Truce.ai — Accord Lifecycle Intelligence

Privacy Policy

How we collect, use, host, protect and delete personal data across the Truce.ai platform, our websites and our professional services — and the rights you hold over that data.

Version: 1.0Effective date: 7 September 2026
Document control
Platform
Truce.ai — Accord Lifecycle Intelligence (ALI)
Issued by
Virtuos Digital Limited — Futuristry Division
Business unit
Futuristry, a Strategic Business Unit (SBU) of Virtuos, formed under the Virtuos Transformation Economy initiative
Applies to
www.truce.ai, the Truce platform, connected apps and mobile clients, trials, sandboxes and related services
Version
1.0
Effective date
7 September 2026
Review cycle
Annually, or on material change to law, hosting or processing
Clause 1

Scope and application

1.1
This Privacy Policy explains how Truce.ai handles personal data. It applies to the website at www.truce.ai, to the Truce platform and every module, agent, connector, API and mobile or desktop client we make available under it, to trials, sandboxes, proofs of concept and pilots, to onboarding, support, training and professional services, and to our marketing, events and recruitment activity.
1.2
Throughout our website and documentation the names Truce and Truce.ai are used interchangeably. Both refer to the same product and the same legal entity behind it. Where this policy says "Truce", "we", "us" or "our", it means Truce.ai as operated by Virtuos Digital Limited — Futuristry Division.
1.3
This policy does not replace any signed agreement. Where you are a customer under a Master Services Agreement, Order Form, Data Processing Agreement or a government contract, the terms of that agreement govern the processing of the data you place in the platform, and this policy describes our general practices around it.
1.4
Read this policy alongside our Terms & Conditions, our Safe Harbour Policy and our Data Protection, Security & Compliance Policy. Where a Data Processing Agreement executed with a customer conflicts with this policy on the treatment of that customer's data, the Data Processing Agreement prevails.
Clause 2

Who we are

2.1
Truce.ai is a trademark of Virtuos Digital Limited, operated through its Futuristry Division. Futuristry is a Strategic Business Unit (SBU) at Virtuos, established as part of the Virtuos Transformation Economy initiative — a programme dedicated to building AI-native products and delivery models rather than retrofitting intelligence onto legacy software.
2.2
Truce is an Accord Lifecycle Intelligence (ALI) platform. ALI governs the full life of an accord — the intent behind it, its negotiation, its execution, the obligations it creates, the performance of those obligations, its renewal, variation and closure — and applies machine intelligence at each of those stages. ALI is not Contract Lifecycle Management. The two overlap in obvious places such as authoring, approval routing, repositories and e-signature, but ALI treats an accord as a living, reasoning-capable object rather than a document to be stored and searched. That difference is why our data practices are described in terms of reasoning, inference, model access and derived insight, and not simply document storage.
2.3
Depending on your relationship with us and the contract you hold, the Virtuos Digital Limited entity, or an affiliate of it identified in your Order Form, acts as the controller or processor of your personal data. Entity and registered-office details, including the address for formal notices, appear at clause 25.
Clause 3

Truce, Truce.ai and the .ai domain

3.1
We chose the .ai extension deliberately, and it carries meaning for privacy. Accord Lifecycle Intelligence is built on frontier models. Truce is an AI-first, AI-born platform: intelligence is not a feature bolted to a records system, it is the substrate the product is constructed on. Language understanding, obligation extraction, risk detection, clause reasoning, negotiation assistance, comparison and summarisation are core runtime behaviour, not optional add-ons.
3.2
Because of that, a privacy policy for Truce has to say more than a conventional software policy. It must explain what happens when your text is put in front of a model, where that inference runs, whether it leaves a jurisdiction, whether it is retained, and whether it can influence a model's future behaviour. Sections 9, 13 and 21 address those questions directly.
3.3
The names Truce and Truce.ai are used interchangeably across our website, contracts, documentation and support channels, and refer to the same offering.
Clause 4

Definitions

4.1
The following terms carry the meanings given below wherever they appear in this policy.
TermMeaning
Personal dataAny information relating to an identified or identifiable natural person. Equivalent to "personal information" and to "personal data" as defined in the Digital Personal Data Protection Act, 2023 (India), the UK and EU GDPR, and comparable laws.
Special category dataPersonal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, health data, or data concerning sex life or sexual orientation. Includes data on criminal offences where local law treats it as sensitive.
CustomerThe organisation — company, government department, ministry, statutory body, Public Sector Undertaking or agency — that contracts with us for the platform.
Authorised userAn individual permitted by a Customer to access the platform under that Customer's subscription.
Customer DataAll data a Customer or its authorised users submit to, generate in, or transmit through the platform, including accords, drafts, attachments, obligations, metadata, comments and audit records.
CounterpartyThe other party to an accord governed in the platform, and the individuals acting for it.
ControllerThe party that determines the purposes and means of processing. Called "Data Fiduciary" under India's DPDP Act, 2023.
ProcessorThe party that processes personal data on behalf of a controller. Called "Data Processor" under the DPDP Act, 2023.
Data principal / data subjectThe individual to whom personal data relates.
Sub-processorA third party engaged by us to process personal data on a Customer's behalf.
Model providerA provider of frontier or foundation models used to deliver platform intelligence, engaged as a sub-processor under contractual terms that forbid training on Customer Data.
InferenceA single act of sending text or structured input to a model and receiving output.
Derived insightStructured output produced by the platform from Customer Data — extracted obligations, risk scores, clause classifications, summaries, comparisons.
Service dataOperational data we generate about use of the platform — logs, telemetry, error traces, usage counts, performance metrics.
Clause 5

Our role: controller and processor

5.1
Our role changes with the data, and the distinction determines who you approach with a request.

Where we act as processor

5.2
For all Customer Data placed in the platform, we act as a processor on the Customer's documented instructions. The Customer is the controller — or, in Indian terms, the Data Fiduciary. We do not decide what accords a Customer loads, whose personal data appears inside them, how long the Customer wishes to keep them, or what the Customer does with derived insight. We process only to deliver, secure, support and maintain the service, and as the Customer's written instructions require.
5.3
If you are an individual whose personal data appears inside a Customer's accords — an employee, supplier contact, citizen, applicant, vendor representative or counterparty signatory — direct your rights request to that organisation. We will assist them in responding, and if you contact us first we will pass your request to them and tell you we have done so, unless law prevents us.

Where we act as controller

5.4
We act as controller for: visitors to www.truce.ai; prospects and their business contact details; the account and identity records of authorised users, to the extent needed to run the service securely; billing and finance contacts; support and ticket correspondence; event and webinar registrations; job applicants; service data and security telemetry; and our own vendor and partner records.
5.5
Where we are joint controllers with a Customer — an arrangement we enter into rarely and only in writing — the allocation of responsibility is set out in the relevant agreement and made available to the individuals concerned on request.
Clause 6

Personal data we process

6.1
The categories below describe the data we handle. Not every category applies to every person; what applies depends on how you interact with us.

Website visitors and prospects

6.2
Name, business email, telephone number, employer, job title, country, and the content of any enquiry or demo request. Technical data including IP address, approximate location derived from it, browser and device type, operating system, referring URL, pages viewed, session duration and interaction events. Marketing preferences, consent records and communication history.

Authorised users of the platform

6.3
Name, business email, username, organisational unit, role and permission set, manager or approver relationships, authentication identifiers including SSO subject identifiers, multi-factor enrolment status, language and time-zone preferences, notification settings, profile image where uploaded, and last-login and session records.

Data inside accords

6.4
Truce processes whatever a Customer places in it. Accords routinely contain the names, titles, signatures, contact details, employment details and bank or payment identifiers of individuals acting for the parties. Public sector accords may additionally contain officer designations, file and tender reference numbers, sanction and approval trails and departmental identifiers. Some accords contain special category data — for example, health information in an insurance or welfare arrangement, or biometric or identity numbers in a citizen-facing service.
A note on sensitive data in accords

Truce is not designed as a repository for special category data, government-issued identity numbers or payment card data, and we ask Customers not to place such data in the platform except where it is intrinsic to the accord and permitted by their own lawful basis and by their contract with us. Where sensitive data is intrinsic, we support redaction, field-level encryption and restricted-visibility controls; Customers should engage those controls and record them in their own processing register.

Negotiation and collaboration records

6.5
Comments, redlines, version history, approval and rejection decisions with the identity of the decision maker and a timestamp, delegation records, chat or thread messages inside the platform, and e-signature evidence including signer identity, IP address, timestamp and audit certificate.

Support, training and services

6.6
Ticket contents, correspondence, screenshots and attachments you send us, call and meeting notes, and — where you are told in advance and where local law permits — recordings of support or training sessions. Diagnostic exports you choose to share with us.

Billing and commercial records

6.7
Billing contact name and address, purchase order and tender references, GSTIN, VAT or equivalent tax identifiers, invoices, payment status and correspondence. We do not store full payment card numbers; card payments, where offered, are handled by a PCI DSS compliant payment processor.

Service data and security telemetry

6.8
Application and infrastructure logs, API call records, error traces, feature usage counts, performance timings, authentication events, administrative actions, and security signals such as failed logins, anomalous access patterns and integrity alerts.

Job applicants

6.9
CV, employment and education history, references, right-to-work evidence, interview notes and assessment results, and any background verification we are required or permitted to conduct.
Clause 7

Where the data comes from

7.1
Directly from you, when you complete a form, request a demonstration, register for an event, raise a ticket, sign a contract, apply for a role or use the platform.
7.2
From your organisation, when it provisions you as an authorised user, synchronises identity from its directory, or loads accords that name you.
7.3
Automatically, through cookies, tags, server logs and platform telemetry generated as you use our website and product.
7.4
From counterparties, when a party on the other side of an accord submits information into a shared workspace, portal or signature flow.
7.5
From integrations a Customer connects — identity providers, ERP, CRM, procurement, e-signature, government e-procurement portals, storage and communication tools — which pass data into Truce under the Customer's configuration and authorisation.
7.6
From public and licensed sources for business development, such as company registries, official gazettes, tender and procurement notices, professional networking platforms and reputable business data providers, limited to business contact information.
Clause 8

Purposes and lawful bases

8.1
Where the EU or UK GDPR applies, we rely on the lawful bases in the table below. Where the Digital Personal Data Protection Act, 2023 applies, we rely on consent or on a legitimate use recognised by that Act, and the Customer as Data Fiduciary is responsible for obtaining and evidencing consent from data principals whose data it places in the platform.
PurposeData usedLawful basis (GDPR)
Providing the platform and its intelligence featuresCustomer Data, user account dataPerformance of a contract; for individuals inside accords, the Customer's own basis, with us processing on instruction
Authenticating users and protecting accountsIdentity, authentication and session dataContract; legitimate interests in securing the service
Support, incident diagnosis and service maintenanceTicket content, logs, diagnostic exportsContract; legitimate interests
Security monitoring, fraud and abuse preventionTelemetry, access logs, security signalsLegitimate interests; legal obligation
Service improvement using aggregated, de-identified dataAggregated service data onlyLegitimate interests
Billing, collections, tax and statutory recordsBilling and finance dataContract; legal obligation
Marketing to business contactsBusiness contact details, engagement dataConsent where required; otherwise legitimate interests, with opt-out always available
Events, webinars and trainingRegistration and attendance dataConsent; contract
RecruitmentApplicant dataSteps prior to entering a contract; legitimate interests; consent where required
Responding to lawful requests from authoritiesAs required by the requestLegal obligation
Establishing, exercising or defending legal claimsAs relevant to the claimLegitimate interests; legal obligation
Corporate transactions such as merger or reorganisationRelevant recordsLegitimate interests
8.2
Where we rely on legitimate interests, we carry out and record a balancing assessment weighing our interest against your rights and reasonable expectations. You may ask us for a summary of the assessment relevant to you, and you may object to that processing under clause 17.
8.3
Where we rely on consent — for example for certain marketing or for non-essential cookies — you may withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
Clause 9

Artificial intelligence and your data

9.1
Because Truce is an AI-first, AI-born ALI platform built on frontier models, this section states plainly what happens to your data when intelligence is applied to it.

We do not train on Customer Data

9.2
We do not use Customer Data to train, fine-tune, re-train or otherwise improve any foundation or frontier model, whether ours or a third party's. Our contracts with model providers prohibit the use of data we submit for their model training or improvement, and prohibit its retention beyond what is needed to return a response, subject to any short abuse-monitoring window contractually agreed and disclosed. Where a Customer expressly asks us in writing to build a model or configuration trained on its own data for its exclusive use, that is a separate, ordered engagement documented in a statement of work, and clause 9.7 applies.

How inference works

9.3
When a feature requires reasoning — extracting obligations, classifying clauses, drafting a redline, summarising a negotiation, answering a question about an accord — the platform assembles the relevant text and context and submits it to a model for inference. The model returns output; the platform stores that output as derived insight within the Customer's tenant. Inference is transient: input is not added to any training corpus, and is not retained by the model provider beyond the terms described above.

Where inference runs

9.4
Inference runs in the region the Customer has selected, wherever the chosen model is available in that region. We prefer models hosted inside the Customer's chosen cloud region — for example a model service running within the same AWS, Microsoft Azure or Google Cloud region as the tenant — so that content used for inference does not leave the residency boundary. Where a required capability is available only outside the region, we tell the Customer, we obtain a decision before enabling it, and we apply the transfer safeguards in clause 13.

Minimisation before inference

9.5
We send the least text needed for the task. The platform supports redaction and tokenisation of identified personal data and configurable exclusion of nominated fields, clauses or document classes from AI features. Customers operating in regulated or sovereign environments can disable individual AI features, or all of them, at tenant level.

Derived insight

9.6
Derived insight belongs to the Customer as part of its Customer Data and is stored within its tenant. It is not pooled across tenants. It is not used to improve outcomes for other Customers.

Human review

9.7
Our personnel do not read Customer Data as a matter of course. Access occurs only for a defined support or incident reason, is authorised, time-limited, logged and reviewable by the Customer, and is subject to confidentiality obligations. Where practicable we ask the Customer's permission first, and where a Customer has enabled a customer-controlled access approval workflow we obtain approval before each access.

Ordered or bespoke models

9.8
If a Customer specifically orders a bespoke model, fine-tune or private configuration trained on its own corpus, that model is built and hosted for that Customer alone, its weights and artefacts are used for no other Customer, and the arrangement is governed by a statement of work with its own data protection terms, retention schedule and deletion commitment. Nothing about such an engagement grants any other Customer a benefit from it.

Accuracy and human oversight

9.9
Model output can be wrong, incomplete or misleading. Truce is decision support, not a decision maker. Outputs are for review by a qualified person, and are not legal advice. Customers must keep meaningful human oversight over any outcome affecting a person's rights, entitlements, employment, benefits or legal position. See clause 21.

Aggregated and de-identified data

9.10
We may generate aggregated, statistical or de-identified information — for example, counts of features used, median processing times, error rates — to operate, secure, benchmark and improve the platform. This information is produced so that it cannot reasonably be used to identify a Customer, a counterparty or an individual, and we do not attempt to re-identify it or permit others to do so. It does not include the substance of any accord.
Clause 10

Counterparty and third-party data

10.1
Accords have at least two sides. When a Customer invites a counterparty into a shared workspace, negotiation room, portal or signature flow, we process the counterparty representatives' names, email addresses, roles, comments, redlines and signature evidence in order to run that exchange.
10.2
In that processing the Customer that initiated the accord remains the controller. It is responsible for having a lawful basis for inviting those individuals, for giving them the information their local law requires, and for handling their rights requests. We support the Customer in doing so.
10.3
If you are a counterparty representative and want to know how your data is being used, contact the organisation that invited you. If you cannot identify it, write to us at the address in clause 25 and we will route your request and confirm that we have.
10.4
We do not use counterparty contact details captured through a Customer's accords for our own marketing.
Clause 11

Cookies and website analytics

11.1
On www.truce.ai we use cookies and similar technologies in four categories.
CategoryWhat it doesBasis
Strictly necessarySession handling, authentication, load balancing, security and consent-state storage. The site does not work without these.Necessary — no consent required
PreferenceRemembers language, region and display choices.Consent
AnalyticsMeasures page views, journeys, referral sources and campaign performance in aggregate.Consent
MarketingMeasures advertising effectiveness and supports remarketing on third-party platforms.Consent
11.2
Non-essential cookies are set only after you consent through our cookie banner. You can change or withdraw your choices at any time through the cookie preferences control on the site, and you can block or delete cookies in your browser — though blocking strictly necessary cookies will break parts of the site.
11.3
Authenticated areas of the Truce platform use only cookies and local storage necessary to operate the application securely. We do not run advertising trackers inside the authenticated product.
11.4
We honour Global Privacy Control and similar opt-out preference signals where the law recognises them.
Clause 12

Disclosure and sub-processors

12.1
We do not sell personal data. We do not share personal data for cross-context behavioural advertising. We do not disclose Customer Data to third parties except as set out below or as a Customer instructs.

Sub-processors

12.2
We engage a controlled set of sub-processors to deliver the service. Each is assessed before engagement, bound by a written contract imposing data protection obligations no less protective than ours, restricted to the minimum data needed, and reviewed periodically. Categories are listed below; the current named list with entity, function, location and processing scope is maintained at www.truce.ai and is available to Customers on request.
CategoryFunction
Cloud infrastructureAmazon Web Services, Microsoft Azure and Google Cloud — compute, storage, database, networking and managed services in the Customer's chosen region
Model providersFrontier and foundation model services, preferentially consumed in-region through the Customer's cloud, under no-training terms
Identity and accessEnterprise identity, SSO and multi-factor services
Observability and securityLog aggregation, monitoring, alerting, vulnerability scanning, endpoint protection
CommunicationsTransactional email and notification delivery
Support toolingTicketing, knowledge base and, with notice, session assistance tools
Signature and verificationE-signature and identity verification providers, where a Customer enables them
Business operationsBilling, tax, CRM and marketing automation — used for our controller-side data, not Customer Data
12.3
Customers subscribed to sub-processor notifications receive advance notice of any addition or replacement, with a reasonable window to object on genuine data protection grounds. If a reasonable objection cannot be resolved, the Customer may terminate the affected service without penalty for the unused portion of its prepaid term.

Other disclosures

12.4
To our affiliates within Virtuos, where they perform support, delivery, security or administrative functions, under equivalent obligations.
12.5
To professional advisers — lawyers, auditors, insurers, accountants — under duties of confidentiality.
12.6
To a Customer's own nominated implementation partner, systems integrator or auditor, where the Customer instructs it in writing.
12.7
To public authorities, courts, regulators or law enforcement, where we are legally compelled. We assess every request for validity and scope, we push back on requests that are overbroad or unlawful, we require due process, and unless legally prohibited we notify the affected Customer before disclosing so that it can seek protective relief. We publish periodic transparency information about the volume and type of requests received.
12.8
In connection with a merger, acquisition, financing, reorganisation or sale of assets, subject to confidentiality and to this policy continuing to govern the data transferred.
Clause 13

Hosting, residency and transfers

13.1
Truce runs exclusively on tier-one public cloud infrastructure — Amazon Web Services, Microsoft Azure and Google Cloud. We operate no data centres of our own. This gives our Customers the physical security, resilience, regional coverage and independently audited control environment of the world's leading providers, with Truce responsible for everything above the infrastructure layer.

Data residency

13.2
We strictly observe local data residency requirements. Each Customer tenant is provisioned in a nominated region and its Customer Data — primary storage, backups, search indexes, derived insight and, wherever the capability is regionally available, model inference — remains within that region for the life of the subscription.
Customer locationTypical hosting regionPrincipal framework
India, including central and state government and PSUsIndian regions of AWS, Azure or Google Cloud, or a MeitY-empanelled cloud arrangement where the tender requires itDigital Personal Data Protection Act 2023; Information Technology Act 2000 and rules made under it; CERT-In directions; sectoral regulator requirements
European UnionEU regionsEU GDPR
United KingdomUK regionsUK GDPR; Data Protection Act 2018
United StatesUS regionsState privacy laws; sectoral law as applicable
Middle EastUAE or Saudi regionsUAE and KSA data protection law; national cloud policy
Asia PacificSingapore, Australia or other in-region optionsPDPA; Australian Privacy Principles; local law
13.3
Where a tender, statute or sectoral regulator demands a stricter arrangement — an in-country sovereign region, a government community cloud, a private-cloud or on-premises deployment, or an arrangement where a Customer holds its own encryption keys — we accommodate it by agreement, and record it in the Order Form.

Cross-border transfers

13.4
A limited set of functions may involve access from outside the hosting region, principally follow-the-sun engineering support and 24×7 security monitoring. Where that occurs we apply, as appropriate: adequacy decisions; the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum; a documented transfer impact assessment; and supplementary technical measures including encryption in transit and at rest, pseudonymisation, least-privilege time-bound access and full audit logging.
13.5
A Customer may require that no access occur from outside its region. Where a Customer selects region-locked support, we staff support from within the region and record the restriction contractually. This may affect support hours and response times, which we state before the option is taken.
13.6
Onward transfer by a sub-processor is permitted only on terms at least as protective as those we owe to the Customer, and only with the same safeguards.
13.7
Copies of the transfer mechanisms we rely on, and our transfer impact assessments in summary form, are available to Customers on written request.
Clause 14

Government and public sector customers

14.1
A substantial part of our work is with governments, ministries, statutory bodies, regulators, municipal corporations and Public Sector Undertakings. That work carries obligations beyond ordinary commercial practice, and we build to them.
14.2
Accords in the public sector are matters of public administration and often of public record. They may relate to procurement, concessions, grants, licences, public–private partnership, land, welfare delivery or defence-adjacent supply. They may carry classification, and they attract audit by constitutional and statutory auditors.
14.3
For such engagements we support, on agreement: hosting confined to a nominated in-country region or an empanelled or sovereign cloud; segregated or single-tenant deployment; deployment inside the customer's own cloud subscription or data centre; support delivered only by personnel located in-country; security clearance, police verification or background checks for named personnel, to the extent lawful; restricted administrative access with customer-approved break-glass procedures; extended and tamper-evident audit logging; and retention schedules aligned to public records law and departmental record-retention rules.
14.4
We cooperate with audit and inspection by the Comptroller and Auditor General, internal audit, vigilance functions, and any regulator with jurisdiction, on the terms recorded in the relevant contract or tender document.
14.5
Where a public authority is subject to right-to-information or freedom-of-information law, we assist it in locating and producing records held in the platform, and we do not assert confidentiality over the authority's own records to obstruct a lawful disclosure obligation.
14.6
We report security incidents to the customer and to national computer emergency response authorities, including CERT-In where applicable, within the timelines those authorities prescribe. See clause 22.
Clause 15

How we secure personal data

15.1
We apply organisational and technical measures appropriate to the risk. This section summarises them; our Data Protection, Security & Compliance Policy sets them out in full.
15.2
Encryption. Data is encrypted in transit using TLS 1.2 or above, and at rest using AES-256 or an equivalent standard. Key management uses the managed key service of the hosting cloud, with support for customer-managed keys and, where contracted, customer-held keys.
15.3
Access control. Least privilege, role-based access, mandatory multi-factor authentication for all administrative and privileged access, just-in-time elevation with approval, quarterly access reviews and immediate revocation on role change or exit.
15.4
Tenant isolation. Logical separation of every Customer's data with enforcement at the application, data and key layers, so that one Customer's data cannot be reached from another's session.
15.5
Secure engineering. Secure development lifecycle, peer review, static and dependency analysis, secrets scanning, segregated environments, change control, and the use of masked or synthetic data in non-production.
15.6
Testing and assurance. Continuous vulnerability scanning, periodic independent penetration testing, and remediation to defined severity-based timelines.
15.7
Monitoring. Centralised logging, security event monitoring, alerting on anomalous access and administrative action, and tamper-evident audit trails available to Customers.
15.8
Resilience. Encrypted backups, tested restoration, multi-availability-zone architecture, and documented recovery objectives stated in the applicable service description.
15.9
People. Background verification consistent with local law, confidentiality undertakings, mandatory security and privacy training at induction and annually, and disciplinary consequences for breach.
15.10
No system is perfectly secure. We do not promise that the measures above will prevent every incident; we promise that they are maintained, tested, reviewed and improved, and that we will act quickly and tell you when something goes wrong.
Clause 16

Retention and deletion

16.1
We keep personal data only as long as needed for the purpose it was collected for, or as long as law requires.
DataRetention
Customer Data in an active tenantFor the subscription term, and thereafter under the Customer's own retention configuration. The Customer controls retention within the platform.
Customer Data after terminationAvailable for export for 30 days after termination unless a longer period is agreed. Deleted from production within 30 days of the export window closing, and from backups within a further 90 days as backup cycles expire.
User account recordsFor the life of the account, then 12 months, then deleted or anonymised.
Security and audit logsTypically 12 months; longer where a contract, regulator or investigation requires it.
Support tickets36 months from closure.
Billing, tax and statutory recordsAs required by applicable tax and companies law, commonly 7 to 8 years.
Marketing contactsUntil you opt out, or after 24 months without engagement, whichever comes first.
Job applicant records12 months after the decision, unless you consent to a longer talent-pool retention.
Public sector recordsPer the contracting authority's record retention schedule and applicable public records law, which may extend well beyond the periods above.
16.2
Where deletion is not immediately possible — for example data held in an immutable backup or a write-once archive required by law — we isolate it, stop active processing, and delete it when the cycle expires. Records under a litigation hold or a regulatory preservation notice are retained until the hold lifts.
16.3
On written request at termination we provide a certificate of deletion.
Clause 17

Your rights

17.1
Subject to the law that applies to you, you have the following rights. Where we act as processor, exercise them with the Customer that controls the data; we will help that Customer respond.
17.2
Access. To be told whether we process your personal data and to receive a copy of it, with information about purposes, recipients, retention and sources.
17.3
Correction. To have inaccurate data corrected and incomplete data completed.
17.4
Erasure. To have data deleted where it is no longer needed, where consent is withdrawn and no other basis applies, where you successfully object, or where processing was unlawful.
17.5
Restriction. To have processing limited while a dispute over accuracy or lawfulness is resolved.
17.6
Portability. To receive data you gave us, in a structured, commonly used, machine-readable format, and to have it sent to another controller where technically feasible.
17.7
Objection. To object to processing based on legitimate interests, and to object to direct marketing at any time — an absolute right we act on without question.
17.8
Withdrawal of consent. To withdraw consent at any time, with no effect on processing already carried out.
17.9
Rights relating to automated decisions. Not to be subject to a decision producing legal or similarly significant effects based solely on automated processing, and to obtain human intervention, express your view and contest the decision. See clause 21.
17.10
Nomination. Under India's DPDP Act, 2023, to nominate an individual to exercise your rights in the event of death or incapacity.
17.11
Grievance redressal. Under the DPDP Act, 2023, to have a readily available means of grievance redressal, which we provide through the Grievance Officer at clause 25.
17.12
Complaint. To complain to a supervisory authority — the Data Protection Board of India, the Information Commissioner's Office in the UK, or your EU member state authority. We ask that you raise the matter with us first so we can put it right.
17.13
We do not discriminate against anyone for exercising a right. Your service, pricing and support are unaffected.
Clause 18

Making a request to us

18.1
Send requests to privacy@truce.ai, or to the Grievance Officer at clause 25. Tell us what you want, and enough about your relationship with us — customer, website visitor, applicant, counterparty — for us to find your records.
18.2
We verify identity before acting, proportionately to the sensitivity of the request. We will not ask for more information than we need, and any identity evidence you send is used only for verification and then deleted.
18.3
An authorised agent may act for you with written authority, which we will verify with you.
18.4
We respond within one month, or sooner where local law requires it. Complex or numerous requests may take up to two further months; if so we tell you within the first month and explain why. Requests are handled free of charge unless manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline, and we will tell you why.
18.5
If we cannot act — because we hold no data about you, because we are a processor and must refer you to the controller, or because an exemption applies — we explain the reason and how to challenge it.
Clause 19

Regional disclosures

India

19.1
We process personal data in accordance with the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000 and the rules made under it, and applicable CERT-In directions. Where we are a Data Processor for a Customer, that Customer is the Data Fiduciary and is responsible for notice and consent. Our Grievance Officer for India is identified at clause 25. Data principals may approach the Data Protection Board of India if a grievance is not resolved.

European Economic Area and United Kingdom

19.2
We comply with the EU GDPR and, for UK data, the UK GDPR and the Data Protection Act 2018. Where required we have appointed representatives under Article 27; their details are available on request at privacy@truce.ai. Transfers are made under the safeguards described at clause 13.

United States

19.3
For residents of states with comprehensive privacy laws, including California, Virginia, Colorado, Connecticut and Utah: we do not sell personal information and do not share it for cross-context behavioural advertising. You have rights of access, correction, deletion, portability, and to opt out of targeted advertising and profiling, exercisable through clause 18. We honour opt-out preference signals. Californian residents may also request information about categories of personal information disclosed for a business purpose in the preceding twelve months.

Other jurisdictions

19.4
Where you are located elsewhere, we apply this policy together with any additional rights your local law grants, and we will tell you if a specific local requirement changes how we handle your data.
Clause 20

Children's data

20.1
Truce is an enterprise and government platform intended for use by adults acting in a professional capacity. It is not directed at children and we do not knowingly collect personal data from children through our website or product.
20.2
Where India's DPDP Act, 2023 applies and a Customer's use case unavoidably involves the data of a child or of a person with a disability who has a lawful guardian — for example a welfare, scholarship or public entitlement accord — the Customer as Data Fiduciary is responsible for obtaining verifiable consent from the parent or lawful guardian, and must not permit tracking, behavioural monitoring or targeted advertising directed at children. We will support the Customer with technical controls for such processing.
20.3
If you believe a child's data has reached us in error, write to privacy@truce.ai and we will delete it promptly.
Clause 21

Automated decision-making

21.1
Truce does not make decisions about individuals that produce legal or similarly significant effects without human involvement. The platform produces recommendations, extractions, classifications, scores and drafts. A person decides.
21.2
Customers configure workflows, and a Customer could in principle build an approval chain with limited human review. Our contracts require Customers to keep meaningful human oversight where an outcome affects a person's rights, entitlements, employment, benefits, licences or legal position, and to give affected individuals a route to human review. A Customer that ignores this is acting outside its permitted use.
21.3
Where the EU AI Act or comparable legislation applies to a Customer's use case, we provide the technical documentation, logging, accuracy information and human-oversight capabilities a deployer reasonably needs to meet its obligations, and we tell the Customer where responsibility sits between us as provider and it as deployer.
21.4
We do not use AI to profile website visitors or to make eligibility, pricing or creditworthiness decisions about individuals.
Clause 22

Breach notification

22.1
We maintain a documented incident response process covering detection, triage, containment, eradication, recovery, notification and post-incident review, tested at least annually.
22.2
Where we act as processor, we notify the affected Customer without undue delay and in any event within 48 hours of becoming aware of a personal data breach affecting its data, and we give the Customer the information it needs to meet its own notification duties — the nature of the breach, the categories and approximate number of records and individuals affected, the likely consequences, the measures taken, and a point of contact.
22.3
Where we act as controller, we notify the competent supervisory authority within 72 hours where the law requires it, and we notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms.
22.4
Where CERT-In directions apply, we report qualifying cyber incidents to CERT-In within six hours of becoming aware of them, maintain logs within India for the prescribed period, and synchronise systems to the prescribed time source.
22.5
We do not delay notification to complete an investigation. We tell the Customer what we know, and we update as we learn more.
Clause 23

Third-party sites and marketplaces

23.1
Our website and product link to third-party resources, and Customers may connect Truce to third-party applications through our integrations and APIs. Those third parties operate under their own privacy policies, and we are not responsible for their practices.
23.2
When a Customer authorises an integration, data flows to the connected application on that Customer's instruction and under that application's terms. Review those terms before connecting. A Customer can revoke an integration at any time from the platform's administration console; revocation stops future flows but does not retrieve data already transferred.
23.3
Where Truce is listed on a cloud marketplace, the marketplace operator processes transaction and account data under its own policy.
Clause 24

Changes to this policy

24.1
We update this policy as our services, our infrastructure and the law change. The version number and effective date at the head of this document always show the current edition.
24.2
For material changes — a new category of processing, a new class of recipient, a change to residency arrangements, or a change that reduces your rights — we give at least 30 days' notice by email to account administrators and by a notice on www.truce.ai before the change takes effect.
24.3
Non-material changes, such as clarifications of wording or updates to contact details, take effect on publication.
24.4
Previous versions are retained and provided to Customers on request. Continued use of the platform after a change takes effect indicates acceptance of the revised policy; where consent is required for a change, we ask for it separately.
Clause 25

Contact, DPO and grievance officer

25.1
Write to us. We would rather resolve a concern directly than have you go to a regulator, and we treat privacy correspondence as a priority.
Data protection and privacy
Data Protection Officer
Grievance Officer (India — DPDP Act, 2023)
Security and vulnerability reports
Legal and contractual notices
Postal address
Virtuos Digital Limited — Futuristry Division
308-311 Emaar Digital Greens,
Tower A Golf Course Ext. Road,
Sector 61 Gurgaon - 122102
25.2
Mark correspondence for the attention of the Data Protection Officer or the Grievance Officer as appropriate. We acknowledge privacy correspondence within 3 business days and respond substantively within the timelines at clause 18.
25.3
If you are dissatisfied with our response, you may escalate to the supervisory authority with jurisdiction over you, as described at clause 17.

Truce.ai — Accord Lifecycle Intelligence. A trademark of Virtuos Digital Limited, operated through the Futuristry Division, a Strategic Business Unit at Virtuos formed under the Transformation Economy initiative. Privacy Policy version 1.0, effective 7 September 2026. Read with the Truce.ai Terms & Conditions, Safe Harbour Policy, and Data Protection, Security & Compliance Policy.