Privacy Policy
Effective Date: August 1, 2026 · Last Updated: August 11, 2026 · Compliant with India's Digital Personal Data Protection (DPDP) Act 2023 & Information Technology Act 2000.
1. Overview & Data Controller Identification
AgentIQ Technologies ("AgentIQ", "we", "us", or "our") operates as a managed AI chatbot and voice agent provider based in Mumbai, Maharashtra, India. This Privacy Policy details how we collect, store, encrypt, process, and delete personal data when client businesses, their end customers, and website visitors interact with our services via Meta WhatsApp Cloud API webhooks, Instagram Direct Messaging APIs, Web Chat Widgets, and Vapi Telephony voice channels.
2. Information We Collect
We process data exclusively for the purpose of executing automated conversational workflows requested by our clients:
- End-Customer Chat Payloads: Phone numbers, WhatsApp display names, user messages, appointment request dates, order status queries, and form inputs sent to your business.
- Voice Call Audio Data: Temporary streaming audio buffers during live inbound/outbound phone calls for speech-to-text transcription and Hinglish response generation.
- Client Account Details: Name, business email, WhatsApp contact number, GST registration details, and integration credentials (e.g. Google Sheets API keys, CRM webhooks).
- Technical Metadata: IP addresses, browser user agents, and essential session identifiers for site security and chat widget state maintenance.
3. Compliance with India DPDP Act 2023 & IT Act 2000
In accordance with India's Digital Personal Data Protection (DPDP) Act 2023 and Section 43A of the Information Technology Act 2000:
- Explicit Opt-in Consent: All automated WhatsApp notifications and outbound AI voice calls require prior explicit consent from the data principal.
- Purpose Limitation: Collected data is strictly used to answer customer enquiries, confirm bookings, process payments via tokenized gateways (e.g. Razorpay), or sync leads to specified client CRMs.
- Data Minimization: We do not capture sensitive medical records, biometric data, or unencrypted payment card information.
4. Zero AI Model Training Guarantee
🔒 Strict Tenant Memory Isolation: Your proprietary business data, customer messages, patient details, and restaurant orders are NEVER used to train, fine-tune, or reinforce public base AI models (such as Claude, OpenAI GPT, or Gemini). All context memory remains strictly isolated within your private tenant space.
5. Security Architecture & Encryption
- Data in Transit: All communication across Meta WhatsApp Cloud API webhooks, website chat widgets, and voice endpoints is enforced over TLS 1.3 encryption with real-time HMAC-SHA256 signature verification.
- Data at Rest: Database records and lead logs are encrypted using bank-grade AES-256 storage algorithms.
- PCI-DSS Compliance: Payment transactions are handled directly via PCI-DSS compliant third-party gateways (Razorpay). AgentIQ stores zero credit card numbers or UPI PINs.
6. Data Deletion & User Rights
Data Principals have the right to request access to their personal data, request correction of inaccurate records, or demand complete erasure from AgentIQ memory ("Right to be Forgotten"). Data deletion requests are processed automatically within 48 hours upon receipt of verification.
7. Contact Data Protection Officer (DPO)
For privacy enquiries, DPDP Act data deletion requests, or security audit reviews, contact our Data Protection Officer:
AgentIQ Technologies — Data Protection Lead
Email: privacy@agentiq.co.in / shane@agentiq.co.in
WhatsApp: +91 91596 65277
Location: Mumbai, Maharashtra, India 🇮🇳