We use essential cookies to run this site, and optional analytics cookies to understand how it's used. We only load analytics after you accept. See our Cookie Policy for details.

GDPR Notice

GDPR compliance at Vistaaraihub

GDPR roles, rights, lawful bases, transfers, and processor practices.

1. Purpose

This GDPR Notice explains how Vistaaraihub approaches personal data under the EU General Data Protection Regulation and UK GDPR where those laws apply. It supplements our Privacy Policy.

2. Roles

For account, billing, website, and direct customer relationship data, Vistaaraihub generally acts as a controller. For lead records, CRM data, WhatsApp messages, call transcripts, chatbot messages, and similar customer-controlled data processed inside a workspace, Vistaaraihub generally acts as a processor or service provider acting on the customer's instructions.

3. Legal Bases

  • Contract performance to provide accounts, subscriptions, support, and platform features.
  • Legitimate interests for security, fraud prevention, product improvement, business communications, and service analytics.
  • Consent where required for cookies, marketing communications, or specific optional features.
  • Legal obligation for tax, accounting, lawful requests, and compliance requirements.

4. Data Subject Rights

Where GDPR applies, individuals may have rights to be informed, access personal data, request rectification, request erasure, restrict processing, object to processing, request portability, and avoid certain solely automated decisions. Requests may be submitted through the contact method listed in this document.

5. Customer-Controlled Lead Data

If an individual is a lead, prospect, website visitor, or customer of one of our business customers, that business is usually the controller of the data. We may direct the individual to that customer or process the request according to the customer's documented instructions.

6. International Transfers

Where personal data is transferred outside the EEA, UK, or Switzerland, we rely on appropriate safeguards such as contractual protections, data processing terms, technical security controls, and provider transfer mechanisms where applicable.

7. Subprocessors

We may use subprocessors for hosting, databases, communications, email, payments, security, analytics, AI processing, support, and monitoring. Customers should review connected third-party services and ensure they are suitable for their compliance needs.

8. Security and Breach Handling

We use reasonable security controls and will assist customers with security incident assessment where required. If a personal data breach affects GDPR-covered data, notices will be handled according to applicable law and the relevant customer relationship.

9. Automated Processing and AI

Our AI features may produce drafts, summaries, scoring suggestions, transcripts, and recommendations. These outputs are assistive and should not be used as the sole basis for decisions with legal or similarly significant effects without meaningful human review.

10. Product Data Map

AI Sales Agent data may include lead records, outreach history, WhatsApp messages, emails, appointment data, scores, summaries, and handoff notes. AI Chatbot data may include visitor messages, knowledge-base responses, widget settings, captured lead fields, and site configuration. AI CRM data may include contacts, accounts, deals, tasks, activities, reports, automations, and team assignments. AI Calling Agent data may include phone numbers, provider call IDs, recordings or links, call transcripts, summaries, outcomes, and CRM updates.

11. Controller Instructions and Deletion

For customer-controlled data, Vistaaraihub processes information according to the customer's instructions through the product interface, support requests, API calls, and written directions. If a customer deletes records or requests deletion, we will take reasonable steps to remove active records, subject to backup cycles, legal obligations, dispute records, billing logs, and security retention needs.

12. Processor Assistance

Where Vistaaraihub acts as processor, we will provide reasonable assistance for access, deletion, correction, portability, restriction, objection, security incident review, and data protection impact assessment requests, taking into account the nature of the processing and information available to us.

13. AI and Human Review

GDPR-covered customers should not use Vistaaraihub AI scores, summaries, recommendations, or automation as the sole basis for decisions with legal or similarly significant effects on individuals. The products are designed to support human sales, support, and operations teams, not to replace required human judgement.

14. Contact

GDPR requests and questions can be sent to support@vistaaraihub.com or to the registered office address listed below.

VISTAARAI INFOTECH PRIVATE LIMITED · Registered office: 02-007, 2nd Floor, Sector 66, Emar The Palm Square, Bhondsi, Gurgaon - 122102, Haryana, India · CIN: U62099HR2026PTC148294