General information
Viritala provides AI integration and automation solutions to businesses. This privacy policy describes processing of personal data related to our services, website interactions and support. It outlines what data we collect, the purposes for processing, legal bases where applicable, how data is shared and how individuals can exercise their rights. The policy applies to visitors to the Viritala website and clients using our platform.
Key definitions
This section defines terms used in the policy to clarify the types of data and processing activities. Definitions are provided to help readers identify which provisions apply to them, and how different categories of information are treated in the context of Viritala services.
Data collection
We collect data that is necessary to provide the Service, maintain accounts, communicate with users, and improve product performance. Data collection categories are set out below and include information provided directly by users, data generated automatically and data obtained from third parties when relevant.
Data you provide directly
When you contact Viritala, register for an account, request a quote or use our platform, we collect the information you supply. This enables account management, billing, support and service delivery.
- Contact details such as name, business email address and telephone number (+60123872567)
- Company information including business name and Business ID (e.g., 445695644006) and billing details
- Account credentials and profile information submitted during registration
- Content and configuration data uploaded to the platform for automation and integration tasks
- Communications with Viritala, including support requests and feedback
- Contractual and procurement information provided in the course of engaging Viritala services
Automatically collected data
We collect technical and usage data automatically when you access the website or use the platform. This helps improve reliability, detect issues and maintain security for our services.
- IP address and approximate location information
- Device and browser type, operating system version and user agent string
- Usage metrics such as pages visited, feature usage, API call logs and timestamps
- Performance and error logs generated by the application
- Cookie identifiers and settings stored on the device
- Aggregated analytics data used for product improvement
Data received from third parties
In some cases Viritala receives data from third parties to deliver services or support integrations. We limit third-party collection to what is necessary for operational or contractual purposes.
- Identity and contact information shared by business partners or resellers as part of an onboarding process
- Technical data from third-party identity providers when single sign-on is enabled
- Supplier and subcontractor data used for fulfillment of contracted services
Purposes of processing
We process personal data for legitimate business purposes required to provide and improve our services, and to comply with legal obligations. Processing is conducted with appropriate safeguards and limited to data necessary for each purpose.
- Provision of the platform, APIs and integration services and related account management
- Customer support, incident management and communications about service status
- Billing, invoicing and fraud prevention related to purchases or subscriptions
- Security, auditing, monitoring and protection of systems and data
- Product development, improvement and analytics based on aggregated usage data
- Compliance with legal obligations and responding to lawful requests from authorities
- Onboarding and integration work necessary to configure clients' automation workflows
- Marketing communications where consent has been obtained and managed in accordance with applicable law
Legal bases for processing
Where applicable law requires identification of a legal basis, we rely on one or more of the following. The specific basis depends on the context of the processing activity and the relationship with the data subject.
- Performance of a contract: processing necessary to provide services under a client agreement
- Legal compliance: processing required to meet legal or regulatory obligations
- Legitimate interests: processing to operate, secure and improve the platform, where those interests are not overridden by the rights of data subjects
- Consent: where required for specific marketing or analytics practices, consent will be requested and recorded
Data subject rights and GDPR-related information
Individuals located in jurisdictions covered by data protection laws such as the GDPR may have specific rights in relation to their personal data. Viritala provides mechanisms to exercise those rights and responds in accordance with applicable timelines.
- Right of access: request a copy of personal data processed by Viritala
- Right to rectification: request correction of inaccurate or incomplete personal data
- Right to erasure: request deletion of personal data where processing is no longer necessary and no legal retention requirement applies
- Right to restriction: request limitation of processing in certain circumstances
- Right to data portability: obtain personal data in a structured, commonly used and machine-readable format where processing is carried out by automated means
- Right to object: object to processing based on legitimate interests, subject to applicable legal requirements and balancing
Sharing of personal data
Viritala limits data sharing to situations necessary for service delivery, legal compliance, or where a client instructs us to share data. When sharing occurs, recipients are selected based on purpose and subject to contractual safeguards.
- Service providers and subcontractors who perform functions on our behalf, such as hosting, analytics and payment processing
- Third-party connectors and integration partners where the client authorizes a connection to external systems
- Legal and regulatory authorities when required by applicable law or to respond to lawful requests
- Business partners and resellers involved in onboarding or support, subject to confidentiality obligations
- Affiliated entities for corporate administration and service coordination
- Auditors and professional advisors under confidentiality terms to support compliance and operational reviews
International data transfers
Viritala may transfer data to jurisdictions outside the country of origin to provide global infrastructure and support. Transfers are conducted in accordance with applicable law and safeguards to protect personal data.
When personal data is transferred internationally, appropriate safeguards such as standard contractual clauses, data processing agreements and technical measures are used to protect the data in transit and at rest.
Data retention
Viritala retains personal data only as long as necessary for the purposes set out in this policy, or as required by law. Retention periods vary by data type and usage context.
Account information and contract records are retained for the duration of the customer relationship and for a reasonable period afterward to meet legal and accounting obligations.
Support messages and correspondence are retained for service continuity and quality purposes, typically for a period aligned with account retention unless otherwise requested or required by law.
System and audit logs are retained according to security and operational requirements, with access limited to authorized personnel for troubleshooting, security and compliance objectives.
When data is no longer required, we take steps to securely delete or anonymize it. Clients may request deletion of their account data in accordance with contractual terms and applicable law.
Security measures
Viritala maintains organizational, technical and administrative controls to protect personal data against unauthorized access, accidental loss, or unlawful processing. Security measures are periodically reviewed and improved in response to operational changes and emerging threats.
- Encryption of data in transit (TLS) and encryption at rest for stored sensitive data where applicable
- Access controls, role-based permissions and multi-factor authentication for privileged accounts
- Regular security testing, logging, monitoring and incident response procedures
User rights
To exercise rights related to your personal data, or for questions about how data is processed, please contact Viritala using the details below. Requests will be processed in accordance with applicable law and internal procedures and we may require verification of identity before responding.
- Right to access: You can request a copy of personal data that Viritala holds about you and receive information on how it is processed.
- Right to rectification: You may ask Viritala to correct inaccurate or incomplete personal information that relates to you.
- Right to deletion: Subject to legal and contractual limits, you can request that Viritala delete personal data that is no longer necessary for the purposes for which it was collected.
- Right to restriction of processing: In certain circumstances you may ask Viritala to restrict the processing of your personal data while a dispute is resolved.
- Right to data portability: Where processing is based on consent or a contract and is carried out by automated means, you may request a copy of your personal data in a structured, commonly used, machine-readable format.
- Right to object: You may object to processing based on legitimate interests or direct marketing. Viritala will review such requests and inform you of the outcome.
- Right to withdraw consent: If processing is based on consent, you can withdraw that consent at any time; withdrawal does not affect processing conducted prior to withdrawal.
- Right to lodge a complaint: If you believe your rights are not being respected, you may contact Viritala or file a complaint with a relevant supervisory authority in Malaysia.
How to exercise your privacy rights
To exercise any of the rights listed above, submit a request to Viritala with sufficient information to verify your identity and to locate the relevant records. Provide a description of the information you seek and the action you request. Requests may be subject to verification steps and, where permitted by law, reasonable administrative fees for repetitive or manifestly unfounded requests.
Viritala aims to acknowledge receipt of privacy requests within 5 business days and to provide a substantive response within 30 calendar days. Complex requests may require additional time; you will be informed if an extension is needed and the reason for it.
Marketing communications and preferences
Viritala may send informational updates, product announcements, and event invitations where you have opted in or where permitted by applicable law. Marketing communications will identify the sender and include information on how to modify your preferences. Marketing content may reference Viritala services provided via the domain aqriala.digital.
You can opt out of marketing messages at any time by using the unsubscribe link in the message, by updating your communication preferences in your account settings, or by contacting Viritala support. Opt-out instructions will be processed within a reasonable time; transactional messages may continue where required for service delivery.
Children's privacy
Viritala services are intended for business and professional use. We do not knowingly collect personal data from children under the age of majority in the relevant jurisdiction for account creation or paid services. If we learn that we have collected such information without parental permission, we will take steps to delete it in accordance with applicable law.
External links and third-party services
Pages and communications from Viritala may include links to third-party websites, services, or integrations. Viritala is not responsible for the privacy practices or content of third parties. Review the privacy policies of linked sites before providing personal information. Integrations that process personal data will be described where applicable in the service documentation.
Changes to this privacy policy
Viritala may update this privacy policy to reflect operational, regulatory, or legal changes. Material changes will be posted on the aqriala.digital website with an updated effective date. Users are encouraged to review the policy periodically to stay informed about how personal data is managed.