HomePrivacy
Trust

Privacy &
data security.

What we collect, why we collect it, and exactly how your company's field data is protected — written plainly, not in legal fog. Last updated: October 2026.

1 · What we collect

This website collects only what you type into the demo request form: your name, company, work email, phone number, industry, field-team size and your message. We use it for one thing — responding to your request. Nothing else is captured: no analytics trackers, no advertising pixels, no cross-site identifiers.

Inside the product, your company's data is what your team puts in — field visits, orders, GPS tracks, inventory, invoices and staff accounts. That data belongs to your organization, not to us; we process it only to run the service for you.

2 · Legal basis & your rights — everywhere you operate

We process form submissions on the basis of your consent (you chose to contact us) and, for customers, the contract to provide the service. Wherever you are, you can ask us to:

  • Access the personal data we hold about you
  • Correct anything inaccurate
  • Delete your data (subject to what we must keep for legitimate records)
  • Export your data in a usable format, and withdraw consent anytime

These rights cover GDPR (EU/UK), India's Digital Personal Data Protection Act 2023, CCPA/CPRA (California), and equivalent regimes elsewhere — write to sales@visaler.com and we respond within 30 days.

3 · Data security — how client data is protected

  • Tenant isolation at the database layer — Postgres row-level security binds every row to its organization. There is no shared namespace and no query path that crosses tenants; isolation is enforced by the database itself, not just application code.
  • Encrypted in transit and at rest — all connections run over TLS; data at rest sits on encrypted volumes managed by our cloud providers.
  • Admin-controlled access — there is no public sign-up. Every user account is created by your own organization admin under your unique org code, so access is provisioned, not discovered.
  • Least-privilege roles — field reps, managers, HQ roles and distributors see only what their role requires, enforced server-side.
  • Device data safety — the offline-first app queues field actions locally and syncs over encrypted channels; nothing sensitive leaves the device unencrypted.

4 · Infrastructure security — where your data lives

  • ISO/IEC 27001-certified infrastructure — Visaler runs on enterprise cloud providers that maintain ISO/IEC 27001 certification for their infrastructure and operations — physical security, network controls and provider-side compliance are inherited from them.
  • Managed cloud controls — provider firewalls, DDoS mitigation, redundancy and monitoring are supplied by the cloud platforms we deploy on.
  • Data location — deployments run in the regions we provision for your organization; tell us if you need a specific region for regulatory reasons.

ISO/IEC 27001 certifications are held by the respective cloud providers for their infrastructure and services.

5 · Sharing, retention & transfers

We never sell or share your data for marketing. Information moves only where needed to deliver the service: our cloud providers (hosting) and our transactional email path (Google Workspace, which delivers form submissions to our sales inbox). That's the full list.

Retention: demo-request emails are kept while your inquiry is active and removed when it closes. Product data is retained for the life of your subscription and deleted or exported on termination — your choice.

International transfers: where data crosses borders, it travels under the cloud providers' contractual and certified safeguards. For EU/UK personal data this relies on the providers' standard contractual clauses and certified frameworks.

6 · Cookies, children & changes

Cookies: this website uses no tracking or advertising cookies — only what's technically needed to serve the pages. The product uses session cookies strictly for keeping your staff logged in.

Children: Visaler is a business product; it is not directed at children and we don't knowingly collect their data.

Changes: if this policy changes, the updated version is posted here with a new date. Material changes to how customer data is handled are notified to organization admins directly.

Questions or a rights request?

Write to sales@visaler.com — include your name, company and what you need (access, correction, deletion, export). We answer within 30 days, usually much faster.