Skip to content
Draft — this policy is a template under review by counsel and is not yet legally binding.

Privacy Policy

Last updated: 28 July 2026

1. Introduction

This Privacy Policy explains how the Radicept platform (“Radicept”, “we”, “us”) collects, uses, stores and protects personal data. The platform is operated by SOCCKA under the Radicept brand, and is built by SOCCKA in collaboration with Metaboard.

It applies to the Radicept marketing website (radicept.com) and the application at app.radicept.com. Where an organization uses Radicept to assess its own compliance, that organization is the Data Fiduciary and we act as its Data Processor for the personal data it uploads.

2. Information we collect

We collect the following categories of information:

  • Account & identity data — name, work email, organization and role, used to create and secure your account.
  • Content you provide — documents, questionnaire responses and other materials uploaded for assessment. These may themselves contain personal data of your customers or employees.
  • Usage & device data — log data such as IP address, browser type, and actions taken in the application, used for security and reliability.
  • Communications — messages you send us, including demo and support requests.

3. How we use information

We use information to:

  • Provide and operate the compliance assessment service.
  • Read and map uploaded documents against provisions and generate reports and evidence snapshots.
  • Authenticate users and keep the platform secure.
  • Respond to your requests and communicate about the service.
  • Improve product quality and accuracy. Indian PII is scrubbed before any AI model call, and inference stays in India by default.
  • Comply with legal obligations.

4. Legal bases

We process personal data in accordance with the Digital Personal Data Protection Act, 2023 (the “DPDP Act”). Our processing relies principally on your consent and, where applicable, the certain legitimate uses recognized under the Act. Where we act as a Data Processor for a client Data Fiduciary, we process personal data only on that client’s documented instructions.

5. Data residency & storage

Personal data and AI processing stay in India, including for disaster recovery. This reflects our approach to the data-localisation and cross-border considerations under §16 of the DPDP Act.

6. Sharing & processors

We do not sell personal data. We share it only:

  • with sub-processors that support the service (such as cloud hosting and infrastructure), under contractual safeguards;
  • with authorized users within your own organization; and
  • where required by law or to protect rights and safety.

7. Data retention

We retain personal data for as long as needed to provide the service and to meet legal, audit and contractual obligations. Evidence snapshots and audit logs may be retained for longer, so that a compliance posture remains provable after the fact. When data is no longer required, it is deleted or anonymised.

8. Your rights as a Data Principal

Under the DPDP Act, you have the right to:

  • access a summary of your personal data and how it is processed;
  • correction, completion and updating of your personal data;
  • erasure of your personal data, subject to legal retention needs;
  • grievance redressal for concerns about our processing; and
  • nominate another individual to exercise your rights in the event of death or incapacity.

To exercise these rights, contact us using the details below. Where we process personal data on behalf of a client Data Fiduciary, we will direct your request to that organization.

9. Security

We protect personal data with technical and organizational measures, including:

  • encryption in transit and at rest;
  • database-level tenant isolation between customers;
  • multi-factor authentication and short-lived access tokens; and
  • audit logging of security-relevant events.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Independent certifications such as SOC 2 and ISO 27001 are on our roadmap and are not yet held.

10. Cookies

We use strictly necessary cookies to run the website and application — for example, to keep you signed in, maintain security, and remember preferences. We aim to minimise non-essential cookies.

11. Children’s data

Radicept is intended for business and organizational use and is not directed to children. Under the DPDP Act, processing a child’s personal data requires verifiable parental consent. We do not knowingly collect children’s personal data through the platform; if you believe we have, please contact us so we can address it.

12. Changes to this policy

We may update this policy from time to time. When we make material changes, we will post the updated policy here and revise the “Last updated” date above.

13. Contact

For questions about this policy, or to make a Data Principal request, contact SOCCKA at soccka@zohomail.in .