PRIVACY NOTICE & POLICY
This Privacy Notice explains how XploroTech Solutions Private Limited (“XploroTech”, “Company”, “we”, “us”, or “our”) collects, uses, stores, shares, protects, and otherwise processes Personal Data in connection with VENTA Xploro POS, VENTA Admin, VENTA Insights, VENTA Captain, Xploro AI, related mobile applications, websites, APIs, dashboards, integrations, support services, and future VENTA-branded services (collectively, the “Services”).
This Privacy Notice should be read together with the Master Service Agreement, Data Processing Addendum, VENTA User Terms, Acceptable Use Policy, Xploro AI Addendum, AI Subprocessors & Data Use Notice, and Data Retention & Customer Exit Policy.
1. Scope of This Privacy Notice
This Privacy Notice applies to Personal Data processed by XploroTech when:
a. you visit our websites or contact us;
b. you register for, access, use, administer, support, or interact with the Services;
c. you communicate with us through email, phone, chat, support tickets, social media, demonstrations, or meetings;
d. you receive invoices, proposals, marketing communications, operational updates, security notices, or service notifications;
e. you use Xploro AI or submit information through AI-enabled features; or
f. XploroTech processes Personal Data for account management, billing, security, fraud prevention, support, legal compliance, product operations, and other legitimate business purposes.
This Privacy Notice does not replace the privacy notices, customer notices, or statutory notices that our Customers may be required to provide to their own employees, guests, customers, members, vendors, suppliers, and other individuals.
2. Data Roles
2.1 Customer-Controlled Operational Data
When a Customer uses VENTA to process business, outlet, employee, guest, reservation, invoice, inventory, loyalty, membership, supplier, delivery, or operational data, the Customer generally decides why and how that Personal Data is processed.
In that situation:
a. the Customer generally acts as the Data Fiduciary or equivalent responsible party;
b. XploroTech generally acts as a Data Processor on behalf of the Customer; and
c. the Data Processing Addendum governs XploroTech’s processing of that Customer Personal Data.
If you are a guest, diner, customer, employee, member, vendor, supplier, delivery recipient, or other individual whose Personal Data was entered by a VENTA Customer, please contact that Customer first regarding your privacy rights or questions.
2.2 XploroTech-Controlled Data
XploroTech acts as an independent Data Fiduciary or controller for Personal Data we process for our own purposes, including:
a. account registration and administration;
b. subscription management, billing, payment collection, and tax compliance;
c. sales enquiries, demos, proposals, and customer communications;
d. support, implementation, training, troubleshooting, and service management;
e. security monitoring, fraud prevention, misuse detection, and audit logging;
f. legal compliance, dispute resolution, recordkeeping, and enforcement of agreements;
g. website analytics, product analytics, and service improvement; and
h. marketing communications where permitted by applicable law.
3. Personal Data We May Collect
Depending on how you interact with the Services, we may collect or receive the following categories of Personal Data.
3.1 Account and Contact Information
This may include:
a. name;
b. business name;
c. designation or job title;
d. email address;
e. mobile number or telephone number;
f. business address;
g. billing address;
h. GSTIN or other business registration details where applicable;
i. account username, user role, Company ID, outlet ID, and user preferences; and
j. communication preferences.
3.2 Customer, Guest, Reservation, Membership and Transaction Information
Where entered into VENTA by or on behalf of a Customer, this may include:
a. customer or guest name;
b. mobile number, email address, address, or delivery details;
c. reservation details;
d. order, invoice, payment-reference, refund, discount, loyalty, membership, or credit information;
e. purchase history, menu preferences, order notes, customer feedback, and communications;
f. delivery details and recipient information; and
g. other operational information submitted by the Customer.
3.3 Employee, User and Operational Information
This may include:
a. employee or user name;
b. role, designation, outlet, department, and access permissions;
c. login history, access activity, session records, device assignment, and audit trails;
d. attendance-related information where enabled by the Customer;
e. support, training, implementation, and configuration records; and
f. activity relating to orders, invoices, voids, refunds, discounts, inventory, reservations, reports, and other authorised workflows.
3.4 Technical, Device and Usage Information
This may include:
a. IP address;
b. browser type, app version, operating system, device type, device identifier, and language settings;
c. login time, logout time, session activity, access logs, and audit logs;
d. crash reports, error logs, diagnostic information, network details, performance records, and support-related technical information;
e. pages, modules, features, reports, and functions accessed; and
f. cookies, similar technologies, analytics information, and website usage data.
3.5 Support, Communications and Training Information
This may include:
a. emails, calls, chats, tickets, screenshots, recordings, attachments, and messages shared with us;
b. support history, implementation notes, training attendance, project records, and issue-resolution records;
c. technical logs, diagnostic information, configuration details, and error messages; and
d. information voluntarily provided during demonstrations, enquiries, meetings, surveys, feedback, or events.
3.6 Billing and Payment Information
This may include:
a. invoice details;
b. billing contact details;
c. payment-reference details;
d. payment status;
e. bank-reference information supplied for payment verification or refund processing; and
f. tax and accounting records required for business operations.
VENTA does not require users to submit full payment-card numbers, CVV details, PINs, OTPs, magnetic-stripe data, passwords, API keys, private keys, or similar sensitive authentication information through ordinary VENTA workflows.
3.7 Xploro AI Information
Where Xploro AI is enabled, we may process:
a. prompts, queries, questions, instructions, and feedback;
b. AI-generated answers, reports, recommendations, summaries, SQL, code suggestions, troubleshooting guidance, and help content;
c. authorised business data selected or made available for the AI request;
d. report definitions, schema details, metadata, diagnostic data, error logs, code fragments, and support information;
e. AI usage records, model-routing records, quality feedback, error reports, and audit logs; and
f. other information submitted by authorised users for permitted AI functionality.
4. How We Collect Personal Data
We may collect Personal Data:
a. directly from you;
b. from the Customer organisation that authorises your access to VENTA;
c. from authorised users, administrators, employees, consultants, or representatives of the Customer;
d. automatically through use of the Services, website, apps, APIs, devices, logs, cookies, and analytics tools;
e. through integrated third-party services authorised by the Customer;
f. from support interactions, demonstrations, meetings, calls, training, and communications;
g. from publicly available business sources where permitted by law; or
h. from service providers, affiliates, payment providers, implementation partners, and other authorised parties.
5. Why We Process Personal Data
We may process Personal Data for the following purposes:
a. to create, manage, authenticate, secure, and administer accounts;
b. to provide VENTA POS, Admin, Insights, Captain, Xploro AI, APIs, integrations, dashboards, and related Services;
c. to process orders, invoices, reservations, memberships, loyalty transactions, inventory, reports, support requests, and other Customer-authorised workflows;
d. to provide implementation, training, onboarding, maintenance, support, troubleshooting, bug analysis, upgrades, and service communications;
e. to maintain logs, audit trails, access controls, security controls, fraud detection, misuse detection, and incident response;
f. to manage subscriptions, billing, payment collection, invoices, refunds, taxes, and account administration;
g. to investigate security incidents, fraud, misuse, policy violations, legal claims, customer complaints, and disputes;
h. to maintain and improve the performance, functionality, reliability, usability, and security of the Services;
i. to provide Xploro AI functionality, including authorised report queries, business analytics, help articles, troubleshooting, code analysis, bug analysis, and related permitted uses;
j. to comply with legal, regulatory, tax, accounting, audit, court, insurance, contractual, and lawful-authority requirements;
k. to send operational, product, support, billing, security, maintenance, policy, and service-related communications; and
l. where permitted, to send marketing, product, event, webinar, and promotional communications.
6. Consent, Withdrawal and Communication Preferences
6.1 Where we rely on consent for processing Personal Data, we will seek consent through an appropriate notice, app flow, web form, written communication, or other permitted method.
6.2 You may withdraw consent where applicable by contacting us at [PRIVACY EMAIL] or using the relevant opt-out, account, or preference-management option made available by us.
6.3 Withdrawal of consent will not affect processing completed before withdrawal, processing required by applicable law, processing necessary to provide an active Service, or processing based on another lawful basis.
6.4 You may opt out of non-essential marketing communications by using the unsubscribe link in the message or by contacting us at [MARKETING EMAIL].
6.5 You may continue to receive essential operational, account, billing, legal, security, service, or transaction-related communications where necessary.
7. Cookies and Similar Technologies
7.1 Our websites and web-based Services may use cookies, local storage, pixels, analytics technologies, and similar tools to:
a. keep you signed in;
b. remember preferences;
c. improve website performance and service usability;
d. understand usage patterns;
e. protect accounts and detect suspicious activity;
f. measure communication, campaign, and website effectiveness; and
g. provide relevant product and support content.
7.2 You may control cookies through your browser or device settings. Disabling certain cookies may affect the availability or functionality of parts of the Services.
7.3 Where legally required, we will provide an appropriate cookie notice or consent mechanism.
8. Xploro AI and AI Data Processing
8.1 Xploro AI may use XploroTech-hosted models and approved third-party AI service providers to provide authorised AI features.
8.2 Depending on the feature, AI processing may involve authorised prompts, selected business data, reports, transaction summaries, schema details, logs, error details, code fragments, support information, and AI outputs.
8.3 AI features are designed to respect applicable user permissions and tenant boundaries. AI access should be limited to data that the requesting user is authorised to access.
8.4 AI-generated outputs may be inaccurate, incomplete, outdated, biased, or unsuitable for a particular purpose. Users must review and validate AI outputs before relying on, sharing, filing, implementing, or deploying them.
8.5 Xploro AI is not a substitute for tax, legal, accounting, financial, employment, regulatory, medical, or other professional advice.
8.6 XploroTech will not use Customer Data, AI prompts, source code, schema details, support logs, or AI outputs to train a general-purpose AI model unless the Customer separately opts in through a written agreement or expressly enabled product setting.
8.7 The approved AI providers, data categories, purposes, and relevant processing information are described in the AI Subprocessors & Data Use Notice at [AI SUBPROCESSOR NOTICE URL].
8.8 Users must not submit passwords, OTPs, PINs, full payment-card details, CVV, API keys, private keys, confidential credentials, malware, or information they are not authorised to disclose.
9. How We Share Personal Data
We may share Personal Data only where necessary for the purposes described in this Privacy Notice, including with:
a. the relevant Customer organisation and its authorised users;
b. XploroTech affiliates, employees, contractors, and authorised representatives;
c. cloud-hosting, storage, backup, monitoring, security, email, SMS, communication, analytics, support, payment, accounting, AI, and infrastructure service providers;
d. implementation, support, integration, hardware, and professional-service partners acting under appropriate arrangements;
e. delivery aggregators, payment providers, accounting platforms, communication services, and other third-party integrations authorised by the Customer;
f. professional advisers, auditors, insurers, banks, payment processors, and collection service providers;
g. law-enforcement agencies, courts, regulators, government authorities, or other parties where required by law or lawful request; and
h. a purchaser, successor, affiliate, investor, lender, or adviser in connection with a merger, acquisition, financing, restructuring, sale of assets, or corporate transaction, subject to appropriate protections.
Our current approved Subprocessors are listed at https://venta-pos.com/ai-subprocessors-and-data-use/
10. International Processing and Transfers
10.1 Personal Data may be processed in India and in other countries or territories where XploroTech, its affiliates, cloud providers, Subprocessors, or approved AI providers operate.
10.2 We take reasonable steps to ensure that cross-border processing is carried out in accordance with applicable law and appropriate contractual, technical, and organisational safeguards.
10.3 Where applicable law, government direction, customer contract, or regulatory obligation requires specific storage, localisation, access, or transfer controls, the Customer must inform XploroTech before enabling the relevant Service or providing the relevant Personal Data.
11. Data Retention
11.1 We retain Personal Data only for as long as reasonably necessary for the purposes described in this Privacy Notice, including service delivery, account management, security, support, billing, tax, audit, backup, legal compliance, fraud prevention, dispute resolution, and enforcement of agreements.
11.2 Retention periods may vary depending on:
a. the type of data;
b. the purpose of processing;
c. the Customer’s subscription status;
d. legal, tax, accounting, audit, security, or regulatory requirements;
e. the need to preserve evidence for disputes, fraud prevention, or incident response; and
f. the applicable backup and disaster-recovery cycle.
11.3 Customer Data retention, export, deletion, and post-termination handling are described in the Data Retention & Customer Exit Policy at https://venta-pos.com/data-retention-and-customer-exit/
11.4 Where Personal Data is no longer required, we may delete, anonymise, aggregate, archive, or otherwise securely dispose of it, subject to lawful retention obligations.
12. Security
12.1 We use reasonable administrative, technical, organisational, and physical safeguards designed to protect Personal Data against unauthorised access, disclosure, alteration, loss, destruction, or misuse.
12.2 Security measures may include, where appropriate:
a. role-based access controls;
b. authentication controls;
c. encryption in transit;
d. logging and monitoring;
e. vulnerability management and security patching;
f. secure development and change-management practices;
g. backup, restoration, and business-continuity arrangements;
h. confidentiality obligations for personnel; and
i. Subprocessor due diligence and contractual controls.
12.3 No system, network, device, cloud environment, internet connection, or security control is completely secure. You should protect your credentials, devices, and access methods and promptly report suspected unauthorised access or security issues.
13. Your Privacy Rights and Requests
13.1 Depending on applicable law and your relationship with XploroTech or the Customer, you may have rights to:
a. request information about Personal Data processed about you;
b. request correction, completion, or updating of inaccurate Personal Data;
c. request deletion or erasure of Personal Data where applicable;
d. withdraw consent where processing is based on consent;
e. make a privacy grievance or complaint;
f. nominate another person to exercise rights where permitted by law; and
g. receive information about how to contact the relevant privacy or grievance contact.
13.2 If your Personal Data is controlled by a VENTA Customer, you should first contact that Customer. We may assist the Customer where required by law or contract.
13.3 If XploroTech controls the relevant Personal Data, you may submit a request to xploro@xplorotech.com
13.4 We may need to verify your identity and authority before responding to a request.
13.5 We may decline, limit, or defer a request where permitted or required by applicable law, where the request affects another person’s rights, where data must be retained for legal or contractual reasons, or where the request is excessive, repetitive, fraudulent, or technically impracticable.
14. Children’s Personal Data
14.1 The Services are designed for business use and are not intended for independent use by children.
14.2 Customers must not knowingly submit Personal Data of children unless they have a lawful and appropriate basis to do so and all required notices, permissions, and consents have been obtained.
14.3 Where XploroTech becomes aware that Personal Data of a child has been processed in a manner inconsistent with applicable law, we may take reasonable steps to restrict, delete, or otherwise address the relevant data.
15. Third-Party Services
15.1 The Services may contain links to, connect with, or enable use of third-party websites, payment providers, delivery platforms, communication tools, AI providers, cloud services, accounting systems, hardware systems, and other external services.
15.2 Those third parties may have their own privacy notices, terms, security practices, retention policies, and data-processing arrangements.
15.3 XploroTech is not responsible for the privacy practices of third parties except to the extent required by applicable law or our contractual obligations.
16. Changes to This Privacy Notice
16.1 We may update this Privacy Notice from time to time to reflect changes in law, regulations, technology, security practices, Services, AI features, Subprocessors, business practices, or operational requirements.
16.2 We will publish the updated version in the VENTA Legal Centre and update the effective date and version number.
16.3 For material changes, we may provide additional notice through the Services, email, dashboard, app notification, website notice, or another reasonable electronic method.
17. Contact and Grievance Redressal
For privacy requests, consent withdrawal, complaints, or grievances, contact:
Privacy / Grievance Contact: xploro@xplorotech.com
Privacy Contact Name / Designation: Shubhi Aggarwal – Director
+91 77039 82223
Grievance Response Period: 5-7 Business Days
Security Incident Reporting: xploro@xplorotech.com
Legal Notices: xploro@xplorotech.com
VENTA Legal Centre: https://www.venta-pos.com/legal
If you are not satisfied with our response, you may have the right to pursue remedies available under applicable law.


