1. Introduction
Vyzma AI Private Limited (“Vyzma”, “we”, “us” or “our”) operates the Vyzma.ai website and related pages (collectively, the “Site”). This Privacy Policy explains how we collect, use, share and protect personal data when you visit the Site, contact us, or book a call with us.
By using the Site, you agree to the practices described in this Policy. If you do not agree, please do not use the Site or send us information.
Vyzma builds and operates its own products (currently Agriva and FireOS). Those products have their own privacy notices, which govern data collected inside them. This Policy governs only the Vyzma.ai marketing site and direct engagement channels described below.
2. Scope and Applicable Law
This Policy is published in accordance with the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 (including the Reasonable Security Practices and Sensitive Personal Data Rules, 2011). It applies to visitors and business contacts in India and, to the extent applicable, elsewhere.
3. Information We Collect
The Site is a marketing website. It does not offer user accounts, listings, or user-uploaded content. We collect only what you actively give us or what is generated by ordinary web usage:
- Inquiry data you submit via the contact form or send to us directly — typically your name, work email address, and a short description of what you are trying to build.
- Booking data from calls you schedule via our booking tool (Calendly) — your name, email address, the time you selected, and any notes you added. This data is collected and stored by Calendly on our behalf under their processor terms.
- Communication data — the content of emails, messages or documents you send us in the course of exploring or delivering an engagement.
- Device and usage data generated automatically by your browser — IP address, device / browser type, referring URLs, pages viewed, and interaction events. This is used to understand traffic and improve the Site.
- Cookies and similar technologies — as described in Section 10.
We do not knowingly collect sensitive personal data through the Site. Please do not send us government IDs, financial information, health data or other sensitive data via the inquiry form — if such information is genuinely needed for an engagement, we will collect it through a secure, separately-agreed channel.
4. How We Use Your Information
We process personal data to:
- Respond to your inquiries and coordinate discovery calls;
- Evaluate whether Vyzma is a good fit for your project and, if so, scope and deliver the engagement;
- Send transactional messages related to your inquiry or booking (see Section 8);
- Operate, maintain, secure and improve the Site;
- Detect, investigate and prevent fraud, abuse and security incidents;
- Meet legal, tax, regulatory and audit obligations.
5. AI-Powered Features and Automated Processing
The Vyzma.ai Site itself does not use AI to make decisions about you. AI is central to what Vyzma builds for clients and inside our own products (Agriva, FireOS), and those systems are governed by their own product-specific notices and contracts — not by this Policy.
In the course of a client engagement we may use AI-assisted tools to draft, review, analyse or summarise material you share with us. Where we do:
- We do not use fully automated processing to make decisions that produce legal or similarly significant effects about you.
- AI outputs are assistive and are reviewed by a human before they influence anything material to the engagement.
- We do not submit your confidential material to third-party AI services in a way that would allow it to be used to train those services’ general-purpose models. Where an AI service is involved, we use enterprise / no-training modes or self-hosted models per the engagement’s data-handling terms.
If you believe an AI-generated output about you is materially incorrect, please contact us (Section 20) — we will review it and, where appropriate, provide human review or correction.
6. Legal Basis for Processing
We rely on your consent under the DPDP Act’s Section 6 for most processing, and on legitimate uses recognised under the Act’s Section 7 (such as responding to inquiries you initiated, providing services you have requested, and complying with legal obligations). You can withdraw your consent at any time as described in Section 7 of this Policy below.
7. Consent, Preferences and Consent Managers
Where we rely on your consent under Section 6 of the DPDP Act, we obtain it through clear, affirmative actions — for example, sending us an inquiry, booking a call, or subscribing to updates. Consent for marketing (see Section 8) is separate from consent required to respond to a request you have made.
You can manage your consent and preferences at any time by writing to our Grievance Officer (Section 20). Withdrawing consent is as easy as giving it; the consequences of withdrawal will be limited to the specific processing you have withdrawn.
Once the Data Protection Board of India notifies Consent Managers under Section 6(7) of the DPDP Act, we will integrate with recognised Consent Managers so you can review, grant and withdraw consent across data fiduciaries from a single interface.
8. Marketing Communications
We distinguish between two categories of messages we send:
- Transactional / service messages — required to respond to your inquiry, confirm a booking, or deliver an engagement. You will continue to receive these while our engagement is active.
- Promotional / marketing messages — such as newsletters, case studies or product updates. We only send these where you have opted in. You can opt out at any time by:
- Replying “STOP” to an SMS or WhatsApp message from us;
- Using the “unsubscribe” link at the bottom of any marketing email; or
- Writing to our Grievance Officer (Section 20).
We also honour the Telecom Commercial Communications Customer Preference Regulations, 2018 (TRAI TCCCPR 2018). If you have registered your number on the National Customer Preference Register (NCPR / DND), we will only place promotional voice or SMS communications to you where permitted by that registration and your consent.
9. Sharing and Disclosure
We share personal data only as necessary and never sell it. Recipients may include:
- Service providers who host the Site, deliver email, schedule calls, or provide analytics on our behalf under confidentiality and data-protection obligations (for example, our website host, our email provider, and Calendly for call scheduling).
- Professional advisors — our lawyers, accountants and auditors, where necessary and under professional duties of confidentiality.
- Law-enforcement, regulators or courts when required by law or to protect our rights and the safety of others.
- Successors in the event of a merger, acquisition or corporate restructuring, subject to this Policy.
10. Cookies and Tracking
We use a small number of cookies and similar technologies to remember your preferences, measure how the Site is used and improve your experience. You can control cookies through your browser settings. Disabling certain cookies may affect functionality (for example, embedded Calendly booking).
If we introduce additional analytics or advertising cookies in the future, we will update this Policy and, where required, obtain your consent through an on-page banner before those cookies are set.
11. Data Retention
We retain personal data only as long as needed for the purposes described in this Policy:
- Inquiries that do not turn into an engagement — typically retained for up to 24 months, then deleted or anonymised.
- Active or past engagements — retained for the duration of the engagement and for a reasonable period thereafter to meet contractual, tax and legal obligations.
- Server logs and analytics — retained for shorter operational windows, generally no more than 12 months.
When data is no longer required, we delete or anonymise it.
12. Data Security
We follow reasonable security practices consistent with Rule 8 of the IT (Reasonable Security Practices) Rules, 2011, including encryption in transit (HTTPS), access controls on internal systems, and monitoring. No system can be guaranteed fully secure; please protect your credentials and notify us of any suspected unauthorised access.
13. Data Breach Notification
If we become aware of a personal-data breach, we will act promptly to contain and investigate it, and will notify the Data Protection Board of India and affected individuals in accordance with the DPDP Act and Rule 7 of the DPDP Rules, 2025. Notifications to affected individuals will describe, to the extent known, the nature and likely consequences of the breach, the measures we have taken and the steps you can take to protect yourself. Where required by law, we will also cooperate with sectoral regulators and law-enforcement authorities.
14. Your Rights
Subject to applicable law, you have the right to:
- Access a summary of the personal data we process about you;
- Request correction or erasure of your personal data;
- Withdraw consent for any processing based on consent;
- Nominate an individual to exercise your rights in specified events;
- Raise a grievance with our Grievance Officer (see Section 20).
To exercise any right, please contact us using the details in Section 20. We will respond within the timelines prescribed by law.
15. Your Responsibilities
Section 15 of the DPDP Act requires every Data Principal to comply with certain duties when interacting with us. By using the Site or engaging with us, you agree that you will:
- Provide accurate, complete and truthful information about yourself and your project;
- Not impersonate another person or misrepresent your identity or affiliation;
- Not suppress information that is material to the accuracy of any inquiry or agreement;
- Not raise frivolous or false grievances against us; and
- Furnish only verifiably authentic information when exercising your rights under Section 14.
The DPDP Act provides for financial penalties (up to ₹10,000 per breach) where Data Principal duties are wilfully violated. Compliance with these duties also helps us keep our engagement channels trustworthy for everyone.
16. Children’s Data
The Site and our services are intended for individuals aged 18 or above, typically acting in a professional capacity. We do not knowingly collect personal data from children. Where processing of a child’s data is required, we will obtain verifiable parental consent as required by the DPDP Act and will not undertake behavioural tracking or targeted advertising directed at children.
17. Cross-Border Transfers
Vyzma is a distributed team based in India and the United States. Personal data may be processed or stored on infrastructure located outside India (for example, our website host and Calendly), subject to restrictions notified by the Government of India under Section 16 of the DPDP Act. We take reasonable steps to ensure such transfers meet applicable safeguards.
18. Third-Party Links
The Site links to third-party websites and services (for example, our product sites at agriva.ai and the FireOS demo, and our booking tool Calendly). This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their policies before providing personal data.
19. Changes to this Policy
We may update this Policy from time to time. Material changes will be indicated by updating the “Last updated” date at the top and, where appropriate, notifying you by email. Your continued use of the Site after the effective date of any update constitutes acceptance of the revised Policy.
20. Grievance Officer and Contact
For questions, requests or complaints regarding this Policy or your personal data, please contact our Grievance Officer:
We will acknowledge your request and respond within the timelines required by the DPDP Act and applicable Indian law. If you are dissatisfied with our response, you may escalate the matter to the Data Protection Board of India.