Legal
Privacy
How we collect, use and protect personal data: for people who visit this site, and for the clients whose business data we run dashboards and automations on.
Last updated [[ EFFECTIVE DATE ]]
Short version
- We collect the basics: what you send us when you email or book a call, plus standard web server logs. Nothing else, from site visitors, today.
- We never sell personal data, and we run no third-party analytics, ad tracking or tracking cookies. Fonts and video are served from our own server, not Google, YouTube or an ad network.
- For clients: your business data and your customers' data stay yours. We process it only on your instructions, to run your dashboard and automations.
- We keep client data only for the length of the engagement, then delete or return it within [[ RETENTION PERIOD ]] of it ending.
- You can ask what we hold, correct it, or have it deleted. Email [[ PRIVACY EMAIL ]].
- No automated system makes a legally significant decision about you on its own.
- The site sets no non-essential cookies. If that ever changes, tracking only loads after you opt in.
- Anyone talking to our Voice AI or automations is told it's an assistant, not a person.
Contents
Who we are
Vartha is [[ LEGAL ENTITY NAME ]], registered in India at [[ REGISTERED ADDRESS ]], registration number [[ REGISTRATION NUMBER ]]. We're an India-based agency selling business intelligence and automation to owner-run businesses in the United States, Europe (the EU and the UK) and the Middle East (the UAE, Saudi Arabia and the wider Gulf).
For anything to do with privacy, write to [[ PRIVACY EMAIL ]]. That inbox reaches the people responsible for this notice.
A company outside the EU and UK that offers services to people there usually has to appoint a local representative. We haven't appointed one yet: [[ EU ARTICLE 27 REPRESENTATIVE ]] for the EU under Article 27 of the GDPR, and [[ UK REPRESENTATIVE ]] for the UK under the UK GDPR. Both are in progress.
Scope and our two roles
This notice covers two different relationships, and different sections apply to each.
When we're the controller
If you visit this site, book a call, or email us, we decide why and how that data is used. We're the controller for that data. The sections on cookies, your rights and marketing mostly concern this relationship.
When we're the processor
If you're a client, you decide why and how your business data and your customers' data are used, and we act on your instructions. We're the processor. Your Stripe, QuickBooks, HubSpot and Google Sheets data, and the data our automations create about your customers (calls, messages, bookings, reviews), fall here. The section “For our clients: how we handle your data” covers this specifically. Security, sub-processors, international transfers and retention apply to both roles.
What we collect
The first three tables are about people we deal with directly, where we're the controller. The last is about client systems we process on a client's instructions, where we're the processor.
Site visitors
| Data | Where it comes from | Why | How long we keep it |
|---|---|---|---|
| Standard server log data: IP address, browser type, pages requested, timestamps | Automatically, from your browser, when you load the site | To run the site and investigate abuse or technical faults | Set by [[ HOSTING PROVIDER AND REGION ]], our hosting provider |
People who book a call or email us
| Data | Where it comes from | Why | How long we keep it |
|---|---|---|---|
| Name, email address, and anything else you tell us | Typed by you, in an email or a booking request | To reply, schedule the call, and follow up | [[ RETENTION PERIOD ]], or until you ask us to delete it |
| Booking details (date, time of a call) | Entered by you into [[ BOOKING TOOL ]], our booking tool, once we use one | To hold the call | Set by [[ BOOKING TOOL ]], or [[ RETENTION PERIOD ]] |
Client staff
| Data | Where it comes from | Why | How long we keep it |
|---|---|---|---|
| Name, work email, phone number, role | Given to us by the client, or by the staff member directly, to set up and run the service | To deliver the dashboard and automations, and to support the account | For the length of the engagement, then deleted or returned within [[ RETENTION PERIOD ]] |
| Access to tools we're given on the client's behalf (Stripe, QuickBooks, HubSpot, Google Sheets) | Shared by the client | To connect the client's data to their dashboard | For the length of the engagement |
Personal data inside a client's systems, that we process for them
| Data | Where it comes from | Why | How long we keep it |
|---|---|---|---|
| Business data: revenue, invoices, jobs, leads (from Stripe, QuickBooks, HubSpot, Google Sheets) | The client's own systems, connected on their instruction | To build and run the dashboard | For the length of the engagement, then deleted or returned |
| Customer data an automation creates: call recordings and transcripts, WhatsApp and DM messages, booking details, review requests and responses | Generated when an automation runs (Voice AI, fast lead reply, lead reactivation, review requests, ads) | To answer, book, reply to or follow up with the client's customer, on the client's instruction | [[ RETENTION PERIOD ]], or the client's own retention setting where we offer one |
Why we use it, and on what legal basis
We rely on different legal bases depending on the relationship and the region.
- Performing a contract: to deliver what we've agreed with a client, or to handle a call or email from you.
- Legitimate interests: to keep the site secure, to reply to enquiries, and to follow up with people who've shown interest, weighed each time against your right to privacy so it doesn't override it.
- Consent: where the law specifically requires it, for example marketing email to someone who isn't already a client, or non-essential cookies if we ever add them.
Those are the GDPR and UK GDPR bases. In the UAE and Saudi Arabia we rely on the equivalent bases under the UAE Personal Data Protection Law (PDPL) and the Saudi PDPL, which follow a similar pattern: contract, legitimate interest, consent and legal obligation.
We try not to collect special category data (health, biometric, religious, political or similar sensitive information) at all. If a client's dashboard or systems would put this kind of data in front of us, tell us before you connect them, so we can agree how to handle it.
International transfers
We operate from India. Our clients, and their customers, are mostly in the United States, Europe (the EU and UK) and the Gulf (the UAE, Saudi Arabia and neighbouring countries). Personal data often crosses borders as a result.
- From the EU or UK to India: we rely on the EU Standard Contractual Clauses, and the UK's International Data Transfer Addendum or an equivalent IDTA, backed by a transfer impact assessment. We're not aware of any adequacy decision covering India, and we don't claim one.
- From the UAE: transfers follow the UAE PDPL's rules on cross-border transfer, which generally call for an adequate level of protection at the destination, standard contractual clauses, or the individual's consent.
- From Saudi Arabia: transfers follow the Saudi PDPL, which sets its own conditions for sending personal data outside the Kingdom, including regulator approval in some cases.
- If a client needs their data to stay in a particular region, we can discuss hosting it there.
The underlying transfer paperwork (the SCCs, the UK addendum, and the transfer impact assessment) is in progress and isn't all signed yet.
How long we keep things
| Data type | Retention |
|---|---|
| Enquiry and booking details (not yet a client) | [[ RETENTION PERIOD ]], or until you ask us to delete it |
| Client account and staff contact details | For the length of the engagement |
| Client business data (Stripe, QuickBooks, HubSpot, Google Sheets) | For the length of the engagement, deleted or returned within [[ RETENTION PERIOD ]] of it ending |
| Customer data an automation creates (call recordings, transcripts, messages, bookings, reviews) | [[ RETENTION PERIOD ]], or the client's own retention setting where we offer one |
| Server logs | [[ RETENTION PERIOD ]], set by [[ HOSTING PROVIDER AND REGION ]] |
| Marketing email list | Until you unsubscribe, or [[ RETENTION PERIOD ]] of inactivity |
When an engagement with a client ends, we delete or return their data within [[ RETENTION PERIOD ]].
Security
- Data is encrypted in transit (HTTPS, TLS) between your browser, our site and our systems.
- Access to client data and to this site's infrastructure is limited to the people who need it to do their job.
- Multi-factor authentication is required on the accounts that hold client data.
- Where a client connects their own Google Sheet, the underlying data stays in the client's own Google account. We work with it through the access they grant, not a separate copy we hold by default.
If something goes wrong
If we discover a personal data breach, we tell the people affected and, where the law requires it, the relevant regulator, as fast as we reasonably can. Under the GDPR that means notifying the supervisory authority within 72 hours of becoming aware, where the breach is likely to be a risk to people. The UAE, Saudi Arabia and US state laws each set their own timelines; we follow whichever applies to the data and the people involved.
Your rights
Europe and the UK
Under the GDPR and the UK GDPR, you can ask us to:
- give you access to the personal data we hold about you
- correct it if it's wrong
- delete it
- restrict how we use it
- object to us using it
- give it to you, or someone else, in a portable format
- let you withdraw consent at any time, where consent is the basis we're relying on
You can also complain to your national supervisory authority.
United States
Most US states with a comprehensive privacy law give you the right to:
- know what we collect about you
- access it
- delete it
- correct it
- get it in a portable format
- opt out of sale, sharing, and targeted advertising
- limit the use of sensitive personal information
- not be retaliated against for exercising any of these rights
We do not sell or share personal information, and we do not use it for cross-context behavioural advertising. We honour the Global Privacy Control browser signal as an opt-out request where it applies.
If we refuse a request, you can appeal: write to [[ PRIVACY EMAIL ]] and say so. You can also use an authorised agent to make a request on your behalf.
About twenty US states now have a comprehensive privacy law, with Indiana, Kentucky and Rhode Island taking effect on 1 January 2026. Rather than work out which state applies to you, we apply the same rights to everyone in the US.
The Gulf
The UAE PDPL and the Saudi PDPL give broadly similar rights: to be informed, to access your data, to have it corrected or deleted, and to object to certain processing. If you're a client in the DIFC or ADGM free zones, their own data protection regimes may also apply to you.
Making a request
Write to [[ PRIVACY EMAIL ]]. We may ask for information to verify it's really you asking. We aim to respond within one month under the GDPR and UK GDPR, and within 45 days under US state rules; where another region's law sets a different deadline, we follow that one.
AI, call recording and automated decisions
- Voice AI answers missed calls for clients. Anyone who reaches it is told they're speaking to an assistant, not a person.
- Calls handled by the Voice AI are recorded and transcribed so the automation can work and so the client can review what happened. [[ VOICE AI PROVIDER ]] processes the audio. Recordings and transcripts are kept for [[ RETENTION PERIOD ]] and are accessible to the client and to the people on our side who support their account.
- WhatsApp, DM and other message automations similarly log the conversation so it can be followed up and reviewed.
Recording and messaging consent rules differ by region. Several US states require every party's consent before a call can be recorded. Europe requires a lawful basis and a clear notice at the point of the call. The UAE and Saudi Arabia have their own rules on recording and consent. The client's customers are the client's, so the client is responsible for giving them the right notice; we help set that notice up as part of the automation.
We do not use client data to train any AI model. [[ MODEL PROVIDER ]]'s terms back this; we'll name the specific commitment here once the provider and terms are confirmed.
No automated system makes a decision with a legal or similarly significant effect about anyone on its own. A missed-call booking or a lead reply drafted by AI still runs through the client's own process; nothing life-changing is decided by a machine acting alone.
Marketing
We send email about our own services to people who've asked to hear from us, or who are already talking to us about a project. Every email has a one-click unsubscribe. We follow the marketing rules of the recipient's own country, including opt-in requirements where they apply.
Children
Vartha is a business service, not aimed at anyone under 18. We don't knowingly collect personal data from children, and if we learn we have, we'll delete it.
For our clients: how we handle your data
- A data processing agreement is available and forms part of our contract with you.
- We act only on your documented instructions.
- The sub-processors we use are listed above; we tell you before adding a new one.
- When the engagement ends, we delete or return your data within [[ RETENTION PERIOD ]].
- If one of your customers contacts us directly about their data, we pass the request to you rather than act on it ourselves, since you're the controller for it.
- Access to your account, on our side, is limited to the people who work on it.
Changes
If we change this notice in a way that matters, we'll update the date at the top and, for significant changes, tell clients directly.
| Date | Change |
|---|---|
| [[ EFFECTIVE DATE ]] | First published. |