01 Overview & Regulatory Framework
Vyavastha Technologies ("Vyavastha", "we", "our", or "us") provides a software-as-a-service (SaaS) operations platform for equipment rental, asset scheduling, inventory dispatch, GST invoicing, and customer coordination at app.vyavastha.com and marketing information at vyavastha.com.
This Privacy Policy sets out how we collect, store, process, transfer, and protect personal and operational data in compliance with:
- The Digital Personal Data Protection Act, 2023 (DPDP Act) of India;
- The Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 (SPDI Rules);
- Applicable guidelines issued by the Ministry of Electronics and Information Technology (MeitY).
All core database servers, tenant records, financial ledgers, and transaction backups are hosted in ISO/IEC 27001-certified Tier-III cloud data centers located within the territorial boundaries of the Republic of India.
02 Data Fiduciary vs Data Processor Roles
To ensure clear accountability under the DPDP Act 2023, Vyavastha operates under two distinct legal capacities:
For website inquiries, trial requests, and portal administrator login accounts, Vyavastha determines the purpose of data collection.
You (our subscriber/tenant) remain the Data Fiduciary of your end-customers' rental contracts, deposits, and phone numbers. Vyavastha acts solely as a secure Data Processor on your behalf.
03 Categories of Information Collected
We collect data only to the extent strictly necessary to provide dependable operational software:
- Lead & Trial Registration: Contact person's full name, business or enterprise name, 10-digit Indian mobile number, official email address, primary industry classification, and field executive team size.
- Tenant Account Profiles: Business GSTIN, registered office address, authorized billing administrators, and billing preferences.
- Operational Business Records: Equipment asset inventory, serial numbers, rental schedules, delivery manifests, customer names, contact numbers, security deposit transactions, and GST invoice line-items entered by you into your portal workspace.
- System Telemetry & Anti-Abuse Tokens: Anonymized SHA-256 client IP hash, browser user-agent header, submission timestamps, and authentication session tokens used strictly to safeguard against brute-force attacks and rate limit abuse.
04 Purpose and Lawful Basis for Processing
We process your data strictly under lawful consent and contract fulfillment grounds:
- To provision, authenticate, and maintain your tenant portal environment at
app.vyavastha.com; - To calculate and display rental schedules, return dates, outstanding dues, and deposit ledgers;
- To trigger automated transaction alerts (such as booking confirmations and dispatch notices via WhatsApp or SMS, as configured by you);
- To generate compliant GST tax invoices, delivery challans, and gate passes;
- To provide technical support, troubleshooting, and scheduled system updates;
- To fulfill statutory bookkeeping requirements under Indian company and taxation laws.
Vyavastha never sells, rents, monetizes, or shares your customer records, rental rates, or asset inventory with third-party advertisers, data brokers, or competitor rental agencies under any circumstances.
05 Multi-Tenant Data Isolation Guarantee
Vyavastha employs an architectural boundary known as Tenant Isolation. Every rental order, asset record, security deposit entry, and customer profile is cryptographically or logically scoped to your specific tenant identification code (tenant_id).
Database queries executed within the platform are enforced through an automated scoping layer (SqlScoper & TenantContext), ensuring that no tenant can ever read, access, or query data belonging to another business organization.
06 Security Architecture & Encryption Standards
We implement comprehensive administrative, physical, and technical safeguards pursuant to Rule 8 of the IT SPDI Rules 2011:
- Data in Transit: Transport Layer Security (TLS 1.3) with mandatory HTTPS enforcement and HSTS header protection.
- Data at Rest: Database tables encrypted using AES-256; sensitive credentials salted and hashed using modern bcrypt/Argon2 algorithms.
- Access Governance: Multi-factor authentication (MFA) supported for platform superadmins; strict role-based access control (RBAC) separating administrative views from tenant data.
- Automated Backups: Geographically redundant automated daily database snapshots with verifiable disaster recovery procedures.
07 Data Retention & Right to Erasure
We retain operational data for the duration of your active subscription and as required to fulfill statutory obligations:
- Active Accounts: Retained for the lifetime of your subscription to facilitate historical equipment analytics, depreciation tracking, and customer audit trails.
- Cancelled or Terminated Subscriptions: Upon account termination, you have a 30-day window to export your entire database (in CSV or Excel format). Following this grace period, tenant records are permanently expunged or irreversibly anonymized, except where retention is mandated by the Income Tax Act or GST regulations (typically 6-8 fiscal years for tax invoices).
- Marketing Leads: Inactive trial requests and demo leads are automatically purged or archived after 180 days.
08 Authorized Sub-Processors & Gateways
To deliver automated operational services, Vyavastha integrates with specialized infrastructure providers bound by non-disclosure and strict DPDP data processing agreements:
Servers situated in Mumbai / Bengaluru; ISO 27001 & SOC2 Type II audited.
End-to-end encrypted dispatch notices and payment receipt messages.
Password reset emails, security alerts, and system health notifications.
09 Rights of the Data Principal
Under Chapter III of the Digital Personal Data Protection Act 2023, you and your authorized staff possess the following enforceable rights:
- Right to Access Information: Request a summary of the personal data undergoing processing and the identities of any data processors involved.
- Right to Correction & Erasure: Rectify inaccurate, misleading, or outdated personal contact information, or request deletion where processing is no longer required.
- Right of Grievance Redressal: Avail readily accessible grievance redressal mechanisms with our designated compliance officer.
- Right to Nominate: Nominate an individual who, in the event of death or incapacity, shall exercise rights on your behalf.
10 Grievance Officer & Regulatory Contact
Pursuant to Section 5(2) of the DPDP Act 2023 and Rule 5(9) of the IT SPDI Rules 2011, Vyavastha has appointed a designated Grievance Officer to address any privacy inquiries, data access requests, or regulatory queries:
Attention: Privacy & Data Protection Desk
Entity: Vyavastha Technologies
Official Email: grievance@vyavastha.com • support@vyavastha.com
Registered Office: Vyavastha Plaza, Kurla West, Mumbai, Maharashtra 400070, India
Standard Response Window: Within 48 hours for acknowledgment; resolution within 15 calendar days.