Important: This Privacy Policy explains how Xryzex AI collects, uses, stores, secures, and discloses personal data and business data in connection with its B2B AI SaaS products for automated Voice AI telephony and WhatsApp-based content management workflows used by manufacturing businesses in India.
1. Who We Are
Xryzex AI provides AI-enabled software infrastructure for manufacturing factories and industrial businesses, including inbound and outbound Voice AI telephony and WhatsApp-based workflow and content management systems.
For the purposes of applicable Indian law, including the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 together with applicable rules thereunder (“IT Act”), Xryzex AI may act in different capacities depending on the dataset involved:
- As Data Fiduciary / Data Controller for Client account data: where we determine the purpose and means of processing data relating to our business customers and their authorized personnel.
- As Data Processor / service provider for End-User interaction data: where we process caller or messaging data on behalf of our Clients in order to operate the Voice AI or WhatsApp workflows configured by those Clients.
2. Scope of This Policy
This Privacy Policy applies to:
- our website;
- our client dashboard and related authenticated interfaces;
- our Voice AI telephony services;
- our WhatsApp-based AI and CMS workflows; and
- all associated support, billing, provisioning, logging, and security processes.
This Policy does not apply to personal data practices of our Clients themselves. Each Client remains responsible for the legality of the prompts, contact lists, instructions, telephony flows, and WhatsApp communications they choose to configure through our platform.
3. Categories of Data We Actually Collect
Xryzex AI follows a strict data minimization model. We collect only the categories of data listed below. We do not collect speculative or unrelated identity fields such as physical addresses, marital status, passport numbers, social security numbers, Aadhaar, PAN, biometric templates, or banking credentials through our platform.
3.1 Client Account Data
- Email addresses
- Factory names
- Master WhatsApp phone numbers
- Authorized employee phone numbers
- SIP / telecom numbers used for telephony integrations
3.2 Business Knowledge Base Data
- Product catalogs
- Pricing rules
- Operational instructions and business logic provided by the Client
We treat this category as confidential business information and trade-secret-sensitive material.
3.3 Telephony and End-User Interaction Data
- Caller ID / phone numbers
- Call durations
- Call dispositions such as “Order Taken,” “Missed,” “Inquiry Closed,” or comparable workflow outcomes
- Temporary transcripts generated during call handling
3.4 WhatsApp Session Memory
- We store and use only a limited context window of the last 15 WhatsApp messages per session for operational continuity and response coherence.
- We intentionally cap message memory to prevent unnecessary data accumulation and token bloat.
3.5 Financial and Subscription Data
- Prepaid minute usage
- Base-rent subscription status
- Billing state, including active, suspended, unpaid, or terminated status
We do not store credit card numbers, UPI IDs, bank account numbers, CVVs, or full payment instrument details. Payment processing is handled externally by Razorpay.
4. Data We Do Not Intentionally Collect
Unless a Client improperly inserts such information into free-text business materials contrary to contract and instructions, Xryzex AI does not intentionally request or design its systems to collect:
- government ID numbers;
- financial account credentials;
- health records;
- biometric identifiers;
- precise location histories;
- children’s data; or
- website tracking profiles for advertising.
5. Purposes of Processing
We process the above categories of data strictly for the following business and technical purposes:
- provisioning Client accounts and authorized user access;
- configuring telephony numbers, SIP routing, and WhatsApp channels;
- delivering automated inbound and outbound Voice AI workflows;
- generating temporary transcripts required to understand and respond to live calls;
- running WhatsApp-based factory communication and content workflows;
- maintaining limited conversational memory for the last 15 WhatsApp messages per session;
- hosting and querying Client-provided knowledge bases, catalogs, pricing rules, and operational instructions;
- measuring prepaid minute usage, subscription status, and service entitlements;
- preventing abuse, fraud, unauthorized access, or service misuse;
- maintaining logs required for reliability, debugging, and security response; and
- complying with legal obligations under applicable Indian law.
6. Legal Basis Under Indian Law
Where the DPDP Act applies, Xryzex AI processes personal data on one or more of the following grounds, as relevant to context:
- consent, where a data principal or our Client obtains and relies on consent for a specific interaction or communication workflow;
- performance of contract, including onboarding, account administration, subscription delivery, and customer support;
- legitimate uses recognized under applicable law, including fraud prevention, network and information security, service integrity, and business continuity; and
- compliance with legal obligations under the DPDP Act, the IT Act, contractual recordkeeping obligations, and lawful governmental requests.
Where we process End-User interaction data on behalf of our Clients, the relevant Client remains responsible for establishing the legal basis for that underlying engagement, and we act on the Client’s documented instructions subject to our service architecture and contractual terms.
7. AI, Voice, and Model Handling
7.1 No Public Model Training
Xryzex AI uses enterprise-grade AI infrastructure, including Google Cloud Platform and Vertex AI, to support reasoning and workflow execution. Client data, product catalogs, operational instructions, call-derived transcripts, and chat histories are logically isolated and are not used by Xryzex AI to train public foundation models.
7.2 Ephemeral Audio Processing
Live voice calls are processed in real time for speech recognition and response generation. The raw audio stream is ephemeral. We do not permanently store raw call audio after the STT/TTS pipeline has concluded, unless a separate written agreement expressly states otherwise.
7.3 Temporary Transcript Use
Temporary transcripts are used only to operate the call, determine intent, create the required workflow output, and support service logs or call dispositions. We do not repurpose those transcripts for unrelated advertising, profiling, or public model training.
7.4 Limited WhatsApp Memory
For WhatsApp workflows, session context is intentionally limited to the last 15 messages in order to reduce over-retention, minimize unnecessary token consumption, and align with data minimization principles.
8. Sub-Processors and Data Sharing
To run our infrastructure at production scale, we share limited and encrypted data with the following service providers acting as sub-processors or independent service providers, depending on function. Data shared is restricted to what is operationally necessary.
| Provider | Function | Categories of Data Involved |
|---|---|---|
| Supabase (PostgreSQL) | Encrypted database storage with strict Row Level Security (RLS) | Client account data, knowledge base records, limited call logs, limited session memory, subscription state |
| Google Cloud Platform (GCP) & Vertex AI | Server hosting and enterprise LLM inference, including workloads in Mumbai/Delhi regions where configured and available | Knowledge base queries, temporary transcripts, workflow prompts, operational inference data, application hosting metadata |
| LiveKit | Ultra-low latency WebRTC audio routing | Ephemeral live audio streams and call session transport data |
| Sarvam AI | Indic-language Speech-to-Text and Text-to-Speech services | Ephemeral voice processing inputs and generated speech outputs necessary for live call handling |
| ChakraHQ | Operational routing of official WhatsApp messages and alerts | WhatsApp phone numbers, message payloads, delivery and routing metadata |
| Meta (WhatsApp API) | Official WhatsApp messaging infrastructure | WhatsApp phone numbers, message content, message status and routing metadata |
| Razorpay | Secure payment processing and billing workflows | Transaction references, billing status, subscription payment confirmations; not full card, UPI, or banking credentials |
We may also disclose data where legally required, including in response to lawful requests from courts, regulators, law enforcement, or other competent authorities, subject to applicable law.
9. Cross-Border Processing Position
Xryzex AI is architected primarily for Indian business operations, with core hosting and processing aligned to Indian deployments, including Mumbai/Delhi-based cloud regions where configured and available. However, some sub-processors may involve support operations, routing layers, or controlled processing outside India. Where that occurs, we apply contractual confidentiality obligations, encryption, access restrictions, and reasonable security safeguards consistent with applicable Indian law and any restrictions validly imposed under the DPDP Act or related governmental directions.
10. Cookies, Website Tracking, and Dashboard Authentication
Xryzex AI maintains a strict no-tracking posture for its website and client dashboard.
- Zero advertising trackers
- Zero marketing pixels
- Zero non-essential cookies
We use only a single secure HTTP-only JWT session cookie strictly required for authenticated dashboard access and session integrity. This cookie is used only for essential login and security functions and not for behavioral advertising or cross-site profiling.
11. Data Security Measures
We implement technical and organizational safeguards proportionate to the nature of our services, including:
- encryption in transit for network communications;
- encrypted storage layers where applicable;
- strict database access segmentation, including Row Level Security (RLS) in Supabase/PostgreSQL;
- access limitation to authorized personnel only;
- credential, session, and environment controls for administrative access;
- service monitoring, logging, and abuse prevention controls; and
- data minimization by design, including limited WhatsApp memory and non-retention of raw voice audio after pipeline completion.
No system can be guaranteed as absolutely immune from risk. However, we design our systems to reduce unauthorized access, excessive retention, and non-essential exposure.
12. Data Retention and the 90-Day Kill-Switch
We retain data only for as long as necessary to operate the service, comply with applicable law, resolve disputes, protect service integrity, and enforce our agreements.
12.1 Active Accounts
For active Client accounts, we retain the data reasonably required to provide the contracted services, including account configuration, knowledge base contents, call dispositions, limited temporary transcript records, WhatsApp session memory, and subscription status data.
12.2 Suspended Accounts
If a Client account is suspended for non-payment, we halt AI and API operations to prevent further token usage, telephony consumption, or workflow execution.
12.3 Purge After 90 Consecutive Days of Non-Payment
If an account remains unpaid or suspended for 90 consecutive days, Xryzex AI reserves the right to permanently purge the relevant Client’s:
- knowledge base materials;
- call logs and related session records; and
- stored WhatsApp session memory
from our servers, except to the limited extent retention is required by law, fraud prevention necessity, or binding dispute preservation obligations.
13. Client Responsibilities
Our Clients are responsible for ensuring that data they provide to Xryzex AI, or instruct us to process, is lawfully obtained and lawfully used. This includes, where applicable:
- obtaining valid notices or consents for outbound communications or call flows;
- ensuring they do not upload prohibited or unlawfully obtained personal data;
- ensuring business knowledge bases do not include unnecessary sensitive personal data; and
- using the platform in compliance with telecom, consumer protection, employment, and privacy laws applicable to their operations.
14. Rights and Requests
Subject to applicable law and our role in the relevant processing context, data principals may have rights to request access to personal data, correction, updating, erasure, withdrawal of consent where consent is the basis, and grievance redressal under the DPDP Act.
Where Xryzex AI processes End-User data on behalf of a Client, requests may need to be directed first to the relevant Client, as that Client may be the primary decision-maker for the underlying interaction. We will reasonably support our Clients in responding to valid requests where contractually and legally appropriate.
15. Children
Xryzex AI maintains a strict 18+ policy. Our services are designed for industrial and business use and are not directed to children. We do not knowingly collect personal data from children. If we become aware that children’s data has been submitted to our systems without lawful basis, we will take reasonable steps to delete it or restrict processing as required by applicable law.
16. Confidentiality of Client Business Data
Client-provided product catalogs, pricing rules, process instructions, escalation rules, and related manufacturing workflows are treated as confidential commercial information. We do not sell, publish, or repurpose this data for public datasets, public model training, advertising systems, or unrelated commercial exploitation.
17. No Sale of Personal Data
Xryzex AI does not sell personal data. We do not monetize caller records, WhatsApp context, business catalogs, or employee contact data through ad networks, marketing exchanges, or data brokerage activity.
18. Changes to This Policy
We may amend this Privacy Policy from time to time to reflect legal, operational, security, or product changes. The updated version will be posted on our website or dashboard with a revised effective date. Material changes affecting data handling substance will be communicated through reasonable business channels where appropriate.
19. Governing Law and Jurisdiction
This Privacy Policy shall be governed by and construed in accordance with the laws of the Republic of India, including the Digital Personal Data Protection Act, 2023, the Information Technology Act, 2000, and all applicable rules, notifications, and lawful regulatory directions issued thereunder.
Any disputes, complaints, or claims arising from or relating to this Privacy Policy shall be subject to the jurisdiction of the competent courts and authorities in India, unless a specific client agreement provides a narrower forum selection clause to the extent legally permissible.
20. Grievance Officer and Contact
For privacy concerns, rights requests, legal notices relating to personal data, or complaints regarding processing under this Privacy Policy, please contact our designated Grievance Officer at:
Email: legal@xryzex.com
We will review and address grievances in accordance with applicable Indian law and our internal compliance procedures.