Automataiz
ENTERPRISE TRUST CENTER // PRIVACY POLICY v1.0

Your Privacy Matters. Enterprise Trust by Design.

At Automataiz, protecting your business data is one of our highest priorities. This Privacy Policy explains how we collect, use, protect, and manage your information when you use our AI Business Operating System.

AES-256 & TLS 1.3
Bank-Grade Encryption
Zero AI Model Training
Customer Data Protected
Tenant Isolation
Multi-Tenant Guardrails
DPDP & GDPR Ready
Global Privacy Aligned

1. Introduction & Scope

Who we are, the purpose of this policy, and whom it protects across the Automataiz ecosystem.

Governance

Welcome to the Automataiz Trust & Privacy Center. Automataiz Technologies ("Automataiz," "we," "our," or "us"), headquartered in Bhubaneswar, Odisha, operates the all-in-one AI-powered Business Operating System (the "Platform") designed to help modern businesses market, sell, operate, and scale through a unified intelligent environment.

This Privacy Policy sets forth our high standards of transparency, data governance, and privacy protection. It outlines how we collect, store, process, transfer, and safeguard business data, personal credentials, customer records, and AI interactions across our web applications, APIs, mobile interfaces, and digital workforce agents.

Who This Policy Applies To:

  • Business Customers & Account Owners: Registered organizations, founders, administrators, and team members utilizing our operating system.
  • End-Users & Client Leads: Individuals who interact with our customers via Automataiz-hosted funnels, landing pages, forms, web chat widgets, WhatsApp WABA broadcasts, or IVR calls.
  • Website Visitors: Any person accessing our public web properties, interactive simulators, knowledge resources, or booking pages.

2. Information We Collect

Comprehensive catalog of personal, operational, communication, and technical data collected.

Data Inventory

We collect information strictly necessary to provide enterprise-grade software capabilities, maintain multi-tenant security, and deliver intelligent automated business outcomes.

A. Personal & Account Information

Full names, business email addresses, verified phone numbers, authentication credentials, billing contact details, staff roles, and profile preferences.

B. Business & Operational Telemetry

Company names, industry vertical configurations, team member headcount, pipeline stages, revenue inputs entered into ROI simulators, and custom field schemas.

C. Communications & Customer Data

Customer contact records, form submissions, appointment bookings, email campaign engagement, official WhatsApp Business API (WABA) transcripts, SMS logs, and IVR telecalling records.

D. AI Interactions & Knowledge Assets

Prompts entered into Nova AI, instructions for AI SDR and digital agents, and proprietary business documents (SOPs, PDFs, policy docs) uploaded into the Knowledge Vault or AI Studio.

Device & Usage Analytics:IP addresses, browser signatures, operating system telemetry, login timestamps, referral URLs, and session performance logs to prevent unauthorized account access and optimize platform speed.

3. How We Use Your Information

The specific legitimate business and operational purposes governing all data processing.

Processing Rationale

Automataiz processes collected information solely to fulfill our contractual commitments, deliver requested business services, and improve platform reliability.

Service Delivery & Multi-Engine ExecutionExecuting CRM pipeline automations, routing WhatsApp messages, powering drag-and-drop builders, and provisioning unified inbox operations.
AI Co-Pilot & Digital Workforce CapabilitiesSupplying real-time context to Nova AI, enabling AI SDR lead qualification, and generating automated executive briefings on the CEO dashboard.
Billing & Financial OperationsProcessing recurring SaaS subscriptions, calculating wallet ledger usage for metered telephony/AI APIs, and issuing GST-compliant invoices.
Platform Security, Fraud Prevention & Audit LoggingDetecting malicious traffic, enforcing role-based permissions, monitoring SLA thresholds, and maintaining immutable security audit trails.
Customer Support & Systems EngineeringDiagnosing technical bottlenecks, responding to support inquiries, and delivering critical service advisories.

4. AI Data Processing & Zero-Model-Training Guarantee

Our strict zero-training privacy architecture, tenant isolation, and customer-owned AI models.

AI Architecture
THE AUTOMATAIZ ZERO-MODEL-TRAINING GUARANTEE

We hold a strict foundational policy: Your proprietary business data, uploaded SOPs, customer records, and private prompts are NEVER used to train public or foundational third-party AI models. Your organizational intelligence remains 100% yours.

1. Ephemeral Retrieval-Augmented Generation (RAG)

Documents in your Knowledge Vault are converted into private cryptographic vector embeddings. Context is injected into prompts strictly at runtime and deleted from processing memory immediately after response generation.

2. Strict Multi-Tenant Logical Isolation

Every business organization operates in an isolated cryptographic tenant space. AI Agents assigned to your workspace cannot query, cross-reference, or leak data into another company's environment.

3. Customer-Owned API Key (BYOK) Support

For enterprises with direct contracts with LLM vendors (OpenAI, Anthropic, Google Vertex AI), Automataiz supports direct API key passthrough so all telemetry stays bound to your sovereign enterprise agreements.

4. Human Review & Access Controls

Automataiz engineers and staff do NOT inspect private business prompts or uploaded documents unless explicitly granted temporary written permission by your authorized administrator for debugging purposes.

5. Cookie Policy & Tracking Technologies

How cookies, session tokens, and local storage are utilized and how you can manage them.

Tracking Controls

We use cookies and secure browser storage technologies to maintain authenticated sessions, secure user accounts, and provide responsive platform interactions.

Essential & Security Cookies:Mandatory cookies required for user authentication, CSRF token validation, session persistence, and load balancing across our cloud cluster.
Functional & Preference Cookies:Preserve user interface settings, dark-mode styling, active simulator configurations, and temporary form draft data.
Analytics & Performance Cookies:Anonymized, aggregated telemetry to gauge page load velocities, API response latency, and feature adoption across the platform.

You can configure your browser to block or alert you about cookies; however, disabling essential session cookies will prevent login into the Automataiz application.

6. Third-Party Services & Sub-Processors

Verified infrastructure partners, payment gateways, and communication networks.

Ecosystem Partners

To deliver global enterprise SaaS reliability, Automataiz partners with industry-leading sub-processors adhering to stringent data protection standards (SOC 2, ISO 27001, PCI-DSS).

Cloud Infrastructure & Compute

AWS / Google Cloud enterprise data centers with 99.99% uptime SLAs and hardware encryption.

Payment & Billing Gateways

Razorpay and Stripe for PCI-DSS Level 1 compliant card, UPI, and recurring subscription processing.

Telephony & WhatsApp WABA

Meta WhatsApp Business API, licensed telecom DLT SMS aggregators, and Twilio/Exotel for voice IVR.

Third-Party Customer Integrations

Any optional app connected via the App Store (e.g. Google Calendar, Zoom) only receives data explicitly permitted by your admin.

7. Enterprise Data Security & Encryption

Bank-grade cryptographic standards, role-based access, automated backups, and disaster recovery.

Defense in Depth

We implement defense-in-depth architectural safeguards to shield your business against unauthorized access, loss, or data alteration.

TLS 1.3
In-Transit Encryption for all API & Web traffic
AES-256
At-Rest Database & File Vault Encryption
RBAC + MFA
Role-based controls and mandatory multi-factor auth
Automated Backups & Disaster Recovery: Encrypted multi-region daily snapshots with 15-minute point-in-time recovery capabilities.
Immutable Audit Trails: Every administrative change, staff login, and API request is logged with immutable timestamps.
AI 3-Level Governance Guard: Multi-tiered approval requirements (Level 1: Auto, Level 2: Manager, Level 3: Executive) to prevent unintended actions.

8. International Data Transfers & Sovereignty

Mechanisms ensuring cross-border transfer compliance with global privacy regulations.

Global Compliance

Automataiz serves enterprises globally. When customer data is routed across international boundaries for processing (such as global CDN edge nodes or multi-region LLM endpoints), we enforce rigorous safeguards.

All international transfers are executed pursuant to Standard Contractual Clauses (SCCs), robust Data Processing Addendums (DPAs), and strict compliance with the Indian Digital Personal Data Protection Act (DPDP), the European General Data Protection Regulation (GDPR), and cross-border encryption mandates.

9. Data Retention & Account Deletion

How long information is preserved and our instant data portability and purge processes.

Lifecycle

We retain business and account data for the duration of your active subscription. You maintain total sovereign ownership over your customer records.

Account Closure & Complete Purge:

Upon account cancellation, all customer contact databases, Knowledge Vault assets, and AI history are permanently erased from active servers within 30 days.

1-Click Full Data Portability:

Export your entire CRM contact registry, deals, pipeline logs, and invoice receipts in standardized CSV or JSON formats at any time.

10. Your Privacy Rights & Controls

Your rights regarding access, rectification, deletion, restriction, and consent withdrawal.

User Empowerment

Regardless of your geographical location, Automataiz extends full privacy rights to all organizations and their authorized users:

Right to Access: Request a full copy of all data stored in your organization.
Right to Rectification: Correct inaccurate or outdated customer details.
Right to Erasure (Be Forgotten): Request permanent deletion of specific records.
Right to Restrict Processing: Limit how specific sub-modules handle your data.
Right to Object: Opt out of marketing notifications and non-essential telemetry.
Right to Withdraw Consent: Revoke previously granted permissions instantly.

To exercise any of these statutory rights, submit a request directly to our Data Protection Office at privacy@automataiz.com. We fulfill verified requests within 30 days with zero processing fees.

11. Children's Privacy

Automataiz is exclusively a commercial enterprise B2B platform.

B2B Restriction

Automataiz is an enterprise Business Operating System designed strictly for commercial organizations, entrepreneurs, and professional teams. The Platform is not intended for or directed toward individuals under the age of 18. We do not knowingly solicit or collect personal information from minors.

12. Changes & Policy Version Updates

Notification protocol for policy amendments and revision logs.

Versioning

As Automataiz introduces new AI capabilities, vertical solutions, and regulatory adaptations, we may update this Privacy Policy periodically.

When material updates occur, we will notify registered account administrators via email and display a prominent notification banner inside the platform dashboard at least 30 days prior to the effective date.

Current Version: v1.0 (Enterprise Trust Release)Effective: January 1, 2025

13. Privacy Office & Grievance Contact

Direct contact channels for our Legal, Privacy, and Grievance Officer in Bhubaneswar, Odisha.

Direct Contact

If you have questions, inquiries, or security disclosures regarding this Privacy Policy or our data governance architecture, please contact our dedicated Privacy & Legal Office:

Automataiz Privacy & Grievance Office

Officer: Debasish Kabi (Founder & CEO)
Headquarters:Automataiz, Om City, Mancheswar, Bhubaneswar, Odisha – 751017, India
Dedicated Privacy Email:privacy@automataiz.com
CC: hello@automataiz.com
Helpline & Legal Desk:+91 8338091603
Response SLA:Under 24 business hours guaranteed

Need an Enterprise Custom DPA or BAA?

We provide custom Data Processing Addendums (DPAs), standard security questionnaires, and audit assistance for scaling enterprises.

Request Enterprise DPA