BESPEAKK PRIVACY POLICY
Version: 1.0
Effective Date: 25 July 2026
Company
SVAAPTA IT-Ally Solutions Private Limited
Registered Office:
National Plaza, S7, RC Dutt Road,
Aradhana Society,
Vishwas Colony,
Alkapuri,
Vadodara,
Gujarat – 390007,
India
Email: bespeakk@outlook.com
1. INTRODUCTION
This Privacy Policy ("Policy") describes the manner in which SVAAPTA IT-Ally Solutions Private Limited, operating under the brand name BeSpeakk ("Company," "BeSpeakk," "we," "our," or "us"), collects, receives, stores, accesses, uses, processes, transfers, discloses, secures, retains, and otherwise handles Personal Data, Business Data, Operational Data, and other information obtained through the BeSpeakk platform, including all related websites, mobile applications, desktop software, APIs, cloud infrastructure, locally deployed software, hybrid deployments, integrations, and associated services (collectively, the "Services").
The Company is committed to maintaining the confidentiality, integrity, and availability of Customer Data while complying with applicable laws governing privacy, information technology, electronic commerce, cybersecurity, and data protection, including but not limited to the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and applicable rules and regulations issued thereunder.
By accessing, browsing, registering for, subscribing to, installing, integrating with, or otherwise using the Services, the Customer acknowledges that it has read, understood, and agreed to the collection and processing of information in accordance with this Policy.
2. DEFINITIONS
For purposes of this Policy, unless the context otherwise requires:
"Account" means a registered profile created for accessing the Services.
"Administrator" means the individual authorized by a Customer to manage the Customer's BeSpeakk account.
"Business Data" means information relating to a Customer's business operations, including restaurant details, hotel information, menus, inventory, billing records, orders, reservations, customer databases, employee information, analytics, reports, and operational records.
"Customer" means any individual, company, restaurant, hotel, hospitality establishment, enterprise, franchise, organization, or legal entity subscribing to or using the Services.
"Customer Data" means all information submitted, uploaded, stored, generated, processed, or maintained by the Customer through the Services.
"Personal Data" means any information relating to an identified or identifiable natural person.
"Processing" includes collecting, recording, organizing, storing, adapting, retrieving, consulting, using, disclosing, transmitting, combining, restricting, erasing, destroying, or otherwise handling information.
"Services" means all software, products, applications, APIs, integrations, websites, mobile applications, desktop software, dashboards, cloud services, locally deployed software, hybrid deployments, and related technology provided by the Company.
3. SCOPE OF THIS POLICY
This Policy applies to all users of the Services, including but not limited to:
- Restaurant owners
- Hotel owners
- Hospitality businesses
- Cafés
- Cloud kitchens
- Multi-location enterprises
- Franchise operators
- Administrators
- Managers
- Employees
- Cashiers
- Waitstaff
- Kitchen staff
- Delivery personnel
- Customers placing orders
- Website visitors
- Mobile application users
- API users
- Third-party integration users
This Policy governs information processed through:
- BeSpeakk Restaurant CommerceOS
- BeSpeakk Hospitality CommerceOS
- QR Ordering Platform
- POS System
- Billing Software
- Inventory Management
- CRM Modules
- Loyalty Programs
- Kitchen Display System (KDS)
- WhatsApp Ordering
- Reservation System
- Online Ordering
- Customer Feedback Module
- Business Analytics Dashboard
- Mobile Applications
- Desktop Applications
- APIs
- Cloud Infrastructure
- Local Installations
- Hybrid Deployments
4. INFORMATION WE COLLECT
Depending upon the Services used, we may collect the following categories of information.
4.1 Business Information
The Company may collect information including but not limited to:
- Business name
- Trade name
- GST Number
- PAN Number
- Business registration details
- Address
- Branch information
- Business category
- Restaurant type
- Hotel classification
- Contact numbers
- Email addresses
- Website
- Social media links
- Tax configuration
- Operational settings
4.2 Owner Information
We may collect:
- Name
- Email address
- Mobile number
- Business designation
- Authentication credentials
- Account preferences
- Profile information
4.3 Employee Information
Where entered by the Customer, the Services may process:
- Employee name
- Employee ID
- Role
- Contact information
- Attendance records
- Shift information
- Salary configuration
- Login credentials
- Access permissions
- Operational activities
The Customer acknowledges that it is solely responsible for obtaining all necessary permissions, consents, or legal authorizations from its employees prior to entering such information into the Services.
4.4 Customer Information
Customers using BeSpeakk-powered businesses may provide:
- Name
- Mobile number
- Email address
- Delivery address
- Reservation information
- Loyalty information
- Order history
- Preferences
- Feedback
- Reviews
- Communication history
4.5 Order Information
The Services may collect and process:
- Orders
- Invoices
- Bills
- Receipts
- Payment references
- Discounts
- Coupons
- Taxes
- GST information
- Table information
- Kitchen tickets
- Delivery information
- Reservation details
- Booking history
- Cancellation history
4.6 Device and Technical Information
The Company may automatically collect:
- IP address
- Browser type
- Device model
- Device identifiers
- Operating system
- Language settings
- Access timestamps
- Error logs
- Diagnostic reports
- Application usage statistics
- Session information
- Network information
Such information is primarily used for security, diagnostics, fraud prevention, system optimization, and service improvement.
4.7 Payment Information
Payments are processed through third-party payment service providers, including Razorpay. The Company does not store complete payment card numbers, CVV values, or banking credentials on its servers.
Payment processors may independently collect and process financial information in accordance with their respective privacy policies and regulatory obligations.
4.8 Communications
The Company may collect communications exchanged through:
- Customer Support
- WhatsApp Business integrations
- Live Chat
- Support tickets
- Telephone calls (where legally permitted)
- Product demonstrations
- Training sessions
- Feedback forms
5. INFORMATION COLLECTED AUTOMATICALLY
When the Services are accessed, the Company may automatically generate and collect technical information relating to system usage, performance, diagnostics, security events, application logs, authentication attempts, and service interactions. Such information is used exclusively for operational, security, maintenance, compliance, analytics, and product improvement purposes.
6. INFORMATION RECEIVED FROM THIRD PARTIES
The Company may receive information from third-party service providers and integrations authorized by the Customer, including but not limited to:
- Razorpay
- WhatsApp Business API providers
- Firebase
- Google services
- SMS gateway providers
- Email delivery services
- Identity verification providers
- Cloud infrastructure providers
Information received from such providers shall be processed solely for the purposes for which it was supplied and in accordance with applicable contractual obligations.
7. PURPOSES OF PROCESSING
The Company shall collect, process, use, store, analyze, transmit, disclose, retain, and otherwise handle Personal Data and Customer Data solely for legitimate business purposes and in accordance with applicable law.
Without limitation, the Company may process information for the following purposes:
7.1 Provision of Services
To establish, configure, operate, maintain, administer, and continuously improve the Services provided through the BeSpeakk Platform.
This includes, without limitation:
- Restaurant management
- Hotel management
- Point-of-Sale (POS)
- Billing
- Kitchen Display System (KDS)
- QR Ordering
- Online Ordering
- Reservations
- Table Management
- Inventory
- CRM
- Loyalty Programs
- Customer Feedback
- Business Analytics
- Multi-Branch Management
- Staff Management
- Franchise Operations
7.2 Customer Account Management
The Company may process information to:
- Create Accounts
- Authenticate Users
- Verify identity
- Manage subscriptions
- Manage user permissions
- Configure business settings
- Maintain access controls
- Provide technical assistance
7.3 Transaction Processing
Customer information may be processed to facilitate:
- Order processing
- Billing
- Invoice generation
- GST calculations
- Payment reconciliation
- Refund management (where legally applicable)
- Subscription renewals
- Financial reporting
7.4 Service Communications
The Company may communicate with Customers regarding:
- Account notifications
- Security alerts
- System maintenance
- Software updates
- Product announcements
- Billing reminders
- Subscription renewals
- Customer support
- Service interruptions
- Feature releases
7.5 Security and Fraud Prevention
Information may be processed to:
- Detect unauthorized access
- Prevent fraud
- Prevent cyber-attacks
- Detect suspicious activities
- Maintain audit logs
- Investigate security incidents
- Protect system integrity
- Ensure platform stability
7.6 Compliance
The Company may process information to comply with:
- Applicable laws
- Court orders
- Regulatory requests
- Government investigations
- Tax obligations
- Accounting requirements
- Law enforcement requests
- Legal proceedings
7.7 Product Improvement
The Company may use aggregated and anonymized information for:
- Product development
- Performance optimization
- User experience enhancement
- Artificial Intelligence features
- Machine Learning
- Statistical reporting
- Business analytics
No Personal Data shall be disclosed publicly through such analyses.
8. LEGAL BASIS FOR PROCESSING
Where required by applicable law, the Company processes information on one or more of the following legal bases:
- Performance of contractual obligations.
- Compliance with legal obligations.
- Legitimate business interests.
- Customer consent, where applicable.
- Protection of vital interests.
- Prevention and detection of fraud.
- Protection of legal rights.
- Regulatory compliance.
Where consent forms the basis for processing, such consent may be withdrawn by the Customer at any time, subject to legal and contractual limitations.
9. CUSTOMER DATA OWNERSHIP
The Company expressly acknowledges that all Customer Data remains the exclusive property of the Customer.
Except for the limited rights expressly granted under this Policy and the applicable Terms of Service, nothing contained herein shall operate to transfer ownership, title, intellectual property rights, database rights, trade secrets, or proprietary interests in Customer Data to the Company.
The Customer retains exclusive ownership of, without limitation:
- Customer database
- Menu data
- Inventory records
- Employee records
- Billing information
- Financial reports
- Customer profiles
- Reservations
- Order history
- Loyalty information
- Analytics generated from Customer Data
- Business configurations
- Uploaded documents
- Images
- Custom settings
The Company shall not sell Customer Data.
The Company shall not claim ownership of Customer Data.
The Company shall process Customer Data solely for providing the Services.
10. DEPLOYMENT MODELS
The BeSpeakk Platform supports multiple deployment models.
10.1 Local Deployment
Where the Services are deployed exclusively on Customer-controlled infrastructure:
- Customer Data shall remain stored on Customer-controlled servers or devices.
- The Company shall not receive operational data unless expressly authorized by the Customer.
- No cloud synchronization shall occur unless enabled by the Customer.
- The Customer assumes responsibility for backups, local security, infrastructure maintenance, disaster recovery, and hardware availability unless otherwise agreed in writing.
10.2 Cloud Deployment
Where the Services are hosted on cloud infrastructure:
The Company may process information necessary to:
- Host the Services
- Synchronize business information
- Maintain backups
- Provide disaster recovery
- Improve system reliability
- Deliver software updates
- Enable remote access
- Generate reports
Cloud-hosted Customer Data shall remain subject to this Policy.
10.3 Hybrid Deployment
For hybrid deployments:
Certain information may remain on local infrastructure while selected information may synchronize with cloud infrastructure based upon Customer configurations.
Synchronization settings shall be controlled by the Customer.
11. DISCLOSURE OF INFORMATION
The Company shall not sell, rent, lease, trade, or commercially exploit Customer Data.
Information may only be disclosed under the following circumstances.
11.1 Service Providers
The Company may disclose limited information to trusted third-party service providers including:
- Razorpay
- Firebase
- WhatsApp Business API providers
- Cloud hosting providers
- Email delivery providers
- SMS providers
- Analytics providers
- Security vendors
Such providers shall only receive information necessary for providing their respective services.
11.2 Legal Requirements
The Company may disclose information where required:
- by law;
- pursuant to a valid court order;
- in response to lawful governmental requests;
- to comply with regulatory obligations;
- to protect legal rights;
- to investigate fraud;
- to prevent criminal activity;
- to protect public safety.
11.3 Business Transfers
In the event of:
- merger;
- acquisition;
- restructuring;
- insolvency;
- corporate reorganization;
- sale of assets;
Customer information may be transferred as part of the transaction, subject to applicable confidentiality obligations and applicable law.
12. DATA SECURITY
The Company implements commercially reasonable administrative, organizational, technical, and physical safeguards designed to protect Customer Data against unauthorized access, disclosure, alteration, destruction, or loss.
Such safeguards may include:
- Encryption of data in transit where applicable
- Role-based access controls
- Multi-factor authentication (where supported)
- Password hashing
- Audit logging
- Network firewalls
- Continuous monitoring
- Vulnerability management
- Secure software development practices
- Access reviews
- Security updates
- Backup procedures
- Disaster recovery planning
While the Company endeavors to employ industry-recognized security measures, no method of transmission over the Internet or method of electronic storage can be guaranteed to be completely secure. Accordingly, the Company does not warrant that unauthorized access, data loss, or cybersecurity incidents will never occur.
13. INTERNATIONAL DATA TRANSFERS
Where the provision of the Services requires the transfer, storage, or processing of information outside the jurisdiction in which the Customer is located, the Company shall take reasonable measures to ensure that such transfers are carried out in accordance with applicable law and appropriate contractual, technical, or organizational safeguards.
14. DATA RETENTION
The Company shall retain Customer Data, Personal Data, Business Data, Operational Data, and other information only for as long as necessary to fulfill the purposes described in this Policy, comply with applicable legal obligations, resolve disputes, enforce contractual rights, maintain business continuity, or satisfy regulatory requirements.
Unless otherwise required by applicable law:
- Customer Data shall be retained for the duration of the active subscription.
- Upon expiration or termination of the subscription, Customer Data may be retained for a limited period to facilitate restoration requests, legal compliance, audit obligations, or dispute resolution.
- The Customer may request deletion of Customer Data in accordance with applicable law.
- Backup copies may remain in encrypted archival systems for a reasonable period before permanent deletion.
- Certain accounting, taxation, and regulatory records may be retained for the period prescribed under applicable law.
The Company reserves the right to anonymize data for statistical, analytical, research, and product improvement purposes, provided that such anonymized information no longer identifies any individual or Customer.
15. CUSTOMER RIGHTS
Subject to applicable law, Customers and Data Principals may exercise the following rights:
15.1 Right to Access
Request confirmation regarding whether Personal Data is being processed and obtain access to such information.
15.2 Right to Correction
Request correction of inaccurate, incomplete, outdated, or misleading Personal Data maintained by the Company.
15.3 Right to Update
Request updates to Personal Data where required to maintain accuracy.
15.4 Right to Erasure
Request deletion of Personal Data where:
- the information is no longer required;
- consent has been withdrawn;
- processing is unlawful; or
- deletion is required under applicable law.
The Company may decline deletion where retention is legally required or necessary to establish, exercise, or defend legal claims.
15.5 Right to Withdraw Consent
Where processing is based on consent, such consent may be withdrawn at any time by contacting the Company.
Withdrawal of consent shall not affect the lawfulness of processing undertaken before such withdrawal.
15.6 Right to Object
Customers may object to specific categories of processing where permitted under applicable law.
15.7 Right to Data Portability
Where technically feasible and legally applicable, Customers may request a copy of Customer Data in a structured, commonly used, and machine-readable format.
16. DATA DELETION REQUESTS
Requests for deletion may be submitted through:
Email: bespeakk@outlook.com
The Company may require reasonable verification of identity before acting upon any request.
Deletion requests shall be processed within a commercially reasonable period, subject to legal, contractual, regulatory, taxation, security, and operational requirements.
17. COOKIES AND TRACKING TECHNOLOGIES
The Company's websites and applications may utilize cookies, web beacons, pixels, local storage technologies, session identifiers, and similar technologies for purposes including:
- User authentication
- Session management
- Remembering user preferences
- Security
- Fraud prevention
- Website performance
- Analytics
- Service optimization
- Error diagnostics
Customers may configure browser settings to disable or reject cookies; however, certain features of the Services may become unavailable or function improperly.
Where legally required, the Company shall obtain consent before placing non-essential cookies.
18. THIRD-PARTY WEBSITES AND SERVICES
The Services may contain links to third-party websites, applications, payment gateways, social media platforms, or other online services.
The Company does not own or control such third-party services and shall not be responsible for:
- their privacy practices;
- security measures;
- content;
- availability;
- policies; or
- data processing activities.
Customers are encouraged to review the privacy policies of all third-party services before providing Personal Data.
19. CHILDREN'S PRIVACY
The Services are designed primarily for business and commercial use.
The Company does not knowingly collect Personal Data directly from children in violation of applicable law.
Where the Company becomes aware that Personal Data has been collected from a child without appropriate legal authorization, the Company shall take reasonable steps to delete such information promptly.
20. CONFIDENTIALITY
The Company recognizes that Customer Data may include confidential and commercially sensitive information.
Except as expressly permitted under this Policy, required by law, or authorized by the Customer, the Company shall not disclose confidential Customer information to any third party.
Employees, contractors, consultants, and service providers authorized to access Customer Data shall be subject to appropriate confidentiality obligations.
21. CHANGES TO THIS POLICY
The Company reserves the right to amend, modify, update, replace, or revise this Privacy Policy at any time to reflect:
- changes in applicable law;
- regulatory guidance;
- technological developments;
- security requirements;
- new products or services;
- business operations; or
- operational practices.
Where material changes are made, the Company may notify Customers through the Platform, email, website notices, or other reasonable communication channels.
Continued use of the Services after the effective date of the revised Policy shall constitute acceptance of the updated Policy.
22. GRIEVANCE REDRESSAL
Questions, concerns, complaints, or requests relating to this Privacy Policy or the processing of Personal Data may be directed to:
Privacy & Grievance Officer
BeSpeakk
SVAAPTA IT-Ally Solutions Private Limited
National Plaza, S7, RC Dutt Road, Aradhana Society, Vishwas Colony, Alkapuri, Vadodara, Gujarat – 390007, India
Email: bespeakk@outlook.com
The Company shall make commercially reasonable efforts to acknowledge and address grievances within the timelines prescribed under applicable law.
23. GOVERNING LAW
This Privacy Policy shall be governed by and construed in accordance with the laws of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and other applicable laws.
24. JURISDICTION
Subject to applicable law, any dispute arising out of or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the competent courts located in Vadodara, Gujarat, India.
25. SEVERABILITY
If any provision of this Privacy Policy is held by a court or competent authority to be invalid, illegal, or unenforceable, the remaining provisions shall continue in full force and effect.
26. NO WAIVER
Failure by the Company to enforce any provision of this Privacy Policy shall not constitute a waiver of that provision or any other rights available under applicable law.
27. ENTIRE POLICY
This Privacy Policy constitutes the entire understanding between the Company and the Customer with respect to the collection, processing, use, disclosure, retention, and protection of Personal Data through the Services and supersedes all prior representations or understandings on the same subject matter, except where supplemented by additional contractual agreements.
28. CONTACT INFORMATION
SVAAPTA IT-Ally Solutions Private Limited
Operating under the brand name BeSpeakk
Registered Office:
National Plaza, S7, RC Dutt Road,
Aradhana Society, Vishwas Colony,
Alkapuri, Vadodara, Gujarat – 390007, India
Support & Privacy Email:
bespeakk@outlook.com
