
Privacy Policy
How we collect, use, host, protect and delete personal data across the Truce.ai platform, our websites and our professional services — and the rights you hold over that data.
- Platform
- Truce.ai — Accord Lifecycle Intelligence (ALI)
- Issued by
- Virtuos Digital Limited — Futuristry Division
- Business unit
- Futuristry, a Strategic Business Unit (SBU) of Virtuos, formed under the Virtuos Transformation Economy initiative
- Applies to
- www.truce.ai, the Truce platform, connected apps and mobile clients, trials, sandboxes and related services
- Version
- 1.0
- Effective date
- 7 September 2026
- Review cycle
- Annually, or on material change to law, hosting or processing
Scope and application
Who we are
Truce, Truce.ai and the .ai domain
Definitions
| Term | Meaning |
|---|---|
| Personal data | Any information relating to an identified or identifiable natural person. Equivalent to "personal information" and to "personal data" as defined in the Digital Personal Data Protection Act, 2023 (India), the UK and EU GDPR, and comparable laws. |
| Special category data | Personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Includes data on criminal offences where local law treats it as sensitive. |
| Customer | The organisation — company, government department, ministry, statutory body, Public Sector Undertaking or agency — that contracts with us for the platform. |
| Authorised user | An individual permitted by a Customer to access the platform under that Customer's subscription. |
| Customer Data | All data a Customer or its authorised users submit to, generate in, or transmit through the platform, including accords, drafts, attachments, obligations, metadata, comments and audit records. |
| Counterparty | The other party to an accord governed in the platform, and the individuals acting for it. |
| Controller | The party that determines the purposes and means of processing. Called "Data Fiduciary" under India's DPDP Act, 2023. |
| Processor | The party that processes personal data on behalf of a controller. Called "Data Processor" under the DPDP Act, 2023. |
| Data principal / data subject | The individual to whom personal data relates. |
| Sub-processor | A third party engaged by us to process personal data on a Customer's behalf. |
| Model provider | A provider of frontier or foundation models used to deliver platform intelligence, engaged as a sub-processor under contractual terms that forbid training on Customer Data. |
| Inference | A single act of sending text or structured input to a model and receiving output. |
| Derived insight | Structured output produced by the platform from Customer Data — extracted obligations, risk scores, clause classifications, summaries, comparisons. |
| Service data | Operational data we generate about use of the platform — logs, telemetry, error traces, usage counts, performance metrics. |
Our role: controller and processor
Where we act as processor
Where we act as controller
Personal data we process
Website visitors and prospects
Authorised users of the platform
Data inside accords
Truce is not designed as a repository for special category data, government-issued identity numbers or payment card data, and we ask Customers not to place such data in the platform except where it is intrinsic to the accord and permitted by their own lawful basis and by their contract with us. Where sensitive data is intrinsic, we support redaction, field-level encryption and restricted-visibility controls; Customers should engage those controls and record them in their own processing register.
Negotiation and collaboration records
Support, training and services
Billing and commercial records
Service data and security telemetry
Job applicants
Where the data comes from
Purposes and lawful bases
| Purpose | Data used | Lawful basis (GDPR) |
|---|---|---|
| Providing the platform and its intelligence features | Customer Data, user account data | Performance of a contract; for individuals inside accords, the Customer's own basis, with us processing on instruction |
| Authenticating users and protecting accounts | Identity, authentication and session data | Contract; legitimate interests in securing the service |
| Support, incident diagnosis and service maintenance | Ticket content, logs, diagnostic exports | Contract; legitimate interests |
| Security monitoring, fraud and abuse prevention | Telemetry, access logs, security signals | Legitimate interests; legal obligation |
| Service improvement using aggregated, de-identified data | Aggregated service data only | Legitimate interests |
| Billing, collections, tax and statutory records | Billing and finance data | Contract; legal obligation |
| Marketing to business contacts | Business contact details, engagement data | Consent where required; otherwise legitimate interests, with opt-out always available |
| Events, webinars and training | Registration and attendance data | Consent; contract |
| Recruitment | Applicant data | Steps prior to entering a contract; legitimate interests; consent where required |
| Responding to lawful requests from authorities | As required by the request | Legal obligation |
| Establishing, exercising or defending legal claims | As relevant to the claim | Legitimate interests; legal obligation |
| Corporate transactions such as merger or reorganisation | Relevant records | Legitimate interests |
Artificial intelligence and your data
We do not train on Customer Data
How inference works
Where inference runs
Minimisation before inference
Derived insight
Human review
Ordered or bespoke models
Accuracy and human oversight
Aggregated and de-identified data
Counterparty and third-party data
Hosting, residency and transfers
Data residency
| Customer location | Typical hosting region | Principal framework |
|---|---|---|
| India, including central and state government and PSUs | Indian regions of AWS, Azure or Google Cloud, or a MeitY-empanelled cloud arrangement where the tender requires it | Digital Personal Data Protection Act 2023; Information Technology Act 2000 and rules made under it; CERT-In directions; sectoral regulator requirements |
| European Union | EU regions | EU GDPR |
| United Kingdom | UK regions | UK GDPR; Data Protection Act 2018 |
| United States | US regions | State privacy laws; sectoral law as applicable |
| Middle East | UAE or Saudi regions | UAE and KSA data protection law; national cloud policy |
| Asia Pacific | Singapore, Australia or other in-region options | PDPA; Australian Privacy Principles; local law |
Cross-border transfers
Government and public sector customers
How we secure personal data
Retention and deletion
| Data | Retention |
|---|---|
| Customer Data in an active tenant | For the subscription term, and thereafter under the Customer's own retention configuration. The Customer controls retention within the platform. |
| Customer Data after termination | Available for export for 30 days after termination unless a longer period is agreed. Deleted from production within 30 days of the export window closing, and from backups within a further 90 days as backup cycles expire. |
| User account records | For the life of the account, then 12 months, then deleted or anonymised. |
| Security and audit logs | Typically 12 months; longer where a contract, regulator or investigation requires it. |
| Support tickets | 36 months from closure. |
| Billing, tax and statutory records | As required by applicable tax and companies law, commonly 7 to 8 years. |
| Marketing contacts | Until you opt out, or after 24 months without engagement, whichever comes first. |
| Job applicant records | 12 months after the decision, unless you consent to a longer talent-pool retention. |
| Public sector records | Per the contracting authority's record retention schedule and applicable public records law, which may extend well beyond the periods above. |
Your rights
Making a request to us
Regional disclosures
India
European Economic Area and United Kingdom
United States
Other jurisdictions
Children's data
Automated decision-making
Breach notification
Third-party sites and marketplaces
Changes to this policy
Contact, DPO and grievance officer
Truce.ai — Accord Lifecycle Intelligence. A trademark of Virtuos Digital Limited, operated through the Futuristry Division, a Strategic Business Unit at Virtuos formed under the Transformation Economy initiative. Privacy Policy version 1.0, effective 7 September 2026. Read with the Truce.ai Terms & Conditions, Safe Harbour Policy, and Data Protection, Security & Compliance Policy.