Legal Document

Privacy Policy

This policy explains how Veloqit Technologies Private Limited collects, uses, shares, and protects personal data in connection with the Veloqit Bloom service.

Last updated: 21 June 2026

§ Introduction

Veloqit Technologies Private Limited ("Veloqit", "we", "us", or "our"), a company incorporated under the Companies Act, 2013 with its registered office at Nagpur, Maharashtra, India, operates Veloqit Bloom — a cloud-based salon management platform.

This Privacy Policy describes how we collect, use, share, retain, and protect personal data when you use our services. It applies to:

  • Salon Owners — individuals or entities who register for a Bloom account to manage their salon business.
  • Salon Customers — end-customers of salon owners whose data is processed through the Bloom platform on behalf of the salon.

By accessing or using Veloqit Bloom, you acknowledge that you have read and understood this policy. If you do not agree, please discontinue use of the service.

DPDP Act 2023: This policy is designed to comply with India's Digital Personal Data Protection Act, 2023 ("DPDP Act") and the rules made thereunder.

§ Definitions

  • Personal Data: Any data about an individual who is identifiable by or in relation to such data.
  • Data Principal: The individual to whom personal data relates.
  • Data Fiduciary: The entity that determines the purpose and means of processing personal data.
  • Data Processor: Any person who processes personal data on behalf of, and under the instructions of, a Data Fiduciary.
  • Processing: Any operation performed on personal data, whether automated or not, including collection, storage, use, disclosure, or deletion.
  • Consent: Free, specific, informed, unconditional, and unambiguous agreement of the Data Principal to the processing of their personal data.
  • Service: The Veloqit Bloom platform accessible at bloom.veloqit.com and associated APIs and mobile interfaces.

§ Who We Are: Data Fiduciary & Data Processor

Our role under the DPDP Act 2023 differs depending on whose data is being processed:

Data SubjectOur RoleImplication
Salon OwnersData FiduciaryWe determine the purpose and means of processing your registration, account, and billing data.
Salon CustomersData ProcessorWe process your customers' data strictly on your instructions. The salon owner is the Data Fiduciary for their customers.

Salon owners are responsible for obtaining lawful consent from their customers before entering their personal data into the Bloom platform, and for informing customers that Veloqit Bloom processes such data as their service provider.

§ Personal Data We Collect

4.1 — Salon Owners (Direct Relationship)

  • Full name, business name, and contact details (email address, phone number)
  • Business address and salon location(s)
  • GSTIN (Goods & Services Tax Identification Number) for invoicing
  • Payment information (processed via Razorpay — we do not store raw card data)
  • Subscription and billing records
  • Account usage data, login history, and session tokens
  • Support communications

4.2 — Salon Customers (Via Salon Owners)

  • Full name and mobile phone number
  • Visit history, appointment records, and service preferences
  • Spending history and transaction records
  • WhatsApp messaging data — inbound messages from customers parsed by AI for booking intent
  • Opt-in/opt-out status for WhatsApp notifications
  • Notes or tags added by salon staff

4.3 — Automatically Collected Data

  • IP address, device type, browser, and operating system
  • Pages visited, features used, and interaction timestamps
  • Error logs and performance metrics (via Sentry)
  • Cookies and session tokens (see our Cookie Policy)

§ Purpose of Processing

  • Service Delivery: Creating and managing your Bloom account, appointments, staff, invoices, and customer records.
  • Billing & Payments: Processing subscription fees, generating GST-compliant invoices, and managing Razorpay subscriptions.
  • WhatsApp Automation: Sending appointment confirmations, reminders, and AI-generated booking suggestions to salon customers via Twilio/WhatsApp.
  • AI Predictor Feature: Using Claude Haiku (Anthropic) to parse inbound WhatsApp messages and predict booking intent, then generating smart suggestions.
  • Customer Support: Responding to queries, bug reports, and account issues.
  • Service Improvement: Aggregated, anonymised analytics to improve product features and performance.
  • Legal & Compliance: Meeting our obligations under Indian tax law (GST), the DPDP Act 2023, the IT Act 2000, and other applicable regulations.

§ Sub-Processors & Third-Party Disclosure

We engage the following sub-processors to deliver the Bloom service. Each sub-processor is bound by data processing agreements and is required to maintain appropriate security standards:

Sub-ProcessorPurposeCountryPrivacy Notice
Supabase Inc.Database, Authentication, File StorageUSA (AWS us-east-1)supabase.com/privacy
Anthropic, PBCAI message parsing — Claude Haiku processes WhatsApp booking messagesUSAanthropic.com/privacy
Twilio Inc. / Meta PlatformsWhatsApp Business messaging via Twilio SendGridUSA / Irelandtwilio.com/privacy
Razorpay Software Pvt. Ltd.Payment processing, subscriptions, invoicesIndiarazorpay.com/privacy
Resend Inc.Transactional email (receipts, OTPs, notifications)USAresend.com/privacy
Vercel Inc.Application hosting, edge CDNUSA (multiple regions)vercel.com/legal/privacy-policy
Sentry (Functional Software Inc.)Error monitoring & performance tracingUSAsentry.io/privacy

We will notify salon owners of any material change to our sub-processor list at least 30 days before the change takes effect, by email to the registered account address.

§ Cross-Border Data Transfers

Some of our sub-processors, including Supabase (USA/AWS), Anthropic (USA), Vercel (USA), Resend (USA), and Sentry (USA), may process or store your data outside India.

Veloqit ensures that such transfers are covered by appropriate safeguards as required by the DPDP Act 2023 and rules notified by the Central Government. These include:

  • Standard Contractual Clauses (SCCs) or equivalent data transfer mechanisms.
  • Sub-processors' compliance with applicable international data protection frameworks (SOC 2, ISO 27001, GDPR where applicable).
  • Processing limited to the minimum data necessary for the stated purpose.

Razorpay processes payment data within India in compliance with RBI guidelines, including Payment Aggregator and Payment Gateway (PA-PG) regulations.

§ WhatsApp & AI Processing Disclosure

WhatsApp Messaging

Bloom's WhatsApp Automation feature sends messages (booking confirmations, appointment reminders, and re-engagement offers) to salon customers via Twilio's WhatsApp Business API, which is powered by Meta's WhatsApp platform.

  • Messages are sent only to customers whose numbers have been registered by the salon owner.
  • Customers can opt out at any time by sending STOP to any Bloom-sent WhatsApp message. Opt-out requests are processed within 24 hours.
  • Message content, delivery timestamps, and read receipts may be stored for audit and troubleshooting.

AI Booking Parser (Powered by Anthropic Claude)

When a salon customer sends an inbound WhatsApp message to the salon's Bloom-connected number, the message text is transmitted to Anthropic's Claude Haiku API for natural language processing. Claude parses the booking intent (e.g., "I want a haircut tomorrow at 3 PM") and returns a structured response that Bloom uses to auto-fill an appointment.

What is shared with Anthropic: Inbound message text only (e.g., "Book me for Sunday 2 PM"). We do not share the customer's name, phone number, or visit history with Anthropic. Anthropic does not use API inputs to train its models without explicit consent.

Anthropic's data processing is governed by their API Data Processing Agreement. Data sent to Anthropic's API is processed in the USA. Retention by Anthropic is as per their API usage policy (typically 30 days for trust & safety review).

§ Data Retention

Data CategoryRetention PeriodReason
Salon owner account dataDuration of subscription + 3 yearsContractual & tax compliance
Invoice & billing records7 years from financial year endGST Act / Income Tax Act requirement
Salon customer recordsDuration of salon's active subscriptionService delivery
WhatsApp message logs90 daysOperational troubleshooting
AI parsed message data (Bloom side)30 daysDebugging & audit
Error logs (Sentry)30 daysOperational
Auth session tokensUntil logout or 30-day expirySecurity

After the applicable retention period, personal data is securely deleted or anonymised. Anonymised and aggregated data (e.g., platform usage statistics) may be retained indefinitely.

§ Your Rights as a Data Principal

Under the DPDP Act 2023, you have the following rights:

  • Right to Access: Request a summary of personal data we hold about you and the purposes for which it is processed.
  • Right to Correction: Request correction of inaccurate, incomplete, or outdated personal data.
  • Right to Erasure: Request deletion of your personal data where processing is no longer necessary, subject to legal retention obligations.
  • Right to Grievance Redressal: Lodge a complaint with our Grievance Officer (see below). If unresolved within 30 days, you may escalate to the Data Protection Board of India.
  • Right to Nominate: Nominate another individual to exercise these rights on your behalf in the event of your incapacity or death.
Response Commitment: We will respond to all verifiable data rights requests within 7 business days. Complex requests may take up to 30 days; we will notify you of any extension.

To exercise your rights, email privacy@veloqit.com or use the in-app data settings panel. Salon customers should contact the salon owner in the first instance; the salon owner may escalate to us as their Data Processor.

§ Security

We implement industry-standard technical and organisational measures to protect personal data, including:

  • Data in transit encrypted via TLS 1.2+
  • Data at rest encrypted via AES-256 (Supabase/AWS)
  • Row-level security (RLS) policies in Supabase to prevent cross-tenant data access
  • Multi-factor authentication available for all owner accounts
  • Regular automated vulnerability scanning and dependency auditing
  • Access control policies limiting staff access to personal data on a need-to-know basis

In the event of a personal data breach that is likely to result in high risk to your rights, we will notify affected individuals and the Data Protection Board of India within the timeframes prescribed by the DPDP Act.

§ Children's Privacy

Veloqit Bloom is a B2B professional service directed at salon owners and their adult customers. We do not knowingly collect personal data from individuals under the age of 18 years. If you become aware that a minor has provided personal data through our platform, please contact us at privacy@veloqit.com and we will delete such data promptly.

Salon owners are responsible for ensuring that their use of the Bloom platform, including the entry of customer data, complies with applicable law regarding minors.

§ Policy Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will:

  • Update the "Last Updated" date at the top of this page.
  • Send an in-app notification and email to all registered salon owners at least 15 days before the change takes effect.
  • Seek fresh consent where required by the DPDP Act.

Your continued use of the Service after the effective date of changes constitutes your acceptance of the updated policy.

§ Grievance Officer & Contact

As required by the DPDP Act 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer:

Name: Shubham Jiotode

Designation: Data Protection Officer & Grievance Officer

Email: grievance@veloqit.com

Address: Veloqit Technologies Private Limited, FLAT NO 102, BUILDING C, DREAM AAWAS PANJARI FARM, Bori (Nagpur), Nagpur, Nagpur- 441108, Maharashtra, India

Response Time: Within 30 days of receipt of grievance

If your grievance is not resolved within 30 days, you may escalate to the Data Protection Board of India as per the mechanism prescribed under the DPDP Act 2023.

For general privacy enquiries: privacy@veloqit.com