Veriq Technology by Kaido TechBack to sign in

Veriq Privacy Policy

Effective date:
[INSERT PUBLICATION DATE]
Version:
0.9
Status:
Pre Incorporation

1. About this Privacy Policy

1.1This Privacy Policy explains how personal data is collected, used, disclosed, stored and otherwise processed in connection with Veriq.

1.2Veriq is a business data consolidation, validation and reporting platform developed under the Kaido Tech brand.

1.3Kaido Tech Pte. Ltd. is currently undergoing incorporation in Singapore and is intended to become the operator of Veriq after successful incorporation and completion of the necessary legal and operational arrangements.

1.4Nothing in this Privacy Policy represents that Kaido Tech Pte. Ltd. has already been incorporated.

1.5In this Privacy Policy, Kaido Tech, we, us and our refer to the team responsible for developing and operating Veriq during the pre incorporation period.

2. Scope

2.1This Privacy Policy applies to personal data processed through:

  • Veriq user accounts
  • authentication
  • Workspace administration
  • use of Platform features
  • support communications
  • audit and security logging
  • invitations and onboarding
  • Platform websites
  • Customer Data where it contains personal data.

2.2It applies to:

  • Authorised Users
  • Customer administrators
  • people who contact support
  • individuals whose personal data appears in Customer Data
  • other individuals who interact with Veriq.

2.3This Privacy Policy does not replace a Customer’s own privacy notices or internal policies.

3. Roles and responsibilities

3.1Customers generally determine:

  • who may access their Workspace
  • which data is submitted
  • why Customer Data is processed
  • which reports are generated
  • how reports and exports are used.

3.2Kaido Tech processes Customer Data to provide, maintain, secure and support Veriq.

3.3For Customer Data containing personal data, the Customer may be primarily responsible for deciding the purposes of processing.

3.4For account information, security records, usage records, support communications and operational information, Kaido Tech may determine the purposes of processing.

3.5Questions about information submitted by your organisation should normally be directed first to your organisation’s administrator.

4. Personal data we may collect

4.1 Account information

We may collect:

  • name
  • work email address
  • organisation
  • job title or function
  • Workspace membership
  • assigned role
  • permissions
  • profile information
  • account status.

4.2 Authentication information

We may process:

  • login identifiers
  • authentication tokens
  • session information
  • magic link records
  • multi factor authentication status
  • identity provider information.

Passwords must not be stored in readable form.

4.3 Technical information

We may collect:

  • IP address
  • browser type
  • operating system
  • device type
  • language
  • time zone
  • session timestamps
  • application version
  • diagnostic information.

4.4 Usage and audit information

We may collect:

  • login and logout activity
  • pages or modules accessed
  • files uploaded or processed
  • reports viewed or exported
  • account and permission changes
  • administrative activity
  • alert activity
  • error events
  • security events.

4.5 Support and communications

We may collect:

  • support requests
  • emails
  • feedback
  • issue reports
  • screenshots
  • files submitted for support
  • contact details included in communications.

4.6 Customer Data

Customers may submit business information such as:

  • distributor reports
  • market information
  • sales information
  • inventory information
  • product information
  • SKU information
  • customer supplied mappings
  • reporting structures
  • business classifications
  • other operational data.

Customer Data may occasionally contain personal data relating to employees, representatives, suppliers, customers or other individuals.

4.7 Cookies and similar technologies

Veriq may use:

  • authentication cookies
  • session cookies
  • security cookies
  • preference storage
  • infrastructure cookies
  • analytics cookies where analytics is enabled.

Before publishing, confirm the actual cookies and technologies used in the repository and production environment.

5. How personal data is collected

Personal data may be collected:

  • directly from you
  • from your organisation
  • from a Workspace administrator
  • through your use of Veriq
  • from authentication providers
  • from Customer Data
  • from support communications
  • from monitoring systems
  • from authorised integrations.

6. Purposes of processing

We may process personal data to:

  • create and maintain accounts
  • authenticate users
  • manage roles and permissions
  • provide access to the correct Workspace
  • operate Platform features
  • ingest, validate, transform and consolidate Customer Data
  • produce dashboards, reports, exports and alerts
  • provide onboarding and support
  • respond to communications
  • maintain audit trails
  • monitor performance
  • diagnose and correct errors
  • prevent misuse and unauthorised access
  • investigate security incidents
  • maintain backups and resilience
  • meet legal obligations
  • enforce applicable terms
  • improve reliability, usability and security
  • support the transition to Kaido Tech Pte. Ltd. after incorporation.

7. Customer Data processing

7.1Customer Data is processed according to the Customer’s authorised instructions.

7.2Users must not submit information that their organisation is not authorised to process.

7.3Kaido Tech does not independently determine the commercial reasons for which Customers submit their business data, except where needed to operate, support and secure Veriq.

8. Artificial intelligence and model training

8.1Artificial intelligence features may be introduced only where separately enabled.

8.2Customer Data will not be used to train public or general purpose artificial intelligence models unless the relevant Customer has expressly agreed in writing.

8.3This statement must be technically accurate before the Privacy Policy is published.

8.4If artificial intelligence features are introduced, this Privacy Policy may be updated to explain:

  • which provider is used
  • what information is sent
  • whether information is retained
  • whether it is used for training
  • where processing occurs
  • what controls are available.

9. Disclosure of personal data

Personal data may be disclosed to:

  • the relevant Customer
  • authorised Customer administrators
  • authorised users within the relevant Workspace
  • Kaido Tech personnel and authorised contributors
  • hosting providers
  • database providers
  • storage providers
  • authentication providers
  • email providers
  • monitoring and security providers
  • professional advisers
  • regulators, courts or authorities where required by law
  • a future incorporated operator where responsibility is lawfully transferred.

Personal data is not sold to advertisers.

10. Service providers

10.1Veriq may use third party providers for:

  • application hosting
  • databases
  • file storage
  • authentication
  • transactional email
  • monitoring
  • analytics
  • backups
  • support.

10.2The confirmed service providers used by Veriq are listed below. Only verified providers are published.

Confirmed providers, based on the current production configuration:

  • Application hosting and serverless functions — Vercel Inc.
  • Managed application database (PostgreSQL) — Neon Inc.
  • File and object storage — Vercel Blob (Vercel Inc.)
  • Authentication and session management — self hosted using the Better Auth library on the application database; magic link sign in is used
  • Transactional email delivery (sign in links) — Resend (Resend, Inc.)

Monitoring, analytics and independent error tracking providers are not currently configured. This section will be updated if such providers are introduced.

11. Overseas processing

11.1Some service providers may process or store information outside Singapore.

11.2Where personal data is transferred overseas, reasonable contractual, technical or organisational measures will be used to provide appropriate protection.

11.3Actual processing locations must be confirmed from the selected providers and deployment regions.

12. Data retention

12.1Personal data is retained only for as long as it is reasonably required for the purposes for which it was collected or processed.

12.2Retention periods may reflect:

  • the period during which the relevant account or Workspace remains active
  • the time required to provide and secure Veriq
  • Customer instructions
  • backup and recovery cycles
  • audit and incident investigation needs
  • legal and regulatory obligations
  • dispute resolution requirements
  • legitimate operational requirements.

12.3Unless a different period is agreed with the relevant Customer, the following standard retention periods apply.

12.3.1 User account information

User account information is retained while the account remains active.

After access ends, account information will ordinarily be deleted or anonymised within 90 days, except where limited records must be retained for security, audit, dispute resolution or legal purposes.

12.3.2 Authentication and session records

Authentication and session records will ordinarily be retained for up to 90 days from the date of creation.

12.3.3 General application logs

General application and diagnostic logs will ordinarily be retained for up to 90 days.

Logs should not contain copies of Customer Data unless this is technically necessary and appropriately protected.

12.3.4 Security and access audit logs

Security and access audit logs will ordinarily be retained for up to 12 months from the relevant event.

Records connected to a suspected security incident, misuse investigation or legal dispute may be retained until the matter is resolved and any applicable legal retention period has ended.

12.3.5 Administrative audit records

Records of material administrative actions, permission changes and Workspace configuration changes may be retained for up to 24 months.

12.3.6 Support communications

Support requests and related communications may be retained for up to 24 months after the relevant request is closed.

Attachments containing Customer Data should be deleted earlier where they are no longer required.

12.3.7 Temporary uploads and processing files

Temporary uploads, intermediate files and successfully processed source files will ordinarily be deleted within 7 to 30 days after they are no longer required.

Failed uploads may be retained for up to 30 days to support troubleshooting, unless deleted earlier.

12.3.8 Customer Data in active Workspaces

Customer Data may be retained while the relevant Workspace remains active and while it is required to provide Veriq.

When a Workspace or Customer relationship ends:

  • access may be disabled on the effective termination date
  • a data export period of up to 30 days may be provided
  • Customer Data will ordinarily be deleted from active systems within 90 days after termination or expiry
  • residual backup copies will expire according to the applicable backup cycle.

12.3.9 Backups

Backups will be maintained on a rolling basis and will ordinarily expire within 30 to 90 days from creation.

Deleted information may remain in protected backups until the relevant backup expires.

Backup data will not ordinarily be restored except for disaster recovery, business continuity, security investigation or other legitimate operational purposes.

12.3.10 Accounting records

Invoices, payment records and accounting records may be retained for at least five years, or for any longer period required by applicable law.

12.3.11 Contracts and legal records

Signed agreements, material acceptance records and records required to establish legal rights or obligations may be retained for up to six years after the relevant relationship ends, or longer where required by law or an active legal hold.

This does not mean that all underlying Customer Data will be retained for the same period.

12.3.12 Security incident records

Records relating to material security or personal data incidents may be retained for up to six years after the incident is closed, subject to legal review.

12.3.13 Anonymised information

Information that has been effectively anonymised so that it can no longer reasonably identify an individual may be retained for product analysis, security, statistical and service improvement purposes.

12.4Specific retention periods may differ where:

  • a Customer requests and agrees to another period
  • a Customer Agreement requires another period
  • an investigation or legal hold applies
  • applicable law requires a longer period
  • deletion is temporarily prevented by a security or recovery process
  • a shorter period is appropriate because the information is no longer required.

12.5When personal data is no longer required, reasonable steps will be taken to:

  • delete it
  • anonymise it
  • aggregate it so that individuals can no longer reasonably be identified
  • remove the means by which it can be associated with an identifiable person.

12.6Before publishing this Privacy Policy, confirm that the production architecture can meet these periods across:

  • the application database
  • file storage
  • authentication systems
  • hosting logs
  • monitoring tools
  • email providers
  • cached files
  • exports
  • temporary processing systems
  • backups.

13. Security

13.1Reasonable administrative, technical and organisational safeguards are used to protect personal data.

13.2Depending on the implemented architecture, safeguards may include:

  • access controls
  • role based permissions
  • authentication
  • encryption in transit
  • encryption at rest where supported
  • logging
  • monitoring
  • secret management
  • backups
  • dependency management
  • incident response procedures.

13.3No system can be guaranteed to be completely secure.

14. Data incidents

14.1Suspected loss, unauthorised access, disclosure or misuse should be reported to: [INSERT SECURITY EMAIL]

14.2Reported incidents will be assessed and reasonable containment, investigation and remediation steps will be taken.

14.3Relevant Customers will be informed where their Customer Data is affected and notification is appropriate.

14.4Notifications to affected individuals or authorities will be made where required.

15. Access and correction

15.1For personal data submitted or controlled by your organisation, contact your organisation’s administrator first.

15.2For account or operational information managed through Veriq, contact: [INSERT PRIVACY EMAIL]

15.3Identity verification may be required.

15.4Access or correction may be restricted where permitted or required by law.

16. Withdrawal and objections

16.1Where processing depends on consent, an individual may contact the relevant organisation to withdraw consent.

16.2Withdrawal may affect access to certain Platform functions.

16.3Not all processing depends on consent. Some processing may be necessary to operate Veriq, maintain security or meet legal obligations.

17. Account management and deletion

17.1Customers and their administrators are generally responsible for adding, changing and removing user access.

17.2When a user is no longer authorised, the Customer should request prompt removal of access.

17.3Removing an account does not necessarily require immediate deletion of all security, audit or legal records.

17.4Customer Data deletion and export will be managed according to:

  • the Customer’s instructions
  • the retention periods in this Privacy Policy
  • applicable backup cycles
  • operational requirements
  • applicable legal obligations.

18. Children

18.1Veriq is a business platform intended for authorised personnel of organisations.

18.2It is not designed or intended for use by children.

19. External links

19.1Veriq may include links to third party services.

19.2This Privacy Policy does not govern independent third party websites or services.

20. Changes to this Privacy Policy

20.1This Privacy Policy may be updated to reflect:

  • changes to Veriq
  • incorporation of Kaido Tech Pte. Ltd.
  • changes in data handling practices
  • changes to providers
  • changes in legal requirements
  • changes to retention periods
  • clarification of existing practices.

20.2Material changes will be communicated through Veriq or another reasonable channel.

20.3The current version and effective date will be displayed on this page.

20.4Users may be asked to acknowledge a materially updated version.

21. Post incorporation update

21.1After successful incorporation, this Privacy Policy may be updated to identify Kaido Tech Pte. Ltd. as the operator of Veriq.

21.2The updated version may include:

  • the UEN
  • registered office
  • DPO or privacy contact
  • confirmed service providers
  • confirmed processing locations
  • confirmed retention periods
  • updated legal identity wording
  • a new effective date and version number.

21.3Users may be asked to acknowledge the updated Privacy Policy.

22. Contact

Questions about privacy or personal data may be sent to:

Privacy email:[INSERT PRIVACY EMAIL]

Security incidents may be reported to:

Security email:[INSERT SECURITY EMAIL]