1. About this policy
This Privacy Policy explains how CompIQ AI Ventures Private Limited (“CompIQ”, “we”, “us”, “our”) collects, uses, shares and protects personal data, and the choices and rights you have. It applies to:
- visitors to our website www.compiq.ai;
- prospective customers, partners and business contacts who contact us, request a demo or attend our events;
- users of the CompIQ platform whose accounts are set up by their employer; and
- people who apply for jobs with us.
We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Digital Personal Data Protection Rules, 2025, and the Information Technology Act, 2000 and rules made under it.
2. Who we are
CompIQ AI Ventures Private Limited is a company incorporated in India with its registered office at 2902, Prestige Turf Tower, Shakti Mills Lane, Mahalaxmi, Mumbai 400018, Maharashtra, India. We provide CompIQ, an AI-driven compensation and pay-intelligence platform for businesses.
For personal data we collect for our own purposes (for example website, business-contact and job-applicant data), CompIQ is the Data Fiduciary.
3. Employee data we process for our customers
Our customers (employers) upload information about their workforce to the CompIQ platform — for example names, employee IDs, roles, job levels and compensation details. For this data:
- the customer (your employer) is the Data Fiduciary and decides how and why the data is used;
- CompIQ acts as a Data Processor and processes the data only on the customer’s documented instructions and under our contract with them; and
- we do not use this data for our own marketing, and we never sell it.
If you are an employee of one of our customers and want to access, correct or erase your data, or have questions about how it is used, please contact your employer. If you contact us directly, we will forward your request to your employer and help them respond.
4. Personal data we collect
| Who you are | Data we collect | How we get it |
|---|---|---|
| Website visitor | IP address, browser and device information, pages visited, referring site, and cookie identifiers | Automatically when you use our website |
| Prospect, partner or business contact | Name, business email, phone number, company, job title and the content of your messages | From you – contact and demo forms, email, meetings and events |
| Platform user | Name, business email, role, login and authentication details, activity and audit logs, and support requests | From your employer when they set up your account, and from your use of the platform |
| Job applicant | Name, contact details, CV, education and employment history, interview notes and, if you receive an offer, information needed for background verification | From you, recruiters, referees and background-verification providers |
Our website does not ask for sensitive personal data. Please do not send us more personal data than we need to respond to you.
5. How and why we use your data
Under the DPDP Act we use personal data either with your consent or for a legitimate use permitted under Section 7 of the Act.
| Purpose | Basis |
|---|---|
| Responding to your enquiries and demo requests | Consent, or data you voluntarily provided for that purpose (s.7(a)) |
| Sending product updates, newsletters and marketing communications | Consent – you can unsubscribe or withdraw consent at any time |
| Providing, securing and supporting the CompIQ platform for our customers’ users | Our contract with your employer; data provided for that specified purpose (s.7(a)) |
| Operating, measuring and improving our website | Consent, where cookies are not strictly necessary |
| Assessing job applications and hiring | Consent, and legitimate uses relating to employment (s.7(i)) |
| Keeping our systems secure and investigating incidents | Legitimate uses, including compliance with law and CERT-In directions |
| Complying with legal obligations, court orders and lawful requests from authorities | Legitimate uses (s.7(c) and (d)) |
Where we rely on consent we will ask for it clearly, and you may withdraw it at any time as easily as you gave it. Withdrawal does not affect processing carried out before you withdrew.
Artificial intelligence. CompIQ uses home-trained, and privately-hosted AI models to generate compensation insights and recommendations for our customers. Customer data is used to provide the service to that customer and is not used to train AI models for other customers.
6. Who we share data with
We do not sell personal data. We share it only with:
- Service providers (sub-processors) that help us run our business, under contracts requiring them to protect the data and use it only on our instructions;
- your employer, if you are a platform user, for example activity information relating to your account;
- professional advisers such as auditors, lawyers and certification bodies, under confidentiality obligations;
- government and law-enforcement authorities, where required by law; and
- a buyer or successor in the event of a merger, acquisition or sale of all or part of our business, subject to this policy.
| Sub-processor | Purpose | Location |
|---|---|---|
| Amazon Web Services | Hosting of the CompIQ platform and data | India (Mumbai); disaster recovery in India (Hyderabad) |
| Microsoft (Microsoft 365) | Email, identity and collaboration | India (Mumbai) |
7. International transfers
Customer platform data is hosted in India (AWS Mumbai region). Some service providers may process limited personal data, such as email and collaboration data, outside India. We transfer personal data outside India only as permitted under the DPDP Act and not to any country restricted by the Government of India.
8. How long we keep data
We keep personal data only for as long as needed for the purpose it was collected for, or as required by law:
- Enquiries and business contacts: up to 2 years from our last contact, or until you ask us to delete it;
- Platform and customer data: for the duration of our contract with your employer, then returned or deleted within 30 days in line with that contract; backups expire within 60 days;
- Security logs: at least 180 days, as required by CERT-In directions;
- Job applicants: up to 2 years after the hiring decision, unless you join us or agree to us keeping your details longer.
9. How we protect data
We maintain reasonable security safeguards, including encryption of data in transit and at rest, access on a need-to-know basis, multi-factor authentication, logging and monitoring, regular vulnerability assessment and penetration testing, backups, and security training for our staff. We operate an information security management system aligned with ISO/IEC 27001 and the AICPA SOC 2 Trust Services Criteria.
If a personal data breach occurs, we will notify affected individuals and the Data Protection Board of India as required by law and, for customer data, our customers without undue delay.
10. Your rights
Subject to the DPDP Act, you have the right to:
- Access a summary of the personal data we process about you, the processing activities, and the identities of those we have shared it with;
- Correct, complete or update your personal data;
- Erase personal data that is no longer needed, unless we must keep it by law;
- Withdraw consent at any time;
- Grievance redressal – raise a complaint with us and receive a response; and
- Nominate another person to exercise your rights in the event of your death or incapacity.
To exercise these rights, email our Grievance Officer at security@compiq.ai. We may need to verify your identity before acting on a request, and we will respond within the period required under the DPDP Rules. Platform users should first contact their employer (see section 3).
11. Grievance Officer and contact
- Grievance Officer
- Himanshu Gupta, COO
- security@compiq.ai
If you are not satisfied with our response, you may complain to the Data Protection Board of India after first using our grievance redressal process.
12. Additional information for individuals in the EEA and UK
If the EU General Data Protection Regulation (GDPR) or UK GDPR applies to our processing of your personal data, CompIQ is the controller for the data described in section 4 (and a processor for our customers’ employee data). We rely on these lawful bases: contract (to provide services and respond to requests you make), legitimate interests (to run, secure and improve our business and website, and for B2B communications where permitted), consent (for non-essential cookies and certain marketing) and legal obligation.
Where we transfer personal data from the EEA/UK to India or other countries, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Addendum. In addition to the rights in section 10, you may have the right to object to processing, to restrict processing and to data portability, and you may complain to your local data protection supervisory authority.
13. Cookies
We use cookies and similar technologies on our website. For details of the cookies we use, why we use them and how to manage your choices, see our Cookie Policy. Our website uses cookies that are strictly necessary for it to function. You can control cookies through your browser settings; blocking strictly necessary cookies may affect how the website works.
14. Children
Our website and services are intended for businesses and are not directed at children (persons under 18). We do not knowingly collect children’s personal data. If you believe a child has provided us with personal data, please contact our Grievance Officer and we will delete it.
15. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page with a new “last updated” date and, where changes are significant, notify you by appropriate means.
© 2026 CompIQ AI Ventures Private Limited. See also our Terms of Use and Cookie Policy.