xVio Platform — Privacy Policy
Last updated: 15 August 2026
Privacy Policy — Part A
1. Who is responsible for your data
The xVio platform and its applications (each, an "App") are provided by ExonPro Innovations LLP, a limited liability partnership incorporated in India ("ExonPro", "we", "us", "our"). This Part A is the common core that applies to every App. Each App also has its own addendum below that describes the data practices specific to that App; where the addendum and this Part A differ, the addendum governs for that App.
Grievance Officer (India). In accordance with applicable Indian law, you may raise any concern, question, or complaint about your personal data with our Grievance Officer:
Kusaldip Das, Grievance Officer ExonPro Innovations LLP — LLPIN: ABB-5575 SGIL Orchid, Flat No. 3A, Rajarhat Canal Road, Sikharpur, Bhangar-II, South 24 Parganas, West Bengal, India – 700135 Email: grievance@exonpro.in
We will acknowledge and address grievances within the timelines required by applicable law.
2. Information we collect
The specific categories of information collected depend on which App you use and are set out in that App's addendum below. Across the platform, information we may collect falls into these general groups:
- Account and identity information you provide or that is provided when you sign in (for example, name, email address, and an identifier from a sign-in provider you choose).
- Content and information you put into an App — the material you create, upload, capture, or import while using it. The nature of this content, and whether it stays on your device or is sent to our servers, is described in the App's addendum.
- Device and technical information needed to operate the service securely (for example, a per-installation device or session identifier, and basic diagnostic information). Where an App treats any of this as identifying an installation rather than a person, its addendum says so.
We collect only what an App needs to do what you have asked it to do. An App's addendum lists what it does not collect.
3. How we use information
We use the information described in each App's addendum to:
- provide, operate, and secure the App and its features;
- perform the specific function you asked the App to carry out;
- maintain and improve reliability, and diagnose problems;
- communicate with you about the service; and
- comply with our legal obligations.
The App's addendum describes any use that is specific to that App. We do not sell or rent your personal data, and we do not share it for advertising.
4. Data residency, our role, and international transfers
Where your data is stored (region selection). For each App, we select the hosting region in which server-stored data is kept, and we name that region in the App's addendum below. Region is chosen per product to suit its users and obligations; Part A does not fix a single global region for the whole platform. Some front-end delivery may be served from a global content-delivery network for performance, but the App's server-stored data resides in the region named in its addendum.
Our role — controller vs processor. Our data-protection role differs by App and is stated in each addendum:
- For xVio Vision (enterprise document processing), ExonPro acts as a processor (a "data processor" / "data fiduciary's processor" as applicable) that handles content on behalf of the organisation that engages it; that organisation is the controller of the content its users upload.
- For Daykit (a consumer, local-first App), ExonPro acts as the controller of the limited account and service data it holds.
Each addendum states the role that applies and, for processor Apps, that the engaging organisation's own terms govern the content it controls.
International transfers. Depending on the region named in an App's addendum and where you are located, your information may be processed in a country other than the one you live in. The lawful mechanism we rely on for a cross-border transfer depends on the data-protection law that applies to you, because the applicable regimes use different models. Where the GDPR applies (EEA/UK), we rely on EU/UK Standard Contractual Clauses — or, where one exists for the destination country, an adequacy decision. Under India's DPDP Act, the model is different: cross-border transfer is permitted unless the Indian government specifically restricts a particular destination country (no country is currently restricted), and India does not operate a Standard-Contractual-Clauses equivalent. In every case we take steps to ensure your information remains protected to the standard described in this policy.
5. How we share information
We share information only as needed to run the service and as described in each App's addendum, namely with:
- service providers who host or support the App under contract (for example, our cloud hosting provider) and who act on our instructions;
- sign-in and integration providers you choose to connect, and only for the purpose you connected them for; and
- authorities or others where the law requires it, or to protect rights, safety, and the integrity of the service.
The providers an App relies on are named in its addendum. These are service providers and, where an App captures information from a source you connect, lead sources — not advertising partners.
6. Data retention
We keep personal data only for as long as it is needed for the purposes described in this policy, or for as long as the law requires. Because retention depends heavily on what an App does, the specific retention periods for each App are set out in its addendum below — see the app addendum below. As a general framework:
- account and identity data is kept while your account is active and until you ask us to delete it;
- session and device records are kept until they expire or you sign out;
- connected-integration credentials are kept until you disconnect them; and
- content you create is kept for the period stated in the App's addendum, subject to any deletion tools the App provides.
When data is no longer needed, we delete it or irreversibly de-identify it.
7. Data security
We protect information using measures appropriate to its sensitivity — including encryption of data in transit, storing secrets and provider credentials in a managed secrets store, and storing device and account keys as hashes rather than in the clear. No system is perfectly secure, and we do not claim otherwise; App-specific security measures are described in each addendum.
8. Your rights and choices
Wherever you are, and subject to applicable law, you may ask us to:
- access — obtain a copy of the personal data we hold about you;
- rectify — correct data that is inaccurate or incomplete;
- erase — delete your data (each App's addendum describes its in-App deletion tools and its full account-deletion route);
- port — receive your data, where technically applicable, in a portable form; and
- object / restrict — object to or ask us to restrict certain processing.
To exercise any of these rights, use the contact route in the relevant App's addendum or contact our Grievance Officer (§1). We will respond within the timelines required by applicable law.
Children and age. Our Apps are intended for adults and are not directed at children. The minimum age to use an App, and how that App handles age, is set by each App's addendum below — different Apps carry different minimum ages. We do not knowingly collect personal data from anyone below the minimum age stated for the App they are using; if we learn that we have, we will delete it.
9. Regional privacy rights
Additional rights may apply to you depending on where you live — for example under the EU/UK GDPR, India's DPDP Act, the UAE's data-protection law, California's CCPA and other US state laws, Canada's PIPEDA/Quebec Law 25, Australia's Privacy Act, Singapore's PDPA, or Brazil's LGPD.
10. Changes and contact
We may update this policy from time to time; material changes will be reflected by an updated effective date and, where appropriate, additional notice. For any privacy question you may contact the route named in the relevant App's addendum, or our Grievance Officer at grievance@exonpro.in (§1).
GDPR (EU/UK)
These regional rights apply to you only to the extent the relevant law actually covers your situation. ExonPro Innovations LLP is established in India, and this section is provided for those users to whom this law applies. This section applies if you are in the European Economic Area (EEA), the United Kingdom, or Switzerland. It supplements the common core of this policy; where this section and the common core differ for EEA/UK/Swiss users, this section governs. "GDPR" here means Regulation (EU) 2016/679 and, for the UK, the UK GDPR and the Data Protection Act 2018 as applicable.
Controller or processor
Whether ExonPro Innovations LLP acts as a data controller or a data processor depends on the app you use — this is stated in that app's addendum (Part B). Where we act as a processor on behalf of your organization (the controller), we process personal data only on that controller's documented instructions, and you should direct data-subject requests to the controller in the first instance; we will assist the controller in responding. Where we act as a controller, the rights and routes below apply directly.
Legal bases for processing
We rely on one or more of the following legal bases under Article 6 GDPR, depending on the processing activity:
- Contract (Art. 6(1)(b)) — to provide the service you or your organization have requested and to perform our agreement (e.g. account/session handling, core in-app functionality).
- Legitimate interests (Art. 6(1)(f)) — to secure, maintain, debug and improve the service and to prevent abuse, balanced against your rights and freedoms. You may object to processing on this basis (see rights below).
- Consent (Art. 6(1)(a)) — for processing that is optional (e.g. optional diagnostic/telemetry data, or connecting an optional third-party account), which you may withdraw at any time without affecting the lawfulness of processing before withdrawal.
- Legal obligation (Art. 6(1)(c)) — where we must process data to comply with a legal requirement.
Where ExonPro acts as a processor (e.g. xVio Vision, handling documents on an organization's behalf), the Art. 6 legal basis for that content is determined by the organization as controller; the bases listed above describe ExonPro's own processing as a controller (e.g. account, sign-in, and billing/admin data).
We do not carry out solely-automated decision-making that produces legal or similarly significant effects on you without meaningful human involvement. Any AI-assisted processing performed by an app is described in that app's addendum and is intended to assist, not to make automated determinations about you.
Note: the EU and UK regimes for automated decisions now differ. The EU relies on the Article 22 prohibition-based model. In the UK, the rules changed under the Data (Use and Access) Act 2025, which introduced new UK GDPR Articles 22A–22D (effective 5 February 2026): solely-automated decisions are permitted by default for non-special-category data, subject to safeguards.
Your rights
Subject to the conditions and exceptions in the GDPR, you have the right to: access your personal data; rectify inaccurate or incomplete data; erase data ("right to be forgotten"); restrict processing; data portability (receive certain data in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible); object to processing based on legitimate interests and to object to direct marketing at any time; and to withdraw consent at any time where processing is based on consent.
Where any processing does meet the definition of a solely-automated decision with legal or similarly significant effect, you have the right to obtain human intervention, express your point of view, and contest the decision (GDPR Art. 22(3) / UK Art. 22C–22D safeguard).
International data transfers
The platform is hosted on Microsoft Azure. The specific hosting region for the data of each app is stated in that app's addendum (the common core describes how the region is selected per app). Where personal data is transferred outside the EEA/UK/Switzerland — including to Azure regions outside those areas — we rely on an appropriate transfer mechanism recognised under the GDPR, which may include: transfer to a country covered by an adequacy decision; Standard Contractual Clauses (SCCs) adopted by the European Commission (and, for UK transfers, the UK International Data Transfer Addendum / IDTA or the UK Addendum to the EU SCCs); and supplementary technical and organisational measures (such as encryption in transit and at rest) where needed. A copy of the relevant safeguards can be requested using the contact route below.
How to exercise your rights
Contact the Part A grievance officer, Kusaldip Das, at grievance@exonpro.in. We will respond within the period required by the GDPR (generally one month, extendable by two further months for complex or numerous requests, with notice to you). We may need to verify your identity before acting. There is normally no charge, though we may charge a reasonable fee or refuse a request that is manifestly unfounded or excessive.
Right to complain to a supervisory authority
You have the right to lodge a complaint with a data-protection supervisory authority, in particular in the EU/EEA member state of your habitual residence, place of work, or place of the alleged infringement. In the United Kingdom, the supervisory authority is the Information Commissioner's Office (ICO). We would, however, appreciate the chance to address your concern first via the contact route above.
India DPDP Act, 2023
This section applies to the processing of digital personal data governed by India's Digital Personal Data Protection Act, 2023 (DPDP Act) and rules made under it. India is the primary jurisdiction for ExonPro Innovations LLP, and this policy is written to align with the DPDP Act as its baseline; this section states the DPDP-specific rights and routes. In DPDP Act terms, "Data Principal" means the individual to whom the personal data relates and "Data Fiduciary" means the entity that determines the purpose and means of processing.
Our role
Whether ExonPro acts as a Data Fiduciary (determining purpose and means) or processes on behalf of another Data Fiduciary depends on the app you use, as stated in that app's addendum (Part B). Where an app is consumer-facing and local-first, ExonPro is generally the Data Fiduciary for the limited personal data that leaves your device; where an app processes documents on behalf of your organization, that organization is the Data Fiduciary and ExonPro processes on its behalf.
Notice and consent
We process your personal data for the specified purposes described in this policy and in the relevant app addendum. Where our lawful basis is your consent, we ask for it through a clear notice that describes the personal data to be processed and the purpose, and you may withdraw your consent at any time with an ease comparable to that with which it was given; withdrawal does not affect processing already carried out lawfully. Where the Act permits processing for certain legitimate uses without separate consent, we rely on those provisions only to the extent the Act allows.
International data transfers
Under the DPDP Act, cross-border transfer of personal data is permitted by default and is restricted only to countries the Indian government specifically notifies as restricted (no country is currently notified). India does not use a Standard Contractual Clauses or adequacy-list model. Each app's server-storage region is named in its addendum (xVio Vision = East US 2; Daykit = Central India).
Your rights as a Data Principal
Subject to the DPDP Act and its rules, you have the right to: access a summary of the personal data we process about you and the processing activities; correction, completion, and updating of your personal data; erasure of your personal data where retention is no longer necessary for the purpose or required by law; grievance redressal (see below); and to nominate another individual to exercise your rights in the event of your death or incapacity.
Grievance-officer route
For any grievance about how your personal data is handled, contact the Part A Grievance Officer designated under this policy:
- Grievance Officer: Kusaldip Das
- Email: grievance@exonpro.in
The Grievance Officer is the readily available means for you to raise a grievance under the DPDP Act. We will acknowledge and respond to your grievance within the timeframe prescribed under the Act and its rules.
Complaint to the Data Protection Board
If your grievance is not resolved to your satisfaction, or you do not receive a response within the applicable period, you may make a complaint to the Data Protection Board of India established under the DPDP Act, in the manner prescribed. We would appreciate the opportunity to resolve your concern first through the Grievance Officer route above.
UAE Federal PDPL (United Arab Emirates)
This section applies if you are a consumer located in the United Arab Emirates. ExonPro Innovations LLP is established in India, and this section is provided for those users to whom UAE data-protection law applies. It states your UAE-specific rights and the routes to exercise them, and supplements the common core of this policy; where this section and the common core differ for UAE users, this section governs.
Which law applies
As drafted, this section relies on the UAE Federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the "PDPL") as the default regime for personal data of individuals in the onshore UAE. The financial free-zone regimes — the DIFC Data Protection Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021 — are separate and do not apply absent a DIFC or ADGM establishment or a processing presence in one of those zones (see the company-fact flag above).
Status of the regime
The Federal PDPL is in force (since January 2022), but its Executive Regulations have not yet been issued, and the federal data authority (reorganised into the UAE Federal Authority for Artificial Intelligence and Data in 2026) is still standing up its operations. This section therefore states your rights in principle but deliberately does not assert operational specifics that do not yet publicly exist — it names no specific complaint portal and relies on no UAE adequacy list.
Our role
Whether ExonPro Innovations LLP acts as a controller or a processor depends on the app you use — this is stated in that app's addendum (Part B). Where we act as a processor on behalf of your organisation (the controller), we process personal data only on that controller's documented instructions, and you should direct requests to the controller in the first instance; we will assist the controller in responding. Where we act as a controller, the rights and routes below apply directly.
Lawful basis for processing
We rely principally on your consent and on the necessity of processing to perform a contract with you (for example, to provide the app and the functionality you have asked it to carry out). We do not assert "legitimate interest" as a lawful basis under the PDPL.
Your rights
Subject to the PDPL and its Executive Regulations (once issued), you have the right to: access your personal data; rectification of inaccurate or incomplete data; erasure of your personal data; restriction of processing; data portability; and to object to processing. We do not cite specific article numbers for these rights here, as they remain to be verified against the Executive Regulations.
Cross-border data transfers
The platform is hosted on Microsoft Azure; Daykit's data is hosted in Central India (the specific hosting region for each app's data is stated in that app's addendum). There is no public UAE adequacy list at present. Accordingly, any transfer of your personal data outside the UAE relies on appropriate contractual and technical safeguards (such as contractual data-protection commitments and encryption in transit and at rest) — this is not an "adequacy" claim.
Children — age floor
Each app states its own minimum age in its addendum (for example, Daykit is 18+); we do not knowingly collect personal data from anyone below the minimum age stated for the app they are using.
How to exercise your rights, and complaints
To exercise any of these rights, contact the Part A grievance officer, Kusaldip Das, at grievance@exonpro.in. The UAE federal regulator is still standing up its complaint infrastructure, so we do not name a specific complaint portal or URL here; we would appreciate the chance to address your concern first via the contact route above.
CCPA / CPRA (California)
This section applies to California residents and supplements the common core, as required by the California Consumer Privacy Act as amended by the California Privacy Rights Act (together, the "CCPA"). Terms such as "personal information", "sell", "share", and "service provider" have the meanings given in the CCPA. California is a market we actively serve, and we provide the rights and routes below for our California users and intend to honour them operationally. As a matter of legal accuracy, the CCPA's specific "business" obligations attach only once ExonPro meets the statutory thresholds ($25M+ annual revenue / personal information of 100,000+ California consumers or households / 50%+ of annual revenue from selling personal information), which ExonPro likely does not yet meet; the rights described here are provided for our California users regardless, and become binding "business" obligations if and when ExonPro crosses those thresholds.
Categories of personal information
Depending on the app you use, we may collect the following CCPA categories of personal information (the exact data elements for each app are described in the common core and that app's addendum):
- Identifiers — e.g. name, email address, account/sign-in identifiers, provider user ID, device or installation identifiers.
- Customer records / account information — e.g. contact details you or your organization provide.
- Commercial information — e.g. records of services requested or used (where applicable).
- Internet or other electronic network activity — e.g. session and diagnostic/telemetry data (where the app collects it, generally optional).
- Geolocation — only if an app states it collects it; several apps expressly collect no location data (see the app addendum).
- Audio/visual and file information — e.g. documents or images you choose to capture or upload in apps that offer that (as described in that app's addendum).
- Inferences — we do not build behavioural/advertising profiles about you.
We collect these for the business and commercial purposes described in this policy (providing, securing, maintaining and improving the service), and we obtain them from you, your organization, your device, and the third-party sign-in / integration providers you choose to connect.
Selling and sharing of personal information
We do not sell your personal information for money. Our websites use standard analytics tools to understand and improve the service; under the CCPA, some of that activity may be treated as a "sale" or "share" of personal information for cross-context behavioural advertising. Where that applies to you, you may opt out — and exercise your other rights below — by contacting our Grievance Officer at grievance@exonpro.in. Within the xVio apps themselves, we do not sell or share your personal information. Our services are not directed to children, and we do not knowingly collect personal information from consumers under 16. We use service providers (such as our cloud host and sign-in providers) under contracts that restrict their use of personal information to providing services to us.
Your California rights
Subject to the CCPA and its exceptions, you have the right to:
- Know / Access — request the categories and specific pieces of personal information we have collected, the sources, the business/commercial purposes, and the categories of third parties to whom it is disclosed.
- Delete — request deletion of personal information we collected from you.
- Correct — request correction of inaccurate personal information.
- Opt out of sale/sharing — we do not sell or share personal information (see above), so there is nothing to opt out of; the right is stated here for completeness.
- Limit use of sensitive personal information — see the ⚠ note above; applicable only if an app collects sensitive personal information for a purpose that triggers this right.
- Non-discrimination — you have the right not to receive discriminatory treatment for exercising any of your CCPA rights. We will not deny you services, charge different prices, or provide a different level or quality of service because you exercised your rights.
How to exercise your rights, and authorized agents
To exercise any of these rights, contact the Part A grievance officer, Kusaldip Das, at grievance@exonpro.in. Where the CCPA applies to us, we will confirm receipt within 10 business days and respond within 45 calendar days (extendable by a further 45 days with notice), in each case as required by the CCPA. We will take reasonable steps to verify your identity before acting on a request, and may decline a request we cannot verify.
You may use an authorized agent to make a request on your behalf. We may require the authorized agent to provide proof that you gave them signed permission to act for you, may require you to verify your own identity directly with us, and may require you to directly confirm that you gave the agent permission, as permitted by the CCPA.
Canada (PIPEDA + Quebec Law 25)
This section applies to users located in Canada. ExonPro Innovations LLP is established in India, and this section is provided for those users to whom Canadian data-protection law applies. Canada is not a single regime: the federal Personal Information Protection and Electronic Documents Act (PIPEDA) applies nationally, and Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25, applies additionally — and more strictly — to Quebec residents. These laws can reach us extraterritorially (PIPEDA through a "real and substantial connection" to Canada; Law 25 through the offering of goods or services to Quebec residents). We provide the rights below to our Canadian users and intend to honour them; the binding statutory obligations attach if and when we actively serve the Canadian / Quebec market. Where this section and the common core differ for Canadian users, this section governs.
Accountable privacy officer
PIPEDA requires us to designate an individual accountable for our compliance. Under Quebec Law 25 this role defaults to ExonPro's person with the highest authority unless it is delegated in writing — and where it is delegated, that person's name, title, and contact must be published.
Consent
Under PIPEDA we rely on meaningful consent, scaled to the sensitivity of the data and presented in a layered form. Quebec Law 25 adds that, where consent is relied on, it must be requested separately from any other information, in clear and plain language, and for each specific purpose.
Your rights
- Under PIPEDA you may access the personal information we hold about you and request correction of inaccuracies. PIPEDA does not provide a general federal right to erasure or to data portability.
- Quebec residents additionally have the right to data portability, to request de-indexing or cessation of dissemination, and to be informed about, and to object to, automated decision-making. These Quebec-only rights do not extend to residents of other provinces.
Cross-border transfers
Under PIPEDA a transfer for processing is treated as a use, addressed through accountability and contractual protection rather than an adequacy list or Standard Contractual Clauses. Quebec Law 25 (§17) requires a written Privacy Impact Assessment before any transfer of personal information outside Quebec — assessing the sensitivity of the data, the purpose, the protection afforded in the destination, and a written agreement. Each app's server-storage region is named in its addendum (xVio Vision = East US 2; Daykit = Central India), both of which are outside Quebec.
Breach notification
Under PIPEDA we report a breach to the Office of the Privacy Commissioner of Canada (OPC) and notify affected individuals where it creates a "real risk of significant harm", and we keep a record of breaches for 24 months. Under Quebec Law 25 we notify the Commission d'accès à l'information (CAI) and affected individuals where the incident presents a "risk of serious injury", as soon as possible, and maintain an incident register.
Children
Each app states its own minimum age in its addendum; both current apps are 18+ and we do not knowingly collect personal data from anyone below the stated minimum age.
Complaints
You may complain first to us via our Grievance Officer at grievance@exonpro.in. You may then escalate to the OPC (federal — an ombudsman without direct fining power) or, for Quebec residents, to the CAI, which can issue orders and impose penalties (up to the greater of C$25M or 4% of worldwide turnover), and Law 25 provides a private right of action with a C$1,000 statutory minimum. We would appreciate the chance to resolve your concern first.
Australia (Privacy Act 1988 / Australian Privacy Principles)
This section applies if you are located in Australia. ExonPro Innovations LLP is established in India, and this section is provided for those users to whom Australian privacy law applies. The Privacy Act 1988 (Cth) and its Australian Privacy Principles (APPs) can reach us extraterritorially where we have an "Australian link" or "carry on business in Australia" (a test widened on 13 December 2022; no local presence is required). We provide the rights below to our Australian users and intend to honour them; the binding obligations attach if and when the Act applies to ExonPro. Where this section and the common core differ for Australian users, this section governs.
Notice, collection, and use
We handle notice and collection under APP 1 (open and transparent policy content), APP 5 (a collection notice at or before collection, including whether we disclose personal information overseas and, where practicable, the countries), and APP 6 (use limited to the purpose of collection).
Sensitive information
Under APP 3, we collect sensitive information only with your consent.
Cross-border disclosure — accountability model
Australia does not use adequacy decisions or Standard Contractual Clauses. Under APP 8 we must take reasonable steps to ensure an overseas recipient does not breach the APPs, and under s.16C we may be held liable as if we had committed the breach ourselves. Cloud hosting can be treated as a "use" rather than a "disclosure" where the contract is storage-only and we retain effective control. Each app's region is named in its addendum (xVio Vision = East US 2; Daykit = Central India).
GDPR (Ch. V) │ Australia (APP 8 + s.16C)
───────────────────────────────────┼──────────────────────────────────────
Pick a lawful transfer mechanism │ Take "reasonable steps" so the overseas
(adequacy / SCCs / BCRs) and the │ recipient won't breach the APPs — and we
transfer is then permitted. │ STAY ACCOUNTABLE: s.16C deems us liable
│ for the recipient's breach as if it were
│ our own. No mechanism "clears" the transfer.
Your rights
Under APP 12 you may access your personal information — for a private-sector organisation, within a "reasonable period" with no fixed statutory day-count (this differs from the CCPA's 45-day period) — and under APP 13 you may request correction.
Breach notification
Under the Notifiable Data Breaches scheme we assess a suspected breach (a 30-day assessment ceiling) and notify the OAIC and affected individuals where it is likely to result in serious harm — applicable only if the Act applies to ExonPro per the turnover position above.
Children
Each app states its own minimum age; both current apps are 18+.
Complaints
Complain to us first via our Grievance Officer at grievance@exonpro.in (we have 30 days to respond), then to the Office of the Australian Information Commissioner (OAIC), within a 12-month window.
Singapore (PDPA)
This section applies to individuals located in Singapore. ExonPro Innovations LLP is established in India, and this section is provided for those users to whom Singapore's Personal Data Protection Act (PDPA) applies — it can reach a foreign organisation that collects the personal data of Singapore users through an activity nexus, with no local office required. We provide the rights below to our Singapore users and intend to honour them; the binding obligations attach if and when we actively serve the Singapore market. Where this section and the common core differ for Singapore users, this section governs.
Consent, notification, and purpose
We rely on consent (including deemed consent by conduct, contractual necessity, or notification-with-opt-out where permitted), we notify you of the purpose at or before collection, and we limit use to that purpose.
Your rights
You have the right to access the personal data we hold about you and to request correction.
Cross-border transfers — Transfer Limitation Obligation
Singapore does not use an adequacy list. Any transfer of personal data outside Singapore requires comparable protection to be established by contract or certification (e.g. APEC CBPR — the US participates, India does not). Each app's region is named in its addendum (xVio Vision = East US 2; Daykit = Central India), so comparable protection must be affirmatively established for both the US and India legs.
Children
Each app states its own minimum age; both current apps are 18+, which exceeds the PDPC's 13/18 guidance thresholds.
Complaints
Contact our DPO first (we aim to respond within ~10 business days), then escalate to the Personal Data Protection Commission (PDPC).
Brazil (LGPD)
This section applies to individuals located in Brazil. ExonPro Innovations LLP is established in India, and this section is provided for those users to whom Brazil's Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) applies — it reaches organisations offering goods or services to, or collecting data in, Brazil. We provide the rights below to our Brazilian users and intend to honour them; the binding obligations attach if and when we actively serve the Brazilian market. Where this section and the common core differ for Brazilian users, this section governs.
Legal bases for processing
Unlike some regimes, the LGPD provides ten legal bases and legitimate interest is an established basis (though not for sensitive data). We may rely on performance of a contract, legitimate interest, consent, and compliance with a legal obligation, among others; consent is not required for every processing activity.
Your rights
You have the right to: confirmation of processing; access; correction; anonymization, blocking, or deletion; data portability; information about entities with which we share data; and to revoke consent.
Data protection officer (Encarregado)
LGPD Art. 41 requires appointing an encarregado (DPO) and publishing that person's identity and contact.
Cross-border transfers
Children
Each app states its own minimum age; both current apps are 18+. The LGPD treats a child as under 12 (parental consent) and an adolescent as 12–18 (best-interest standard).
Breach notification
We notify the ANPD and affected individuals within three business days of confirming an incident that presents a relevant risk.
Complaints
You may complain to the ANPD (via gov.br), which distinguishes a Denúncia (report) from a Petição de Titular (data-subject petition). No Art. 27-style local representative is required for a foreign controller in the LGPD — a favourable position we state plainly. We would appreciate the chance to resolve your concern first via our Grievance Officer at grievance@exonpro.in.
Other US State Privacy Laws (beyond California)
This section applies to residents of US states — other than California — that have comprehensive consumer privacy laws in force. Roughly 19 states have such laws in force in 2026: Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, and Rhode Island. We consolidate them here as one regime because their consumer rights are broadly aligned. We provide the rights below to residents of these states and intend to honour them; the binding statutory obligations attach if and when ExonPro meets a given state's applicability threshold. Where this section and the common core differ for these users, this section governs.
How this differs from California — state up front
- (a) Sensitive data is OPT-IN. These states require affirmative opt-in consent to process sensitive data — not California's opt-out "right to limit".
- (b) Universal opt-out / Global Privacy Control (GPC) is a legal REQUIREMENT in most of these states, not merely recommended.
- (c) Right to appeal. You have a right to appeal a denied request, and to escalate an unresolved appeal to the state Attorney General.
Your rights
Subject to the applicable state law, you have the right to: access, correction, deletion, data portability, opt out of targeted advertising, the sale of personal data, and profiling that produces significant effects, and non-discrimination for exercising these rights.
We do not sell your personal data
As with our California statement, we do not sell your personal data for money; some analytics activity may be treated as a "sale" or "share" under certain state laws, and where that applies to you, you may opt out by contacting our Grievance Officer at grievance@exonpro.in.
Officers, assessments, and response times
No DPO or local representative is required under these laws. A data-protection assessment duty attaches to high-risk processing once a law is triggered. To exercise a right, appeal a denial, or raise a concern, contact our Grievance Officer at grievance@exonpro.in.
Other regions
Universal catch-all.
If you are in a country or region with its own data-protection law not specifically addressed above, those rights may still apply to you. Contact our Grievance Officer at grievance@exonpro.in and we will honour the rights available to you under the applicable law.
