Back
Legal

Privacy Policy

Last updated: July 26, 2026

1. Introduction & Our Role

Alphoris Technologies Pvt. Ltd. (“Alphoris”, “we”, “our”, “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you access or use our AI voice and messaging platform and related services (“Service”). This policy is issued under the Digital Personal Data Protection Act, 2023 (“DPDP Act”), the Information Technology Act, 2000 and the rules made thereunder.

Under the DPDP Act, our role depends on whose data is being processed:

  • We are the Data Fiduciary for personal data of our own customers — the account holders, administrators and staff of organisations who sign up for Alphoris. This policy governs that data directly.
  • We are a Data Processor for personal data that our customers upload or generate through the Service — their contact lists, their end customers' call recordings, transcripts and CRM records. For that data, the customer organisation is the Data Fiduciary and determines the purpose of processing; we act only on their documented instructions under our Data Processing Agreement.

If you received a call from an AI agent operating on Alphoris and wish to exercise your rights over that call, the organisation that placed the call is your Data Fiduciary. We will assist them in responding to you, and you may also contact our Grievance Officer (Section 12) who will route your request.

2. Information We Collect

We collect the following categories of information:

  • Account Information: Name, email address, phone number, company name, and password (stored as a secure hash) when you register.
  • Call Data: Recordings, transcripts, call duration, outcomes, and sentiment scores for campaigns you create or receive.
  • Contact Lists: Phone numbers, names, and metadata of contacts you upload for outbound campaigns.
  • Usage Data: Pages visited, features used, actions taken, session duration, and device/browser information.
  • Payment Information: Billing details processed and stored by our payment partner (Razorpay). Alphoris does not store raw card numbers.
  • Knowledge Base Content: Documents and FAQs you upload for AI reference during calls.
  • Communication Data: Messages you send to our support team via email or contact forms.

3. How We Use Your Information

  • Provide, operate, and improve the Alphoris platform and services.
  • Process and complete transactions, including billing and credit management.
  • Send transactional and administrative communications (account updates, invoices, security alerts).
  • Analyse platform usage patterns to improve user experience.
  • Ensure platform security, prevent fraud, and enforce our Terms of Service.
  • Comply with applicable legal and regulatory obligations.

We do not train AI models on your data. Alphoris uses Google Gemini on a paid enterprise tier under which Google does not use your prompts, call audio, or transcripts to train its models. We do not use your contact lists, call recordings, or transcripts for advertising, for building profiles of individuals, or to train any model of our own.

4. Legal Basis for Processing

The DPDP Act permits processing of personal data on two grounds only: the consent of the Data Principal, and a defined set of “legitimate uses” under Section 7 of the Act. We rely on:

  • Consent (Section 6): Where you have given free, specific, informed, unconditional and unambiguous consent through a clear affirmative action — for example, when you accept this policy on registration, or when a call recipient is told at the start of a call that they are speaking to an AI agent and that the call is recorded. Consent may be withdrawn at any time, and withdrawal is as easy as giving it.
  • Voluntary provision for a specified purpose (Section 7(a)): Where you voluntarily provide personal data to us for a purpose and have not indicated that you object to its use for that purpose — for example, submitting your email to receive an invoice.
  • Compliance with law or judicial order (Sections 7(b), 7(c), 7(i)): Where processing is necessary to comply with any Indian law, judgment, order or decree, including TRAI regulations and lawful requests from government authorities.

We do not rely on “legitimate interest” as a legal basis. That concept exists under the EU GDPR but is not a lawful ground under Indian law, and we do not process personal data on that footing.

Where we act as a Data Processor for a customer organisation, the obligation to establish a valid legal basis — including obtaining consent from call recipients before they are contacted — rests with that organisation as Data Fiduciary.

5. Call Recording & AI Disclosure

Calls placed or received through the Service are handled by an automated AI agent and are recorded. Both facts are disclosed to the other party in the agent's opening line, before any substantive conversation takes place, in the language of the call. Specifically:

  • The agent identifies itself as an AI assistant acting for the calling organisation. It will never claim to be human, and will confirm that it is an AI if asked at any point.
  • The agent states that the call is being recorded before the conversation begins.
  • These disclosures are enforced by the platform and cannot be disabled or overridden by a customer's script, prompt or knowledge base.

A call recipient who does not consent may end the call at that point, and may ask the calling organisation to delete the recording. Recordings are used to deliver the Service (transcription, summarisation, quality review and dispute resolution) and are deleted on the schedule set out in Section 10.

6. Data Storage & Security

Account data, contact lists, call recordings and transcripts are stored on servers located in India (AWS Asia Pacific — Mumbai). We implement the following security measures:

  • AES-256 encryption for data at rest.
  • TLS 1.3 for all data in transit.
  • Role-based access controls (RBAC) — only authorised personnel can access personal data.
  • Comprehensive audit logging of all data access and modifications.
  • Regular security assessments and penetration testing.
  • Multi-factor authentication for all internal systems.

No system is completely secure, and we do not represent that ours is. We take reasonable security safeguards as required by Section 8(5) of the DPDP Act.

7. Data Breach Notification

In the event of a personal data breach, we will:

  • Notify the Data Protection Board of India without delay upon becoming aware of the breach, and provide a detailed report within 72 hours (or such longer period as the Board allows on request).
  • Notify each affected Data Principal without delay, in a clear and plain-language description of the breach, its likely consequences, and the measures we have taken to mitigate risk.
  • Where we act as a Data Processor, notify the affected customer organisation without delay so they can meet their own obligations as Data Fiduciary.
  • Notify CERT-In in accordance with its applicable directions.

These notifications are made for every personal data breach. The DPDP Act does not permit us to apply a severity threshold or withhold notice on the basis that harm is unlikely.

8. Data Sharing & Disclosure

We do not sell, rent, or trade personal information. We share data only with the processors and in the circumstances listed below:

  • Telephony: Exotel Techcom Pvt. Ltd. (India) — call origination, termination and connectivity.
  • Cloud hosting: Amazon Web Services (India) — application servers and data storage.
  • AI processing: Google LLC (Gemini API) — speech recognition, conversation and summarisation, under Google's enterprise data protection terms.
  • Payments: Razorpay Software Pvt. Ltd. (India) — payment processing and invoicing.
  • Transactional email: Resend — account and system notifications.
  • Messaging: Meta Platforms (WhatsApp Business Platform) — where the customer enables WhatsApp messaging.
  • Legal requirements: Where required by Indian law, court order, or a lawful request from a government authority.
  • Business transfers: In a merger, acquisition, or asset sale, with 30 days' prior notice to affected customers.

Each processor is engaged under a written contract imposing confidentiality and security obligations consistent with this policy. The current list is maintained in the Sub-processor Annex to our Data Processing Agreement. We will give customers at least 30 days' notice before adding or replacing a sub-processor, during which a customer may object.

9. Cross-Border Processing

Personal data is stored at rest in India. However, some processing necessarily occurs outside India: in particular, call audio and transcripts are sent to Google's Gemini API for speech recognition and language processing, and may be processed on Google infrastructure located outside India. Transactional email delivery may likewise be routed through infrastructure outside India.

Section 16 of the DPDP Act permits transfer of personal data outside India except to countries specifically restricted by the Central Government. We do not transfer personal data to any restricted country. All cross-border processing is covered by contractual data protection terms with the relevant processor. If your organisation requires that data not leave India at all, contact us before onboarding — the Service in its current form cannot meet that requirement.

10. Data Retention

  • Account data is retained while your account is active and for 90 days post-deletion request.
  • Call recordings are automatically and permanently deleted 90 days after the call — this runs as an automated daily process, not on request.
  • Transcripts, call summaries, and analytics are retained for the lifetime of your account (they are not automatically deleted at 90 days) so you retain a durable record of past conversations; you can request deletion of specific records at any time.
  • Payment records are retained for 8 years as required by Indian tax and companies law.
  • You can request deletion of specific data types at any time.

On termination of your account, personal data is deleted or returned within 90 days, except where retention is required by law. Where we act as Data Processor, deletion and return are governed by the Data Processing Agreement.

11. Your Rights

Under Chapter III of the DPDP Act, as a Data Principal you have the right to:

  • Access (Section 11): Obtain a summary of the personal data we process about you, the processing activities undertaken, and the identities of other Data Fiduciaries and Processors with whom it has been shared.
  • Correction, completion, updating and erasure (Section 12): Have inaccurate or misleading data corrected, incomplete data completed, and your data erased where retention is no longer necessary for the purpose or required by law.
  • Grievance redressal (Section 13): Use the mechanism in Section 12 below. You must exhaust this before approaching the Data Protection Board.
  • Nominate (Section 14): Nominate another individual to exercise your rights in the event of your death or incapacity.
  • Withdraw consent (Section 6(4)): Withdraw consent at any time, as easily as it was given. Withdrawal does not affect the lawfulness of processing carried out before it.

You also have a duty under Section 15 of the Act not to furnish false particulars or file frivolous complaints.

To exercise any right, email privacy@alphoris.in. We respond within 30 days. If your data was uploaded to the platform by a customer organisation, we will forward your request to that organisation and assist them in responding.

12. Grievance Redressal

In accordance with Section 13 of the DPDP Act and Rule 3(2) of the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021, we have appointed a Grievance Officer:

Grievance Officer & Data Protection Officer
Name: [TO BE APPOINTED — INSERT NAME BEFORE PUBLICATION]
Email: grievance@alphoris.in
Phone: +91 99802 70969
Address: Alphoris Technologies Pvt. Ltd., Bangalore, Karnataka, India

The Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 15 days of receipt. If you are not satisfied with the resolution, or if we fail to respond within that period, you may lodge a complaint with the Data Protection Board of India.

13. Cookies & Tracking

We use the following types of cookies:

  • Essential Cookies: Required for authentication, session management, and basic platform functionality. These are strictly necessary to deliver the Service and cannot be disabled.
  • Analytics Cookies: Help us understand how users navigate the platform so we can improve it. These are set only with your consent, which you may withdraw at any time through your browser settings.

We do not use third-party advertising cookies or cross-site tracking technologies.

14. Children's Privacy

The Service is not directed to individuals under 18 years of age. Section 9 of the DPDP Act prohibits processing a child's personal data without verifiable parental consent, and prohibits tracking, behavioural monitoring or targeted advertising directed at children. We do not knowingly collect personal data from minors. If we become aware that a minor has registered, we will delete the account and associated data promptly. Parents or guardians who believe their child has provided data to us should contact privacy@alphoris.in.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top and notify you by email if the changes are material. Where a change materially expands the purposes for which we process personal data, we will seek fresh consent rather than rely on continued use.

16. Contact Us

Alphoris Technologies Pvt. Ltd.
CIN: [INSERT CIN]
GSTIN: [INSERT GSTIN]
Registered office: Bangalore, Karnataka, India

Privacy & data requests: privacy@alphoris.in
Grievances: grievance@alphoris.in
General: alphoris.ai@gmail.com
Phone: +91 99802 70969