Vezel
Vezel
  • HomeHome
  • SolutionSolution
  • How It WorksHow It Works
  • DemosDemos
  • BlogBlog
  • Book a DemoBook a Demo
Book a DemoBook a Demo
Vezel
Vezel

Howdy!

Embedded AI extension platform making every SaaS customizable and loved by users.

Vezel
Vezel AI
Vezel AI

Popular searches

  • UI / UX Design
  • Photography
  • Digital Marketing
  • Creative
  • Innovative
  • Visionary
  • Disruptive
  • Adaptive
  • Reliable
  • Scalable
  • Impactful
  • Dynamic
HomeLegalPrivacy Policy
Legal & Data GovernanceLegal & Data Governance

Privacy Policy

This Privacy Policy sets forth how NEOCORTEX AI PRIVATE LIMITED (“Company”, “we”, “us”, or “our”) collects, processes, safeguards, and respects personal data and technical telemetry across Vezel (“Vezel AI”), our embedded AI extension builder, and our website (https://vezel.ai).

Registered Entity:NEOCORTEX AI PVT LTD
Jurisdiction:India
Effective Date:October 6, 2026
Last Updated:October 6, 2026
Zero Model Training

We never use customer proprietary business data, schema metadata, or prompts to train foundation AI models.

Tenant-Isolated Runtime

Generated extensions execute within sandboxed browser environments that strictly enforce host SaaS permissions and RBAC.

Dual Role Clarity

Clear segregation between our role as Data Controller/Fiduciary and Data Processor on behalf of host SaaS platforms.

Global Compliance

Aligned with India's DPDP Act 2023, the Information Technology Act 2000, GDPR (EU/UK), and California's CCPA/CPRA.

Table of Contents
  • 01Introduction & Corporate Identity
  • 02Dual Roles: Fiduciary / Controller vs. Processor
  • 03Categories of Data We Collect
  • 04AI Data Governance & Zero-Training Guarantee
  • 05Purposes & Legal Grounds for Processing
  • 06Data Sharing, Sub-processors & Disclosures
  • 07Cross-Border & International Data Transfers
  • 08Enterprise Security & Protection Standards
  • 09Data Retention & Secure Sanitization
  • 10Your Statutory Rights Across Jurisdictions
  • 11Cookies & Tracking Technologies
  • 12Children's Privacy Protection
  • 13Updates & Amendments to This Policy
  • 14Statutory Grievance Officer in India & Contact
Enterprise Compliance?

Need a tailored Data Processing Addendum (DPA) or security whitepaper?

Contact Privacy Team
Section 01

1. Introduction & Corporate Identity

Welcome to Vezel. This Privacy Policy (“Policy”) governs the collection, processing, storage, and disclosure of personal data and operational technical telemetry by NEOCORTEX AI PRIVATE LIMITED, a private company duly incorporated and registered under the laws of the Republic of India (hereinafter referred to as “Company”, “Neocortex AI”, “we”, “us”, or “our”).

Neocortex AI operates the Vezel platform (accessible via https://vezel.ai, related subdomains, client dashboards, software development kits (“SDKs”), application programming interfaces (“APIs”), command-line tools, and embedded runtime environments, collectively the “Platform” or “Services”).

Vezel is an embedded AI extension builder that enables B2B Software-as-a-Service (“SaaS”) companies to deliver Adaptive SaaS. By embedding Vezel into their core applications, our SaaS customers allow their users to declare, generate, and run custom workflows, interactive dashboards, dynamic forms, tailored reports, and contextual generative UI experiences directly inside the host SaaS environment—without altering the host application's underlying standardized codebase.

This Policy explains your privacy rights and how we handle information in our dual capacities: as a Data Fiduciary / Controller for direct interactions, and as a Data Processor when embedded within host SaaS platforms.

Section 02

2. Dual Roles: Data Fiduciary / Controller vs. Data Processor

Under data protection frameworks—including India's Digital Personal Data Protection Act, 2023 (“DPDP Act”), the European Union's General Data Protection Regulation (“GDPR”), and the United Kingdom's UK GDPR—data responsibilities depend upon our relationship with you:

A. Neocortex AI as Data Fiduciary / Controller

We act as a Data Fiduciary (or Data Controller) with respect to personal data collected directly from visitors to our website (vezel.ai), prospective enterprise buyers booking product demos, direct enterprise account administrators, developers signing up for developer keys, and recipients of our direct business marketing and billing communications.

B. Neocortex AI as Data Processor

When our B2B SaaS Customers embed the Vezel SDK or runtime inside their own software platform, the SaaS Customer is the Data Fiduciary / Controller of end-user data. Neocortex AI acts strictly as a Data Processor, processing extension prompts and runtime execution payloads strictly pursuant to the Customer Agreement, Data Processing Addendum (DPA), and the host product's authorization rules.

If you are an end-user accessing an extension generated via Vezel within a third-party host SaaS product, the privacy practices, access permissions, and data retention rules of that host SaaS company govern your personal data. You should review their privacy policy or direct data rights requests to them directly.

Section 03

3. Categories of Data We Collect

Depending on how you interact with our Platform, we collect and process the following categories of data:

3.1 Information You Provide Directly to Us
  • Account & Commercial Profile Data: Full name, professional work email address, phone number, corporate employer name, job title, department, username, cryptographic password hash, and developer authentication credentials.
  • Billing & Tax Information: Corporate billing address, business registration numbers, Goods and Services Tax Identification Number (“GSTIN”) in India, VAT numbers, and transaction records. Payment card details are captured and processed directly by our PCI-DSS Level 1 certified payment processor (e.g. Stripe); we never store raw credit card numbers or CVV codes.
  • Communications & Demo Notes: Information submitted via contact forms, inquiries sent to hello@vezel.ai, calendar booking notes entered through Cal.com, and customer support ticket logs.
3.2 Host Platform Integration Context & Extension Blueprints
  • Host Application Schema & Metadata: To render seamless, native extensions that conform to your existing product, our SDK ingests schema definitions, API endpoints, entity metadata, design system tokens (colors, typography, spacing), and role-based permission scopes declared by our SaaS Customers.
  • Natural Language Prompts & Declarations:User instructions, natural language prompts (e.g., “Generate a custom churn analysis dashboard for tier-1 accounts”), and workflow constraints provided by authorized users to build extensions.
  • Generated Blueprints & Abstract Syntax Trees (ASTs): The structural blueprints, layout configurations, component hierarchies, and client-side reactive logic compiled by the Vezel platform engine to render dynamic widgets.
3.3 Technical, Device & Automated Telemetry
  • Diagnostic Telemetry:Internet Protocol (“IP”) address, browser type and version, user agent string, operating system, time zone, system locale, referring URLs, and API latency metrics.
  • Runtime Error Logs & Audit Traces: Compilation errors, sandbox exception traces, token counts, and execution timestamps necessary to debug system anomalies, optimize compiler heuristics, and maintain security integrity.
Section 04

4. AI Data Governance & Zero-Training Guarantee

Enterprise trust is the non-negotiable core of Adaptive SaaS. We adhere to rigorous AI governance principles designed specifically for enterprise B2B environments:

OUR FIRM GUARANTEE
Zero AI Model Training

NEOCORTEX AI PRIVATE LIMITED does NOT use your proprietary enterprise data, host SaaS data payloads, customer schema configurations, or private prompt declarations to train, retrain, or fine-tune public foundation AI models (including third-party frontier Large Language Models). Your data remains strictly segregated and proprietary to you.

  • Tenant-Isolated Sandboxing:Generated extensions execute in isolated client-side sandbox environments. Runtime components inherit the host product's existing session cookies, tokens, and role-based access control (RBAC). Vezel never bypasses the host platform's security or authorization perimeter.
  • Ephemeral Inference Processing: Operational business data queried by generated widgets or custom forms is processed ephemerally in-memory for the duration of the active render cycle. We do not maintain secondary data stores of your operational business records.
  • Enterprise API Agreements: Where third-party enterprise LLM infrastructure is utilized to compile blueprints, processing occurs under strict zero-data-retention (ZDR) and enterprise confidentiality agreements prohibiting the provider from retaining or learning from prompt inputs.
  • Aggregated Compiler Telemetry: De-identified, aggregated compilation metadata, latency numbers, and token volumes may be analyzed to improve compiler performance, system resilience, and runtime execution efficiency without accessing proprietary customer records.
Section 05

5. Purposes & Legal Grounds for Processing

We process personal data only when an applicable legal basis exists under India's DPDP Act, the EU/UK GDPR, or other applicable jurisdictions:

Processing PurposeData Categories InvolvedLegal Basis (DPDP / GDPR)
Platform Hosting & Delivery
Delivering and operating the Vezel SDK runtime
Account credentials, host schema metadata, extension blueprintsContractual Necessity; Legitimate Uses (DPDP Sec 7)
Blueprint Compilation & Execution
Compiling user prompts into dynamic UI widgets & workflows
Natural language prompts, UI state, developer configurationsContractual Necessity; Customer Instructions (as Processor)
Billing & Tax Accounting
Processing invoices, taxes, and accounting records
Billing address, tax identifiers (GSTIN), payment transaction tokensLegal Obligation; Contractual Necessity
Diagnostics & Security
System monitoring, latency optimization, incident forensics
IP addresses, runtime crash reports, audit traces, telemetryLegitimate Interests; Security of Information Technology
Sales & Customer Support
Responding to demo inquiries and technical support tickets
Contact info, communication history, meeting notesConsent; Legitimate Interests
Statutory Compliance
Compliance with Indian statutory audits and regulatory orders
Account records, corporate filings, transaction historyCompliance with Law (DPDP Act, IT Act, Companies Act 2013)
Section 06

6. Data Sharing, Sub-processors & Disclosures

We do not sell, rent, lease, or monetize your personal data. We disclose personal data only under the following limited, legally defined circumstances:

  • Authorized Sub-processors & Cloud Infrastructure: We engage vetted enterprise third-party vendors who assist in hosting, database operations, communication, and infrastructure delivery. All sub-processors are bound by strict contractual Data Processing Agreements (DPAs) requiring confidentiality and security standards at least as protective as those in this Policy. Typical categories include:
    • • Cloud Hosting & Content Delivery Networks (e.g. Amazon Web Services, Google Cloud Platform, Vercel)
    • • Managed Relational Database Services (e.g. PostgreSQL, Supabase, Neon)
    • • Enterprise AI Inference Infrastructure (providing zero-data-retention APIs)
    • • Payment Gateways (e.g. Stripe, for PCI-DSS compliant billing)
    • • Scheduling & Customer Communication Tools (e.g. Cal.com, transactional email relays)
  • Host SaaS Platform Integration:When you build or interact with an extension embedded inside a host SaaS application, your actions and operational data flow within that host application in accordance with the host customer's permissions.
  • Corporate Transactions: In the event of a merger, acquisition, corporate restructuring, sale of company assets, or financing, user records may be transferred as a business asset under appropriate non-disclosure and continuity protections.
  • Statutory Disclosures & Law Enforcement: We may disclose information if required to do so by applicable law, court order, regulatory direction, or formal notice from law enforcement agencies or courts of competent jurisdiction in India or internationally.
Section 07

7. Cross-Border & International Data Transfers

Neocortex AI Private Limited is headquartered in India. Our cloud infrastructure and sub-processors operate across secure data centers located in India, the United States, and the European Union.

When personal data is transferred across national borders:

  • Transfers from the EEA / UK: We rely on European Commission-approved Standard Contractual Clauses (“SCCs”) and the UK International Data Transfer Addendum, supplemented by rigorous technical safeguards (including in-transit and at-rest encryption).
  • Transfers under Indian Law: We comply with all cross-border transfer directives, statutory guidelines, and negative-list restrictions issued under the Digital Personal Data Protection Act, 2023.
Section 08

8. Enterprise Security & Protection Standards

We maintain comprehensive technical, administrative, and physical security measures designed to protect personal and operational data against accidental loss, unauthorized access, destruction, or disclosure.

  • Strong Cryptographic Controls: Data in transit is protected using modern cryptographic protocols (TLS 1.3 / HTTPS). Data at rest in databases, persistent snapshots, and backups is encrypted using industry-standard AES-256 encryption.
  • Least-Privilege & Role-Based Access:Access to production systems is restricted on a strict need-to-know basis, protected by multi-factor authentication (“MFA”), hardware security keys, and ephemeral bastion access.
  • Vulnerability Management & Code Scans: Continuous automated dependency scanning, static code analysis (SAST), and recurring architectural audits are performed across our codebases.
  • Incident Response & Breach Notification: In the event of a verified personal data breach, we follow established security incident response procedures and provide statutory notifications to affected customers, data subjects, and authorities (such as CERT-In in India or relevant European Data Protection Authorities) in accordance with legal deadlines.
Section 09

9. Data Retention & Secure Sanitization

We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was gathered, comply with our legal obligations, resolve disputes, and enforce our contracts:

  • Active Customer Accounts: Account profiles and extension blueprints are retained during the term of your active commercial contract with Vezel.
  • Account Termination & Offboarding: Upon written termination of an enterprise agreement, customer-specific configurations, AST blueprints, and developer credentials are permanently purged or rendered irreversibly anonymous within 30 to 60 calendar days, unless statutory preservation is legally mandated.
  • Diagnostic Telemetry & Logs: Raw server access and diagnostic logs are rotated and purged on rolling cycles (typically between 90 and 180 calendar days).
  • Tax & Statutory Records: Financial invoices, GST filings, and payment receipts are retained for statutory periods mandated under Indian corporate and taxation laws (typically 7 to 8 years).
Section 10

10. Your Statutory Rights Across Jurisdictions

Depending on your geographical location and applicable laws, you possess specific statutory rights regarding your personal data:

A. Rights Under India's DPDP Act, 2023
  • • Right to Access Information: Request a summary of personal data being processed and identities of data fiduciaries/processors with whom it has been shared.
  • • Right to Correction & Erasure: Request the correction, completion, or deletion of personal data no longer necessary for the purpose for which it was collected.
  • • Right of Grievance Redressal: Register complaints with our designated Grievance Officer and escalate to the Data Protection Board of India if unresolved.
  • • Right to Nominate: Nominate an individual who, in the event of death or incapacity, shall exercise your data rights.
B. Rights Under the GDPR / UK GDPR
  • • Right of Access (Art. 15): Obtain confirmation and copies of your personal data.
  • • Right to Rectification (Art. 16): Rectify inaccurate or incomplete data.
  • • Right to Erasure (Art. 17): “Right to be forgotten” subject to statutory exemptions.
  • • Right to Restriction & Portability (Art. 18 & 20): Restrict processing or receive data in a structured, machine-readable format.
  • • Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing.
  • • Right to Lodge a Complaint: Lodge a complaint with your local EU/UK Supervisory Authority.
C. Rights Under California Law (CCPA / CPRA)
  • • Right to know what personal information is collected, disclosed, or sold (we do not sell).
  • • Right to delete personal information collected from you.
  • • Right to correct inaccurate personal information.
  • • Right to freedom from discrimination for exercising privacy rights.

How to Exercise Your Rights: To submit a verified request, please email our privacy team at privacy@vezel.ai. We acknowledge receipt within 48 hours and process requests within statutory timeframes (normally 30 calendar days).

Section 11

11. Cookies & Tracking Technologies

We use cookies, session tokens, and local storage mechanisms on our website and developer portals:

  • Strictly Necessary Cookies: Required to authenticate sessions, prevent cross-site request forgery (CSRF), and maintain secure developer sessions.
  • Performance & Analytics Cookies: Privacy-preserving aggregated telemetry (such as Vercel Web Analytics and Speed Insights) to evaluate aggregate site traffic, page load performance, and optimize SDK responsiveness.

You may adjust your browser settings to refuse or delete cookies. However, disabling strictly necessary cookies may degrade your ability to log in or use certain administrative dashboard capabilities.

Section 12

12. Children's Privacy Protection

Vezel is strictly a business-to-business (B2B) enterprise platform and developer service. Our website and services are not directed to individuals under the age of 18 (or the applicable age of legal majority in your country of residence).

We do not knowingly collect, solicit, or maintain personal information from minors. If you believe a child has provided us with personal information, please notify us at privacy@vezel.ai and we will take immediate measures to permanently delete such records.

Section 13

13. Updates & Amendments to This Policy

We may periodically update this Privacy Policy to reflect technical platform enhancements, architectural modifications in the Adaptive SaaS runtime, changes in sub-processors, or statutory regulatory developments.

When changes are published, the “Last Updated” date at the top of this document will be updated. In the event of material modifications that alter your rights, we will provide conspicuous advance notice through our website, via direct email to registered enterprise administrators, or inside our customer portal.

Section 14

14. Statutory Grievance Officer in India & Contact

In compliance with the Information Technology Act, 2000, the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011, and Section 13 of the Digital Personal Data Protection Act, 2023, NEOCORTEX AI PRIVATE LIMITED has designated a Grievance Redressal Officer:

Company:NEOCORTEX AI PRIVATE LIMITED
Designation:Data Protection & Grievance Redressal Officer
Privacy & Grievance Email:privacy@vezel.ai
General Inquiries:hello@vezel.ai
Registered Jurisdiction:Republic of India

Turnaround Time: In accordance with statutory directives, we acknowledge receipt of user grievances within forty-eight (48) hours of receipt and endeavor to redress complaints within one (1) month from date of receipt.

hello@vezel.ai

  • Home
  • Solution
  • How It Works
  • Demos
  • Blog
  • Book a Demo
  • Privacy Policy
  • Terms & Conditions

Build Vezel Vezel

[ Conversion-focused ]

[ Data-driven ]

[ Built for scale ]

[ User-centric ]

[Future-proof]