This Privacy Policy explains how Verdeshell Technologies Pvt Ltd (operating the Pleisys brand) collects, uses, and protects personal data when you use Cortex. The policy is designed to satisfy the Indian Digital Personal Data Protection Act 2023 (DPDP), the EU General Data Protection Regulation (GDPR), and the California Consumer Privacy Act / California Privacy Rights Act (CCPA/CPRA).
1. Roles
For Tenant content (conversations, memos, agent role definitions, products, prompts), Cortex acts as a data processor on behalf of the Tenant (the data fiduciary or controller). For account-level data (the email address you sign up with, billing details, login telemetry), Cortex acts as an independent data controller.
2. Categories of personal data we process
- Account: email, display name, hashed password, two-factor authentication secret and recovery codes where you have enabled them (the secret is AES-256-GCM encrypted at rest; recovery codes are stored only as hashes), last login timestamp.
- Billing: legal entity name, GSTIN (for Indian Customers), billing address, currency, payment-gateway customer + subscription IDs, invoice line items.
- Tenant content: conversations, memos, agent prompts, uploaded files (stored in AWS S3).
- Telemetry: IP address, User-Agent, request IDs, error stack traces (PII-redacted before leaving the server).
- Cross-product links: if you connect Cortex to another Verdeshell/Pleisys product, the linked account’s external user ID and email.
3. Purposes and legal bases
- Operating the Service — contractual necessity (DPDP s.7(a), GDPR Art. 6(1)(b)).
- Billing and tax compliance — legal obligation (DPDP s.7(c), GDPR Art. 6(1)(c)).
- Security, fraud prevention, abuse detection — legitimate interest (GDPR Art. 6(1)(f)).
- Service improvement (aggregated, anonymised metrics) — legitimate interest.
- Optional analytics + marketing — consent (cookie banner).
- Cross-product linking — consent (explicit opt-in when you create the link; revocable at any time from Settings).
4. International transfers
Cortex stores primary tenant data on a hardened, self-managed Hostinger VPS (native PostgreSQL); file/object storage uses AWS S3 (ap-south-1, Mumbai). Automated encrypted database backups are on our roadmap and not yet running — see /security. Anthropic, our LLM provider, processes prompts and completions in the United States under our enterprise no-training agreement. Cross-border transfers rely on EU→India Standard Contractual Clauses, with onward transfer to Anthropic (US) under SCCs, DPDP-compliant cross-border transfer agreements, and equivalent contractual protections. The full list of sub-processors is at /legal/sub-processors.
5. Retention
Active tenant data is retained for as long as the subscription remains active. On Customer-initiated closure, a 30-day reversible grace window applies; after that, an erasure cascade removes conversations, memos, synthesis sessions, agent role definitions, product topics, and prompt templates. Invoices and audit logs are retained for a minimum of 7 years to meet Indian regulatory obligations; audit logs are append-only with no deletion path implemented yet, including past the 7-year mark.
6. Your rights (DPDP / GDPR / CCPA)
You may exercise the following rights at any time by visiting /settings/account when logged in, or by emailing privacy@cortex.pleisys.com:
- Right of access — export a machine-readable bundle of all your tenant data (DSAR).
- Right of correction — account admins can correct a user’s role assignment in-product today (Settings → Users); display-name, email, and billing/legal-name correction are not yet self-service. Email privacy@cortex.pleisys.com for those.
- Right of erasure — a Customer (tenant) can request account closure and full deletion after the 30-day grace window. An individual whose employer’s account stays open can request erasure of their own personal data by emailing privacy@cortex.pleisys.com; we handle this manually today rather than through a self-service control.
- Right to withdraw consent — revoke analytics and marketing-cookie consent from the cookie banner.
- Right to restriction of processing and right to object — no self-service control exists for these yet; email privacy@cortex.pleisys.com and we will handle the request manually.
- Right to lodge a complaint — with the Data Protection Board of India (DPDP) or your local supervisory authority (GDPR).
7. Security
Three layers of tenant isolation: JWT-bound tenant claim, per-request SET LOCAL app.tenant_id, and FORCED Postgres Row-Level Security on every tenant-scoped table. Passwords are hashed with Argon2id (memory: 64 MiB, iterations: 3, parallelism: 4). Refresh tokens rotate per request with family reuse detection. Transport is TLS 1.3.
8. Children
Cortex is intended for business use. We do not knowingly collect data from anyone under 18. If you believe we have, contact us and we will remove the data.
9. Changes
Material changes will be notified by email 30 days in advance.
10. Contact
Privacy and data-protection enquiries: privacy@cortex.pleisys.com. We have not appointed a formal, independent Data Protection Officer under GDPR Art 37 / DPDP — neither is currently required at our processing scale, and we’ll appoint one and update this notice if that changes. The mailbox above is monitored by the founder for privacy and data-protection matters in the meantime. Postal: Verdeshell Technologies Pvt Ltd, Registered Office: Manesar, Gurgaon, Haryana, India.