Who this policy covers
This Privacy Policy explains how Vercentlabs LLP ("Vercentlabs", "we", "us") collects, uses, and protects information when you visit this website (the "Site") or submit a request through it. It does not cover the Vercentlabs ERP application itself, which has its own in-product privacy and data-handling terms provided separately to customers as part of onboarding.
We are an India-based limited liability partnership. Where this policy references a specific data-protection law, it refers to India's Digital Personal Data Protection Act, 2023 (the "DPDPA") and its associated rules, which are being brought into force in phases through 2027 — see "Applicable law" below.
Information you provide to us
When you submit the demo-request form on this Site (/book-demo), you may provide: first and last name, work email address, phone number, company name, job title, industry, company size, the modules or workflows you're interested in, a short description of the problem you're trying to solve, a preferred contact time, and consent to be contacted. Only first name, email, phone, company name, and consent are required — every other field is optional, and we don't ask for anything we don't have a real, stated use for (see our public form-friction audit methodology, which governs what fields this form is allowed to ask for).
This information is submitted voluntarily, only when you choose to request a demo. We do not require an account, a login, or any information to browse the rest of the Site, read our resource content, or use the ERP requirements checklist.
Information collected automatically
First-touch attribution: when you first arrive at this Site, we record which campaign parameters (if any) brought you here (utm_source, utm_medium, utm_campaign, utm_content, utm_term), the page you landed on, a broad referrer category (direct, search, social, referral, or email), and a timestamp. This is stored only in your browser's local storage on this Site's own domain — not in a cookie, and not shared with any third party by itself. It is included with a demo-request submission (if you make one) so our sales team understands how you found us. It is never overwritten by a later visit; if you first arrive via one campaign and return later via another, the original attribution is preserved.
Technical performance signals: we collect anonymous page-performance metrics (Largest Contentful Paint, Interaction to Next Paint, Cumulative Layout Shift) to understand how fast the Site loads for real visitors. These are reported with a normalized route pattern (e.g. "/modules/[slug]", never the literal page URL with any query string), a rounded metric value, and a quality rating — never your name, IP address, or any other identifying information. As of the date of this policy, this data has no third-party analytics backend attached to it — it is collected by our own code but not yet transmitted anywhere; this will be updated if that changes.
Server logs: like most websites, our servers automatically log basic request information (timestamp, a randomly generated request ID, response status, and processing duration) for the purpose of diagnosing failures and preventing abuse of the demo-request form. We do not log the content of your submission — only whether it succeeded, failed validation, or failed for a technical reason. Your IP address is used to apply a simple rate limit against automated abuse of the form.
Abuse-prevention fingerprint: if you submit the demo-request form, a one-way cryptographic hash (not your raw IP address or browser identifier) derived from your IP address and browser type is included with the submission and retained alongside it in our CRM, solely to help detect duplicate or automated submissions. This hash cannot be reversed back into your original IP address or used to identify you outside the context of that one submission. A hidden "honeypot" field is also included in the form, invisible to real visitors — if it's filled in (a strong signal of automated form-filling software rather than a person), the submission is rejected and never reaches our CRM at all.
ERP requirements checklist progress: if you use the interactive requirements checklist (/resources/erp-requirements-checklist), which capability areas you've marked as reviewed is stored only in your browser's local storage. It is never sent to us, never included in any analytics event, and never leaves your device.
How we use your information
We use the information you submit through the demo-request form solely to respond to your request: to schedule and prepare for a demo call, to route your enquiry to the right specialist based on the modules or industry you indicated, and to follow up about your evaluation. We do not sell your information, and we do not use it for advertising targeting.
Your submission is delivered to our own customer relationship management (CRM) system — the same Vercentlabs ERP platform this website describes — via a signed, authenticated request from this website's server directly to that system. It is not routed through, or shared with, any third-party marketing or advertising platform.
Data retention
We retain demo-request information for as long as reasonably necessary to respond to your enquiry and, if you become a customer, as part of your account relationship — governed at that point by your customer agreement rather than this policy. If you'd like your demo-request information deleted and you have not become a customer, contact us using the details below.
Your rights
You may ask us to confirm what information we hold about you, to correct inaccurate information, or to delete information you've submitted, by emailing privacy@vercentlabs.com. We will respond within a reasonable time. If you are located in India, these rights are informed by the DPDPA's provisions for data principals as they come into force; we intend to honor requests of this kind regardless of the exact phase of the Act's implementation.
Security
Demo-request submissions are transmitted over an encrypted connection and authenticated with a signed request between this website and our CRM system, so a submission can't be forged or intercepted by a third party in transit. We apply standard web security practices to this Site, including a restrictive content security policy, security response headers, and rate limiting on the demo-request endpoint to reduce automated abuse.
Children's privacy
This Site and the Vercentlabs ERP product are intended for business use by adults evaluating enterprise software on behalf of an organization. We do not knowingly collect information from children, and this Site is not directed at them.
Applicable law
This policy is written with reference to India's Digital Personal Data Protection Act, 2023, which is being implemented in phases (key rules were notified in November 2025, with full provisions — including detailed consent, notice, and security obligations — scheduled to take effect by May 2027). We will review and update this policy as those provisions come into force. Nothing in this policy is intended as legal advice; it describes our actual practices as verified against our own code and infrastructure.
Changes to this policy
We may update this policy as our practices change or as applicable law evolves. The date at the top of this page reflects the last review. Material changes will be reflected here with an updated date.
Contact us
Questions about this policy, or requests regarding your information, can be sent to privacy@vercentlabs.com. For general support, use support@vercentlabs.com.