LEGAL & TRUST

Privacy Policy

How Ultro collects, uses, protects, and processes information across the Ultro ERP platform and related services.

Ultro ERP Last updated: Sep 7, 2026
Ultro Softtech India Private Limited
C-001/A2, Wework Berger Delhi One, Sector 16-B, Noida, Gautam Budh Nagar, UP, 201301, India
Effective Date Sep 7, 2026
Last Updated Sep 7, 2026
Privacy Contact info@ultro.ai

1. Introduction

Ultro Softtech India Private Limited ("Ultro") provides Ultro ERP, a business management and enterprise resource planning platform designed to help organisations manage and automate business processes, including finance, accounting, procurement, sales, inventory, human resources, customer relationship management, operations, workflows, reporting, analytics, and related business activities.

This Privacy Policy explains how Ultro collects, uses, stores, discloses, and otherwise processes personal data in connection with:

  • the Ultro ERP platform;
  • Ultro websites and web applications;
  • Ultro mobile applications;
  • customer support and related services;
  • integrations and connected services; and
  • optional artificial intelligence and large language model ("AI/LLM") features.

This Privacy Policy is intended to provide transparency about our privacy practices and to explain the rights and responsibilities that may apply to individuals and organisations using Ultro.

Depending on the nature of the information and our relationship with the relevant organisation or individual, Ultro may act as a Data Fiduciary / Data Controller or as a Data Processor / Data Processor on behalf of a customer.

2. Our Role in Processing Personal Data

2.1 Ultro as Data Fiduciary / Data Controller

Ultro may determine the purposes and means of processing certain personal data relating to individuals who interact directly with Ultro.

Examples may include information relating to:

  • website visitors;
  • prospective customers;
  • customer and partner contacts;
  • users of Ultro's public websites;
  • account administrators;
  • individuals who communicate with Ultro;
  • individuals who request support or information; and
  • users of Ultro services where Ultro determines the purposes of processing.

In such circumstances, Ultro may act as a Data Fiduciary under India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and as a Data Controller under applicable data protection laws, including the GDPR where applicable.

2.2 Ultro as Data Processor

When an organisation subscribes to Ultro and uses the platform to manage its own business operations, that organisation generally determines the purposes for which business data is processed.

Such data may include employee, customer, supplier, partner, financial, transactional, operational, or other business information entered into Ultro by or on behalf of the customer.

In these circumstances, the customer may act as the Data Fiduciary / Data Controller, while Ultro acts as a Data Processor / Data Processor on behalf of a customer, processing information in accordance with the customer's instructions and applicable contractual arrangements.

The customer's instructions, contractual terms, and applicable Data Processing Agreement ("DPA") may contain additional provisions governing the processing of customer data.

3. Information We Process

The information processed through Ultro depends on the modules, features, integrations, configuration, and services used by each customer.

We may process the following broad categories of information.

3.1 Account and Business Information

Information relating to organisations and business accounts, including:

  • organisation name;
  • business contact information;
  • registration and tax-related information;
  • business addresses;
  • industry and business profile information;
  • subscription and account information; and
  • information relating to authorised representatives.

3.2 Identity and Account Information

Information relating to users and account administration, including:

  • name;
  • email address;
  • phone number;
  • username and login information;
  • role, designation, department, and organisational information;
  • account preferences;
  • authentication and access-related information; and
  • information used to manage user permissions.

3.3 Employee and Human Resources Information

Where customers use Ultro's HR functionality, the platform may process information relating to employees, contractors, or other workforce members, including information necessary to manage:

  • employee profiles;
  • employment and organisational information;
  • attendance and leave;
  • payroll and compensation;
  • benefits;
  • employee documents;
  • performance and related HR processes; and
  • other workforce-related activities configured by the customer.

3.4 Location Information

Where location-based functionality is enabled, Ultro may process location information associated with authorised business activities, such as field operations, attendance, visits, service activities, or other customer-configured workflows.

The availability and precision of location information depend on the relevant feature, device permissions, and customer configuration.

3.5 Customer, CRM and Sales Information

Where CRM and sales functionality is used, Ultro may process information relating to:

  • customers and prospects;
  • contacts;
  • leads and opportunities;
  • sales activities;
  • quotations and sales orders;
  • communications and interactions;
  • customer preferences;
  • service or relationship information; and
  • other CRM information entered or generated through the platform.

3.6 Vendor, Supplier and Partner Information

Ultro may process information relating to suppliers, vendors, service providers, business partners, and other third parties managed through the platform.

3.7 Financial and Transactional Information

Depending on the modules used, Ultro may process business and financial information such as:

  • invoices and bills;
  • payments and receipts;
  • accounting records;
  • tax information;
  • purchase transactions;
  • sales transactions;
  • expense information;
  • banking and payment-related information;
  • financial reports; and
  • other transactional information entered into the platform.

3.8 Operational and Business Information

Ultro may process information relating to business operations, including:

  • inventory;
  • products and services;
  • warehouses;
  • procurement;
  • projects;
  • tasks;
  • workflows;
  • approvals;
  • assets;
  • service operations;
  • manufacturing or operational information; and
  • other business information configured by the customer.

3.9 Communications and User-Generated Content

We may process information contained in communications, support requests, messages, comments, notes, feedback, uploaded content, and other information users submit through the platform or communicate to Ultro.

3.10 AI and LLM Interaction Data

Where AI/LLM features are enabled, information may be processed in connection with user interactions with those features.

Depending on the functionality used, this may include:

  • prompts and questions submitted by users;
  • information selected or referenced by users;
  • relevant ERP data retrieved to answer a request;
  • AI-generated responses;
  • information required to prepare or facilitate business transactions;
  • interaction and usage information; and
  • other information necessary to provide the requested AI functionality.

3.11 Technical and Usage Information

We may automatically collect certain technical and usage information, such as:

  • IP address;
  • browser and device information;
  • operating system;
  • application version;
  • log information;
  • timestamps;
  • session information;
  • diagnostic information;
  • security events;
  • feature usage; and
  • information relating to how the platform is accessed and used.

3.12 Documents and Media

Where supported by the platform, users may upload or otherwise provide:

  • documents;
  • images;
  • attachments;
  • files;
  • scanned records;
  • business records; and
  • other digital content.

The specific information processed depends on the customer's configuration and use of the platform.

4. How We Use Personal Data

We process personal data for purposes that are reasonably necessary to provide, secure, maintain, and improve Ultro and the services requested by our customers and users.

4.1 Provide and Operate the Platform

We may use personal data to:

  • provide and maintain Ultro;
  • create and manage accounts;
  • authenticate users;
  • manage roles and permissions;
  • process business transactions;
  • operate workflows and approval processes;
  • provide reporting and analytics;
  • store and retrieve business information;
  • enable integrations;
  • provide customer support; and
  • perform other functions requested or configured by customers.

4.2 Security and Protection

We may process information to:

  • protect accounts and systems;
  • detect and prevent unauthorised access;
  • identify fraud, abuse, or security incidents;
  • investigate suspicious activity;
  • maintain system integrity;
  • troubleshoot technical issues; and
  • protect Ultro, our customers, users, and other parties.

4.3 Communications

We may use personal data to communicate with customers and users regarding:

  • account administration;
  • service updates;
  • security notifications;
  • support requests;
  • product-related communications;
  • billing and subscription matters; and
  • other service-related matters.

Where required by applicable law, we will obtain appropriate consent for marketing communications.

4.4 Customer-Configured Features and Integrations

Customers may configure Ultro to connect with third-party services, applications, APIs, or other systems.

Where such integrations are enabled, information may be processed or exchanged as necessary to provide the requested functionality and in accordance with the customer's configuration and applicable contractual terms.

4.5 AI and LLM Features

Where enabled by a customer, we may process information to provide AI-powered capabilities, including:

  • answering natural-language questions about business information;
  • generating summaries and insights;
  • analysing sales, purchasing, financial, operational, or other ERP information;
  • assisting with business workflows;
  • preparing or facilitating business transactions;
  • generating recommendations or draft content; and
  • supporting other AI-enabled functionality.

AI functionality may involve transmission of relevant information to an external LLM provider selected and authorised by the subscribing organisation.

4.6 Improve and Maintain Ultro

We may process appropriate technical, operational, and usage information to:

  • maintain platform reliability;
  • diagnose problems;
  • monitor performance;
  • improve functionality;
  • develop new features;
  • enhance security; and
  • improve the overall user experience.

Where customer business data is processed for these purposes, we will do so in accordance with applicable contractual restrictions and data protection requirements.

4.7 Legal and Regulatory Requirements

We may process information where necessary to:

  • comply with applicable laws and regulations;
  • respond to lawful requests from authorities;
  • establish, exercise, or defend legal claims;
  • enforce agreements;
  • prevent or investigate unlawful activity; or
  • protect rights, safety, and property.

4.8 Business Administration

We may process information necessary for:

  • billing and payment administration;
  • accounting;
  • auditing;
  • corporate governance;
  • business operations;
  • maintaining business records;
  • managing contracts; and
  • other legitimate administrative purposes.

5. AI and Large Language Model Integrations

Ultro may provide optional capabilities that allow customers to connect Ultro with third-party artificial intelligence and large language model ("LLM") providers.

Depending on the features and configuration available, customers may connect providers such as:

  • OpenAI;
  • Google Gemini;
  • Anthropic Claude; and
  • other supported AI/LLM providers.

Ultro is not itself the underlying third-party LLM provider. Instead, Ultro provides an integration and orchestration layer that can facilitate communication between the Ultro ERP environment and an LLM provider selected and authorised by the subscribing organisation.

5.1 How AI Interactions Work

When an authorised user initiates an AI interaction, Ultro may, depending on the requested functionality:

  1. authenticate the user;
  2. verify the user's permissions;
  3. identify the relevant ERP information required to fulfil the request;
  4. retrieve relevant information from the customer's Ultro environment;
  5. construct the appropriate request or context;
  6. transmit the relevant information to the LLM provider selected and authorised by the customer;
  7. receive the resulting AI-generated response;
  8. display the response to the user; and
  9. where supported, facilitate an authorised action within Ultro.

The exact processing flow depends on the AI provider, model, feature, customer configuration, and functionality being used.

5.2 Customer-Controlled AI Providers

The subscribing organisation is responsible for selecting and authorising the AI/LLM providers it connects to Ultro.

The customer may configure the providers, models, credentials, and related settings available through Ultro.

API credentials and similar authentication information supplied by the customer are intended for secure system use and should not be exposed to ordinary users.

5.3 AI Transactional Actions

Certain AI-enabled functionality may assist users in preparing or carrying out business activities, such as:

  • preparing purchase requisitions;
  • preparing purchase orders;
  • preparing sales orders;
  • retrieving business information;
  • generating or analysing reports;
  • initiating workflows; or
  • other ERP actions supported by the platform.

AI functionality does not by itself grant a user permissions that the user does not otherwise have.

Where an AI interaction results in an ERP action, the action remains subject to applicable user permissions, system controls, approval workflows, and customer configuration.

5.4 Transmission to LLM Providers

The user initiates the AI interaction, and Ultro facilitates the transmission of the relevant data to the LLM provider selected and authorised by the subscribing organisation.

The applicable LLM provider may process information in accordance with its own terms, privacy policy, data processing terms, security practices, and configuration selected by the customer.

Customers should review the applicable terms and privacy documentation of the LLM providers they connect to Ultro.

5.5 AI Output

AI-generated information may contain inaccuracies, omissions, or errors.

AI-generated outputs should not automatically be treated as authoritative financial, legal, tax, HR, operational, or other professional advice.

Users should review and verify AI-generated information before relying on it or taking material business action.

6. Legal Basis for Processing

The legal basis for processing depends on the applicable law and the context in which information is processed.

Where applicable, we may process personal data based on:

  • consent;
  • performance of a contract or provision of requested services;
  • compliance with legal obligations;
  • legitimate interests, where permitted by applicable law;
  • protection of rights and safety; and
  • other lawful grounds available under applicable legislation.

Where Ultro processes customer data as a Data Processor, the customer generally determines the applicable lawful basis for processing and is responsible for ensuring that its processing instructions and use of the platform comply with applicable law.

7. Data Sharing and Disclosure

We may disclose or make personal data available where necessary to operate Ultro and provide requested services.

7.1 Service Providers and Subprocessors

We may use third-party service providers to support areas such as:

  • hosting and cloud infrastructure;
  • database and storage services;
  • communications;
  • analytics;
  • security;
  • monitoring;
  • customer support;
  • payment processing;
  • infrastructure management; and
  • other services required to operate Ultro.

Where required, appropriate contractual and technical safeguards are implemented.

7.2 AI and LLM Providers

Where an AI/LLM integration is enabled by a customer, relevant information may be transmitted to the LLM provider selected and authorised by that customer.

7.3 Customer-Configured Integrations

Information may be shared with third-party services that a customer chooses to connect to Ultro.

7.4 Legal and Regulatory Authorities

We may disclose information where required or permitted by applicable law, including in response to lawful requests, court orders, regulatory requirements, or governmental processes.

7.5 Corporate Transactions

Information may be disclosed as part of a merger, acquisition, financing, restructuring, sale of assets, or similar corporate transaction, subject to applicable legal requirements.

7.6 Protection of Rights and Safety

We may disclose information where reasonably necessary to prevent fraud, abuse, security threats, unlawful activity, or harm to Ultro, our users, customers, or others.

We Do Not Sell Personal Data

Ultro does not sell personal data.

8. Data Retention

We retain personal data for as long as reasonably necessary to:

  • provide the requested services;
  • maintain customer accounts;
  • fulfil contractual obligations;
  • comply with legal, tax, accounting, or regulatory requirements;
  • resolve disputes;
  • enforce agreements; and
  • protect our legitimate business interests.

Where Ultro processes information on behalf of a customer, retention may be determined by the customer's instructions and contractual arrangements.

Following termination of a customer's subscription or services, customer data may remain available for a limited period for purposes such as account closure, recovery, legal compliance, backup management, and dispute resolution, subject to applicable contractual and legal requirements.

Different categories of information may be retained for different periods.

9. Data Security

Ultro takes reasonable technical and organisational measures designed to protect personal data against unauthorised access, use, alteration, disclosure, loss, or destruction.

Depending on the nature of the service and information involved, safeguards may include:

  • access controls;
  • authentication mechanisms;
  • role-based permissions;
  • encryption and secure transmission mechanisms;
  • secure storage practices;
  • logging and monitoring;
  • backup and recovery controls;
  • vulnerability and security management;
  • infrastructure security controls; and
  • organisational security procedures.

No method of electronic transmission or storage can be guaranteed to be completely secure.

Customers are also responsible for implementing appropriate security practices within their organisation, including managing user access, credentials, permissions, devices, and integrations.

10. Mobile App \u2014 Location & Attendance Data

The Ultro mobile application captures location data across several distinct business workflows, each with a specific and limited purpose. Location is never collected passively, never collected in the background outside of an active work session, and never used for advertising or profiling.

10.1 Attendance \u2014 All Employees

Any employee using the app to record their attendance (clock-in / clock-out) has a single GPS coordinate captured at the moment of that action. This is used to verify the employee was at or near their designated workplace or site at the time of the attendance event.

No continuous or background tracking occurs during normal attendance use \u2014 it is a one-time location snapshot per check-in or check-out.

10.2 Field Staff & Field Trip Tracking

Employees assigned to field operations use the app's Field Staff Management module to log and track their movements during active field trips. When a field session is started, the app collects continuous GPS coordinates \u2014 including when the app is running in the background \u2014 for the full duration of the session.

This data is used to:

  • Verify presence at client, vendor, or project sites
  • Record travel routes for operational reporting
  • Provide subscribing organisations with real-time and historical location records for field staff management

Location collection starts only when the user explicitly begins a session and stops immediately when the session is ended. Field staff are made aware by their employer that tracking is active for the duration of their session.

10.3 Project Site Visits & On-Site Work

Employees assigned to projects that involve physical site visits \u2014 such as engineers, project managers, or inspectors visiting client premises, construction sites, or installation locations \u2014 may have their location captured when logging a site visit, recording a timesheet entry at a location, or completing a site-based task or milestone.

Location capture in this context is triggered by the specific action taken in the app (e.g. marking a task complete on site) and is not continuous.

10.4 Support Tickets & Service Visits

Technicians, service engineers, and support staff attending customer sites to resolve support tickets, perform repairs, carry out warranty service, or fulfil work orders may have their location recorded at the point of check-in at the customer site and check-out upon completion.

This is used to verify service delivery, confirm on-site attendance for SLA compliance, and provide a verifiable record of the visit for both the organisation and the customer.

10.5 Work Orders, Job Work & Site-Based Operations

Staff executing work orders, job work orders, or other site-based operational tasks may have a location timestamp recorded when the task is started or completed on-site.

This is used for operational accountability and record-keeping by the subscribing organisation.

Controls, Transparency & Data Protection

Across all of the above use cases:

  • User-initiated only \u2014 location capture in all scenarios is triggered by a deliberate action taken by the user in the app (starting a session, clocking in, checking in at a site). The app never silently or automatically activates location.
  • Background location is session-scoped \u2014 background GPS is only active during an explicitly started field session and terminates the moment the session ends.
  • Encrypted transmission \u2014 all location data is transmitted to the subscribing organisation's Ultro account over an encrypted HTTPS connection.
  • Access is restricted \u2014 only authorised administrators and managers within the subscribing organisation can view location records. Ultro staff do not access individual location data except where required to resolve a technical support issue, with the client's consent.
  • No advertising use \u2014 location data is never used by Ultro for advertising, profiling, or any purpose unrelated to the operational feature that captured it.
  • No third-party sharing \u2014 location data is never sold or shared with third parties outside the subscribing organisation, except as required by law.
  • Retention controlled by the organisation \u2014 subscribing organisations configure how long location records are retained, subject to applicable employment and data protection law.
  • User control \u2014 users can revoke location permissions at any time via iOS Settings \u2192 Privacy \u2192 Location Services. Revoking permission will disable location-dependent features but will not affect other app functionality.

11. Cookies and Similar Technologies

Ultro websites and applications may use cookies, local storage, pixels, logs, and similar technologies for purposes such as:

  • authentication;
  • maintaining sessions;
  • security;
  • remembering preferences;
  • measuring usage;
  • improving functionality; and
  • understanding how our services are used.

Where required by applicable law, we will obtain consent for non-essential cookies and similar technologies.

Users may also be able to control cookies through their browser or device settings.

12. International Data Transfers

Ultro may use service providers and infrastructure located in countries other than the country in which the customer or user is located.

Where personal data is transferred across jurisdictions, Ultro will take steps appropriate to the applicable legal requirements, which may include:

  • contractual safeguards;
  • adequacy mechanisms where available;
  • approved transfer mechanisms;
  • technical and organisational safeguards; and
  • other legally recognised transfer mechanisms.

Where Ultro acts as a Data Processor, applicable international transfer arrangements may also be governed by the customer's agreement and DPA with Ultro.

13. Children's Privacy

Ultro is a business-oriented enterprise platform and is not intended to be directed primarily toward children.

Customers are responsible for ensuring that their use of Ultro and the personal data they provide through the platform complies with applicable requirements relating to children.

Where applicable law imposes specific requirements regarding the processing of children's personal data, we will comply with those requirements.

14. Your Privacy Rights

Depending on applicable law and the circumstances of processing, individuals may have rights relating to their personal data.

These may include rights to:

  • access information;
  • obtain information about processing;
  • correct inaccurate information;
  • request deletion or erasure;
  • withdraw consent where processing is based on consent;
  • object to or restrict certain processing;
  • request portability of information where applicable;
  • lodge a complaint with a relevant supervisory or regulatory authority; and
  • exercise other rights provided by applicable law.

Where Ultro processes personal data on behalf of a customer, requests relating to that data may need to be directed to the relevant customer or Data Fiduciary / Data Controller.

We may need to verify the identity and authority of a person making a request before responding.

Requests can be submitted using our privacy contact: info@ultro.ai

We will respond within the period required by applicable law.

15. India \u2014 Digital Personal Data Protection Act, 2023

Where applicable, Ultro processes digital personal data in accordance with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and applicable rules and regulations made under it.

Depending on the circumstances, Ultro may act as a Data Fiduciary or Data Processor.

Where Ultro acts as a Data Fiduciary, we may process personal data for lawful purposes such as:

  • providing requested services;
  • managing accounts;
  • providing customer support;
  • maintaining security;
  • complying with legal obligations; and
  • other purposes permitted under applicable law.

Where consent is the applicable basis for processing, we will provide appropriate information and mechanisms as required by law.

Data Principals may have rights provided under the DPDP Act, including applicable rights relating to:

  • access to information;
  • correction and updating;
  • erasure;
  • grievance redressal; and
  • withdrawal of consent.

These rights are subject to applicable legal conditions and limitations.

Requests may be submitted to: info@ultro.ai

Where Ultro processes personal data on behalf of a customer acting as Data Fiduciary, the relevant Data Principal may need to exercise applicable rights through that customer.

16. European Union / EEA \u2014 GDPR

Where the General Data Protection Regulation ("GDPR") applies to Ultro's processing activities, Ultro will process personal data in accordance with applicable GDPR requirements.

Depending on the circumstances, Ultro may act as a Data Controller or Data Processor.

Where Ultro acts as a Data Controller, individuals may have rights under the GDPR, including, where applicable:

  • the right to access;
  • the right to rectification;
  • the right to erasure;
  • the right to restriction of processing;
  • the right to data portability;
  • the right to object;
  • rights relating to automated decision-making where applicable;
  • the right to lodge a complaint with a supervisory authority.

Where applicable, information about the controller, purposes of processing, legal bases, recipients, retention, international transfers, and individual rights will be provided in accordance with GDPR requirements.

If Ultro is required to appoint a Data Protection Officer under applicable law, the relevant DPO contact details will be provided as required.

17. Subprocessors

Ultro may engage third-party service providers to process personal data on its behalf.

Such providers may support:

  • cloud hosting;
  • infrastructure;
  • storage;
  • communications;
  • monitoring;
  • security;
  • customer support;
  • analytics;
  • payment processing;
  • AI/LLM integrations; and
  • other operational services.

Where required by applicable law or contract, Ultro will maintain appropriate contractual protections for subprocessors.

Information about material subprocessors may be provided separately through a Subprocessor List or other applicable customer documentation.

18. AI Provider Responsibilities

Where customers connect third-party AI/LLM providers to Ultro, customers are responsible for:

  • selecting appropriate AI/LLM providers;
  • reviewing applicable provider terms and privacy documentation;
  • configuring provider settings appropriately;
  • determining what information may be transmitted;
  • maintaining and protecting API credentials;
  • configuring access and user permissions;
  • ensuring appropriate user authorisation;
  • reviewing AI-generated outputs; and
  • complying with applicable laws governing their use of AI services.

Third-party AI/LLM providers may have their own privacy policies, data processing terms, security practices, retention policies, and data-use settings.

Customers should review those terms before enabling an integration.

19. Customer Responsibilities

Customers using Ultro are responsible for:

  • determining the appropriate lawful basis for processing personal data within their organisation;
  • providing required notices to their employees, customers, suppliers, and other individuals;
  • obtaining required consents where applicable;
  • configuring user roles and permissions appropriately;
  • protecting account credentials;
  • ensuring that users have appropriate authorisation;
  • ensuring that information entered into Ultro is lawful and appropriate;
  • configuring integrations appropriately;
  • selecting and authorising AI/LLM providers where applicable;
  • reviewing AI-generated information before taking material business action; and
  • complying with applicable data protection, employment, tax, accounting, sector-specific, and other legal requirements.

Customers should not use Ultro to process information in violation of applicable law or their contractual obligations.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect:

  • changes to Ultro;
  • new features and services;
  • changes in technology;
  • changes in legal or regulatory requirements; or
  • changes to our privacy practices.

When we make material changes, we may provide notice through the platform, website, email, or other appropriate means where required.

The updated Privacy Policy will indicate its revised "Last Updated" date.

21. Contact Us

If you have questions, concerns, requests, or complaints relating to this Privacy Policy or the processing of personal data by Ultro, please contact us.

Ultro Softtech India Private Limited
Registered Office: C-001/A2, Wework Berger Delhi One, Sector 16-B, Noida, Gautam Budh Nagar, UP, 201301, India
Privacy Contact: info@ultro.ai
Website: www.ultro.ai

For privacy, data protection, rights-related, or other privacy enquiries, you may contact us at info@ultro.ai.

22. Relationship With Other Agreements and Documents

This Privacy Policy should be read together with the other agreements and documents applicable to your use of Ultro.

Depending on the services and relationship involved, these may include:

  • Terms of Service;
  • Subscription or Customer Agreement;
  • Data Processing Agreement ("DPA");
  • Security and Technical & Organisational Measures documentation;
  • Subprocessor List;
  • Acceptable Use Policy;
  • AI/LLM Terms or AI-specific notices;
  • Service-specific terms; and
  • other contractual or product documentation.

Where a customer has entered into a separate written agreement with Ultro that specifically governs the processing of personal data, that agreement may contain additional or different provisions concerning such processing.

In the event of a conflict, the applicable contractual agreement will govern to the extent provided in that agreement.