Privacy Policy
We're committed to protecting your personal information and being transparent about what we collect, how we use it, and who we share it with.
1. Who We Are
VISION AI is operated by VisionTwice ("we", "us", or "our"), a technology company providing AI-powered customer support automation services. Our platform enables businesses to turn their documentation into an intelligent, always-on support agent.
For privacy-related inquiries, contact us at privacy@visiontwice.com.
2. Information We Collect
2.1 Account & Registration Data
- Full name and email address when you create an account
- Business name and website URL
- Payment information (processed securely by our payment provider โ we do not store card details)
- Communications you send us, including support requests
2.2 Usage & Platform Data
- Documents, PDFs, help articles, and URLs you upload to train your AI agent
- Chat and email messages processed by your AI agent (end-user conversations)
- Dashboard interactions, feature usage, and configuration settings
- API requests, response logs, and accuracy analytics
2.3 Technical & Device Data
- IP address, browser type, operating system, and device identifiers
- Log files including access timestamps and error reports
- Cookies and similar tracking technologies (see our Cookie Policy)
- Referring URLs and pages visited within our platform
2.4 End-User Data (Your Customers)
When your customers interact with the VISION AI chat widget or email auto-responder, we process conversation data on your behalf as a data processor. You remain the data controller responsible for your customers' data. We process this data solely to deliver the service.
3. How We Use Your Information
| Purpose | Legal Basis |
|---|---|
| Providing and maintaining the VISION AI platform | Contract performance |
| Processing payments and managing billing | Contract performance |
| Training your AI agent on uploaded documents | Contract performance |
| Sending service updates, maintenance notices, and security alerts | Legitimate interest |
| Improving our models and platform features | Legitimate interest |
| Sending product newsletters and marketing emails (if opted in) | Consent |
| Complying with legal obligations | Legal obligation |
| Preventing fraud and abuse | Legitimate interest |
4. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We share data only in the following circumstances:
- Service Providers: Cloud hosting (e.g., AWS/GCP), payment processors, email delivery providers, and analytics services โ all operating under data processing agreements
- AI Infrastructure: Underlying large language model providers used to power the AI agent (data is processed only to generate responses, not retained for model training by third parties)
- Legal Compliance: When required by law, court order, or to protect our legal rights
- Business Transfers: In the event of a merger, acquisition, or sale of assets, with appropriate notice to you
- With Your Consent: For any other purpose with your explicit permission
5. Data Retention
We retain your data for as long as your account is active or as needed to provide services. Specifically:
- Account data: Retained until account deletion + 30 days
- Uploaded documents: Retained until you delete them or close your account
- Conversation logs: Retained for 90 days by default (configurable in settings)
- Billing records: Retained for 7 years as required by Indian tax law
- Anonymised analytics: May be retained indefinitely in aggregated form
6. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete information
- Delete your account and associated data ("right to be forgotten")
- Restrict or object to certain processing activities
- Port your data in a machine-readable format
- Withdraw consent for marketing communications at any time
To exercise any of these rights, email privacy@visiontwice.com. We will respond within 30 days.
7. Data Security
We implement industry-standard security measures including encryption in transit (TLS 1.2+), encryption at rest, regular security audits, and strict access controls. See our Security page for full details.
8. International Transfers
VISION AI operates primarily from India. If you access our services from the European Union or other regions with data transfer restrictions, we ensure appropriate safeguards are in place (such as Standard Contractual Clauses) for any cross-border transfers.
9. Children's Privacy
VISION AI is a B2B platform intended for business use. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor has provided us with personal data, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on our platform. Continued use after changes constitutes acceptance of the updated policy.
11. Contact Us
Terms & Conditions
These terms govern your access to and use of the VISION AI platform. Please read them carefully before using our services.
1. Acceptance of Terms
These Terms and Conditions ("Terms") constitute a legally binding agreement between you ("Customer", "you", or "your") and VisionTwice ("VISION AI", "we", "us", or "our") governing your use of the VISION AI platform and all related services (collectively, the "Service").
By registering for an account, clicking "Start free," or otherwise accessing the Service, you confirm that you have the legal authority to enter this agreement on behalf of yourself or your organisation.
2. Description of Service
VISION AI provides an AI-powered customer support automation platform that enables businesses to:
- Upload documents to train a custom AI knowledge base
- Deploy an AI chat widget on their website for automated customer responses
- Enable AI-powered email auto-reply for customer support inboxes
- Access analytics dashboards to monitor performance and customer satisfaction
We reserve the right to modify, suspend, or discontinue any part of the Service at any time with reasonable notice.
3. Account Registration & Eligibility
- You must be at least 18 years old and have legal capacity to enter contracts
- You must provide accurate, complete, and current registration information
- You are responsible for maintaining the security of your account credentials
- You must notify us immediately of any unauthorised account access
- One person or legal entity may not maintain more than one free account
- Accounts registered by bots or automated methods are prohibited
4. Acceptable Use
4.1 Permitted Use
You may use VISION AI solely for legitimate business purposes โ to automate and improve your customer support operations in accordance with these Terms.
4.2 Prohibited Activities
You must not use VISION AI to:
- Violate any applicable laws, regulations, or third-party rights
- Upload content that is illegal, defamatory, fraudulent, or infringes intellectual property rights
- Generate deceptive, misleading, or harmful content to end-users
- Attempt to reverse-engineer, decompile, or extract the underlying AI models
- Resell, sublicense, or white-label the Service without written authorisation
- Conduct automated attacks, scraping, or any activity that disrupts the platform
- Collect personal data from end-users without appropriate consent and disclosure
- Use the Service for spam, phishing, or any form of unsolicited communication
5. Plans, Pricing & Billing
5.1 Plans
| Plan | Price | Responses | Seats |
|---|---|---|---|
| Free Trial | $0 / month | 100 / day | 1 |
| Basic | $199 / month | 1,00,000 / month | 5 |
| Pro / Enterprise | Custom | Unlimited | Unlimited |
5.2 Billing
- Paid plans are billed monthly or annually in advance
- All fees are non-refundable except as required by applicable law or our Refund Policy
- We reserve the right to change pricing with 30 days' advance notice
- Failure to pay may result in service suspension after a 7-day grace period
- Taxes (including GST where applicable) are the responsibility of the Customer
5.3 Usage Limits
Exceeding plan limits may result in throttling or temporary service degradation. We will notify you when you approach your limits and offer upgrade options.
6. Intellectual Property
6.1 Your Content
You retain full ownership of all documents, knowledge base content, and data you upload to VISION AI ("Your Content"). By uploading content, you grant us a limited, non-exclusive licence to process and store Your Content solely to provide the Service.
6.2 Our Platform
VISION AI, its software, algorithms, AI models, brand, trademarks, and all associated intellectual property remain exclusively owned by VisionTwice. Nothing in these Terms grants you any rights in our platform beyond the limited right to use the Service.
6.3 Feedback
If you provide feedback, suggestions, or feature requests, we may use them freely without obligation to you.
7. Data Processing
As a business using VISION AI, you act as the data controller for your customers' data. VISION AI acts as your data processor. You are responsible for ensuring your use of our Service complies with applicable data protection laws, including obtaining necessary consents from your end-users.
A Data Processing Addendum (DPA) is available on request for Enterprise customers.
8. Confidentiality
Each party agrees to keep the other's confidential information (including pricing, technical specifications, and business data) strictly confidential and not to disclose it to third parties without prior written consent, except as required by law.
9. Warranties & Disclaimers
VISION AI is provided "as is" and "as available" without warranties of any kind, express or implied. We do not warrant that:
- The Service will be uninterrupted, error-free, or completely secure
- AI responses will be 100% accurate or appropriate for every situation
- The Service will meet all of your specific business requirements
You acknowledge that AI-generated responses may occasionally be inaccurate and that human oversight of customer communications is recommended for high-stakes use cases.
10. Limitation of Liability
To the maximum extent permitted by applicable law, VisionTwice's total aggregate liability to you for any claims arising out of or related to these Terms or the Service shall not exceed the fees paid by you in the three (3) months preceding the claim.
In no event shall we be liable for indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or goodwill, even if advised of the possibility of such damages.
11. Indemnification
You agree to indemnify, defend, and hold harmless VisionTwice and its officers, employees, and agents from any claims, damages, or expenses (including legal fees) arising from: (a) your use of the Service, (b) Your Content, (c) your violation of these Terms, or (d) your violation of any applicable law or third-party rights.
12. Termination
- By you: You may cancel your account at any time via account settings
- By us: We may suspend or terminate your account for breach of these Terms, non-payment, or if we reasonably believe your use poses a risk to other users or our platform
- Effect of termination: Upon termination, your access ceases immediately. We will retain your data for 30 days for potential export before deletion
13. Governing Law & Disputes
These Terms are governed by the laws of India. Any disputes arising under these Terms shall be subject to the exclusive jurisdiction of the courts in Bhopal, Madhya Pradesh, India.
We encourage you to contact us first at legal@visiontwice.com before initiating any formal proceedings โ most issues can be resolved quickly and amicably.
14. Changes to Terms
We may update these Terms periodically. We will provide at least 14 days' notice of material changes via email or an in-platform notification. Your continued use of the Service after the effective date constitutes acceptance of the revised Terms.
15. Contact
Cookie Policy
We use cookies and similar technologies to make VISION AI work, understand how you use it, and improve your experience.
1. What Are Cookies?
Cookies are small text files placed on your device when you visit a website. They help websites remember your preferences, keep you logged in, and understand how you navigate. Cookies are not programs and cannot carry viruses or install software.
We also use similar technologies such as local storage, session storage, and pixel tags. This policy covers all of these collectively as "cookies."
2. Cookies We Use
2.1 Strictly Necessary Cookies
These cookies are essential for the platform to function. You cannot opt out of these without breaking core functionality.
| Cookie | Purpose | Duration |
|---|---|---|
vision_session | Maintains your authenticated session | Session |
vision_csrf | Protects against cross-site request forgery | Session |
vision_prefs | Stores your dashboard preferences | 1 year |
vision_plan | Remembers your current plan for UI rendering | 30 days |
2.2 Analytics Cookies
Help us understand how you use VISION AI so we can improve the product. All data is aggregated and anonymised where possible.
| Cookie / Tool | Purpose | Duration |
|---|---|---|
_ga, _gid (Google Analytics) | Page views, sessions, traffic sources | Up to 2 years |
vision_analytics | In-app feature usage events | 90 days |
vision_perf | Page load times and error tracking | Session |
2.3 Functional Cookies
Enable enhanced functionality and personalisation.
| Cookie | Purpose | Duration |
|---|---|---|
vision_lang | Remembers your language preference | 1 year |
vision_onboard | Tracks onboarding completion state | 90 days |
vision_tour | Remembers if you've seen product tours | 1 year |
2.4 Marketing Cookies
Used to show relevant ads and measure campaign performance. These are only set with your consent.
| Cookie / Tool | Purpose | Duration |
|---|---|---|
_fbp (Meta Pixel) | Conversion tracking for ads | 90 days |
vision_ref | Attribution of sign-up source | 30 days |
2.5 Third-Party Cookies
Some features embed third-party services that may set their own cookies:
- Stripe โ payment processing (Airwallex Privacy Policy)
- Google Analytics โ usage analytics (Google Privacy Policy)
- YouTube โ embedded demo video on the marketing page
3. The VISION AI Chat Widget (for your customers)
If you embed the VISION AI chat widget on your website, the widget may set cookies on your visitors' browsers to maintain conversation context and remember returning visitors. As the website owner, you are responsible for disclosing this in your own cookie/privacy policy.
4. Your Cookie Choices
4.1 Cookie Consent Banner
When you first visit VISION AI, a consent banner allows you to accept all cookies or manage your preferences by category. Your choice is saved for 12 months.
4.2 Browser Controls
You can control or delete cookies via your browser settings:
Note: Disabling cookies may affect platform functionality, particularly authentication and dashboard features.
4.3 Opt-out of Analytics
You can opt out of Google Analytics across all sites using the Google Analytics Opt-out Browser Add-on.
5. Do Not Track
Some browsers send a "Do Not Track" (DNT) signal. Currently, there is no industry-standard response to DNT signals. We do not respond to DNT signals at this time but honour your explicit cookie preferences set in our consent manager.
6. Updates to This Policy
We may update this Cookie Policy as we add new features or third-party integrations. We'll notify you of significant changes via email or platform notice.
7. Contact
Questions about our use of cookies? Contact us at legal@visiontwice.com.
Security
Security is foundational to everything we build. Here's how we protect your data and keep the VISION AI platform safe.
1. Infrastructure Security
Network & Hosting
- VISION AI is hosted on enterprise-grade cloud infrastructure (AWS / GCP) with ISO 27001 certification
- All services run in private Virtual Private Clouds (VPCs) with strict network segmentation
- Web Application Firewall (WAF) protects against OWASP Top 10 attacks
- DDoS protection with automatic traffic scrubbing at the network edge
- All data transfers use TLS 1.2 or higher; TLS 1.0 and 1.1 are disabled
- HTTP Strict Transport Security (HSTS) enforced across all endpoints
Data Storage
- All data at rest is encrypted using AES-256
- Database encryption keys are managed via cloud KMS (Key Management Service)
- Encryption keys are rotated regularly and stored separately from data
- Uploaded documents are stored in isolated, encrypted object storage buckets
2. Application Security
Secure Development
- Security is integrated into our software development lifecycle (SDLC)
- All code changes undergo peer review before deployment
- Automated static application security testing (SAST) runs on every commit
- Third-party dependencies are continuously monitored for known vulnerabilities
- Production deployments require multi-party authorisation
Input & Output Security
- All user inputs are validated and sanitised server-side
- Content Security Policy (CSP) headers prevent cross-site scripting (XSS)
- AI-generated responses are filtered to prevent prompt injection attacks
- SQL parameterisation prevents injection attacks at the database layer
- API endpoints are protected by rate limiting and authentication tokens
3. Authentication & Access Control
- Passwords: Stored using bcrypt hashing with salt โ never in plaintext
- Multi-factor Authentication (MFA): Available and strongly recommended for all accounts
- Session Management: Secure, HTTP-only cookies with automatic expiry and rotation
- OAuth / SSO: Supported for Enterprise plans (Google Workspace, Microsoft Azure AD)
- Role-Based Access Control (RBAC): Team members can be assigned specific permission levels
- Principle of Least Privilege: Internal staff access is granted on a need-to-know basis only
- API Keys: Can be generated, scoped, and revoked from the dashboard at any time
4. AI & Data Isolation
Your knowledge base and AI agent are completely isolated from other customers. Specifically:
- Each customer's knowledge base is stored and indexed in isolated data stores
- Your AI agent will never draw on another customer's uploaded documents
- End-user conversation data is scoped strictly to your account
- We do not use your uploaded content or customer conversations to train shared AI models
- AI inference requests are processed with your data only โ no cross-contamination
5. Operational Security
Monitoring & Detection
- 24/7 automated monitoring of all production systems and APIs
- Anomalous access patterns trigger automatic alerts and investigation
- Centralised security information and event management (SIEM) system
- Intrusion detection systems (IDS) on all network segments
Incident Response
- Documented incident response plan with defined roles and escalation paths
- Critical security incidents trigger immediate containment procedures
- Affected customers notified within 72 hours of a confirmed data breach
- Post-incident reviews conducted to prevent recurrence
Backups & Recovery
- Automated daily backups of all customer data with 30-day retention
- Point-in-time recovery (PITR) supported for databases
- Disaster recovery procedures tested quarterly
- Recovery Time Objective (RTO): 4 hours; Recovery Point Objective (RPO): 24 hours
6. Employee & Vendor Security
- All employees undergo background verification before access to production systems
- Security awareness training conducted regularly for all staff
- Production access is logged, time-limited, and requires justification
- All third-party vendors and sub-processors are vetted for security practices
- Data Processing Agreements (DPAs) are in place with all sub-processors
7. Responsible Disclosure Policy
We welcome security researchers who help us improve our platform. If you discover a vulnerability:
- Email security@visiontwice.com with a detailed description
- Include steps to reproduce, potential impact, and any PoC (proof of concept)
- Please do not publicly disclose before we've had a chance to investigate and patch
- We commit to: acknowledging your report within 48 hours, providing a resolution timeline within 7 days, and crediting researchers who report valid issues (if desired)
8. Compliance
VISION AI is built to support customers operating under various regulatory frameworks:
| Framework / Regulation | Our Position |
|---|---|
| Indian IT Act 2000 & DPDP Act 2023 | Compliant โ data processed per Indian law |
| GDPR (EU) | Supported โ DPA available, SCCs for transfers |
| CCPA (California) | Supported โ data deletion and access requests honoured |
| SOC 2 Type II | In progress โ audit scheduled for 2025 |
| ISO 27001 | Aligning practices โ certification roadmap underway |