Legal

Disclaimer

Effective 24 August 2026 - Oris Intelligence Private Limited, operating Custelis

Not legal advice

Nothing on custelis.com, in the product, or in any Custelis communication - including the DPDP-readiness guide and the DPDP section of the homepage - constitutes legal advice. It reflects our own understanding of the Digital Personal Data Protection Act, 2023, its 2025 Rules, and comparable laws, current as of the date published. Laws change, and how they apply to your specific organization, sector, and jurisdiction is a question for your own counsel, not for us.

"DPDP-ready" is not a certification

No employee-monitoring vendor - including Custelis - can claim certified DPDP compliance today, because the Act's substantive provisions are still phasing in through 13 May 2027 and there is no accreditation body to certify against in the meantime. When we say Custelis is "DPDP-ready," we mean specific, checkable mechanics (data-principal rights self-service, the 72-hour breach clock, a Section-7-legitimate-use default configuration) are built and running in the product today. It is not a compliance guarantee for your organization, and it doesn't replace a DPIA or your own counsel's sign-off for your specific use case.

Compliance is a shared responsibility

Custelis gives you the tools - retention controls, screenshot gating, DLP rules, the rights-request workflow. Whether your organization's actual use of those tools satisfies your legal obligations depends on decisions only you can make: what you monitor, why, for how long, and under what notice to your employees. See the Terms of Service, Section 4, for how this responsibility is allocated contractually.

AI-assisted drafts

Where the product uses AI to draft a data-principal-rights response, that draft is exactly that - a starting point grounded in your workspace's own record counts, generated to save your compliance officer time. It is never sent automatically. A human at your organization reviews, edits, and approves every response before it goes to an employee.

"Never covert" and "never implemented" claims

Claims like "no keylogging," "no credential capture," and "no webcam or microphone access" describe what the product's code does and does not do, verified by our own test suite as of the date published. They are engineering claims about this product, not a guarantee about how any given deployment is configured, used, or extended in the future.

Third-party services

Custelis relies on shared ORIS ecosystem infrastructure (identity, billing) and Razorpay for payment processing. We aren't responsible for outages or issues originating in those third-party services, though we'll tell you if one affects you.

Questions: legal@custelis.com. See also the Privacy Policy and Terms of Service.