Virsae Privacy Policy

Hero Privacy

Virsae Privacy Policy

Last updated: March 1, 2026

Virsae (“us”, “we”, or “our”) is a group of companies that provide the virsae.com websites (together referred to as the “Service”). The companies include

  • Virsae Limited (CN: 4346440) which is incorporated in New Zealand
  • Virsae, Inc. (FN: 5522302) which is a Delaware registered corporation in the USA
  • Virsae UK Limited (CN: 10458174) which is incorporated in the United Kingdom

This page informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data. This Privacy Policy should be read in conjunction with our Terms of Use.

This Privacy Policy does not apply to, and we are not responsible for, any third-party websites or services which may be accessible through links from virsae.com websites.

We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this Virsae Privacy Policy.

Definitions

Personal Data

Personal Data means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).

Usage Data

Usage Data is data collected automatically either generated using the Service or from the Service infrastructure itself (for example, the duration of a page visit).

Data Controller

Data Controller means a person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed.

Virsae Service Management (VSM) automatically collects metadata from customer systems to provide analytics and troubleshooting services.

VSM collects metadata associated with a customer organization’s Unified Communications and Contact Center systems and devices. This metadata may include PII, but does not include the content of messages, calls, or other communications.

For the purposes of this Privacy Policy, our customer is the Data Controller, for the data processed by our platform.

Data Processor (or Service Providers)

Data Processor (or Service Provider) means any person (other than an employee of the Data Controller) who processes the data on behalf of the Data Controller.

For the purposes of this Privacy Policy, we are a Data Processor of our customer’s data that relates to the primary service.

For interactive users (i.e. a customer’s service administrators), who log in directly to the Service, the system will collect contact, website usage and marketing information. For this class of data, Virsae may be the Data Controller.

We may use the services of various Service Providers to process your data more effectively. These providers, if any, are classified as Data Subprocessors.

Data Subject

Data Subject is any living individual who is the subject of Personal Data.

User

The User is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.

Information Collection

We collect several different types of information for various purposes to provide and improve our Service to you. We collect only the data required to fulfill the functions described below, and as consented to in our Terms of Use

The following are types of data collected:

Device Performance and Metadata Collection

The VSM application is primarily focused on the automated collection and processing of device metadata, associating metrics and performance data with in-scope managed devices.

In-scope devices belong to a customer organization and VSM does not have a mechanism to import or register customer end-users, or to link devices to end-users.

Some customers’ systems do provide data elements to VSM that can relate in-scope managed devices to their users (e.g. Phone Number, UserID) and in this specific scenario, the collected data can be personally identifying.

Virsae is the Data Processor for this class of data.

Personal Data

For customer tenant account administration and authentication (“Login Details”), we process personal data on behalf of our customers as Data Processor. For certain operational purposes, including service security, audit logging, platform administration, and analytics relating to the use and performance of our websites and services (“Usage Data”), we act as Controller.

Login Details
To use or manage our service (limited specifically to administrative users of our application), we may ask you to provide us with certain personally identifiable information that can be used to authenticate, contact, or identify you (“Personal Data”). Personally identifiable information includes:

  • Email address
  • First name and last name
  • Phone number
  • Time zone

This user data is not associated, or linked, to any other data or device information collected by Virsae VSM.

We may use this Personal Data to contact you with newsletters, marketing or promotional materials and other information that may be of interest to you. You may opt out of receiving any, or all, of these communications from us by following the “unsubscribe” link or instructions provided in any email we send or by contacting us.

Virsae VSM supports federation with Customer Identity Providers to provide a single-sign-on (SSO) experience for users. Where SSO is utilized, Virsae does not collect, manage, or store user passwords.

VSM also supports an option for “local” login (non-federated). In this case, we use a standard OAuth based Identity Server:

  • User passwords are never stored in plain text
  • We utilize strong, one-way cryptographic hashing algorithms with salting to protect your credentials
  • We do not log user passwords or other sensitive authentication details

Usage Data Collection

We may also collect information that your browser sends whenever you visit our Service or when you access the Service by or through a mobile device (“Usage Data”).

This Usage Data may include information such as your computer’s internet protocol address (“IP address”), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.

When you access the Service by or through a mobile device, this Usage Data may include information such as the type of mobile device you use, your mobile device unique ID, the IP address of your mobile device, your mobile operating system, the type of mobile internet browser you use, unique device identifiers and other diagnostic data.

Usage Logging

This Usage Data may be automatically recorded in system log files, including your IP address, browser type, operating system, referring URLs, access times, and pages viewed.

Cookie Data

We use cookies and similar tracking technologies to track the activity on our Service and hold certain information. For information on this, refer to our Virsae Cookies Policy.

Data Protection

Data Sovereignty

Virsae customer data will be explicitly located in, and remain in, a customer-specified geographical region, defined in our onboarding process. 

High-availability data processing and your data backups stay in the same geographic region. 

These geographic regions are currently Microsoft Azure data centers in the United States of America, Canada, the United Kingdom, and Australia.

Data Encryption

All customer data collected by Virsae is encrypted using industry-standard encryption protocols (e.g., AES-256 for data at rest, TLS 1.2+ for data in transit) to protect your personal and sensitive information. 

Access to Data

Notwithstanding that all data is encrypted at rest, any administrative access is managed on a least privileged basis: 

  • Access to your data is strictly limited to authorized personnel who require it to perform their job functions, adhering to a 'need-to-know' basis
  • Our systems implement robust access controls, including multi-factor authentication, role-based access, and privileged identity management, to protect sensitive information

Use of Data

Service Metadata
Unified communications and contact center metadata collected from customer’s devices forms the basis of our Service.

A customer’s metadata is not used for any purpose other than to deliver our Service to that customer.

Usage Data
We use the Usage Data, collected from interactive users of our system (versus from managed devices) for various purposes, primarily:

  • To provide and maintain our Service
  • To notify you about changes to our Service
  • To allow you to participate in interactive features of our Service when you choose to do so
  • To provide customer support
  • To gather analysis or valuable information so that we can improve our Service
  • To monitor the usage of our Service
  • To detect, prevent and address technical issues
  • To provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information
  • To utilize analytics services (e.g., Google Analytics) that collect anonymized data on user interactions, page views, and traffic sources to improve our services

In addition to the above, we may use your information together with other people’s information in an anonymized and aggregated form (so that it is not identifiable to you) for marketing and strategic development purposes, and may disclose it to third parties for this purpose.

We do not sell or trade your information.

Data Retention

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Virsae Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period of time, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.

Transfer of Data

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ than those from your jurisdiction.

Your consent to this Virsae Privacy Policy followed by your submission of such information represents your agreement to this type of transfer.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Virsae Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

Transfers to Third Parties
Virsae does not share customer data with any third party, except in special cases, where our customers may request data sharing with another of their own suppliers. In this case, explicit permission must be granted to Virsae to enable this data sharing.

Working with Controllers

As a Data Processor, Virsae will assist our customers to meet their obligations as Data Controller.

If a data breach occurs in our application, we will notify our customers (the Controller) as soon as possible, in accordance with the Virsae Security Incident Management procedure.

Disclosure of Data

Business Transaction

If we are involved in a merger, acquisition or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

Disclosure for Law Enforcement

Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities (e.g. a court or a government agency).

Legal Requirements

We may disclose your Personal Data in the good faith belief that such action is necessary:

  • To comply with a legal obligation
  • To protect and defend the rights or property of Virsae
  • To prevent or investigate possible wrongdoing in connection with the Service
  • To protect the personal safety of users of the Service or the public 
  • To protect against legal liability

Security of Data

The security of your data is important to us, but remember that no method of transmission over the internet, or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

Virsae uses approved encryption methods for protecting data in-transit and when stored at-rest in data repositories.

“Do Not Track” Signals

We do not currently respond to 'Do Not Track' (DNT) signals. While some web browsers may offer a DNT setting, we do not alter our data collection and usage practices in response to such signals.

For information on DNT signals, refer to the Future of Privacy Forum website.

Your Rights

We will take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

Whenever possible, you can update your Personal Data directly within your account settings section. If you are unable to change your Personal Data, please contact us to make the required changes. Email us at privacy@virsae.com with your request.

Your Data Protection Rights

Virsae would like to ensure you are fully aware of all your data protection rights. Every user is entitled to the following:

      Right to Access

You have the right to request Virsae for copies of your personal data.

      Right to Rectification

You have the right to request that Virsae correct any information you believe is inaccurate. You also have the right to request Virsae to complete information you believe is incomplete.

      Right to Erasure
      (right to be forgotten)

You have the right to request that Virsae erase your personal data, under certain conditions.

      Right to Restrict Processing

You have the right to request that Virsae restrict the processing of your personal data, under certain conditions.

      Right to Object to Processing

You have the right to object to Virsae’s processing of your personal data, under certain conditions.

      Right to Data Portability

You have the right to request that Virsae transfer the data that we have collected to another organization, or directly to you, under certain conditions.

      Right to Be Informed

You have the right to receive clear, transparent, and easily understandable information about how we use your data.

      Rights in Relation to Automated Decision-Making and Profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.

 

Please note that we may ask you to verify your identity before responding to such requests.

If you make a request, we have one month to respond to you. To exercise any of these rights, please contact us at the addresses listed at the end of this document.

Service Providers

We may employ third-party companies or individuals to facilitate our Service (“Service Providers”), to provide the Service on our behalf, or to assist us in analyzing how our Service is used.

These third parties may have access to your Personal Data to perform these tasks on our behalf.

Refer to our Virsae Cookies Policy for details on how we use third-party cookies.

Links to Other Sites

Our Service may contain links to other sites that are not operated by us. If you click on a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies or practices of any third-party sites or services.

Children’s Privacy

Our Service does not address anyone under the age of 13 (“Child” or “Children”).

Users are invited to, and added to, our site by our Customers (the Data Controller). As the Data Processor, Virsae does not screen for user eligibility.

We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from Children without verification of parental consent, we instruct the Data Controller to remove that information from our servers.

Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update the “effective date” at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Privacy Regulations

Virsae adheres to and upholds the data privacy principles and articles of Privacy Regulations globally and the following are examples:

  • Asia-Pacific Economic Community (APEC) Privacy Recognition for Processors (PRP) System
  • The California Consumer Privacy Act (CCPA)
  • The European Union (EU) General Data Protection Regulations (GDPR)

If you have any unresolved privacy or data use concerns that we have not addressed satisfactorily, please contact us on privacy@virsae.com.

Contact Us

If you have any questions about this Virsae Privacy Policy, or you would like us to take any of the actions available under this Virsae Privacy Policy, please contact us.

You can email us specifically about data or privacy at: privacy@virsae.com.

You can also contact us at the following address:

Virsae Limited
Attention: CISO
PO Box 100120
North Shore Mail Centre 0745
Auckland
New Zealand

For all other inquiries, please visit our contact us web page.