Privacy Policy
Last updated: 15 August 2026
VizPass is built and operated by BeyondBoxAI Technologies Pvt. Ltd. (“we”, “us”), an Indian company. This policy explains what personal data we handle, in which role, and what you can ask us to do about it.
The two roles we play
VizPass is visitor and gate management software, so we handle personal data in three distinct capacities, and your rights run differently under each:
- For website visitors and trial signups — people who browse this site, submit the contact form or start a trial — we decide what is collected and why, so we are the data fiduciary and you deal with us directly.
- For employees of our customers — the hosts, guards and staff whose records live inside a VizPass account — the employer is the data fiduciary and we process on their instructions. Ask them first; we will help them answer.
- For people checked in at a customer's gate — if your name, phone, photo or ID number was recorded when you visited a workplace, that record belongs to that workplace, not to us. They decide what is collected, how long it is kept and who may see it. Ask the organisation whose gate you visited; if you cannot reach them, write to us and we will route it.
What we collect, and why
From website visitors and signups
- What you give us — name, work email, company name, approximate headcount and phone number when you start a trial, request a download, submit the contact form or take the HR health check. We use it to create your account, respond, and follow up on your interest.
- What the site records — pages viewed and referrers, tied to a session rather than to advertising profiles. You can decline analytics cookies from the banner, and we honour that with a two-year opt-out cookie whose only job is remembering that you said no.
Inside a customer account
- Staff records — the name, contact details, department and role of the people who work at a customer's site, entered by the employer so a visitor can be announced to the right host.
- Gate records — for each visit: who came, who they came to see, why, when they arrived and left, the ID type and number a guard checked, and a photograph taken at check-in. Also couriers, material movements and staff exit passes, each with the person who authorised them.
- Sensitive fields are encrypted at rest — identity-document numbers and bank details are stored encrypted, so a database copy alone does not expose them.
- Attendance, where the customer uses it — punch times for their own staff, and location only where the employer has switched it on and the employee has recorded consent.
- Photographs and ID captures — taken at the gate to make a pass identifiable and a register verifiable. They are held against the visit for as long as the customer keeps that register.
What we never do
- We do not sell personal data, to anyone, for anything.
- We do not use one customer's data to benefit another. Every company's data is isolated to that company by a tenancy boundary enforced in the software and covered by automated tests.
- We do not let AI write to records on its own. Every AI-drafted entry waits for a human to confirm it — that is the product's founding rule, and it is also a privacy control.
AI, honestly described
Where a customer switches on AI assistance, the relevant text or image is sent to an external model provider — currently Anthropic (Claude) and Google (Gemini) — to draft a record. Nothing is written by AI on its own: a person confirms every draft before it is saved. Providers are used under their API terms and not for training on our customers' data.
Who else touches the data (sub-processors)
These are our sub-processors — the only third parties that handle personal data on our behalf. We keep the list short and each entry has one job. Customers will find the full list, with locations and what each one sees, in Annex C of the Data Processing Agreement:
- Hosting — our application and database run on managed servers operated by Hostinger.
- Messaging — gate passes, host alerts and OTPs sent over WhatsApp go through Meta's WhatsApp Business platform; email is sent through the employer's own configured mailbox where set, or ours.
- AI model providers — as described above, only for the AI features and only the content needed for the task.
- Payments — when online payment is offered, card and bank details are entered directly with an RBI-authorised payment gateway. We never see or store card numbers.
How long we keep it, and how you leave
- Gate and staff records stay for as long as the customer's account is active, plus any period the organisation is required to retain a visitor register. Retention is the customer's decision, not ours.
- Leaving is always possible. A customer can export everything — visitors, passes, couriers, material and the audit trail — at any time, in usable formats, without asking us.
- Compressed daily backups exist for disaster recovery and are pruned on a fixed schedule; deleted data leaves the backup cycle as those backups expire.
Your rights
Under the DPDP Act you may ask us (or, for employee records, ask your employer, whom we will assist) to access, correct, or erase your personal data (the right to erasure), and you may withdraw a consent you gave — such as field-location consent — from within the app. We answer requests at the address below, and we do not make you prove more than your identity to exercise a right.
If something goes wrong
If a breach affects your personal data we will notify the affected customers and the Data Protection Board as the DPDP Act requires, tell you what happened in plain language, and what we are doing about it. Every change to a record in VizPass is written to an audit trail that cannot be edited afterwards, which is what makes an honest account of any incident possible.
Children
VizPass is workplace software for organisations, their staff and the people who visit them. It is not directed at children and we do not knowingly collect their data.
Grievances and contact
Grievance contact under the DPDP Act:
Amreesh Nehra, BeyondBoxAI Technologies Pvt. Ltd.
sales@beyondboxai.com · +91 81304 68801
We reply to privacy grievances within the timelines the law sets, and usually much faster.
Changes to this policy
When we change this policy we change the date at the top and, for material changes, tell account owners directly. We do not weaken a commitment quietly.