veerha

Privacy Policy

Effective date: 8 October 2026 · Last updated: 8 October 2026

This Privacy Policy explains how Catabatic Technology Private Limited ("Catabatic", "VEERHA", "we", "us", or "our") collects, uses, shares and protects personal data when you visit veerha.com, use the VEERHA platform at app.veerha.com, or interact with a business that uses VEERHA (together, the "Services").

It should be read together with our Terms & Conditions at https://veerha.com/terms. We process personal data in accordance with applicable Indian law, including the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.

  1. 1. Our Role

    VEERHA is used by businesses ("Customers") to manage their own leads, customers and conversations. The role we play depends on whose data it is:

    • Account data: for the people who sign up for and use VEERHA on behalf of a business, we decide how that data is used, and we are responsible for it under this policy.
    • Customer Data: for the leads, guests, buyers and other people a business manages in VEERHA, the business decides why and how that data is processed. We process it on the business's behalf and on its instructions. If you are one of those people, please contact that business first; we will help them respond to you.
  2. 2. Information We Collect

    Information you give us

    • Account and profile details: name, work email, phone number, business name, role and password.
    • Business setup: industry, products, services, prices, working hours, team members, templates and the knowledge you add for the AI to use.
    • Billing details: plan, invoices and payment status. Card, UPI and bank details are collected by our payment provider, Razorpay, and are not stored on our systems.
    • Support and onboarding: messages, call notes and requests you send us.

    Customer Data a business brings into VEERHA

    • Contact details of leads and customers, such as name, phone number, email address and address.
    • Conversations on WhatsApp, Instagram, Facebook Messenger and email, and the answers people give to the questions a business asks.
    • AI phone and WhatsApp calls: a written transcript, a summary and the details captured during the call. We do not store audio recordings of calls.
    • Bookings, quotations, orders, payments recorded by the business, and, for hotels, guest check-in details and identity documents where the hotel collects them.
    • Leads and their form answers from connected sources such as Meta Lead Ads, website forms and imported spreadsheets or CRMs.

    Information from connected accounts

    When you choose to connect an account, we receive only what that connection needs. Section 6 describes Google, Microsoft and Zoom connections in detail.

    Information collected automatically

    • Technical data: IP address, browser and device type, and log records of requests, kept for security, rate limiting and troubleshooting.
    • Browser storage: the VEERHA app keeps your signed-in session and some display preferences in your browser's local storage. Marketing source details (such as UTM tags) from the page you arrived on are kept in session storage so they can be attached to your sign-up.
    • Bot protection: sign-up and some public forms use Cloudflare Turnstile to tell people from automated abuse.
  3. 3. How We Use Information

    • To provide the Services: running your workspace, sending and receiving messages, booking meetings, placing calls, preparing quotations and keeping records.
    • To power AI features: answering and qualifying enquiries, drafting replies, summarising conversations and email threads, and extracting details from messages.
    • To secure the Services: authentication, fraud and abuse prevention, rate limiting and audit trails.
    • To bill you and keep financial records required by law.
    • To support you, and to send service messages such as account verification, password resets, invoices and important changes.
    • To improve the Services, using aggregated and operational information about how features are used.
    • To comply with legal obligations and respond to lawful requests.

    We do not sell personal data, and we do not use Customer Data to advertise to anyone.

  4. 4. Artificial Intelligence

    VEERHA's AI features are provided using Google's Gemini models. To produce a reply, summary, draft or call, the relevant content (for example, the conversation, the email thread or the business's own knowledge) is sent to the model provider for processing and the result is returned to VEERHA.

    A business may also connect its own AI provider keys, for example for image generation. When it does, content for those features is sent to the provider that business chose.

    When a person on your team corrects or approves an AI output, that example can be saved to your own workspace so the AI follows your guidance next time. These examples stay within your workspace. They are not shared with other businesses and are not used to train AI models.

    We do not use Customer Data or Google user data to train or improve general-purpose AI or machine-learning models.

  5. 5. Google, Microsoft and Zoom Data

    Connecting any of these accounts is optional. Each team member connects their own account, and can disconnect it at any time from Settings in VEERHA or from their Google, Microsoft or Zoom account settings.

    Google Calendar

    Access requested: calendar.events.owned (events on calendars you own) and your email address. VEERHA uses it only to create, update and delete the calls and meetings it books for you, including Google Meet links when you choose Meet. VEERHA does not read, list or store the other events in your calendar.

    Gmail

    Access requested: full mail access (mail.google.com) and your email address, used over IMAP and SMTP so you can read and send your business email inside VEERHA. VEERHA reads message headers to sort your mailbox, and downloads and stores the content of business-relevant messages so it can show them, summarise threads and draft replies. Message content is deleted after your workspace's retention period (90 days by default); headers and the details extracted for your records are kept while your account is active.

    Google Business Profile

    Access requested: business.manage and your email address, used to show your business's reviews in VEERHA and post the replies you approve.

    Microsoft (Outlook and Microsoft 365)

    For email, VEERHA requests IMAP and SMTP access to read and send your mail, as described for Gmail. For calendar, it requests Calendars.ReadWrite to create, update and delete the meetings it books, including Microsoft Teams links.

    Zoom

    Used only to create, update and cancel the Zoom meetings VEERHA books for you.

    Google API Services User Data Policy

    VEERHA's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. In particular:

    • We use Google user data only to provide and improve the user-facing features described above, which you can see and control in VEERHA.
    • We do not transfer Google user data to others, except as needed to provide those features (for example, sending an email thread to our AI provider to draft your reply), to comply with law, for security, or as part of a merger or acquisition with notice to you.
    • We do not use Google user data for advertising, and we do not sell it.
    • We do not use Google user data to develop, improve or train generalised AI or machine-learning models.
    • No one at VEERHA reads your Google user data unless you ask us to (for example, for support), it is needed for security or to investigate abuse, or it is required by law.
  6. 6. How We Share Information

    We share personal data only with service providers that help us run VEERHA, with the integrations a business chooses to connect, and where the law requires it. Our service providers process data on our instructions:

    • Google (Gemini AI models, and the Google services you connect)
    • Meta Platforms (WhatsApp Business, WhatsApp calling, Instagram, Facebook and Lead Ads)
    • Microsoft and Zoom, when you connect them
    • Resend and Elastic Email (sending email)
    • Razorpay (payments)
    • Cloudflare (Turnstile bot protection)
    • eZee and other channel managers, for hotels that connect them
    • OpenStreetMap Nominatim, to look up the location of an address you enter
    • Any other integration a business chooses to connect, such as its own AI provider or webhook

    We may also disclose information to comply with law, a court order or a request from a government authority; to protect the rights, safety and security of VEERHA, our users or the public; or to a successor in a merger, acquisition or sale of assets, subject to this policy.

  7. 7. Public Booking Pages and Tracking

    veerha.com does not use advertising or analytics trackers.

    A business can choose to add its own Meta Pixel, Google tag or Microsoft Clarity to its public VEERHA booking pages, to measure its own advertising. When it does, those services may set cookies and collect information about visits to that page under the business's and the provider's own policies.

  8. 8. Security

    We use technical and organisational measures appropriate to the data we hold, including:

    • Encryption in transit using HTTPS (TLS).
    • Encryption at rest of access tokens, API keys and passwords for connected services.
    • Per-person encryption keys for sensitive customer identifiers, so that erasing a person also destroys the key to their data.
    • Passwords stored only as salted hashes (PBKDF2-SHA256).
    • Short-lived sign-in sessions, refresh tokens that rotate on every use and are stored only as hashes, and automatic revocation when a token is reused.
    • Strict separation of each business's data, role-based access within a workspace, rate limiting and audit logs.

    No system is completely secure. If we become aware of a personal data breach that affects you, we will notify you and the relevant authorities as required by law.

  9. 9. Data Retention

    We keep personal data only for as long as it is needed for the purposes in this policy, unless the law requires us to keep it longer.

    • Account data: while your account is active, and for a reasonable period afterwards so you can export your data and we can meet legal and accounting obligations.
    • Email content synced from Gmail or Outlook: deleted after your workspace's retention period (90 days by default).
    • Files attached to emails sent from VEERHA: deleted 30 days after sending.
    • Guest identity documents collected at hotel check-in: deleted after the period the hotel sets, which cannot exceed the maximum VEERHA allows.
    • Invoices, payment and tax records: for the period required by law.
    • Customer Data: for as long as the business keeps it in VEERHA, or until it is erased.
  10. 10. Your Rights

    Subject to applicable law, you have the right to:

    • Access the personal data we hold about you and get a summary of how it is processed.
    • Correct or update inaccurate or incomplete data.
    • Erase your personal data. When a person is erased in VEERHA, their profile, contact details, conversations, messages and call transcripts are deleted, and the encryption key for their data is destroyed. Financial records the law requires us to keep are retained.
    • Withdraw consent at any time, for example to marketing messages. People contacted by a business through VEERHA can use the unsubscribe or preference link where a message includes one, or ask that business to stop contacting them.
    • Nominate another person to exercise these rights on your behalf in the event of death or incapacity.
    • Raise a grievance with us, and, if it is not resolved, with the Data Protection Board of India.

    If you are a lead or customer of a business that uses VEERHA, please send your request to that business. If you contact us instead, we will pass it on to them.

    To make a request, email care@veerha.com. We may need to verify your identity before acting on it.

  11. 11. Where Data Is Processed

    VEERHA's servers and databases are hosted in India.

    Some of our service providers, including our AI provider, may process data outside India. Where they do, we rely on their contractual commitments to protect it, and we transfer data only as permitted by Indian law.

  12. 12. Children

    VEERHA is a business service and is not directed at children. We do not knowingly collect personal data from anyone under 18 for our own purposes. If you believe a child has provided personal data to us, please contact us and we will delete it.

  13. 13. Changes to This Policy

    We may update this Privacy Policy from time to time. The updated version will be published on this page with a new "Last updated" date. If a change materially affects how we use personal data, we will notify account holders by email or in the app before it takes effect.

  14. 14. Contact and Grievances

    For privacy questions, requests or complaints:

    We aim to acknowledge every request promptly and to resolve grievances within the time required by applicable law.

© 2026 Catabatic Technology Private Limited. All Rights Reserved.