Privacy Notice
How Veranox Systems Private Limited handles personal data: what we collect, why, how long we keep it, who else processes it, and how to exercise your rights under the Digital Personal Data Protection Act, 2023.
Veranox Systems Private Limited · Chennai, Tamil Nadu, India
In effect from 22 August 2026 · version 2.0
1Who is responsible
Veranox Systems Private Limited is the Data Fiduciary for personal data processed through this website and, under a pilot agreement, for learner data an institution entrusts to us. We are incorporated in India and based in Chennai, Tamil Nadu. If you are the person whose data is being processed, the DPDP Act 2023 calls you the Data Principal. Questions, requests and complaints go to our Grievance Officer — section 11.
2What this website collects
Nothing. There is no enquiry form on this site, no account, no newsletter sign-up and no analytics. We set no cookies. We run no advertising trackers and build no behavioural profile of visitors. The site is a set of static pages, and its content security policy permits it to talk to no third-party host at all, so the absence of tracking is enforced by the way the site is built.
Our hosting provider processes ordinary server and delivery logs, such as IP address and request metadata, transiently and for the sole purpose of serving and securing the site. We do not receive those logs in a form that identifies you and we do not use them to identify you.
3What you send us by email
The only way to reach us from this site is to write to [email protected] or to call the number on the access page. If you do, we hold what you chose to put in that message — typically your name, your email address, your institution and whatever you decided to tell us. We did not ask for any of it through a form and we do not require any particular field.
We use it for one purpose: to read your enquiry, work out whether a GradiumOS pilot fits, and reply to you. We do not repurpose it, we do not market to you off the back of it, and we do not sell or share it with advertisers or data brokers.
4Our legal basis
For enquiries, we process on the basis of your consent under the DPDP Act, which you give by choosing to write to us. That consent is specific, informed and freely given, and you can withdraw it at any time by telling us so — as easily as you gave it. Withdrawing consent does not make anything we lawfully did before you withdrew it unlawful. For learner data in a pilot, consent is collected inside the product from the learner before any assessment happens; see section 7.
5How long we keep it
Enquiry correspondence sits in our mailbox, visible to the founder and to the limited tooling used to run Veranox. If a conversation does not go anywhere, we delete it within twelve months. If it becomes a pilot, retention moves to the pilot agreement with your institution, which bounds it to what the purpose needs and sets an end date.
6Who else processes it
We keep the chain of processors short, and we name each of them:
- Cloudflare — delivers this website and the product portals. Sees request metadata; holds no personal data of ours.
- Render — runs the GradiumOS application services.
- Supabase — the product database, in the ap-south-1 (Mumbai) region.
- Zoho Mail — carries and stores the email you send to [email protected].
- Model providers — grade submitted work. What is and is not sent to them is set out in section 8.
Each processes only to provide its service to us, under its own data-processing terms. There are no data brokers and no ad networks in this list.
7Learner data inside GradiumOS
A learner reaches GradiumOS through their institution. Inside the product they control four separate consents rather than one blanket agreement — assessment grading, resume processing, employer discovery and the AI tutor — and every optional one is off until they turn it on. Each states plainly what withdrawing it will do. The full breakdown is in section 2 of the data-protection notice.
The design principle behind all of it is that competence can be verified in public without exposing identity:
- Bands, not raw scores, and never PII. The public verifier returns whether a Signal is valid and the competence bands it attests. It never returns a name, an institution, a contact detail or a raw score.
- No login to verify. Anyone can check a Signal's Ed25519 signature without an account, and the check returns no personal data.
- Selective disclosure. A Signal carries a pseudonym and competence bands. Identity is revealed only when the learner chooses to reveal it.
- Consent-gated discovery. An employer sees a learner only if that learner granted discovery consent. Withdraw it and they disappear from every employer's search; with no consents on file, a search returns nothing at all.
- Small groups are suppressed in aggregate views. Where we show an institution which employers are hiring against which competences, we withhold the employer names until at least five distinct employers are in the set, so a small sample cannot be reverse-engineered to one party.
8How we use AI, and what we never send it
GradiumOS uses third-party language models to mark open-ended work against a rubric. We think you should know exactly what crosses that boundary, because most services in this category do not say.
What we send: the question, the rubric, and the answer the learner submitted. What we do not send: the learner's name, email address, roll number, institution, or any identifier that would let the provider connect the work to a person. The grading call carries the work and nothing that says whose it is.
No person marks anything. There is no examiner, no moderator, no second marker and no human review step anywhere in the pipeline. Marking is deterministic where the question has a fixed answer, and model-graded against a rubric where it does not. Where a model is unreachable, a fixed rubric fallback marks the attempt and the result is recorded as provisional until the live marker re-marks it.
No model output reaches a learner without passing a content-safety classifier first, and that gate fails closed — if it cannot reach a verdict, the output is discarded rather than shown.
We do not train models on submitted work, and we do not engage a provider whose terms would let it train on what we send. Model providers may process outside India; we reduce what that exposes by sending work without identifiers, and we will name the providers in use to any institution that asks before a pilot begins.
9Security
We apply safeguards proportionate to what we hold: encrypted transport, access controls, least-privilege handling and pseudonymisation. Signals are protected by Ed25519 digital signatures, so a credential cannot be forged or silently altered — a tampered Signal fails verification rather than passing quietly. If a personal-data breach occurs we will act on our obligations under the DPDP Act, including notifying the Data Protection Board and affected Data Principals. No system is perfectly secure; our answer to that is to hold as little as possible.
10Your rights, and how to use them
Under the DPDP Act you may ask us to do any of the following. Write to the Grievance Officer in section 11; we will verify who you are and respond within the timelines the Act requires.
- Access — a summary of what we hold about you and what we do with it.
- Correction and completion — fix anything inaccurate or incomplete.
- Erasure — delete it where we no longer need it for the purpose you gave it.
- Withdraw consent — at any time, as easily as you gave it.
- Grievance redressal — complain to us, and escalate to the Data Protection Board of India if we do not resolve it.
- Nominate — name someone to exercise these rights for you on death or incapacity.
11Grievance Officer
Every request, question and complaint about personal data goes here. We acknowledge within 72 hours and resolve within 30 days.
Grievance Officer
Veranox Systems Private Limited
Chennai, Tamil Nadu, India
If we do not resolve your grievance to your satisfaction, you may escalate it to the Data Protection Board of India.
12Children and learners under 18
This website is built for institutional and professional enquiries and is not directed at children. We do not knowingly take personal data from a child through it.
Inside a pilot the position is different. Some first-year undergraduates are under 18. Where a learner in a pilot cohort is under 18, the institution is responsible for obtaining verifiable parental consent before that learner is enrolled, and the pilot agreement says so. We do not profile learners for advertising and we do not run behavioural advertising at all, at any age.
13Changes to this notice
We will update this notice as the product and our obligations change, and we will move the date and version at the top when we do. A change that affects how we use personal data is communicated directly to active pilot institutions rather than left to be noticed.