Skip to content

Data Protection · DPDP Act 2023

Built to the Act,not bolted on after.

How GradiumOS is engineered around the Digital Personal Data Protection Act, 2023 — consent, minimisation, selective disclosure, and a clear path to exercise your rights.

Updated 2 July 2026

DPDP Act 2023

The page your legal and IT team should read.

This notice explains, concretely, how Veranox Systems Private Limited aligns GradiumOS with the Digital Personal Data Protection Act, 2023. It is written for the people who scrutinise it: an institution’s legal, data-protection, and IT functions. Where this notice and our Privacy Policy overlap, read them together.

01

Roles under the Act

Veranox is the Data Fiduciary for personal data processed through this site and, under the terms of a pilot, acts for the partner institution in respect of learner data it is entrusted with. The individual whose data is processed — a learner, a staff member, an enquirer — is the Data Principal.

02

Consent

We process personal data on the basis of free, specific, informed, unambiguous consent, given through a clear affirmative action. Consent requests are tied to a stated purpose, and consent can be withdrawn as easily as it was given. On this site, submitting the enquiry form is the consent action; inside the product, learner consent gates assessment, the issuing of a Signal, and any discovery.

03

Purpose limitation

Personal data is processed only for the purpose for which consent was given. Enquiry data is used to handle your enquiry. Learner data in a pilot is used to assess competence, compute Readiness, and issue a Signal — and for nothing outside that purpose. We do not repurpose data for unrelated analytics or marketing.

04

Data minimisation

We collect the least data needed for the purpose. The marketing site collects five fields and a message — no more. The product works on the evidence required to grade competence, and the public surface of a Signal is reduced to the minimum that makes it useful: bands and validity.

05

Selective disclosure — bands, never PII

This is the core of the design. Competence is made verifiable without exposing identity:

  • The public verifier exposes competence as bands plus validity — never raw scores, names, institutions, or contact details.
  • A Signal carries a pseudonym and competence bands. Raw personal data is never placed on the public surface.
  • Verification needs no login — anyone can confirm authenticity by checking the Ed25519 signature on the issued Signal, and the check returns no personal data.
06

Consent-gated, k-anonymity-floored discovery

Where the product supports discovery of learners by employers or institutions, it is constrained on two axes at once. Discovery is consent-gated: a learner is only discoverable if they have consented to be. It is also k-anonymity-floored: results are only returned when a query resolves to a group large enough that no single individual can be singled out. Pseudonymisation is applied throughout, so identity is revealed only when a learner chooses to reveal it.

07

Security safeguards

We apply reasonable security safeguards proportionate to the data: encrypted transport, access controls, least-privilege handling, and pseudonymisation. Signals are protected by Ed25519 digital signatures, so a credential cannot be forged or silently altered. In the event of a personal-data breach, we will act in accordance with our obligations under the DPDP Act, including notification to the Data Protection Board and affected Data Principals as required.

08

Retention

Personal data is retained only for as long as the purpose requires or the law mandates, and is then deleted or anonymised. Enquiry data that does not lead to a pilot is removed within a reasonable period. Learner-data retention in a pilot is set by the pilot agreement with the institution and bounded to what the purpose needs.

09

Cross-border processing

Veranox is based in India and operates under Indian law. Where data is processed using hosting providers (Vercel, Render), processing may occur in jurisdictions those providers operate in, subject to their data-processing terms and any restrictions notified by the Central Government under the DPDP Act. We minimise what crosses any border by keeping personal data out of the public Signal surface entirely.

10

Your rights and how to exercise them

As a Data Principal you may exercise the following rights. Send your request to the Grievance Officer in section 11; we will verify your identity and respond within the timelines required under the Act.

  • Access — a summary of the personal data we process about you and the processing activities.
  • Correction and completion — fix inaccurate or incomplete data.
  • Erasure — deletion where the data is no longer needed for its purpose.
  • Withdraw consent — withdraw at any time, without penalty to the lawfulness of prior processing.
  • Grievance redressal — a readily available means to raise a complaint (section 11).
  • Nomination — nominate another individual to exercise your rights on death or incapacity.
11

Grievance redressal and Officer

We operate a clear, reachable grievance mechanism. If you have a concern about how your data is handled, contact our Grievance Officer below. If your grievance is not resolved to your satisfaction, you may escalate to the Data Protection Board of India.

Data Fiduciary
Veranox Systems Private Limited
Grievance Officer
Uday Volety (Founder)
Place
Chennai, Tamil Nadu, India
12

Updates to this notice

We will keep this notice current as the DPDP Act’s rules are operationalised and as the product evolves. The effective date is shown at the top of this page; material changes will be communicated to active pilot institutions.

Related policies

Privacy PolicyTerms of UseData Protection (DPDP)