drishva.ai

Home / Privacy

Privacy policy

Written to cover the EU GDPR, UK GDPR, India's Digital Personal Data Protection Act and the California Consumer Privacy Act in a single document.

Last updated: August 2026

Who we are

drishva.ai is an AI visibility firm working with hospitality businesses, based in Mumbai, India. For the purposes of data protection law we act as a controller for data you provide directly to us, and as a processor where we handle personal data on behalf of a client under a data processing agreement.

What we collect

  • Information you send us. Name, work email, company or property name, city, property count and any message you include when requesting a visibility check or contacting us.
  • Correspondence. Emails and messages you send, and our replies.
  • Client engagement data. Where you become a client, information necessary to deliver the service — including access credentials you grant us to your own platforms.

What we do not collect

  • We do not use cookies. This site sets no cookies of any kind, which is why you were not shown a consent banner.
  • We do not use third-party trackers. No advertising pixels, no social media trackers, no session recording.
  • We do not load fonts or scripts from third-party networks. Typefaces are served from our own domain, so your browser makes no request to any external provider.
  • We use privacy-preserving analytics only. Aggregate page-view counts with no cookies, no cross-site tracking and no individual identification.

Why we process it, and on what basis

PurposeLawful basis (GDPR / UK GDPR)
Responding to a visibility check requestSteps taken at your request prior to entering a contract
Replying to enquiriesLegitimate interests — responding to someone who contacted us
Delivering services to clientsPerformance of a contract
Meeting legal and tax obligationsLegal obligation

Under India's DPDP Act we process personal data for the specified purposes above with your consent or where otherwise permitted for legitimate uses.

Sharing

We do not sell personal data. We do not share it for advertising. We do not trade or rent contact lists.

We share data only with service providers necessary to operate — email hosting, website hosting, accounting and payment processing — each bound by contract to process it only on our instructions.

International transfers

We are based in India. Where we process personal data originating in the European Economic Area or the United Kingdom, transfers are made under Standard Contractual Clauses, supplemented by appropriate technical and organisational measures. Clients engaging us as a processor receive a data processing agreement with those clauses annexed.

How long we keep it

  • Enquiries that do not become clients: up to 24 months, then deleted.
  • Client records: for the engagement, plus the period required by Indian tax and company law.
  • Access credentials: revoked and deleted at the end of an engagement.

Your rights

Depending on where you are located, you may have the right to access, correct, delete, restrict or object to our processing of your personal data; to receive it in a portable format; to withdraw consent; and to complain to a supervisory authority.

  • EU: your national data protection authority.
  • UK: the Information Commissioner's Office.
  • India: the Data Protection Board of India.

To exercise any right, contact us. We respond within one month, and will tell you if we need longer.

California residents

We do not sell or share personal information as those terms are defined under the CCPA and CPRA, and we have not done so in the preceding twelve months. California residents may request disclosure, deletion or correction of personal information, and will not be discriminated against for exercising those rights.

Security

We apply measures proportionate to the data we hold: encrypted devices, multi-factor authentication on all business accounts, a password manager for credential storage, least-privilege access, and revocation of access on offboarding. Where a personal data breach occurs we notify affected parties and regulators within the periods required by applicable law.

Children

This is a business-to-business service. We do not knowingly collect personal data from anyone under 18.

Changes

We update this policy as our practices or the law change. The date at the top reflects the most recent revision.