Introduction
- VIANSEC Solutions Private Limited ("VIANSEC", "we", "us", "our"), operating under the brand name KAVACH, is committed to protecting the privacy, confidentiality, and security of personal data entrusted to us.
The platform delivers decision-support services across five operational pillars:
- What personal data we collect
- Why we collect it
- How we use, store, and protect it
- With whom we share it
- Your rights in relation to your personal data
- How to contact us with privacy concerns
This Policy is published in compliance with:
- Digital Personal Data Protection Act, 2023 (DPDP Act)
- Information Technology Act, 2000 (IT Act)
- IT (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011
- General Data Protection Regulation (GDPR) — where applicable to data subjects in the European Union
Who We Are
- Legal Name — VIANSEC Solutions Private Limited
- Brand Name — KAVACH
- Registered Office — Hafeezpet, Hyderabad, Telangana — 500049
- Email — support@kavachtechnologies.com
- Website — www.kavachtechnologies.com
- Nature of Business — Enterprise intelligence software platform — B2B SaaS
- Certifications — ISO 27001:2022 · GDPR Compliant · DPDP Compliant
VIANSEC's Role — Data Processor, Not Data Fiduciary for Client-Site Data
For all personal data processed through the KAVACH platform at Client premises, VIANSEC Solutions Private Limited acts solely as a Data Processor as defined under the DPDP Act, 2023.
The Client organisation is the Data Fiduciary — solely responsible for determining the purpose and means of processing, obtaining consents, and fulfilling all Data Fiduciary obligations.
VIANSEC Solutions Private Limited has no direct legal obligation to data subjects — including employees, visitors, contractors, or members of the public — in connection with data processed at Client premises under a duly executed Data Processing Agreement.
All rights requests, complaints, and claims from data subjects whose data is processed at Client premises must be directed to the Client organisation, not to VIANSEC Solutions Private Limited.
- VIANSEC will cooperate with the Client to facilitate data subject rights as required by the DPA, but bears no independent liability to data subjects for such processing.
Who This Policy Applies To
- Website Visitors — Any person visiting or interacting with www.kavachtechnologies.com
- Client Representatives and Platform Users — Individuals accessing KAVACH on behalf of a Client organisation under a signed MSA
- Data Subjects on Client Premises — Individuals whose data is processed through KAVACH at Client facilities; for this category VIANSEC acts as Data Processor and the Client is Data Fiduciary
Personal Data We Collect
A. From Website Visitors
- Name and email address — when submitted through contact or demo request forms
- Organisation name and job designation — when voluntarily provided
- Phone number — when voluntarily provided
- IP address, browser type, operating system, and device information — collected automatically
- Pages visited, time spent, and interactions — via cookies and analytics tools
B. From Client Representatives and Platform Users
- Full name, job title, and email address
- Mobile number — for OTP authentication and alert notifications
- Login credentials — encrypted; passwords never stored in plain text
- Platform usage logs — modules accessed, actions performed, alerts acknowledged, reports generated
- Support and communication records with VIANSEC
C. Data Processed at Client Premises (as Data Processor)
- Visitor and contractor records — name, ID reference, contact number, purpose, timestamps, vehicle number
- Guard patrol records — GPS checkpoint data, timestamps, photographs
- Safety observation data — photographs, descriptions, risk categorisations, action logs
- Incident records — descriptions, photographs, CAPA actions, resolution logs
- Emergency evacuation data — real-time occupancy status and communication records
- Employee-linked facility data — shift schedules, transport bookings, room reservations, occupancy check-ins
- IoT and sensor data — machine parameters, energy readings, temperature levels, utility consumption (primarily non-personal)
How We Use Personal Data
A. Website Visitors
- To respond to contact forms, demo requests, and general enquiries
- To send relevant product updates or communications — only with your consent and with easy opt-out in every communication
- To analyse website traffic in aggregate, anonymised form to improve our website
- To maintain website security and prevent fraudulent activity
B. Client Representatives and Platform Users
- To create, maintain, and secure platform accounts
- To authenticate user identity and manage authorised access
- To deliver alerts, reports, notifications, and escalation communications
- To generate and maintain audit logs for security and compliance
- To provide customer support, training, and onboarding assistance
- To improve the KAVACH platform based on aggregated, anonymised usage patterns
C. Data on Client Premises (as Data Processor)
- Exclusively as instructed by the Client under the Data Processing Agreement
- To deliver the contracted services across KAVACH's five operational pillars
VIANSEC Solutions Private Limited does not use Client-site personal data for its own marketing, profiling, secondary analytics, or any purpose beyond contracted service delivery.
Legal Basis for Processing
- Consent — For website visitors who voluntarily submit forms or accept non-essential cookies
- Contractual necessity — For processing data of Client representatives to deliver contracted services
- Legitimate interests — For platform security, fraud prevention, and service improvement, where not overridden by data subject rights
- Legal obligation — Where required to comply with applicable Indian law or directions of a competent authority
- Data Processing Agreement — For all personal data processed on behalf of Clients at their premises
Data Retention
- Website contact and inquiry data — 12 months from date of last interaction, unless a commercial engagement commences
- Client representative account data — duration of active engagement plus 12 months following termination
- Platform audit and activity logs — 24 months from the date of the recorded activity
- Visitor and contractor records — as specified in the DPA; typically 12 months, unless the Client requires longer
CCTV and video stream data — VIANSEC processes video feeds in real time and does not independently store video content unless specifically agreed in the DPA. Client-side storage is governed by the Client's own retention policy.
- Safety observation and incident records — 36 months, or longer as required by applicable regulation including the Factories Act, 1948
- Guard patrol records — 12 months
- Emergency evacuation event records — 36 months
- IoT and sensor data — as agreed in the DPA; typically 24 months for trend analysis
- At the end of the applicable retention period, personal data is securely and permanently deleted or anonymised so that re-identification is no longer possible.
How We Share Personal Data
VIANSEC Solutions Private Limited does not sell, rent, or trade personal data to any third party under any circumstances.
We may share personal data only in the following limited circumstances:
- With authorised Client personnel — Platform outputs and reports shared only with individuals expressly authorised by the Client
- With technology sub-processors — Under equivalent contractual data protection terms; list available on written request to support@kavachtechnologies.com
- With regulatory or law enforcement authorities — Where required by court order, regulatory direction, or applicable Indian law; Client notified where legally permissible
- In a business restructuring — Subject to equivalent data protection commitments by the successor entity
Data Security
VIANSEC Solutions Private Limited implements the following security measures:
- ISO 27001:2022 certification — Independently audited and certified information security management system
- Encryption — All data encrypted in transit using TLS and at rest using AES-256
- Role-based access control — Each user accesses only data relevant to their designated role
- Multi-factor authentication — Required for all platform user accounts
- Regular security assessments — Including vulnerability scanning and periodic penetration testing
- Comprehensive audit trails — All data access, administrative actions, and system events logged and time-stamped
- Incident response procedures — Documented and tested, aligned with ISO 27001 and DPDP Act, 2023 requirements
Data breach notification — in the event of a personal data breach likely to result in risk or harm to data subjects, VIANSEC Solutions Private Limited will notify affected Clients within 72 hours of becoming aware of the breach.
No Direct Liability of VIANSEC to Data Subjects for Client-Site Processing
VIANSEC Solutions Private Limited processes personal data at Client premises solely as a Data Processor acting on the Client's instructions.
VIANSEC Solutions Private Limited accepts no direct legal liability to any data subject — whether an employee, visitor, contractor, patient, student, guard, or member of the public — for data processed at Client premises under a DPA.
Any complaint, claim, or rights request from such a data subject must be directed to the Client organisation as the Data Fiduciary.
This clause shall be interpreted broadly to provide the fullest possible protection to VIANSEC Solutions Private Limited from direct data subject claims arising from Client-site processing.
Your Rights as a Data Subject
Under the DPDP Act, 2023, website visitors and platform users have the following rights in relation to data held directly by VIANSEC:
- Right to access — Obtain a copy of your personal data held by VIANSEC
- Right to correction — Correct inaccurate or incomplete data
- Right to erasure — Request deletion where no lawful basis exists for retention, subject to legal retention obligations
- Right to grievance redressal — Contact our Grievance Officer at support@kavachtechnologies.com
- Right to nominate — Nominate another individual to exercise rights on your behalf in the event of death or incapacity
For data processed at Client premises: direct all requests to the Client organisation as Data Fiduciary. VIANSEC has no independent obligation to the data subject and will assist the Client as required under the DPA only.
- To exercise any right as a website visitor or platform user, write to: support@kavachtechnologies.com
Limitation of Liability
VIANSEC Solutions Private Limited shall under no circumstances be liable for:
- Indirect, incidental, special, punitive, exemplary, or consequential losses or damages of any nature whatsoever
- Loss of revenue, profit, business, opportunity, goodwill, reputation, or data
- Losses arising from the Client's failure to maintain human oversight of platform outputs
- Losses arising from the Client's failure to inform or obtain consent from data subjects
- Losses arising from decisions made solely on the basis of KAVACH platform outputs without independent human verification
- Losses arising from failure or misconfiguration of the Client's own hardware, network, or existing systems
- Losses arising from any incident, injury, accident, or emergency occurring at the Client's premises, whether or not the KAVACH platform was in use at the time
- Losses arising from inaccurate, incomplete, or delayed AI-generated outputs including missed alerts, false positives, or false negatives
- Losses arising from the acts or omissions of the Client's employees, agents, contractors, visitors, or any third party
Nothing in this clause limits liability for fraud, wilful misconduct, or death or personal injury caused directly and solely by VIANSEC's negligence — to the extent such limitation is not permitted under Indian law.
Disclaimer of Warranties
VIANSEC Solutions Private Limited expressly disclaims all warranties, whether express, implied, statutory, or otherwise, including:
- Any implied warranty of merchantability, fitness for a particular purpose, or non-infringement
- Any warranty that the platform will be uninterrupted, error-free, completely secure, or free from viruses
- Any warranty that AI-generated alerts, predictions, or analyses will be accurate, complete, or timely
- Any warranty that the platform will meet every specific requirement of the Client
- KAVACH's AI Video Intelligence does not use facial recognition or biometric identification. All detection is based on object recognition, behaviour patterns, zone monitoring, and movement analysis only.
No Waiver of Rights by VIANSEC
- No failure, omission, delay, or forbearance by VIANSEC in exercising any right, power, or remedy shall operate as a waiver of that right, power, or remedy.
- A waiver of any breach shall not be construed as a waiver of any subsequent breach of the same or any other provision.
Force Majeure
- Neither party shall be liable for delay or failure in performance caused by circumstances beyond their reasonable control, including: acts of God, floods, earthquakes, epidemics, pandemics, government orders, war, civil unrest, terrorism, fire, power grid failures, or telecommunications outages.
- The affected party must notify the other in writing within seven (7) days of the event.
- If a Force Majeure event continues for more than thirty (30) days, either party may terminate the affected services by written notice without liability.
Dispute Resolution and Governing Law
- These Terms are governed by the laws of India, without regard to conflict of law principles.
- All disputes shall first be attempted to be resolved through good-faith discussion within 30 days of written notice.
- If unresolved, disputes shall be referred to arbitration under the Arbitration and Conciliation Act, 1996, as amended, with a sole arbitrator mutually appointed by the parties.
- The seat and venue of arbitration shall be Hyderabad, Telangana, India.
- The language of arbitration shall be English.
- The arbitrator's award shall be final and binding.
Audit Rights — Limited
- The Client may request, not more than once per calendar year and with at least 30 days' written notice, a review of VIANSEC's information security practices relevant to the Client's data, conducted through VIANSEC's sharing of its current ISO 27001 certification, audit summaries, or third-party security assessment reports.
- Any audit conducted under this clause shall be at the Client's cost and shall not disrupt VIANSEC's operations.
General Provisions
- Entire Agreement — These Terms, together with the MSA, SOW, DPA, SLA, Disclaimer, and Privacy Policy, constitute the entire agreement between the parties and supersede all prior agreements, representations, warranties, and understandings — whether written, oral, or implied.
- No Oral Modifications — No oral statement, promise, or representation — including any made during sales, demonstration, or onboarding — shall modify, vary, or supplement these Terms. Only a written amendment signed by authorised representatives of both parties shall have effect.
- Severability — If any provision is found invalid or unenforceable, it shall be modified to the minimum extent necessary, and remaining provisions shall continue in full force.
- Survival — Clauses 5, 6, 7, 8, 9, 10, 11, 13, 14, 15, 17, and 19 shall survive the termination or expiry of these Terms.
- Assignment — The Client may not assign these Terms without VIANSEC's prior written consent. VIANSEC may assign these Terms in connection with a merger, acquisition, or sale of substantially all of its assets.
- Third-Party Rights — These Terms do not create any rights enforceable by any third party, including any data subject, employee, visitor, or contractor of the Client.
- Language — In the event of any conflict between the English version of these Terms and any translation, the English version shall prevail.
Amendments
- VIANSEC reserves the right to amend these Terms at any time.
- Clients will be notified of material changes at least 15 days before the amended Terms take effect via email or platform notification.
- Continued use after the effective date constitutes acceptance of the updated Terms.
Contact
- Company — VIANSEC Solutions Private Limited (Operating under the brand name KAVACH)
- Address — Hafeezpet, Hyderabad, Telangana — 500049
- Email — support@kavachtechnologies.com
- Website — www.kavachtechnologies.com