VisaFit legal information · Updated 13 September 2026

VisaFit Data Processing Terms

Schedule A forms part of the Master Services Agreement. It explains agency and provider responsibilities, data handling, service providers, security, requests, incidents and data return.

Schedule A — 1 Scope, roles and instructions

This schedule forms part of the MSA. The agency determines the purposes of applicant and workforce processing and ordinarily acts as Data Fiduciary; Rishabh Softwares acts as its Data Processor for that processing. For its own account administration, billing, security and legal-compliance purposes, the provider acts separately under its Privacy Notice. These roles depend on the actual processing, not merely the label in this agreement.

The agency's documented instructions are the accepted order, this schedule, lawful workspace configuration and authorised support requests. Processing includes collection, recording, organisation, storage, retrieval, communication, export, correction and deletion needed to supply the contracted features. The provider will not sell agency personal data or use it to train general-purpose AI models under this agreement. A new purpose or external AI integration requires a separate assessment, disclosure and lawful authorisation before data is sent.

Processing continues during the service and any justified suspension, offboarding or legal-retention period. Instructions conflicting with applicable law must be raised with the agency; the affected processing may be paused while resolved. Legally compelled disclosure is limited to what is required, with notice where lawful.

Schedule A — 2 People, information and purposes

Data subjects may include applicants, customers, guardians, agency owners, staff, managers, branch heads, vendors and other contacts entered by the agency. Depending on enabled modules, data may include names and contact details; assessment responses; passport and visa documents; education, employment and financial-support information; case and lead records; messages and appointments; staff attendance and employment records; invoices, expenses and commission records.

The agency must minimise data, restrict access and collect only information necessary for specified purposes. Especially sensitive documents, children's records and third-party financial information require additional scrutiny. Do not upload card CVV, account passwords or unnecessary identity documents. Payment instruments are entered into the payment provider's checkout, not agency notes or VisaFit support requests.

The agency is responsible for its applicant-facing notice and valid consent or other applicable lawful basis. An owner accepting the MSA is not consent on behalf of every applicant. Processing of children or persons with lawful guardians requires the applicable verification and authorisation procedures; a generic checkbox alone must not be treated as sufficient evidence.

Schedule A — 3 Confidentiality and safeguards

The provider will restrict access to authorised personnel and service providers with a business need and confidentiality obligations. Support access must be tenant-specific and recorded. Safeguards include tenant-scoped access checks, role permissions, authenticated sessions, upload and request validation, rate limiting and audit records. The provider is responsible for maintaining appropriate production encryption, key management, backup protection and recovery controls and reviewing their effectiveness.

Files and exports must be protected against public access and execution. Credentials must remain in protected server configuration or encrypted integration storage, not public code or exported business records. Security safeguards and their effectiveness must be reviewed regularly. Neither source-code checks nor this schedule constitute a security certification.

Schedule A — 4 Service providers and transfers

Only necessary providers may process agency data on documented instructions and subject to appropriate contractual and security controls. The provider will maintain a register identifying legal provider name, service, purpose, data categories, locations, access, retention and review status. It will supply the applicable register to the agency and notify material provider or location changes before they affect its data where practicable, giving the agency an opportunity to raise a reasoned data-protection objection through support.

Supabase provides the PostgreSQL database, with the primary database located in Mumbai, India (South Asia region, ap-south-1). Hostinger KVM 2 is the selected application-hosting service; its server location remains subject to deployment verification. Razorpay provides payment checkout and optional recurring-payment services. Google reCAPTCHA provides login abuse protection when enabled. Email delivery uses the platform's or agency's configured SMTP provider. Hosting, edge delivery, logs, support access, database replicas and backups can involve separate locations; a Mumbai primary database does not mean that all processing takes place in India. Contact rshbhkataria@gmail.com for the provider and location information applicable to your service.

Where the agency selects its own email, webhook or other destination, it is responsible for authorising that recipient and its instructions; the provider remains responsible for its own processing obligations. No general permission is given for unrestricted exports or onward transfers. Overseas processing must comply with applicable Indian restrictions and other binding requirements; this agreement does not promise that every provider processes data only in India.

Schedule A — 5 Requests, consent and grievances

Privacy and grievance requests may be sent to Rishabh at rshbhkataria@gmail.com or by post to the registered business address above. Include a contact email, the relevant agency and the nature of the request; do not send passwords, CVV or full identity documents in the initial request. Identity and authority will be verified proportionately, with additional evidence requested through an appropriate secure channel only when needed.

The provider will assist the agency with applicable requests for information, correction, erasure, grievance redressal, nomination and withdrawal of consent, taking account of the nature of processing and information available. Requests about agency-controlled applicant records are routed to that agency unless law requires a different response. The provider will address requests about its own account and billing processing directly.

The provider records receipt, identity checks, routing, due dates, decisions and completion. Its response target for privacy requests and grievances is 30 calendar days from receipt, with shorter mandatory deadlines taking precedence. If a complete response requires further information or lawful additional time, it will explain the reason and next steps within that period; this does not extend a statutory deadline. A refusal or legal hold must be explained where lawful. Contract cancellation, non-payment and the no-refund policy do not extinguish statutory privacy remedies. Grievances may be escalated to the competent authority under the procedure then in force.

Schedule A — 6 Personal-data incidents

The provider will inform the affected agency without undue delay after becoming aware of a personal-data breach affecting its entrusted data, provide available information on nature, timing, affected information, likely consequences, containment and recommended steps, and provide updates as the investigation develops. The agency must promptly report suspected compromise to support. The initial notification must not wait for a complete investigation.

The parties will preserve relevant evidence, restrict access and cooperate on remediation and legally required communications. The agency ordinarily handles notices for processing where it is Data Fiduciary; the provider handles its own applicable duties. Statutory reporting deadlines and regulator directions prevail over this schedule. No automatic notification to a regulator or affected individual is represented as having occurred merely because an internal incident was logged.

Schedule A — 7 Return, deletion and retention

An authorised owner can request available tenant records with record-linked attachments through support, including while suspended. The provider must verify authority and deliver exports securely to an approved recipient. Technical secrets, other tenants' data and records that cannot lawfully be disclosed are excluded or appropriately restricted. Generated export archives have their own expiry; that is not the retention period for source records.

Retention is determined by the purpose of each record, the agency's lawful instructions, applicable legal obligations and documented legal holds. Expiry suspends access without automatically deleting business data. Retention during suspension is reviewed for continuing necessity. Permanent offboarding follows the written notice and export process in section 9; source records, generated export files, security evidence and backups have separate retention treatment. The provider will explain the applicable schedule on an authorised request; there is no single statutory period for every category.

On completion of the lawful retention period or a valid erasure instruction, the provider will delete or anonymise applicable records and instruct relevant processors accordingly, except for restricted records retained under law or a documented legal hold. Backups follow the approved infrastructure expiry schedule; deletion requests must not be undone by a later restore. Completion records must distinguish application deletion from independently verified backup expiry.

Schedule A — 8 Accountability and applicable law

The provider will keep processing, access, acceptance, request and incident evidence proportionate to the service and applicable law, and make relevant compliance information available to the agency on a reasonable, confidentiality-protected request. Any agreed audit must avoid exposing other tenants' data, secrets or operational security. No unrestricted platform or database access is granted.

The Digital Personal Data Protection Act, 2023 and its rules apply to the extent in force and applicable to the processing, alongside other applicable laws. This schedule does not certify compliance, appoint the provider as a registered Consent Manager, or declare it a Significant Data Fiduciary. Changes in law, deployment, vendors or processing purposes require review of instructions, safeguards and notices.

Return to VisaFit