Privacy Policy
Learn how XpertLync Solutions Pvt. Ltd collects, uses, and protects your data when you use the Valideur platform.
Last Updated: October 9, 2026
This Privacy Policy describes the policies and procedures of XpertLync Solutions Pvt. Ltd, Hyderabad ("we", "our", or "us") on the collection, use, and disclosure of your information when you use the Valideur website and platform services.
1. Information We Collect
We collect information to provide better services to all our users. The types of personal information we collect include:
- Account Information: Name, business email address, company name, role, and phone number when you request a demo or register for our platform.
- Usage Data: Information about how you interact with our platform, including access logs, IP addresses, browser types, and navigation paths.
- Platform Data: Data you input into the Valideur GRC platform regarding your organization's risk assessments, audit logs, and compliance evidence. This data is strictly segregated and encrypted.
2. How We Use Your Data
XpertLync Solutions Pvt. Ltd uses the collected data for the following purposes:
- To provision, operate, and maintain the Valideur GRC platform.
- To process and complete transactions, and send related information including transaction confirmations and invoices.
- To send technical notices, updates, security alerts, and support messages.
- To respond to your comments, questions, and requests and provide customer service.
- To monitor and analyze trends, usage, and activities in connection with our services.
3. Data Security & Storage
Security is at the core of Valideur. We implement advanced, industry-standard security measures including:
- Encryption: Data is encrypted at rest using AES-256 and in transit using TLS 1.3.
- Access Controls: Strict Role-Based Access Controls (RBAC) and mandatory MFA for administrative access.
- Infrastructure: We utilize secure, compliant cloud infrastructure providers (such as AWS) located in specific geographical regions to comply with data residency requirements.
4. Global Compliance (GDPR, CCPA, DPDP)
As a Governance, Risk, and Compliance platform, we adhere to the highest global data protection standards, including the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and India's Digital Personal Data Protection (DPDP) Act.
We act as a Data Processor for the compliance data you upload to the Valideur platform, and as a Data Controller for your account and billing information.
5. Your Privacy Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you.
- Request the correction of inaccurate personal information.
- Request the deletion of your personal information (Right to be Forgotten).
- Object to or restrict the processing of your data.
- Request data portability.
Data Protection Officer (DPO) & Data Subject Requests
XpertLync Solutions Pvt. Ltd has appointed a Data Protection Officer to oversee compliance with global privacy regulations. For any DPO-related information, inquiries regarding this Privacy Policy, or to submit a Data Subject Access Request (DSAR), please refer to our dedicated corporate privacy portal.
Visit XpertLync Privacy CenterContact Us
If you have general questions about Valideur's privacy practices, you can reach out to us at:
