Data Governance and Handling Policy
How we govern, secure, retain and dispose of the data we hold — including data we process on behalf of connected merchants.
Last updated · 26th July, 2026
This Data Governance and Handling Policy ("Policy") sets out how UO Tech Private Limited ("Company", "UONEX", "We", "Us", "Our") governs the data it collects, processes, stores and disposes of in operating the UONEX platform, its business portal, and the UONEX Connect integrations and extensions it publishes on third-party commerce platforms.
This Policy describes Our governance and control framework. It is a companion to, and does not replace, Our Privacy Notice, which is the authoritative statement of what personal data We process, for what purpose, and what rights a data principal may exercise. Where this Policy and the Privacy Notice address the same subject, the Privacy Notice governs the treatment of personal data.
TABLE OF CONTENTS
1. PURPOSE AND SCOPE
1.1. This Policy applies to all data held by Us in the course of operating the platform, and to all personnel, systems and third parties involved in processing it.
1.2. It covers two distinct categories of data, which We govern differently:
1.2.1. Data for which We are the Data Fiduciary. Data of users who hold a UONEX account, or who interact with Our platform directly.
1.2.2. Data We process on behalf of a merchant.Where a merchant connects a commerce or point-of-sale system to Us through UONEX Connect, We receive catalogue, inventory and transaction data from that system, and act as a processor on that merchant's instructions. The merchant remains the Data Fiduciary for their customers' personal data. We process such data only for the purposes the merchant has enabled, We do not sell it, and We do not use one merchant's data for another merchant's benefit.
1.3. This Policy is designed to operate consistently with the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000 including rules made thereunder, and to support Our obligations under the General Data Protection Regulation and the California Consumer Privacy Act where those apply to a given processing activity.
2. PRINCIPLES OF DATA GOVERNANCE
2.1. Accountability.We accept responsibility for the data in Our custody, including data held on a merchant's behalf, and for the conduct of the sub-processors We engage.
2.2. Purpose limitation and minimisation. We collect only what a given feature requires, and use it only for the purpose for which it was collected or a purpose compatible with it.
2.3. Transparency. What We collect, why, and how long We keep it is published in Our Privacy Notice rather than described only internally.
2.4. Data quality. Where data originates from a connected system, We treat that system as the source of truth and reconcile against it, rather than allowing Our copy to diverge silently.
2.5. Security by default. Access is granted by role and withheld otherwise; encryption and isolation are applied as standard rather than on request.
2.6. Compliance. We hold Ourselves to applicable statutory, regulatory and contractual obligations, including the terms of the commerce platforms on which We publish integrations.
3. ROLES AND RESPONSIBILITIES
3.1. Overall accountability for this Policy rests with the Company's directors.
3.2. Our Nodal cum Grievance Officer, named in Section 8, is the point of contact for data protection queries, grievances and requests from data principals, and for notices from platform partners and regulators.
3.3. Access to production systems and to data held within them is limited to personnel whose role requires it, and is revoked when that role changes or ends.
4. DATA HANDLING LIFECYCLE
4.1. Collection. We collect data directly from users, and from systems a merchant has explicitly connected and authorised. Where consent is the basis for a processing activity, it is obtained before that activity begins and may be withdrawn.
4.2. Storage.Data is held in managed cloud infrastructure within access-controlled private networks, encrypted at rest, and logically segregated by account and by connected merchant so that one merchant's data is not reachable from another's context.
4.3. Use. Data is used only for the purposes set out in Our Privacy Notice and, for merchant data, only for the purposes that merchant has enabled. Access by personnel is limited by role.
4.4. Sharing. We share data only with sub-processors engaged to deliver a feature, under written terms imposing confidentiality and security obligations no less protective than those in this Policy, and with authorities where legally compelled. We do not sell personal data.
4.5. Retention. Data is retained only for as long as the purpose for which it was collected requires, or for a longer period where law obliges Us. The retention periods that apply to personal data are stated in Our Privacy Notice.
4.6. Disposal. On expiry of the applicable retention period, or on a valid deletion request from a data principal or an instructing merchant, data is deleted or irreversibly anonymised. Where a record cannot be deleted immediately because it exists in backup media, it is isolated from further processing until deletion is possible.
5. SECURITY MEASURES
5.1. Encryption in transit. Traffic between users and Our platform, and between Our platform and connected systems, is encrypted using current industry standard transport security.
5.2. Encryption at rest. Databases and object storage holding platform data are encrypted at rest by the managed cloud services on which they run. Integration credentials supplied by merchants are additionally encrypted under a dedicated managed key and are never returned to a client in readable form.
5.3. Access control.Access is role-based and least-privilege. Every request to Our systems is authenticated, and access to a merchant's data is scoped cryptographically to that merchant rather than enforced only in the interface.
5.4. Multi-factor authentication. Administrative and internal access requires a second authentication factor.
5.5. Network isolation. Databases and internal services are not exposed to the public internet and are reachable only from within Our private network.
5.6. Logging and traceability. Administrative actions and privileged operations are recorded, with the identity of the actor and the reason given, so that a change can be attributed after the fact.
5.7. Change management. Changes to production systems are made through version control with review, automated testing and staged deployment, rather than applied directly.
6. SUB-PROCESSORS AND THIRD PARTIES
6.1. We engage sub-processors to provide infrastructure, communications and analytics capability. Each is engaged under terms requiring confidentiality, security measures equivalent to those in this Policy, and processing limited to Our instructions.
6.2. We assess a prospective sub-processor's security and data protection posture before engaging it, and remain accountable to the merchant and to the data principal for its conduct.
6.3. Categories of recipient, and the basis on which personal data may be transferred outside India, are set out in Our Privacy Notice.
7. INCIDENTS AND BREACH NOTIFICATION
7.1. Suspected security incidents are triaged on discovery, contained, and investigated to establish what data was affected.
7.2. Where a personal data breach has occurred, We notify affected data principals and the competent authority in the form and within the timeframes applicable law prescribes.
7.3. Where the affected data was processed on a merchant's behalf, We notify that merchant without undue delay so that they may discharge their own obligations as Data Fiduciary, and We support them in doing so.
7.4. Reporting a vulnerability. We welcome reports of suspected security vulnerabilities affecting Our platform. Reports may be sent to security@uonex.ai, which is also published at /.well-known/security.txt. We acknowledge receipt, keep the reporter informed of Our assessment, and do not require a report to be kept confidential indefinitely.
7.5. We will not pursue or support legal action against a reporter who acts in good faith, reports promptly and privately, does not access, modify or retain more data than is necessary to demonstrate the issue, and does not degrade the service for others. Testing that requires accessing another person's account or data is outside this undertaking.
8. GOVERNANCE, GRIEVANCES AND COMPLIANCE
8.1. A data principal, merchant or platform partner may raise a question, grievance or request concerning this Policy or Our handling of data with Our Nodal cum Grievance Officer, whose details are below. We acknowledge and respond within the period applicable law prescribes.
Details of the Nodal cum Grievance Officer
Name: Mr. Chandrasekara Reddy
Designation: Director
Address: UO Tech Private Limited, Attn: Grievance Redressal Officer, WeWork Prestige Cube, Site No. 26 Laskar, Hosur Rd, Bangalore, Karnataka 560030.
Email: gro@uonex.ai
8.2. Where a merchant requires a written data processing agreement in order to connect their systems to Us, or a platform partner requires evidence of the controls described in Section 5, requests may be directed to the Officer named above.
9. REVIEW CYCLE
9.1. This Policy is reviewed at least once every twelve months, and additionally whenever there is a material change to Our processing activities, Our sub-processors, or the law applicable to them.
9.2. The date of the most recent revision is shown at the top of this page. Material changes are notified in the manner set out in Our Privacy Notice.