Follow our newsletter for curated insights

Legal

Privacy Policy

Last updated: 19th June, 2026

Table of Contents

  1. Overview
  2. Scope
  3. Information We Collect
  4. How We Use Information
  5. Legal Bases for Processing
  6. AI and Automated Processing
  7. Cookies and Tracking Technologies
  8. Sharing and Disclosure of Information
  9. Security and Retention
  10. International Transfers
  11. Privacy Rights
  12. EU AI Act Transparency
  13. Data Breach Notification
  14. Children's Privacy
  15. Contact Information, Grievance Officer, and Data Protection Officer
  16. Changes to this Privacy Policy
01

Overview

Vaia Investment Advisory LLP (“Vaia”, “we”, “our”, or “us”) provides software and advisory solutions for investment management, family offices, sustainability, reporting, due diligence, monitoring, and related business workflows.

This Privacy Policy explains how we collect, use, disclose, process, store, and protect information when you access or use our websites, platforms, applications, integrations, and services, including VAIA GPT and VAIA Prism.

We are committed to handling information responsibly and in accordance with applicable privacy and data protection laws, including the Digital Personal Data Protection Act, 2023 (India) (“DPDP Act”), the General Data Protection Regulation (“GDPR”), the UK GDPR, the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and the European Union Artificial Intelligence Act (“EU AI Act”).

By accessing or using our services, you acknowledge the practices described in this Privacy Policy.

02

Scope

This Privacy Policy applies to:

  • Visitors to our websites and digital properties;
  • Users of Vaia platforms, products, and services, including VAIA GPT and VAIA Prism;
  • Customers and prospective customers;
  • Business partners, service providers, and contractors; and
  • Individuals who communicate or interact with Vaia in a professional capacity.

This Policy applies to information collected through our websites, applications, integrations, communications, and services. It does not apply to third party websites, applications, or services that are not operated or controlled by Vaia, even where those services are linked from or connected to our platforms.

03

Information We Collect

3.1 Information You Provide

We may collect information that you or your organization provide directly to us, including:

  • Name and business contact information;
  • Email address and account information;
  • Company and professional details;
  • Communications with Vaia;
  • Information submitted through forms, support requests, or onboarding processes; and
  • Other information necessary to provide requested services.

3.2 Customer Documents and Business Data

Depending on the services used, customers may upload or connect documents, reports, financial information, sustainability disclosures, research materials, portfolio information, spreadsheets, presentations, and other business data required to use our services.

The information collected depends on the products, integrations, and services being used.

3.3 Authentication and Usage Data

To operate and secure our services, we may collect:

  • IP addresses;
  • Browser and device information;
  • Authentication records;
  • Login timestamps;
  • Access logs;
  • Session information; and
  • Platform usage and activity data.

3.4 Information from Third Parties

Where authorized by customers, we may receive information from connected systems, integrations, public sources, and third party data providers to enrich datasets, improve accuracy, and provide requested functionality.

If you sign in using Google OAuth, we may receive basic account information associated with your Google account, including your name, email address, profile picture, and authentication details required to manage your account.

3.5 Categories of Personal Information (CCPA/CPRA Disclosure)

For California residents, in the preceding twelve (12) months we have collected the following categories of personal information, as defined under Cal. Civ. Code Section 1798.140:

CCPA CategoryExamples Collected by VaiaCollected?
IdentifiersName, email address, IP address, account identifiersYes
Customer records informationBusiness contact details, billing informationYes
Commercial informationSubscription history, services purchasedYes
Internet or network activityBrowsing activity on our platform, log data, session dataYes
Professional or employment informationJob title, employer, business roleYes
Geolocation dataApproximate location derived from IP addressYes
Sensitive personal informationAccount login credentialsLimited, only as required for authentication
Audio, electronic, visual informationNot collected, unless voluntarily submitted in support communicationsLimited
Biometric informationNot collectedNo
Protected classification characteristicsNot collectedNo
InferencesService usage patterns used to improve platform functionalityYes

Vaia does not sell or share personal information, as those terms are defined under the CCPA/CPRA, and has not done so in the preceding twelve (12) months.

04

How We Use Information

We use information to:

  • Provide, operate, maintain, and improve our services;
  • Authenticate users and manage accounts;
  • Process customer documents and business data;
  • Generate analyses, reports, insights, and other requested outputs;
  • Facilitate customer workflows and integrations;
  • Respond to inquiries and provide support;
  • Monitor platform performance, reliability, and security;
  • Detect, prevent, and investigate fraud, abuse, unauthorized access, or security incidents;
  • Comply with legal, regulatory, and contractual obligations; and
  • Protect the rights, security, and integrity of Vaia, our customers, and our services.

Vaia processes information only for purposes related to providing, securing, and supporting its services.

05

Legal Bases for Processing

For individuals in the European Economic Area, the United Kingdom, and other jurisdictions that require a documented legal basis for processing, Vaia relies on one or more of the following bases under Article 6 of the GDPR:

  • Contractual necessity. Processing required to perform a contract with a customer or to take steps requested prior to entering into a contract.
  • Legitimate interests. Processing necessary for our legitimate business interests, such as securing our platform, improving our services, and preventing fraud, provided those interests are not outweighed by the interests or fundamental rights of the individual.
  • Legal obligation. Processing necessary to comply with a legal or regulatory obligation, such as tax, accounting, or audit requirements.
  • Consent. Processing based on consent, such as optional marketing communications or certain analytics cookies, which may be withdrawn at any time.

Where Vaia processes special categories of personal data, this is generally limited to data voluntarily included by customers within uploaded business documents, and is processed solely to deliver the requested service, consistent with Article 9 of the GDPR.

06

AI and Automated Processing

Vaia uses artificial intelligence and machine learning technologies to support customer workflows, including information extraction, document analysis, summarization, reporting, research assistance, and other customer requested functionality, through products such as VAIA GPT and VAIA Prism.

6.1 Purpose and Scope of AI Processing

Information submitted to the platform may be processed by AI systems operated by Vaia or approved infrastructure providers solely for the purpose of delivering requested services. This includes, where applicable, large language model inference, retrieval augmented generation against customer authorized data sources, and automated document classification or extraction.

6.2 Customer Data and Model Training

Customer data is processed only to provide the services requested by the customer and remains the property of the customer.

Unless expressly agreed in writing, Vaia does not use customer data, documents, prompts, outputs, or proprietary information to train, fine tune, or improve public, shared, or general purpose AI models. Where Vaia trains its own proprietary vertical models, such as VAIA GPT, training data sources, methods, and safeguards are governed separately under customer agreements and are not derived from confidential customer business data without express written authorization.

6.3 Human Oversight and Review

AI generated outputs are intended to assist users and should be reviewed before being relied upon for investment, financial, legal, sustainability, compliance, or business decisions. Vaia does not represent AI generated outputs as a substitute for professional judgment, licensed advice, or human review.

Where applicable, Vaia maintains appropriate controls and governance processes relating to the use of AI enabled functionality, including human review checkpoints for outputs used in client facing deliverables.

6.4 AI Generated Content Disclosure

Where Vaia products generate content that could reasonably be mistaken for human authored content, such as narrative reports or summaries, Vaia takes reasonable steps to ensure that such content is identifiable as AI generated or AI assisted, consistent with applicable transparency obligations, including those under the EU AI Act described in Section 12.

07

Cookies and Tracking Technologies

Vaia and its service providers may use cookies, web beacons, pixels, and similar tracking technologies on our websites and platforms for the following purposes:

  • Strictly necessary technologies. Required for authentication, session management, security, and core platform functionality. These cannot be disabled without affecting the operation of the service.
  • Performance and analytics technologies. Used to understand platform usage, diagnose issues, and improve performance and reliability.
  • Functional technologies. Used to remember preferences, such as language or display settings.

Vaia does not currently use third party advertising cookies. Where analytics tools are used, data is processed in aggregate or pseudonymized form wherever feasible.

You may control cookie preferences through your browser settings. Disabling certain cookies may affect the availability or functionality of parts of our platform. Where required by applicable law, Vaia will obtain consent prior to placing non essential cookies and will provide a mechanism to withdraw that consent at any time.

08

Sharing and Disclosure of Information

Vaia does not sell personal information or customer data.

We may share information in the following circumstances:

8.1 Service Providers and Subprocessors

We may share information with trusted service providers and subprocessors that assist in operating, hosting, securing, maintaining, and supporting our services. Such providers are authorized to access information only as necessary to perform services on our behalf and are contractually required to protect it appropriately, including, where applicable, through a signed data processing agreement.

Categories of subprocessors engaged by Vaia may include:

CategoryPurpose
Cloud infrastructure and hosting providersHosting platform data, application infrastructure, and backups
AI model and inference providersProcessing prompts and documents to generate AI assisted outputs
Authentication providersEnabling secure account sign in, such as Google OAuth
Communication and support toolsEnabling customer support and internal communication
Analytics and monitoring toolsPlatform performance monitoring and error tracking

A current list of named subprocessors is available upon written request to the contact in Section 15, and customers may request advance notice of material changes to this list under the terms of their Data Processing Addendum.

8.2 Customer Authorized Integrations

Where customers choose to connect third party applications, platforms, or services, information may be shared as necessary to enable those integrations and provide requested functionality.

8.3 Legal and Regulatory Requirements

We may disclose information where required by applicable law, regulation, court order, governmental request, or legal process.

We may also disclose information where necessary to protect the rights, property, security, or integrity of Vaia, our customers, or others.

8.4 Corporate Transactions

Information may be disclosed or transferred in connection with a merger, acquisition, financing, reorganization, sale of assets, bankruptcy proceeding, or similar corporate transaction, subject to applicable legal requirements.

09

Security and Retention

Protecting customer information is a core part of our operations.

Vaia maintains administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or destruction.

These safeguards include access controls, encryption in transit and at rest, monitoring, audit logging, secure development practices, periodic security reviews, vendor risk management processes, and other security measures appropriate to the nature of the information we process.

Vaia has successfully completed a SOC 2 Type II audit covering the trust services criteria of security, availability, and confidentiality. A copy of the audit report or bridge letter is available to customers and prospective customers under a mutual non disclosure agreement, upon request to the contact in Section 15.

9.1 Retention Schedule

Information is retained only for as long as necessary to provide services, fulfill contractual obligations, comply with legal and regulatory requirements, resolve disputes, enforce agreements, and protect legitimate business interests, generally in accordance with the following schedule:

Data TypeTypical Retention Period
Customer business documents and outputsFor the duration of the customer agreement, plus a transition period defined in the customer agreement, after which data is deleted or returned at the customer's instruction
Account and authentication dataFor the duration of the account, plus a limited period thereafter for security and fraud prevention purposes
Access and session logsA limited rolling period sufficient for security monitoring and incident investigation
Billing and contractual recordsAs required to meet applicable tax, accounting, and statutory recordkeeping obligations
Marketing and communications preferencesUntil consent is withdrawn or the individual opts out

When information is no longer required, it is securely deleted, anonymized, or de identified, as appropriate.

While we take reasonable measures to protect information, no method of transmission or storage can be guaranteed to be completely secure.

10

International Transfers

Information may be processed and stored in jurisdictions outside the country in which it was originally collected.

Where international transfers occur, Vaia implements appropriate contractual, organizational, and technical safeguards designed to protect information in accordance with applicable legal requirements, including, where applicable, Standard Contractual Clauses approved by the European Commission, the UK International Data Transfer Addendum, or equivalent recognized transfer mechanisms.

Where required, Vaia may enter into a Data Processing Addendum (“DPA”) with customers to support compliance with applicable data protection laws. The DPA sets out the categories of personal data processed, the purposes and duration of processing, the subprocessors engaged, and the technical and organizational measures applied, and is incorporated into the customer agreement upon execution. Customers seeking a DPA may request one from the contact listed in Section 15.

Where Vaia processes personal data of individuals located in the European Economic Area or the United Kingdom without a local establishment there, Vaia will, where legally required, designate a representative in the European Union or United Kingdom in accordance with Article 27 of the GDPR and the equivalent provision of the UK GDPR, details of which will be made available on request.

11

Privacy Rights

Depending on your location and applicable law, you may have the rights described below.

11.1 General Rights

Subject to applicable law, you may have rights to:

  • Access personal information we process about you;
  • Request correction of inaccurate information;
  • Request deletion of personal information;
  • Withdraw consent where processing is based on consent;
  • Request information regarding how your information is processed; and
  • Exercise additional rights available under applicable law.

To exercise any of these rights, please contact us using the information provided in Section 15. We will respond to requests in accordance with applicable legal requirements.

11.2 Rights Under the GDPR and UK GDPR

If you are located in the European Economic Area or the United Kingdom, you have the right, subject to certain exceptions and limitations, to:

  • Request access to and a copy of your personal data;
  • Request rectification of inaccurate or incomplete personal data;
  • Request erasure of your personal data;
  • Request restriction of processing;
  • Object to processing carried out on the basis of legitimate interests or for direct marketing purposes;
  • Request portability of personal data you have provided to us, in a structured, commonly used, machine readable format; and
  • Lodge a complaint with your local supervisory authority.

We will respond to verified requests within one month of receipt, which may be extended by a further two months for complex or numerous requests, with notice provided to you of any such extension.

11.3 Rights Under the CCPA/CPRA

If you are a California resident, you have the right, subject to certain exceptions, to:

  • Know the categories and specific pieces of personal information we have collected about you, as set out in Section 3.5;
  • Know the categories of sources from which personal information is collected, the business purpose for collecting it, and the categories of third parties with whom it is shared;
  • Request deletion of personal information we have collected from you;
  • Request correction of inaccurate personal information;
  • Opt out of the sale or sharing of personal information, noting that Vaia does not currently sell or share personal information as defined under the CCPA/CPRA;
  • Limit the use and disclosure of sensitive personal information to that necessary to perform the services reasonably expected by an average consumer;
  • Not be discriminated against for exercising any of these rights; and
  • Designate an authorized agent to make a request on your behalf, provided we are able to verify the agent's authority to act on your behalf.

You may submit a verifiable consumer request through the contact details in Section 15. We will respond within forty five (45) calendar days, which may be extended by an additional forty five (45) days where reasonably necessary, with notice provided to you of any such extension. We may need to verify your identity before processing a request, using information already held about you or additional information you provide for verification purposes.

11.4 Rights Under the DPDP Act, 2023

If you are located in India, as a Data Principal under the DPDP Act, you have the right, subject to applicable exceptions, to:

  • Obtain a summary of personal data processed by Vaia as a Data Fiduciary, and of the processing activities undertaken with respect to such data;
  • Request correction, completion, or updating of your personal data;
  • Request erasure of personal data that is no longer necessary for the purpose for which it was processed, subject to retention obligations described in Section 9.1;
  • Withdraw consent at any time where processing is based on consent, with the withdrawal taking effect prospectively and without affecting the lawfulness of processing carried out prior to withdrawal;
  • Have readily available means to register a grievance with Vaia regarding the processing of your personal data; and
  • Nominate another individual to exercise these rights on your behalf in the event of death or incapacity.

Grievances and rights requests under the DPDP Act may be submitted to the Grievance Officer identified in Section 15. Vaia will acknowledge and respond to such grievances within a reasonable timeframe consistent with the DPDP Act and its implementing rules.

12

EU AI Act Transparency

Vaia maintains transparency measures relating to AI enabled functionality in accordance with relevant obligations under the European Union Artificial Intelligence Act.

12.1 Nature of the AI Systems

Vaia's AI enabled products, including VAIA GPT and VAIA Prism, are designed to support investment research, sustainability reporting, document analysis, and related professional workflows. These systems are intended to be used by trained professional users as decision support tools, and are not designed or marketed for use in the high risk categories enumerated under Annex III of the EU AI Act, such as biometric identification, critical infrastructure management, or determinations of access to essential public services.

Based on this intended use, Vaia's AI systems are generally classified as limited risk or minimal risk under the EU AI Act's tiered framework, primarily subject to the transparency obligations described in Article 50 of the Act, rather than the conformity assessment obligations applicable to high risk systems.

12.2 Transparency Obligations

In line with Article 50 of the EU AI Act, where individuals interact with an AI system operated by Vaia, Vaia takes reasonable steps to inform users that they are interacting with an AI system, unless this is obvious from the context of use. Where Vaia's systems generate synthetic audio, image, video, or text content that could be mistaken for human generated content, Vaia takes reasonable steps to ensure that such content is marked or otherwise identifiable as artificially generated, where technically feasible and where required by applicable law.

12.3 Human Oversight

Consistent with the human oversight principles underlying the EU AI Act, Vaia's AI enabled products are designed to support, rather than replace, human professional judgment. Outputs generated by VAIA GPT and VAIA Prism are intended to be reviewed by a qualified human user before being relied upon for investment, financial, legal, sustainability, or compliance decisions, as described in Section 6.3.

12.4 Contact for AI Related Concerns

Individuals may contact Vaia regarding AI enabled features, automated processing activities, or concerns relating to AI generated outputs using the contact details provided in Section 15.

13

Data Breach Notification

Vaia maintains an incident response process designed to detect, contain, and respond to security incidents affecting personal information or customer data.

In the event of a confirmed personal data breach that poses a risk to the rights and freedoms of affected individuals, Vaia will, where legally required:

  • Notify affected customers without undue delay following confirmation of the incident, to enable customers to meet their own regulatory notification obligations;
  • Notify the relevant supervisory authority or regulator within the timeframe required by applicable law, which is seventy two (72) hours under the GDPR where feasible, and within the timeframe prescribed under the DPDP Act and its implementing rules for incidents involving Data Principals in India;
  • Provide affected individuals with information reasonably necessary to understand the nature of the incident and any recommended protective steps, where required by applicable law; and
  • Cooperate with customers and regulators in investigating and remediating the incident.

This section describes Vaia's general approach to breach notification and does not modify or supersede any specific incident response or notification terms agreed in a customer's Data Processing Addendum or master services agreement, which will govern in the event of any conflict.

14

Children's Privacy

Vaia's products and services are intended for business and professional use and are not directed toward individuals under the age of 18.

We do not knowingly collect personal information from children. If we become aware that such information has been collected, we will take reasonable steps to delete it.

15

Contact Information, Grievance Officer, and Data Protection Officer

If you have questions regarding this Privacy Policy, your privacy rights, our data practices, or the processing of information through our services, please contact:

Vaia Investment Advisory LLP

General inquiries: foundersoffice@vaia.co.in

Website: vaia.co.in

Grievance Officer (Digital Personal Data Protection Act, 2023):
Name, designation, and direct contact details of the Grievance Officer to be inserted here, as required under the DPDP Act and its implementing rules. Until such time as a dedicated Grievance Officer is named, grievances may be directed to the general inquiries address above.

Data Protection Officer or EU/UK Representative (where applicable):
Where Vaia is required under the GDPR, the UK GDPR, or other applicable law to designate a Data Protection Officer or an EU or UK representative, the name and contact details of that individual or entity will be inserted here and made available to data subjects and supervisory authorities on request.

California Privacy Requests (CCPA/CPRA):
Requests under Section 11.3 may be submitted to the general inquiries address above, with the subject line “California Privacy Request.”

16

Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, security practices, or business operations.

Updated versions will be published with a revised “Last Updated” date. Where changes are material, Vaia will take reasonable steps to notify customers and users, such as through email or an in platform notice, in addition to publishing the updated policy. Continued use of our services after such updates become effective constitutes acceptance of the revised Privacy Policy.