Legal

Privacy Policy

Last updated: 06 September 2026

⚠️ This is a working draft describing what INSπRE actually does today. It has not yet been reviewed by counsel and should not be treated as a final, legally binding privacy notice until it has — particularly before onboarding customers in regulated sectors (banking, insurance) where DPDP Act, GDPR, or sector-specific obligations apply.

What we collect

Account information you provide at registration (name, work email, company, country). Content you enter into the platform (risks, controls, policies, audit data, and similar compliance records) belongs to your organisation and is stored to provide the service. Basic usage/activity logs are kept for security and audit-trail purposes within your organisation.

How we use it

To operate the platform, respond to support and sales enquiries submitted through our contact forms, and to improve the product. We do not sell personal data.

AI processing

The AI assistant and AI-generated reports are powered by a third-party model provider. Content you send to the assistant is transmitted to that provider to generate a response, subject to their processing terms. Ask us for current provider details before sending highly sensitive data through the assistant.

Data retention & deletion

Your organisation's data is retained for as long as your account is active. You can request export or deletion of your organisation's data by contacting support@inspre.io.

Your rights

Depending on your jurisdiction (including under India's DPDP Act or the EU GDPR), you may have rights to access, correct, or delete your personal data, and to withdraw consent. Contact us to exercise these rights.

Contact

Questions about this policy: support@inspre.io · Chennai, Tamil Nadu, India.