Legal

Privacy Notice

HR Shastra, trading as HR Shastra, is the data controller for the personal data described below.

Last updated 28 August 2026

1. Data we collect and why

  • Identity and contact data (name, business email address): to create your account, verify that you are using a business mailbox, and communicate with you. Legal basis: performance of a contract.
  • Authentication data (one-time codes, session records, login timestamps): to sign you in securely and detect abuse. Legal basis: contract and legitimate interests in security.
  • Research inputs and saved sessions (company scope, geographies, problem descriptions, validation choices): to provide the Service and store your work. Legal basis: performance of a contract.
  • Support messages: to answer your enquiries. Legal basis: legitimate interests.
  • Usage and technical data (pages viewed, feature events, device identifiers, IP address, error logs): to keep the Service secure, diagnose faults and improve the product. Legal basis: legitimate interests.
  • Subscription status: to grant access to paid features. Legal basis: contract and legal obligation.

We do not ask for special category data. Please do not enter employee-identifying HR data into research fields.

2. Who we share data with

  • Service providers and subprocessors: hosting, database and authentication infrastructure, AI model and research providers, email delivery, error monitoring — all bound by contract to process data only on our instructions.
  • Professional advisers (legal, accounting) where necessary.
  • Authorities where required by law or to protect our rights.

We do not sell personal data and do not use it to train third-party models.

3. International transfers

Our providers may process data outside your country, including outside the UK and EEA. Where that happens we rely on adequacy decisions or Standard Contractual Clauses together with appropriate technical safeguards.

4. Retention

Account and access records are kept while your account is active and for up to 24 months afterwards to handle disputes and meet legal obligations. Saved research sessions are kept until you delete them or your account closes, plus a 30-day export window. Billing records are kept as long as tax law requires. Logs are kept for up to 12 months. Data is deleted or anonymised once no longer needed.

5. Your rights

Subject to applicable law you may request access to your data, correction, erasure, restriction of processing, portability, and object to processing based on legitimate interests. Where we rely on consent you may withdraw it at any time. Contact satrajit@viscap-cs.com and we will respond within one month. If you are in the UK or EEA you may also complain to your supervisory authority.

6. Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, row-level access controls, least-privilege service credentials, business-email verification and audit logging of access changes.

7. Cookies and local storage

We use strictly necessary cookies and browser storage to keep you signed in, remember your language preference and preserve in-progress research. We do not use advertising cookies. Any analytics we introduce will be limited to aggregate product usage, and you can clear or block storage in your browser settings — doing so will sign you out.