Privacy Policy & Data Protection
Data Protection Baseline • In alignment with DPDP Act, 2023 principles • Effective August 2026
1. Commitment to Data Privacy
Virtufy operates with a fundamental commitment to privacy by design. We understand that service businesses, clinics, and enterprises trust us with critical operational, customer, and business data. This policy details how data is collected, processed, isolated, and safeguarded under the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000.
2. Categories of Data We Process
Account & Organization Data
Business legal name, GSTIN, PAN, registered office address, staff names, work email, and authorized telephone numbers.
Lead & Customer Telemetry
Inbound customer enquiry details, booking records, contact numbers, and lead qualification stages recorded in your CRM mirror.
Approvals & Communications
Creative draft feedback, asset approvals, sprint task updates, and timestamped decision audit records.
Billing & Tax Records
Tax invoices, GST SAC 9983 breakdowns, transaction references, and payment reconciliation receipts.
3. Multi-Tenant Data Isolation
Every database query within the Virtufy platform is strictly scoped to the authenticated tenant organization using PostgreSQL Row-Level Security (org_id). All network communications are encrypted with TLS in transit and stored in protected storage with automated backup snapshots.
4. AI Processing & Zero Base Model Training
Zero Public Model Training Policy:
Your organization’s customer lists, patient inquiries, pricing models, and private business assets are NEVER used to train public foundation artificial intelligence models. Automated features operate strictly within bounded context windows via enterprise APIs with zero retention for base training.
5. Direct Integration Security
When connecting external advertising or communication channels (Meta Business Manager, Google Ads, or WhatsApp Business API), Virtufy utilizes official OAuth flows or designated platform identifiers. Virtufy never asks for or stores third-party account passwords.
6. Rights of Data Principals
In accordance with the DPDP Act 2023, organizations and their authorized users maintain the following rights:
- Access & Export: Download all customer records, leads, and task data in standard formats directly from the Client Portal.
- Rectification: Correct business, contact, or profile information via organization settings.
- Erasure: Request permanent deletion of organization accounts and associated data upon contract termination.
7. Contacting Privacy Governance
For any questions regarding data governance, privacy rights, or compliance audits, please contact our team at privacy@virtufy.com.
Review Our Commercial Policies
Learn about our refund schedule, sprint cycles, and cancellation terms.