Privacy Policy & Digital Personal Data Protection (DPDP) Compliance

Privacy Policy & DPDP Act Compliance

Effective Date: August 2026 | Pragatic AI (pragaticai.com)

1. Overview & Regulatory Framework

Pragatic AI (“Company”, “We”, “Us”, or “Our”) is committed to protecting the privacy, security, and personal data of our users, business clients, and end-consumers. This Privacy Policy sets out how we collect, process, store, and safeguard personal data in strict compliance with India’s Digital Personal Data Protection (DPDP) Act, 2023, the European Union’s General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and applicable global data privacy laws.

2. Roles under Data Protection Laws

  • Data Fiduciary / Data Controller: For client account details, platform registration data, and direct website visitors on pragaticai.com and app.pragaticai.com.
  • Data Processor: When processing customer interactions, call transcripts, WhatsApp messages, and CRM records on behalf of our business clients utilizing our Voice AI agents and chatbot automation tools.

3. Categories of Personal Data Collected

We process personal data necessary to deliver conversational CRM, Voice AI, and automation services:

  • Account & Profile Data: Name, business email address, phone number, organization details, and payment transaction references.
  • Voice AI Call Data: Audio call recordings, automated transcriptions, caller phone numbers, and call sentiment logs generated during inbound AI phone handling.
  • Messaging & Chatbot Data: WhatsApp phone numbers, chat logs, user queries, form responses, and appointment booking selections.
  • Technical & Usage Data: IP address, device information, browser type, cookies, and platform session logs.

4. Legal Grounds for Processing Personal Data

We process personal data only when we have a valid, lawful basis under applicable data protection laws, including Section 6 of India’s Digital Personal Data Protection (DPDP) Act, 2023 and Article 6 of the EU GDPR:

  • ree, Specific, Informed, & Unambiguous Consent (DPDP Act & GDPR):

    • Primary Ground: Under Section 6(1) of the DPDP Act, personal data is processed strictly after obtaining your explicit, affirmative consent at the time of account registration, chatbot interaction, or service onboarding.

    • Withdrawal: You retain the right to withdraw your consent at any time via your account dashboard or by contacting our Grievance Officer.

  • Certain Legitimate Uses (DPDP Act – Section 7 Statutory Exemptions):

    • Processing without fresh consent occurs strictly within the narrow statutory exemptions defined under Section 7 of the DPDP Act, such as data voluntarily provided by you for a specified purpose where consent has not been expressly withheld, or to comply with applicable legal judgments, obligations, and law enforcement requests.

  • Contractual Necessity & Legitimate Interests (GDPR & Global Users Only):

    • For users located in jurisdictions outside India recognizing these bases (e.g., EU/UK under GDPR Article 6(1)(b) & (f)), we process data to execute our service contracts, fulfill business automation, run Voice AI operations, and safeguard platform security.

5. Rights of Data Principals / Data Subjects

Under the DPDP Act 2023 and international privacy standards, individuals (“Data Principals”) possess the following enforceable rights:

  1. Right to Access Information: Summary of personal data being processed and identities of data processors with whom data is shared.
  2. Right to Correction & Erasure: Request correction of inaccurate data or complete deletion (“Right to be Forgotten”) when processing is no longer required.
  3. Right to Withdraw Consent: Withdraw consent at any time through account settings or written request to our Grievance Officer.
  4. Right of Grievance Redressal: Access to a dedicated, responsive grievance mechanism for privacy complaints.
  5. Right to Nominate: Nominate another individual to exercise data rights in the event of death or incapacity.

6. Cross-Border Data Transfers & Storage Security

Personal data is stored in secure, encrypted cloud environments. International transfers comply with DPDP Act cross-border transfer directives, EU Standard Contractual Clauses (SCCs), and industry-standard AES-256 encryption at rest and TLS 1.3 in transit.

7. Data Retention & Security Protocols

Personal data is retained only for as long as necessary to fulfill the original purpose or comply with statutory tax, legal, and regulatory obligations (e.g., GSTR reporting, GSTIN records). Upon contract expiration or consent withdrawal, data is permanently purged or anonymized.

 

8 .  Child Data & Parental Consent (DPDP Requirement)

  • Under Section 9 of the DPDP Act, processing data of minors (under 18) requires verifiable parental consent and strictly prohibits behavioral tracking or targeted advertising.

  • Data Breach Notification Obligation: The DPDP Act mandates that Data Fiduciaries must notify both affected Data Principals and the Data Protection Board of India (DPBI) immediately in the event of a personal data breach.
  • Specific Third-Party Data Sharing Disclosures: Disclose the categories of third-party vendors (e.g., OpenAI/Google Gemini API, cloud hosting like AWS/GCP, payment gateways like Razorpay/Stripe) that act as Data Processors on your behalf.

  • Consent Manager Provisions: Mention that Data Principals may exercise or withdraw consent through registered Consent Managers under DPDP guidelines

8. Grievance Officer & Contact Information

Pursuant to the DPDP Act, 2023, you may address any questions, privacy concerns, or data principal requests to our designated Grievance Officer:

Grievance Redressal Officer — Pragatic AI

Email: privacy@pragaticai.com

Platform URL: app.pragaticai.com

Website: pragaticai.com