Privacy Policy
Last Updated: September 2, 2026
This Privacy Policy explains how ArohaTech ("Vista ERP", "we", "us" or "our") collects, uses, stores, protects and otherwise processes information when you visit our website, use our products or services, or otherwise interact with us.
Vista ERP respects your privacy and is committed to protecting personal information and personal data. We seek to collect and process information fairly, transparently and only for legitimate business and service-related purposes.
Vista ERP does not sell or rent personal information or Customer Data to third parties.
This Privacy Policy applies primarily to information collected through the Vista ERP website, marketing activities, enquiries, demonstrations, partner interactions and other direct interactions with Vista ERP. Additional contractual terms, including a Data Processing Agreement (DPA), may apply to personal data processed through the Vista ERP SaaS platform on behalf of our customers.
1. Information We Collect
1.1 Information You Provide
We may collect information that you voluntarily provide when you interact with Vista ERP, including when you:
- Submit an enquiry or contact form;
- Request a product demonstration;
- Request information about Vista ERP;
- Register for an account or service;
- Apply to become a Vista ERP partner;
- Subscribe to communications;
- Contact our sales or support teams;
- Participate in events, surveys or business activities; or
- Otherwise communicate with us.
Depending on the interaction, this information may include:
- Name;
- Company or organisation name;
- Business email address;
- Telephone or mobile number;
- Job title or professional role;
- Business address;
- Country, state, region or city;
- Business and customer requirements;
- Partnership information;
- Sales and business-development information; and
- Other information voluntarily provided by you.
1.2 Information Collected Automatically
When you visit our website or use our online services, certain technical information may be collected automatically, including:
- IP address;
- Browser type and version;
- Operating system and device information;
- Approximate location information;
- Pages visited and website interactions;
- Referring website or URL;
- Date and time of access;
- Website performance information;
- Cookies and similar technologies; and
- Other technical or usage information.
2. How We Use Information
We may use information collected by us for legitimate and appropriate business purposes, including:
- Providing, operating and maintaining our website and services;
- Responding to enquiries and requests;
- Providing product demonstrations;
- Managing customer and partner relationships;
- Providing customer and technical support;
- Improving our products, services and website;
- Understanding website usage and service performance;
- Managing sales and business-development activities;
- Sending service-related communications;
- Sending marketing communications where permitted;
- Measuring and improving marketing campaigns;
- Maintaining security and preventing misuse;
- Detecting and investigating fraud or unauthorised activity;
- Complying with applicable legal obligations; and
- Protecting our legal rights and legitimate business interests.
3. Cloud Infrastructure and Customer Data
Vista ERP is a cloud-based software service. Depending on the services used by a customer, information and data entered, uploaded, generated or otherwise processed through Vista ERP may be stored and processed on cloud servers and other technology infrastructure operated by Vista ERP and/or authorised third-party infrastructure and service providers.
Such information may include business records, transactions, documents, files, user information, customer information, employee information, supplier information and other information that a Vista ERP customer or its authorised users choose to enter into or process through the platform ("Customer Data").
3.1 Customer-Controlled Data
Where Customer Data is entered into Vista ERP by or on behalf of a customer, the customer generally determines the purposes for which that information is collected and processed.
Depending on the nature of the processing and applicable law, the customer may act as the data controller or equivalent data fiduciary, while Vista ERP may act as a data processor, service provider or equivalent data intermediary.
Customers are responsible for ensuring that they have the appropriate rights, permissions, notices and lawful basis required to collect and process personal data through the Vista ERP platform.
3.2 Limited Access to Customer Data
Vista ERP does not routinely access, view, inspect, monitor or use the private business information, personal information, documents, records or other Customer Data entered or uploaded by customers or their authorised end users for purposes unrelated to providing, securing, maintaining or supporting the services.
Access to Customer Data by Vista ERP personnel is restricted through appropriate technical and organisational controls and is intended to be limited to authorised personnel with a legitimate business need.
Where technically and operationally feasible, access is governed by principles such as least privilege, need-to-know, role-based access, authentication, authorisation and appropriate logging and monitoring.
3.3 Circumstances Where Limited Access May Be Required
Although Vista ERP does not routinely access Customer Data, limited and controlled access may be necessary in specific circumstances, including:
- Providing customer-requested technical or support assistance;
- Investigating and resolving service or system issues;
- Detecting, preventing or investigating security incidents;
- Investigating fraud, abuse or unauthorised activity;
- Maintaining and securing the Services and infrastructure;
- Diagnosing system failures or performance issues;
- Complying with applicable legal or regulatory requirements;
- Protecting the rights, safety or security of Vista ERP, customers or users; or
- Other purposes expressly authorised under the applicable agreement.
Where such access is required, Vista ERP seeks to limit the scope and duration of access to what is reasonably necessary for the relevant purpose and to apply appropriate confidentiality and security controls.
3.4 System Telemetry and Product Improvement
Vista ERP may collect and use technical, operational and usage information generated through the Services to maintain, secure, monitor and improve the performance, reliability and functionality of our products.
Such information may include system performance metrics, application events, error information, aggregated usage statistics, service health information, configuration information and other technical telemetry.
Where appropriate, Vista ERP seeks to use aggregated, anonymised, de-identified or otherwise non-identifying information for analytics, product improvement, capacity planning, service optimisation and research and development.
We seek to avoid using Customer Data or directly identifiable personal information for product analytics or improvement purposes where such use is not necessary for providing, securing or maintaining the Services.
3.5 Cloud Providers and Subprocessors
Vista ERP may use reputable third-party cloud infrastructure providers, hosting providers, database providers, storage providers, security providers and other technology service providers to operate and deliver the Services.
These providers may process or store Customer Data on behalf of Vista ERP where necessary to provide the Services. We seek to select service providers that provide appropriate security, confidentiality and data protection commitments and, where required, enter into appropriate contractual arrangements.
3.6 Backups and Business Continuity
Customer Data may be included in backups and disaster-recovery systems maintained to support service availability, data resilience and business continuity.
Backup copies may remain available for a limited period after information has been deleted from active systems, subject to applicable retention and disaster-recovery practices.
4. Marketing and Advertising
Vista ERP may use third-party analytics, marketing, advertising and remarketing services to understand our audience, measure campaigns and promote our products and services.
Such services may help us:
- Understand website traffic and usage;
- Measure advertising performance;
- Understand campaign effectiveness;
- Create relevant audience segments;
- Conduct remarketing or retargeting;
- Measure conversions; and
- Improve marketing activities.
Vista ERP does not sell or rent personal information to advertising, marketing or other third parties.
Third-party marketing and advertising platforms may process information in accordance with their own privacy policies and terms. Where consent is required under applicable law, we will seek appropriate consent before using relevant tracking or advertising technologies.
5. Cookies and Similar Technologies
We may use cookies, pixels, tags, scripts, local storage and similar technologies to operate our website, remember preferences, understand usage, improve performance, maintain security and support marketing activities.
These technologies may be used for:
- Essential website functionality;
- Security;
- Analytics;
- Performance monitoring;
- Remembering preferences;
- Marketing;
- Advertising; and
- Remarketing.
You may control or disable certain cookies through your browser, device settings or available cookie-management controls. Disabling certain cookies may affect website functionality.
6. Third-Party Service Providers
We may use trusted third-party service providers to support our business and deliver our website and Services.
These providers may support:
- Website hosting and cloud infrastructure;
- Cloud storage and computing;
- Analytics;
- Customer relationship management;
- Email and communications;
- Marketing automation;
- Advertising and remarketing;
- Customer support;
- Form processing;
- Security and fraud prevention;
- Performance monitoring; and
- Other legitimate business operations.
Such providers may process information on our behalf and are expected to handle information in accordance with applicable contractual, security and legal requirements.
7. Information Sharing and Disclosure
We do not sell or rent personal information or Customer Data.
We may disclose or provide access to information where reasonably necessary to:
- Service providers working on our behalf;
- Cloud and infrastructure providers;
- Marketing and analytics providers;
- Professional advisers;
- Legal, regulatory or governmental authorities where required;
- Protect our rights, property or safety;
- Investigate fraud, abuse or security incidents;
- Enforce our agreements and policies; or
- Support a merger, acquisition, restructuring or transfer of business assets.
We seek to limit such disclosure or access to information reasonably necessary for the applicable purpose.
8. Data Security
Vista ERP takes reasonable technical and organisational measures designed to protect personal information and Customer Data against unauthorised access, disclosure, alteration, loss, misuse or destruction.
Depending on the nature of the information and associated risks, these measures may include:
- Access controls;
- Role-based access;
- Authentication and authorisation mechanisms;
- Encryption where appropriate;
- Secure transmission;
- Need-to-know access restrictions;
- Logging and monitoring;
- Backup and recovery procedures;
- Security monitoring and testing;
- Confidentiality obligations; and
- Controls over third-party service providers.
No method of electronic transmission, storage or processing can be guaranteed to be completely secure. Accordingly, while we take reasonable measures to protect information, we cannot guarantee absolute security.
9. India Data Protection and Privacy
Vista ERP is committed to complying with applicable Indian laws and regulations relating to privacy and protection of personal data.
Depending on the nature of the processing and the applicable implementation requirements, this may include the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, and other applicable laws, regulations and directions relating to information technology, cybersecurity and data protection.
The Indian digital personal data protection framework includes obligations relating to matters such as notice, consent or other permitted grounds for processing, security safeguards, rights of individuals, grievance handling, data retention and other data-protection responsibilities, subject to the applicable law and commencement of the relevant provisions.
Where Vista ERP processes personal data on behalf of a customer, the respective responsibilities of the customer and Vista ERP may be further defined through applicable agreements, including a Data Processing Agreement where appropriate.
Nothing in this Privacy Policy is intended to exclude or limit any right or protection that cannot lawfully be excluded or limited under applicable Indian law.
10. GDPR and Personal Data Protection
Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") applies to our processing of personal data, Vista ERP seeks to process such data in accordance with applicable GDPR requirements and other applicable data-protection laws.
For purposes of this Privacy Policy, "Personal Data" means information relating to an identified or identifiable individual. The term "PII" (Personally Identifiable Information) may also be used in this Policy where appropriate.
10.1 Data Protection Principles
Where applicable, Vista ERP seeks to follow principles including:
- Lawfulness, fairness and transparency;
- Purpose limitation;
- Data minimisation;
- Accuracy;
- Storage limitation;
- Integrity and confidentiality; and
- Accountability.
10.2 Lawful Bases for Processing
Where GDPR applies, personal data may be processed on an applicable lawful basis, including consent, performance of a contract, compliance with a legal obligation, protection of vital interests where applicable, or legitimate interests where permitted and appropriate.
10.3 Data Subject Rights
Where GDPR applies, individuals may have rights regarding their personal data, subject to applicable legal conditions and exceptions. These may include:
- Right to be informed;
- Right of access;
- Right to rectification;
- Right to erasure in applicable circumstances;
- Right to restriction of processing in applicable circumstances;
- Right to object to certain processing;
- Right to data portability where applicable;
- Right to withdraw consent where processing is based on consent; and
- Rights relating to certain automated decision-making and profiling.
Requests may be submitted using the contact details provided in this Privacy Policy.
10.4 Data Protection by Design and Default
Where appropriate, Vista ERP seeks to incorporate privacy and data protection considerations into the design, development and operation of its systems and Services.
This may include access restrictions, data minimisation, security controls, privacy considerations during product development and appropriate safeguards for personal data.
10.5 Pseudonymisation and Anonymisation
Where appropriate, Vista ERP may use aggregation, pseudonymisation, de-identification or anonymisation techniques to reduce privacy risks.
Pseudonymised information that can still be associated with an identifiable person may continue to constitute personal data under applicable law.
10.6 International Transfers
Vista ERP may use cloud infrastructure and service providers located in countries other than the country in which information was originally collected.
Where GDPR or other applicable laws regulate international transfers, Vista ERP seeks to use appropriate legally recognised safeguards and transfer mechanisms.
11. Controller, Processor and Customer Responsibilities
The role of Vista ERP in relation to personal data depends on the nature of the processing activity.
In relation to information collected directly through our website, marketing activities and business interactions, Vista ERP may determine the purposes and means of processing and may therefore act as a data controller or equivalent entity under applicable law.
In relation to Customer Data processed through the Vista ERP SaaS platform on behalf of a customer, the customer may determine the purposes and means of processing and Vista ERP may act as a data processor or equivalent service provider.
Where appropriate, processing of Customer Data may be governed by a separate Data Processing Agreement, customer agreement or other contractual arrangement.
Customers remain responsible for determining the appropriate lawful basis for processing information under their control and for providing required notices to their employees, customers, vendors, users and other data subjects, where applicable.
12. Data Retention
We retain personal information and other information only for as long as reasonably necessary for the purposes for which it was collected, or as required or permitted by applicable law, contractual obligations, security requirements or legitimate business needs.
Customer Data may be retained for the duration of the applicable customer relationship and for appropriate periods thereafter in accordance with contractual obligations, backup procedures, legal requirements and legitimate business requirements.
When information is no longer required, we may securely delete, anonymise or otherwise dispose of it in accordance with applicable retention practices.
13. Privacy Choices and Data Rights
Depending on applicable law, you may have rights regarding personal information held by us.
You may contact us to request access to, correction of, or deletion of personal information, or to raise an objection or other privacy-related request where applicable.
You may also unsubscribe from marketing communications using the unsubscribe mechanism provided in the communication or by contacting us.
Certain information may need to be retained where required by law, necessary to establish or defend legal claims, required for security, or otherwise necessary for legitimate business purposes.
14. Marketing Communications
We may send business, product, promotional or marketing communications where permitted by applicable law.
You may opt out of marketing communications at any time by following the unsubscribe instructions included in the communication or by contacting us.
Opting out of marketing communications will not necessarily prevent us from sending important transactional, service, security or account-related communications.
15. Security Incidents and Data Breaches
Vista ERP maintains processes intended to identify, investigate and respond to security incidents involving information processed through our systems.
Where applicable law or contractual obligations require notification of a personal data breach or security incident to a regulatory authority, customer or affected individual, Vista ERP will take steps consistent with the applicable requirements.
Customers using Vista ERP as a SaaS platform are responsible for notifying Vista ERP of relevant incidents involving their accounts or Customer Data where such notification is required under the applicable customer agreement or DPA.
16. Third-Party Websites and Services
Our website or Services may contain links to third-party websites, applications or services.
We are not responsible for the privacy practices, security, content or policies of third-party websites or services. We recommend reviewing the privacy policy of any third-party service before providing personal information.
17. Children's Privacy
Vista ERP is a business-focused software platform and our website and Services are not directed toward children.
We do not knowingly collect personal information from children where prohibited by applicable law. If you believe that a child has provided personal information to us, please contact us so that appropriate action can be taken.
18. International Data Processing
Depending on our infrastructure, service providers and business operations, information may be processed or stored in countries other than the country in which it was originally collected.
Where applicable law requires safeguards for international transfers, Vista ERP seeks to implement appropriate legally recognised mechanisms and contractual safeguards.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, business practices, technology, applicable laws or privacy practices.
When we make changes, we will update the "Last Updated" date displayed at the beginning of this Privacy Policy.
We encourage you to review this Privacy Policy periodically to remain informed about how we handle information.
20. Contact Us
If you have questions about this Privacy Policy, our privacy practices, personal data processing, Customer Data or your privacy rights, you may contact us using the details below:
ArohaTech IT Services Pvt. Ltd.
Website: www.arohatech.com
Privacy Email: [email protected]
Address: RM 1810, Galaxy Blue Sapphire Plaza, Sector 4, Greater Noida - 201318, UP, India
21. General Disclaimer
This Privacy Policy is intended to describe Vista ERP's general privacy and data-protection practices. It does not constitute legal advice and does not create contractual rights beyond those expressly provided under applicable law or written agreements.
Depending on the nature of the Services, customer relationship, data processing activities and applicable jurisdiction, additional contractual terms, security documentation, privacy notices or Data Processing Agreements may apply.
Where there is a conflict between this Privacy Policy and a separately executed agreement governing the processing of Customer Data, the applicable agreement will govern to the extent provided in that agreement.