Terms of Service
PLEASE READ CAREFULLY. THESE TERMS LIMIT AND EXCLUDE THE COMPANY'S LIABILITY, PUT YOU IN CHARGE OF YOUR OWN COMPLIANCE, REQUIRE YOU TO INDEMNIFY THE COMPANY, AND SEND DISPUTES TO ARBITRATION. IF YOU DO NOT AGREE, DO NOT USE THE SERVICE.
In one paragraph. VERIDIAN DPDP is software that helps an organisation manage the work of implementing India's data-protection law: it turns the law into a list of jobs, gives each job to a named person, sends reminders, and keeps a dated record of who said what. It is a workflow, reminder and record-keeping tool. It is not a cybersecurity product, not a system that finds, scans, cleans, masks, deletes or protects your data, not a law firm, not an auditor, and not a certificate. You remain responsible for your compliance. Section 2 says this precisely.
1. Who we are, and what these Terms cover
- The Company. VERIDIAN DPDP is owned and operated by SHOBHA KAMAL SOLUTIONS PRIVATE LIMITED, a company incorporated in India under the Companies Act, 2013 (CIN U74999UP2017PTC098453), whose registered office is B-1105, Plot No. 14, Shipra Krishna Vista, Ahinsa Khand-1, Indirapuram, Ghaziabad, Uttar Pradesh 201014, India (the "Company", "we", "us").
- The Service. "Service" means VERIDIAN DPDP in every form: the websites at veridian-aios.com, dpdp.veridian-aios.com and app.veridian-aios.com; the signed-in application; the job library and playbooks; emails and reminders we send; the pages reached from those emails (including confirmation, consent and unsubscribe pages); the AI work link feature; the dpdp@veridian-aios.com mailbox; documentation; and any related support, trial or pilot, whether free or paid.
- You. "You" and "Customer" mean the organisation (company, firm, school, institution, NGO, partnership or other business) that signs up or on whose behalf anyone uses the Service, and each individual who uses it for that organisation. If you accept these Terms for an organisation, you confirm that you are authorised to bind it.
- Acceptance. You accept these Terms by ticking a box or clicking a button that refers to them, by signing up, or by using the Service, whichever is first. This is an electronic contract and is valid under the Information Technology Act, 2000 without a physical signature. The Disclaimer is part of these Terms.
- Order of precedence. If documents conflict, this order applies: (a) a written agreement signed for the Company by a director or an authorised signatory, and then only on the point it expressly covers; (b) these Terms; (c) the Disclaimer; (d) the Privacy Notice, but only as to how personal data is handled. Nothing on a web page, in a demonstration, in an email, in marketing material or said by any person changes these Terms unless it is in a document described in (a).
2. What the Service is, and what it is not
- What it is. The Service is a DPDP implementation and compliance-management tool (software as a service). It helps you plan, assign, chase and record the management of your obligations under the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 ("DPDP law"), and of the Information Technology Act, 2000 section 43A and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules") for as long as those apply.
- What it is not. The table below is part of these Terms. Each row is a thing the Service does not do, and you must not assume or rely on it.
| The Service is NOT… | What that means for you |
|---|---|
| A cybersecurity, data-security or data-protection system | It does not protect your networks, devices, servers, email, cloud accounts, databases or files. It does not detect, prevent, monitor, investigate or respond to intrusions, malware, leaks or breaches. Securing your data is your job, done with your own tools and advisers. |
| A data-cleaning, data-discovery or data-governance engine | It does not connect to, scan, crawl, inventory, classify, tag, mask, anonymise, pseudonymise, encrypt, back up, move, correct or delete personal data held in your systems, your vendors' systems or anywhere else. When a job says "erase" or "delete", it is a task for your people to carry out; the Service records that someone says it was done. |
| A document store | The Service is designed not to keep your documents. Where evidence is recorded it is recorded as a fingerprint (a hash) and a note, not the document. Keep your own documents safely. |
| A Consent Manager or a Data Fiduciary for your data | It is not a "Consent Manager" registered with the Data Protection Board of India. Consent and notice pages it offers are tools for you; you are the one who asks for, receives, records and honours consent. It does not decide your purposes or means of processing. |
| Your Data Protection Officer, Grievance Officer, Data Auditor or representative | You must appoint and equip your own people where the law requires them. The Service can help you record and publish who they are. |
| A law firm, a legal adviser, an auditor or an accountant | Nothing in the Service is legal, tax, accounting, audit or professional advice. The job library and playbooks are general working aids, not an opinion on your facts. |
| A certification, an audit, an assurance or a regulatory approval | No DPDP certification exists in India and we offer none. A completed job, a green status, a score or a report does not mean you comply with any law and is not a defence before the Board, a court or any authority. |
| A guarantee of any outcome | We do not promise that you will avoid a complaint, inquiry, penalty, breach or loss. |
| A breach-response or incident service | Reminders about time limits (for example 72 hours for a breach report) are aids only. You alone are responsible for deciding whether an event is a breach, for meeting every deadline and for making every report. |
- Lawful purpose. The Service is offered for compliance management only. You must not use it to hide wrongdoing, to mislead a regulator or a person, or to create a record you know to be false.
3. Business use only; eligibility
- The Service is sold to and used by businesses and organisations acting in the course of their business, profession or institution, and not by consumers for personal, family or household purposes. You confirm that your use is for such a purpose.
- You confirm that you are at least 18 years old and capable of entering a binding contract. The Service is not directed at children. Schools and other institutions that hold children's data do so as your own responsibility (clause 6.4).
4. Your account, people and access
- Sign-in is by email link and/or the methods the Service offers. Anyone who can read the mailbox that receives a link, or who holds an AI work link or any other link or token we issue for your organisation, can act with that person's authority. Links and tokens are credentials. You must protect them, must not forward them to anyone not entitled to use them, and must tell us promptly at dpdp@veridian-aios.com (subject: Security) if you think one has been exposed.
- You are responsible for everything done through your organisation's account, links and tokens, for who you invite, and for the roles and authority you give each person.
- You must give accurate information and keep it current.
- When you add or invite a person (an employee, a partner, a client, a vendor, a parent), you confirm that you are entitled to give us that person's business contact details and that they may lawfully receive the emails the Service sends to them.
5. Acceptable use
You must not, and must not help anyone to: (a) break the law or infringe anyone's rights; (b) put in data you have no right to use, or that is unlawful, defamatory, malicious or obscene; (c) enter more personal data than the Service needs (in particular, do not upload identity documents, health records, financial credentials, passwords, biometric data or children's records; describe them instead); (d) attempt to gain access to another customer's data, bypass access controls or probe, scan or test the Service's security without our written permission; (e) copy, scrape, harvest, reverse engineer, decompile or derive the source code or structure of the private parts of the Service, or build a competing product from them; (f) overload or disrupt the Service; (g) resell or sub-license the Service, or use it as a bureau for others, except as a CA, CS, audit or legal firm or other adviser using it to manage your clients' compliance under a written arrangement with us; (h) send spam or use the Service to contact people who have not agreed to hear from you; (i) use the Service in any way that misleads a person into thinking we have certified, audited, approved or endorsed them. The public pages may be read by search engines and AI systems as permitted by our robots.txt; that permission does not extend to the private application.
6. Your data; who is responsible for what
- Your data stays yours. As between you and us you own the content you put in, including records of your organisation's people, vendors, clients, answers and notes ("Customer Data"). You give us a limited, non-exclusive licence to host, copy, transmit, display and otherwise process Customer Data, and to create fingerprints and back-ups of it, only to provide and secure the Service for you, to keep the record the Service promises, to comply with law and to exercise our rights under these Terms.
- Roles under DPDP law. For the personal data in Customer Data, you are the Data Fiduciary (or, if you are an adviser acting for a client, the client is the Data Fiduciary and you act for it) and we act as your Data Processor, processing it only on your documented instructions as given by your use of the Service and these Terms. For personal data we collect for our own purposes (your account and contact details, billing, security and service logs, enquiries to dpdp@veridian-aios.com), we are a Data Fiduciary in our own right; the Privacy Notice explains that. Under DPDP law a Data Fiduciary stays responsible for compliance whatever its agreements with a processor say. Using the Service does not transfer your responsibility to us.
- Processor terms. As your Data Processor we will: (a) process Customer Data only to provide the Service and as you instruct; (b) keep it confidential and allow access only to people who need it and are bound to confidentiality; (c) take reasonable security safeguards appropriate to the Service, including access controls that separate one customer's data from another's, use of encrypted connections, and an append-only record of changes; (d) use sub-processors only as described in clause 6.6 and bind them to safeguards no less protective in substance; (e) tell you without undue delay after we become aware of a personal data breach affecting Customer Data in our systems, with the information we then have, so that you can decide what to tell the Data Protection Board and the people affected; (f) give reasonable help, at your cost if it goes beyond the ordinary operation of the Service, with requests from the people whose data it is and with your regulatory duties; (g) on termination, make the Customer Data available to you for export for 30 days and then delete or irreversibly de-identify it from live systems within a reasonable time thereafter, except what we must keep by law, for security, or to defend a claim (back-ups expire in the ordinary course). This clause 6.3 is intended to be the written contract between a Data Fiduciary and a Data Processor that DPDP law requires.
- Your duties as Data Fiduciary. You are solely responsible for: having a lawful basis and, where needed, valid consent for the personal data you put in and for the emails and reminders the Service sends to the people you add; giving the notices the law requires; verifiable parental or guardian consent and all special rules for children's data (a school or other institution using the parent-consent pages does so as the Data Fiduciary, and we only carry the page); answering requests and grievances from the people whose data it is; the accuracy of your data; how long you keep it; and reporting breaches to the Board and to affected people.
- Accuracy and fitness of your own records. The record the Service keeps shows what was entered and when, by whom (as identified by the link or sign-in used). It does not prove that what was entered is true.
- Sub-processors and places. To run the Service we use third parties, currently: Supabase (database and authentication; the database is in Mumbai, India, AWS region ap-south-1); Cloudflare (website hosting, network and incoming-mail routing); Resend (outgoing email; a US company, so email content passes through the United States); and a Google mailbox used by our operator to receive mail forwarded from dpdp@veridian-aios.com. If you choose to use an AI work link, the content you or your AI assistant retrieve is then handled by the AI provider you chose, under its terms, and not as our sub-processor. We may change sub-processors; we will keep the current list on the Privacy Notice. Cross-border transfers are made subject to section 16 of the DPDP Act and any restriction the Central Government notifies, which we will follow. We are not responsible for the acts or failures of a third party we do not control, except as the law requires.
- Your AI assistant. An AI work link lets an AI assistant you select read and (within the level you allow) change records and draft items on your behalf. AI output can be wrong, incomplete or invented. You are responsible for choosing an AI provider you are entitled to share the data with, for deciding what to share, for checking everything it produces before anyone relies on it, for switching a link off or rotating it when needed, and for every action taken through it as if you had taken it yourself. We do not train AI models on Customer Data and will not do so without your separate written agreement.
7. Fees and payment
- Some features are free. Fees for other features are as quoted to you in writing (a proposal, order form or invoice). Until a fee is agreed in writing you owe none and we may change or end a free feature at any time.
- Fees are exclusive of GST and other taxes, which you pay in addition. Invoices are payable within the time stated on them; if none, within 15 days. We may suspend the Service for non-payment after 7 days' notice.
- Fees are non-refundable except where a written agreement says otherwise or the law requires. We may change fees for a later period on 30 days' written notice; you may end the Service before the change takes effect.
8. Our intellectual property
The Service, the job library, playbooks, drafts, software, design, text, data structures and the names VERIDIAN, VERIDIAN DPDP and "VERy INDIAN" belong to the Company or its licensors. We give you a limited, non-exclusive, non-transferable, revocable right to use the Service for your own internal compliance management while these Terms apply. Nothing else is licensed. Anything you suggest about the Service may be used by us freely without payment or credit. Open-source components are used under their own licences. Third-party names are used only to identify them and imply no affiliation.
9. Availability and changes to the Service
We work to keep the Service available but give no uptime, speed, recovery or response-time commitment unless a signed agreement does. We may maintain, change, suspend or stop any feature. Emails are sent over the public internet through third parties and may be delayed, filtered, bounced or lost; a reminder that did not arrive does not extend or excuse any legal deadline. The job library reflects the law as we understood it on the date shown in the Service and is updated from time to time; laws change, are read differently by different authorities, and some of our citations are still marked for verification. Check the current law with your own adviser.
10. Warranty disclaimer
TO THE FULLEST EXTENT THE LAW PERMITS, THE SERVICE AND EVERYTHING IN IT ARE PROVIDED "AS IS" AND "AS AVAILABLE", WITHOUT ANY WARRANTY OR CONDITION, EXPRESS OR IMPLIED, INCLUDING OF ACCURACY, COMPLETENESS, MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, UNINTERRUPTED OR ERROR-FREE OPERATION, OR THAT USING IT WILL MAKE YOU COMPLIANT. The Disclaimer sets out more.
11. Limits on our liability
- What we are not liable for. To the fullest extent the law permits, the Company is not liable, whether in contract, tort (including negligence), breach of statutory duty or otherwise, for: (a) any penalty, fine, interest, compensation, order or direction imposed on you or anyone by the Data Protection Board, any regulator, court or tribunal, or any amount you pay or owe to a Data Principal or any other person; (b) indirect, special, incidental or consequential loss; (c) loss of profit, revenue, business, contracts, goodwill, reputation or savings; (d) loss, corruption or unavailability of data that was in your systems or not caused by our breach of clause 6.3; (e) cost of breach response, notification, investigation, forensic or legal work; (f) anything arising from your decision to rely, or not rely, on the Service or its output; (g) a breach, leak or cyber-incident affecting your systems, your people, your vendors or your AI provider; or (h) anything caused by events beyond our reasonable control.
- Overall cap. To the extent any liability cannot be excluded, the Company's total liability for all claims together arising out of or connected with the Service is limited to the fees you actually paid us for the Service in the 12 months before the first event giving rise to liability or, if you paid nothing, ₹1,000. Connected claims are one claim. This cap is the price of making the Service available on these terms and you accept it as reasonable.
- What is not limited. Nothing in these Terms excludes or limits liability for fraud or wilful misconduct, or any liability that the law does not allow to be excluded or limited.
- The people behind the Company. The Service is provided only by the Company. No director, officer, employee, shareholder, associate, affiliate, group company, contractor, consultant, agent, licensor, supplier or sub-processor of the Company, and no successor or assign of any of them (together, the "Protected Persons"), owes you any duty or has any liability to you in connection with the Service, and you agree to bring any claim only against the Company and never against a Protected Person personally, whether in contract, tort or otherwise. You will not sue or join a Protected Person. The Company accepts this clause for itself and as agent and trustee for each Protected Person, each of whom may enforce it, and you agree that the benefit is held on their behalf. If a Protected Person is nevertheless made to defend a claim you or anyone claiming through you brings, you will indemnify them as in clause 12. This does not exclude a liability imposed directly on an individual by a statute that cannot be contracted out of.
- Claims notice. You must tell us in writing about a claim as soon as you become aware of it, and in any case in time for us to investigate and limit the loss; we are released to the extent we are prejudiced by delay. Statutory limitation periods are not shortened by this clause.
12. Your indemnity
You will defend, indemnify and hold harmless the Company and each Protected Person against every claim, demand, proceeding, inquiry, penalty, loss, liability, cost and expense (including legal fees on a full-indemnity basis) arising out of or in connection with: (a) Customer Data, including any claim that you had no right or lawful basis to collect, hold, upload or send it, or that it infringes a right; (b) your breach of these Terms or any law; (c) your failure to meet your own obligations as a Data Fiduciary or otherwise under DPDP law, the SPDI Rules or any other law; (d) any claim by a person whose data you hold, a regulator, a client, an employee, a customer, a vendor or any other person relating to your compliance or non-compliance; (e) your use of an AI assistant with the Service; and (f) acts of anyone using your account, links or tokens. We will tell you of a claim promptly, let you defend it with counsel reasonably acceptable to us (we may take over at your cost if you do not), and you will not settle it in a way that admits fault for, or imposes duties on, us without our written consent.
13. Term, suspension and ending
- These Terms start when you accept them and continue until ended. You may stop using the Service and close your account at any time by writing to dpdp@veridian-aios.com.
- We may suspend or end your access (in whole or part) at once if you breach these Terms or the law, if your use threatens the Service, other customers or any person, if fees are overdue as in clause 7.2, if we are required to by law or authority, or on 30 days' notice for any reason. Free accounts may be ended at any time.
- On ending, your right to use the Service stops; clause 6.3(g) applies to Customer Data; and clauses that by nature should continue (including 2, 6, 8, 10, 11, 12, 14 and 15) continue. Ending does not affect accrued rights or fees.
14. Governing law and disputes
- Law. These Terms and any dispute connected with them are governed by the laws of India.
- Talk first. Write to the other party describing the dispute. Senior representatives will try in good faith to settle it within 30 days of that notice.
- Arbitration. A dispute not settled in that time will be finally decided by arbitration under the Arbitration and Conciliation Act, 1996 by a sole arbitrator appointed by agreement of the parties or, if they do not agree within 15 days of a written request, appointed on the application of either party by the court of competent jurisdiction under that Act. The seat and venue are Ghaziabad, Uttar Pradesh; the language is English. The award is final and binding. Each party bears its own costs unless the arbitrator directs otherwise. The arbitrator must apply these Terms as written, including clause 11.
- Courts. Subject to clause 14.3, the courts at Ghaziabad, Uttar Pradesh have exclusive jurisdiction over any matter the courts may decide, including support of the arbitration. Either party may seek urgent interim relief from a competent court. We may go to a court of competent jurisdiction to protect our intellectual property or the security of the Service.
- Not affected. Nothing here limits any right a person whose personal data you hold has against you, or any right to complain to the Data Protection Board of India or another authority.
15. General
- Changes. We may change these Terms. For a change that materially reduces your rights we will give at least 30 days' notice by email to your account contact or in the Service; for other changes the new version applies when posted. If you do not accept a change, stop using the Service before it takes effect; using it afterwards is acceptance.
- Entire agreement. These Terms, the Disclaimer and any signed agreement are the whole agreement and replace earlier discussions, proposals and demonstrations. You have not relied on any statement not set out in them; nothing limits liability for fraud.
- No relationship. No partnership, joint venture, agency, employment, fiduciary or professional-client relationship arises between you and the Company.
- Assignment. You may not assign or transfer your rights without our written consent. We may assign these Terms, including on a merger, restructuring or sale of the business.
- Severability and waiver. An invalid or unenforceable provision is cut back to the minimum needed to make it enforceable, or severed, and the rest continues. Delay in enforcing a right is not a waiver.
- Force majeure. Neither party is liable for delay or failure caused by events beyond its reasonable control, including natural disaster, epidemic, war, terror, strikes, government action, failure of power, network, cloud or third-party services, and cyber-attack. Payment duties are not excused.
- Third parties. Only you, the Company and the Protected Persons may enforce these Terms.
- Notices. Notices to us: in writing to the registered office above, with a copy by email to dpdp@veridian-aios.com. Notices to you: by email to your account contact or in the Service. Email notices are received on the next business day.
- Interpretation. Headings are for convenience. "Including" is without limitation. These Terms are not read against the Company because it wrote them. The English text prevails over any translation.
16. Questions, complaints and notices
Write to dpdp@veridian-aios.com and put the topic in the subject: Grievance, Data request, Sales, Partner or Security. The Grievance Officer of the Company answers grievances sent to that address.
SHOBHA KAMAL SOLUTIONS PRIVATE LIMITED · CIN U74999UP2017PTC098453 · B-1105, Plot No. 14, Shipra Krishna Vista, Ahinsa Khand-1, Indirapuram, Ghaziabad, Uttar Pradesh 201014, India.