Privacy Policy — Vyuha
Last updated: 4 August 2026 · Effective: 4 August 2026
This Privacy Policy explains how Vyuha ("the Service") handles information. Vyuha is a company operating system provided by Rosnil Technology Private Limited ("Rosnil", "we", "us", "our"). Contact: rosnil@apeitnow.com.
1. Our two roles under the DPDP Act
Because Vyuha is a workspace an organisation runs its own operations in, our role depends on whose data it is:
- For your organisation's business data (the messages, tasks, payments, records and people your company puts into Vyuha), the customer organisation is the Data Fiduciary and Rosnil acts as a Data Processor, processing that data only under the customer's instructions and the service agreement.
- For account and billing data we collect to provide and bill the Service (the administrator's contact details, subscription records), Rosnil is the Data Fiduciary.
2. Information the Service processes
- Workspace content. WhatsApp and connector messages you route into Vyuha, and the records derived from them — tasks, approvals, payments, projects, vendors, meetings, documents and attachments (including evidence photos and their capture location where provided).
- People records. Names, roles, phone numbers, email addresses, aliases, and — where your organisation chooses to store them — sensitive fields such as salary or bank details. Sensitive fields are masked by role.
- Identity & access. The login identity your organisation's single sign-on presents (a subject id, and email/name when supplied), used to resolve you to a person and show your own queue.
- Operational logs. An append-only audit trail of actions on records, plus technical logs needed for security, reliability and support.
3. How AI is used
Vyuha's understanding layer — reading a message, classifying it, deriving context, summarising a thread — runs on a local/self-hosted model under your deployment, so routine content stays on your infrastructure. Only high-level management queries (the AI command bar and company-context Q&A) may be sent to a cloud AI provider, and only when your deployment is configured with a cloud key. If no cloud key is set, those queries fall back to the local model, then to deterministic rules. The AI proposes; it never finalises a record on its own. See our AI Policy.
4. What we do not do
- We do not sell your data or share it with data brokers.
- We do not use your workspace content to serve advertising.
- We do not use one customer's business data to train models for other customers.
- We do not let one tenant access another tenant's data — isolation is enforced on every request.
5. Sub-processors
To run the Service we use a small set of infrastructure providers — cloud hosting and managed databases, and, only for high-level queries and only when enabled, a cloud AI provider. These act as our sub-processors under contractual confidentiality and security terms. A customer may instead run Vyuha on their own infrastructure, in which case no third-party sub-processor handles workspace content. A current list of sub-processors is available on request.
6. Where data is stored and for how long
Workspace data is stored on servers operated by, or on behalf of, your deployment. We retain your organisation's data for as long as the account is active. On termination, or on a verified request, we export and then delete the organisation's data within a commercially reasonable period, except where retention is required by law (for example, financial records).
7. Security
Access is role-based and least-privilege; sensitive fields are masked from operations roles; every action is recorded in an append-only audit trail; identity is verified on every request and revoked sessions are denied. Data is encrypted in transit. We keep this reasonable and up to date, but no system is perfectly secure.
8. Your rights
If you are an end user within a customer organisation, that organisation controls your workspace data — direct access, correction and deletion requests to your organisation's Vyuha administrator, who can act on them in the Service or ask us to. If you are a customer administrator, you may request export or deletion of your organisation's data, and raise DPDP rights (access, correction, erasure, grievance) with us at the address below.
9. Children
Vyuha is a workplace tool intended for business use by adults and is not directed to children.
10. Changes
We may update this policy; material changes will be notified to customer administrators. The "Last updated" date above reflects the current version.
11. Contact & grievance
Rosnil Technology Private Limited — rosnil@apeitnow.com. For data-deletion requests, see Data Deletion.