Effective Date: June 1, 2026
Indicus Software Pvt Ltd (“INDICUS”, “we”, “our”) operates the GraphX™ platform. This Privacy Policy describes how we collect, use, store, share, and protect information when you use GraphX, including the platform, APIs, browser extensions, AI agents, the Intelligence Marketplace, and related services (collectively, the “Service”).
By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account information: name, email address, company name, role, and contact details provided during registration or waitlist signup.
- Organization details: industry, organization size, technical level, and audience type collected via forms.
- Customer Data: data, files, documents, configurations, workflows, agent definitions, and business processes you upload or create within GraphX.
- Creator Content: capabilities, agents, patterns, and applications you publish to the Intelligence Marketplace.
- Communications: messages sent to our support team, feedback, and survey responses.
- Payment information: billing details processed by third-party payment processors. INDICUS does not store credit card numbers.
1.2 Information Collected Automatically
- Usage data: features accessed, actions performed, session duration, and interaction patterns.
- Device and browser information: IP address, browser type, operating system, device identifiers, and screen resolution.
- Telemetry and diagnostics: platform performance metrics, error logs, and operational data for service reliability.
- Cookies and similar technologies: session management, authentication, and analytics. See Section 8.
1.3 Information from Third-Party Integrations
When you connect external services (via MCP servers, A2A protocols, REST APIs, or browser extensions), GraphX may process data from those services solely to provide the requested functionality. We do not retain third-party data beyond the scope of the active session or workflow unless you explicitly configure persistent storage.
2. How We Use Your Information
- Provide and operate the Service: process your requests, generate applications, orchestrate agents, and deliver AI-powered outputs.
- Maintain and improve the platform: monitor performance, diagnose issues, and develop new features.
- Enforce terms and ensure security: detect fraud, prevent abuse, and protect the integrity of the Service.
- Communicate with you: send service notifications, respond to inquiries, and provide technical support.
- Process payments: manage subscriptions, invoicing, and revenue sharing for Marketplace participants.
- Comply with legal obligations: respond to lawful requests from regulatory authorities and courts.
3. AI Processing and Generated Outputs
GraphX uses AI models, including large language models (LLMs), to generate applications, workflows, agents, recommendations, and other outputs (“Generated Outputs”).
3.1 How AI Processes Your Data
- Prompts, uploaded content, and contextual information are processed to deliver AI Services.
- Processing occurs within the deployment environment selected by the Licensee (on-premise, sovereign cloud, private cloud, or air-gapped).
- Generated Outputs may contain inaccuracies and require human review.
3.2 AI Training
INDICUS does not use Customer Data to train or fine-tune AI models unless the Licensee provides explicit written opt-in consent. Anonymized, aggregated platform usage patterns (not containing Customer Data or proprietary logic) may be used for general platform improvement.
4. Multi-Tenant Data Isolation
GraphX enforces strict multi-tenant isolation:
- Each tenant’s data, capabilities, agent configurations, and query results are logically and technically isolated.
- No tenant can access, view, or query another tenant’s data.
- Cross-enterprise configurations (via the XENT Cross-Enterprise Fabric) require explicit, policy-based permission grants by the data-owning enterprise. Access is governed by read/write/query/subscribe permissions set per node, per role, per tenant.
- All cross-enterprise data access events are logged in audit trails accessible to both parties.
5. Data Sharing and Disclosure
We do not sell your personal information or Customer Data. We may share information in the following limited circumstances:
- Service providers: trusted third parties who assist in operating the Service (hosting, payment processing, analytics), bound by confidentiality obligations.
- Intelligence Marketplace: if you publish Creator Content, other Marketplace users may access it under the terms you set. Your account name and published content descriptions are visible to Marketplace users.
- Legal requirements: when required by applicable law, regulation, legal process, or governmental request.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to the receiving party assuming obligations under this Privacy Policy.
- With your consent: when you explicitly authorize sharing with a named third party.
6. Data Retention
- Account data: retained for the duration of your subscription and for twelve (12) months thereafter, unless earlier deletion is requested.
- Customer Data: retained during the Subscription Term. Upon termination, Licensee may export all Customer Data in machine-readable format. INDICUS deletes Customer Data within thirty (30) days of termination unless retention is required by law.
- Creator Content: retained on the Marketplace for as long as the creator elects to publish it. Delisted content is removed within thirty (30) days.
- Usage and telemetry data: retained in aggregated, anonymized form for up to twenty-four (24) months for platform improvement.
- Communications: retained for as long as necessary to resolve the matter, then for up to twelve (12) months.
7. Data Security
We implement commercially reasonable technical and organizational measures to protect your information:
- Encryption at rest and in transit (TLS 1.2+).
- Role-based access control (RBAC) and least-privilege principles.
- Audit logging for administrative and cross-enterprise actions.
- Regular security assessments and vulnerability management.
- Incident response procedures with seventy-two (72) hour breach notification to affected Licensees.
No system is fully secure. Licensee is responsible for maintaining the security of its own credentials, configurations, and connected systems.
8. Cookies and Tracking Technologies
GraphX uses cookies and similar technologies for:
- Essential cookies: authentication, session management, and security. Required for the Service to function.
- Analytics cookies: aggregated usage patterns to improve the Service. Can be disabled without affecting core functionality.
We do not use advertising cookies or sell data to advertisers. Third-party integrations connected by the Licensee may set their own cookies subject to their own privacy policies.
9. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the personal information we hold about you.
- Correction: request correction of inaccurate or incomplete information.
- Deletion: request deletion of your personal information, subject to legal retention requirements.
- Data portability: receive your data in a structured, machine-readable format.
- Restriction: request restriction of processing in certain circumstances.
- Objection: object to processing based on legitimate interests.
- Withdrawal of consent: withdraw consent for optional processing (e.g., AI training opt-in) at any time.
To exercise these rights, contact us at privacy@indicussoftware.com. We will respond within thirty (30) days.
10. International Data Transfers
INDICUS is headquartered in India. If you access the Service from outside India, your information may be transferred to and processed in India or other jurisdictions where our infrastructure operates.
For deployments where data residency is required, GraphX supports on-premise, sovereign cloud, and air-gapped configurations that keep all data within the Licensee’s selected jurisdiction.
Where cross-border transfers are necessary, INDICUS relies on applicable legal mechanisms (Standard Contractual Clauses, adequacy decisions, or equivalent safeguards) as required by applicable law.
11. Children’s Privacy
The Service is not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected information from a child, we will delete it promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated with at least thirty (30) days’ advance notice via email or in-product notification. Continued use after the notice period constitutes acceptance. The “Effective Date” at the top reflects the most recent revision.
13. Contact Information
For questions, concerns, or requests related to this Privacy Policy:
Indicus Software Pvt Ltd
Email: privacy@indicussoftware.com
Website: https://graphx.world
For data protection inquiries specific to Japanese operations, you may also contact our Japanese representative details as provided on our website.
14. Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of India. Courts located in Pune, Maharashtra, India shall have exclusive jurisdiction over disputes arising from this Privacy Policy.
For Licensees subject to the EU General Data Protection Regulation (GDPR), Japan’s Act on the Protection of Personal Information (APPI), or other applicable data protection laws, the provisions of those laws shall apply to the extent they provide additional protections.