Legal

Privacy Policy

Version 2026-09-12 · Effective 12 September 2026

Ayorax, Inc. ("Ayorax", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services. Please read this policy carefully. By using Ayorax, you agree to the practices described here.

1. Scope and our role

This Privacy Policy explains how AYORAX Technologies ("we", "us") handles personal data in connection with the Ayorax platform. It is written with reference to the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the Information Technology Act, 2000 and rules thereunder. **Two different roles.** For the account, billing, and usage data we collect about our customers directly, we are the Data Fiduciary and this policy governs. For personal data our customers bring into their workspace about their own contacts and leads ("Customer Data"), the customer is the Data Fiduciary and we act as a Data Processor on their instructions — in that case, that customer’s own privacy notice governs, and requests from those individuals should be directed to them.

2. Information we collect

**Information you give us when you register or use the Service:** • Your name and work email address • Your mobile number, stored in international (E.164) format • Your organisation name and, optionally, your company domain • Your country, state, and city • Your GSTIN and GST registration status, where you supply them for tax invoicing • Your password, which is stored only as a salted cryptographic hash — never in plain text • Profile details and preferences you choose to add, such as an avatar and language **Information we collect automatically:** • IP address, including the IP recorded at sign-in and at the time you accept our terms • Device, browser, and operating system information • Product usage and diagnostic events, feature interactions, and error logs • Authentication and security events, including failed sign-in attempts • Cookies and similar technologies used to keep you signed in and to remember preferences **Customer Data you bring into your workspace:** • Contact and lead records, including names, phone numbers, email addresses, and any custom fields you define • Conversations and message content across email, WhatsApp, and Instagram • Call metadata, and call recordings and transcripts where you enable those features • Files and attachments you or your contacts upload **Payment information.** Card and bank details are collected and processed directly by our payment gateways. We do not store full card numbers on our systems; we retain transaction identifiers, invoice records, and the tax details required for compliance.

3. Why we process it

We process personal data for the following purposes: • **To provide the Service** — creating and securing your workspace, delivering the features you use, and syncing the integrations you connect • **To bill you and meet tax obligations** — processing payments, issuing GST-compliant invoices, and maintaining statutory financial records • **To keep the Service secure** — authentication, fraud and abuse prevention, rate limiting, audit logging, and incident investigation • **To support you** — responding to your requests and diagnosing problems you report • **To operate and improve the Service** — aggregated and de-identified analytics on reliability, performance, and feature usage • **To communicate with you** — service, security, and billing notices, and product updates you can opt out of • **To comply with law** — responding to lawful requests and enforcing our Terms Where the DPDP Act requires consent, we obtain it — including your explicit acceptance of these documents at registration, which we record with a version identifier, timestamp, and IP address. Where processing is necessary to perform our contract with you, to meet a legal obligation, or for another legitimate use recognised by law, we rely on that basis. We do not sell personal data. We do not use Customer Data to train general-purpose AI models for our own benefit.

4. When we share it

We share personal data only as described here: • **Sub-processors and infrastructure providers** who host, store, and transmit data on our behalf under contractual confidentiality and security obligations. By category, with current examples: cloud hosting and storage; telephony and voice (Plivo, Twilio, Exotel, Knowlarity, Vapi); messaging and social platforms (Meta, for WhatsApp Business and Instagram); email delivery; payment processing (Razorpay, Stripe); AI model providers; error monitoring and analytics. • **Integrations you connect.** When you connect a third-party service, data flows to it at your direction and under its own privacy policy. • **Within your organisation.** Other members of your workspace can see data according to the roles and permissions your administrator assigns. • **Legal and safety.** Where required by law, court order, or a valid request from a competent authority, or to establish, exercise, or defend legal claims. • **Corporate transactions.** In connection with a merger, acquisition, or sale of assets, subject to equivalent protections and with notice to you. We do not sell, rent, or trade personal data to third parties for their own marketing.

5. Cross-border transfers

Some of our sub-processors operate outside India. Where personal data is transferred outside India, we do so in accordance with the DPDP Act and any restrictions notified by the Central Government, and we require the recipient to apply protections consistent with this policy. Where your plan offers a specific data residency option, the location you select governs where your Customer Data is stored at rest.

6. How long we keep it

• **Account data** is retained while your account is active. • **Customer Data** is retained while your subscription is active. After termination it remains available for export for a limited window communicated to you, and is then deleted from active systems. • **Call recordings and transcripts** are retained for the period configured in your workspace, subject to any shorter period you set. • **Billing, invoice, and tax records** are retained for the period required by Indian tax and companies law, even after you close your account. • **Security and audit logs** are retained for a limited period proportionate to their security purpose. • **Consent records** — the version of these documents you accepted, with timestamp and IP — are retained for as long as needed to evidence that consent. Backups are rotated on a defined schedule; deleted data persists in backups only until those backups expire.

7. Your rights

Subject to applicable law, you have the right to: • **Access** a summary of the personal data we process about you and the processing activities involved • **Correct** inaccurate or incomplete data, and complete or update it • **Erase** personal data where it is no longer needed for the purpose it was collected for and we are not required to retain it • **Withdraw consent** where processing relies on consent, with effect for the future • **Nominate** another individual to exercise your rights in the event of death or incapacity • **Raise a grievance** with our Grievance Officer, and escalate to the Data Protection Board of India if you are not satisfied with our response Most of this can be done directly in Settings. Otherwise, write to our Grievance Officer using the details in section 9. We will verify your identity before acting, and will respond within the timelines prescribed by applicable law. If you are a contact or lead held inside a customer’s workspace rather than an account holder, please direct your request to that organisation — they control that data. If you contact us, we will refer you to them and assist them in responding.

8. Security

We maintain technical and organisational measures appropriate to the risk, including: • Encryption of data in transit (TLS) and of sensitive data at rest • Passwords stored only as salted hashes, never in recoverable form • Role-based access control, least-privilege internal access, and audit logging • Tenant isolation so one workspace cannot read another’s data • Session management, rate limiting, and account lockout on repeated failed sign-ins • Optional two-factor authentication • Encrypted storage of third-party credentials and integration secrets • Monitoring, alerting, and a documented incident response process No system is perfectly secure. If a personal data breach occurs, we will notify the Data Protection Board of India and affected individuals in the manner and within the timelines required by law. To report a vulnerability, write to security@ayorax.com.

9. Cookies, children, and contact

**Cookies.** We use strictly necessary cookies to keep you signed in and to maintain session security, and limited functional cookies to remember preferences such as your language. You can block cookies in your browser, but the Service will not function correctly without the necessary ones. **Children.** The Service is not directed to children. We do not knowingly create accounts for anyone under 18. If you believe a child’s data has been provided to us, contact grievance@ayorax.com and we will delete it. **Changes.** We will update this policy from time to time and will change the version identifier at the top. Where a change is material we will notify you before it takes effect. **Contact.** AYORAX Technologies Plot no 212, Shiv Nagar 2nd, Murlipura, Jaipur, Rajasthan 302039, India GSTIN: 08EQOPP4778N1ZL Grievance Officer: Sanju Purohit, grievance@ayorax.com Privacy and legal: legal@ayorax.com Security: security@ayorax.com