1. About this policy

This Privacy Policy explains how CompIQ AI Ventures Private Limited (“CompIQ”, “we”, “us”, “our”) collects, uses, shares and protects personal data, and the choices and rights you have. It applies to:

  • visitors to our website www.compiq.ai;
  • prospective customers, partners and business contacts who contact us, request a demo or attend our events;
  • users of the CompIQ platform whose accounts are set up by their employer; and
  • people who apply for jobs with us.

We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000 and rules made under it.

2. Who we are

CompIQ AI Ventures Private Limited is a company incorporated in India with its registered office at 2902, Prestige Turf Tower, Shakti Mills Lane, Mahalaxmi, Mumbai 400018, Maharashtra, India. We provide CompIQ, an AI-driven compensation and pay-intelligence platform for businesses.

For personal data we collect for our own purposes (for example website, business-contact and job-applicant data), CompIQ is the Data Fiduciary.

3. Employee data we process for our customers

Our customers (employers) upload information about their workforce to the CompIQ platform — for example names, employee IDs, roles, job levels and compensation details. For this data:

  • the customer (your employer) is the Data Fiduciary and decides how and why the data is used;
  • CompIQ acts as a Data Processor and processes the data only on the customer’s documented instructions and under our contract with them; and
  • we do not use this data for our own marketing, and we never sell it.

If you are an employee of one of our customers and want to access, correct or erase your data, or have questions about how it is used, please contact your employer. If you contact us directly, we will forward your request to your employer and help them respond.

4. Personal data we collect

Our website does not ask for sensitive personal data. Please do not send us more personal data than we need to respond to you.

5. How and why we use your data

Under the DPDP Act we use personal data either with your consent or for a legitimate use permitted under Section 7 of the Act.

Where we rely on consent we will ask for it clearly, and you may withdraw it at any time as easily as you gave it. Withdrawal does not affect processing carried out before you withdrew.

Artificial intelligence. CompIQ uses home-trained, and privately-hosted AI models to generate compensation insights and recommendations for our customers. Customer data is used to provide the service to that customer and is not used to train AI models for other customers.

6. Who we share data with

We do not sell personal data. We share it only with:

  • Service providers (sub-processors) that help us run our business, under contracts requiring them to protect the data and use it only on our instructions;
  • your employer, if you are a platform user, for example activity information relating to your account;
  • professional advisers such as auditors, lawyers and certification bodies, under confidentiality obligations;
  • government and law-enforcement authorities, where required by law; and
  • a buyer or successor in the event of a merger, acquisition or sale of all or part of our business, subject to this policy.

7. International transfers

Customer platform data is hosted in India (AWS Mumbai region). Some service providers may process limited personal data, such as email and collaboration data, outside India. We transfer personal data outside India only as permitted under the DPDP Act and not to any country restricted by the Government of India.

8. How long we keep data

We keep personal data only for as long as needed for the purpose it was collected for, or as required by law:

  • Enquiries and business contacts: up to 2 years from our last contact, or until you ask us to delete it;
  • Platform and customer data: for the duration of our contract with your employer, then returned or deleted within 30 days in line with that contract; backups expire within 60 days;
  • Security logs: at least 180 days, as required by CERT-In directions;
  • Job applicants: up to 2 years after the hiring decision, unless you join us or agree to us keeping your details longer.

9. How we protect data

We maintain reasonable security safeguards, including encryption of data in transit and at rest, access on a need-to-know basis, multi-factor authentication, logging and monitoring, regular vulnerability assessment and penetration testing, backups, and security training for our staff. We operate an information security management system aligned with ISO/IEC 27001 and the AICPA SOC 2 Trust Services Criteria.

If a personal data breach occurs, we will notify affected individuals and the Data Protection Board of India as required by law and, for customer data, our customers without undue delay.

10. Your rights

Subject to the DPDP Act, you have the right to:

  • Access a summary of the personal data we process about you, the processing activities, and the identities of those we have shared it with;
  • Correct, complete or update your personal data;
  • Erase personal data that is no longer needed, unless we must keep it by law;
  • Withdraw consent at any time;
  • Grievance redressal – raise a complaint with us and receive a response; and
  • Nominate another person to exercise your rights in the event of your death or incapacity.

To exercise these rights, email our Grievance Officer at security@compiq.ai. We may need to verify your identity before acting on a request, and we will respond within the period required under the DPDP Rules. Platform users should first contact their employer (see section 3).

11. Grievance Officer and contact

If you are not satisfied with our response, you may complain to the Data Protection Board of India after first using our grievance redressal process.

12. Additional information for individuals in the EEA and UK

If the EU General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data, CompIQ is the controller for the data described in section 4 (and a processor for our customers’ employee data). We rely on these lawful bases: contract (to provide services and respond to requests you make), legitimate interests (to run, secure and improve our business and website, and for B2B communications where permitted), consent (for non-essential cookies and certain marketing) and legal obligation.

Where we transfer personal data from the EEA/UK to India or other countries, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum. In addition to the rights in section 10, you may have the right to object to processing, to restrict processing and to data portability, and you may complain to your local data protection supervisory authority.

13. Cookies

We use cookies and similar technologies on our website. For details of the cookies we use, why we use them and how to manage your choices, see our Cookie Policy. Our website uses cookies that are strictly necessary for it to function. You can control cookies through your browser settings; blocking strictly necessary cookies may affect how the website works.

14. Children

Our website and services are intended for businesses and are not directed at children (persons under 18). We do not knowingly collect children’s personal data. If you believe a child has provided us with personal data, please contact our Grievance Officer and we will delete it.

15. Changes to this policy

We may update this policy from time to time. We will post the updated version on this page with a new “last updated” date and, where changes are significant, notify you by appropriate means.