1. Scope and Roles
We act as a Data Fiduciary when we determine the purposes and means of processing (for example, managing your account). We act as a Data Processor when we process Customer Data on a customer's documented instructions to provide the Service. This Policy describes both, and where a distinction matters, we say so. Our processing of personal data is intended to align with the Digital Personal Data Protection Act, 2023 and other applicable Indian law.
2. Information We Collect
2.1 Information you provide
- Account and business details: name, business email, phone number, company name, role, and billing information;
- Verification (KYC) data: identity and business-verification documents and identifiers required to enable telephony, messaging and higher usage limits;
- Content and configuration: prompts, knowledge bases, contacts, leads, templates and settings you create;
- Support and communications: messages, tickets and information you share with our team.
2.2 Information generated through use of the Service
- Conversation data: voice-call recordings and transcripts, WhatsApp, Instagram and Facebook messages and comments, web and email messages, and form submissions that AURA handles for you;
- CRM and lead data: contact records, lead scores, activity history and analytics;
- Usage, log and device data: IP address, device and browser information, timestamps, feature usage and diagnostics;
- Cookies and similar technologies (see Section 7).
2.3 Payment data
Payments are processed by third-party payment partners. We receive limited transaction details (such as status and amount) but do not store full card numbers.
3. How We Use Information
We use personal data to:
- Provide, operate, secure, maintain and support the Service, and manage your account and billing;
- Route, deliver and process the calls, messages and conversations you configure;
- Apply AI processing to generate responses, summaries, intents, transcriptions and analytics (see Section 5);
- Detect, prevent and investigate fraud, abuse, security incidents and violations of our Terms;
- Comply with legal, tax, regulatory and KYC obligations and respond to lawful requests;
- Send service and transactional communications, and, with your consent, product updates and marketing;
- Create aggregated or de-identified data that does not identify any individual, which we may use for any lawful business purpose including improving the Service.
We do not sell personal data.
4. Legal Bases and Consent
Where required, we process personal data on the basis of your consent, the performance of our contract with you, our legitimate and lawful business interests, and compliance with legal obligations. Where processing relies on consent, you may withdraw it at any time; withdrawal does not affect processing already carried out and may limit your ability to use parts of the Service. For Customer Data processed on a customer's behalf, the customer is responsible for establishing the lawful basis and obtaining any required consents from End Users.
5. AI Processing
AURA relies on proprietary and third-party artificial-intelligence models (including large-language, text-to-speech and speech-to-text models) to deliver its features. Conversation content may be processed by these models to generate transcripts, summaries, responses and analytics.
- AI outputs may be inaccurate or incomplete and should be reviewed before being relied upon;
- We do not use the content of customer conversations to train third-party foundation models for their general benefit, except where a feature expressly requires it or where data has been aggregated or de-identified;
- Automated processing may assist routing and prioritisation; you can request human review of decisions that significantly affect you.
8. International Data Transfers
We store data for our Indian customers on servers located in India. However, certain sub-processors and AI providers may process limited data outside India. Where personal data is transferred across borders, we take steps to ensure it is protected through appropriate contractual and security safeguards and in accordance with applicable law.
9. Data Retention
We retain personal data only as long as necessary for the purposes described in this Policy and to meet legal, tax and regulatory obligations:
- Conversation data is retained for the period you configure (12 months by default) and then deleted or de-identified;
- Account, billing and KYC records are retained for the duration of your account and for any period required by law (financial and tax records may be retained for several years);
- Backups are retained for a limited period and then overwritten;
- After termination, Customer Data may be exported for up to 30 days, after which it may be deleted in line with our retention practices unless retention is required by law.
You can ask us to delete data sooner, subject to our legal obligations. See also our Data Deletion page.
10. Security
We use administrative, technical and organisational measures designed to protect personal data, including encryption in transit and at rest, access controls on a need-to-know basis, and continuous monitoring. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a personal-data breach that is likely to result in risk to affected individuals, we will take steps to address it and provide notifications required by applicable law.
11. Your Rights
Subject to applicable law and verification of your identity, you may:
- Request access to, and a copy of, the personal data we hold about you;
- Request correction or updating of inaccurate or incomplete data;
- Request erasure of your personal data;
- Withdraw consent where processing is based on consent;
- Nominate another individual to exercise your rights in the event of death or incapacity;
- Raise a grievance with our Grievance Officer, and, where available, complain to the Data Protection Board of India or other competent authority.
To exercise any right, email info@saarvix.ai. If you are an End User of one of our customers, please direct your request to that business, which controls the relevant data; we will support them as their processor.
12. Children's Data
The Service is intended for businesses and is not directed to children. We do not knowingly collect personal data of children (individuals under 18) as a Data Fiduciary without verifiable parental or guardian consent, and we do not knowingly carry out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child's data has been provided to us, contact us so we can take appropriate action.
13. Third-Party Links and Services
The Service and our websites may link to or integrate with third-party sites and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Please review their policies.
14. Changes to This Policy
We may update this Policy from time to time. If we make a material change, we will notify you by email or in-app notice before it takes effect. The "last updated" date indicates the latest revision.
15. Grievance Officer and Contact
For privacy questions, requests or grievances, contact our Grievance Officer:
We will acknowledge and address grievances within the timelines required by applicable law.
Questions about how AURA handles your data? We're happy to help.
Contact our privacy team