Privacy Policy
Version 2.0 · Last updated 28 July 2026 · VEKTORLABS TECHNOLOGIES (OPC) PRIVATE LIMITED
In short
- We collect what we need to run your billing: your shop and GST details, your product list, your bills, and the voice spoken at the counter.
- Your shop data is yours. We do not sell it, and we do not share it with other shops or with advertisers.
- Voice: we send what is spoken to a speech provider to turn it into text. We keep a recording only if you switch on the setting that lets us use it to improve accuracy — it is off unless you turn it on.
- You can ask what we hold, correct it, or have it deleted. Write to our grievance officer and we will reply within 30 days.
- If you stop using Kaasa, you can export everything for 90 days, after which we delete it.
சுருக்கமாக
- உங்க கடை விவரம், ஜிஎஸ்டி எண், பொருள் பட்டியல், பில் விவரம், கவுண்டரில் பேசுவது — இதுதான் நாங்க சேகரிக்கிறோம்.
- உங்க கடை தகவல் உங்களுடையது. நாங்க அதை விற்க மாட்டோம், வேற யாருக்கும் தர மாட்டோம்.
- பேசுறத எழுத்தா மாத்த ஒரு சேவைக்கு அனுப்புறோம். பதிவை சேமிக்கணுமா வேண்டாமா என்பது உங்க விருப்பம் — நீங்க ஆன் பண்ணாத வரை சேமிக்க மாட்டோம்.
- உங்க தகவலை பார்க்க, திருத்த, அழிக்க கேட்கலாம். 30 நாட்களுக்குள் பதில் தருவோம்.
- காசா நிறுத்தினா, 90 நாட்கள் வரை எல்லா தகவலையும் எடுத்துக்கலாம்.
This policy explains how VEKTORLABS TECHNOLOGIES (OPC) PRIVATE LIMITED ("Vektor Labs", "we") handles personal data in connection with Kaasa, our voice billing software, and this website. We are the Data Fiduciary for that data under India's Digital Personal Data Protection Act, 2023 ("DPDP Act").
1. What we collect
| What | Why we need it |
|---|---|
| Shop details — business name, address, GSTIN, owner name, phone, email | To create your account, issue GST-compliant invoices, and bill you |
| Staff accounts — name and role of each counter user you create | So each bill is attributable and you can set permissions |
| Product catalogue — item names, prices, HSN codes, stock levels | To match what is spoken to what you actually sell |
| Transaction records — bills, tax breakups, payments, returns | To run billing and produce your GST reports |
| Voice and speech data — audio captured when staff speak an order | To convert speech into a bill. Section 2 covers this in full |
| Device and usage data — device model, OS and app version, crash logs, feature usage | To keep the app working on the hardware you actually use |
| Website data — pages visited, referrer, approximate region | To understand which pages are useful |
We do not collect your customers' personal data unless you enter it yourself (for example, a name or phone number on a bill). If you do, you are responsible for having a lawful basis to share it with us, and we process it only to provide the service to you.
2. Voice data — what actually happens to what you say
This is the question most shop owners ask first, so here is the direct answer.
How it is processed. When staff speak an order, the audio is sent to a third-party speech-recognition provider, which converts it to text. Kaasa matches that text against your product catalogue and builds the bill. Audio is transmitted over an encrypted connection.
Whether it is retained. By default, no. Audio is processed and discarded. We keep the resulting text only as long as needed to produce the bill, and then the bill itself. We do not keep a rolling archive of everything said at your counter.
Improving accuracy. Kaasa has a setting — "Help improve voice recognition" — which is off unless you turn it on. If you switch it on, we retain samples of audio and their corrections so we can improve recognition of Tamil and English retail speech. You can switch it off at any time and ask us to delete samples already retained. Turning it off does not reduce any other functionality.
Retention when enabled. Retained voice samples are kept for a maximum of 24 months and then deleted. They stay associated with your shop account so they can be found and deleted on request.
What we never do. We do not listen passively — capture begins only when a staff member starts a voice bill. We do not use voice data for advertising, and we do not sell or licence it to anyone.
3. Lawful basis and consent
We process personal data on the basis of your consent, given when you create an account and accept this policy, and for the legitimate uses permitted under section 7 of the DPDP Act.
Consent is requested for each purpose, in clear language, before collection. You can withdraw consent at any time, as easily as you gave it, through in-app settings or by writing to our grievance officer. Withdrawal does not affect processing already carried out, and may mean we can no longer provide parts of the service.
4. Who else touches your data
We use a small number of processors, named here by category:
- Speech recognition provider — converts spoken orders to text.
- Cloud hosting and database provider — stores your account and shop data.
- Payment gateway — processes subscription payments. Card details go to the gateway, not to us; we never see or store your full card number.
- Communication tools — email and WhatsApp, for support and billing notices.
Each is bound by contract to process data only on our instructions. We do not sell personal data, and we do not share it with advertisers or data brokers.
5. Where your data is stored
Shop and transaction data is stored on servers located in India. Some processors — speech recognition in particular — may process data on infrastructure outside India. Where that happens, transfers are limited to what is necessary to deliver the service, are subject to contractual protections, and are made only to countries not restricted by the Central Government under the DPDP Act.
6. How long we keep things
- Shop and transaction data — while your account is active. GST records are retained for the period Indian tax law requires them to be kept.
- After you cancel — exportable by you for 90 days, then deleted from live systems; backups age out within a further 30 days.
- Voice samples — not retained unless you opt in; 24 months maximum if you do.
- Support correspondence and website data — up to 24 months.
7. How we protect it
We follow reasonable security practices as required by section 43A of the Information Technology Act, 2000 and the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011: encryption in transit, encryption at rest, role-based access limited to staff who need it, and logging of administrative access. If a personal data breach occurs we will notify the Data Protection Board and affected users as the DPDP Act requires.
8. Your rights
As a Data Principal under the DPDP Act you have the right to:
- Access — a summary of the personal data we process about you and what we do with it.
- Correction and completion — to fix data that is wrong, incomplete or out of date.
- Erasure — to have data deleted where we no longer need it, or where you withdraw consent, unless a law requires us to keep it.
- Grievance redressal — to complain to us first, using the details below.
- Nomination — to nominate another person to exercise these rights if you die or become incapacitated.
To exercise any of these, write to the grievance officer below. We will respond within 30 days. If our response does not satisfy you, you may complain to the Data Protection Board of India.
9. Cookies
This website uses only the cookies and local storage it needs to work — for example, remembering that you have already seen the intro animation. We use no advertising cookies and no third-party tracking pixels. Your language choice lives in the page address (?lang=ta), not in a cookie. The Kaasa app does not use advertising identifiers.
10. Children
Kaasa is a business tool and is not directed at children. We do not knowingly process the personal data of anyone under 18. If you believe a child's data has reached us, contact the grievance officer and we will delete it.
11. Changes to this policy
If we change this policy we will update the version number and date at the top of this page. For changes that materially affect how we use your data — particularly anything about voice retention — we will notify you in the app and by email or WhatsApp before the change takes effect, and where the law requires it, ask for fresh consent.
12. Grievance officer
Under section 13 of the DPDP Act, complaints about how we handle your personal data go to a named individual:
- Name: Kishan
- Designation: Founder & Grievance Officer
- Email: privacy@vektorlabs.in
- Phone: +91 90432 60810
- Post: VEKTORLABS TECHNOLOGIES (OPC) PRIVATE LIMITED, Chennai, Tamil Nadu, India
We acknowledge complaints within 72 hours and resolve them within 30 days.
