Privacy Policy
Zudu AI Private Limited
Last Updated: 21 August, 2025
1. Introduction & Scope
Zudu AI (“we,” “our,” or “us”) is an advanced AI-driven voice automation platform that enables businesses to deliver human-like, multilingual, and context-aware voice interactions at scale. This Privacy Policy explains how we collect, use, store, share, and protect personal and business information when you use:
- Zudu AI’s Voice AI Agent Platform
- Related websites, mobile applications, and dashboards
- API integrations and telephony services
- Any other service where this policy is linked or referenced
Definitions
- Clients – Businesses, organizations, or professionals who create an account with Zudu AI, configure integrations, manage subscriptions, and determine how the platform is used. Clients act as the data controllers for their End Users’ information where required by law.
- End Users – The customers, callers, or other individuals whose interactions (voice, text, or call metadata) are processed through Zudu AI on behalf of a Client. End Users do not directly contract with Zudu AI but may have personal data processed by our platform.
This policy applies to both our direct business clients (who create accounts and integrate Zudu AI into their systems) and end-users/customers whose interactions are processed through our platform.
By using Zudu AI, you consent to the practices described in this Privacy Policy. We comply with applicable privacy laws, including GDPR, CCPA/CPRA, PIPEDA, and other regional requirements, and this policy forms part of our Terms of Service.
2. Information We Collect
We collect the following categories of information to deliver, improve, and secure our Services:
a. Account Information
- Name, business name, email, and phone number
- Login credentials (encrypted; we never store raw passwords)
- Billing and payment details (processed via PCI-DSS–compliant providers)
- Information provided during sign-up, subscription purchase, or platform integration
b. Call Content
- Audio call recordings and/or real-time streams (where enabled by Client)
- Voicemails and transcripts generated by our AI agents
- Caller ID, callee ID, call duration, and timestamps
- IVR menu inputs or keypad tones
c. User Communications
- Support inquiries (email, chat, or ticket systems)
- Feedback forms and survey responses
- Interactions with our customer support team
d. Technical & Usage Data
- IP addresses, device identifiers, browser type, operating system
- Activity logs (pages visited, features used, time spent)
- Cookies, pixels, and similar tracking technologies (see Section 12)
- AI usage telemetry (error logs, concurrency metrics, service performance)
e. Third-Party Data
- Data received from integrated telephony providers (e.g., Twilio, Vonage)
- CRM/helpdesk integrations (contact records, API tokens, identifiers)
- Single Sign-On (SSO) data from Google, Microsoft, or other identity providers
- External compliance databases (e.g., do-not-call registry status)
Exclusions & Assurances
- We do not collect sensitive government identifiers (e.g., Aadhaar, Social Security) or raw bank account numbers unless required for a specific feature and subject to strict protection.
- Call recordings and transcripts are processed solely to deliver Client-requested services and are not used to train our AI models.
3. How We Collect Data
- Directly from Users: Information entered into our sign-up forms, uploaded call lists, audio files, or scripts
- Automatically: Metadata, cookies, and technical logs collected when users access our website, dashboard, or make/receive calls
- From Third Parties: OAuth login providers, telephony carriers, CRM systems, or public databases
4. Purpose of Processing Data
We use collected data for:
- Service Delivery – Transcribing calls, responding via AI, routing calls, authenticating accounts
- Service Improvement – Analysing interactions to enhance AI models, fix bugs, and optimize features
- Analytics – Understanding usage patterns, feature adoption, and call performance metrics
- Communication – Sending account updates, service notices, billing, and—with consent—marketing content
- Compliance & Protection – Detecting fraud, enforcing Terms of Service, meeting legal obligations
- Personalization – Tailoring dashboard settings and recommendations
We do not process personal data for unrelated purposes without consent.
5. Data Storage & Retention
- Storage: Secure cloud servers with encryption at rest (AES-256) and in transit (TLS 1.2+). Primary storage in Microsoft Azure with regional options where required.
- Retention:
- Account data – retained while the account is active
- Call recordings/transcripts – default retention period is 90 days unless otherwise specified by the client or required by law.
- Legal retention – certain data may be stored longer to meet regulatory requirements
- Data is securely deleted or anonymized after retention periods expire.
6. Data Sharing & Disclosure
We share data only with:
Service Providers – Cloud hosting, telephony carriers, speech AI APIs, analytics, payment processors
Telephony & Integrations – Call metadata/audio sent to integrated carriers or CRM systems as configured by clients
Affiliates – For internal business purposes consistent with this policy
Business Transfers – In case of merger/acquisition, subject to this policy
Legal & Safety – As required by law or to protect our rights and users
- We do not sell personal data.
- We may share limited personal data with trusted service providers (“sub-processors”) solely for the purpose of delivering our Services. These include cloud hosting, telecommunication platforms, analytics providers, and payment processors.
- A current list of sub-processors (e.g., Microsoft Azure, Twilio, Google Cloud, payment gateways) is maintained and available on request or via our website.
7. User Rights & Control
We recognize different roles under applicable data protection laws:
- Clients (business customers): Zudu AI acts as a data controller for Client account data, billing information, and communications.
- End Users (callers interacting with AI agents): Zudu AI acts as a data processor, processing End User data only on behalf of and under the instructions of our Clients.
Depending on your jurisdiction, you may have the right to:
- Access and correct personal data
- Request deletion of personal data
- Restrict or object to processing
- Data portability (export in common formats)
- Withdraw consent for optional processing
Requests can be made via [email protected]
If you are an end-customer of one of our clients, please contact that client directly; we will assist them as required.
8. Call Recording & Consent Policy
- Calls may be recorded/transcribed to deliver AI services.
- Clients are responsible for ensuring consent under local law.
- Opt-out and “privacy mode” features are available to disable storage of call content.
- Metadata (time, duration, numbers) is always logged for service and billing.
- Training use of call data is opt-in.
- We don’t use call recordings to train our AI models.
9. Data Security Measures
- We implement technical and organizational safeguards aligned with recognized industry standards, including SOC 2 Type II and ISO/IEC 27001 frameworks.
- We are preparing for HIPAA readiness and may enter into Business Associate Agreements (BAAs) with healthcare sector Clients when required.
- Encryption – In transit and at rest
- Access Controls – Role-based permissions and limited staff access
- Monitoring – Intrusion detection, penetration testing, incident response procedures
- Breach Notification – Prompt communication as required by law
9A. Business Continuity, Backups & Disaster Recovery
We maintain disaster recovery and business continuity measures to ensure resilience and minimize disruption to our Services.
These include:
- Data Backups – Encrypted backups of account data and call-related records are performed regularly and stored in geographically redundant data centers.
- Redundancy – Critical infrastructure is hosted on cloud providers with high-availability zones to mitigate single points of failure.
- Disaster Recovery – Documented disaster recovery plans allow restoration of core services within defined Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), subject to system dependencies.
- Testing & Review – Our disaster recovery processes are periodically tested and reviewed to ensure effectiveness.
- Client Responsibilities – While we safeguard platform continuity, Clients are encouraged to maintain their own backups and business continuity plans, especially for data exported or stored outside Zudu AI systems.
10. International Data Transfers
Zudu AI operates globally, and data may be transferred across jurisdictions where our service providers are located. All such transfers comply with applicable laws and safeguards.
As we are headquartered in India, we also comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) for processing of Indian personal data.
11. Compliance with Privacy Laws
We comply with:
- GDPR – Legal bases include contract, legitimate interest, and consent
- CCPA/CPRA – Right to know, delete, and opt-out; “Do Not Sell” honored
- HIPAA – Optional compliance mode with BAAs for healthcare clients
- Other – PIPEDA (Canada), PDPA (Singapore), etc.
12. Cookies & Tracking Technologies
We use cookies and similar technologies for analytics, performance monitoring, and improving user experience. Where Google Analytics or similar tools are used, IP anonymization is enabled to reduce identifiability.
We do not sell personal data to third parties. Data collected through cookies may be shared with trusted analytics and advertising partners in accordance with this Policy and subject to consent where required.
We use:
- Essential Cookies – For authentication and security
- Preference Cookies – To remember settings
- Analytics Cookies – For usage insights (e.g., Google Analytics)
- Advertising Cookies – Only if enabled and with consent
You can control cookies via browser settings or our cookie preferences page.
13. Children’s Privacy
Zudu AI’s Services are intended for business and enterprise use only. We do not knowingly collect personal information from individuals under the age of 18. If we become aware of such data being provided, we will promptly delete it.
14. Changes to the Privacy Policy
We may update this policy. Material changes will be notified via email or in-app. Continued use after the effective date indicates acceptance.