Exac Logo
Exac by Veloryn

Privacy Policy

Effective date: 1 June 2026

This Privacy Policy explains how Exac collects, uses, stores, shares, and protects personal data when you visit our website, contact us, request information, use our products, participate in a pilot, or interact with our services.

For the purposes of this Privacy Policy, "Exac," "we," "us," or "our" means Exac by Veloryn, a company registered in Singapore, with its registered office at Asia Square Tower 1.

Exac provides a precision quoting and commercial execution layer for B2B sales teams and operations. Our system helps organisations enforce pricing rules, eliminate discount leakage, manage approval workflows, and generate accurate, audit-ready quotes at volume.

This Privacy Policy applies to:

  • visitors to our website
  • people who contact us or submit forms
  • prospective customers, partners, and business contacts
  • authorised users of the Exac platform
  • individuals whose personal data may be processed through Exac by our customers
  • suppliers, vendors, and service providers

Where Exac processes personal data on behalf of a customer, that customer is usually responsible for deciding why and how the data is processed. In that situation, Exac acts as a processor, service provider, or equivalent role under applicable law.

This Privacy Policy does not replace the privacy policy of any organisation, reseller, partner, or customer that uses Exac.

Section 01

Who controls your personal data

Exac may act in different roles depending on the context.

When Exac is the controller

Exac is the controller of personal data when we collect and use information for our own business purposes, such as:

  • operating our website
  • responding to enquiries
  • managing sales conversations
  • running pilots and demos
  • managing customer relationships
  • sending business communications
  • improving our website and services
  • managing legal, compliance, and security obligations

When Exac is a processor or service provider

Exac is usually a processor or service provider when we process data inside the Exac platform on behalf of a customer. For example, a business may use Exac to process product, pricing, customer, discount, approval, and commercial data in order to generate accurate quotes, enforce pricing rules, manage approval workflows, and maintain a full audit trail of every commercial decision.

In those cases, the customer determines the purpose and lawful basis for processing. Exac processes the data according to the customer's instructions, the applicable contract, and applicable law.

If your data is processed by one of our customers through Exac, you should contact that organisation directly to exercise your privacy rights.

Section 02

Personal data we collect

The personal data we collect depends on how you interact with Exac.

2.1 Website and enquiry data

  • name
  • work email address
  • phone number
  • company name
  • job title
  • country or region
  • company website
  • message content
  • business goals or areas of interest
  • information you choose to provide in forms or communications

2.2 Business and customer relationship data

  • business contact details
  • company information
  • role and department
  • communication history
  • meeting notes
  • proposal and contract details
  • billing and payment information
  • support requests
  • commercial preferences
  • pilot and implementation requirements

2.3 Platform user data

  • name and email address
  • user role and organisation
  • login and authentication data
  • access permissions
  • activity and audit logs
  • support interactions
  • usage patterns
  • device, browser, and session data

2.4 Commercial and quoting data processed through Exac

  • customer and contact identifiers
  • product and SKU catalogues
  • pricing rules and discount structures
  • quote requests and quote history
  • approval status and approval chain records
  • discount application and override records
  • margin and revenue data
  • sales representative activity
  • CRM data
  • contract and commercial terms
  • audit trail records
  • workflow routing and outcome data

This data is usually provided by, or processed on behalf of, our customer.

2.5 Technical and usage data

  • IP address
  • browser and device type
  • operating system
  • referring pages and pages viewed
  • time spent on pages
  • login activity
  • system and error logs
  • diagnostic data
  • approximate location derived from technical data

2.6 Cookies and similar technologies

We may use cookies, pixels, tags, local storage, and similar technologies to operate our website, improve performance, understand usage, remember preferences, and support security. Cookies may include strictly necessary cookies, analytics cookies, preference cookies, security cookies, and marketing cookies where enabled. You can manage cookies through your browser settings. Where required by law, we will request consent before placing non-essential cookies.

Section 03

How we use personal data

3.1 To operate and improve our website

  • provide website functionality and respond to enquiries
  • monitor website performance and understand visitor interest
  • improve content and user experience
  • protect against spam, abuse, fraud, and security threats

3.2 To communicate with you

  • respond to messages and schedule calls
  • provide information about Exac
  • send proposals or documents
  • manage commercial conversations
  • provide product updates and business communications

You may opt out of marketing communications at any time.

3.3 To provide and manage our services

  • create and manage accounts and authenticate users
  • configure customer environments and deliver pilots
  • provide support and troubleshoot issues
  • monitor performance and maintain service reliability
  • improve product functionality

3.4 To power precision quoting and commercial execution

Where Exac is configured by a customer, the platform may process data to:

  • enforce pricing rules and discount guardrails
  • generate accurate, compliant quotes automatically
  • route quotes through the correct approval workflow
  • flag discount exceptions and margin violations
  • maintain a full audit trail behind every commercial decision
  • provide management with real-time visibility over quoting activity

Unless otherwise agreed, Exac supports controlled commercial execution. Final authority for pricing, discount approval, and contract terms remains with the customer and its approved governance process.

3.5 To support compliance, security, and auditability

  • maintain audit logs and enforce access controls
  • detect suspicious activity and prevent unauthorised access
  • comply with legal and regulatory obligations
  • protect our rights, customers, users, and systems

3.6 To improve Exac

We may use usage data, feedback, diagnostics, aggregated data, and de-identified data to improve product performance, enhance reliability, improve security, and develop new features. We do not use customer platform data or end-customer personal data to train public general-purpose AI models unless expressly agreed in writing with the customer.

Section 04

Legal bases for processing

Depending on the applicable law and context, we may process personal data based on one or more of the following legal bases.

Consent

We may process personal data where you have given consent, such as for certain marketing communications or optional cookies.

Contract

We may process personal data where necessary to enter into, perform, or manage a contract with you or your organisation.

Legitimate interests

We may process personal data where necessary for our legitimate business interests, including operating and improving Exac, responding to business enquiries, securing our systems, managing customer relationships, preventing fraud and misuse, and measuring business performance.

Legal obligation

We may process personal data where necessary to comply with applicable laws, regulations, court orders, regulatory requests, tax obligations, or accounting rules.

Customer instructions

Where we process data on behalf of a customer, we process that data according to the customer's instructions and the applicable contract.

Section 05

Automated processing and quoting logic

Exac is designed to automate and govern commercial quoting at scale. Depending on configuration, Exac may use rules engines, pricing logic, workflow automation, approval routing, and audit systems to process quote requests and generate outputs. These may include:

  • automated pricing calculations based on configured product and pricing rules
  • discount limit enforcement by user role and approval level
  • margin floor validation before quote generation
  • approval routing based on deal size, discount depth, or product type
  • exception flagging for out-of-policy requests
  • full audit trail generation for every quote event

Exac is designed to support controlled commercial execution, not uncontrolled automation. Where Exac is used in commercial workflows:

  • pricing logic is configured and owned by the customer
  • discount thresholds can be set and reviewed
  • human approval can be required at any stage
  • all decisions and overrides are logged and auditable
  • outputs can be reviewed, adjusted, approved, or rejected before being sent
  • final commercial authority remains with the relevant organisation unless otherwise configured

Section 06

Sensitive personal and commercial data

Exac may process sensitive or commercially significant data where a customer lawfully provides it or configures Exac to process it. This may include:

  • pricing and margin information
  • commercial contract terms
  • discount structures and approval thresholds
  • customer revenue and transaction records
  • data that may be considered sensitive under applicable law

We process this data only where permitted by applicable law, contract, and customer instruction. Exac does not intentionally collect sensitive personal data through public website forms.

Section 07

How we share personal data

We do not sell personal data. We may share personal data with the following categories of recipients where necessary and lawful.

Customers

Where Exac processes data on behalf of a customer, outputs, logs, quote records, approval trails, and workflow actions may be made available to that customer and its authorised users.

Service providers

We may share data with trusted service providers including cloud hosting providers, infrastructure providers, security tools, analytics providers, CRM systems, email and communication tools, payment processors, professional advisers, and customer support tools. These service providers are authorised to use personal data only as necessary to provide services to us, subject to contractual obligations.

Professional advisers

We may share data with lawyers, auditors, accountants, consultants, insurers, and advisers where necessary.

Legal and regulatory authorities

We may disclose personal data where required to comply with law, regulation, legal process, court order, government request, or regulatory obligation.

Business transfers

If Exac is involved in a merger, acquisition, financing, restructuring, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate safeguards.

Section 08

International data transfers

Exac may process and store personal data in countries where we, our customers, or our service providers operate. Where personal data is transferred internationally, we take steps designed to protect it in accordance with applicable law, including contractual data protection clauses, data processing agreements, transfer impact assessments where required, security safeguards, access controls, encryption, and customer-approved hosting arrangements.

For enterprise customers, hosting region, deployment model, data residency, and cross-border transfer requirements can be agreed in the relevant contract.

Section 09

Data security

We use technical and organisational measures designed to protect personal data against unauthorised access, loss, misuse, alteration, disclosure, or destruction. These measures may include:

  • encryption in transit and at rest where appropriate
  • access controls and role-based permissions
  • multi-factor authentication where available
  • audit logging and security monitoring
  • least-privilege access and secure development practices
  • vulnerability management and vendor due diligence
  • incident response procedures

No system is completely secure. We cannot guarantee absolute security, but we work to protect personal data using appropriate safeguards for the nature of the data and processing involved.

Section 10

Data retention

We keep personal data only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.

  • website enquiry data may be retained for as long as necessary to respond and manage business follow-up
  • customer relationship data may be retained for the duration of the relationship and a reasonable period afterwards
  • platform user data may be retained while the account is active and for a reasonable period after closure
  • customer platform and quoting data is retained according to the customer contract, configuration, and instructions
  • audit logs may be retained for security, compliance, and accountability purposes
  • billing and legal records may be retained as required by tax, accounting, and legal obligations

Where appropriate, we may delete, anonymise, aggregate, or de-identify data.

Section 11

Your privacy rights

Depending on where you are located and the applicable law, you may have rights in relation to your personal data, including the right to:

  • access your personal data
  • request correction of inaccurate data
  • request deletion of your data
  • object to or restrict certain processing
  • withdraw consent where processing is based on consent
  • request a copy of your data or data portability
  • object to direct marketing
  • lodge a complaint with a regulator

These rights may be limited in some circumstances. If Exac processes your data on behalf of a customer, we may refer your request to that customer. To exercise your rights, contact us using the details in Section 19.

Section 12

Marketing communications

We may send business communications about Exac, including product updates, pilot opportunities, events, insights, or relevant services. You can opt out of marketing emails at any time by using the unsubscribe link or contacting us directly. Even if you opt out of marketing, we may still send non-marketing messages such as service updates, security notices, or support responses.

Section 13

Customer responsibilities

Customers who use Exac are responsible for ensuring that their use of the platform complies with applicable law. This may include responsibility for:

  • providing appropriate privacy notices to end users
  • obtaining required consents and establishing a lawful basis for processing
  • ensuring data accuracy and setting appropriate access permissions
  • configuring pricing rules, discount thresholds, and approval workflows responsibly
  • reviewing automated quote outputs before sending
  • responding to data subject requests and managing retention instructions

Exac provides technology to support commercial execution. Customers remain responsible for their own business decisions and regulatory obligations.

Section 14

Children's privacy

Exac is not directed to children and is not intended for use by children. We do not knowingly collect personal data from children through our website. If you believe a child has provided personal data to us, please contact us and we will take appropriate steps to delete it.

Section 15

Third-party links and integrations

Our website or platform may contain links to third-party websites, products, or services. Exac may also integrate with customer-selected systems such as CRM tools, ERP platforms, communication channels, analytics tools, cloud services, or internal systems. We are not responsible for the privacy practices of third parties. Their use of personal data is governed by their own privacy policies and contractual terms.

Section 16

Data breach and incident response

If we become aware of a security incident involving personal data, we will investigate and take appropriate action. Where required by law or contract, we will notify affected customers, regulators, or individuals within applicable timeframes. Customers are responsible for notifying their own users, customers, regulators, or other parties where required, unless otherwise agreed by contract.

Section 17

Copyright and intellectual property

All content, materials, names, branding, designs, text, graphics, platform descriptions, product concepts, system architecture, workflows, frameworks, methodologies, visual identity, logos, user interface elements, website structure, documentation, and other materials displayed on or made available through Exac are owned by or licensed to Exac by Veloryn and/or Veloryn, unless otherwise stated.

The names Exac, Exac by Veloryn, Veloryn, and any related logos, marks, product names, service names, designs, slogans, trade dress, and brand identifiers are protected intellectual property and may not be copied, reproduced, modified, imitated, republished, distributed, displayed, reverse engineered, scraped, or used in any commercial context without prior written permission. Any unauthorised use is strictly prohibited and may result in legal action.

Section 18

Changes to this Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we may notify you by updating the date at the top of this page, posting a notice on our website, or sending an email. Your continued use of our website or services after an update means that you acknowledge the updated Privacy Policy.

Section 19

Contact us

If you have questions about this Privacy Policy, our data practices, or your privacy rights, you can contact us at:

Exac Privacy Team

Exac by Veloryn
Asia Square Tower 1, Singapore
Email: privacy@exac.cc
Website: exac.cc

Section 20

Additional terms for enterprise customers

For enterprise customers, this Privacy Policy should be read together with the applicable master services agreement, data processing agreement, security schedule, pilot agreement, statement of work, service order, confidentiality agreement, and customer-specific deployment documentation.

If there is a conflict between this Privacy Policy and a signed agreement with a customer, the signed agreement will control to the extent of that conflict.

Section 21

Summary

Exac is designed to help organisations enforce pricing discipline, eliminate quoting errors, and execute commercial decisions with speed, accuracy, and a full audit trail.

We take privacy, security, auditability, and responsible deployment seriously. Our goal is to support faster, more accurate, and more governed commercial execution — while keeping data use controlled, transparent, and aligned with applicable law.