Legal β€” GDPR & CCPA Compliant

Privacy Policy

Veztraa Solutions ("Veztraa," "we," "us," or "our") is committed to protecting the privacy and security of your personal data. This Privacy Policy is designed in accordance with the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), and the information security principles of ISO/IEC 27001.

Questions about this policy? Contact our Data Protection team at inquiry@veztraa.com

This Privacy Policy explains how Veztraa Solutions, a company incorporated in India ("Veztraa," "we," "us," or "our"), collects, uses, discloses, and safeguards personal data when you visit veztraa.com, engage our software development and consulting services, or otherwise interact with us (collectively, the "Services"). It also describes the rights available to you under applicable data protection laws, including the GDPR, UK GDPR, and the CCPA/CPRA.

By accessing or using the Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with its terms, please discontinue use of the Services. This policy does not apply to the information practices of third parties we do not own or control, including third-party websites, services, or applications you may access through our Services.

1. Data We Collect

We collect personal data in the following categories:

Identity & Contact Data

Name, job title, company name, email address, and phone number β€” provided when you complete a contact form, request a consultation, or subscribe to our communications.

Usage & Technical Data

IP address, browser and device type, operating system, referring URLs, pages viewed, and timestamps β€” collected automatically via cookies and server logs when you visit our website.

Client & Project Data

Billing information, project-related communications, and access credentials necessary to deliver services where you engage us as a client.

2. Legal Basis & How We Use Your Data

We process personal data only where we have a valid legal basis under the GDPR:

Performance of a Contract

To deliver the products or services you request, including responding to inquiries and fulfilling client engagements.

Legitimate Interests

To improve our website, prevent fraud, and market our services in a manner that does not override your rights.

Legal Obligation

To comply with applicable law, such as tax, accounting, and regulatory requirements.

Consent

Where you have given consent, for example for marketing communications or non-essential cookies β€” which you may withdraw at any time.

3. Data Sharing & Third Parties

We do not sell your personal data. We may share personal data with: (a) vetted sub-processors and service providers who support our operations (e.g., cloud hosting, analytics, email delivery, payment processing, customer support tooling), each bound by written data processing agreements consistent with GDPR Article 28; (b) professional advisors such as legal, accounting, and insurance providers; (c) regulators, law enforcement, or courts where required by law or to protect our legal rights; and (d) a successor entity in the event of a merger, acquisition, or asset sale, subject to equivalent privacy protections. A current list of our key sub-processors is available on request to inquiry@veztraa.com.

4. International Data Transfers

As a global software development company headquartered in India with clients and infrastructure providers across multiple jurisdictions, your personal data may be transferred to, stored, and processed in countries other than your country of residence, including India, the United States, and countries within the European Economic Area. Where we transfer personal data of individuals in the EEA, UK, or Switzerland to a country not deemed to provide an adequate level of protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, supplementary technical and organizational measures.

5. Cookies & Tracking Technologies

We use cookies, web beacons, and similar tracking technologies to operate our website, remember your preferences, analyze site traffic, and, where you consent, deliver personalized content. Strictly necessary cookies do not require consent; analytics and marketing cookies are only set with your consent, which you can grant, withdraw, or manage at any time via our cookie banner or your browser settings. For EEA and UK visitors, we operate on an opt-in consent model consistent with the ePrivacy Directive and GDPR.

6. Data Retention

We retain personal data only for as long as reasonably necessary to fulfil the purposes described in this Privacy Policy, including satisfying any legal, accounting, contractual, or reporting requirements. As a general rule, inquiry and marketing data is retained for up to 24 months from your last interaction with us, client engagement records are retained for the duration of the contractual relationship plus any period required by applicable law (typically up to 7 years for financial and tax records), and website analytics data is retained per our analytics provider's default retention settings. When retention is no longer necessary, we securely delete or anonymize the data.

7. Data Security

Veztraa Solutions maintains an Information Security Management System (ISMS) certified to ISO/IEC 27001, the international standard for information security management. Our safeguards include encryption of data in transit and at rest, role-based access controls, regular vulnerability assessments, employee security awareness training, and documented incident response procedures. While we take security seriously and apply industry-recognized controls, no method of electronic transmission or storage is 100% secure, and we cannot guarantee the absolute security of any information you transmit to us.

8. Children's Privacy

Our Services are not directed to, and we do not knowingly collect personal data from, children under the age of 16 (or the applicable age of digital consent in your jurisdiction), and in no case from children under 13 within the meaning of the U.S. Children's Online Privacy Protection Act (COPPA). If we become aware that we have inadvertently collected personal data from a child without appropriate parental or guardian consent, we will take reasonable steps to delete that information promptly. Parents or guardians who believe their child has provided us with personal data should contact us at inquiry@veztraa.com.

9. Your Rights Under GDPR

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the right to:

Right to Access

Request access to the personal data we hold about you.

Right to Rectification

Request correction of inaccurate or incomplete data.

Right to Erasure

Request deletion of your data ("right to be forgotten").

Right to Restrict Processing

Request that we limit how we use your data.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Right to Data Portability

Request a copy of your data in a portable, machine-readable format.

Right to Withdraw Consent

Withdraw consent at any time without affecting prior lawful processing.

Right to Lodge a Complaint

File a complaint with your local data protection supervisory authority.

10. California Privacy Rights (CCPA/CPRA)

Under the California Consumer Privacy Act, as amended by the CPRA, California residents have the right to:

Right to Know

Know what personal information we collect, use, disclose, and sell or share.

Right to Access

Request access to and a copy of your personal information.

Right to Delete

Request deletion of your personal information.

Right to Correct

Request correction of inaccurate personal information.

Right to Opt-Out

Opt out of the sale or sharing of personal information (Veztraa does not sell or share personal information for cross-context behavioral advertising).

Right to Limit Sensitive Data Use

Limit the use and disclosure of sensitive personal information.

Right to Non-Discrimination

Not be discriminated against for exercising any of these rights.

11. Do-Not-Track & Global Privacy Control

Some browsers offer a "Do Not Track" (DNT) signal; because no uniform industry standard for DNT currently exists, we do not respond to DNT signals at this time. Where legally required, we do honor the Global Privacy Control (GPC) as a valid method for California residents to opt out of the sale or sharing of personal information. We will update this policy if a common industry standard for DNT is adopted.

12. Data Breach Notification

We maintain documented incident response procedures aligned with ISO/IEC 27001 to detect, contain, and remediate security incidents. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours where required under GDPR Article 33, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights, in accordance with applicable law.

13. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices, technologies, legal requirements, or other factors. The "Last Updated" date at the top of this page indicates when this notice was last revised. Material changes will be communicated via a prominent notice on our website or, where appropriate, by direct email. We encourage you to review this notice periodically.

14. Contact Us

For any questions, concerns, or requests regarding this Privacy Policy or your personal data, you may contact us by email at inquiry@veztraa.com or by post at: Veztraa Solutions, IT Tower 3, Gate 1 Road, Infocity, Near IT Tower 1, Gandhinagar, Gujarat 382007, India.

inquiry@veztraa.com

15. Exercising Your Rights

You may submit a request to review, correct, update, or delete your personal data at any time by emailing inquiry@veztraa.com or using our online contact form. We will respond to verified requests within the timeframe required by applicable law and, where a request cannot be fulfilled β€” for example, where data must be retained for legal compliance β€” we will explain the basis for our decision.