Privacy Policy
This Privacy Policy explains how Exac collects, uses, stores, shares, and protects personal data when you visit our website, contact us, request information, use our products, participate in a pilot, or interact with our services.
For the purposes of this Privacy Policy, "Exac," "we," "us," or "our" means Exac by Veloryn, a company registered in Singapore, with its registered office at Asia Square Tower 1.
Exac provides a precision quoting and commercial execution layer for B2B sales teams and operations. Our system helps organisations enforce pricing rules, eliminate discount leakage, manage approval workflows, and generate accurate, audit-ready quotes at volume.
This Privacy Policy applies to:
- visitors to our website
- people who contact us or submit forms
- prospective customers, partners, and business contacts
- authorised users of the Exac platform
- individuals whose personal data may be processed through Exac by our customers
- suppliers, vendors, and service providers
Where Exac processes personal data on behalf of a customer, that customer is usually responsible for deciding why and how the data is processed. In that situation, Exac acts as a processor, service provider, or equivalent role under applicable law.
This Privacy Policy does not replace the privacy policy of any organisation, reseller, partner, or customer that uses Exac.
Contents
- 01Who controls your personal data
- 02Personal data we collect
- 03How we use personal data
- 04Legal bases for processing
- 05Automated processing and quoting logic
- 06Sensitive personal and commercial data
- 07How we share personal data
- 08International data transfers
- 09Data security
- 10Data retention
- 11Your privacy rights
- 12Marketing communications
- 13Customer responsibilities
- 14Children's privacy
- 15Third-party links and integrations
- 16Data breach and incident response
- 17Copyright and intellectual property
- 18Changes to this Privacy Policy
- 19Contact us
- 20Additional terms for enterprise customers
- 21Summary
Section 01
Who controls your personal data
Exac may act in different roles depending on the context.
When Exac is the controller
Exac is the controller of personal data when we collect and use information for our own business purposes, such as:
- operating our website
- responding to enquiries
- managing sales conversations
- running pilots and demos
- managing customer relationships
- sending business communications
- improving our website and services
- managing legal, compliance, and security obligations
When Exac is a processor or service provider
Exac is usually a processor or service provider when we process data inside the Exac platform on behalf of a customer. For example, a business may use Exac to process product, pricing, customer, discount, approval, and commercial data in order to generate accurate quotes, enforce pricing rules, manage approval workflows, and maintain a full audit trail of every commercial decision.
In those cases, the customer determines the purpose and lawful basis for processing. Exac processes the data according to the customer's instructions, the applicable contract, and applicable law.
If your data is processed by one of our customers through Exac, you should contact that organisation directly to exercise your privacy rights.
Section 02
Personal data we collect
The personal data we collect depends on how you interact with Exac.
2.1 Website and enquiry data
- name
- work email address
- phone number
- company name
- job title
- country or region
- company website
- message content
- business goals or areas of interest
- information you choose to provide in forms or communications
2.2 Business and customer relationship data
- business contact details
- company information
- role and department
- communication history
- meeting notes
- proposal and contract details
- billing and payment information
- support requests
- commercial preferences
- pilot and implementation requirements
2.3 Platform user data
- name and email address
- user role and organisation
- login and authentication data
- access permissions
- activity and audit logs
- support interactions
- usage patterns
- device, browser, and session data
2.4 Commercial and quoting data processed through Exac
- customer and contact identifiers
- product and SKU catalogues
- pricing rules and discount structures
- quote requests and quote history
- approval status and approval chain records
- discount application and override records
- margin and revenue data
- sales representative activity
- CRM data
- contract and commercial terms
- audit trail records
- workflow routing and outcome data
This data is usually provided by, or processed on behalf of, our customer.
2.5 Technical and usage data
- IP address
- browser and device type
- operating system
- referring pages and pages viewed
- time spent on pages
- login activity
- system and error logs
- diagnostic data
- approximate location derived from technical data
2.6 Cookies and similar technologies
We may use cookies, pixels, tags, local storage, and similar technologies to operate our website, improve performance, understand usage, remember preferences, and support security. Cookies may include strictly necessary cookies, analytics cookies, preference cookies, security cookies, and marketing cookies where enabled. You can manage cookies through your browser settings. Where required by law, we will request consent before placing non-essential cookies.
Section 03
How we use personal data
3.1 To operate and improve our website
- provide website functionality and respond to enquiries
- monitor website performance and understand visitor interest
- improve content and user experience
- protect against spam, abuse, fraud, and security threats
3.2 To communicate with you
- respond to messages and schedule calls
- provide information about Exac
- send proposals or documents
- manage commercial conversations
- provide product updates and business communications
You may opt out of marketing communications at any time.
3.3 To provide and manage our services
- create and manage accounts and authenticate users
- configure customer environments and deliver pilots
- provide support and troubleshoot issues
- monitor performance and maintain service reliability
- improve product functionality
3.4 To power precision quoting and commercial execution
Where Exac is configured by a customer, the platform may process data to:
- enforce pricing rules and discount guardrails
- generate accurate, compliant quotes automatically
- route quotes through the correct approval workflow
- flag discount exceptions and margin violations
- maintain a full audit trail behind every commercial decision
- provide management with real-time visibility over quoting activity
Unless otherwise agreed, Exac supports controlled commercial execution. Final authority for pricing, discount approval, and contract terms remains with the customer and its approved governance process.
3.5 To support compliance, security, and auditability
- maintain audit logs and enforce access controls
- detect suspicious activity and prevent unauthorised access
- comply with legal and regulatory obligations
- protect our rights, customers, users, and systems
3.6 To improve Exac
We may use usage data, feedback, diagnostics, aggregated data, and de-identified data to improve product performance, enhance reliability, improve security, and develop new features. We do not use customer platform data or end-customer personal data to train public general-purpose AI models unless expressly agreed in writing with the customer.
Section 04
Legal bases for processing
Depending on the applicable law and context, we may process personal data based on one or more of the following legal bases.
Consent
We may process personal data where you have given consent, such as for certain marketing communications or optional cookies.
Contract
We may process personal data where necessary to enter into, perform, or manage a contract with you or your organisation.
Legitimate interests
We may process personal data where necessary for our legitimate business interests, including operating and improving Exac, responding to business enquiries, securing our systems, managing customer relationships, preventing fraud and misuse, and measuring business performance.
Legal obligation
We may process personal data where necessary to comply with applicable laws, regulations, court orders, regulatory requests, tax obligations, or accounting rules.
Customer instructions
Where we process data on behalf of a customer, we process that data according to the customer's instructions and the applicable contract.
Section 05
Automated processing and quoting logic
Exac is designed to automate and govern commercial quoting at scale. Depending on configuration, Exac may use rules engines, pricing logic, workflow automation, approval routing, and audit systems to process quote requests and generate outputs. These may include:
- automated pricing calculations based on configured product and pricing rules
- discount limit enforcement by user role and approval level
- margin floor validation before quote generation
- approval routing based on deal size, discount depth, or product type
- exception flagging for out-of-policy requests
- full audit trail generation for every quote event
Exac is designed to support controlled commercial execution, not uncontrolled automation. Where Exac is used in commercial workflows:
- pricing logic is configured and owned by the customer
- discount thresholds can be set and reviewed
- human approval can be required at any stage
- all decisions and overrides are logged and auditable
- outputs can be reviewed, adjusted, approved, or rejected before being sent
- final commercial authority remains with the relevant organisation unless otherwise configured
Section 06
Sensitive personal and commercial data
Exac may process sensitive or commercially significant data where a customer lawfully provides it or configures Exac to process it. This may include:
- pricing and margin information
- commercial contract terms
- discount structures and approval thresholds
- customer revenue and transaction records
- data that may be considered sensitive under applicable law
We process this data only where permitted by applicable law, contract, and customer instruction. Exac does not intentionally collect sensitive personal data through public website forms.
Section 07
How we share personal data
We do not sell personal data. We may share personal data with the following categories of recipients where necessary and lawful.
Customers
Where Exac processes data on behalf of a customer, outputs, logs, quote records, approval trails, and workflow actions may be made available to that customer and its authorised users.
Service providers
We may share data with trusted service providers including cloud hosting providers, infrastructure providers, security tools, analytics providers, CRM systems, email and communication tools, payment processors, professional advisers, and customer support tools. These service providers are authorised to use personal data only as necessary to provide services to us, subject to contractual obligations.
Professional advisers
We may share data with lawyers, auditors, accountants, consultants, insurers, and advisers where necessary.
Legal and regulatory authorities
We may disclose personal data where required to comply with law, regulation, legal process, court order, government request, or regulatory obligation.
Business transfers
If Exac is involved in a merger, acquisition, financing, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.
Section 08
International data transfers
Exac may process and store personal data in countries where we, our customers, or our service providers operate. Where personal data is transferred internationally, we take steps designed to protect it in accordance with applicable law, including contractual data protection clauses, data processing agreements, transfer impact assessments where required, security safeguards, access controls, encryption, and customer-approved hosting arrangements.
For enterprise customers, hosting region, deployment model, data residency, and cross-border transfer requirements can be agreed in the relevant contract.
Section 09
Data security
We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These measures may include:
- encryption in transit and at rest where appropriate
- access controls and role-based permissions
- multi-factor authentication where available
- audit logging and security monitoring
- least-privilege access and secure development practices
- vulnerability management and vendor due diligence
- incident response procedures
No system is completely secure. We cannot guarantee absolute security, but we work to protect personal data using appropriate safeguards for the nature of the data and processing involved.
Section 10
Data retention
We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
- website enquiry data may be retained for as long as necessary to respond and manage business follow-up
- customer relationship data may be retained for the duration of the relationship and a reasonable period afterwards
- platform user data may be retained while the account is active and for a reasonable period after closure
- customer platform and quoting data is retained according to the customer contract, configuration, and instructions
- audit logs may be retained for security, compliance, and accountability purposes
- billing and legal records may be retained as required by tax, accounting, and legal obligations
Where appropriate, we may delete, anonymise, aggregate, or de-identify data.
Section 11
Your privacy rights
Depending on where you are located and the applicable law, you may have rights in relation to your personal data, including the right to:
- access your personal data
- request correction of inaccurate data
- request deletion of your data
- object to or restrict certain processing
- withdraw consent where processing is based on consent
- request a copy of your data or data portability
- object to direct marketing
- lodge a complaint with a regulator
These rights may be limited in some circumstances. If Exac processes your data on behalf of a customer, we may refer your request to that customer. To exercise your rights, contact us using the details in Section 19.
Section 12
Marketing communications
We may send business communications about Exac, including product updates, pilot opportunities, events, insights, or relevant services. You can opt out of marketing emails at any time by using the unsubscribe link or contacting us directly. Even if you opt out of marketing, we may still send non-marketing messages such as service updates, security notices, or support responses.
Section 13
Customer responsibilities
Customers who use Exac are responsible for ensuring that their use of the platform complies with applicable law. This may include responsibility for:
- providing appropriate privacy notices to end users
- obtaining required consents and establishing a lawful basis for processing
- ensuring data accuracy and setting appropriate access permissions
- configuring pricing rules, discount thresholds, and approval workflows responsibly
- reviewing automated quote outputs before sending
- responding to data subject requests and managing retention instructions
Exac provides technology to support commercial execution. Customers remain responsible for their own business decisions and regulatory obligations.
Section 14
Children's privacy
Exac is not directed to children and is not intended for use by children. We do not knowingly collect personal data from children through our website. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to delete it.
Section 15
Third-party links and integrations
Our website or platform may contain links to third-party websites, products, or services. Exac may also integrate with customer-selected systems such as CRM tools, ERP platforms, communication channels, analytics tools, cloud services, or internal systems. We are not responsible for the privacy practices of third parties. Their use of personal data is governed by their own privacy policies and contractual terms.
Section 16
Data breach and incident response
If we become aware of a security incident involving personal data, we will investigate and take appropriate action. Where required by law or contract, we will notify affected customers, regulators, or individuals within applicable timeframes. Customers are responsible for notifying their own users, customers, regulators, or other parties where required, unless otherwise agreed by contract.
Section 17
Copyright and intellectual property
All content, materials, names, branding, designs, text, graphics, platform descriptions, product concepts, system architecture, workflows, frameworks, methodologies, visual identity, logos, user interface elements, website structure, documentation, and other materials displayed on or made available through Exac are owned by or licensed to Exac by Veloryn and/or Veloryn, unless otherwise stated.
The names Exac, Exac by Veloryn, Veloryn, and any related logos, marks, product names, service names, designs, slogans, trade dress, and brand identifiers are protected intellectual property and may not be copied, reproduced, modified, imitated, republished, distributed, displayed, reverse engineered, scraped, or used in any commercial context without prior written permission. Any unauthorised use is strictly prohibited and may result in legal action.
Section 18
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we may notify you by updating the date at the top of this page, posting a notice on our website, or sending an email. Your continued use of our website or services after an update means that you acknowledge the updated Privacy Policy.
Section 19
Contact us
If you have questions about this Privacy Policy, our data practices, or your privacy rights, you can contact us at:
Exac Privacy Team
Exac by Veloryn
Asia Square Tower 1, Singapore
Email: privacy@exac.cc
Website: exac.cc
Section 20
Additional terms for enterprise customers
For enterprise customers, this Privacy Policy should be read together with the applicable master services agreement, data processing agreement, security schedule, pilot agreement, statement of work, service order, confidentiality agreement, and customer-specific deployment documentation.
If there is a conflict between this Privacy Policy and a signed agreement with a customer, the signed agreement will control to the extent of that conflict.
Section 21
Summary
Exac is designed to help organisations enforce pricing discipline, eliminate quoting errors, and execute commercial decisions with speed, accuracy, and a full audit trail.
We take privacy, security, auditability, and responsible deployment seriously. Our goal is to support faster, more accurate, and more governed commercial execution — while keeping data use controlled, transparent, and aligned with applicable law.