Skip to content

Privacy Policy

Varcio Privacy Policy

What personal data we collect, why we use it, who receives it, how long we keep it, and how you can exercise your rights, including under India's Digital Personal Data Protection Act 2023.

Last updated

1. Who we are and what this covers

Varcio provides a cloud-cost management platform. This notice explains how we handle personal data when you visit our website, create or use an account, contact us, or when an organisation uses the service and personal data about you is part of what it puts in.

We act in two different roles, and the difference matters for how you exercise your rights:

  • Our own data about you (your account, sign-in and billing details, support requests, status-page subscription, and website use). We decide why and how this is used. We are the data fiduciary and this notice applies directly.
  • Data an organisation puts into the service (for example a colleague's name in a resource tag, a support ticket, or an uploaded document). That organisation decides why and how it is used. We process it on its instructions as its data processor, under our Data Processing Agreement. If your request concerns that data, we pass it to the organisation and tell you we have.

2. Personal data we collect

We collect only what we need for the purposes in section 4.

  • Account and identity: name, work email, phone number (if you give one), company name, role, country, sign-in identifiers, and the details of any sign-in provider you use (Google or GitHub).
  • Security and device: IP address, browser and device signals, session records, multi-factor and passkey enrolment data, and audit events of what was done in your account.
  • Billing: subscription and invoice records, payment status, tax details you provide, and references from our payment processors. Card and bank details are entered with the payment processor and are not stored by us.
  • Support and communications: tickets, messages, attachments, emails, complaints, and requests you make under this notice.
  • Content in the service: cloud inventory and billing metadata, resource tags (which can include names or email addresses of owners), assistant conversations, and documents you upload.
  • People who have not signed up: an invited colleague's name and email, a status-page subscriber's email, and prospects who contact us.

We do not knowingly collect payment-card numbers, government identity numbers or health data, and ask you not to submit them.

3. Where it comes from

From you, from your use of the service, from the cloud accounts, identity providers and tools your organisation connects, and from your organisation's administrators, who may invite you or set up your account.

4. Why we use it

We use personal data only for these purposes, and each is limited to the data it needs. Where the law requires your consent, we ask for it and you can withdraw it (section 9). Otherwise we rely on the uses the law permits, such as data you give us voluntarily to receive the service, and compliance with legal obligations.

  • Create and run your account, sign you in, and keep it secure, including detecting misuse and investigating incidents.
  • Provide the service your organisation subscribed to, including analysis, recommendations, reports, notifications and the assistant.
  • Bill for the service and keep the records tax and company law require.
  • Give support and answer your questions and requests.
  • Send service messages: security alerts, invitations, approvals, and (where you have not turned them off) product notices about your own workspace.
  • Meet our legal duties, including incident reporting to authorities, and establish or defend legal claims.
  • Improve the reliability and quality of the service using aggregate, de-identified measures. We do not use your content to train machine-learning models, we do not sell personal data, and we do not use it for advertising.

5. Who receives it

We share personal data only with service providers that help us run the service, and only what they need. We publish the current list, what each receives, and where it is located on our Trust Center, and we give customers 30 days' notice of changes (see the Data Processing Agreement). They include our cloud host, AI model providers, email delivery, payment processors, and sign-in providers.

We also share data with the third-party systems you or your organisation connect and instruct us to use (for example a chat or ticketing tool), with our professional advisers, and with courts, regulators or law-enforcement authorities where the law requires it.

AI features send the question and the workspace context needed to answer it to the model providers listed on the Trust Center. Changes to your cloud accounts follow the approval rules your workspace sets.

6. Where it is stored and transferred

The region where we host personal data, and any transfer outside India, are stated on the Trust Center and kept current. We follow India's Digital Personal Data Protection Act 2023, including any restriction the Government notifies on transfers to particular countries, and we give customers notice before moving where their data is hosted.

7. How long we keep it

We keep personal data no longer than the purpose needs, and erase it when the purpose is served, unless the law requires us to keep it. In practice:

  • Account and workspace data is kept while the account is active. When an organisation is closed there is a 30-day window to export, after which its records and uploaded files are deleted; backups and earlier file versions expire within 7 days.
  • Sign-in session records, recognised-device records and one-time verification records are kept only for the short periods listed on the Trust Center.
  • Audit records are kept for at least one year and for the period of the organisation's plan, whichever is longer.
  • Processing logs and the personal data in them are kept for at least one year, as India's data-protection rules require for security investigations, and then erased.
  • Invoices and payment records are kept as accounting law requires, without a link to a closed organisation.

8. How we protect it

We use encryption in transit and at rest, role-based access, multi-factor and passkey sign-in, tamper-evident audit logs, and backups. The specific, dated measures are on the Trust Center. If personal data is involved in a breach, we notify the authorities and affected people as the law requires, following a written procedure that includes reporting to India's CERT-In within six hours.

9. Your rights and how to use them

You can ask us to:

  • Access a summary of the personal data we process about you and who it has been shared with.
  • Correct, complete or update data that is inaccurate or incomplete.
  • Erase data we no longer need for the purpose it was collected, or that you gave on consent you now withdraw.
  • Withdraw consent to processing that relies on it. It is as easy to withdraw as to give.
  • Nominate another person to exercise these rights if you die or cannot act.
  • Complain about how we handled your data or a request (grievance redressal).

Use the privacy request form, or email support@varcio.com with the subject "Privacy request". You get a reference number straight away. We may ask you to confirm your identity so that we never give your data to someone else. We answer within 30 days; the law allows a maximum of 90 days, and if we cannot meet 30 we tell you why and when.

If you are not satisfied with our answer, ask for a review by a different person on the same thread. If the matter is still unresolved you may complain to the Data Protection Board of India once it is operating; the law asks you to use our grievance process first. We keep a record of requests and outcomes for 24 months.

10. Children

The service is for business users and is not directed at anyone under 18. If we learn that we hold a child's personal data without a parent or guardian's verifiable consent, we delete it.

11. Cookies and similar technologies

We use only cookies and browser storage that are needed to sign you in, keep your session secure, and remember basic preferences. We do not use advertising cookies or third-party analytics. Our payment providers may set their own cookies on their checkout pages. If you block essential cookies the service will not work.

12. Contact and grievances

Privacy questions, data requests and grievances go to our Privacy Lead through the privacy request form or support@varcio.com. To report a security concern, write to security@varcio.com.

13. Changes to this notice

We update this notice when the service, our practices or the law change. The date at the top shows the current version; for a material change we tell account administrators by email before it takes effect.

Exercise your data rights

To ask for access, correction or erasure of your data, to raise a grievance, or to withdraw consent, use the privacy request form. You get a reference number and the date by which we will respond.

Make a privacy request
General support
support@varcio.com
Billing and invoice questions
billing@varcio.com

Signed-in customers can also use the in-product Support page for account-specific issues.

Back to top

  • Varcio is a digital software service. No physical goods are shipped.
  • Cloud-provider usage and infrastructure charges remain billed by the relevant cloud provider.
  • If a signed order form, MSA, or enterprise agreement exists, that document controls over these public pages to the extent of any conflict.