iVaak Privacy Policy
Intelligence India.Com Limited (IICL) · iVaak Unified Conversational AI Operating System
Effective date: 5 September 2026
Last updated: 5 September 2026
Version: 1.0
This Privacy Policy explains how Intelligence India.Com Limited (“IICL”, “we”, “us”, or “our”) handles personal data in connection with iVaak, our Unified Conversational AI Operating System, our websites, and related business interactions.
IICL is an Indian company having its registered office at Unit No. 308 & 309, Jain Sadguru Image's Capital Park, Capital Pk Rd, VIP Hills, Silicon Valley, Madhapur, Hyderabad, Telangana 500081 and corporate identification number U72900TG2001PLC036080. iVaak is a product and brand operated by IICL; it is not the contracting entity.
This Policy is designed to address the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and rules under it as their relevant provisions commence, the Information Technology Act, 2000 and applicable rules while in force, and the EU General Data Protection Regulation (“GDPR”) where it applies. It is not intended to replace the privacy notice that an enterprise using iVaak must provide to its own customers, prospects, employees, or other end users.
1. Scope
This Policy applies to personal data that IICL handles when:
- an enterprise client uses iVaak to communicate with or provide services to its end users;
- an authorised user accesses the iVaak administration console, dashboards, APIs, support, or related services;
- a person visits an iVaak or IICL website, requests a demonstration, submits an enquiry, attends an event, or communicates with our business team;
- IICL monitors, secures, supports, and improves the operation of iVaak; or
- IICL is required to process information for legal, regulatory, fraud-prevention, or security purposes.
This Policy does not govern a third party’s independent processing, including processing by an enterprise client, Meta or WhatsApp, a telecommunications carrier, SMS or RCS gateway, email provider, client CRM or ERP provider, or another service chosen by the client. Their own notices and terms apply to their independent activities.
2. Key Definitions
“Enterprise Client” or “Client” means a business, public authority, institution, or other organisation that contracts with IICL to use iVaak.
“End User” means an individual who communicates with, is contacted by, or is the subject of a workflow operated by an Enterprise Client through iVaak, such as the Client’s customer, prospect, patient, citizen, supplier contact, employee, or website visitor.
“Data Principal”, “Data Fiduciary”, “Data Processor”, “personal data”, and “processing” have the meanings given in the DPDP Act. Where the GDPR applies, corresponding references include “data subject,” “controller,” and “processor.”
“Channels” means communication entry points supported by iVaak, including Voice AI; Meta or WhatsApp Business automation offered as iWac; web chat and browser voice offered as iCognito; email automation offered as iEmac; SMS; and Rich Communication Services (“RCS”).
“Conversation Data” means call audio, recordings, transcripts, messages, chats, emails, interaction metadata, conversation state, summaries, classifications, handoff records, and related logs.
“Integration Fabric” means iVaak’s connectivity and orchestration layer that reads from, writes to, or triggers authorised workflows in systems such as Zoho CRM, Shopify, Tally, Google Sheets, support platforms, enterprise databases, and custom APIs.
“System Integration Data” means information retrieved from, supplied to, or synchronised with an Enterprise Client’s connected systems, such as lead status, customer records, order history, inventory, invoice information, appointment details, site-visit information, and support tickets.
“Service Telemetry” means operational information about usage volumes, performance, availability, security events, errors, device or browser characteristics, and feature interaction.
3. Our Data Roles
Our legal role depends on why and how personal data is processed.
| Processing context | IICL's role | Enterprise Client's role |
|---|---|---|
| End-User Conversation Data and System Integration Data processed to provide the Client's configured service | Data Processor / processor | Data Fiduciary / controller |
| Client user accounts, service administration, commercial relationship, billing records, fraud prevention, and platform security | Data Fiduciary / controller for those limited purposes | Independent Data Fiduciary / controller for its own records |
| Website enquiries, demo requests, events, and direct IICL communications | Data Fiduciary / controller | Not ordinarily applicable |
| A Third-Party Channel's independent account, network, policy-enforcement, or legal processing | IICL is not the controller of that independent activity | Roles depend on the provider's terms and the Client's configuration |
3.1 IICL as Data Processor
When iVaak processes an End User’s call, recording, transcript, WhatsApp message, web chat, email, order history, or other Client-directed information, the Enterprise Client determines the purpose and means of that interaction and is the Data Fiduciary or controller. IICL acts as its Data Processor or processor.
The Enterprise Client is responsible for:
- identifying a lawful purpose and legal basis;
- giving a clear privacy and recording notice;
- obtaining, recording, and managing consent where required;
- complying with telecom, marketing, recording, sectoral, and Channel rules;
- deciding which data, knowledge sources, workflows, and integrations iVaak may use;
- keeping the information supplied to iVaak accurate and proportionate; and
- responding to End-User rights and grievances.
IICL processes this data on the Client’s documented instructions, under the applicable agreement and data-processing terms, unless law requires otherwise.
3.2 IICL as Data Fiduciary or Controller
IICL acts independently as a Data Fiduciary or controller when it decides why and how to process personal data for its own legitimate business administration, including management of Client accounts, contracting, invoicing, security, abuse prevention, support administration, direct enquiries, regulatory compliance, and protection of legal rights.
3.3 Third Parties May Have Independent Roles
Communication networks and connected applications may process personal data for their own purposes. For example, Meta or WhatsApp may process account and message data under their policies; carriers may process call and routing information; and a Client’s CRM provider may process records under its agreement with the Client. IICL does not control those independent purposes.
4. Personal Data We Process
The exact information depends on the Channels and workflows selected by the Enterprise Client.
4.1 Account and Business Contact Data
We may process:
- name, work email address, telephone number, job title, organisation, and business address;
- user role, account identifier, authentication information, permissions, and administrator activity;
- contracting, billing, tax, procurement, support, and relationship-management records; and
- correspondence, meeting notes, demo requests, survey responses, and event information.
4.2 Voice and Text Conversation Data
Depending on Client configuration, iVaak may process:
- live voice streams, call audio recordings, caller and called numbers, call timestamps, duration, routing, disposition, and quality information;
- automated speech-recognition transcripts, text-to-speech output, language, and voice settings;
- WhatsApp or other Meta message content, approved templates, media, delivery events, and opt-in or opt-out indicators;
- iCognito web chats, browser voice interactions, page or session context, and human-agent handoffs;
- SMS and RCS content, delivery status, sender or header information, and campaign or consent references;
- iEmac email content, sender and recipient information, attachments where enabled, classifications, and response drafts; and
- AI-generated summaries, extracted fields, detected intent, sentiment or priority labels, recommended responses, and workflow outcomes.
4.3 Conversational Metadata and Cross-Channel Context
To maintain continuity, iVaak may process interaction times, Channel identifiers, conversation state, customer or account references, prior-intent summaries, authentication status, language preference, handoff status, and continuity links between interactions such as WhatsApp, web, email, and voice.
Persistent conversational memory is limited to the Client’s configured purpose, retention settings, identity-matching rules, and authorised data sources. It should not be treated as a universal identity profile.
4.4 System Integration Data
The Integration Fabric may process information fetched from or written to Enterprise Client systems, including:
- CRM leads, contacts, opportunities, notes, ownership, and follow-up status;
- ecommerce or order identifiers, status, delivery information, returns, inventory, and catalogue information;
- accounting or ERP records such as invoice status or approved transaction references;
- bookings, appointments, site visits, service schedules, and reminders;
- support cases, ticket status, warranties, and service history;
- spreadsheet fields and custom database records selected by the Client; and
- workflow requests, API responses, validation results, write confirmations, and error logs.
IICL does not require unrestricted access to a Client system. Clients should configure least-privilege access and expose only the fields and actions necessary for the approved use case.
4.5 Technical, Usage, and Security Data
We may process IP address, device and browser type, operating system, session and authentication events, API request metadata, approximate network location, timestamps, diagnostic logs, feature usage, latency, errors, fraud signals, security alerts, and audit records.
4.6 Website and Cookie Data
Our websites may use essential cookies and similar technologies required for security, session management, preferences, and basic operation. Analytics, advertising, or non-essential cookies will be used only as described in an approved cookie notice and consent mechanism where required. See our Cookie Notice for the full list of cookies and similar technologies we use. Non-essential analytics and advertising technologies are not activated unless you give consent through our cookie banner, and you can change or withdraw that consent at any time using the Cookie preferences link in the footer of every page.
4.7 Support Data
When a Client seeks support, we may process contact details, issue descriptions, diagnostic files, screenshots, recordings, test data, and relevant account or system information. Clients should remove or mask personal data that is not needed to resolve the issue.
4.8 Sensitive and Special-Category Data
iVaak is capable of processing information that may be sensitive because of a Client’s chosen use case, such as health information, financial information, government identifiers, authentication data, or voice data that could be treated as biometric data if processed for unique identification. IICL does not require such data by default.
An Enterprise Client must not configure iVaak to process sensitive or special-category information unless it has a valid legal basis, has completed an appropriate risk assessment, and has agreed suitable safeguards with IICL. Payment-card authentication secrets, passwords, one-time passwords, and similar credentials should not be placed in general conversation logs unless an expressly approved secure workflow requires them.
5. How We Collect Personal Data
We receive personal data:
- directly from Enterprise Clients and their authorised users;
- from End Users when they call, message, chat, email, complete a form, or otherwise interact through a Client-configured Channel;
- from Client systems connected through the Integration Fabric;
- from Channel and network providers that deliver or report an interaction;
- automatically from browsers, devices, APIs, logs, and security systems; and
- from public or commercial business sources for legitimate enterprise sales and relationship management, subject to Applicable Law.
The Client controls which End Users, databases, fields, and workflows are connected to iVaak. IICL does not independently acquire contact lists for a Client’s campaigns unless separately agreed and lawfully sourced.
6. Why We Process Personal Data
We process personal data only for specified purposes appropriate to our role.
6.1 Client-Directed Product Purposes
As a Data Processor, we process personal data to:
- automate customer service and routine enterprise conversations;
- answer questions using Client-approved knowledge and data;
- maintain appropriate conversational context across enabled Channels;
- recognise returning interactions using Client-approved identifiers;
- resolve transactional requests such as order tracking, appointment scheduling, service requests, site visits, lead qualification, reminders, and status enquiries;
- generate transcripts, summaries, classifications, and follow-up tasks;
- route an interaction to a human agent with relevant context;
- execute approved, permission-controlled workflows in connected systems;
- provide dashboards, reporting, quality review, and operational analytics; and
- deliver, troubleshoot, secure, and support the Services.
6.2 IICL's Independent Purposes
As a Data Fiduciary or controller, we process limited personal data to:
- create and administer Client accounts;
- manage contracts, billing, support, and business relationships;
- respond to enquiries and arrange demonstrations;
- authenticate users and protect accounts, networks, and the Platform;
- prevent misuse, spam, fraud, unauthorised access, and security incidents;
- monitor availability, capacity, and reliability;
- meet legal, tax, audit, regulatory, and record-keeping obligations;
- establish, exercise, or defend legal claims; and
- communicate relevant operational, security, and product-service information to authorised Client contacts.
6.3 Legal Grounds
Under Indian law, we rely on consent or another permitted legitimate use, as applicable to the particular processing and as the relevant DPDP Act provisions commence. Under the GDPR, where applicable, processing may be based on performance of a contract, legitimate interests that are not overridden by individual rights, compliance with legal obligations, consent, or another lawful basis available to the Client or IICL for its respective role.
Where IICL acts as Data Processor, the Enterprise Client—not IICL—selects and documents the legal basis for End-User processing.
7. AI Processing and Automated Workflows
7.1 How AI Is Used
iVaak may use speech recognition, language models, natural-language processing, classification, retrieval, text-to-speech, and workflow automation to understand an interaction and produce a response or action. AI systems are probabilistic. A transcript, summary, inference, recommendation, or generated response may be inaccurate, incomplete, or inappropriate.
7.2 Human Oversight
Enterprise Clients decide the level of automation, validation, approval, and human handoff. Clients must use meaningful human review for decisions or actions that may materially affect an individual’s rights, safety, health, employment, credit, insurance, housing, education, access to essential services, or legal position, unless the use has been specifically assessed and is permitted by law.
7.3 Model Training
IICL does not use the content of Client Conversation Data or System Integration Data to train a general-purpose or shared AI model for the benefit of other customers unless the Enterprise Client gives express written authorisation. We may use irreversibly aggregated or de-identified Service Telemetry that cannot reasonably identify a Client or individual to operate, secure, measure, and improve the Services.
7.4 No Sale or Behavioural Advertising Using Client Data
IICL does not sell Client Data or use the content of End-User conversations processed on a Client’s behalf for third-party behavioural advertising.
8. Consent, Notices, Recording, and Marketing Communications
The Enterprise Client is responsible for deciding whether it may lawfully contact an End User and whether it may record, transcribe, analyse, retain, or combine an interaction. Where required, the Client must:
- provide a clear notice identifying the Client and the purpose of the interaction;
- disclose that the interaction is automated, AI-assisted, recorded, or monitored;
- obtain valid, specific, informed, and unambiguous consent;
- maintain evidence of consent and the applicable notice;
- offer a practical method to opt out, withdraw consent, or reach a human; and
- honour telecom preferences, suppression lists, Channel rules, and statutory restrictions.
For Indian commercial communications, the Client is responsible for TRAI and DLT obligations, including registrations, approved sender identities, headers, templates, consent, preference scrubbing, number-series requirements, and opt-outs. For WhatsApp automation, the Client must comply with applicable Meta and WhatsApp Business policies, including opt-in and template rules.
IICL may suspend or block a workflow where it reasonably believes consent, lawful authority, or required Channel approval is absent.
9. Cross-Channel Memory and Identity Matching
Where enabled, iVaak can carry context from one Channel to another—for example, a WhatsApp enquiry followed by a voice call. This may require matching identifiers such as a verified telephone number, Client customer ID, email address, session token, or other Client-approved reference.
IICL will use the matching rules configured or approved by the Client. Because shared numbers, recycled identifiers, data-entry errors, and incomplete authentication can lead to incorrect matches, Clients must apply appropriate verification before disclosing account information or taking a consequential action. End Users may ask the Client to correct an incorrect match or delete the associated context where legally available.
10. How We Share Personal Data
We disclose personal data only where reasonably necessary for the purposes described in this Policy, under appropriate legal and contractual controls.
10.1 Enterprise Clients and Their Users
Conversation Data, System Integration Data, analytics, and support information are made available to the Enterprise Client and its authorised personnel according to configured permissions. The Client controls its personnel’s subsequent use.
10.2 Subprocessors and Service Providers
IICL may use carefully selected providers for hosting, cloud infrastructure, telecommunications, messaging, email delivery, speech processing, AI model processing, observability, customer support, identity and access management, security, and professional services. They may process data only for contracted purposes and must protect it under applicable law and agreement.
An up-to-date list of material subprocessors will be available on request from reachus@iicl.in and may later be published at a dedicated subprocessor webpage.
10.3 Communication Networks and Channels
To deliver an interaction, information necessarily flows through upstream networks. Depending on the Client’s configuration, this may include:
- Meta and WhatsApp Business APIs for WhatsApp messages or calls;
- telecommunications carriers, access providers, number providers, and voice gateways for calls;
- SMS aggregators, DLT platforms, access providers, and RCS providers for messaging;
- email providers for email delivery; and
- internet, content-delivery, domain, and hosting infrastructure.
These providers may handle message or call content, identifiers, routing data, delivery status, abuse signals, and account information. They may operate under their own privacy policies and may act as independent Data Fiduciaries/controllers for network operation, policy enforcement, fraud prevention, legal compliance, or their relationship with the Client.
10.4 Connected Enterprise Systems
At the Client’s instruction, the Integration Fabric exchanges data with systems such as Zoho CRM, Shopify, Tally, Google Sheets, support platforms, or custom databases. IICL does not control the data already held by those systems or their independent retention, security, and processing practices.
10.5 Legal, Safety, and Corporate Disclosures
We may disclose information where reasonably necessary to comply with law, respond to a valid court or regulator request, protect rights or safety, investigate fraud or security incidents, or establish or defend legal claims. If a merger, reorganisation, financing, or transfer of relevant business assets occurs, information may be disclosed under confidentiality and transferred subject to this Policy and Applicable Law.
We do not disclose Client Data to another customer.
11. Data Residency and International Transfers
11.1 Hosting Region
The hosting region for Enterprise Client data is defined in the applicable contract or Order Form. For IICL's India deployment, primary IICL-controlled production data at rest is hosted in India. This commitment does not automatically mean that every transmission, support access, backup, or Third-Party Channel processing event remains within India.
11.2 Third-Party Routing
Meta or WhatsApp, telecommunications carriers, SMS or RCS gateways, email networks, model providers, and other enabled services may route, transiently process, or store information outside the selected IICL hosting region under their architecture and terms. IICL will provide material subprocessor and location information to the Enterprise Client on request.
11.3 Strict India-Only Deployment
Where an Enterprise Client requires all storage, processing, support access, backups, and subprocessors to remain within India, that requirement must be expressly stated in its contract and accepted by IICL after a dependency-by-dependency technical review. A public statement that “all personal data is hosted in India” must not be used unless IICL has verified that every enabled architecture path supports it.
11.4 Lawful Transfers
Indian law does not create an unconditional, universal localisation requirement for all personal data under the DPDP Act. Transfers from India are subject to restrictions or requirements notified by the Central Government, applicable DPDP rules as they commence, and any stricter sectoral law or contractual obligation.
Where the GDPR or UK GDPR applies, IICL and the Enterprise Client will use an approved transfer mechanism when required, such as applicable standard contractual clauses, and implement supplementary safeguards appropriate to the risk.
12. Data Retention and Deletion
We retain personal data only for as long as necessary for the purpose described, the Enterprise Client’s documented instruction, security and dispute requirements, and Applicable Law.
12.1 Client Data
Conversation Data and System Integration Data are retained according to the Enterprise Client’s contract and configuration. At the end of the Services, IICL will return or delete Client Data as agreed, except where retention is legally required. Data in protected backups is isolated from ordinary use and deleted through the normal backup cycle.
Publication gate: IICL must publish or contractually document verified default periods for live Conversation Data, call recordings, transcripts, security logs, exports, post-termination access, and backup deletion. Until approved, use the periods stated in the Enterprise Client’s signed Order Form.
12.2 Account and Business Records
IICL retains account, contracting, billing, tax, support, security, and legal records for the period required to manage the relationship, comply with law, resolve disputes, and enforce agreements.
12.3 Erasure Exceptions
We may retain limited information where necessary to comply with law, preserve evidence, prevent fraud, maintain suppression or opt-out records, protect security, or establish, exercise, or defend legal claims. Where feasible, retained information is restricted from other processing.
13. Security
IICL maintains administrative, technical, and physical safeguards appropriate to the nature, scope, context, and risk of the processing. These include, as applicable:
- encryption in transit and encryption at rest for IICL-controlled production data stores;
- access-controlled APIs, least-privilege permissions, and strong authentication;
- logical tenant separation and controlled production access;
- audit logging, monitoring, alerting, and periodic access review;
- secure development, code review, change control, vulnerability management, and patching;
- secrets management and restrictions on production credentials;
- backups, restoration testing, business continuity, and disaster-recovery procedures;
- incident response, escalation, and forensic preservation;
- personnel confidentiality, privacy and security training, and access termination; and
- vendor due diligence and contractual security obligations.
No method of transmission or storage is completely secure. Enterprise Clients are also responsible for protecting their accounts, credentials, connected systems, configurations, exports, and authorised users.
IICL will not describe itself as certified against a security standard or publish a specific encryption, residency, recovery, or testing claim unless the claim is supported by current evidence and its exact scope is stated.
14. Personal Data Breaches
IICL maintains procedures to identify, investigate, contain, remediate, and document personal data breaches.
Where IICL acts as a Data Processor, it will notify the affected Enterprise Client without undue delay after confirming a personal data breach involving that Client’s data and will provide reasonably available information needed for the Client’s assessment and notices. The Enterprise Client remains responsible for notifying Data Principals and regulators unless law imposes a direct obligation on IICL.
Where IICL acts as Data Fiduciary or controller, it will provide notices required by applicable law. This may include notification to the Data Protection Board of India and affected Data Principals under the DPDP framework as relevant provisions commence, and reporting qualifying cyber incidents to CERT-In within applicable timelines.
15. Rights of Data Principals and Data Subjects
Rights depend on the applicable law and IICL’s role.
15.1 End Users of an Enterprise Client
If you interacted with an organisation through an iVaak-powered voice, WhatsApp, web, email, SMS, or RCS experience, submit your request first to that organisation. It is the Data Fiduciary/controller and can identify the purpose, legal basis, source systems, and full record associated with your interaction.
Subject to Applicable Law, you may be able to request:
- information about processing and access to relevant personal data;
- correction of inaccurate data, completion of incomplete data, or updating of data;
- erasure of data that is no longer necessary or lawfully retained—sometimes described as a “right to be forgotten”;
- withdrawal of consent, where processing is based on consent;
- cessation or temporary restriction of processing where applicable, including while a valid correction or erasure request is assessed;
- grievance redressal;
- nomination of another person to exercise rights in circumstances recognised by Indian law; and
- where the GDPR applies, restriction, objection, portability, and rights relating to certain automated decisions.
Withdrawing consent does not affect processing already lawfully completed. A Client or IICL may continue limited processing where another lawful ground or mandatory retention duty applies.
15.2 How IICL Assists
When IICL receives an End-User request relating to Client-controlled data, we will ordinarily:
- acknowledge or record the request;
- identify the relevant Enterprise Client where reasonably possible;
- refer the requester to the Client or securely transmit the request to it;
- assist the Client with search, access, correction, restriction, export, or deletion where technically and legally required; and
- preserve only the minimum information needed to evidence completion or maintain a lawful suppression record.
IICL will not disclose Client-controlled data until the responsible Client confirms the request and appropriate identity verification is completed. This protects End Users against fraudulent access or deletion requests.
15.3 Direct IICL Data
For data IICL controls directly—such as an iVaak account, business enquiry, or website interaction—send a request to reachus@iicl.in with your name, organisation if applicable, the nature of your relationship with IICL, the right you wish to exercise, and enough information to locate the record. Do not send passwords, one-time passwords, or unnecessary identity documents by ordinary email.
We may request proportionate information to verify identity and authority. We will respond within the period required by Applicable Law. Our internal grievance response target must not exceed 30 days.
15.4 Complaints and Escalation
Contact our Grievance Officer or privacy contact first so we can investigate. If you remain dissatisfied, you may have the right to approach the Data Protection Board of India when its jurisdiction applies, or an appropriate supervisory authority under the GDPR. This does not limit any other lawful remedy.
16. Children and Persons Requiring a Lawful Guardian
iVaak is a business platform and is not directed to children for IICL’s own purposes. An Enterprise Client must not configure iVaak to process a child’s personal data, or the data of a person for whom a lawful guardian acts, unless the use is legally permitted and the Client has implemented verifiable parental or guardian consent and all applicable restrictions.
Where the relevant provisions of the DPDP Act apply, the Enterprise Client must not undertake tracking, behavioural monitoring, or targeted advertising directed at children except where a lawful exemption applies. If IICL becomes aware of an unauthorised child-data workflow, it may suspend the affected processing and require deletion or remediation.
17. Client Responsibilities for Accuracy and System Integrations
The Enterprise Client controls the source data, field mappings, access permissions, business logic, and authoritative systems connected to iVaak. The Client must maintain appropriate backups, reconciliation, validation, approval, and rollback controls.
IICL will investigate a reported sync or workflow issue and will correct errors caused by its failure to implement an agreed specification. IICL cannot correct an inaccurate source record, Client-created rule, insufficient permission, expired credential, undocumented API change, or independent failure of a Client or third-party system.
18. Links and Third-Party Experiences
An iVaak interaction may link to a Client website, payment page, map, document, or third-party application. IICL is not responsible for the privacy or security practices of an independently operated destination. Review the relevant provider’s notice before submitting personal data.
19. Changes to This Policy
We may update this Policy to reflect changes in law, technology, our Services, or our data practices. We will publish the updated date and, where required, provide additional notice or obtain consent. Material changes will not retroactively authorise a materially different use of Client-controlled personal data without a lawful basis and appropriate instruction.
20. Contact and Grievance Officer
Intelligence India.Com Limited (IICL)
Product: iVaak Unified Conversational AI Operating System
Registered office: Unit No. 308 & 309, Jain Sadguru Image's Capital Park, Capital Pk Rd, VIP Hills, Silicon Valley, Madhapur, Hyderabad, Telangana 500081
Corporate identification number: U72900TG2001PLC036080
Privacy contact: reachus@iicl.in
Grievance Officer: Kutumba Rao Meka, Chief Executive Officer
Grievance email: reachus@iicl.in
Security incident contact: reachus@iicl.in
Website: https://ivaak.ai
Telephone: +91 99894 42002
For an End-User interaction, please also identify the Enterprise Client, Channel, approximate interaction date and time, and telephone number or account reference used, but do not include sensitive authentication information in your first message.
Appendix A — Processing Transparency Summary
| Topic | Public commitment |
|---|---|
| Product provider | Intelligence India.Com Limited (IICL), operating iVaak |
| End-User data role | IICL is ordinarily Data Processor; Enterprise Client is Data Fiduciary/controller |
| Core data | Voice, transcripts, chats, WhatsApp, email, SMS/RCS, metadata, cross-channel context, integration records, and operational logs |
| Core purposes | Customer-service automation, persistent context, transactional resolution, approved workflows, analytics, security, and human handoff |
| Ownership | Enterprise Client retains ownership of Client Data under the enterprise agreement |
| Shared-model training | No use of Client conversation content to train a shared or general-purpose model without express written authorisation |
| Primary India hosting | Primary IICL-controlled production data at rest is hosted in India; upstream Channel routing exceptions apply |
| Channel routing | Upstream providers may process data under their architecture, locations, terms, and legal duties |
| Rights route | End Users contact the Enterprise Client first; IICL assists the Client and handles direct-IICL requests itself |
| Security | Risk-based administrative, technical, and physical safeguards, including encryption and access-controlled APIs |
