1. About this Privacy Policy
Zoqi is a business-to-business AI-powered data analytics platform operated by NviSust Innovations Private Limited (“Zoqi”, “NviSust”, “we”, “us” or “our”).
Zoqi enables authorised users of business customers to connect supported databases and data sources, ask questions in natural language and receive generated queries, analytical results, explanations, reports and visualisations.
Zoqi is intended for businesses, institutions and professional users. It is not offered as a consumer service.
This Privacy Policy explains how we process personal data relating to:
- Visitors to zoqiai.com;
- Prospective and existing business customers;
- Customer representatives and administrators;
- Authorised Zoqi workspace users;
- Partners, suppliers and service providers; and
- Individuals whose information may be contained in systems connected by our customers.
This Privacy Policy is intended to support compliance with applicable data protection laws, including, where relevant, the Indian Digital Personal Data Protection Act and Rules, the EU GDPR, UK GDPR, California CCPA/CPRA, Brazilian LGPD and comparable privacy laws.
References to these laws do not mean that every law applies to every Zoqi customer or processing activity.
2. Our Role and the Customer’s Role
Zoqi may process personal data in two different roles.
Zoqi as a controller or Data Fiduciary
Zoqi determines how and why personal data is processed when handling:
- Website and sales enquiries;
- Business contact information;
- Account administration;
- Billing and contractual records;
- Product usage and security logs;
- Support requests;
- Supplier and partner information; and
- Zoqi’s own business operations.
Zoqi as a processor or Data Processor
When a customer connects its databases, documents, systems or integrations to Zoqi, the customer generally acts as the controller or Data Fiduciary and Zoqi acts as its processor or Data Processor.
The customer determines:
- What data is connected;
- Which users may access it;
- The purposes for which it is analysed;
- The applicable access restrictions;
- The appropriate legal basis;
- Applicable retention requirements; and
- Whether individuals must receive additional privacy notices.
Zoqi processes Customer Data according to the customer’s documented instructions, the applicable customer agreement and, where executed, a Data Processing Agreement.
Where this Privacy Policy conflicts with a signed customer agreement or Data Processing Agreement regarding Customer Data, the signed agreement will control to the extent permitted by law.
3. Information We Process
Depending on the customer’s deployment, configuration and use of Zoqi, we may process the following information.
Business and contact information
- Name;
- Work email address;
- Business telephone number;
- Job title;
- Company or organisation;
- Country or business location;
- Sales enquiry details;
- Support communications; and
- Meeting, onboarding or demonstration information.
Account information
- User name and business email;
- Organisation and workspace membership;
- Authentication identifiers;
- User roles and permissions;
- Account settings;
- Single sign-on identifiers; and
- Account activity.
Database and integration information
- Database type and connection configuration;
- Schema, table and column information;
- Metadata, relationships and data types;
- Semantic definitions and business terminology;
- Connection credentials, tokens or certificates;
- Integration identifiers;
- Permission scopes; and
- Connection and synchronisation status.
Credentials and secrets may be stored using security controls appropriate to the selected deployment. Customers should use read-only credentials and provide only the minimum permissions necessary.
Prompts and analytical information
- Natural-language questions;
- Conversation history;
- Generated SQL or other queries;
- Query execution information;
- Query results;
- Saved reports and dashboards;
- Charts, summaries and explanations;
- User feedback; and
- Scheduled report configurations.
Technical and usage information
- IP address;
- Device and browser details;
- Login and authentication events;
- Feature usage;
- Error and diagnostic information;
- Audit logs;
- Date and time of activity; and
- Security-related information.
Billing and contractual information
- Billing contacts;
- Company address;
- Subscription and invoice information;
- Payment status;
- Tax information; and
- Contract and procurement records.
Payment details may be processed directly by an authorised payment provider. Zoqi may receive transaction references and payment status without receiving complete payment-card information.
4. Customer Data and AI Processing
Zoqi uses artificial-intelligence technologies to interpret user questions, understand database structures, generate queries and prepare analytical responses.
Zoqi is designed so that schema information, metadata and business definitions can be used to generate queries without ordinarily sending complete raw database records to the query-generation model.
Depending on the deployment and requested functionality, query results may be processed to generate explanations, summaries, charts or reports.
Customer Data will be processed only as necessary to:
- Provide the contracted services;
- Execute authorised customer instructions;
- Maintain security and reliability;
- Provide support;
- Comply with applicable law; or
- Fulfil another purpose agreed with the customer.
Unless a customer expressly authorises it in writing, Zoqi will not use identifiable Customer Data to train publicly available or general-purpose AI models.
Zoqi may use aggregated or appropriately de-identified information to operate, secure, measure and improve the service, provided that such information does not reasonably identify the customer or an individual.
AI-generated queries, explanations and reports may occasionally be inaccurate or incomplete. Customers and authorised users are responsible for reviewing outputs before relying on them for material business, financial, employment, legal, healthcare, regulatory or other high-impact decisions.
5. How We Use Personal Data
We may use personal data to:
- Create and administer Zoqi accounts;
- Authenticate users and manage permissions;
- Connect authorised data sources;
- Generate and execute queries;
- Provide reports, explanations and visualisations;
- Operate integrations and scheduled reports;
- Provide customer support and onboarding;
- Process subscriptions and payments;
- Secure the platform and prevent misuse;
- Maintain audit and operational records;
- Diagnose errors and improve performance;
- Communicate service and security updates;
- Respond to sales enquiries;
- Send permitted business communications;
- Enforce customer agreements;
- Protect our rights and systems;
- Comply with legal obligations; and
- Establish, exercise or defend legal claims.
Where required by applicable law, processing will be based on contractual necessity, legitimate interests, consent, legal obligations or another recognised legal basis.
6. How We Disclose Information
We may disclose personal data to:
Authorised service providers
We may use carefully selected providers for infrastructure, cloud hosting, AI processing, authentication, monitoring, communication delivery, analytics, billing, customer support and security.
These providers may process information only for authorised purposes and are subject to contractual confidentiality and data-protection obligations.
A current subprocessor list may be provided to business customers separately or under the applicable customer agreement.
Customer administrators
A customer’s authorised administrators may access and manage:
- Workspace users;
- Permissions;
- Connected data sources;
- Prompts and reports;
- Usage records;
- Audit logs; and
- Other information relating to their organisation’s Zoqi workspace.
Professional advisers
Information may be shared with legal advisers, accountants, auditors, insurers and consultants where reasonably necessary.
Authorities and legal recipients
We may disclose information where reasonably necessary to:
- Comply with applicable law or a lawful request;
- Respond to a court order;
- Investigate fraud, misuse or security incidents;
- Enforce an agreement;
- Protect the rights or safety of Zoqi or others; or
- Establish, exercise or defend legal claims.
Where legally permitted and reasonably practical, we may notify the affected customer before disclosing Customer Data in response to a government request.
Corporate transactions
Information may be disclosed in connection with a merger, financing, acquisition, restructuring, sale of assets or similar corporate transaction, subject to appropriate confidentiality protections.
Zoqi does not sell personal data for monetary consideration or use Customer Data for third-party behavioural advertising.
7. International Data Transfers
Zoqi and its authorised providers may process information outside the country in which a customer or user is located.
Where required by applicable law, Zoqi may implement appropriate transfer safeguards, including:
- Contractual data-protection clauses;
- Standard Contractual Clauses;
- Approved transfer addenda;
- Data Processing Agreements;
- Access restrictions;
- Encryption or equivalent safeguards; and
- Customer-selected private or self-hosted deployment arrangements.
Available data-location and deployment options may depend on the applicable customer plan and agreement.
8. Data Security
Zoqi uses reasonable technical and organisational measures appropriate to the nature of the information, the selected deployment and the associated risks.
Measures may include:
- Read-only database access;
- Encryption during transmission;
- Access controls and user permissions;
- Authentication controls;
- Secure-tunnel or private-network options;
- Credential and secret management;
- Logging and auditing;
- Environment and customer separation;
- Backup and recovery procedures;
- Security monitoring; and
- Incident-response procedures.
Customers remain responsible for:
- Securing their databases and infrastructure;
- Configuring appropriate user permissions;
- Using read-only credentials;
- Protecting account credentials;
- Reviewing connected data sources;
- Restricting access according to business need; and
- Maintaining lawful and secure use of exported reports and results.
No electronic system can be guaranteed to be completely secure. Zoqi therefore does not warrant absolute security or that every attempted intrusion, misuse or unauthorised access will be prevented.
Where a personal-data breach occurs, Zoqi will investigate and provide notifications where required by applicable law or the relevant customer agreement.
9. Data Retention
We retain personal data only for as long as reasonably necessary to:
- Provide the service;
- Maintain business and contractual records;
- Protect platform security;
- Resolve disputes;
- Enforce agreements; and
- Meet legal, tax, accounting or regulatory requirements.
Customer Data is retained according to the customer’s configuration, applicable agreement and documented instructions.
Following termination, Customer Data may be deleted or returned in accordance with the applicable customer agreement. Residual copies may remain temporarily in secure backups until they are overwritten through ordinary backup cycles.
We may retain aggregated or de-identified information where it no longer reasonably identifies an individual or customer.
10. Privacy Rights
Depending on the applicable law and the individual’s location, an individual may have rights to:
- Request information about processing;
- Access personal data;
- Correct inaccurate data;
- Request deletion;
- Restrict or object to processing;
- Withdraw consent;
- Receive certain data in a portable format;
- Opt out of permitted marketing;
- Opt out of sale, sharing or targeted advertising where applicable;
- Request review of certain automated processing; and
- Submit a complaint or grievance.
These rights are subject to legal limitations and exceptions.
Where personal data is controlled by a Zoqi business customer, the individual should first contact that customer. Zoqi will provide reasonable assistance to the customer where required by law or contract.
Zoqi may request information necessary to verify the identity and authority of a person making a request.
11. Cookies and Business Communications
Zoqi may use essential cookies and similar technologies for authentication, security, session management and platform operation.
Analytics or marketing technologies may be used where permitted by law and, where required, after obtaining consent.
Business contacts may receive information about Zoqi products, services or events where legally permitted. Recipients may unsubscribe from promotional emails, but may continue to receive essential contractual, billing, account and security communications.
12. Sensitive and Regulated Data
Customers must not connect or submit sensitive, special-category, regulated or high-risk personal data unless:
- The processing is necessary for an authorised business purpose;
- The customer has established an appropriate legal basis;
- The processing is permitted by the customer agreement;
- Required notices and consents have been provided;
- Appropriate access restrictions are implemented; and
- Any required assessment or regulatory approval has been completed.
Customers are solely responsible for determining whether their use of Zoqi is subject to sector-specific laws relating to healthcare, finance, employment, education, children, government records or other regulated activities.
13. Children
Zoqi is a B2B service and is not intended for individuals under 18 years of age.
Customers must not use Zoqi to process children’s personal data unless such processing is lawful, contractually authorised and protected by appropriate safeguards.
14. Third-Party Services
Zoqi may integrate with third-party databases, identity providers, communication platforms and other services.
Third-party services are governed by their own terms and privacy practices. Zoqi is not responsible for services that it does not own or control.
Customers are responsible for reviewing and approving third-party integrations before enabling them.
15. Changes to This Policy
We may update this Privacy Policy to reflect legal, technical, operational or product changes.
The updated version will be published with a revised “Last updated” date. Where required by law or contract, we will provide additional notice of material changes.
16. Contact and Grievances
Privacy enquiries, rights requests and grievances may be submitted to:
NviSust Innovations Private Limited
TPHT LHS PLTF 100,
Thripunithura Metro Station,
Thripunithura, Ernakulam, 682301
Website: zoqiai.com