Privacy Policy
1. Scope and applicability
This Privacy Policy applies to all personal data processed by Vansera in connection with:
- visits to and interactions with the website at
https://vansera.inand any subdomain we operate; - the interactive browser-based AI voice demonstration on our homepage;
- inbound and outbound voice calls routed through Vansera-operated phone numbers (currently
09513886363through Exotel Techcom Pvt. Ltd. and Twilio Inc. international DIDs); - inbound and outbound WhatsApp messages handled by Vansera-operated WhatsApp numbers (currently routed through Twilio Inc. / WhatsApp Business Platform);
- the administrator portal at
/adminused by Vansera personnel to monitor service health and resolve issues; - reservation, modification and cancellation transactions captured by the Service on behalf of Client Establishments;
- automated WhatsApp confirmation, reminder and feedback messages we send under Client Establishment instruction;
- technical telemetry generated by our infrastructure (server logs, rate-limit records, error traces) for security, abuse-prevention and operational continuity.
It does not apply to: the in-restaurant experience at any Client Establishment, third-party websites we link to, or personal data you provide directly to a Client Establishment by walking in, calling a non-Vansera number, or messaging a non-Vansera WhatsApp number. Those are governed by the Client Establishment's own privacy practices.
2. Definitions
We use defined terms from the DPDP Act so that this notice is interpretable in legal proceedings. For clarity:
- Personal Data — any data about an individual who is identifiable by or in relation to such data.
- Data Fiduciary — the person who, alone or with others, determines the purpose and means of processing of personal data. For data described in Section 4(a)–(c), (g) and (h) of this notice, Vansera is the Data Fiduciary.
- Data Processor — a person who processes personal data on behalf of a Data Fiduciary. For data described in Section 4(d)–(f) below (booking records held on a Client Establishment's behalf), Vansera acts as Data Processor and the Client Establishment is the Data Fiduciary.
- Data Principal — the individual to whom the personal data relates. If you are calling, messaging, or visiting our site, you are the Data Principal.
- Significant Data Fiduciary — a Data Fiduciary the Central Government notifies as significant on volume/sensitivity criteria under Section 10 of the DPDP Act. Vansera does not presently qualify; we will update this notice and adopt the additional Section 10 obligations if and when notified.
- Service — the Vansera AI receptionist platform in all its forms, including voice, WhatsApp, browser demo and administrator portal.
- Sub-processor — a third party that processes personal data on Vansera's instructions in order to deliver the Service (full list in Section 8).
- Client Establishment — a restaurant, cafe or other hospitality business that subscribes to Vansera and on whose behalf the Service interacts with you.
3. Who we are — identity of the Data Fiduciary
Udyam Registration Number: UDYAM-TS-02-0027127
Registered office: Flat 002, Vishnu Towers, Somajiguda, Hyderabad, Telangana – 500082, India
Service contact: contact@vansera.in
Founders: Vanshraj Gupta (Founder & CEO) and Sujay Kandi (Co-CEO & Co-Founder)
Throughout this notice, "Vansera", "we", "us" and "our" refer to the entity above. References to "you" or "the Data Principal" mean the individual whose personal data is being processed.
4. Categories of personal data we process
We have organised every category of personal data we touch into a single table. We do not process any category not listed below. Where the source column says "you", the data came directly from the Data Principal; where it says "Client Establishment", the data was provided by the cafe (for example when they imported an existing reservation book during onboarding); where it says "system", the data was generated by Vansera's infrastructure.
| Ref | Category | Examples of fields | Source | Vansera's role |
|---|---|---|---|---|
| 4(a) | Voice audio (transient) | Raw microphone audio streamed during a phone call or browser demo conversation. | You | Data Fiduciary (for the duration of transit). Audio is processed in real time; we do not retain audio recordings as files once the call ends. |
| 4(b) | Conversation transcripts | Text transcription of what you said and what the AI replied. Stored as a JSON file per call in call_logs/<call_id>.json on our server and linked to a row in the calls table of our database. |
You (via Deepgram speech-to-text) | Data Fiduciary. We use transcripts to enable in-call context, post-call quality review, dispute resolution and abuse detection. |
| 4(c) | Call metadata | Call identifier, channel ("voice"/"browser"/"whatsapp"/"exotel"), start timestamp, end timestamp, duration in seconds, outcome ("completed"/"error"/"in_progress"), associated client identifier. | System | Data Fiduciary. |
| 4(d) | Reservation details | Customer name as spoken or typed; phone number in E.164 form (+91xxxxxxxxxx); reservation date and time; party size; special requests/notes; booking source label. | You | Data Processor on behalf of the Client Establishment. Vansera holds a copy in SQLite (data/agency.db, bookings table) for service operation; the canonical record is the Client Establishment's own Google Sheet. |
| 4(e) | Confirmation identifier | A six-character alphanumeric code (e.g. VAN-A1B2C3) prefixed with the Client Establishment's identifier. |
System | Data Processor. |
| 4(f) | Feedback responses | A numeric rating from 1 to 5 you send by WhatsApp after your visit; optional free-text comment; the timestamp of the feedback message. | You | Data Processor. |
| 4(g) | WhatsApp message content | Inbound message body, outbound message body, sender phone number, recipient phone number, message timestamp, delivery status, WhatsApp message SID issued by Twilio. | You + system | Data Fiduciary for content used in service operation; Data Processor for booking-specific fields routed to the Client Establishment. |
| 4(h) | Technical telemetry | Source IP address; user agent string; HTTP request method and path; HTTP response status code; latency; rate-limit hits; error stack traces; webhook signatures verified or rejected; session identifiers (32-character hex tokens we issue to bind a browser demo conversation). | System | Data Fiduciary. Used solely for security, abuse prevention, rate-limit enforcement and operational diagnostics. |
| 4(i) | Administrator credentials | For Vansera personnel only: a username-less password authentication credential and an HMAC-signed session cookie (vansera_admin) with seven-day expiry. End Users do not have administrator accounts. |
Vansera personnel | Data Fiduciary. |
We do not collect, by any channel: Aadhaar or other government identifiers; PAN; voter ID; biometric templates; voice prints used for identification; financial account numbers, credit card numbers, CVVs or UPI handles; location data of any kind (GPS, Wi-Fi or cell-tower); device contact lists, photos or calendars; health, medical or insurance information; sexual orientation or sex life; political opinions, religious beliefs, caste or community; criminal records or pendency of proceedings; trade-union membership; or any data of any individual we have actual knowledge is below 18 years of age. If you transmit any such information to us inadvertently (for example by reading a card number aloud over the phone), we will redact it from transcripts upon detection and will not retain it.
5. How we collect personal data (channels of collection)
| Channel | How data reaches us |
|---|---|
| Voice call to an Exotel-routed Indian number | Audio arrives over Exotel's media stream into our Pipecat pipeline; Deepgram transcribes; Groq Llama 3.3 70B produces a response; Sarvam AI Bulbul v3 generates speech; the audio returns to you through Exotel. |
| Voice call to a Twilio-routed international number | Same as above, with Twilio in place of Exotel as the carrier. |
| Browser-based demonstration on vansera.in | Your browser captures microphone audio after you click the call button and grant microphone permission; the audio is POSTed to /api/turn; Deepgram transcribes; Groq responds; Sarvam returns audio; the audio plays back through your browser speakers. |
| Inbound WhatsApp to a Vansera-operated WhatsApp number | Twilio delivers the message body and your phone number to our /whatsapp/incoming webhook; we verify a Twilio HMAC signature; the message is handled by our WhatsApp agent. |
| Outbound WhatsApp from Vansera to you | We instruct Twilio to send a confirmation, reminder or feedback message containing only the fields necessary for that purpose. |
| Imports from a Client Establishment during onboarding | Where a Client Establishment uploads pre-existing reservation records into the Service, those records are processed by us strictly as Data Processor under the Client Establishment's instructions. The Client Establishment is responsible for having lawful basis to share those records. |
| Visits to vansera.in | Standard HTTP request data captured in our server logs and an essential session cookie set when you log in to the administrator portal (if you are Vansera personnel). |
6. Purposes for which we process your personal data
We process personal data only for the purposes set out below, and only to the extent necessary for each purpose:
- to provide the Service — that is, to enable the AI agent to converse with you, take, modify or cancel a reservation, answer your question about a Client Establishment's menu, opening hours, address or policies, and to confirm and remind you of your reservation;
- to notify the relevant Client Establishment's owner of each new, modified or cancelled booking, by means of an automated WhatsApp message from us to a single number that the Client Establishment has configured;
- to send confirmation, reminder (24-hour and 2-hour) and feedback messages on behalf of the Client Establishment, where you have provided a phone number for that purpose;
- to detect, prevent and investigate fraud, abuse, security incidents and excessive or anomalous use;
- to enforce per-IP rate limits and reject unsigned webhook payloads;
- to maintain operational continuity (backups, error reporting, restoring service after an outage);
- to comply with our obligations under the DPDP Act, the IT Act, the SPDI Rules, the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 ("TRAI TCCCPR"), the Consumer Protection Act, 2019, the Indian Contract Act, 1872, applicable taxation laws and any other applicable Indian law;
- to respond to lawful requests from courts, tribunals, regulators or law-enforcement authorities of competent jurisdiction;
- to enforce our Terms of Service and Acceptable Use Policy and to defend or assert legal claims (whether by us, the Client Establishment, or you).
7. Lawful basis for processing under the DPDP Act
The Digital Personal Data Protection Act, 2023 permits processing on the basis of (a) the Data Principal's consent or (b) certain "legitimate uses" enumerated in Section 7. We rely on each as follows:
- Consent (Section 6). When you place a call to a Vansera-operated number, message a Vansera-operated WhatsApp number or click the demo button on vansera.in, the AI agent discloses that it is an automated assistant and indicates that the conversation will be transcribed and stored for the purposes set out in Section 6 of this notice. Your continued engagement constitutes consent under Section 6 of the DPDP Act. You may withdraw consent at any time by ending the call, replying
STOPon WhatsApp, or writing to contact@vansera.in. Withdrawal does not affect the lawfulness of processing carried out before withdrawal. - Performance of a service requested by you (Section 7(a)). Where you ask the AI to book, modify or cancel a reservation, the processing of your name, phone number and reservation details is necessary to perform the service you have requested.
- Compliance with a legal obligation (Section 7(c)). Where the law requires retention or disclosure (for example, in response to a validly issued summons), we process accordingly.
- Maintaining safety and security (Section 7(i)). Server logs, rate-limit records and webhook signatures are processed under the legitimate use of preventing fraud and ensuring service safety.
We do not rely on any deemed-consent, public-interest or implied-consent ground other than those enumerated above.
8. Sub-processors, recipients and third-party service providers
The following third parties process personal data on Vansera's instructions in order to deliver the Service. Each is bound by its own data-protection commitments. We have selected each on the basis of published documentation of contractual and technical safeguards. We do not sell, license, rent or otherwise commercialise personal data to any party.
| Sub-processor | Role | What we send | Place of processing |
|---|---|---|---|
| Groq, Inc. | Large language model inference (the AI brain — Llama 3.3 70B). | The conversation transcript so far (text only) plus our system prompt. No audio. | United States. Groq's published policy states inputs and outputs are not used to train its models. |
| Deepgram, Inc. | Speech-to-text transcription (Nova-3 model). | Streaming or batched audio of the current utterance. | United States. Per Deepgram's published policy, customer audio is not retained for model training. |
| Sarvam AI (Sarvam AI Foundation Pvt. Ltd.) | Text-to-speech generation (Bulbul v3, "Ishita" voice). | The text of each agent reply. | India. |
| Twilio Inc. | International call routing and WhatsApp Business Platform message delivery. | Audio streams for international calls; WhatsApp message bodies and sender/recipient phone numbers; Twilio MessageSid metadata. | United States; routing through regional points of presence. |
| Exotel Techcom Pvt. Ltd. | Indian voice call routing for 09513886363. |
Audio streams; signalling metadata (caller number, called number, duration). | India. |
| Google LLC (Google Workspace / Google Sheets API) | Per-Client-Establishment booking storage and visualisation. | Booking rows (Booked At, Confirmation ID, Customer Name, Phone, Reservation Date, Reservation Time, Party Size, Notes, Status, Booking Source). | United States. |
| DigitalOcean LLC | Server hosting (single droplet, Bangalore region) and encrypted daily snapshot backups (seven-day rolling). | The whole runtime stack — application code, configuration, SQLite database, call-log JSON, server logs — lives on a DigitalOcean droplet. | Bangalore, India. |
GoDaddy Inc. / Registrant of vansera.in |
Domain registration and email forwarding for contact@vansera.in. |
WHOIS contact data; email message content addressed to or from contact@vansera.in. |
United States. |
| GitHub, Inc. (Microsoft) | Source-code hosting (private repository at github.com/Vansera-ai/vansera). No personal data of End Users is ever pushed to GitHub. The .gitignore excludes .env, credentials, the SQLite database, call logs and any folder containing customer data. |
United States. |
Where we add or replace a sub-processor in a way that materially changes how your personal data is processed, we will update this Section 8 and post a notice on the home page at least thirty (30) days before the change takes effect, unless the change is required by law or by a security incident in which case we will update as soon as practicable.
9. Cross-border transfers of personal data
Some sub-processors listed in Section 8 are located outside India. Under Section 16 of the DPDP Act, transfers of personal data to a country outside India are permitted unless the Central Government, by notification, restricts such transfer to a specific country. As of the effective date of this notice, the Central Government has not issued any such notification restricting transfers to the United States, where most of our sub-processors are based.
For each cross-border transfer, we apply the following safeguards:
- all transfers occur over TLS 1.2 or higher in transit;
- each sub-processor has published data-protection commitments which we have reviewed before onboarding;
- we transmit only the minimum data necessary for the sub-processor to perform its role;
- we do not authorise any sub-processor to use the data for training, marketing, profiling or any purpose other than delivering its service to us;
- we will cease transfers to any country, or to any sub-processor in that country, that the Central Government subsequently notifies as restricted.
10. Retention of personal data and method of deletion
| Data category | Retention period | Method of deletion |
|---|---|---|
| Voice audio (4(a)) | Not retained beyond the call. | Discarded from memory once the call ends; no audio file is written to disk. |
| Call/WhatsApp transcripts (4(b)) | Six (6) months from the call end timestamp. | The JSON file in call_logs/ is unlinked; the corresponding row in calls table is purged. Backups remain only until each daily snapshot rolls off (maximum 7 additional days). |
| Call metadata (4(c)) | Six (6) months. | Row purged together with the transcript. |
| Reservation records (4(d), 4(e)) | Until the earlier of: (i) your verified deletion request, (ii) the Client Establishment terminating its subscription (plus 30 days for export), or (iii) such longer period as the Client Establishment instructs us to retain in writing for legitimate business purposes. | Row in bookings table deleted; corresponding row in the Client Establishment's Google Sheet either deleted or anonymised at the Client Establishment's option. |
| Feedback (4(f)) | Twenty-four (24) months or until your verified deletion request, whichever is sooner. | Row purged. |
| WhatsApp message content (4(g)) | Six (6) months for transcript fields; up to twenty-four (24) months for booking-linked confirmation/cancellation message audit trail. | Row purged. |
| Technical telemetry (4(h)) | Thirty (30) days. | Server logs rotated and overwritten. |
| Administrator session cookies (4(i)) | Seven (7) days or until logout. | Cookie expires client-side; no server-side session store. |
| Backup snapshots | Seven (7) days rolling. | DigitalOcean automatically deletes snapshots after seven days. We do not retain snapshots off-platform. |
Retention periods are maxima. We may delete sooner where legitimate business need has ended. Where you exercise your right to erasure under Section 12, we will delete within thirty (30) days of verifying your identity, subject only to retention required by law (for example, for tax-record retention or in response to a litigation hold).
11. Security — technical and organisational measures
We implement the following technical and organisational measures, which we believe satisfy the "reasonable security practices and procedures" required under Section 43A of the IT Act and the SPDI Rules:
- Transport encryption: TLS 1.2 or higher on every public endpoint of
vansera.in; HSTS and security headers enforced at the nginx reverse proxy. - Authentication: the administrator portal is protected by a strong password, an HMAC-SHA256 signed session cookie verified in constant time, and a five-attempts-per-minute brute-force lockout. Cookies carry the
Secure,HttpOnlyandSameSite=Laxflags. - Network exposure: the application server (uvicorn) binds to
127.0.0.1only; all public traffic must traverse nginx, which enforces a defence-in-depth rate-limit ceiling. - Per-endpoint rate limits keyed on the
X-Real-IPheader set by nginx (not the spoofableX-Forwarded-Forleftmost). Limits: 5 requests/minute on the admin login endpoint; 60 requests/minute on AI-cost-sensitive endpoints; 120 requests/minute on telephony webhooks. - Webhook authenticity: every inbound webhook from Twilio is verified using Twilio's published HMAC signature scheme; unsigned or invalid-signature requests are rejected with HTTP 403.
- Input validation: session and client identifiers are validated against fixed regular expressions; password and message bodies are length-capped; request bodies are capped at 5 MB to prevent memory-exhaustion uploads.
- Process isolation: the application runs under a non-privileged systemd unit with
MemoryMax=512M,NoNewPrivileges=yesandProtectSystem=strict, restricting filesystem writes to the data and log directories. - Secret management: API keys, service-account credentials and the admin password live only in a server-local
.envfile and a service-account JSON file. Neither is committed to source control;.gitignorerules have been audited. - Backup: encrypted daily snapshots of the entire droplet are retained for seven days, enabling restoration to any point within that window. Bookings are additionally dual-written to the Client Establishment's own Google Sheet, providing a second copy of the most critical data.
- Documentation hygiene: the auto-generated API documentation endpoints (
/docs,/redoc,/openapi.json) are disabled in production to prevent enumeration of internal endpoints. - Personnel access: only the two named founders have shell access to the production server, and access is gated by an SSH key not stored on any third-party device.
- Test coverage: an automated test suite of 64 checks runs locally before each deployment, including dedicated security tests covering rate limiting, body-size caps, authentication, webhook signature enforcement, and input validation.
No technical or organisational measure can eliminate the risk of a personal-data breach. By using the Service you acknowledge that the controls listed above are reasonable, not absolute.
12. Personal-data breaches — notification commitment
In the event of a personal-data breach as defined in the DPDP Act, we will:
- notify the Data Protection Board of India in the form and within the time period prescribed by the rules made under the DPDP Act;
- notify each affected Data Principal directly, via the most reliable contact information we hold for that individual (typically the WhatsApp number on file for booking purposes), without undue delay and in any event within seventy-two (72) hours of discovery, unless a different timeline is prescribed by law;
- notify each affected Client Establishment within the same period, where booking data they own may have been affected;
- publish a public notice on this page summarising the nature of the breach, the categories of data and the number of Data Principals affected, the remediation taken and the steps Data Principals can take to protect themselves.
13. Your rights as a Data Principal under the DPDP Act
The DPDP Act confers the following rights on you. We honour each without charge and without conditioning your continued use of the Service on whether you have exercised them.
- Right to access information about personal data (Section 11). You may obtain (i) a summary of the personal data we are processing about you, (ii) the activities of processing undertaken with respect to your data, and (iii) the identities of all Data Fiduciaries and Data Processors with whom your data has been shared.
- Right to correction, completion, updation and erasure (Section 12). You may have inaccurate or misleading data corrected, incomplete data completed, outdated data updated, and personal data erased where it is no longer necessary for the purposes for which it was collected.
- Right of grievance redressal (Section 13). You may raise a grievance with the Grievance Officer named in Section 14, who will respond within fourteen (14) days. If you are not satisfied with our response, you may escalate to the Data Protection Board of India.
- Right to nominate (Section 14). You may nominate any other individual to exercise the rights above in the event of your death or incapacity. Nomination instructions may be sent to the Grievance Officer.
- Right to withdraw consent (Section 6(4)–(6)). You may withdraw consent at any time, with the same ease with which it was given. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal, nor does it require us to retain or transfer data that is no longer needed.
How to exercise a right. Email the Grievance Officer at contact@vansera.in with the subject line Data Request — [your phone number]. To enable us to verify that you are the Data Principal (and not a third party trying to obtain your data), we may ask you to confirm a one-time code we send to the phone number on file. We will respond within thirty (30) days of receipt, or earlier where the law requires it. If your request is manifestly unfounded or excessive, we may decline it with reasons or charge a reasonable fee, as permitted by the DPDP Act and the rules made under it.
14. Grievance Officer
Vansera (a unit of M/S. Bhagwati Jewellers)
Address: Flat 002, Vishnu Towers, Somajiguda, Hyderabad, Telangana – 500082, India
Email: contact@vansera.in
Phone: +91 93906 70390
Acknowledgement of grievance: within 48 hours of receipt · Resolution: within 14 days
If, after escalation to the Grievance Officer, your grievance remains unresolved, you may approach the Data Protection Board of India once it is constituted and operational under the DPDP Act, 2023. You may also have a remedy under the Information Technology Act, 2000, the Consumer Protection Act, 2019, or in the civil courts of competent jurisdiction.
15. Automated decision-making and AI disclosure
The Service uses an automated AI system to take and manage your reservation. There is no human intervention in the moment-to-moment conversation. The AI is configured to disclose, when asked or at the start of the interaction, that it is an automated assistant.
We do not use the conversation to make any decision that produces legal effects concerning you or that significantly affects you in a similar way; the AI's decisions are limited to whether a particular booking can be accepted given availability, and whether the conversation can be advanced to the next step. You retain the right to decline interaction with the AI at any time, including by ending the call, replying STOP on WhatsApp, or asking to be transferred to a human (where the relevant Client Establishment has enabled call forwarding for its number).
We do not generate or store voice biometric profiles, voice prints, speaker-identification embeddings or any other biometric template of your voice. The audio of your speech is converted to text in transit and the audio itself is not retained.
16. Children
The Service is intended for adults making restaurant reservations. We do not knowingly process the personal data of any individual we have actual knowledge is below 18 years of age. Where you make a reservation that includes minors as guests, we process only the headcount and any allergy or dietary information you supply; we do not collect minors' names, contact details or any other identifier.
If you become aware that a person below 18 has provided personal data to the Service, please write to the Grievance Officer named in Section 14 and we will promptly delete such data and any related records.
17. Marketing communications and TRAI compliance
We send only transactional and service messages: reservation confirmations, reminders, modifications and feedback requests on behalf of the Client Establishment. We do not send promotional or advertising messages to End Users. Should we ever introduce promotional messaging in future, it will be on an explicit opt-in basis and in compliance with the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018 (TRAI TCCCPR), including registration with a DLT platform where required.
You may stop all messages from a Vansera-operated WhatsApp number at any time by replying STOP to that number; we will cease sending further messages within twenty-four (24) hours.
18. Cookies and similar technologies
The vansera.in marketing website uses only essential first-party cookies necessary to operate the administrator session and to remember consent state where applicable. We do not run third-party analytics, advertising pixels, social-media share trackers or fingerprinting libraries on this domain.
| Cookie | Purpose | Duration | Type |
|---|---|---|---|
vansera_admin | Authenticates an administrator session for Vansera personnel. | 7 days | Essential (HMAC-signed, Secure, HttpOnly, SameSite=Lax) |
19. Lawful interception, court orders and government requests
We will disclose personal data to law-enforcement, regulatory or judicial authorities only where compelled by a validly issued summons, court order, warrant or other legal process under Indian law. Where law permits us to do so, we will notify the affected Data Principal and any affected Client Establishment of the request before disclosure, so that they may pursue any remedies available to them.
20. Independent retention by sub-processors
Some sub-processors retain limited operational metadata about their interaction with us (for example, Twilio retains message-delivery logs for its own audit purposes). Such retention is governed by the sub-processor's own privacy policy. You may obtain a current list of the sub-processors' published privacy commitments from us on request.
21. Changes to this Privacy Policy
We may revise this Policy from time to time. Material revisions — including any change to the categories of data collected, the purposes of processing, retention periods, the list of sub-processors, or the categories of recipients — will be posted on this page with a revised "Effective" date, and where reasonably possible we will provide thirty (30) days' advance notice via the home page. Non-material revisions (typographical, clarifying or formatting) take effect immediately.
Your continued use of the Service after a revision takes effect constitutes acceptance of the revised Policy. Prior versions are available on request.
22. Compliance with other Indian laws
In addition to the DPDP Act, our practices are designed to comply with:
- the Information Technology Act, 2000 (including Section 43A on reasonable security practices and Section 72A on punishment for disclosure of information in breach of lawful contract);
- the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011;
- the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021;
- the Consumer Protection Act, 2019 and the Consumer Protection (E-commerce) Rules, 2020 (to the extent applicable to a service intermediary);
- the Indian Contract Act, 1872 with respect to the formation and performance of contracts between Vansera, Client Establishments and End Users;
- the TRAI Telecom Commercial Communications Customer Preference Regulations, 2018;
- applicable tax laws (Goods and Services Tax Act, 2017, where applicable to invoicing of Client Establishments).
23. Contact
For any privacy-related question, write to contact@vansera.in. For commercial, sales and administrative matters, see the home page. For complaints, please first contact the Grievance Officer in Section 14 above.
This Privacy Policy is provided in good faith and reflects our processing as of the effective date above. It is not a substitute for individual legal advice; if you have rights-based concerns you may also consult an advocate or contact the Data Protection Board of India, the Adjudicating Officer under the IT Act, or the Consumer Disputes Redressal Commission of competent jurisdiction. Please also read our Terms of Service, Acceptable Use Policy and Cookie Policy, which form part of the agreement governing your use of the Service.