PRIVACY POLICY

01

Introduction

+
  • VIANSEC Solutions Private Limited ("VIANSEC", "we", "us", "our"), operating under the brand name KAVACH, is committed to protecting the privacy, confidentiality, and security of personal data entrusted to us.

The platform delivers decision-support services across five operational pillars:

  • What personal data we collect
  • Why we collect it
  • How we use, store, and protect it
  • With whom we share it
  • Your rights in relation to your personal data
  • How to contact us with privacy concerns

This Policy is published in compliance with:

  • Digital Personal Data Protection Act, 2023 (DPDP Act)
  • Information Technology Act, 2000 (IT Act)
  • IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
  • General Data Protection Regulation (GDPR) — where applicable to data subjects in the European Union
02

Who We Are

+
  • Legal Name — VIANSEC Solutions Private Limited
  • Brand Name — KAVACH
  • Registered Office — Hafeezpet, Hyderabad, Telangana — 500049
  • Email — support@kavachtechnologies.com
  • Website — www.kavachtechnologies.com
  • Nature of Business — Enterprise intelligence software platform — B2B SaaS
  • Certifications — ISO 27001:2022 · GDPR Compliant · DPDP Compliant
03

VIANSEC's Role — Data Processor, Not Data Fiduciary for Client-Site Data

+

For all personal data processed through the KAVACH platform at Client premises, VIANSEC Solutions Private Limited acts solely as a Data Processor as defined under the DPDP Act, 2023.

The Client organisation is the Data Fiduciary — solely responsible for determining the purpose and means of processing, obtaining consents, and fulfilling all Data Fiduciary obligations.

VIANSEC Solutions Private Limited has no direct legal obligation to data subjects — including employees, visitors, contractors, or members of the public — in connection with data processed at Client premises under a duly executed Data Processing Agreement.

All rights requests, complaints, and claims from data subjects whose data is processed at Client premises must be directed to the Client organisation, not to VIANSEC Solutions Private Limited.

  • VIANSEC will cooperate with the Client to facilitate data subject rights as required by the DPA, but bears no independent liability to data subjects for such processing.
04

Who This Policy Applies To

+
  • Website Visitors — Any person visiting or interacting with www.kavachtechnologies.com
  • Client Representatives and Platform Users — Individuals accessing KAVACH on behalf of a Client organisation under a signed MSA
  • Data Subjects on Client Premises — Individuals whose data is processed through KAVACH at Client facilities; for this category VIANSEC acts as Data Processor and the Client is Data Fiduciary
05

Personal Data We Collect

+

A. From Website Visitors

  • Name and email address — when submitted through contact or demo request forms
  • Organisation name and job designation — when voluntarily provided
  • Phone number — when voluntarily provided
  • IP address, browser type, operating system, and device information — collected automatically
  • Pages visited, time spent, and interactions — via cookies and analytics tools

B. From Client Representatives and Platform Users

  • Full name, job title, and email address
  • Mobile number — for OTP authentication and alert notifications
  • Login credentials — encrypted; passwords never stored in plain text
  • Platform usage logs — modules accessed, actions performed, alerts acknowledged, reports generated
  • Support and communication records with VIANSEC

C. Data Processed at Client Premises (as Data Processor)

  • Visitor and contractor records — name, ID reference, contact number, purpose, timestamps, vehicle number
  • Guard patrol records — GPS checkpoint data, timestamps, photographs
  • Safety observation data — photographs, descriptions, risk categorisations, action logs
  • Incident records — descriptions, photographs, CAPA actions, resolution logs
  • Emergency evacuation data — real-time occupancy status and communication records
  • Employee-linked facility data — shift schedules, transport bookings, room reservations, occupancy check-ins
  • IoT and sensor data — machine parameters, energy readings, temperature levels, utility consumption (primarily non-personal)
06

How We Use Personal Data

+

A. Website Visitors

  • To respond to contact forms, demo requests, and general enquiries
  • To send relevant product updates or communications — only with your consent and with easy opt-out in every communication
  • To analyse website traffic in aggregate, anonymised form to improve our website
  • To maintain website security and prevent fraudulent activity

B. Client Representatives and Platform Users

  • To create, maintain, and secure platform accounts
  • To authenticate user identity and manage authorised access
  • To deliver alerts, reports, notifications, and escalation communications
  • To generate and maintain audit logs for security and compliance
  • To provide customer support, training, and onboarding assistance
  • To improve the KAVACH platform based on aggregated, anonymised usage patterns

C. Data on Client Premises (as Data Processor)

  • Exclusively as instructed by the Client under the Data Processing Agreement
  • To deliver the contracted services across KAVACH's five operational pillars
  • VIANSEC Solutions Private Limited does not use Client-site personal data for its own marketing, profiling, secondary analytics, or any purpose beyond contracted service delivery.

07

Legal Basis for Processing

+
  • Consent — For website visitors who voluntarily submit forms or accept non-essential cookies
  • Contractual necessity — For processing data of Client representatives to deliver contracted services
  • Legitimate interests — For platform security, fraud prevention, and service improvement, where not overridden by data subject rights
  • Legal obligation — Where required to comply with applicable Indian law or directions of a competent authority
  • Data Processing Agreement — For all personal data processed on behalf of Clients at their premises
08

Data Retention

+
  • Website contact and inquiry data — 12 months from date of last interaction, unless a commercial engagement commences
  • Client representative account data — duration of active engagement plus 12 months following termination
  • Platform audit and activity logs — 24 months from the date of the recorded activity
  • Visitor and contractor records — as specified in the DPA; typically 12 months, unless the Client requires longer

CCTV and video stream data — VIANSEC processes video feeds in real time and does not independently store video content unless specifically agreed in the DPA. Client-side storage is governed by the Client's own retention policy.

  • Safety observation and incident records — 36 months, or longer as required by applicable regulation including the Factories Act, 1948
  • Guard patrol records — 12 months
  • Emergency evacuation event records — 36 months
  • IoT and sensor data — as agreed in the DPA; typically 24 months for trend analysis
  • At the end of the applicable retention period, personal data is securely and permanently deleted or anonymised so that re-identification is no longer possible.
09

How We Share Personal Data

+

VIANSEC Solutions Private Limited does not sell, rent, or trade personal data to any third party under any circumstances.

We may share personal data only in the following limited circumstances:

  • With authorised Client personnel — Platform outputs and reports shared only with individuals expressly authorised by the Client
  • With technology sub-processors — Under equivalent contractual data protection terms; list available on written request to support@kavachtechnologies.com
  • With regulatory or law enforcement authorities — Where required by court order, regulatory direction, or applicable Indian law; Client notified where legally permissible
  • In a business restructuring — Subject to equivalent data protection commitments by the successor entity
10

Data Security

+

VIANSEC Solutions Private Limited implements the following security measures:

  • ISO 27001:2022 certification — Independently audited and certified information security management system
  • Encryption — All data encrypted in transit using TLS and at rest using AES-256
  • Role-based access control — Each user accesses only data relevant to their designated role
  • Multi-factor authentication — Required for all platform user accounts
  • Regular security assessments — Including vulnerability scanning and periodic penetration testing
  • Comprehensive audit trails — All data access, administrative actions, and system events logged and time-stamped
  • Incident response procedures — Documented and tested, aligned with ISO 27001 and DPDP Act, 2023 requirements

Data breach notification — in the event of a personal data breach likely to result in risk or harm to data subjects, VIANSEC Solutions Private Limited will notify affected Clients within 72 hours of becoming aware of the breach.

11

No Direct Liability of VIANSEC to Data Subjects for Client-Site Processing

+

VIANSEC Solutions Private Limited processes personal data at Client premises solely as a Data Processor acting on the Client's instructions.

VIANSEC Solutions Private Limited accepts no direct legal liability to any data subject — whether an employee, visitor, contractor, patient, student, guard, or member of the public — for data processed at Client premises under a DPA.

Any complaint, claim, or rights request from such a data subject must be directed to the Client organisation as the Data Fiduciary.

This clause shall be interpreted broadly to provide the fullest possible protection to VIANSEC Solutions Private Limited from direct data subject claims arising from Client-site processing.

12

Your Rights as a Data Subject

+

Under the DPDP Act, 2023, website visitors and platform users have the following rights in relation to data held directly by VIANSEC:

  • Right to access — Obtain a copy of your personal data held by VIANSEC
  • Right to correction — Correct inaccurate or incomplete data
  • Right to erasure — Request deletion where no lawful basis exists for retention, subject to legal retention obligations
  • Right to grievance redressal — Contact our Grievance Officer at support@kavachtechnologies.com
  • Right to nominate — Nominate another individual to exercise rights on your behalf in the event of death or incapacity

For data processed at Client premises: direct all requests to the Client organisation as Data Fiduciary. VIANSEC has no independent obligation to the data subject and will assist the Client as required under the DPA only.

  • To exercise any right as a website visitor or platform user, write to: support@kavachtechnologies.com
13

Cookies and Tracking Technologies

+
  • Essential cookies — Required for website function; cannot be disabled
  • Analytics cookies — Aggregate, anonymised usage data; opt out via browser settings or support@kavachtechnologies.com
  • Preference cookies — Personalise return visits
  • Disabling non-essential cookies may affect certain website features.
14

Children's Privacy

+

We do not knowingly collect data from individuals under 18 years of age. If you believe we have collected data from a minor, contact us immediately at support@kavachtechnologies.com.

15

International Data Transfers

+
  • Primary data infrastructure is located within India.
  • International transfers to sub-processors are made only under appropriate safeguards consistent with the DPDP Act, 2023.
  • Details available on request at support@kavachtechnologies.com.
16

Changes to This Policy

+
  • Material changes communicated via email and/or website notice at least 15 days before taking effect.
  • Continued use after the effective date constitutes acceptance.
  • The "Last Updated" date reflects the most recent revision.
17

Grievance Officer

+

In accordance with the IT Act 2000, IT Rules 2011, and DPDP Act 2023:

  • Name — K. Vijay Kumar
  • Designation — Grievance Officer / Data Protection Contact
  • Organisation — VIANSEC Solutions Private Limited (Brand: KAVACH)
  • Emailsupport@kavachtechnologies.com
  • Postal Address — Hafeezpet, Hyderabad, Telangana — 500049
  • Acknowledgement — Within 48 hours of receiving your grievance
  • Resolution — Within 30 days; complex matters within 45 days with prior notice
18

Contact Us

+