Last updated: 2026-08-25
This Privacy Policy explains how Vharta.ai Private Limited ("Vharta.ai", "we", "us") collects, uses, shares, and protects personal information when you visit https://vharta.ai, contact us, or use the Vharta.ai platform.
Vharta.ai Private Limited is the data controller for personal information collected through our website and marketing activities. For privacy questions, contact admin@vharta.ai.
When we host and run workflows on behalf of a customer, we act as a data processor for the content that customer submits to the platform. That processing is governed by the agreement and Data Processing Addendum (DPA) between us and the customer, not by this policy.
This policy covers website visitors, prospective customers, people who contact us or request a demo, business contacts whose details we obtain from other sources (see section 3), and authorised users of our platform. It does not cover third-party websites we link to, which have their own policies.
We sometimes add business contact details to our records from sources other than you — for example a list of attendees from an event we took part in, or a business contact directory. Where we do, we record which source each contact came from.
Where the GDPR applies, we rely on the following legal bases:
We use a small number of cookies and similar technologies. Strictly necessary cookies are required for the site to function. Analytics cookies are set only after you consent through our cookie banner, and you can change or withdraw your choice at any time. We do not use third-party advertising cookies.
If you request a demo or contact us, a member of our team may reply by email from their own Vharta.ai mailbox, using their ordinary mail software. These are one-to-one business replies written by a person, not marketing campaigns, and we do not operate a bulk mailing system.
To understand which of our materials are useful to you, a link to vharta.ai that we include in such an email may be routed through a redirect on our own domain, so we can record that the link was clicked and which pages you then viewed on our website. We create these links; the email itself is written by a colleague in their own mail software, so we ask them to say when a link is tracked. Specifically:
Legal bases. The click redirect itself is server-side and does not read or write anything on your device; where the UK/EU GDPR applies we rely on our legitimate interest in responding to your enquiry effectively and understanding which information helps. The page views you make on our website afterwards are recorded by our analytics, which runs only if you have accepted analytics cookies— see section 5. Where India's Digital Personal Data Protection Act, 2023 applies, we rely on your consent, since that Act does not provide a legitimate-interest basis for this processing. In that case the notice in the email itself is what asks for it, and choosing to follow the link is the consent — which is why we require that notice to be included whenever a tracked link is created.
We ask our team to say so in any email carrying such a link. You can ask us to stop at any time — simply reply to the email or write to admin@vharta.ai. We will record that objection against your enquiry so it applies to everyone on our team and to any future email, and if you ask, delete the click history we hold about you. Copies of emails already sent also exist in our team's mailboxes; tell us if you want those removed too and we will do so.
We do not sell personal information. We share it only with:
A current list of subprocessors is available to customers on request at admin@vharta.ai.
We are based in India and may process personal information in India and in other countries where we or our service providers operate. Where we transfer personal data internationally, we put appropriate safeguards in place, such as standard contractual clauses, as required by applicable law.
We retain personal information only as long as necessary for the purposes described here, to comply with our legal obligations, resolve disputes, and enforce our agreements, after which we delete or anonymise it. In particular:
We apply technical and organisational measures appropriate to the risk, including encryption in transit, access controls, and audit logging. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Subject to applicable law, including the EU/UK GDPR and India’s Digital Personal Data Protection Act, 2023 (DPDP Act), you may have the right to access, correct, update, or delete your personal data; to restrict or object to processing; to data portability; to withdraw consent; and to lodge a complaint with a supervisory authority or the Data Protection Board of India. To exercise these rights, contact admin@vharta.ai. We will respond within the timeframes required by applicable law.
Our website and platform are intended for businesses and are not directed to children. We do not knowingly collect personal information from individuals under the age of 18.
We may update this policy from time to time. We will revise the “Last updated” date above and, where appropriate, provide additional notice.
Vharta.ai Private LimitedPrivacy and grievance contact: admin@vharta.ai
This policy reflects our current data practices and is reviewed periodically. Enterprise customers can request our Data Processing Addendum and subprocessor list.