Legal

Privacy Policy

Effective date: 1 August 2026
Product: CalliVisit
Controller: Callidora Technology Private Limited (“Callidora”, “we”, “us”, or “our”)

1. Introduction

This Privacy Policy explains how Callidora Technology Private Limited collects, uses, shares, and protects personal information when you use CalliVisit, our visitor management platform for facilities (websites, staff dashboards, kiosks, digital visitor passes, and related messaging).

This policy is provided so that Meta / Facebook / WhatsApp Business reviewers, customer organisations, visitors, and staff can understand our practices. By using CalliVisit, you acknowledge this Privacy Policy.

2. Who this applies to

  • Customer organisations (companies that subscribe to CalliVisit for their sites)
  • Staff users (admins, reception, guards, hosts / employees who sign in)
  • Visitors and invitees (people who check in, receive invites, OTP codes, or visit passes)
  • Website visitors to callivisit.com and related pages

3. Information we collect

Depending on how CalliVisit is used, we may process:

3.1 Visitor and invite data

  • Name, mobile number, email (if provided)
  • Company / organisation name, purpose of visit, host details
  • Visit date, time, location, entrance, and room
  • Photos captured at check-in for badges and security records
  • Form responses, signatures, and similar compliance fields
  • QR pass tokens and visit status (pending, approved, checked in/out)

3.2 Staff account data

  • Name, work email, role, and optional mobile number
  • Authentication identifiers and session information
  • Notification preferences and access assignments

3.3 Messaging and communications data

  • Phone numbers used to send WhatsApp or SMS messages (invites, OTP verification codes, host arrival alerts, approval requests)
  • Message delivery metadata and status (for example sent, delivered, failed), template names, and limited error information for support and billing
  • Message content is limited to approved template variables needed to operate the service (we do not use WhatsApp for marketing spam)

3.4 Technical and usage data

  • IP address, browser/device type, approximate timestamps
  • Log data for security, debugging, and service reliability
  • Push notification tokens when staff enable browser/device push

We do not knowingly collect data from children under 13. CalliVisit is intended for workplace visitor management.

4. How we use personal information

We process personal information to:

  • Provide visitor check-in, host approval, badges, and occupancy views
  • Send transactional messages via WhatsApp Business Cloud API and/or SMS (invites, OTPs, host alerts, approval actions)
  • Authenticate staff and secure customer workspaces
  • Maintain audit logs, reports, and security (including blacklist checks)
  • Provide customer support and improve product reliability
  • Comply with legal obligations and enforce our terms
  • Measure usage of included message allowances for billing support

We process data based on: performance of a contract with the customer organisation; legitimate interests in operating a secure facility product; consent where required (for example certain messaging or cookies); and legal compliance.

5. WhatsApp, Meta, and Facebook Platform data

CalliVisit integrates with Meta WhatsApp Business Cloud API (and related Meta developer products) so customer organisations can send transactional WhatsApp messages to visitors and staff.

  • When a message is sent, phone numbers and template parameters are transmitted to Meta / WhatsApp to deliver the message.
  • Meta processes such data under its own terms and policies (including the WhatsApp Business and Meta Platform terms). See Meta’s Privacy Policy.
  • We use WhatsApp for operational visitor-management messages only, not to sell personal data or build unrelated advertising profiles.
  • Customer organisations are responsible for having a lawful basis and appropriate notice/consent to message recipients on WhatsApp where required by Meta policy or local law.
  • Platform credentials (for example access tokens and app secrets) are stored securely on our systems and are not shared with end users.

If Meta provides Platform Data to us in connection with our app (for example webhook delivery statuses or interactive button replies for visit approval), we use that data only to operate CalliVisit as described in this policy and Meta’s Platform Terms.

6. How we share information

We may share personal information with:

  • The customer organisation that invited or checked in the visitor (their authorised staff see visit records for their site)
  • Service providers who help us host and operate the product (for example cloud database/hosting, email delivery, SMS gateways, and Meta/WhatsApp for messaging)
  • Authorities when required by law or to protect rights, safety, and security

We do not sell personal information. Processors act on our instructions and are expected to protect data appropriately.

7. Data retention

We retain personal information for as long as needed to provide CalliVisit to the customer organisation, maintain security and audit records, resolve disputes, and meet legal requirements. Retention periods may vary by customer contract and local security or labour regulations. When a customer account is closed, we delete or anonymise personal data within a reasonable period, except where retention is required by law.

8. Security

We use administrative, technical, and organisational measures designed to protect personal information, including access controls, encrypted transport (HTTPS), and restricted staff access. No method of transmission or storage is completely secure; please contact us if you believe your account or data has been compromised.

9. Your rights and how to request data deletion

Depending on applicable law, you may have rights to access, correct, update, restrict, or delete personal information, or to object to certain processing.

How to request deletion or other privacy requests: follow the step-by-step instructions on our Data Deletion Instructions page, or email info@callivisit.com with the subject line “Privacy / data deletion request”, your name, mobile number or email, and the organisation/site if known. We typically respond within 30 days after verification.

Staff users may also ask their organisation’s CalliVisit admin to update or remove their staff profile. Visitors may contact the host organisation that collected their details at the gate, or contact us at the email above.

Where Meta Platform Terms require deletion of Platform Data upon a valid user request, we will delete such data unless a law prevents us from doing so.

10. International transfers

CalliVisit may be hosted on cloud infrastructure that processes data in India and/or other countries. Where data is transferred internationally, we take steps appropriate to the transfer and applicable law.

11. Third-party links

CalliVisit may contain links to third-party sites (for example maps links on visitor passes). Their privacy practices are governed by their own policies.

12. Changes to this policy

We may update this Privacy Policy from time to time. The “Effective date” at the top will change when we do. Continued use of CalliVisit after an update means the revised policy applies, except where consent or notice is required by law.

13. Contact us

Callidora Technology Private Limited
Product: CalliVisit
Privacy / support email: info@callivisit.com
Company website: www.callidoratechnology.com
Phone / WhatsApp: +91 99155 21444