects an ERP, accounting suite, bank feed, storage bucket or other SaaS system, the records that flow through those connectors — invoices, statements, ledgers, contracts and the personal data they happen to contain — are processed on that customer's instructions.

  • Processing is ephemeral wherever the workflow allows it: data is used for the run and not retained beyond it.
  • Where retention is required for a workflow — reconciliation history, audit trails, exception queues — it follows the tenant's configured retention policy.
  • Connector scopes are least-privilege and revocable by the customer at any time.
  • We do not mine, profile or repurpose connected data for anything other than delivering the customer's own workflows.

4. Purpose of processing

Each category of data is processed for a stated purpose and no other. Where the GDPR applies, our lawful bases are performance of a contract, our legitimate interests in securing and improving the platform, consent for non-essential cookies and marketing, and compliance with legal obligations. Under the DPDP Act, processing is on the basis of consent or a legitimate use as that Act defines it.

  • Delivering autonomous workflows: document intelligence and OCR, real-time reconciliation, exception resolution, classification and reporting.
  • Providing, maintaining and securing the platform, including authentication, tenancy isolation, fraud and abuse prevention, and incident response.
  • Metering consumption, invoicing, credit control and tax compliance.
  • Support: diagnosing an incident, reproducing a defect, and answering a ticket.
  • Improving reliability and performance using aggregated, de-identified operational metrics only.
  • Sending service, security and contractual notices, and — where consent has been given, or a soft opt-in applies — product and marketing communications, with an unsubscribe link in every one.

5. AI & enterprise data boundary

Customer data is never used to train, fine-tune or evaluate generalised or foundation models without the customer's explicit written consent. This is a contractual guarantee in our Terms & Conditions, not a preference setting.

Every tenant is isolated. Data, indexes, embeddings, prompts and agent state belong to one tenancy and are addressable only from within it; there is no cross-tenant retrieval, caching or training. Deployments in a customer's own cloud account or data centre keep the boundary inside the customer's own network perimeter.

Our control environment is aligned with ISO/IEC 27001 and SOC 2 practices: role-based access control, least privilege, segregated environments, centralised audit logging, vulnerability management, and periodic third-party testing. Access to customer data by our personnel requires prior authorisation, is tied to a named incident, and is time-bound and logged.

  • Encryption at rest with AES-256, and in transit with TLS 1.3.
  • Key management through a managed key service, with rotation and separation of duties.
  • Multi-factor authentication and SSO for administrative access, with break-glass procedures that are logged and reviewed.
  • Backups encrypted to the same standard, with tested restore procedures and a documented rotation.
  • Security incidents assessed without undue delay and notified to affected customers and, where required, to the relevant supervisory authority — within 72 hours under the GDPR and as prescribed under the DPDP Act.

6. Third-party integrations & sub-processors

We use a small number of vetted sub-processors to run the platform. Each is bound by written terms that impose confidentiality, security and data protection obligations no weaker than those in this policy, and none is permitted to use customer data for its own purposes or for model training.

The current list of sub-processors, with their processing purpose and location, is available to customers on request through their account team, and material additions are notified in advance so a customer can raise a reasonable objection.

  • Cloud hosting and managed infrastructure for the regions a customer's deployment runs in.
  • Identity and authentication providers for sign-in, SSO and multi-factor enrolment.
  • Payment gateways and billing platforms, which process billing contact and transaction data; card details are handled by the gateway and are never stored by us.
  • Model inference providers, only where a workflow calls them, and only under contracts that prohibit training and require deletion after inference.
  • Operational tooling for error monitoring, product analytics, email delivery and ticketing, scoped to the minimum data required.
  • Disclosure to a professional adviser, an acquirer in a corporate transaction, or a public authority where the law compels it — in the last case, narrowly and with notice to the customer wherever legally permitted.

7. Cross-border data transfers

Data residency is a deployment decision. Customers can require that their tenancy, including storage and inference, remains within a nominated jurisdiction, and self-managed deployments never leave the customer's own infrastructure.

Where personal data does cross a border — for support, for a sub-processor's regional service, or because a customer selects a region outside its own — the transfer is made under an appropriate safeguard: the European Commission's Standard Contractual Clauses together with a transfer risk assessment for EEA and UK data, and compliance with the transfer restrictions notified under the DPDP Act for data originating in India.

Transfer mechanisms, the regions in use, and the residency options available are documented for customers as part of the data processing agreement.

8. Your rights & data subject access requests

Individuals have rights over their personal data under the GDPR, the DPDP Act 2023 and comparable laws. Where we act as Controller, requests are answered directly. Where we act as Processor for a customer, requests are routed to that customer as Controller, and we assist them in responding.

Requests should be sent to [email protected]. We acknowledge within five (5) business days and respond substantively within 15 to 30 days, depending on the applicable law and the complexity of the request; where an extension is permitted and necessary, we will say so and explain why. We verify identity before acting, and we do not charge for a first request.

  • Access: a copy of the personal data we hold about you, and information about how it is processed.
  • Rectification: correction of data that is inaccurate, and completion of data that is incomplete.
  • Erasure: deletion of data we no longer have a lawful basis to keep.
  • Portability and export: a structured, machine-readable copy, including full tenant export through the platform APIs.
  • Restriction and objection: including objection to processing based on our legitimate interests, and withdrawal of consent at any time without affecting prior processing.
  • Nomination and grievance redressal under the DPDP Act, and the right to complain to a supervisory authority or the Data Protection Board of India.

9. Cookie & tracking transparency

The application sets strictly necessary cookies for authentication, session integrity, security and load balancing. These cannot be switched off without breaking sign-in, so they are set without consent, as the law allows.

Everything else — performance and analytics measurement, and any marketing measurement — is set only after consent is given, is granular by category, and can be changed or withdrawn at any time. No non-essential script loads before a choice is made, and withdrawing consent is as easy as giving it.

We honour browser signals where the law requires it, and we do not use cookies to build advertising profiles of platform users. Our Cookie Policy sets out each category, the cookies in it, how long they last and how to change or withdraw a choice.

10. Data retention & deletion

We keep data only for as long as the purpose it was collected for requires. Tenant business data follows the customer's configured retention policy; account data is kept for the life of the account; billing records are retained for the period Indian tax and company law prescribes.

On termination, customer data is available for export for thirty (30) days, after which it is deleted from production systems and purged from backups in line with the documented backup rotation. Written confirmation of deletion is provided on request.

Security and audit logs are retained on a defined schedule for forensic and compliance purposes, and telemetry used for platform improvement is aggregated or de-identified so that it no longer identifies a customer, an individual or a business record.

11. Updates & amendments

This policy is reviewed periodically and updated when our practices, our products or the law change. The date at the top of the page records the last revision.

Material changes — a new category of processing, a new transfer mechanism, or a change in the sub-processors handling customer data — are notified to account administrators by email, and where required, consent is sought again before the change takes effect. Continued use after the effective date signifies acceptance of the updated policy.

12. Contact & grievance officer

Privacy questions, data subject requests and complaints should be sent to [email protected], which reaches the team responsible for data protection and the grievance officer appointed under the DPDP Act 2023. General enquiries can be sent to [email protected].

Postal correspondence should be addressed to Anekam Datanet Technologies Pvt. Ltd., Bengaluru, Karnataka, India. If a complaint is not resolved to your satisfaction, you may escalate to your local supervisory authority or, in India, to the Data Protection Board.

Vapusdata — Attn: Privacy Team. Address: 4th floor, 806 27th Main, HSR Layout, Sector 1, Bengaluru, Karnataka – 560102. Email: [email protected]. Privacy Officer: Ashesh Anand.

Essential cookies are required for the site to function and cannot be switched off. Everything else is off until you switch it on, and you can change or withdraw your choice at any time from the Cookie settings link in the footer. The Cookie Policy lists the cookies we set and how long each one lasts.

No choice recorded yet