Privacy Policy
How Vistora HRMS collects, uses, protects, and gives you control over information across our web, Android, and iOS experiences.
1. Scope
This policy applies to Vistora HRMS, the Vistora web application, and the official Vistora mobile applications distributed through Google Play and the Apple App Store. Vistora is an employee and workforce-management platform operated by Ahanova AI Technologies. The organisation that provides your account is the data controller for its workforce records; Vistora processes that information to provide the service.
2. Information we collect
Depending on the features enabled by your organisation and your choices, we may process:
- Account and identity details such as name, employee ID, email, phone number, role, company and login credentials.
- Workforce records such as attendance, leave, payroll, payslips, recruitment, documents, interview activity and approvals.
- Medical representative information such as doctors, locations, visit assignments, visit reports and expense claims.
- Device and technical information such as operating system, app version, diagnostics, network status and crash information.
- Precise device location only when you affirmatively continue an attendance punch or use a location-enabled MR visit feature. Attendance coordinates and any resolved address are saved with the attendance record. Vistora does not track location in the background.
- Information you submit, including descriptions, attachments, expense details and support requests.
3. How we use information
- Authenticate users and maintain secure sessions.
- Deliver attendance, leave, payroll, recruitment, MR and other requested HRMS functionality.
- Apply organisation permissions, approval workflows and tenant isolation.
- Calculate authorised attendance, payroll, expenses and statutory or policy-related records.
- Provide support, troubleshoot errors, improve reliability and notify you about important service or app updates.
- Meet legal obligations, prevent misuse, protect the service and enforce our terms.
4. When information is shared
Information is shared only as needed to operate the service: with your organisation’s authorised administrators and approvers; with service providers that host, secure, analyse or deliver the platform under confidentiality obligations; when required by law or to protect rights and safety; or when you direct us to share it. We do not sell personal information.
For an attendance punch in the Vistora mobile app, the app may ask the device’s built-in Android or iOS geocoding service to turn punch coordinates into a readable address. The platform service may process those coordinates under its own service terms. Vistora does not send employee identity or attendance details to a separate geocoding API. The app submits any resulting address together with the punch to Vistora, where it is stored with the attendance record and shown to the employee and authorised tenant HR/Admin and relevant supervisor according to their permissions. Browser attendance captures coordinates only and does not perform reverse geocoding. Vistora does not track location in the background.
5. Security and retention
We use access controls, tenant scoping, encrypted connections, secure authentication storage and audit trails appropriate to the service. No online service can promise absolute security, so please protect your credentials and report suspected misuse promptly. Workforce records are retained according to your organisation’s instructions, contractual needs and legal obligations; account and security records may remain for as long as reasonably necessary to maintain service integrity.
6. Your choices and permissions
You may review or correct profile information through Vistora where available, request assistance from your organisation’s administrator, and withdraw device permissions through Android or iOS settings. Withdrawing location permission may prevent location-validated attendance or visit submission, but does not affect unrelated features. You may also request access, correction or deletion through your organisation, subject to applicable law and record-retention requirements.
Push notifications
Notifications may be used for approvals, workflow updates, reminders and security messages. You can manage notification permissions in your device settings.
7. Contact us
For privacy questions or requests, contact your organisation’s Vistora administrator first. You may also contact Ahanova AI Technologies at wecare@ahanova.in. Please include your organisation, account email, and the nature of your request. Do not send passwords or sensitive documents by email.
We may update this policy when the service or legal requirements change. The latest version will always be published on this page.