Privacy Policy

Version 1.0 · Effective date: 5 September 2026

1. Introduction & scope

This Privacy Policy explains how [Legal Entity Name, e.g. "Vivora Technologies Private Limited"] ("Vivora", "we", "us") collects, uses, discloses, and protects personal data when you use the Vivora manufacturing ERP platform (the "Service"), including our website, application, and any related APIs.

Vivora is a B2B software-as-a-service product. Our direct customers are businesses ("Customer", "you", when we mean the company account) who sign up their organisation for the Service. Employees and authorised users of a Customer ("Users") access the Service under that Customer's account. Where Vivora processes personal data of Users on behalf of a Customer in the course of providing the Service (e.g. names and email addresses of the Customer's staff, records they enter about their own customers/suppliers), Vivora acts as a data processor and the Customer is the data controller for that data. Where Vivora determines the purpose and means of processing (e.g. billing records, account security logs, this website's own visitors), Vivora acts as the data controller. Section 3 states which basis applies to each category of data.

This policy currently addresses India-based operations and compliance (Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011). Sections 12–13 set out how this policy will extend to the EU, UK, and other regions if and when Vivora begins operating there — those sections are not yet in force and are included so the framework is ready ahead of expansion.

2. Data we collect

CategoryExamplesHow it's collected
Account & identity dataName, email address, company name, role/job title, password (stored as a salted hash, never in plain text)Direct input at signup and in Settings
Business/operational dataProduction job records, inventory items and stock movements, customer and supplier records, quotations, sales and purchase orders, invoices, notesDirect input by Users in the course of using the Service
Billing dataBilling name and address, GSTIN (if provided), subscription plan, payment method metadata (e.g. card's last 4 digits, card network)Direct input; processed via our payment processor, Stripe
Usage & log dataLogin timestamps, IP address, browser/device type, pages and features accessed, error logsAutomatically, when you use the Service
Support communicationsEmails or messages you send us, and their contentDirect input when you contact support
Cookies & local storageSee our Cookie PolicyAutomatically, via your browser

We do not knowingly collect full payment card numbers — these are entered directly into Stripe's own secure checkout and never touch Vivora's servers.

3. Legal basis for processing (India)

Under Indian law, Vivora processes personal data on the following bases:

Section 12 sets out the equivalent legal bases under GDPR/UK GDPR (Art. 6), for when this policy is extended to those regions.

4. How we use data

We do not use your business/operational data (your jobs, stock, customer, or supplier records) for any purpose other than providing the Service to you, and we do not sell personal data to third parties. We will not send marketing communications to Users unless they have separately opted in, and every marketing email includes a working unsubscribe link.

5. Who we share data with

RecipientPurposeData shared
Stripe, Inc.Payment processingBilling name/address, payment method metadata, subscription/invoice records. See Stripe's Privacy Policy.
Supabase Inc. (database & authentication hosting)Hosting the application database and handling login/session securityAll account, business, and usage data described above. See Supabase's Privacy Policy.
Cloudflare, Inc. (application hosting/CDN)Serving the application and protecting it from abuseIP address and request metadata. See Cloudflare's Privacy Policy.
PostHog (product analytics — planned, not yet active)Understanding feature usage to improve the ServiceUsage/log data, pseudonymised where possible. See our Cookie Policy and PostHog's Privacy Policy. This integration is not yet live; this disclosure is published in advance of activation.

We do not share your data with third parties for their own marketing purposes. We may disclose data where required by law, court order, or valid legal process, or to protect the rights, property, or safety of Vivora, our Customers, or others.

6. Data retention

Data typeRetention period
Business/operational data (jobs, stock, orders, etc.)For as long as your account is active, plus 90 days after termination to allow export/recovery, after which it is deleted unless a longer period is required to resolve a dispute or comply with law.
Billing and transaction records7 years, to meet Indian tax and accounting record-keeping requirements.
Account credentials/session logsSession logs: 90 days. Account records: for the life of the account.
Support communications3 years from the date of the last message in the thread.

7. Your rights

You may request to:

If you are a User accessing the Service through your employer's Customer account, some of these requests (e.g. deletion of business records) may need to be directed to your employer/Customer account admin first, since they control that data. To exercise any of these rights directly with Vivora, contact privacy@[yourdomain]. We will respond within 30 days.

8. Cookies & tracking

See our standalone Cookie Policy for full detail on session storage, planned analytics, and how to opt out.

9. Security

We apply industry-standard safeguards appropriate to the sensitivity of the data, including encryption of data in transit (HTTPS/TLS) and at rest, salted password hashing (we never store passwords in plain text), role-based access control within each Customer account, and database-level isolation so one Customer's data is never visible to another (enforced at the database layer, not just in the application). No system is perfectly secure, and we cannot guarantee absolute security. See Section 6 of our Data Processing Agreement for further technical and organisational measures where Vivora acts as a processor.

10. Sensitive personal data (India — IT Rules 2011, Rule 4)

Where we collect information classified as "sensitive personal data or information" under the IT Rules 2011 — passwords and financial information (billing/payment metadata) — we do so only with your consent (given by creating an account and agreeing to this policy and our Terms of Service), use it only for the purpose it was collected, apply the security measures described in Section 9, and do not retain it for longer than necessary for that purpose or as required by law.

11. Children's privacy

The Service is a business tool intended for use by working professionals and is not directed at, or intended for use by, anyone under 18. We do not knowingly collect personal data from minors. If you believe a minor has provided us personal data, contact us and we will delete it.

12. International data transfers & multi-region readiness (not yet active)

Vivora's infrastructure (Supabase, Cloudflare) may store or process data outside India. Today, all of Vivora's customers and data subjects are based in India, so this section is included for completeness and to describe the framework that will apply once Vivora expands to other regions:

These sections do not yet apply and create no rights until Vivora actually processes data of individuals in those regions, at which point this policy will be updated and re-dated before that processing begins.

13. Third-party links

The Service may link to third-party websites or services (e.g. Stripe's checkout page). We are not responsible for the privacy practices of those third parties; please review their own policies.

14. Changes to this policy

We will notify you of material changes to this policy by email and/or an in-app notice at least 14 days before the change takes effect. The "Effective date" above reflects the current version.

15. Contact & grievance officer

For privacy questions, data requests, or complaints, contact:

Grievance Officer: [Name]
Email: privacy@[yourdomain]
Address: [Registered business address]

Grievance Officer designation is provided in accordance with the Information Technology (Intermediary Guidelines) Rules. Disputes arising from this policy are subject to the governing law and jurisdiction clause in our Terms of Service.