VARTHABack to home

Legal

Privacy

How we collect, use and protect personal data: for people who visit this site, and for the clients whose business data we run dashboards and automations on.

Last updated [[ EFFECTIVE DATE ]]

Short version

Contents

Who we are

Vartha is [[ LEGAL ENTITY NAME ]], registered in India at [[ REGISTERED ADDRESS ]], registration number [[ REGISTRATION NUMBER ]]. We're an India-based agency selling business intelligence and automation to owner-run businesses in the United States, Europe (the EU and the UK) and the Middle East (the UAE, Saudi Arabia and the wider Gulf).

For anything to do with privacy, write to [[ PRIVACY EMAIL ]]. That inbox reaches the people responsible for this notice.

A company outside the EU and UK that offers services to people there usually has to appoint a local representative. We haven't appointed one yet: [[ EU ARTICLE 27 REPRESENTATIVE ]] for the EU under Article 27 of the GDPR, and [[ UK REPRESENTATIVE ]] for the UK under the UK GDPR. Both are in progress.

Scope and our two roles

This notice covers two different relationships, and different sections apply to each.

When we're the controller

If you visit this site, book a call, or email us, we decide why and how that data is used. We're the controller for that data. The sections on cookies, your rights and marketing mostly concern this relationship.

When we're the processor

If you're a client, you decide why and how your business data and your customers' data are used, and we act on your instructions. We're the processor. Your Stripe, QuickBooks, HubSpot and Google Sheets data, and the data our automations create about your customers (calls, messages, bookings, reviews), fall here. The section “For our clients: how we handle your data” covers this specifically. Security, sub-processors, international transfers and retention apply to both roles.

What we collect

The first three tables are about people we deal with directly, where we're the controller. The last is about client systems we process on a client's instructions, where we're the processor.

Site visitors

People who book a call or email us

Client staff

Personal data inside a client's systems, that we process for them

Cookies, storage and tracking

This site sets no non-essential cookies, runs no third-party analytics, and uses no ad or tracking pixels. Fonts and video are served from our own server, not from Google Fonts, YouTube, Vimeo or similar.

Anything set today

We link out to our booking tool rather than embedding it on this page, so its scripts and cookies don't load until you choose to leave this site and use it.

If that changes

  • Non-essential cookies and analytics load only after you opt in.
  • Refusing is as easy as accepting.
  • Nothing is pre-ticked.
  • You can withdraw consent at any time from a link in the footer.
  • No content is held hostage behind consent: the site works the same either way.

The CookieSettings component in the code is already in place for this. It renders nothing today, because there's nothing to configure.

Who we share data with

We're not necessarily using every provider in that table yet; some rows are placeholders for services we expect to add. We'll update this table, and tell clients directly, before we add a new sub-processor that touches their data.

International transfers

We operate from India. Our clients, and their customers, are mostly in the United States, Europe (the EU and UK) and the Gulf (the UAE, Saudi Arabia and neighbouring countries). Personal data often crosses borders as a result.

  • From the EU or UK to India: we rely on the EU Standard Contractual Clauses, and the UK's International Data Transfer Addendum or an equivalent IDTA, backed by a transfer impact assessment. We're not aware of any adequacy decision covering India, and we don't claim one.
  • From the UAE: transfers follow the UAE PDPL's rules on cross-border transfer, which generally call for an adequate level of protection at the destination, standard contractual clauses, or the individual's consent.
  • From Saudi Arabia: transfers follow the Saudi PDPL, which sets its own conditions for sending personal data outside the Kingdom, including regulator approval in some cases.
  • If a client needs their data to stay in a particular region, we can discuss hosting it there.

The underlying transfer paperwork (the SCCs, the UK addendum, and the transfer impact assessment) is in progress and isn't all signed yet.

How long we keep things

When an engagement with a client ends, we delete or return their data within [[ RETENTION PERIOD ]].

Security

  • Data is encrypted in transit (HTTPS, TLS) between your browser, our site and our systems.
  • Access to client data and to this site's infrastructure is limited to the people who need it to do their job.
  • Multi-factor authentication is required on the accounts that hold client data.
  • Where a client connects their own Google Sheet, the underlying data stays in the client's own Google account. We work with it through the access they grant, not a separate copy we hold by default.

If something goes wrong

If we discover a personal data breach, we tell the people affected and, where the law requires it, the relevant regulator, as fast as we reasonably can. Under the GDPR that means notifying the supervisory authority within 72 hours of becoming aware, where the breach is likely to be a risk to people. The UAE, Saudi Arabia and US state laws each set their own timelines; we follow whichever applies to the data and the people involved.

Your rights

Europe and the UK

Under the GDPR and the UK GDPR, you can ask us to:

  • give you access to the personal data we hold about you
  • correct it if it's wrong
  • delete it
  • restrict how we use it
  • object to us using it
  • give it to you, or someone else, in a portable format
  • let you withdraw consent at any time, where consent is the basis we're relying on

You can also complain to your national supervisory authority.

United States

Most US states with a comprehensive privacy law give you the right to:

  • know what we collect about you
  • access it
  • delete it
  • correct it
  • get it in a portable format
  • opt out of sale, sharing, and targeted advertising
  • limit the use of sensitive personal information
  • not be retaliated against for exercising any of these rights

We do not sell or share personal information, and we do not use it for cross-context behavioural advertising. We honour the Global Privacy Control browser signal as an opt-out request where it applies.

If we refuse a request, you can appeal: write to [[ PRIVACY EMAIL ]] and say so. You can also use an authorised agent to make a request on your behalf.

About twenty US states now have a comprehensive privacy law, with Indiana, Kentucky and Rhode Island taking effect on 1 January 2026. Rather than work out which state applies to you, we apply the same rights to everyone in the US.

The Gulf

The UAE PDPL and the Saudi PDPL give broadly similar rights: to be informed, to access your data, to have it corrected or deleted, and to object to certain processing. If you're a client in the DIFC or ADGM free zones, their own data protection regimes may also apply to you.

Making a request

Write to [[ PRIVACY EMAIL ]]. We may ask for information to verify it's really you asking. We aim to respond within one month under the GDPR and UK GDPR, and within 45 days under US state rules; where another region's law sets a different deadline, we follow that one.

AI, call recording and automated decisions

  • Voice AI answers missed calls for clients. Anyone who reaches it is told they're speaking to an assistant, not a person.
  • Calls handled by the Voice AI are recorded and transcribed so the automation can work and so the client can review what happened. [[ VOICE AI PROVIDER ]] processes the audio. Recordings and transcripts are kept for [[ RETENTION PERIOD ]] and are accessible to the client and to the people on our side who support their account.
  • WhatsApp, DM and other message automations similarly log the conversation so it can be followed up and reviewed.

Recording and messaging consent rules differ by region. Several US states require every party's consent before a call can be recorded. Europe requires a lawful basis and a clear notice at the point of the call. The UAE and Saudi Arabia have their own rules on recording and consent. The client's customers are the client's, so the client is responsible for giving them the right notice; we help set that notice up as part of the automation.

We do not use client data to train any AI model. [[ MODEL PROVIDER ]]'s terms back this; we'll name the specific commitment here once the provider and terms are confirmed.

No automated system makes a decision with a legal or similarly significant effect about anyone on its own. A missed-call booking or a lead reply drafted by AI still runs through the client's own process; nothing life-changing is decided by a machine acting alone.

Marketing

We send email about our own services to people who've asked to hear from us, or who are already talking to us about a project. Every email has a one-click unsubscribe. We follow the marketing rules of the recipient's own country, including opt-in requirements where they apply.

Children

Vartha is a business service, not aimed at anyone under 18. We don't knowingly collect personal data from children, and if we learn we have, we'll delete it.

For our clients: how we handle your data

  • A data processing agreement is available and forms part of our contract with you.
  • We act only on your documented instructions.
  • The sub-processors we use are listed above; we tell you before adding a new one.
  • When the engagement ends, we delete or return your data within [[ RETENTION PERIOD ]].
  • If one of your customers contacts us directly about their data, we pass the request to you rather than act on it ourselves, since you're the controller for it.
  • Access to your account, on our side, is limited to the people who work on it.

Changes

If we change this notice in a way that matters, we'll update the date at the top and, for significant changes, tell clients directly.

Back to top