We at Digicred Technologies Private Limited (“Company”, “Veris” or we”); respect your privacy and value the relationship we have with you. This Privacy Notice (“Notice”) applies to Company’s collection and use of Personal Information (as defined below, and otherwise referenced as “Personal Data” in certain applicable privacy laws) of Users ( or “you,” “your,” or “yours” as per the context later in this Notice) using the Company’s software, devices, websites, mobile applications, and other products and services provided by Company (collectively, the “Services”). Some of your personally identifiable information is collected by our Services in order to operate.
At Veris, we prioritize the privacy and security of Users' personal information. We are committed to safeguarding the data entrusted to us and maintaining its integrity within our secure database. Your personal information will not be shared with advertisers, spammers, or any unauthorized third parties, ensuring a safe and reliable experience. We use certain personal data as mentioned in this Notice, on the basis of such terms as may be agreed with such organisations to whom we provide Services. If you interacted with our Services through your employer, a business you provided services to, or through a company you visited, please contact such organisation directly with any concerns regarding your data.
This Notice applies to all products and services under the Veris umbrella, including but not limited to:
Please note that this Notice does not extend to other services that may integrate with or be associated with Veris Applications.
We may update this Notice periodically to reflect changes in laws or data practices. We encourage you to visit our website regularly for the latest updates. If you have any questions, concerns, or wish to exercise your privacy rights, please reach out to us using the contact details provided in this Notice.
If you have any questions or comments about this Notice, please contact our Data Protection Officer by completing the form at this link or contact us by email at dpo@veris.in, or call us at
+91 11 39595545.
You also may write to us at:
101, Success Towers, Sector 65,
Gurgaon, India 122018.
This Notice outlines how we collect and use personal information and your choices and rights regarding its use. We collect and process your information when you:
As used in this Notice, “Personal Information” (or “PI” or “Personal Data”) means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular User. We collect contact information such as your name, organization, title, email address, phone number, and photo directly from you or from the organization using Veris and having access to your information. When you interact with the Veris Applications, we automatically collect usage data, including the time and IP Address of Veris App usage, times and locations of door unlocks (if integrated with Access control systems), support requests, peer discovery activity, feedback, and other communications via Veris Apps. We also log frequency of logins and commonly used functions within the Veris Applications for purposes agreed with our customers. Login credentials are collected directly from you and are used to verify your access to your organization’s systems and affiliated Third Party Sites. When you scan a government-issued ID, such as Aadhaar, we collect your first and last name, date of birth, picture, zip code, and other identifying information. With your explicit consent, we may collect biometric identifiers such as fingerprints, voice prints, and optionally, facial profiles.
Based upon the terms agreed with our customer, who may be your employer or your host, we may automatically collect data from your mobile device including a unique identification number, IP address, device model and operating system.
We collect information such as contact details, login credentials, license details, and biometric data when you actively provide them, either through registration, scanning IDs, or biometric authentication. Certain information, including usage patterns, mobile data, web analytics, and IP address details, is automatically collected when you interact with the Service or access it through your mobile device. This includes data derived from cookies, Bluetooth signals, IP addresses, and app usage. When you scan or input details from an Aadhaar card or other government-issued ID, we collect personal and identifying details. Through device sensors and hardware mobile information and Location Data, including precise location, may be collected using device sensors, GPS, and Bluetooth features, with your consent. If you enter a premise where Veris operates CCTV systems, your image and movements may be recorded as part of our access and authentication processes. However, we use this information at the directions of our Customers in order to provide our Services to you.
We collect and process your Personal Information for the following purposes:
A Third-Party Site refers to any external website, platform, or service that is not owned or operated by Veris but can be integrated with the Veris Applications. This includes, but is not limited to, organizational platforms, authentication services, and other digital tools that support Veris integration for login or credentialing purposes. As a User, if you choose to integrate your Veris Apps with a Third-Party Site, you may be asked to provide certain personal information, including your name, the specific URL associated with your organization’s Third-Party Site account, and your username or email address associated with such Third-Party Site (collectively hereinafter referred to as “Third Party Site Information”). Your use of Third-Party Sites in general and your relationship with such Third-Party Sites are subject to such Third-Party Sites’ own privacy policies and other terms and policies, which we strongly recommend that you review before you start using the Service or integrate any of your Veris Applications with such Third-Party Sites. We do not control and are not responsible for the processing of your information by Third Party Sites.
When you visit the Site, we may collect certain information by automated means, such as cookies. A cookie is a token that a server gives to your browser when you access a website. Cookies are capable of storing many types of data. Cookies help provide additional functionality to the site or to help us analyse site usage more accurately. For instance, it can “remember” your email address
to save your time. We also use cookies to track responses to our marketing materials, such as emails and online advertisements.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service. Examples of Cookies we use:
We may use web analytics services on the Site and Apps, such as those of Google Analytics. The service providers that administer these services use technologies such as cookies to help us analyse how visitors use the Site. The information collected through these means (including IP address) is disclosed to or collected directly by these service providers, who use the information to evaluate use of the website. To disable Google Analytics, please download the browser add–on for the deactivation of Google Analytics provided by Google at http://tools.google.com/dlpage/gaoptout.
All categories of information listed in Section 4 to 6 together with Third Party Information, are collectively referred to as “User Data”. The Company will use User Data for purposes of providing the Service and:
In addition, the Company may use User Data for the following purposes:
We may share User Data in the following cases:
Users and Customers have the flexibility to determine the retention period for their User Data, including Personal Data, on Veris Applications. The Company does not delete User Data during an active subscription unless explicitly instructed by the User or Customer. Upon termination of a contract with Veris or the contract of such organisation through which User’s data is provided to Veris, all User Data is deleted within 30 days or such other period as agreed with the Customers.
We work hard to ensure the safety of User Data using teams of engineers, automated systems, and advanced technology such as encryption, digital certificates, and machine learning. Additionally, we maintain strict administrative, technical, and physical safeguards to protect the User Data that we collect about you against accidental, unlawful, or unauthorized destruction, loss, alteration, access, disclosure, or use. We follow industry best practices for cybersecurity, including data encryption (AES-256 and TLS 1.3), access control, regular audits, and secure software development practices, aligning our controls with standards like ISO 27001 and SOC 2 type
The Company uses databases located in different jurisdictions to satisfy data residency requirements of its Customers. We may transfer User Data we collect about you to our databases located in countries other than your country of residence, including countries which have laws requiring a different level of data protection compared to your country of residence. We will take all the necessary steps to ensure that such transfers of User Data comply with applicable data protection laws, our respective Data Processing Agreements and in particular, the legal requirements on adequate protection for data transfers to countries outside of the EEA.
If you wish for Veris to stop collecting your Personal Information at any time, uninstall the Veris User App and logout from Veris Applications on all of your devices and contact your organization’s Veris Administrator or privacy team for further information. If applicable law requires and under the terms agreed with our customers, we will provide you with access to the User Data we have retained about you and the ability to review, correct, update, block or delete the information where it is inaccurate. Subject to applicable law, we may limit or deny access to your User Data where providing such access is unreasonably burdensome or expensive under the circumstances. Please submit your request to the address specified in the “Veris Contact Information” section above, or if you are accessing the Services through your employer, a business you provided services to, or through a company you visited, please contact such organisation.
If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights, covered by GDPR. See more at https://eur-lex.europa.eu/eli/reg/2016/679/oj
We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data. If you wish to be informed what Personal Data we hold about you and if you want
it to be removed from our systems, or make use of your data subject rights, you can contact us through our representative “Prighter” by visiting the following website: https://app.prighter.com/portal/19912759085 or contact us at dpo@veris.in .
In certain circumstances, you have the following data protection rights under GDPR:
Please note that we may ask you to verify your identity before responding to such requests and that we may not be able to provide Services without some necessary data.
You have the right to complain to a data protection authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the EEA. By law, you have a number of rights when it comes to your Personal Data. Further information and advice about your rights can be obtained from the data protection regulator in your country.
Our Services are not intended for use by children under the age of 16 (“Children”). We do not knowingly collect personally identifiable information from Children under 16. If you become aware that a Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we take steps to remove that information from our servers.
To process your request, we require at least three pieces of Personal Information and will attempt to match them with our records. Additionally, you must submit a signed declaration confirming your identity under penalty of perjury.
If we cannot verify your identity to the required level of certainty, we will be unable to fulfil your request. In such cases, we will notify you and explain the reason for denial. However, we will treat your request as one for disclosure of the categories of Personal Information we have collected about you and will attempt to verify your identity under the applicable, less-stringent standard.
To verify your request, we will ask for at least two pieces of Personal Information and attempt to match them with our records.
If we are unable to confirm your identity with the required level of certainty, we will be unable to process your request. In such cases, we will notify you and explain the reason for denial.
To process a deletion request, we will require at least two pieces of Personal Information and will attempt to match them with our records.
If we cannot verify your identity with the necessary level of certainty, we will be unable to proceed with the deletion. In such cases, we will notify you and explain the reason for denial.
The CCPA and CalOPPA applies only to the collection and use of the Personal Information of California residents by the Company. These legislations require a person or company in the United States that operates websites collecting personally identifiable information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals with whom it is being shared, and to comply with this policy. See more here :
According to CalOPPA we agree to the following:
We honour Do Not Track signals and do not track, plant cookies, or use advertising when a Do Not Track browser mechanism is in place. Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.
In Sections 4 to 6 above, and otherwise throughout this Notice, we discuss in detail the specific pieces of information we collect from and about users.
We may disclose the categories of personal information identified above for our operational purposes where the use is reasonably necessary and proportionate to achieve the operational purpose for which it was collected or processed, or for another compatible operational purpose.
We do share certain information as set forth in Section 4, 6 and 11 of this Notice, and allow third parties to collect certain information about your activity.
We aim to take reasonable steps to allow you to exercise your rights on your Personal Data. If you wish to be informed what Personal Information we hold about you and if you want to exercise any rights in relation to the same, please email us at privacy@veris.in.
In certain circumstances, you have the following data protection rights under the CCPA:
Subject to certain limits under California Civil Code § 1798.83, California residents may request certain information regarding the Company’s disclosure of their information to third parties for their direct marketing purposes. To make such a request, please contact us as specified in Section 2 of this Notice.
If you are residing within territory of India, you have certain data protection rights, covered by the DPDPA, as mentioned below
We aim to take reasonable steps to allow you to exercise your rights on your Personal Data. If you wish to be informed what Personal Information we hold about you and if you want to exercise any rights in relation to the same, please email us at privacy@veris.in.
In certain circumstances, you may be entitled to the following rights in relation to your Personal Data under the DPDPA:
The Services are not intended for users under the age of 18 (Permissible Age). We do not knowingly collect any personal information from users or market to or solicit information from anyone under the Permissible Age. If we become aware that a person submitting personal information is under the Permissible Age, we will delete the account and any related information as soon as possible. If you believe we might have any information from or about a user under the Permissible Age, please contact us at privacy@veris.in.
This Website is not directed at children below under the applicable permissible age and We cannot distinguish the age of persons who access and use our website. If a minor (according to applicable laws) has provided us with Personal Data without parental or guardian consent, the parent or guardian should contact us to remove the relevant Personal Data and unsubscribe the minor. If we become aware that Personal Data has been collected from a person under the applicable permissible age without parental or guardian consent, we will delete this Personal Data and, where that minor has an account, terminate the minor's account.
The Site and Services may contain links to other sites that are not operated by us. If you click a third-party link, you will be directed to that third party’s site. We strongly advise you to review the privacy policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.
This Notice may be updated periodically and without prior notice to you to reflect changes in our information processing practices or for any other purpose. We will post a notice on the Site to notify you of any significant changes to the Notice and indicate there and at the top of the Notice when it was most recently updated.
Definitions
For the purposes of this Privacy Notice, the following terms shall have the meanings set forth below:
"Administrator" or “Admin” means an individual designated by a Customer to manage and configure Veris Applications on behalf of their organization, with elevated access privileges to User Data and system settings.
“Veris User Apps” or “Apps” or “Veris Applications” means the software application provided by Veris and any other mobile or desktop applications provided by Veris that facilitate access to Services
"Biometric Data" means unique biological characteristics used for identification purposes, including but not limited to fingerprints, voice patterns, facial geometry, iris patterns, and other physiological or behavioral characteristics collected through Veris Applications.
"Company" or "Veris" or "we" means Digicred Technologies Private Limited, a company incorporated under the laws of India, and its affiliates, subsidiaries, and successors.
"Customer" means any organization, entity, or business that has entered into an agreement with Veris to use the Services, and through which Users may access Veris Applications.
"Data Controller" means the entity that determines the purposes and means of processing Personal Information. In most cases, the Customer acts as the Data Controller for their Users' data processed through Veris Applications.
"Data Processor" means an entity that processes Personal Information on behalf of and under the instructions of a Data Controller. Veris typically acts as a Data Processor when providing Services to Customers.
"Data Subject" means an identified or identifiable natural person whose Personal Information is processed through the Services.
"Device Information" means technical information automatically collected from devices used to access Veris Applications, including device identifiers, IP addresses, operating system details, browser information, and mobile device characteristics.
"Mobile Location Data" means information about the physical location of a user's device, collected through GPS, Bluetooth beacons, Wi-Fi networks, cellular towers, or other location-determining technologies integrated with Veris Applications.
“Location Data” means information about the physical location of a User collected upon their use of the Veris application to access a premise or reserve a desk or meeting room or parking space pertaining to the Customer that uses Veris Services.
"Memberbook" means the employee directory feature within Veris Applications that contains User profiles, contact information, and organizational hierarchy data.
"Personal Information" or "Personal Data" or "PI" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular individual, including but not limited to names, email addresses, phone numbers, photographs, biometric identifiers, location data, and device identifiers.
"Processing" means any operation or set of operations performed on Personal Information, whether or not by automated means, including collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, restriction, erasure, or destruction.
"Services" means all software applications, platforms, devices, websites, mobile applications, and related services provided by Veris, including all products listed in Section 1 of this Notice.
"Site" means any website operated by Veris, including but not limited to www.getveris.com , www.veris.in , www.veris.cc and associated subdomains.
"Third-Party Site" means any external website, platform, application, or service that is not owned, operated, or controlled by Veris but may integrate with or be accessed through Veris Applications.
"Usage Information" means data about how Users interact with Veris Applications, including login times, feature usage patterns, access requests, door unlock events, meeting attendance, space bookings, and other activity logs generated through use of the Services.
"User" or "Users" means any individual who uses, accesses, or interacts with the Services, including employees, visitors, contractors, and other persons whose information is processed through Veris Applications.
"User Data" means all Personal Information and other data collected, processed, or generated in connection with a User's interaction with the Services, including but not limited to contact information, biometric data, usage information, Location Data, and device information.
"Veris Applications" or "Veris Apps" means all software applications provided by Veris, including mobile apps, web portals, terminal applications, and administrative interfaces that comprise the Services.
"Veris Badge" means a digital or physical credential issued through Veris Applications that enables access to physical locations, systems, or services within a Customer's environment.
"Veris Invite" or “Invite” means an electronic invitation sent through Veris Applications to facilitate visitor registration, meeting scheduling, or system access for external parties.
"Veris Organization" means the ecosystem of Users, Customers, and connected systems within a particular organization's deployment of Veris Applications.
"Visitor" means any individual who is not a regular employee or member of a Customer organization but who visits, accesses, or uses the Customer's premises or services, and whose information is processed through Veris Applications.