Official Internal System Privacy Policy
This Privacy Policy specifically governs data collection, activity logging, and information security within the Vizai Engineering Admin Portal (admin.vizai.engineering) for authorized personnel. For our public customer and website privacy policy, please visit www.vizaiengineering.com .
Policy Overview & Organizational Scope
Vizai Engineering Private Limited ("Company", "We", "Our") respects the privacy and security of all authorized users accessing our internal Admin Portal (admin.vizai.engineering).
This Privacy Policy details our operational commitments to protecting data integrity, securing system logs, and handling user information in strict accordance with corporate governance guidelines and the Digital Personal Data Protection laws of India.
Categories of Information Collected
To ensure system stability, role authorization, and audit compliance, the Admin Portal processes the following categories of data:
- Identity & Account Details: Employee/User ID, Full Name, Official Email Address, Mobile Number, Assigned Department, Designation, and Role-Based Access Privileges.
- Access & Authentication Logs: Mobile OTP verification timestamps, login success/failure events, IP addresses, network origins, device user-agent strings, and browser session tokens.
- Operational Activity Data: Timestamped records of administrative actions (e.g., viewing customer portfolios, editing department permissions, generating brochures, dispatching WhatsApp/Email communications, or exporting system reports).
- Technical & System Cookies: Essential session cookies required strictly for user session state maintenance and secure authentication.
Consent & Consent Management Framework
Vizai Engineering Private Limited processes personal and administrative operational data based on explicit, informed user consent or legitimate enterprise operational grounds in compliance with the Digital Personal Data Protection (DPDP) Act of India and international data privacy benchmarks:
- Explicit & Voluntary Consent: By registering, logging in, or initiating actions on the Admin Portal, users provide unambiguous, explicit consent to the collection, verification, and processing of their identity details, session logs, and operational activity records as outlined in this policy.
- Granular Consent Controls: Users have the right to grant or specify preferences for non-essential communications (such as secondary system notifications or promotional updates). Essential operational access (e.g., authentication OTPs and RBAC permission checks) remains mandatory for system security.
- Withdrawal of Consent: Users may withdraw or modify their consent for non-mandatory data processing at any time by submitting a formal request to the Data Protection Officer or IT Administration. Upon consent withdrawal, the Company will cease processing such data within 30 business days, subject to statutory audit retention obligations.
- Impact of Consent Revocation: Revoking consent for mandatory operational data processing (e.g., authentication logs or department permissions) will result in immediate suspension or termination of portal access credentials to safeguard enterprise security.
Purpose & Legal Basis of Data Processing
The collection and processing of user data within this portal are limited strictly to official enterprise objectives:
- User Authentication & Authorization: Verifying credentials via secure mobile OTP or password verification to enforce Role-Based Access Control (RBAC).
- Security Auditing & Threat Prevention: Detecting unauthorized login attempts, preventing credential abuse, and conducting real-time vulnerability monitoring.
- Operational Management: Tracking workflow progress, maintaining accountability for corporate transactions, and facilitating internal communications.
- Regulatory & Legal Compliance: Complying with statutory audit requirements, legal inquiries, and enterprise governance mandates.
Data Retention & Archival Lifecycles
Vizai Engineering enforces structured data retention schedules to ensure that information is kept only for as long as required to fulfill operational, legal, and regulatory mandates:
| Data Category | Retention Period | Archival & Purging Standard |
|---|---|---|
| User Profiles & Account Details | Duration of employment/contract + 3 Years | Archival in encrypted cold storage; permanent cryptographic wipe upon period expiry. |
| Security Audit & Authentication Logs | 5 Years from log timestamp | Read-only immutable storage for security audit and forensic compliance under IT Act. |
| Financial & Billing Transaction Records | 7 Years (Statutory Tax requirement) | Secure financial archive accessible only by authorized finance administrators. |
| Session Cookies & Temporary Caches | 30 Days / Session Termination | Automated browser/server memory garbage collection. |
- Automated Data Purging: Data exceeding the applicable retention threshold is systematically sanitized using DoD 5220.22-M compliant digital wiping protocols or secure database truncation.
- Legal & Regulatory Holds: In the event of pending litigation, government investigations, or regulatory audits, affected records will be placed under a formal legal hold and exempt from routine purging until proceedings conclude.
Data Storage Architecture & Localization
To safeguard internal enterprise data against physical and digital vulnerabilities, Vizai Engineering maintains a centralized high-security data storage architecture:
- Primary Data Centers & Cloud Hosting: All portal databases, client records, employee information, and audit logs are hosted in enterprise-grade Tier III/IV data centers certified for ISO/IEC 27001, SOC 1, SOC 2, and PCI-DSS compliance.
- Data Localization in India: In alignment with Indian data sovereignty policies, primary active databases and backup snapshots are physically hosted and processed within secure server facilities located in India.
- Encryption at Rest & In Transit: All stored database volumes and object stores are protected using AES-256 military-grade encryption. Data in transit across public or internal networks is secured via TLS 1.3 encryption protocols.
- Geo-Redundant Backup & Disaster Recovery: Automated differential backups are executed daily and replicated to an isolated secondary geographic facility in India to ensure business continuity and zero-loss disaster recovery.
General Information & Mandatory Disclosures
This section provides transparent disclosure regarding how general system information, corporate data, and aggregated metrics may be disclosed or transferred under official circumstances:
- Statutory & Legal Compulsion: Vizai Engineering may disclose personal or operational data if required to do so by applicable laws, judicial court orders, binding administrative warrants, or statutory demands issued by competent government enforcement authorities.
- Corporate Restructuring & Mergers: In the event of a merger, acquisition, corporate reorganization, asset sale, or joint venture, user and operational databases may be transferred as part of the business assets under strict non-disclosure and continuity agreements.
- Protection of Corporate Rights & Safety: Information may be disclosed to legal counsel, cybersecurity investigators, or law enforcement where necessary to enforce system terms, investigate fraud, protect physical/intellectual property, or defend against legal claims.
- Third-Party Service Providers: Vetted third-party infrastructure partners (such as SMS/WhatsApp gateways, email service providers, and cloud hosting vendors) access data strictly as data processors under contractual non-disclosure mandates. Commercial sale or leasing of user data to third parties is strictly prohibited.
Data Usage, Non-Disclosure & Sharing Policy
Vizai Engineering enforces a zero-commercialization rule regarding internal portal data:
- Strictly Confidential & Internal: User and activity data collected on this portal is used exclusively for internal operations of Vizai Engineering.
- No Commercial Sale or Rental: We never sell, rent, or lease employee or portal operational data to third-party advertisers or external marketing organizations.
- Service Infrastructure Providers: Data may be hosted or processed via secure enterprise cloud infrastructure (such as AWS or Google Cloud) or communications API gateways (such as MSG91 or official email services) bound by strict non-disclosure agreements.
- Statutory Disclosure: Information may be disclosed to government authorities or law enforcement solely when required under binding statutory orders or legal process.
Data Security Architecture & Technical Safeguards
We implement robust, enterprise-grade technical and organizational measures to safeguard portal data against unauthorized access, loss, or alteration:
- Encryption in Transit & Rest: All data transmissions are encrypted using standard TLS 1.3 / SSL protocols. Confidential database parameters and credentials are securely hashed.
- Role-Based Access Control (RBAC): Granular permissions prevent cross-department data exposure and limit access strictly on a need-to-know basis.
- Session Timeout Controls: Automatic session invalidation and idle timeouts mitigate unauthorized physical access on unattended devices.
- Regular Vulnerability Management: Routine system audits, patch updates, and security assessments are conducted by our IT engineering team.
User Rights & Responsibilities
As an authorized user of the Admin Portal, you are entrusted with maintaining data privacy standards:
- Duty to protect all corporate and customer information accessed via the portal from unauthorized view or export.
- Duty to report any identified security flaws, accidental data exposure, or suspicious account activities to IT management immediately.
- Right to request clarification or review of your stored user profile details through your Department Head or IT Administrator.
Policy Revisions & Updates
Vizai Engineering Private Limited reserves the right to revise or update this Privacy Policy periodically to reflect technological advancements, regulatory changes, or system operational enhancements.
The revised policy will be posted directly within the portal with an updated version number and effective date.
Contact & Data Governance Inquiries
For questions, data protection concerns, or security incident reports related to the Admin Portal, please contact:
By logging into and using this portal, you acknowledge your understanding of and compliance with these data privacy practices.