Data Privacy Policy

Metawing Technologies Pvt Ltd (d.b.a Verismart)

Privacy Promise & Data Protection

This Privacy Policy governs the processing and transfer of Personal Data that we, Metawing Technologies Pvt Ltd. (d.b.a “Verismart”) collect.

The Platform helps your company (“Customer”) manage privacy requests. This Privacy Policy is part of our Service Agreement and applies to the processing of Personal Data related to you, an employee of a Customer who provided you with access to the Platform.

Questions or concerns? Contact us at hello@verismart.ai

Definitions

Personal Data

Information that identifies or can identify an individual, such as first and last name, email address, profile picture, unique online identifiers, etc.

Non-Personal Data

Information, usually in aggregated form, that cannot be linked to a single identifiable individual, taking into account all means reasonably likely to be used by Verismart or any other person to identify that individual, directly or indirectly.

Personal Data Collected and Processed

Account & Communication Data

Full name, business email address, and any other Personal Data you upload or provide during sign-in and use of the Platform (including text communications).

Purpose: Perform our contractual duties, maintain contact with you as a Customer representative, and provide customer service & support.

Analytics & Technical Data

IP address, browser type, operating system, device type, preferred language, path taken on the Platform, content interacted with, session time & date, referring URLs, and general geolocation (city level).

Purpose: Operate and improve the Platform.

Cookies & Online Identifiers

Online identifiers included in cookies and other tracking technologies.

Purpose: Support legitimate business interests — operate, protect and improve the Platform, auditing, usage statistics and traffic flow.

Additional Legitimate Purposes

  • Protect the Platform from illegal, fraudulent, abusive or malicious activity
  • Handle inquiries, complaints, disputes and protect legal rights
  • Comply with legal, tax and auditing requirements
  • Respond to court orders, warrants or law enforcement requests

Non-Personal Data

We collect non-personal data about Platform usage such as scope of use, frequency, latency, pages viewed, interactions, and technical device information (including via Google Analytics).

Used for clickstream analysis, Platform maintenance & development, engagement measurement, business analytics, network functioning, fraud prevention, cyber-threat protection, and developing new features.

Third Parties

We will never sell Personal Data related to you to anyone.

We share Personal Data with third parties only in connection with providing and improving the Services (marketing, data management, analytics, support, maintenance).

Additional sharing occurs only when necessary to comply with law, protect vital interests, secure our systems, enforce agreements, or in the event of a corporate transaction (sale, merger, etc.).

Non-Personal, aggregated, statistical and anonymized data may be shared for lawful business purposes without limitation.

Your Rights & Control

Access

Review Personal Data related to you by contacting us.

Delete / Restrict

Request deletion or restriction of processing (subject to our obligations to Customers).

Unsubscribe

Opt out of newsletters and marketing materials at any time.

Complaint

File a complaint with the applicable data protection authority (including EEA supervisory authorities under GDPR).

When exercising rights we may request identity verification. We aim to respond as soon as possible and within legal timelines.

Data Retention

Personal Data is retained for as long as the Customer uses the Platform. Upon account termination we delete Personal Data from active databases within 30 days and from backups within 60 days.

Longer retention may occur for legal, tax, accounting or litigation purposes. Non-Personal / anonymized data is retained without time limitation.

Security of Data

We implement physical, technical and administrative security measures designed to prevent unauthorized access, improper use or disclosure, unlawful destruction or accidental loss.

While we take maximum efforts, transmission of information over the internet cannot be guaranteed 100% secure. In the event of a data incident involving your Personal Data we will contain it, minimize risk, and notify you if required by law.

Your EU / GDPR Rights

When GDPR applies, Verismart acts as a data controller for Personal Data processed under this Policy (and as processor when processing on behalf of Customers).

  • • Right to withdraw consent at any time
  • • Right to rectification of inaccurate data
  • • Right to data portability
  • • Right not to be subject to solely automated decision-making (including profiling) that produces legal or similarly significant effects

Lawful bases include performance of contract, legitimate interests (cyber-security, support, improvements, fraud detection), legal obligation, vital interests, and consent.

International Transfers

Personal Data is primarily kept on servers in the European Union. Some service providers (e.g. customer support) may process data in other countries including the United States.

For EEA users we rely on adequacy decisions (including Israel) and Standard Contractual Clauses or equivalent safeguards for transfers to non-adequate jurisdictions. A copy of the safeguards can be requested at hello@verismart.ai.

Changes to this Policy

We may update this Privacy Policy from time to time. Substantial modifications will be posted on the Platform and notified via email. Substantial changes take effect 30 days after posting; other changes within 7 days (or sooner if required by law).

Contact Us

Metawing Technologies Pvt Ltd.

2nd Floor, Eros City Square, Rosewood City Road,

Sector 49, Gurugram, Haryana – 122018

+91 – 9311702428

+91 – 8368768864

hello@verismart.ai