DATA GOVERNANCE & PRIVACY

Privacy Policy & Data Protection

Data Protection Baseline • In alignment with DPDP Act, 2023 principles • Effective August 2026

1. Commitment to Data Privacy

Virtufy operates with a fundamental commitment to privacy by design. We understand that service businesses, clinics, and enterprises trust us with critical operational, customer, and business data. This policy details how data is collected, processed, isolated, and safeguarded under the Digital Personal Data Protection (DPDP) Act, 2023 and the Information Technology Act, 2000.

2. Categories of Data We Process

Account & Organization Data

Business legal name, GSTIN, PAN, registered office address, staff names, work email, and authorized telephone numbers.

Lead & Customer Telemetry

Inbound customer enquiry details, booking records, contact numbers, and lead qualification stages recorded in your CRM mirror.

Approvals & Communications

Creative draft feedback, asset approvals, sprint task updates, and timestamped decision audit records.

Billing & Tax Records

Tax invoices, GST SAC 9983 breakdowns, transaction references, and payment reconciliation receipts.

3. Multi-Tenant Data Isolation

Every database query within the Virtufy platform is strictly scoped to the authenticated tenant organization using PostgreSQL Row-Level Security (org_id). All network communications are encrypted with TLS in transit and stored in protected storage with automated backup snapshots.

4. AI Processing & Zero Base Model Training

Zero Public Model Training Policy:

Your organization’s customer lists, patient inquiries, pricing models, and private business assets are NEVER used to train public foundation artificial intelligence models. Automated features operate strictly within bounded context windows via enterprise APIs with zero retention for base training.

5. Direct Integration Security

When connecting external advertising or communication channels (Meta Business Manager, Google Ads, or WhatsApp Business API), Virtufy utilizes official OAuth flows or designated platform identifiers. Virtufy never asks for or stores third-party account passwords.

6. Rights of Data Principals

In accordance with the DPDP Act 2023, organizations and their authorized users maintain the following rights:

  • Access & Export: Download all customer records, leads, and task data in standard formats directly from the Client Portal.
  • Rectification: Correct business, contact, or profile information via organization settings.
  • Erasure: Request permanent deletion of organization accounts and associated data upon contract termination.

7. Contacting Privacy Governance

For any questions regarding data governance, privacy rights, or compliance audits, please contact our team at privacy@virtufy.com.

Review Our Commercial Policies

Learn about our refund schedule, sprint cycles, and cancellation terms.

Refund & Cancellation Policy