Legal

Privacy Policy

Last updated 6 October 2026

Draft — not yet reviewed by a lawyer. The structure and the factual descriptions of how the product handles data are accurate, but nothing here is legal advice. Have counsel review it before this page is relied on, then remove this notice.

This explains what personal data the platform holds, who it is shared with, how long it is kept, and what you can ask us to do with it.

  1. 01Who this covers

    ArthaBuddy provides a calling platform to businesses that work enquiries by phone — lenders and loan advisories first, and other sales teams. Those businesses upload their own enquiry lists and use the platform to call them, so for that data they are the Data Fiduciary and we act as a Data Processor on their instructions.

    Where we collect data directly — from someone visiting this website, or from a person we employ to use the platform — we are the Data Fiduciary ourselves. This policy covers both, and says which is which.

    The operator of this platform is [registered entity name and address].

  2. 02If you book a demo

    Demo bookings on this website are handled by Calendly, a scheduling service. When you book, Calendly collects your name, your email address and your answers to the booking questions, and passes them to us so we can arrange the call. For this data we are the Data Fiduciary, and Calendly processes it on our behalf.

    The booking window is loaded from Calendly's servers when a page on this site opens, so Calendly also receives the technical details any website receives from a browser, such as an IP address.

    We use booking details to arrange and prepare for the demo and to follow up about it. To have them deleted, write to [contact email].

  3. 03What we hold about a person being called

    A lead record is created by our customer, not by us. It can contain:

    • name, and mobile number, both required
    • an alternate mobile number, email address and date of birth
    • the product enquired about, employment type, and where the enquiry came from
    • an indicative amount, the name of a referrer, and free-text notes

    The platform has no field for a PAN, Aadhaar or any other government identifier, deliberately, so that this category of data is never handled at all. Leads must be 18 or over; a date of birth that reads as under-18 is rejected at import.

  4. 04Calls, recordings and transcripts

    When a call is placed we record the time it started, how long it lasted, whether it connected, what it cost, and the outcome the caller or the agent selected.

    Calls may be recorded, and calls handled by an AI agent are also transcribed so the conversation can be reviewed. A recording and its transcript are personal data and are treated as such: access is limited to users whose role grants it, and audio is served through short-lived signed links rather than public URLs.

    Our customer decides whether recording is on and is responsible for whatever notice or consent the call requires.

  5. 05Calls made by an AI voice agent

    Some calls are placed by an automated voice agent rather than a person. By default the agent states that it is an AI at the start of the call; a business using the platform can turn that opening announcement off. Either way, the agent never claims to be a person and says that it is an AI whenever it is asked — that part is built into the service and cannot be switched off from the dashboard.

    Anyone can ask to speak to a person, ask not to be called again, or end the call at any point.

  6. 06How calling is restricted

    Every number is checked against the national Do Not Disturb registry at the moment a call is about to be placed, rather than only when the list was uploaded. A registered number is not dialled.

    Calls are placed only between 09:00 and 21:00 India Standard Time, and every attempt — including one that was blocked — is written to an append-only record.

  7. 07Users of the platform

    For the telecallers, managers and administrators who sign in, we hold a name, email address, mobile number, a hashed password, the role assigned, and a log of the actions taken in the application.

    The mobile number is needed because outbound calls ring the user's own phone first and bridge the customer afterwards, which is what keeps the user's personal number hidden from the person being called.

  8. 08Who else the data reaches

    We use a small number of processors, each receiving only what its job requires:

    • a licensed telecom provider, to place calls and store recordings
    • a speech provider, to convert speech to text and text to speech on AI calls
    • a language-model provider, to generate the agent's replies during a call
    • a cloud hosting and database provider
    • a messaging provider, where a customer has enabled WhatsApp follow-ups
    • a scheduling provider, for demo bookings made on this website

    Where a customer has configured it, qualified leads are also pushed to that customer's own CRM. We do not sell personal data, and we do not share it for anyone else's advertising.

  9. 09Where data is stored

    Data is stored on infrastructure that may be located outside India. Some processing — in particular the language model that generates an AI agent's replies — happens outside India because no equivalent service is currently available in-region at usable latency.

  10. 10How long we keep it

    Lead and call records are kept for as long as our customer's account is active, and are deleted or returned when that account closes.

    Recordings held by the telecom provider are deleted by them after 180 days. A recording deleted from the platform is removed from our own storage and stops being playable; the confirmation shown at the time says plainly what has and has not been erased.

    Notifications are cleared automatically after 30 days once read, or 90 days if never read.

  11. 11Security

    Access is controlled by role, and permissions are checked when data is queried rather than only when a page is drawn, so a user cannot reach records outside their assignment by changing a URL.

    Phone numbers are masked for roles that do not need to see them, including in exports and in the activity log. Passwords are stored hashed. Recordings are served through expiring signed links.

    No system is perfectly secure, and we do not claim otherwise.

  12. 12Your rights

    Under the Digital Personal Data Protection Act, 2023 you may ask for access to your personal data, ask for it to be corrected or completed, ask for it to be erased, nominate someone to act for you, and complain about how it has been handled.

    If your data reached us because one of our customers uploaded it, that business decides these requests and we act on their instruction — so the fastest route is to contact them. Ask us and we will tell you who they are and pass the request on.

    To exercise any of these, write to [contact email].

  13. 13Grievance Officer

    The Act requires a named contact for complaints. Ours is:

    • [Name]
    • [Postal address]
    • [Email address]

    We aim to acknowledge a grievance within 72 hours and resolve it within 30 days. If you are not satisfied, you may complain to the Data Protection Board of India.

  14. 14Changes

    We will update this page when the platform changes what it collects or who it sends data to, and the date at the top will change with it. Material changes will be notified to account holders directly.

← Back to the home page