Legal

Data Processing Terms

Last updated: · Describes how Vonera processes Customer Data on behalf of our pharma CDMO / CRO customers.

In one paragraph: When your organisation uses Vonera, you stay the owner and controller of the routes, costings, and proposals you put into the platform — we process that data only to run the platform for you, on infrastructure secured by row-level isolation and encryption, never to train a model, and we hand it back to you in full if you ever leave.

1. Purpose & scope

These Data Processing Terms describe how Vonera Private Limited (“Vonera,” “we”) handles the data your organisation (“Customer,” “you”) puts into the Vonera platform — synthesis routes, costing data, proposal documents, and anything else you or your team upload or generate within the platform (“Customer Data”). These Terms form part of, and should be read together with, our Terms of Service.

Where Customer Data includes personal data about identifiable individuals — for example, a named reviewer, chemist, or customer contact — that data is also subject to our Privacy Policy.

2. Roles

For Customer Data, you are the data fiduciary (or controller) — you decide what goes into the platform and why. Vonera acts as a data processor, handling that data only on your instructions and only to provide the platform. This is separate from account data (the names and emails of the individuals your organisation authorises to use Vonera), where Vonera itself is the data fiduciary, as described in our Privacy Policy.

3. Nature & purpose of processing

We process Customer Data to:

We do not process Customer Data for any other purpose, and we do not use it to train any AI model, by us or by any provider.

4. Categories of data

Technical & commercial data
Synthesis routes, reaction schemes, equipment and process data, costing tables, pricing.
Documents
Draft and final proposals, review comments, approval records.
Embedded personal data
Names of chemists, reviewers, or customer contacts where included in the above by your team.

5. Sub-processors

We use the following categories of sub-processor to provide the platform:

Infrastructure hosting
Enterprise AWS, for hosting, storage, and compute underlying the Vonera platform.

Any sub-processor we engage is bound by confidentiality and security obligations at least as strict as those in these Terms. If we add a new category of sub-processor that materially changes how Customer Data is handled, we will update this section.

6. Security measures

We apply the following measures to Customer Data:

7. Personnel

Vonera personnel who may, in exceptional circumstances, access Customer Data are bound by confidentiality obligations and are granted access only on a need-to-know basis to resolve a specific, authorised issue.

8. Assisting your obligations

Where Customer Data contains personal data and an individual exercises a right under the DPDP Act (such as a request for access, correction, or erasure), we will provide reasonable assistance to help your organisation respond, including by making relevant data available for export as described in Section 10.

9. Breach notification

If we become aware of a breach affecting Customer Data, we will notify your organisation without undue delay, along with the information reasonably available to us about the nature and likely consequences of the breach, so you can meet your own notification obligations under applicable law.

10. Retention & deletion

We retain Customer Data for as long as your organisation’s subscription is active. At any time during that period, and for a reasonable period after termination, your team can export proposals and underlying data to Excel, as described on our Governance & IP page. After that period, we delete or anonymise Customer Data in accordance with our data retention practices, except where we are required to retain it by law.

11. International transfers

Customer Data is hosted on AWS infrastructure. Where processing involves a transfer of data outside India, we handle that transfer in accordance with the DPDP Act and any restrictions the Government of India notifies on transfers to specific countries.

12. Audit

On reasonable written request, and no more than once a year unless required following a security incident, we will provide your organisation with information reasonably necessary to demonstrate our compliance with these Terms, subject to reasonable confidentiality restrictions.

13. Changes to these terms

We may update these Data Processing Terms as the platform or our infrastructure changes. Material changes — particularly to Section 5 (Sub-processors) or Section 6 (Security measures) — will be reflected in the “Last updated” date above, and where a change materially affects an active customer, we will provide reasonable notice before it takes effect.

14. Contact

Email
contact@vonera.in
Phone
+91 93909 62688
Registered address
Somajiguda, Hyderabad, Telangana 500082, India

See Vonera run on one of your own routes

Bring a real bid. We'll cost it live and model the ROI on your actual volume.

Book a walkthrough