By accessing these applications / portals / platforms : https://www.weboccult.com and https://gotilo.ai and other as may be launched from time to time(hereinafter referred to as “Website”, “Platform” and/or “Application”, which shall mean and be used interchangeably having the same meaning) is developed, operated and maintained by WebOccult Technologies Private Limited (“The Company”), a company incorporated under the laws of India, having its registered office at 402-403 & 502-503, Akik Tower, Near Pakwan Dining Hall, S.G. Highway, Ahmedabad, Gujarat 380054, India, you agree to be legally bound by following terms and conditions and other incidental or related aspects for use.
Before you use the platform, you must read all of the terms and conditions (”Policy”) herein and the Privacy Policy provided on the Website. Please also refer the additional legal information as may be applicable to you. The Platform is an enterprise service intended solely for use by business entities and their Authorised Users and is not directed at or intended for use by individuals under the age of eighteen years.
1.Definitions and Interpretation
The following terms carry the meanings assigned below wherever they appear in this Policy.
1.1. “Policy” means this Terms and conditions Policy together with all Service Orders, Data Processing Agreements, Security Annexures and any other schedules incorporated herein by reference.
1.2.“Company” or “WebOccult” means WebOccult Technologies Private Limited, a company incorporated under the laws of India and having its registered office at Ahmedabad, Gujarat, India.
1.3.“Gotilo” or “Platform” means the Gotilo product suite owned and operated by the Company, delivered as cloud-hosted, on-premises, edge-connected or hybrid infrastructure as agreed in the applicable Service Order.
1.4.“Gotilo Product Suite” means the collection of AI vision sub-platforms comprising Gotilo Container, Gotilo Spot and Gotilo Inspect, together with any additional sub-platforms introduced by the Company from time to time.
1.5.“Gotilo Container” means the AI-powered container yard management and gate automation sub-platform described in Clause 3.1.
1.6.“Gotilo Spot” means the real-time AI visual intelligence and workplace safety monitoring sub-platform described in Clause 3.1.
1.7.“Gotilo Inspect” means the AI-powered automated visual and production-line inspection sub-platform described in Clause 3.1.
1.8.“Client” means the enterprise entity identified in the applicable Service Order or any other document, that has subscribed to one or more sub-platforms within the Gotilo Product Suite.
1.9.“Authorised User” means any employee, contractor or representative of the Client who has been granted login credentials to the Platform by the Client.
1.10.“Data Principal” or “Data Subject” means an individual whose personal data is processed through the Platform, including workers, drivers, contractors, visitors and other persons present at the Client’s monitored premises.
1.11.“Personal Data” means any data that identifies or can reasonably identify a living individual, including video footage, images, vehicle number plates and biometric data, where applicable.
1.12. “Client Operational Data” means all data generated from the Client’s premises through connected Devices, including but not limited to container records, video footage, event images, OCR logs, safety alerts and inspection results.
1.13. “AI-Generated Output” means any alert, report, damage assessment, safety flag, inspection result, classification, analytics summary or automated record produced by the Platform’s artificial intelligence and machine learning models.
1.14. “Devices” means cameras, edge compute units, sensors and other hardware installed at the Client’s premises and connected to the Platform.
1.15. “Data Fiduciary” or “Data Controller” means the party that determines the purpose and means of processing personal data. WebOccult acts as Data Fiduciary for data collected directly by it, and the Client acts as Data Fiduciary for personal data processed at its premises.
1.16. “Data Processor” means the party that processes personal data on behalf of and under the instructions of the Data Fiduciary. WebOccult acts as Data Processor in relation to Client Operational Data generated at the Client’s premises.
1.17. “Service Order” means a written or electronic document executed between the Company and the Client specifying the subscribed sub-platforms, deployment scope, fees, payment terms and any special conditions.
1.18. “DPA” means the Data Processing Agreement entered into between the Parties governing the processing of personal data.
1.19. “Subscription Period” means the duration of the Client’s access to the Platform as specified in the applicable Service Order.
1.20. “Confidential Information” means any information disclosed by one Party to the other that is designated as confidential or that a reasonable person would recognise as confidential by its nature.
1.21. “Sub-Processor” means any third party engaged by WebOccult to process Client Operational Data on its behalf.
1.22. “Deployment Model” means the infrastructure arrangement agreed in the applicable Service Order, which may be cloud-hosted, on-premise, edge-only or hybrid.
1.23. “Privacy Policy” means https://weboccult.com/privacy-policy/ Headings are for reference only and do not limit the scope of any clause. Where this Policy conflicts with any other document the Service Order shall prevail for commercial matters and the DPA shall prevail for data protection matters. In all other cases this Policy shall prevail.
2.Scope, Eligibility and Acceptance
2.1. This Policy governs the Client’s access to and use of the Gotilo Product Suite, all associated Devices, APIs, dashboards, web and mobile interfaces, edge compute software and AI analytics services. It applies to all Authorised Users operating under the Client’s account.
2.2. By executing a Service Order or any other similar document and activating access to any Gotilo sub-platform or permitting Authorised Users to access the, Platform the Client confirms that it is a validly incorporated company, partnership, LLP or other legal entity competent to enter into binding contracts under applicable law. The individual accepting on the Client’s behalf warrants that they hold the authority to bind the Client.
2.3. This Policy is an electronic record published in accordance with the Information Technology Act, 2000 of India and the rules made thereunder and does not require a physical or digital signature to be legally binding, except where a wet or digital signature is separately required under a Service Order.
2.4. WebOccult acts in two distinct capacities under this Policy, and the distinction is critical for enterprise compliance purposes.
Data Fiduciary / Data Controller: WebOccult acts as a Data Fiduciary (or Data Controller) when it collects and processes personal data directly from its website visitors, enquiry contacts, demo users, billing contacts, support contacts and marketing subscribers. In this capacity, WebOccult determines the purpose and means of processing such personal data.
Data Processor / Service Provider: WebOccult acts as a Data Processor (or Service Provider) when processing Client Operational Data, including video footage, container records, OCR outputs, safety alerts and inspection results generated at the Client’s premises through connected Devices. In this capacity, WebOccult processes such data solely on the documented instructions of the Client, and the Client shall remain the Data Fiduciary or Data Controller in respect of such data.
2.5. The Client accepts that it is the Data Fiduciary for all personal data of workers, drivers, visitors and contractors captured at its premises through Devices installed as part of the Gotilo deployment. The Client is accordingly responsible for establishing and maintaining the lawful basis for such processing under applicable data protection law.
3.Description of the Gotilo Product Suite
3.1. Gotilo is an AI Vision product suite. The sub-platforms currently available within the suite are described below. Additional sub-platforms may be introduced by the Company from time to time and shall be subject to this Policy and any applicable addendum.
Sub-Platform
Primary Operational Purpose
Key Capabilities
Gotilo Container
Container yard management, gate automation and logistics visibility for container yards, empty depots, ICDs and port facilities.
Gate-in/gate-out automation without manual data entry. OCR-based container ID and ISO code recognition. AI damage detection with visual proof. Real-time yard map with sub-second container positioning. CHE geo-location, engine status, utilisation analytics. Reefer temperature monitoring. Vehicle speed monitoring. Perimeter intrusion detection. Movement history and turnaround time tracking. Yard occupancy and zone utilisation dashboards.
Gotilo Spot
Real-time AI visual intelligence for workplace safety, site monitoring and CCTV analytics at industrial premises.
PPE detection covering helmets, vests, gloves, safety shoes and glasses. Posture and fall-risk analysis. Fire and smoke detection. Slip-surface and unattended object detection. Zone occupancy enforcement and intrusion alerts. Unsafe act and behaviour alerts. Real-time supervisor notifications.
Gotilo Inspect
Automated AI visual inspection for production lines, quality assurance and manufacturing process monitoring.
Inline surface defect and crack detection. Yield analytics and part counting. OCR reading and verification of printed codes and serial numbers. Assembly completeness verification. Golden reference image comparison. Defect classification and severity scoring. Supervisor dashboard accessible from any connected device.
3.2.Platform Access and Integration: The Platform is accessible through a web application, a mobile application for Android and iOS, and edge-connected hardware Devices. Gotilo sub-platforms support integration with enterprise and operational systems including terminal operating systems, warehouse management systems, ERP platforms, SCADA systems, PLC systems, NVR and VMS systems, and access control infrastructure. Integration specifications and supported connectors are set out in the applicable Service Order.
3.3.Deployment Models: The Client’s chosen Deployment Model shall be specified in the Service Order and determines the infrastructure arrangement under which the Platform operates, the location of data storage and the distribution of operational responsibilities.
Cloud-Hosted: Under the Cloud-Hosted deployment model, the Platform and data are hosted on cloud infrastructurmanaged by WebOccult, and the Client accesses the Platform through web and mobile interfaces over the interne
On-Premise: Under the On-Premise deployment model, the Platform software and data are deployed on infrastructure owned or controlled by the Client at its premises, and WebOccult provides software, configuration and support services.
Edge-Only: Under the Edge-Only deployment model, AI inference and local logging operate on edge compute Devices located at the Client’s premises without persistent cloud connectivity, although selected data may be synchronised to the cloud as agreed by the Parties.
Hybrid: Under the Hybrid deployment model, the Platform combines edge processing at the Client’s premises with cloud-hosted analytics, dashboards and storage, as specified in the applicable Service Order.
3.4. For Gotilo Container deployments at active gate operations, certain local functions including gate logging and OCR capture may continue to operate on edge Devices during temporary cloud connectivity interruptions. Full AI analytics, reporting and dashboard functionality requires continuous connectivity to the Company’s cloud or on-premise server infrastructure as applicable.
4.Client Obligations and Acceptable Use
4.1. Lawful Basis and Premises Compliance: The Client is solely and entirely responsible for ensuring that it holds the lawful right to install and operate surveillance cameras, sensors and edge compute Devices at its premises before the Platform goes live. This obligation includes but is not limited to the following.
Obtaining all regulatory approvals, factory licences, workplace permits and statutory permissions required for the installation and operation of surveillance and AI monitoring systems at the relevant premises under applicable Indian and local law.
Establishing and documenting the lawful basis for processing personal data of workers, drivers, visitors and contractors captured by Devices installed at the Client’s premises, under the applicable data protection framework including India’s Digital Personal Data Protection Act 2023 and associated rules.
Providing clear and conspicuous notices and signage at all monitored areas of the premises informing workers, drivers, visitors and contractors that AI-powered video monitoring is in operation and stating the purpose of that monitoring.
Obtaining any consents required under applicable labour law, employment contracts and collective agreements before monitoring employees with AI video analytics tools.
Configuring camera placement in a manner that avoids unnecessary capture of private areas and that is proportionate to the stated monitoring purpose.
Ensuring that any rights requests received from Data Principals regarding data captured at the Client’s premises are handled by the Client in its capacity as Data Fiduciary.
4.2. The Company shall not be responsible for any regulatory penalty, employment tribunal claim, data protection enforcement action or third-party legal claim arising from the Client’s failure to obtain and maintain the consents, notices and permissions described in this clause.
4.3. The Client shall use the Platform exclusively for legitimate operational purposes connected to the Services described in this Policy and the applicable Service Order. The Client shall ensure that all Authorised Users comply with this Policy and shall be responsible for any breach of this Policy by its Authorised Users.
4.4. The Client shall not use AI-Generated Outputs as the sole or determinative basis for any consequential legal, employment, disciplinary, insurance or financial decision without independent verification and shall not represent AI-Generated Outputs as conclusive evidence in any third-party dispute without disclosing their AI-generated nature.
4.5. The Client shall not transmit to or through the Platform any material that contains software viruses, malicious code or any other code designed to interrupt, destroy or limit the functionality of any software or hardware. The Client shall not attempt to reverse-engineer AI models, circumvent access controls or access areas of the Platform that have not been licensed to it. The Client shall not use automated tools including robots, scrapers or data-mining software to extract data from the Platform beyond what is available through official APIs
4.6. The Client shall enforce a password policy requiring alphanumeric passwords with special characters and shall ensure that passwords are changed at intervals of not more than ninety days. The Client shall enable multi-factor authentication for administrator accounts where supported by the Platform. The Client shall maintain accurate records of all Authorised Users and shall promptly revoke access for any individual who ceases to be employed by or engaged with the Client. The Client shall immediately notify the Company upon becoming aware of any unauthorised access to or use of the Platform through the Client’s credentials.
5. Data Collected Through the Platform
5.1. Account and Administrative Data: WebOccult collects account and administrative data directly from the Client’s contact persons and Authorised Users for the purpose of provisioning and managing the Client’s subscription. This data includes name, job title, designation, employer organisation, business email address, business telephone number, login credentials, role assignments within the Platform and support ticket records.
5.2. Client Operational Data: Client Operational Data is generated at the Client’s premises through connected Devices and is processed by WebOccult in its capacity as Data Processor on behalf of the Client. The specific categories collected depend on the Gotilo sub-platform subscribed to and the configuration agreed in the Service Order.
Video and Image Data: Live camera feeds, event-triggered video clips, gate snapshots, yard images and production-line images.
Container and Cargo Data: Container identification numbers, ISO codes, seal numbers, damage photographs, damage type, location and severity records, container movement history and gate-in/gate-out timestamps.
Vehicle Data: Licence plate numbers, vehicle type information, vehicle turnaround times, vehicle speed readings and vehicle movement logs.
Equipment Data: Container handling equipment (CHE) geo-location coordinates, engine on/off status, operational hours, utilisation percentages, movement records and geofencing alerts.
Yard and Facility Data: Zone-wise yard occupancy information, capacity utilisation data, container positions, reefer temperature readings and perimeter event logs.
Safety and Compliance Data: PPE detection results (including helmets, vests, gloves, shoes and safety glasses), posture and fall-risk flags, fire and smoke detection events, zone intrusion records, unsafe act alerts and evidence images attached to violations.
Inspection and Quality Data: Defect detection images and classifications, defect severity scores, part count and yield ratios, OCR reads of printed codes and serial numbers, assembly verification results and golden reference comparison outputs.
AI-Generated Output: Automated alerts, confidence scores, analytics reports, occupancy dashboards, damage assessment reports, safety compliance summaries and production quality dashboards.
Device and System Logs: Camera health status information, edge device performance metrics, API logs, model inference logs, integration logs and error or diagnostic reports.
Support Data: Support tickets, diagnostic logs, remote session records, error reports and configuration change history.
5.3. The Client acknowledges that video feeds and images captured through Devices installed at its premises may incidentally include personal data of workers, drivers, contractors and visitors. The Client is the Data Fiduciary for all such personal data and is responsible for ensuring that its processing under this Policy has a valid lawful basis under applicable law.
5.4.Website and Marketing Data: WebOccult separately collects data from visitors to weboccult.com and Gotilo landing pages for the purpose of marketing, inquiry management and event registration. This data includes name, business email, company name, country and inquiry details submitted through contact or enquiry forms. Website analytics tools including cookies may also be used to understand visitor behaviour on WebOccult’s public websites. This data is collected by WebOccult in its capacity as Data Fiduciary and is governed by Privacy Policy.
6.Purpose of Processing
6.1. WebOccult processes data for the specific and limited purposes described in the table below. Processing for any purpose not listed in this table requires either the prior written consent of the Client or a separate legal basis under applicable law.
Service Delivery: To provide, operate, configure and maintain the Gotilo sub-platforms subscribed to by the Client, including gate automation, AI analytics, damage detection, safety monitoring, inspection services and related outputs
Account Management: To authenticate Authorised Users, manage user roles and permissions, administer subscriptions and process billing and account-related activities.
AI Event Processing: To process video feeds, images and sensor inputs through artificial intelligence and machine learning models for the generation of alerts, classifications, reports, analytics and dashboards.
Audit and Operational Records: To maintain logs, movement histories, gate records, inspection records and other operational audit trails required for the Client’s business operations or compliance obligations.
Platform Security and Troubleshooting: To monitor Platform health, detect and investigate security incidents, diagnose errors, maintain service availability and perform authorised maintenance activities.
Legal Compliance: To comply with applicable laws, regulatory requirements, court orders and lawful requests from governmental or regulatory authorities.
Platform Improvement (Anonymised Only): To improve Platform functionality, performance and AI model accuracy using aggregated, anonymised and de-identified data, subject to the restrictions set out in this Policy.
Client Communication: To send service notices, security alerts, product updates, incident notifications and other account-related communications necessary for the provision of the Services.
Marketing (Opt-In or Legitimate Interest): To send marketing communications, product announcements, newsletters and event invitations to individuals.
7.AI Model Training and Data Use for Improvement
7.1. The Company invests in the continuous improvement of its AI and machine learning models to improve the accuracy and reliability of the Platform for all clients. The following restrictions govern the use of Client Operational Data for model training and improvement purposes and reflect the specific feedback received from enterprise clients on this point.
7.2. WebOccult shall not use identifiable Client Operational Data, raw video footage, event evidence images, container records, safety violation records or inspection outputs for generalised AI model training unless all of the following conditions are met.
The use is expressly permitted in the applicable Service Order or in a separate written addendum signed by an authorised representative of the Client.
The data to be used for model training has been anonymised, masked or de-identified to the extent technically feasible such that it cannot reasonably be used to identify the Client’s premises, individual containers, specific workers or other Data Principals.
The data is not used to expose the Client’s confidential operational methods, throughput patterns, damage rates or commercial information.
Access to such data for model training purposes is restricted to WebOccult’s AI engineering team under a need-to-know access control policy.
The data is processed under a purpose limitation principle and is not retained for model training purposes beyond what is necessary for the approved improvement activity.
7.3. Where WebOccult uses aggregated and anonymised operational benchmarks derived from across its client base for research and product development purposes, such use shall not identify any individual Client, premises, container, worker or transaction and shall be treated as anonymised data not subject to data protection obligations.
The Client may at any time request confirmation of whether and how its data has been used for model improvement purposes by submitting a written request to the Company’s designated privacy contact.
8. AI Accuracy, Output Reliability and Human Review
8.1. The Platform employs AI and machine learning models trained on large and diverse datasets to analyse video feeds and sensor inputs and to generate automated outputs. The Company invests significant resources in model accuracy and continuous validation. However the Client expressly acknowledges the following limitations of AI-Generated Outputs.
No AI system is infallible. AI-Generated Outputs including container damage assessments from Gotilo Container, PPE compliance flags and safety alerts from Gotilo Spot and defect detection results from Gotilo Inspect may on occasion contain errors, misclassifications, false positives or false negatives.
AI confidence scores indicate the model’s degree of certainty but do not guarantee accuracy. A high confidence score does not eliminate the possibility of error.
AI-Generated Outputs are not to be treated as conclusive determinations of fact without independent human review, particularly where the output may be used as the basis for a disciplinary action, employment decision, insurance claim, dispute resolution process, regulatory submission or legal proceeding.
The Client shall establish its own internal verification and review workflows appropriate to the risk profile of each operational decision it takes using AI-Generated Outputs.
8.2. The Company shall not be liable for any loss, damage, contractual penalty, regulatory fine, employment claim or third-party legal action arising from the Client’s reliance on AI-Generated Outputs without the independent verification that this Policy requires.
8.3. Biometric and Sensitive AI Processing
Gotilo Spot and Gotilo Container may include capabilities that involve video analytics applied to individuals present at the Client’s premises. Standard deployment captures PPE compliance, posture, movement, zone presence and vehicle data without identifying individuals by name or using facial recognition.
Facial recognition, person re-identification and other biometric identification features, where technically available, are optional and must be explicitly enabled by the Client in the Service Order. Where enabled the Client accepts that biometric data is special-category personal data under applicable data protection frameworks and requires an elevated lawful basis. The Client shall not enable biometric identification features without first establishing the applicable lawful basis, obtaining any required consents or authorisations under applicable law and notifying affected Data Principals.
WebOccult shall process biometric data only under the Client’s written instructions and in accordance with the terms of the applicable DPA. WebOccult does not use biometric data captured at a Client’s premises for any purpose other than delivering the contracted feature to that Client.
9. Data Sharing and Sub-Processors
9.1. General Principle: WebOccult does not sell Client Operational Data. Client Operational Data is not disclosed to third parties for marketing, advertising or commercial purposes. The following sets out the categories of recipients with whom data may be shared and the purpose of each sharing arrangement.
Cloud Hosting and Infrastructure Providers: For the hosting, storage, processing and backup of Platform data in accordance with the applicable Deployment Model.
Support and Maintenance Service Providers: For Platform maintenance, technical troubleshooting, remote diagnostics and support-related operations.
System Logging and Performance Analytics Providers: For Platform performance monitoring, error tracking, uptime management, security monitoring and event logging.
Payment and Billing Providers: For processing subscription fees, invoices, payment transactions and related billing activities, where applicable.
Legal and Regulatory Authorities: For compliance with applicable laws, court orders, regulatory requirements and lawful requests from governmental or regulatory authorities.
Client-Authorised Integration Partners: For data exchange and system integration with ERP, TOS, WMS, NVR, VMS, access control, PLC, SCADA or other systems designated or approved by the Client in the applicable Service Order.
Professional Advisers: For obtaining legal, audit, tax, compliance or other professional advisory services, subject to applicable confidentiality obligations.
9.2. Sub-Processors: WebOccult may engage Sub-Processors to assist in delivering the Services. All Sub-Processors are bound by confidentiality and data protection obligations that are no less protective than those in this Policy and the applicable DPA. A current list of Sub-Processors is available to the Client on written request. The Company shall notify the Client of any material change to the Sub-Processor list that affects the processing of the Client’s data with reasonable advance notice where practicable.
9.3. No Sale of Client Data: For the avoidance of doubt, WebOccult shall not sell, license or commercially distribute Client Operational Data, including video footage, container records, safety records, inspection records and AI-Generated Outputs, to any third party. Any use of aggregated and anonymised benchmarking data for research or product development shall be subject to the restrictions in Clause 7.
10.Intellectual Propert
10.1. Client Operational Data, including all video footage, container records, safety compliance records, inspection results, OCR logs and movement histories generated from the Client’s premises through connected Devices, is and shall remain the property of the Client. WebOccult holds and processes this data exclusively in its capacity as Data Processor on behalf of the Client and does not acquire any ownership rights in Client Operational Data by virtue of processing it.
10.2. The Platform, including all software, AI models, trained model weights, machine learning algorithms, computer vision pipelines, dashboards, APIs, documentation and all other technology that is not Client Operational Data, is and shall remain the exclusive intellectual property of WebOccult Technologies Private Limited. Nothing in this Policy transfers ownership of any part of the Platform to the Client.
10.3. AI-Generated Outputs produced by the Platform in the course of delivering the contracted Services to the Client are licensed to the Client for its internal operational use during the Subscription Period. Notwithstanding the foregoing, the Client may retain and use copies of AI-Generated Outputs generated during the Subscription Period for its internal record-keeping, audit, compliance and dispute-resolution purposes after termination or expiry. The Client’s rights in AI-Generated Outputs beyond operational use shall be as agreed in the Service Order.
10.4. All trademarks, service marks, trade names, logos and domain names of WebOccult and Gotilo are the exclusive property of the Company. The Client shall not use any of these marks without the prior written consent of the Company.
10.5. The Client acknowledges that the AI models, training data, model architectures and inference pipelines used by the Platform are proprietary to WebOccult and constitute trade secrets. The Client shall not attempt to extract, reverse-engineer, replicate or derive any component of WebOccult’s AI models from the AI-Generated Outputs or from any other access to the Platform.
11. Data Retention and Deletion
11.1. Retention Policy: Data shall be retained only for as long as is necessary for the defined operational purpose, applicable legal obligation or as agreed in the Service Order or the relevant document. The following table provides indicative retention guidance. Specific retention periods for each data category shall be confirmed in the Service Order or the applicable DPA.
Data Category
Indicative Retention Approach
Raw video feed
Not stored by default. Where configured for storage, retained only for the period specified in the Service Order.
Event-triggered video clips and images
Retained for the period agreed in the Service Order, typically 30, 60 or 90 days from capture.
Container identification and movement records
Retained for the operational and audit period agreed in the Service Order.
AI damage detection reports and images
Retained as per contractual audit and claims requirements agreed in the Service Order.
Safety violation records and evidence images
Retained for the period agreed by the Client for safety audit and compliance purposes.
Inspection results and defect records
Retained for quality assurance, audit and regulatory compliance periods as agreed.
Account and administrative data
Retained for the duration of the Subscription Period and for seven (7) years thereafter for account management and legal compliance, or such other period as agreed in the applicable Service Order or contract with the Client, consistent with the Privacy Policy.
System and device logs
Retained for security, troubleshooting and audit purposes, typically 90 days unless otherwise agreed.
Support tickets and diagnostic records
Retained for the duration of the Subscription Period plus a reasonable archive period.
AI model training datasets (where approved)
Retained only for the duration of the approved training activity under a separate written agreement.
Legal records and compliance evidence
Retained for the period required by applicable law regardless of contract termination.
11.2. Data on Contract Termination: Upon termination or expiry of the Subscription Period the Company shall, within thirty days of receiving a written request from the Client, provide the Client with a copy of its Client Operational Data in a commercially reasonable format and shall thereafter securely delete such data from WebOccult’s systems. Where applicable law requires WebOccult to retain certain data beyond termination the Company shall notify the Client of the nature, category and anticipated duration of such retention.
11.3. Where the Client’s Deployment Model is on-premise or hybrid, data stored on infrastructure under the Client’s control shall be the Client’s responsibility to export or delete upon termination of the relevant contract.
12.International Data Transfers and Data Residency
12.1. The location of data storage and processing depends on the Deployment Model agreed in the Service Order and the cloud infrastructure providers used by WebOccult for cloud-hosted deployments. Data may be processed in India or in other jurisdictions depending on the Client’s chosen deployment configuration, cloud region preferences and applicable law.
12.2.Where Client Operational Data is transferred to or processed in a jurisdiction outside India, WebOccult shall implement appropriate safeguards as required by India’s Digital Personal Data Protection Act 2023 and any other applicable data protection legislation. WebOccult shall not transfer Client Operational Data to any jurisdiction that the Government of India has restricted for data transfers without the Client’s prior written consent.
12.3. Enterprise clients may request specific data-residency or regional hosting configurations, including without limitation India-only, APAC or Europe-based hosting, and these shall be agreed and confirmed in the Service Order. Where a specific data residency requirement is not specified in the Service Order WebOccult shall be entitled to store and process data on infrastructure in the most appropriate region for reliable service delivery.
13. Security Measures
13.1. WebOccult implements technical and organisational security measures appropriate to the nature of the data processed and the risk of the Platform’s operational context. The following measures form part of WebOccult’s standard security posture for enterprise deployments.
Encryption of data in transit using TLS protocols between Devices, edge systems and cloud infrastructure.
Encryption of data at rest for stored video clips, event images and operational records where applicable to the Deployment Model.
Role-based access control limiting access to Client Operational Data to Authorised Users with a defined need and to WebOccult personnel with a need-to-know basis.
Multi-factor authentication for administrator-level access to the Platform where supported.
Audit logs recording system access, configuration changes, data exports and administrative actions.
Regular access reviews and revocation of credentials for departed personnel.
Segregation between client environments to prevent cross-client data access.
Secure configuration management for edge compute Devices.
Vulnerability management including periodic assessments and timely patching.
Incident response procedures enabling rapid identification, containment and notification of security events.
Backup and recovery procedures appropriate to the Deployment Model.
Restricted access to production systems and Client Operational Data within WebOccult’s engineering organisation.
13.2.The Client is responsible for the physical security of Devices installed at its premises, for maintaining the network and connectivity infrastructure required for Platform operation and for implementing appropriate cybersecurity controls on the Client-side of the network boundary. WebOccult shall not be liable for data loss, breach or unauthorised access arising from inadequate physical security at the Client’s premises or from network failures or vulnerabilities outside WebOccult’s direct control.
14. Data Breach and Security Incident Response
14.1. WebOccult shall notify the Client without undue delay and in any event within the timeframe required by applicable law upon becoming aware of a security incident that has resulted in or is reasonably likely to result in accidental or unlawful destruction, loss, alteration, unauthorised disclosure of or unauthorised access to Client Operational Data processed by WebOccult as Data Processor.
14.2. The notification shall include the following information to the extent available at the time of notification.
A description of the nature of the incident including the categories of data affected and the approximate number of Data Principals affected.
The likely consequences of the incident.
The measures taken or proposed to be taken by WebOccult to address the incident including where appropriate measures to mitigate its possible adverse effects, unless otherwise agreed in the applicable contract.
The name and contact details of WebOccult’s designated privacy contact for further information.
14.3. The notification may be provided in stages as further information becomes available. WebOccult shall cooperate with the Client in investigating the incident and in complying with any notification obligations the Client has to Data Principals or regulatory authorities in its capacity as Data Fiduciary. The obligation to notify regulatory authorities of a personal data breach rests with the Client as Data Fiduciary. WebOccult shall provide all reasonable assistance to the Client in meeting this obligation.
15.Rights of Data Principals
15.1. Individuals whose personal data is processed through the Platform in the course of the Client’s operations are Data Principals in relation to that processing. Because WebOccult processes such data as Data Processor on the Client’s instructions the Client as Data Fiduciary is the first point of contact for any rights requests from Data Principals.
15.2. Data Principals may have the following rights under applicable law including India’s Digital Personal Data Protection Act 2023 and other applicable frameworks.
Right to Access: A Data Principal may request confirmation as to whether their personal data is being processed and may request access to such personal data, subject to applicable law.
Right to Correction: A Data Principal may request the correction, updating or completion of inaccurate, incomplete or outdated personal data.
Right to Erasure / Deletion: A Data Principal may request the deletion or erasure of their personal data, subject to any legal, regulatory or contractual retention requirements applicable to WebOccult or the Client.
Right to Grievance Redressal: A Data Principal may submit a grievance or complaint regarding the collection, use, disclosure or other processing of their personal data.
Right to Withdraw Consent: Where personal data is processed on the basis of consent, a Data Principal may withdraw such consent at any time. Withdrawal of consent shall not affect the lawfulness of processing carried out prior to such withdrawal.
Right to Nomination: To the extent provided under applicable law, including the Digital Personal Data Protection Act, 2023, a Data Principal may nominate another individual to exercise their rights on their behalf in the event of death or incapacity.
Right to Portability: Where applicable under the relevant legal framework, a Data Principal may request that their personal data be provided or transferred in a structured, commonly used and machine-readable format.
15.3. Where a Data Principal submits a rights request to WebOccult directly in connection with data processed at the Client’s premises WebOccult shall promptly forward that request to the Client and shall provide all reasonable assistance to enable the Client to respond. WebOccult shall process any such request as instructed by the Client subject to applicable law.
15.4. Data Principals wishing to exercise their rights in respect of data captured at a Client’s premises should contact the Client’s designated privacy or data protection officer in the first instance. WebOccult’s privacy contact details are provided in Clause 24.
16.Confidentiality
16.1. Each Party agrees to hold the other Party’s Confidential Information in strict confidence during the term of this Policy and for a period of five years following its termination or expiry, provided that Confidential Information constituting a trade secret shall remain protected for as long as it retains its status as a trade secret. Neither Party shall disclose Confidential Information to
16.2. Each Party may disclose Confidential Information to its employees, contractors, sub-processors and professional advisers who have a need to know the information for the purposes of this Policy and who are bound by confidentiality obligations at least as stringent as those in this clause. Each Party shall be responsible for any breach of confidentiality by persons to whom it has disclosed the other Party’s Confidential Information.
16.3. Confidentiality obligations shall not apply to information that is or becomes publicly available without breach of this Policy by the receiving Party, that was lawfully known to the receiving Party before disclosure, that is received without restriction from a third party who has authority to disclose it, or that is required to be disclosed by applicable law or by order of a competent court or regulatory authority. A Party required to make such a compelled disclosure shall give prompt written notice to the other Party and shall cooperate in seeking appropriate protective measures where reasonably possible.
17.Warranties
17.1.Company Warranties: The Company warrants that the Platform will perform materially in accordance with the Company’s standard product documentation for the subscribed sub-platforms and any functionality expressly committed in writing in the applicable Service Order during the Subscription Period. Where the Platform fails to perform materially as warranted the Client’s sole and exclusive remedy shall be for the Company to use commercially reasonable efforts to restore the Platform to conforming performance within a reasonable timeframe. Where the Company is unable to restore conforming performance within a reasonable period the Client may be entitled to a pro-rated refund of subscription fees attributable to the period of non-conforming performance as agreed in the Service Order. The Gotilo Product Suite is a standardised, productised platform and not a bespoke software development service. Unless expressly agreed in writing in a Service Order, the Company does not warrant that the Platform will meet the Client’s individual requirements, will be customised to Client-specific workflows, or will achieve any particular operational outcome at the Client’s premises. The warranty in this Clause does not apply to any non-conformance arising from use of the Platform contrary to the documentation or this Policy, Client-side network, hardware or environmental conditions, modifications or integrations not performed or approved by the Company, or Devices not supplied or certified by the Company.
17.2. Disclaimer of Additional Warranties: Except as expressly stated in Clause 17.1 the Platform is provided on an as-is and as-available basis. The Company does not warrant that the Platform will be uninterrupted or error-free at all times, that AI-Generated Outputs will be accurate, complete or suitable for any specific purpose beyond those described in this Policy, or that AI-Generated Outputs will meet the evidentiary requirements of any third-party contractual, regulatory or legal process without independent verification by the Client. The Company expressly disclaims any implied warranty of merchantability or fitness for a particular purpose to the maximum extent permitted by applicable law.
18. Limitation of Liability
18.1. The Company’s total maximum aggregate liability to the Client under or in connection with this Policy whether arising in contract, tort including negligence, breach of statutory duty or otherwise shall not exceed the total subscription fees paid by the Client to the Company under the applicable Service Order in the twelve months immediately preceding the event giving rise to the claim.
18.2. Neither Party shall be liable to the other for any loss of profit, loss of revenue, loss of anticipated savings, loss of business, business interruption, loss of goodwill, loss of data or any indirect, consequential, incidental, or special loss
18.3. In addition to the general limitations above the Company shall not be liable in any circumstances for the following specific categories of loss. First, loss or damage arising from the Client’s reliance on AI-Generated Outputs including damage detection reports from Gotilo Container, safety compliance alerts from Gotilo Spot and defect detection results from Gotilo Inspect without the independent verification required under Clause 8. Second, regulatory penalties, employment claims, fines or third-party legal actions arising from the Client’s failure to obtain and maintain the consents, notices and permissions required under Clause 4.1. Third, data loss or service disruption resulting from network failures, power outages, physical security breaches or cybersecurity incidents at the Client’s premises. Fourth, loss arising from actions taken by the Client’s own Authorised Users. Fifth, loss arising from the Client’s failure to configure appropriate retention periods, access controls or security settings within the Platform.
18.4. Nothing in this Policy shall limit or exclude either Party’s liability for death or personal injury caused by negligence, fraud or fraudulent misrepresentation or any other liability that cannot lawfully be excluded under applicable law.
19.Indemnity
19.1. The Client shall indemnify, defend and hold harmless the Company and its officers, directors, employees, affiliates, sub-processors and service providers from and against all claims, demands, losses, damages, fines, penalties, costs and expenses including reasonable legal fees arising out of or connected to the following.
The Client’s failure to obtain or maintain the regulatory approvals, workplace consents, premises notices and statutory permissions required for the deployment and operation of surveillance equipment and AI monitoring systems at its premises as required under Clause 4.1.
Any breach of this Policy by the Client or any Authorised User.
The Client’s reliance on AI-Generated Outputs without the independent verification required under Clause 8.
Any violation by the Client of applicable data protection, labour, workplace surveillance or sector-specific legislation.
Any claim arising from the Client’s enabling of biometric identification features without establishing the required lawful basis or obtaining required consents.
19.2. The Company shall indemnify the Client against any third-party claim alleging that the Platform as delivered by the Company in its standard configuration infringes the intellectual property rights of a third party, provided that the Client promptly notifies the Company of any such claim, grants the Company sole control of the defence and settlement of the claim and provides all reasonable assistance at the Company’s reasonable cost.
20. Service Levels and Maintenance
20.1. The Company shall use commercially reasonable efforts to maintain Platform availability at the service levels specified in the Service Order. Service level commitments, measurement methodologies, exclusions, remedies and credits shall be as described in the SLA schedule attached to or incorporated into the Service Order.
20.2. The Company shall provide the Client with at least forty-eight hours’ advance notice of planned maintenance activities that will affect Platform availability. Emergency maintenance required to prevent a security risk, data loss or service degradation may be performed without advance notice and the Company shall notify the Client as soon as reasonably practicable in such cases. Scheduled downtime for which advance notice has been provided shall not constitute a service level failure.
21. Term, Suspension and Termination
21.1. This Policy commences on the date the Client executes the Service Order and/or any other relevant document, and continues for the Subscription Period specified therein. Unless either Party gives the other at least thirty days’ written notice of non-renewal before the end of the then-current Subscription Period this Policy shall automatically renew for successive periods of the same duration on the same terms.
21.2. Either Party may terminate this Policy immediately upon written notice to the other Party if that other Party commits a material breach and fails to remedy the breach within thirty days of receiving a written notice specifying the breach in reasonable detail. Either Party may terminate immediately upon the insolvency, liquidation, winding-up, appointment of a receiver or administrator or the entry into a voluntary arrangement by the other Party.
21.3. The Company may suspend the Client’s access to the Platform immediately, and without prior notice in the case of a material security risk or use in breach of applicable law, if the Company reasonably believes that the Client or any Authorised User is using the Platform in a manner that poses a material security risk to the Platform or to other clients of the Company, is using the Platform in breach of applicable law, or has failed to pay subscription fees in accordance with the Service Order and has not remedied such failure within five business days of notice.
21.4. Upon termination for any reason all licences granted to the Client under this Policy shall immediately cease. The following clauses shall survive termination: Clause 7 (AI Model Training), Clause 10 (Data Ownership and IP), Clause 11.2 (Data on Termination), Clause 16 (Confidentiality), Clause 18 (Limitation of Liability), Clause 19 (Indemnity), Clause 23 (Dispute Resolution) and Clause 24 (Governing Law).
22.Force Majeure
unrest, actions by governmental or regulatory authorities including the imposition of export controls or sanctions, power grid failures, telecommunications infrastructure failures and internet service provider outages. A Party wishing to claim force majeure relief shall give prompt written notice to the other Party describing the nature and anticipated duration of the event and shall use all reasonable efforts to mitigate its effects. If a force majeure event continues for more than sixty consecutive days either Party may terminate this Policy upon written notice without liability for the termination itself, subject to settlement of amounts due up to the date of termination.
23.Dispute Resolution
23.1. Amicable Resolution: Where any dispute, controversy or claim arises between the Parties in connection with this Policy, including any question as to its validity, interpretation, performance or alleged breach, the Parties shall first attempt to resolve the dispute amicably through good-faith negotiations between senior representatives of each Party who have authority to settle the dispute. Neither Party shall commence formal dispute resolution proceedings before the expiry of thirty days from the date on which the disputing Party first notified the other in writing of the dispute, unless the urgency of the matter makes a shorter period necessary to preserve a Party’s rights.
23.2. Arbitration: If the Parties are unable to resolve the dispute amicably within the period prescribed in Clause 23.1 either Party may serve a written notice invoking arbitration under this clause. The arbitration shall be conducted in accordance with the Arbitration and Conciliation Act, 1996 of India as amended. The arbitration shall be conducted by a sole arbitrator agreed upon by the Parties within fifteen days of the notice invoking arbitration. If the Parties cannot agree on a sole arbitrator each Party shall appoint one arbitrator within fifteen days and the two appointed arbitrators shall jointly appoint the presiding arbitrator within ten days thereafter. The arbitration shall be conducted in the English language and the seat and venue of arbitration shall be Ahmedabad, Gujarat, India. The arbitral award shall be final and binding on both Parties.
23.3. Interim Relief: Nothing in this clause shall prevent either Party from seeking urgent interim or injunctive relief from the courts located in Ahmedabad, Gujarat, India where the delay inherent in awaiting the appointment of an arbitral tribunal would cause irreparable harm to that Party.
24.Governing Law, Jurisdiction and Grievance Officer
24.1. This Policy and any dispute or claim arising out of or in connection with it or its subject matter or formation shall be governed by and construed in accordance with the laws of the Republic of India without regard to its conflict of law provisions. Subject to the arbitration provisions in Clause 23 the courts located in Ahmedabad, Gujarat, India shall have exclusive jurisdiction over any matter that is properly brought before a court.
24.2. For any privacy-related concerns, data rights requests or grievances regarding the processing of personal data through the Platform the Client may contact WebOccult’s designated Grievance Officer at the details below. WebOccult shall
Contact Detail
Information
Grievance Officer
Hardik Sonchhabda
Designation
Chief Operating Officer
Email
Hardik@weboccult.com
Response Timeline
Acknowledgement within 3 business days. Resolution endeavoured within 30 days.
24.3. For operational support, service requests, SLA escalations and account matters the Client should contact their designated account manager or the support channel specified in the Service Order.
25. General Provisions
25.1. Entire Policy: This Policy together with the applicable Service Order, Data Processing Agreement and Security Annexure constitutes the entire agreement between the Parties with respect to the Gotilo Product Suite and supersedes all prior agreements, representations, negotiations, correspondence and understandings whether oral or written relating to the Platform and Services.
25.2. Order of Precedence: In the event of a conflict between documents the order of precedence shall be as follows: (a) the Data Processing Agreement for data protection matters; (b) the Service Order for commercial terms and scope of deployment; (c) this Policy for all other matters. No prior or subsequent agreement shall override this Policy unless it expressly states in writing that it amends or supersedes a specific clause of this Policy.
25.3. Amendments: The Company reserves the right to modify, amend, or update these Terms and Conditions at any time, at its sole discretion. Any changes shall become effective upon posting the revised Terms and Conditions on the Company’s website or through any other communication method the Company considers appropriate, unless otherwise required by applicable law. A user’s continued access to or use of the Company’s services after the effective date of any changes constitutes acceptance of the revised Terms and Conditions. If a user does not agree to the amended Terms and Conditions, the user must discontinue use of the Company’s services. Where required by applicable law, the Company will provide reasonable notice of any material changes before they take effect.
25.4. Policy is found by a competent authority to be invalid, unlawful or unenforceable that provision shall be severed and the remaining provisions shall continue in full force. The Parties shall in good faith negotiate a valid replacement that achieves as nearly as possible the original intention of the severed provision.
25.5. Waiver: No failure or delay by either Party in exercising any right or remedy under this Policy shall constitute a waiver of that right or remedy. A waiver of any breach shall not be construed as a waiver of any subsequent breach of the same or any other provision.
25.6. Assignment: The Client may not assign or transfer any of its rights or obligations under this Policy to any third party without the prior written consent of the Company. The Company may assign its rights and obligations to an affiliate or to a successor entity in connection with a merger, acquisition or sale of all or substantially all of its assets upon written notice to the Client.
25.7. Notices: All formal notices under this Policy shall be given in writing and delivered by email to the addresses specified in the Service Order or to such other address as a Party may notify in writing. An email notice shall be deemed received on the first business day following transmission provided no delivery failure notification has been received by the sender
25.8. Relationship of Parties: The Parties are independent contractors. Nothing in this Policy creates or shall be deemed to create any partnership, joint venture, agency, employment or franchise relationship between the Parties.
25.9. Electronic Record: This Policy is an electronic record published in accordance with the Information Technology Act, 2000 of India and the rules made thereunder and does not require any physical signature to be legally binding except where a wet or digital signature is separately required in a Service Order.
26.Acceptance and Execution
By executing a Service Order or any other relevant Agreement, purchase order, or document that incorporates this Policy, by activating access to any Gotilo sub-platform, or by permitting Authorised Users to access the Platform, the Client confirms all of the following.
The Client has read and understood this Policy in its entirety.
The Client has had the opportunity to seek independent legal advice before accepting.
The individual accepting on the Client’s behalf holds authority to bind the Client.
The Client agrees to be bound by the terms of this Policy with immediate effect.