Trust starts with saying what is public—and what is not.
This hub points to Gerai’s published privacy, security, AI and accessibility information. It also identifies topics that are discussed and agreed for a particular customer during procurement, rather than presented as universal public commitments.
Published information
These pages describe Gerai’s current public position. Each document should be read within its stated scope; publication does not turn a general description into a customer-specific warranty or service level.
Privacy Policy
How Gerai collects, uses, shares, protects, and handles personal data.
PublishedAI Transparency Notice
What Gerai’s AI assistant does, its limits, and how people remain involved.
PublishedAccessibility Statement
Gerai’s approach to accessible websites and how to report a barrier.
PublishedSecurity at Gerai
Gerai’s security boundaries, payment architecture, and reporting channel.
Published
The boundaries in plain English
- Privacy
- What personal data Gerai handles, why it is used, and how rights requests can be made.
- Security
- System boundaries, merchant payment settlement and the channel for reporting concerns.
- AI
- Where AI assists catalogue and messaging work, where people review, and what the system does not claim to be.
- Accessibility
- The public approach to accessible websites and a route for reporting a barrier.
Related published notices
These documents add detail about browser storage, Singapore data-protection information and the rules for using the service responsibly.
Cookie and Browser Storage Notice
How Gerai uses browser storage and server-side operational analytics.
PublishedAcceptable Use Policy
Rules for safe, lawful, and responsible use of Gerai services.
PublishedSingapore PDPA Notice
Singapore-specific information about Gerai’s handling of personal data.
Published
Agreed during enterprise procurement
The entries below are not represented as generally published policies or standard terms. They mark subjects that may require customer scope, provider details, technical review, confidentiality, negotiated wording or an executed agreement before they apply. A registry entry is not evidence that a certification, audit report, location option or service level exists for every customer.
Data Processing Addendum
How enterprise customers can request and agree data-processing terms with Gerai.
ProcurementSubprocessors
How Gerai discloses service providers that process customer personal data.
ProcurementIncident Response
How to report a security concern and how Gerai assesses incidents.
ProcurementData Residency
How to discuss data-location and transfer requirements before onboarding.
ProcurementService Levels
The relationship between Gerai’s public service and individually agreed service levels.
ProcurementService Status
How to check or report a possible Gerai service interruption.
Procurement
No certification by implication
Gerai does not use this hub to claim SOC 2, ISO 27001, PCI DSS or another certification or attestation. References to privacy laws, payment gateways or procurement documents do not imply certification against those frameworks. If a buyer needs a specific control, audit, data-location term, supplier disclosure or contract schedule, it should be raised explicitly and verified against the documents available for that procurement.
Ask a precise question
Email hello@gerai.shop with your organization, role, intended Gerai use, jurisdictions, data categories and the exact document or control you need to assess. Do not send confidential questionnaires or sensitive architecture material until an appropriate handling method has been agreed.