VISSTRO

LEGAL

Privacy Policy

Effective date: 1 October 2026

VISSTRO is a restaurant operating-system product of Anaya Communication Private Limited ("Anaya", "VISSTRO", "we", "us" or "our").

This Privacy Policy explains how we collect, use, disclose and protect personal information when people visit visstro.com, request a demonstration, contact us, or otherwise communicate with us through the VISSTRO Website.

This policy applies to the public VISSTRO Website and Website enquiries. Customer restaurant data processed through a deployed VISSTRO service may also be governed by a separate customer agreement, order form, data-processing agreement or other contractual documentation.

Controller / business responsible

Anaya Communication Private Limited is the business responsible for the personal information described in this policy.

Registered office: 3rd Phase, Kamala, Near Mahajan Flour Mill, Gangyal, Jammu, Jammu and Kashmir 180010, India

Privacy enquiries: info@anayaworld.com

Data we collect

A. Information visitors provide. When someone uses Book a Demo or Contact, we may receive:

  • name
  • business/company name
  • business email
  • phone number where provided
  • country
  • restaurant/business type
  • number of locations where requested
  • enquiry type
  • message or enquiry details
  • marketing preference where explicitly selected
  • information voluntarily included in correspondence

Attribution / context

Where available, we may also receive:

  • referring page
  • UTM/source information
  • locale
  • submission time

Technical / security information

Our hosting and security providers may process information such as IP address, browser/device characteristics, request metadata, and security and abuse-prevention signals.

VISSTRO's lead-alert emails do not intentionally include the visitor's IP address or Turnstile secret/token.

Cloudflare Turnstile is used to distinguish legitimate submissions from automated abuse. We do not use this technical and security information to permanently profile visitors.

How we use information

We may use information to:

  • respond to enquiries
  • arrange and conduct requested demonstrations
  • understand the restaurant/business context of an enquiry
  • communicate about a requested VISSTRO opportunity
  • provide requested information
  • protect forms and infrastructure against fraud, spam and abuse
  • maintain Website and service security
  • comply with legal obligations
  • establish, exercise or defend legal rights
  • send marketing communications only where there is an appropriate lawful basis and, where required, an affirmative marketing choice

We do not sell personal information

We do not sell Website enquiry personal information.

Lawful basis / consent

Depending on a visitor's location and context, our processing may rely on:

  • responding to a person's request / steps prior to entering a business relationship
  • legitimate business interests such as responding to business enquiries, securing the Website and preventing abuse
  • compliance with legal obligations
  • consent where consent is required, including optional marketing communications

Service providers / recipients

We disclose information to the following categories of current core providers, as reasonably necessary to operate the Website and respond to enquiries:

  • Vercel — Website hosting, deployment and infrastructure
  • Cloudflare — Turnstile security / bot-abuse prevention
  • Resend — transactional email delivery for Website enquiry alerts
  • Microsoft 365 / our organisation's business-email environment — receipt and handling of sales enquiries

Other providers

Other professional/service providers may be used where reasonably necessary for operations, security, legal compliance or customer relationship management. We do not currently send Website enquiry data to a CRM, because no CRM is currently integrated.

International processing

Our service providers may process information in countries other than the visitor's own. Where applicable law requires safeguards for international data transfers, we use or rely on appropriate contractual, organisational or legal mechanisms provided by us or the relevant service provider.

Retention

Ordinary Website enquiries: we generally retain this information for up to 24 months after the last meaningful interaction.

If an enquiry becomes a customer/business relationship: relevant information may be retained for the duration of the relationship and for applicable contractual, tax, accounting, dispute or legal-retention requirements.

Marketing preference/consent: retained for as long as needed to honour the preference and demonstrate the consent/withdrawal history.

Security/platform logs: retained for limited periods according to operational need and provider policies.

We delete or anonymise data when it is no longer reasonably required, subject to legal obligations and legitimate claims.

Your rights

Depending on applicable law, you may have rights to:

  • request information/access
  • request correction
  • request deletion/erasure
  • request restriction where applicable
  • object to certain processing
  • withdraw consent
  • data portability where applicable
  • raise a grievance or complaint
  • complain to an appropriate data-protection authority

Exercising your rights

Requests may be sent to info@anayaworld.com. We may ask for reasonable identity verification before acting on a request.

Security

We use reasonable technical and organisational safeguards designed to protect personal information, including access controls, environment-scoped secrets, encrypted HTTPS transport, Turnstile form protection, rate limiting, server-side validation, and restricted email/API credentials.

No system can be described as completely secure, and we do not claim our systems are unhackable.

Children

The VISSTRO Website and its business-enquiry forms are directed to restaurant operators, businesses and professional users and are not designed for children.

We do not knowingly solicit Website-enquiry personal information from children. If we learn that information was submitted by a child in circumstances where we should not process it, we will take appropriate steps consistent with applicable law.

Automated decisions

We do not use Website enquiry data to make solely automated decisions that produce legal or similarly significant effects. Security systems may automatically assess requests for spam/bot protection.

Changes to this policy

We may update this Privacy Policy when our practices, services or legal obligations change. Material revisions will carry a revised effective date.