Privacy Notice
Template: requires legal review
This is a working draft for a pre-launch product. It hasn’t been reviewed by counsel, does not guarantee compliance in any jurisdiction, and bracketed fields are still incomplete.
Controller: [legal entity name, registered address, contact email]. Grievance/privacy contact: [name/role, email].
1. Scope
This notice covers (a) visitors to our website, (b) people who register for or use VisiRelay ("customers" and their users), and (c) people whose data our customers process using VisiRelay ("end contacts"). For (c), the customer is usually responsible for its own data. We process that data on the customer's instructions under [our agreement / data processing addendum].
2. Data we collect
- Account data: name, email, password hash (never the plain password), role, organization.
- Website data: with your consent, a pseudonymous visitor token, pages viewed, referrer and campaign (UTM) parameters. We strip sensitive query parameters and do not capture free-text form fields through tracking.
- Forms: information you submit (for example a demo request) and your consent choices.
- Customer content: leads, contacts, messages, call metadata and recordings (where the customer enables them), deals, payments metadata, search tracking data and reports.
- Technical data: IP address, device/browser information, logs and security events.
- Billing data: subscription and invoice records; card details are handled by our payment processor [Razorpay] and not stored by us.
3. Why we use it
[Counsel to map each purpose to a lawful basis/ground under applicable law, e.g. India DPDP Act 2023 and others where relevant.]
- Provide, secure and support the service.
- Send transactional emails (verification, password reset, receipts).
- Send marketing only where you have consented; you can withdraw at any time.
- Improve the service using aggregated or de-identified information.
- Meet legal obligations.
4. Sharing
Sub-processors (hosting, email, messaging, telephony, payments, data providers) are listed at [link]. We do not sell personal data.
5. Retention
Account data: for the life of the account plus [n] days. Customer content: per customer retention settings; deleted or exported on request; backups expire after [n] days. Logs: [n] days.
6. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your data, to withdraw consent and to raise a grievance. Contact [email]. For data a customer controls, we will forward your request to that customer.
7. Security
See our Security page. No system is perfectly secure; we will notify affected parties of incidents as required by law.
8. International transfers
[Hosting region and transfer safeguards — counsel to complete.]
9. Children
The service is not directed to children under [age].
10. Changes
We will post changes here and update the date above; material changes will be notified [how].