Privacy Policy
This policy explains what personal data AvlokAI handles, why, who else touches it, how long we keep it, and how you exercise your rights. It covers this website and our enquiry channels, and it explains the separate role we take when we process data on behalf of a client.
1. Who we are
AvlokAI (“AvlokAI”, “we”, “us”) is an AI automation studio operating from Hyderabad, Telangana, India. For personal data we collect through this website and our enquiry channels, we are the data fiduciary(controller).
- Email: hello@avlokai.com
- Phone: +91 93466 72015
- Postal address: Hyderabad, Telangana, India
2. Two different roles
As a data fiduciary, we decide the purpose for data you give us directly — an enquiry form, an email, a WhatsApp message, a call. This policy governs that data.
As a data processor, we handle data belonging to a client’s own customers while building or running an automation for that client. There, the client decides the purposes and we act on their documented instructions under a data-processing agreement. That client’s own privacy notice governs the data subject relationship, not this page.
3. What we collect
When you contact us:
- Name, work email address, and any company name and phone number you provide
- The content of your enquiry and any subsequent correspondence
- Phone numbers and message content where you contact us on WhatsApp
- The IP address the enquiry was submitted from and the submission timestamp, kept for abuse prevention
When you browse this website:
- Standard server and delivery-network logs — IP address, user agent, requested URL, timestamp — generated by our hosting provider
- A theme preference stored in your browser’s local storage. It never leaves your device and is not read by us.
We do not run advertising trackers, third-party analytics scripts, or cross-site profiling on this website, and we do not set marketing cookies. If that changes, this section changes with it and the effective date above will be updated.
During a client engagement, we may be given access to systems that contain personal data — a CRM, a mailbox, a document library. What we may access, for what purpose, and for how long is set out in the engagement’s data-processing agreement.
4. Why we process it, and on what basis
- To respond to your enquiry — on the consent you give when submitting the form, which you may withdraw at any time.
- To deliver a project you have engaged us for — necessary for performance of our contract with you.
- To send service and project communications — necessary for performance of our contract. We do not send marketing email to enquirers who have not asked for it.
- To keep the site and our systems secure — our legitimate use in preventing abuse, fraud, and misuse of the contact endpoint.
- To meet legal, tax, and accounting obligations — required by Indian law.
We use personal data only for the purpose it was collected for. We do not sell personal data, and we do not use client or enquiry data to train machine-learning models.
5. Sub-processors and third parties
These are the third parties that may process personal data on our behalf. We disclose them because any serious buyer will ask, and because you are entitled to know who touches your data.
| Sub-processor | Purpose | Processing location |
|---|---|---|
| Anthropic, PBC | Large language model inference for assistant and document-processing workflows | United States |
| OpenAI, L.L.C. | Large language model and embedding inference where a project specifies it | United States |
| Meta Platforms (WhatsApp Business Platform) | Delivery of WhatsApp messages in messaging workflows | United States / Ireland |
| n8n GmbH (self-hosted or n8n Cloud) | Workflow orchestration and execution logs | Germany, or the client’s own infrastructure when self-hosted |
| Cloudflare, Inc. | DNS, CDN, and hosting and delivery of this website and its contact endpoint | United States |
| Google LLC (Workspace) | Business email and document storage for enquiries and project files | United States |
Where a project is deployed into a client’s own cloud accounts and API keys, the client is the controller of that infrastructure and AvlokAI does not retain a copy of the processed data.
We also disclose personal data where we are legally required to — to a court, regulator, or law enforcement agency acting under valid authority — and to professional advisers under a duty of confidence. If our business is transferred, personal data may transfer with it, and you will be told before that takes effect.
6. Cross-border transfers
Several sub-processors listed above process data outside India, principally in the United States and the European Union. Where personal data leaves India, we transfer it only to recipients bound by contractual data-protection commitments, and only to countries not restricted by the Central Government under section 16 of the Digital Personal Data Protection Act 2023.
Where a client requires that data stay within India, we can build to that constraint — say so at scoping, because it changes which model providers and hosting options are available.
7. How long we keep it
- Enquiries that do not become projects: 24 months from last contact, then deleted.
- Project and client records: for the duration of the engagement and 8 years afterwards, to meet Indian tax and accounting record-keeping requirements.
- Data processed on a client’s behalf: as specified in that engagement’s data-processing agreement, and returned or deleted within 30 days of the engagement ending unless the client instructs otherwise.
- Website and abuse-prevention logs: 90 days.
8. Security safeguards
- Access to client systems is scoped to the minimum a workflow requires, and reviewed at handover.
- Credentials are held in a secrets manager, never in workflow definitions, source code, or chat.
- Multi-factor authentication is enforced on our email, cloud, and workflow accounts.
- Data in transit is encrypted with TLS; data at rest is encrypted by the underlying cloud services.
- Access is logged, and logs are retained long enough to reconstruct what a workflow did.
- No security programme is perfect. If something happens, section 10 says what we do about it.
9. Your rights
Under the Digital Personal Data Protection Act 2023 and applicable law, you may:
- Ask for a summary of the personal data we hold about you and how it is being processed
- Ask us to correct or complete inaccurate or incomplete data
- Ask us to erase your data where we no longer need it for the purpose it was collected for
- Withdraw consent you previously gave, without affecting processing already carried out
- Nominate another person to exercise these rights on your behalf if you are incapacitated or deceased
- Raise a grievance with us, and escalate to the Data Protection Board of India if we do not resolve it
To exercise any of these, emailgrievance@avlokai.comfrom the address you contacted us from, or follow the steps on ourdata deletion page. We may ask you to verify your identity before acting, and we respond within 30 days. There is no fee.
Where we hold data as a processor on a client’s behalf, we will forward your request to that client, who is the fiduciary for it, and tell you we have done so.
10. Grievance Officer and breach notification
In accordance with the Digital Personal Data Protection Act 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules 2021, our Grievance Officer is:
- Sushanth Kasturi, Grievance Officer
- Email: grievance@avlokai.com
- Address: Hyderabad, Telangana, India
Grievances are acknowledged within 24 hours and resolved within 15 days. If you are not satisfied with the outcome, you may complain to the Data Protection Board of India.
In the event of a personal data breach, we notify the Data Protection Board of India and every affected person without undue delay, describing what happened, what data was involved, what we are doing about it, and what you should do. Where an engagement makes us a processor, we notify the client without undue delay so they can meet their own notification duties, including the 60-day requirement that applies to US covered entities under HIPAA where a Business Associate Agreement is in place.
11. Children's data
Our services are for businesses. We do not knowingly collect personal data from anyone under 18, and we do not carry out behavioural advertising or tracking directed at children. If you believe a child has given us personal data, contact the Grievance Officer and we will delete it.
12. Changes to this policy
We update this policy when our processing changes — a new sub-processor, a new purpose, a new retention period. The effective date at the top always reflects the current version. Material changes affecting existing clients are notified by email before they take effect.
13. Contact
Questions about this policy: hello@avlokai.com. Privacy requests and grievances:grievance@avlokai.com.