Legal
Privacy Policy
Effective date: 26 September 2026 · vetro.co.in
01 · Overview
Overview
This Privacy Policy describes how Vetro ("we", "us", or "our") collects, uses, and safeguards personal data in connection with vetro.co.in and our AI assurance services.
We are an AI assurance and governance firm. We assess and instrument the AI systems our clients run: adversarial security testing, accuracy evaluation, governance and policy, monitoring and incident response, and cost control.
This policy applies to three groups of people:
- Website visitors - anyone who browses vetro.co.in.
- Prospective and current clients - individuals who submit our enquiry form, book a call, or engage us.
- People whose data sits inside a client's AI systems - most often a client's own users, whose personal data can appear in prompts, conversation logs, retrieval corpora or traces that we read while doing the work. Sections 04 and 05 explain how that is handled and on whose authority.
This policy is written under India's Digital Personal Data Protection Act, 2023 ("DPDP Act"). Under that Act we are a Data Fiduciary and you are a Data Principal.
02 · Information We Collect
What We Collect
From the enquiry form
We collect only what you type into it:
- Name and work email - required, so we can reply.
- Company and your role - optional context.
- What you have in production and your biggest concern - optional, to judge whether we are a sensible fit before either side spends time.
- What you want to improve - whatever you choose to write.
The form is delivered by Web3Forms, a third-party form service, and arrives in our email inbox, which is hosted by Google. It is not stored in a database on this website.
Automatically, when you visit
This site sets no cookies and runs no analytics. We do not build a profile of your browsing.
Loading this page contacts no third-party server other than our host. The typeface, the hero animation and every graphic are served from this site, so no font service, CDN, or analytics provider is told that you visited. Our hosting provider processes standard request data (IP address, requested page, browser type) to serve the page. Other third parties are involved only if you take an action: submitting the enquiry form, or following the booking link.
When you book a call
The booking link takes you to Cal.com, a separate service with its own privacy policy. Whatever you enter there is collected by Cal.com and shared with us as the meeting host.
03 · Purpose
How We Use It
We use personal data only for the purpose it was given for:
- To reply to you - answering enquiries, preparing an AI audit, scoping work.
- To deliver the work - running the audit, building eval sets and tracing, writing policy and controls, and reporting findings.
- To administer the relationship - contracts, invoicing, and statutory accounting records.
- To improve our own methods - in de-identified form only, and never using one client's data on another's work. See section 07.
We do not sell personal data, and we do not share your contact details with anyone for their own marketing.
04 · Client Systems
Data In Client Systems
Assessing an AI system means reading what is inside it. This is the most significant personal data we come near, and almost none of it is ours.
What we may see
- Prompts and conversation logs - which frequently contain whatever a client's own users typed, including things they had no reason to expect a third party would read.
- Retrieval corpora - the documents a system answers from, which may be internal records about identifiable people.
- Traces and tool-call records - inputs, arguments and results of actions the system took on someone's behalf.
- Evaluation sets - which we build from real inputs, because synthetic ones do not measure anything useful.
Whose data it is
The client is the Data Fiduciary for all of it. We handle it only on their instructions and only to deliver the work they engaged us for. We are not a Data Fiduciary in respect of their users, and we do not decide what happens to that data.
What we do about it
- We work inside the client's own environment wherever the task allows, so the data does not move.
- Where an eval set has to be assembled, we redact identifiers at the point of capture and keep the smallest set that still measures the behaviour.
- We do not copy client data into our own systems for our own purposes, never use it to train anything, and never carry it from one client's engagement into another's.
- It is deleted on the timetable in section 07, and sooner on request.
If you are a client's user rather than our client, we are handling your data on their behalf and cannot act on it independently - so requests about it should go to the organisation whose service you used. Write to vetro.team.admin@gmail.com anyway if you cannot reach them, and we will pass it on and tell you we have.
05 · Delegated Access
Delegated Access
To audit and instrument their systems, clients grant us read-only delegated access to their own tooling - typically source repositories, model-provider consoles, observability platforms, and cloud IAM.
- Access is granted through each platform's own permission system, against our own named accounts.
- We never ask for, store, or accept passwords. If you are a client and someone asks you for a password on our behalf, refuse and tell us.
- We request the narrowest role that lets us do the work, and we ask to have access revoked when an engagement ends.
The audit itself is read-only and changes nothing. Where later work needs write access, it is scoped to a named system and agreed in advance rather than granted broadly at the start. What these systems expose about a client's own users is covered by section 04.
06 · AI
AI-Assisted Processing
We use AI tools to speed up parts of our work - drafting findings, summarising traces and logs, and generating candidate test cases for adversarial testing. A human reviews the output before anything reaches a client or gets published.
We do not send client data to any third-party AI provider without the client's prior written approval. Where a client approves it, the provider, the purpose and the provider's retention terms are named in writing before any data is sent, and we send the minimum the task requires, with personal data excluded wherever the work allows.
We do not use AI to make automated decisions that produce a legal or similarly significant effect on any individual. Findings are drafted with AI assistance and every one is verified by a person before it is reported - which is the same standard we would hold a client to.
07 · Retention
Retention
We keep personal data only as long as it serves the purpose it was collected for:
- Enquiries that do not become clients - deleted after 24 months of no contact.
- Client system data - anything we hold outside the client's own environment (extracts, eval sets, trace exports) is deleted within 30 days of the engagement ending, or sooner on the client's instruction.
- Client records - kept for the engagement, then as long as Indian tax and companies legislation requires us to retain financial records.
- Our own methodology notes - what a class of finding looks like and which checks caught it, retained without a fixed limit in aggregate, de-identified form. These hold no client names, no personal data, and nothing that could identify whose system a finding came from.
Deletion requests are honoured regardless of these periods, except where we are legally required to keep a record.
08 · Third Parties
Third-Party Services
These are every third party involved in running this website and our service. Apart from our hosting provider, none of them is contacted by simply loading a page - they engage only when you submit the form, follow the booking link, or email us.
- Railway - hosts this website. railway.com/legal/privacy
- Web3Forms - delivers the enquiry form to our inbox. web3forms.com/privacy
- Google - hosts our email, where enquiries and correspondence are received. policies.google.com/privacy
- Cal.com - call booking. cal.com/privacy
- Client-owned platforms - source control, model providers, observability and cloud consoles, accessed read-only under delegated client permission, as described in section 05.
- AI providers - used for drafting and summarising as described in section 06, and for client data only with that client's prior written approval.
Some of these operate outside India. Where personal data is transferred abroad, it is transferred only as necessary to provide the service described.
09 · Cookies
Cookies & Tracking
This website sets no cookies at all. There is no analytics script, no advertising pixel, no localStorage use, and no cross-site tracking. That is why you are not being shown a cookie banner - there is nothing to consent to.
If we ever add analytics, this section will be updated before it goes live, and a consent mechanism added if the tool requires one.
10 · Your Rights
Your Rights
Under the DPDP Act, as a Data Principal you have the right to:
- Access - a summary of the personal data we hold about you and how we are processing it.
- Correction and completion - to have inaccurate or incomplete data fixed.
- Erasure - to have your data deleted, unless we are legally required to keep it.
- Withdraw consent - at any time, as easily as you gave it.
- Grievance redressal - to complain to us first, and then to the Data Protection Board of India if we do not resolve it.
- Nomination - to nominate someone to exercise these rights on your behalf in the event of death or incapacity.
To exercise any of these, email vetro.team.admin@gmail.com. We respond within 30 days. We may need to confirm your identity first, and we will not charge you for this.
11 · Contact
Grievance Officer
The DPDP Act requires us to publish a contact point for privacy complaints. That is:
- Entity - Vetro
- Privacy contact - vetro.team.admin@gmail.com
If you are not satisfied with how we handle your complaint, you may escalate it to the Data Protection Board of India.
Changes to this policy
If we change how we handle personal data, we will update this page and move the effective date at the top. Material changes will be communicated directly to active clients and, where we hold a contact address for you, to anyone else affected.
This version took effect on 26 September 2026.