Privacy Policy
Version 2.0 · Effective / last updated: 20 July 2026
This Privacy Policy explains how YantrAdhigam Labs Pvt Ltd(“we”, “us”, “VIDU”) collects, uses, shares and protects personal data in connection with the VIDU CRM website and product (the “Services”). It is written to comply with India's Digital Personal Data Protection Act, 2023 (DPDP) and the Information Technology Act, 2000, and, for users outside India, the EU/UK GDPR and the California Consumer Privacy Act (CCPA/CPRA). By using the Services you agree to this Policy.
1. Two categories of data and our role
- (A) Account & usage data: data about you as an account holder and visitor (name, email, phone, billing details, device/usage/analytics). For this, we are the Data Fiduciary (a “controller” under GDPR).
- (B) Customer Content: the contacts, leads and records you upload into the CRM about your own customers. For this, you are the Data Fiduciary and we are only your Processor, handling it on your instructions to run the Services, under our Data Processing Agreement. We do not use identifiable Customer Content for our own purposes.
2. Free vs paid plans, how data use differs
- Free plan. As consideration for the no-cost plan, you permit us to use your Category-A data and de-identified / aggregated data derived from your activity broadly and for any purpose, including analytics, product improvement, security, research, new features, and training machine-learning models and to send you marketing (see §5). We still do not use identifiable Category-B Customer Content for our marketing or model training.
- Paid plans. We process your Customer Content on a processor-only, confidential basis, solely to provide the Services and do not use it for our own marketing or to train models on an identifiable basis. We may use de-identified/aggregated data to operate, secure and improve the Services.
3. Information we collect
- You provide: account details (name, work email, phone, company), authentication data, billing information (processed by our payment processor), support messages, and any content you enter.
- Automatically: usage, log, device and approximate-location data, and cookie/analytics identifiers (see our Cookie Policy).
- From your CRM (Category B): the personal data of your contacts/leads that you upload, processed only as your Processor.
4. How we use personal data (purposes & legal bases)
- Provide, secure, maintain and support the Services (contract; legitimate interests).
- Process payments, billing and tax invoicing (contract; legal obligation).
- Analytics, product improvement and new-feature development, on a de-identified/aggregated basis (legitimate interests; for the Free tier, consent as above).
- Train and improve machine-learning / AI features using de-identified/aggregated data, never identifiable Category-B Customer Content on paid plans (legitimate interests / consent).
- Marketing (offers, product news) to account holders, with consent and an easy opt-out (§5).
- Comply with law, prevent fraud/abuse, and enforce our terms (legal obligation; legitimate interests).
5. Marketing communications & consent
We send marketing only where permitted. On the Free plan, marketing is part of the service bargain and enabled on sign-up; on paid plans it is opt-in. You can withdraw consent at any time, as easily as it was given, via the unsubscribe link in any message or by emailing support@yalabs.in. Service and transactional messages are not marketing and continue regardless. Cookies are governed by consent through our cookie banner and Cookie Policy.
6. Sharing and our no-sale commitment
We do not sell your personal data, and we do not “share” it for cross-context behavioural advertising. We disclose personal data only to: (a) our vetted service providers / sub-processors who help run the Services (payments, hosting, email, storage, analytics) under contract, see our sub-processor register; (b) our affiliates; and (c) authorities or acquirers where required by law or in a corporate transaction, with safeguards.
7. International transfers & hosting
The Services are primarily hosted in India. Where personal data is transferred across borders (including to sub-processors), we use lawful transfer mechanisms, for DPDP, transfers only to jurisdictions not restricted by the Central Government; for the EEA/UK, Standard Contractual Clauses or an adequacy basis. Details are available on request.
8. Data retention
We keep account and Customer Content for as long as your account is active, and after closure only as long as needed for the purposes above or as required by law (typically up to 90 days for operational data, and longer for tax/legal records, GST invoices are retained per statutory periods). You may request earlier deletion (§10). De-identified/aggregated data may be retained indefinitely.
9. Security & breach notification
We apply reasonable technical and organisational safeguards, TLS 1.2+ in transit, encryption at rest, RBAC, tenant isolation and audit logging (see Data & Security). No system is perfectly secure. In the event of a personal-data breach, we will notify the Data Protection Board of India and affected Data Principals, and (where applicable) EEA/UK supervisory authorities, without undue delay and within the timelines the law requires.
10. Your rights (DPDP Act 2023)
As a Data Principal you have the right to: access and obtain a summary of your personal data; correction, completion, updating and erasure; grievance redressal; and to nominate another individual to exercise your rights in the event of death or incapacity. You can export your data or request erasure in-product under Privacy & Your Data, or contact our Grievance Officer. We aim to respond within 30 days.
If you are a contact/lead in a customer's CRM (Category B), please contact that customer (the Data Fiduciary); we will assist them as their Processor.
11. EEA/UK rights (GDPR)
If you are in the EEA or UK, you also have the rights to portability, restriction, objection (including to direct marketing and profiling), and to lodge a complaint with your supervisory authority. Our legal bases are set out in §4. You can object to processing based on legitimate interests at any time.
12. California rights (CCPA/CPRA)
If you are a California resident, you may request to know, access, correct and delete your personal information, and you have the right to opt out of any “sale” or “sharing” although we do not sell or share personal information as those terms are defined. We honour Global Privacy Control (GPC) browser signals and will not discriminate against you for exercising your rights. Use our Do Not Sell or Share control or email grievance@yalabs.in.
13. Automated decisions & profiling
We use scoring/analytics to help you prioritise leads. We do not make decisions producing legal or similarly significant effects about you solely by automated means without a lawful basis; where we profile for our own analytics/marketing (Free tier), you may object.
14. Children
The Services are for businesses and are not directed to children under 18; we do not knowingly collect their data.
15. Changes
We may update this Policy; material changes will be notified through the site or product, and the “effective” date above will change.
16. Contact & Grievance Officer
For privacy questions or to exercise your rights, contact our Grievance Officer via the Grievance Officer page, or email grievance@yalabs.in. You may escalate unresolved complaints to the Data Protection Board of India.