VisaFit legal information · Updated 13 September 2026
VisaFit Master Services Agreement
This Master Services Agreement governs VisaFit subscriptions supplied by Rishabh, sole proprietor trading as Rishabh Softwares, to the agency identified in the accepted subscription order.
1 Parties and acceptance
Rishabh, sole proprietor trading as Rishabh Softwares, is the service provider. The customer is the agency identified in the signup record and subscription order. The individual accepting confirms that they are an adult with authority to bind that agency. A verified account, a manually selected agreement checkbox and the server acceptance record identify the accepting individual; this click acceptance is not represented as a government-certified digital signature.
The order identifies the selected plan, billing term, quoted price, included capacity and purchased add-ons. This agreement, including Schedule A (Data Processing Terms), and the accepted order form the contract. An individually signed amendment takes priority over conflicting standard terms; the order controls its specific commercial details, and Schedule A controls conflicts about agency personal-data processing. Mandatory law prevails.
2 Service and plan scope
VisaFit is multi-tenant software for agency administration, lead assessments, visa case processing, customer portals, documents, appointments, communications and financial records. Access to workforce management, attendance, payroll, dashboards, reports, branches and automation depends on the selected plan and enabled permissions. The current order and plan comparison describe the purchased scope.
VisaFit is not an immigration authority, legal adviser, bank or payment institution. The agency remains responsible for advice, submissions, eligibility decisions, professional authorisations and representations to its applicants. No visa, admission, employment or other third-party outcome is guaranteed.
Rishabh Softwares grants a limited right to use the service for the agency's lawful business during the trial or paid subscription. Ownership of the software and platform intellectual property remains with its respective owners.
3 Agency users and responsibilities
The agency owner manages its staff, roles, branches, integrations and customer access. The agency is responsible for authorised users' actions, appropriate access permissions, secure credentials, timely removal of departing staff and the accuracy of submitted data. Account sharing and circumvention of tenant isolation or usage controls are prohibited.
The agency must have a lawful basis and any required notices, permissions and guardian authorisations for the applicant and staff information it uploads. It must not upload malicious code, unlawful material or data it is not authorised to process, and must not interfere with another tenant or the service.
4 Trial and onboarding
New eligible agencies may start a 14-day trial after email verification and required acknowledgements. Signup does not automatically charge a payment instrument or authorize recurring payments. The owner chooses whether to buy a subscription.
The agency may request one additional seven-day trial extension from the platform owner at rshbhkataria@gmail.com. An extension is discretionary, not automatic or guaranteed, and takes effect only after approval and recording by an authorised Super Admin. Request it before expiry; it does not authorise a payment or recurring mandate.
When an unpaid trial or subscription expires, tenant access is suspended and all tenant users are prevented from signing in. Suspension does not itself delete the agency's data. The agency must contact the platform operator to resolve an expired or manually suspended account; paying an invoice does not override a security suspension.
5 Fees payment and renewals
The owner must review the plan, billing term and final amount before confirming payment. Current checkout totals include no separately added tax. Any legally required change to pricing or tax treatment must be reviewed and reflected transparently in the applicable order and invoice before confirmation; this statement is not a tax exemption representation.
Monthly or annual subscriptions are payable according to the confirmed order. Annual discounts apply as quoted for the selected plan. Add-ons have separate recurring unit prices. Mid-period add-on charges follow the application's disclosed remaining-period calculation; annual-plan additions are payable for the remaining paid term before activation.
Razorpay processes payments through its hosted checkout. The platform activates purchased capacity or paid access only after verified captured payment or an authorised offline-payment reconciliation. The agency should report an unconfirmed debit and should not pay again while reconciliation is pending.
Recurring auto-pay is optional and requires separate owner authorization of a Razorpay mandate showing its amount, frequency, start date and cycle count. Accepting this agreement is not a payment mandate. Cancel the existing mandate before changing the plan, billing dates or add-ons, then authorize the revised recurring amount. Cancelling future auto-pay does not refund past charges or shorten already-paid access.
If a one-hour annual welcome offer is shown, its additional 10% discount applies to the already-discounted annual plan price for the first annual subscription payment only, excluding add-ons. Renewals use the normal annual price disclosed at checkout. The server must accept the secure checkout request before the fixed deadline; an accepted checkout retains its quoted price while payment completes. Expired, unredeemed offers cannot start a new discounted checkout.
6 Capacity and fair use
Storage is calculated per tenant across applicable files and database records. Plan capacity and paid add-ons belong to that tenant only. Uploads and new records may be blocked when allowance is exhausted. The owner may buy capacity or delete eligible data subject to deletion safeguards and legal holds.
Internal user and assessment limits follow the purchased plan and active add-ons. Customer portal users are not internal staff seats. Capacity cannot be reduced below current usage unless a safe supported reduction process is available. Custom assessment fields do not have a separate per-field subscription fee.
Rate limits, file validation, abuse controls and reasonable maintenance restrictions protect service availability. These controls do not authorise arbitrary access to another agency's data.
7 Customer data and confidentiality
The agency retains its rights in customer and business data. It instructs Rishabh Softwares to process that data to operate, secure and support the service and approved integrations. The agency controls its applicant-facing purposes and notices; the platform separately manages account, billing, security and support information for its own disclosed purposes.
Each party must protect the other's non-public information with reasonable care and disclose it only to authorised personnel and service providers who need it, or where required by law. Information already public, independently developed or lawfully obtained without restriction is excluded.
Schedule A governs personal data processed on the agency's behalf. Necessary payment, email, anti-abuse and infrastructure providers may receive information limited to their function. The provider will maintain accurate information about its processing providers and locations, make that information available on request, and apply appropriate contractual and security controls to processing on its behalf.
8 Security support and service changes
The platform uses access controls, tenant scoping, upload validation and audit records, but no system can promise absolute security or uninterrupted operation. The parties must cooperate reasonably on suspected incidents and notify each other through agreed support channels without unnecessary delay, consistent with applicable law.
The provider may maintain and update the service. Database changes must be managed to preserve customer information. Material adverse changes to purchased functionality or commercial terms will be communicated before they apply; additional paid functionality requires the owner's confirmation. No numerical uptime, recovery-time or support-response guarantee is made unless separately agreed in writing.
9 Suspension cancellation and data return
The provider may suspend access for expiry, non-payment, unlawful use, security threats or a material breach. Where practicable and lawful, it will explain the reason and permit corrective action. Urgent security action may be taken without advance notice.
The owner may request cancellation through the available subscription controls or rshbhkataria@gmail.com. Cancelling an auto-pay mandate stops future automatic debits but does not itself terminate the subscription. Cancelling the subscription is a separate action and may end access immediately as explained in the confirmation. Review the effective cancellation date and export needed records before confirming. Cancellation does not remove amounts already due or create a refund entitlement except where mandatory law requires otherwise.
Suspension for expiry or non-payment does not itself erase agency data or start permanent offboarding. The owner may contact support for reactivation or an authorised export while login remains suspended. On permanent termination, the provider will confirm the effective termination date in writing and give the registered owner 30 calendar days from that date to request an export. A timely request will be securely fulfilled before routine source-data deletion. Active tenant business data will be deleted or anonymised within 90 calendar days after permanent termination, except where mandatory retention, a valid legal hold or a binding direction requires otherwise. The provider will communicate any such exception where lawful. Backups follow the applicable infrastructure expiry schedule, which will be supplied with the offboarding notice; they remain protected and must not restore erased data to ordinary use. Suspension is not a promise of indefinite storage: continued retention is reviewed for necessity, and any later permanent termination follows this notice and export process.
Paid subscription, renewal and add-on charges are non-refundable, including for change of mind, non-use, unused time, downgrade or voluntary cancellation. The 14-day trial is the opportunity to evaluate the service before purchasing; any discretionary seven-day extension does not create a refund entitlement. This policy does not exclude refunds, reversals, remedies or dispute rights required by applicable law or binding payment-network rules. Suspected duplicate, erroneous or unauthorised charges will be investigated through rshbhkataria@gmail.com and corrected where required; do not send card numbers, CVV, passwords or login codes.
10 Warranties responsibility and liability
Each party warrants that it has authority to enter this agreement and will comply with laws applicable to its activities. The agency remains responsible for the substance of immigration advice, applicant submissions, employment decisions and third-party services.
Except for express commitments and rights that cannot lawfully be excluded, the service is provided without a guarantee of a particular commercial or immigration outcome. Neither party excludes liability that law prohibits it from excluding.
To the extent permitted by applicable law, each party's aggregate contractual liability for ordinary claims arising from the affected service is limited to subscription fees paid or payable for that service during the twelve months preceding the event giving rise to the claim. Neither party is liable for indirect or consequential loss to the extent law permits that exclusion. These limitations do not apply to fraud, wilful misconduct, payment obligations, breach of confidentiality or data-protection obligations, or liability that cannot lawfully be limited. No statutory penalty or individual right is waived or limited by this agreement.
11 Notices disputes and general terms
Service provider: Rishabh, sole proprietor trading as Rishabh Softwares. Registered business address: 104, New Hargobind Colony, Basti Sheikh, Jalandhar, Punjab - 144002, India. Contract, support, privacy and grievance contact: Rishabh at rshbhkataria@gmail.com. Notices to the agency use its registered owner email; the agency must keep that address current.
This agreement is governed by the laws of India. Subject to mandatory statutory jurisdiction and remedies, the competent courts in Jalandhar, Punjab have jurisdiction over contractual disputes. The parties will first seek resolution through their designated contacts. This does not prevent urgent court relief or approaching a competent statutory authority, and does not require arbitration.
A failure to exercise a right is not a waiver. An invalid provision is severed only to the extent necessary, leaving the remainder effective where lawful. Neither party may assign this agreement without the other's written consent, except as permitted by law. Approved subcontracting does not remove the provider's obligations under Schedule A.
Neither party is responsible for delay caused by events beyond its reasonable control to the extent permitted by law, provided it promptly informs the other and takes reasonable mitigation steps. This does not excuse payment already due, confidentiality, security incident cooperation or mandatory legal obligations. Material contract changes will be communicated and versioned, with fresh acceptance where required; they do not rewrite historical acceptance evidence.
12 Acceptance evidence
The acceptance record retains the presented document text, version and SHA-256 hash, server timestamp in UTC, stated agency and individual identity, email verification linkage, source, request identifier, available network IP and browser user-agent. IP and user-agent are supporting evidence, not proof of personal identity or location.
Privacy acknowledgement and cookie-policy acknowledgement are separate checkbox records. They do not authorize marketing, optional analytics, card storage or recurring debit. Authorised Super Admins may review and export evidence for support, accountability or legal requests. Acceptance and payment evidence are retained only for documented contract, accounting, dispute or security purposes and applicable legal requirements; access remains restricted. Historical acceptance records are not changed when these terms are updated.
Schedule A — 1 Scope, roles and instructions
This schedule forms part of the MSA. The agency determines the purposes of applicant and workforce processing and ordinarily acts as Data Fiduciary; Rishabh Softwares acts as its Data Processor for that processing. For its own account administration, billing, security and legal-compliance purposes, the provider acts separately under its Privacy Notice. These roles depend on the actual processing, not merely the label in this agreement.
The agency's documented instructions are the accepted order, this schedule, lawful workspace configuration and authorised support requests. Processing includes collection, recording, organisation, storage, retrieval, communication, export, correction and deletion needed to supply the contracted features. The provider will not sell agency personal data or use it to train general-purpose AI models under this agreement. A new purpose or external AI integration requires a separate assessment, disclosure and lawful authorisation before data is sent.
Processing continues during the service and any justified suspension, offboarding or legal-retention period. Instructions conflicting with applicable law must be raised with the agency; the affected processing may be paused while resolved. Legally compelled disclosure is limited to what is required, with notice where lawful.
Schedule A — 2 People, information and purposes
Data subjects may include applicants, customers, guardians, agency owners, staff, managers, branch heads, vendors and other contacts entered by the agency. Depending on enabled modules, data may include names and contact details; assessment responses; passport and visa documents; education, employment and financial-support information; case and lead records; messages and appointments; staff attendance and employment records; invoices, expenses and commission records.
The agency must minimise data, restrict access and collect only information necessary for specified purposes. Especially sensitive documents, children's records and third-party financial information require additional scrutiny. Do not upload card CVV, account passwords or unnecessary identity documents. Payment instruments are entered into the payment provider's checkout, not agency notes or VisaFit support requests.
The agency is responsible for its applicant-facing notice and valid consent or other applicable lawful basis. An owner accepting the MSA is not consent on behalf of every applicant. Processing of children or persons with lawful guardians requires the applicable verification and authorisation procedures; a generic checkbox alone must not be treated as sufficient evidence.
Schedule A — 3 Confidentiality and safeguards
The provider will restrict access to authorised personnel and service providers with a business need and confidentiality obligations. Support access must be tenant-specific and recorded. Safeguards include tenant-scoped access checks, role permissions, authenticated sessions, upload and request validation, rate limiting and audit records. The provider is responsible for maintaining appropriate production encryption, key management, backup protection and recovery controls and reviewing their effectiveness.
Files and exports must be protected against public access and execution. Credentials must remain in protected server configuration or encrypted integration storage, not public code or exported business records. Security safeguards and their effectiveness must be reviewed regularly. Neither source-code checks nor this schedule constitute a security certification.
Schedule A — 4 Service providers and transfers
Only necessary providers may process agency data on documented instructions and subject to appropriate contractual and security controls. The provider will maintain a register identifying legal provider name, service, purpose, data categories, locations, access, retention and review status. It will supply the applicable register to the agency and notify material provider or location changes before they affect its data where practicable, giving the agency an opportunity to raise a reasoned data-protection objection through support.
Supabase provides the PostgreSQL database, with the primary database located in Mumbai, India (South Asia region, ap-south-1). Hostinger KVM 2 is the selected application-hosting service; its server location remains subject to deployment verification. Razorpay provides payment checkout and optional recurring-payment services. Google reCAPTCHA provides login abuse protection when enabled. Email delivery uses the platform's or agency's configured SMTP provider. Hosting, edge delivery, logs, support access, database replicas and backups can involve separate locations; a Mumbai primary database does not mean that all processing takes place in India. Contact rshbhkataria@gmail.com for the provider and location information applicable to your service.
Where the agency selects its own email, webhook or other destination, it is responsible for authorising that recipient and its instructions; the provider remains responsible for its own processing obligations. No general permission is given for unrestricted exports or onward transfers. Overseas processing must comply with applicable Indian restrictions and other binding requirements; this agreement does not promise that every provider processes data only in India.
Schedule A — 5 Requests, consent and grievances
Privacy and grievance requests may be sent to Rishabh at rshbhkataria@gmail.com or by post to the registered business address above. Include a contact email, the relevant agency and the nature of the request; do not send passwords, CVV or full identity documents in the initial request. Identity and authority will be verified proportionately, with additional evidence requested through an appropriate secure channel only when needed.
The provider will assist the agency with applicable requests for information, correction, erasure, grievance redressal, nomination and withdrawal of consent, taking account of the nature of processing and information available. Requests about agency-controlled applicant records are routed to that agency unless law requires a different response. The provider will address requests about its own account and billing processing directly.
The provider records receipt, identity checks, routing, due dates, decisions and completion. Its response target for privacy requests and grievances is 30 calendar days from receipt, with shorter mandatory deadlines taking precedence. If a complete response requires further information or lawful additional time, it will explain the reason and next steps within that period; this does not extend a statutory deadline. A refusal or legal hold must be explained where lawful. Contract cancellation, non-payment and the no-refund policy do not extinguish statutory privacy remedies. Grievances may be escalated to the competent authority under the procedure then in force.
Schedule A — 6 Personal-data incidents
The provider will inform the affected agency without undue delay after becoming aware of a personal-data breach affecting its entrusted data, provide available information on nature, timing, affected information, likely consequences, containment and recommended steps, and provide updates as the investigation develops. The agency must promptly report suspected compromise to support. The initial notification must not wait for a complete investigation.
The parties will preserve relevant evidence, restrict access and cooperate on remediation and legally required communications. The agency ordinarily handles notices for processing where it is Data Fiduciary; the provider handles its own applicable duties. Statutory reporting deadlines and regulator directions prevail over this schedule. No automatic notification to a regulator or affected individual is represented as having occurred merely because an internal incident was logged.
Schedule A — 7 Return, deletion and retention
An authorised owner can request available tenant records with record-linked attachments through support, including while suspended. The provider must verify authority and deliver exports securely to an approved recipient. Technical secrets, other tenants' data and records that cannot lawfully be disclosed are excluded or appropriately restricted. Generated export archives have their own expiry; that is not the retention period for source records.
Retention is determined by the purpose of each record, the agency's lawful instructions, applicable legal obligations and documented legal holds. Expiry suspends access without automatically deleting business data. Retention during suspension is reviewed for continuing necessity. Permanent offboarding follows the written notice and export process in section 9; source records, generated export files, security evidence and backups have separate retention treatment. The provider will explain the applicable schedule on an authorised request; there is no single statutory period for every category.
On completion of the lawful retention period or a valid erasure instruction, the provider will delete or anonymise applicable records and instruct relevant processors accordingly, except for restricted records retained under law or a documented legal hold. Backups follow the approved infrastructure expiry schedule; deletion requests must not be undone by a later restore. Completion records must distinguish application deletion from independently verified backup expiry.
Schedule A — 8 Accountability and applicable law
The provider will keep processing, access, acceptance, request and incident evidence proportionate to the service and applicable law, and make relevant compliance information available to the agency on a reasonable, confidentiality-protected request. Any agreed audit must avoid exposing other tenants' data, secrets or operational security. No unrestricted platform or database access is granted.
The Digital Personal Data Protection Act, 2023 and its rules apply to the extent in force and applicable to the processing, alongside other applicable laws. This schedule does not certify compliance, appoint the provider as a registered Consent Manager, or declare it a Significant Data Fiduciary. Changes in law, deployment, vendors or processing purposes require review of instructions, safeguards and notices.