
Data Protection, Security & Compliance Policy
Where your data lives, who can reach it, how it is protected, which laws we meet, and what we will show you to prove it.
- Platform
- Truce.ai — Accord Lifecycle Intelligence (ALI)
- Issued by
- Virtuos Digital Limited — Futuristry Division
- Business unit
- Futuristry, a Strategic Business Unit (SBU) of Virtuos, formed under the Virtuos Transformation Economy initiative
- Applies to
- The Truce platform, its infrastructure, our personnel, our sub-processors and our development and support processes
- Audience
- Customers, prospective customers, procurement and security assessors, auditors, regulators
- Version
- 1.0
- Effective date
- 7 September 2026
- Review cycle
- Annually, and on material change to architecture, hosting or law
Purpose and scope
About Truce.ai and ALI
Our data principles
Governance and accountability
| Role | Accountability |
|---|---|
| Executive sponsor | Ultimate accountability for the security and privacy posture of Truce.ai; approval of this policy and of risk acceptance above defined thresholds. |
| Data Protection Officer | Independent oversight of privacy compliance, advice on impact assessments, liaison with supervisory authorities, and the point of contact for data subjects. Reachable at dpo@truce.ai. |
| Grievance Officer (India) | Receipt and resolution of grievances under the DPDP Act, 2023. Reachable at grievance@truce.ai. |
| Head of Security | The security programme, controls, monitoring, testing, incident response and vendor security assessment. |
| Head of Engineering | Secure design and development, change control, and remediation of identified weaknesses. |
| AI governance lead | Model selection, evaluation, safety, oversight design, and compliance with emerging AI regulation. |
| Security and privacy committee | Cross-functional forum reviewing risk, incidents, audit findings, sub-processor changes and policy exceptions on a defined cadence. |
| Every employee and contractor | Compliance with this policy, completion of training, and prompt reporting of suspected incidents. |
Data classification
| Class | Examples | Handling |
|---|---|---|
| Restricted | Customer accords and attachments, special category data intrinsic to an accord, credentials, encryption keys, security findings | Encrypted at rest and in transit; access on approved need only, time-bound and logged; never in non-production; never in unmanaged tools |
| Confidential | Customer metadata, user directories, support tickets, commercial terms, architecture documentation | Encrypted; role-based access; internal distribution controlled |
| Internal | Operational runbooks, aggregated telemetry, internal plans | Access limited to personnel; not published |
| Public | This policy, published documentation, marketing material | No restriction; accuracy reviewed before publication |
Hosting on AWS, Azure and Google Cloud
Data residency by region
| Region | Hosting | Principal legal framework |
|---|---|---|
| India | Indian regions of AWS, Azure or Google Cloud; MeitY-empanelled cloud arrangements where a tender requires it | Digital Personal Data Protection Act, 2023; Information Technology Act, 2000 and rules; CERT-In directions; sectoral regulator requirements |
| European Union | EU regions | EU GDPR; member state law; EU AI Act as it applies |
| United Kingdom | UK regions | UK GDPR; Data Protection Act 2018 |
| United States | US regions | State comprehensive privacy laws; sectoral law as applicable |
| United Arab Emirates | UAE regions | Federal data protection law; DIFC and ADGM regimes where applicable |
| Saudi Arabia | KSA regions | Personal Data Protection Law; national cloud computing regulatory framework |
| Singapore and ASEAN | Singapore region | Personal Data Protection Act and local equivalents |
| Australia | Australian regions | Privacy Act and Australian Privacy Principles |
| Canada | Canadian regions | PIPEDA and provincial law |
Cross-border transfers
Deployment models
| Model | Description | Typical fit |
|---|---|---|
| Multi-tenant SaaS | Shared infrastructure with logical isolation enforced at application, data and key layers, in the customer's chosen region | Most commercial customers |
| Dedicated tenant | Dedicated database and storage, isolated compute, customer-managed keys, within our cloud account | Regulated industries; large enterprises |
| Single-tenant isolated | Separate cloud account and network with no shared data plane | PSUs; financial services; defence-adjacent supply |
| Customer-subscription deployment | Deployed inside the customer's own AWS, Azure or Google Cloud subscription, under the customer's own account controls | Government departments; organisations with cloud mandates |
| Sovereign or empanelled cloud | Deployment on a government community cloud or an empanelled provider as a tender requires | Central and state government; PSUs |
| Private cloud or on-premises | Deployment in the customer's own data centre where a mandate requires it | Classified or air-gapped environments, by agreement |
Encryption and key management
Identity and access management
Tenant isolation
Secure engineering
AI and model governance
No training on Customer Data
Where inference runs
Minimisation and protection before inference
Model selection and evaluation
Prompt and injection defence
Human oversight
Traceability
AI regulation
Logging and monitoring
Vulnerability and patch management
| Severity | Target remediation |
|---|---|
| Critical | Within 24 hours, or immediate mitigation where a fix takes longer |
| High | Within 7 days |
| Medium | Within 30 days |
| Low | Within 90 days, or accepted with documented rationale |
Incident response and notification
| Obligation | Timeline |
|---|---|
| Notification to an affected customer of a personal data breach | Without undue delay, and in any event within 48 hours of becoming aware |
| Reporting a qualifying cyber incident to CERT-In, where those directions apply | Within 6 hours of becoming aware |
| Notification to a supervisory authority where we act as controller | Within 72 hours where the law requires it |
| Notification to affected individuals where we act as controller | Without undue delay where the breach is likely to result in high risk |
| Notification under the DPDP Act, 2023 | To the Data Protection Board and affected data principals as the Act and its rules prescribe |
| Post-incident report to affected customers | Within 10 business days of resolution |
Continuity, backup and recovery
Sub-processors and vendor risk
People and physical security
Certifications and frameworks
Designing to a framework and holding a current certification are different things. Certification and attestation depend on independent auditors on their own timelines. Where your procurement, tender qualification or regulatory position depends on a specific certification, ask us to confirm its current status in writing at security@truce.ai before you rely on it. Any certification described as planned or in progress is a forward-looking statement governed by the Safe Harbour Policy, and must not be treated as held.
Regulatory compliance map
| Regime | How we meet it |
|---|---|
| Digital Personal Data Protection Act, 2023 (India) | Processing as Data Processor on the Data Fiduciary's instruction; security safeguards; breach reporting; Grievance Officer; support for data principal rights including nomination; children's data controls where a customer's use case requires them |
| Information Technology Act, 2000 and rules (India) | Reasonable security practices and procedures; safeguards for sensitive personal data; contractual and technical controls |
| CERT-In directions (India) | Incident reporting within 6 hours; log retention within India for the prescribed period; time synchronisation to the prescribed source; designated point of contact |
| EU GDPR | Article 28 processor terms; records of processing; security of processing under Article 32; breach notification; transfer safeguards; support for data subject rights and impact assessments |
| UK GDPR and Data Protection Act 2018 | Equivalent controls; UK International Data Transfer Addendum for transfers |
| EU AI Act | Provider obligations for the platform; technical documentation, logging, accuracy information and human oversight capability supplied to customers as deployers |
| US state privacy laws | Service provider or processor terms; no sale or sharing of personal information; support for consumer rights and opt-out signals |
| Sectoral regulators | Where a customer is regulated by a financial, insurance, telecom or health authority, we support the outsourcing, audit, incident reporting and localisation requirements that regulator imposes, as recorded in the contract |
| Electronic signature law | Support for signature workflows and evidence consistent with the Information Technology Act, 2000, eIDAS and comparable regimes, through certified providers where the customer enables them |
| Public records and archival law | Retention configuration aligned to the customer's statutory record-keeping obligations |
Government and PSU compliance
Audit and assurance rights
Data subject requests
Retention, return and deletion
Policy governance and review
Contact
Truce.ai — Accord Lifecycle Intelligence. A trademark of Virtuos Digital Limited, operated through the Futuristry Division, a Strategic Business Unit at Virtuos formed under the Transformation Economy initiative. Data Protection, Security & Compliance Policy version 1.0, effective 7 September 2026. Read with the Truce.ai Privacy Policy, Terms & Conditions, and Safe Harbour Policy.