1. Who we are
[Registered Legal Entity Name] operates the Vidrys recommendation-intelligence platform. For the personal data we process about you, we act as the Data Fiduciary under the DPDP Act, and you are the Data Principal. Where we process personal data on behalf of a customer (for example, data within a customer’s workspace), we act as a Data Processor for that customer.
- Registered entity: [Registered Legal Entity Name] (CIN [CIN / registration number])
- Registered office: [Registered office address, City, State, PIN], India
- Privacy contact: privacy@vidrys.com
- Grievance Officer: [Grievance Officer Name], grievance@vidrys.com (see section 12)
2. Key definitions
- Personal data — any data about an individual who is identifiable by or in relation to such data.
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or erasure.
- Data Principal — the individual to whom the personal data relates.
- Data Fiduciary — the person who determines the purpose and means of processing (that is us, for the data described in section 3).
- Sensitive personal data or information (SPDI) — as defined under the SPDI Rules (for example, passwords, financial information, health data). We keep our collection of SPDI to a minimum (see section 3).
3. Personal data we collect
We collect only the data we need to provide and improve the Service:
3.1 Data you give us
- Account & identity: your name, work email address, a password (stored only as a one-way hash, never in plain text), and your company or workspace name.
- Brand & measurement setup: the brand, website/domain, industry, topics, competitors, and the buyer prompts you choose to track. This is primarily business information, but may include personal data where you enter it.
- Demo & sales enquiries: if you request a demo, your full name, work email, company name, company domain, and (optionally) phone number, job title, and message.
- Support & communications: the contents of emails and messages you send us.
- Billing: we do not currently operate a self-serve payment gateway. When paid billing is enabled, payment-card details will be collected and processed by a third-party payment processor, not stored by us; we will retain only invoicing information (such as GSTIN and billing contact).
3.2 Data we collect automatically
- Usage & log data: pages viewed, features used, actions taken, and timestamps.
- Device & technical data: IP address, browser type, operating system, and similar diagnostic data.
- Cookies & similar technologies: as described in our Cookie Policy.
We do not intentionally collect special-category or sensitive personal data beyond what is described above, and we ask that you do not submit such data into the platform unless necessary.
4. How we use your data, and our lawful basis
Under the DPDP Act we process personal data on the basis of your consent or for certain legitimate uses permitted by the Act. We use personal data to:
- create and administer your account and workspace, and review and activate new workspaces;
- provide the Service — run probes across AI engines, compute scores, and generate recommendations;
- respond to demo requests, enquiries, and support requests;
- operate, secure, debug, and improve the Service and prevent fraud and abuse;
- send service and transactional communications about your account;
- send marketing communications where you have consented — you can withdraw consent at any time; and
- comply with applicable law and enforce our terms.
Where processing is based on consent, you may withdraw it at any time (see section 10); withdrawal does not affect processing carried out before withdrawal.
A note on AI engines:to measure your visibility we send brand-neutral buyer prompts (for example, “best CRM for small teams”) to third-party AI engines. These prompts are written to be brand-neutral and are not intended to contain your personal data.
5. Cookies and similar technologies
We use strictly necessary cookies to keep you signed in and secure, and — with your consent where required — functional and analytics cookies. For details and how to manage them, see our Cookie Policy.
6. How we share your data
We do not sell your personal data. We share it only as follows:
- Service providers (Data Processors): vendors who process data on our instructions under contract, including cloud hosting and database providers, and the third-party AI engines that respond to probes (such as OpenAI, Google, Groq, and similar providers). We require appropriate security and confidentiality safeguards from them.
- Within your organisation: other members of your workspace may see data associated with that workspace, according to the roles you assign.
- Legal & safety: where required to comply with law, a court order, or a lawful government request, or to protect our rights, users, or the public.
- Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
7. Cross-border transfers
Some of our service providers and AI engines operate outside India. Where we transfer personal data outside India, we do so in accordance with the DPDP Act, which permits transfer to countries other than those the Central Government may restrict, and we apply appropriate contractual safeguards.
8. Data retention
We retain personal data for as long as your account is active and as needed to provide the Service, and thereafter only for as long as necessary to satisfy the purposes described here or to comply with legal, tax, accounting, or reporting obligations. When personal data is no longer required and there is no legal requirement to retain it, we delete or anonymise it. On closure of your account we will delete or anonymise personal data within a reasonable period, except where retention is required by law.
9. How we protect your data
We implement reasonable security safeguards designed to protect personal data, consistent with the DPDP Act and the SPDI Rules, including encryption in transit, hashing of passwords, access controls and role-based permissions, tenant isolation, and monitoring. No method of transmission or storage is completely secure; in the event of a personal-data breach, we will take the steps required by law, including notifying the Data Protection Board of India and affected Data Principals where applicable.
10. Your rights as a Data Principal
Subject to the DPDP Act, you have the right to:
- Access — obtain a summary of the personal data we process about you and the processing activities;
- Correction & completion — have inaccurate or incomplete data corrected, completed, or updated;
- Erasure — request deletion of your personal data where it is no longer necessary for the purpose for which it was collected, unless retention is required by law;
- Grievance redressal — a readily available means of registering a grievance (see section 12);
- Nomination — nominate another individual to exercise your rights in the event of your death or incapacity; and
- Withdraw consent — withdraw consent previously given, as easily as it was given.
To exercise any of these rights, email privacy@vidrys.com. We may need to verify your identity before acting on a request. You are responsible for providing accurate information and for not impersonating others when exercising your rights.
11. Children’s data
The Service is intended for business users and is not directed to children. We do not knowingly process the personal data of any individual under 18 years of age without the verifiable consent of a parent or lawful guardian, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children, in line with the DPDP Act. If you believe a child has provided us personal data, please contact us so we can delete it.
12. Grievance redressal & the Data Protection Board
If you have any grievance about how we handle your personal data, please contact our Grievance Officer:
- Grievance Officer: [Grievance Officer Name]
- Email: grievance@vidrys.com
- Address: [Registered office address, City, State, PIN], India
We will acknowledge and endeavour to resolve grievances within the timelines prescribed under applicable law. If you are not satisfied with our response, you may have the right to complain to the Data Protection Board of India under the DPDP Act.
13. Third-party links
Our site and Service may link to third-party websites and services (for example, AI engines and CMS integrations). We are not responsible for their privacy practices; please review their policies.
14. Changes to this Policy
We may update this Policy from time to time. We will post the updated version here and revise the “Last updated” date, and, where required, notify you of material changes. Your continued use of the Service after an update constitutes acceptance of the revised Policy.
15. Contact us
Questions about this Policy or our data practices? Email privacy@vidrys.com or write to us at [Registered office address, City, State, PIN], India.