Privacy Policy
Convarza AI carries your customers’ conversations — chats, emails and phone calls. This policy sets out what we collect, what we do with it, who else touches it, and what you can ask us to do about it.
Last updated 2 September 2026 · Profunnel Technologies Private Limited
The short version. Everything your team and your customers put into Convarza AI — contacts, chats, calls, recordings, transcripts — belongs to you. We are the processor; you are the controller. We do not sell it, and we do not access it except to keep the service running, to answer a support request you raised, or where we are legally obliged to.
1. Who we are
Convarza AI is operated by Profunnel Technologies Private Limited (“Convarza”, “we”, “our”, “us”), a company registered in India with its office at 268, Tower Blossom, Gaur Saundaryam, Techzone IV, Greater Noida West, Gautam Budh Nagar, Uttar Pradesh 201318.
This policy is intended to comply with applicable data protection laws, including the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) and similar global privacy frameworks.
2. What this policy covers
- Visitors to convarza.com and any related domain.
- Users of the Convarza AI platform and its mobile applications.
- People invited into a workspace by one of our customers.
- People who contact us through a form, an advertisement, an event or email.
- End customers of our customers — the people whose calls and messages flow through the platform. For that data, our customer is the controller and we are the processor; see section 5.
3. Two very different kinds of data
Almost every complaint about SaaS privacy policies comes from blurring these, so we will state them separately and keep them separate throughout.
- Account data — we are the controller
- Data about you as our customer: your name, work email, phone number, job title, company, billing details, login credentials, IP address, and how you use the product.
- Customer data — we are the processor
- Everything your workspace holds: contact records, conversations across every channel, call recordings and transcripts, notes, tasks, calendar events, attachments, knowledge-base documents and the prompts you write for your AI agents. This is your data. We hold it on your instructions.
4. What we collect, and how
4.1 When you interact with us
Visiting the site, submitting a form, requesting a demo, signing up, or contacting support. We collect what you give us plus standard technical data — IP address, browser, referring page.
4.2 When you use the platform
Account-level and usage data (who signed in, which features were used, when), plus everything you and your team put into the workspace.
4.3 Calls, recordings and transcripts
Because Convarza AI answers and makes phone calls, we necessarily handle:
- Call metadata — the numbers involved, direction, start and end time, duration, the outcome your agent logged, and which channel carried it.
- Audio recordings, where recording is enabled on the channel or required by the feature you are using.
- Transcripts and AI-generated summaries derived from that audio.
Recording is your legal responsibility, not ours. Consent and notification rules for recording a call differ by country and sometimes by state. You decide whether recording is on, and you are responsible for telling the other party where the law requires it. We give you the controls; we cannot give you the consent.
4.4 Messaging channels
When you connect WhatsApp, Instagram, Facebook, Telegram, Viber, LINE, SMS, email or the web widget, we receive the messages sent to and from that channel, the sender’s identifier (phone number, handle or email address), and delivery metadata. Connecting a channel through single sign-on also gives us the access tokens needed to operate it, which we store encrypted.
4.5 Calendars
If you connect Google or Microsoft, we access — with your explicit OAuth consent, and only within the scopes you approve — the calendars and events you select, so we can show your availability and create the events you or your booking links ask us to. See section 9.
4.6 Cookies
The website uses cookies and similar technologies to remember preferences, understand traffic and measure campaigns. You can manage them in your browser or through our consent banner. The product itself uses only the cookies needed to keep you signed in and secure.
5. Customer data: what we will and will not do
For everything in your workspace, you are the controller and we act on your documented instructions.
- We do not sell it, rent it, or share it for anyone else’s marketing.
- We do not access it except to operate the service, resolve a support request you raised, or comply with a binding legal obligation.
- You are responsible for the accuracy and lawfulness of what you put in, and for having a lawful basis to contact the people in it.
- We will not act on access or deletion requests that reach us from third parties about your data — we will refer them to you, because only you can decide.
6. Outbound calling and messaging
Convarza AI can dial and message at volume. That capability carries obligations that sit with you as the controller:
- You must have a lawful basis to contact each person on your list.
- You must honour do-not-call and do-not-disturb registers that apply where you are calling, and you must respect opt-outs. The platform records a DND lead stage and removes those contacts from calling lists; keeping the register current is your job.
- You must observe the calling-hours restrictions that apply in the recipient’s jurisdiction. The platform lets you set them per channel; it does not know your local law.
- Where you use an AI voice agent, you must not misrepresent it as a human where disclosure is required.
7. How we use account data
- To provide, secure and improve the service.
- To authenticate you and administer your account and billing.
- To answer support requests.
- To send service notices and product updates.
- For marketing, where you have not opted out.
- To understand aggregate usage and decide what to build. Analysis of this kind is done on aggregated or anonymised data that does not identify an individual.
8. Who else processes data
Running the service means data passes through third parties. Data handled on their side is governed by their own privacy policies, and we encourage you to review them before connecting a service. The categories are:
- Cloud hosting and storage
- Infrastructure providers who host the platform and its backups.
- AI model providers
- The large-language-model and speech vendors that power your AI agents. Content is sent to them to generate a response, and is handled under their terms.
- Telephony carriers
- Twilio, Maqsam, or your own SIP carrier — whichever line you connect. Your carrier relationship and its own terms are yours.
- Messaging platforms
- Meta (WhatsApp, Instagram, Facebook), Telegram, Viber, LINE and your email or SMS provider. Data on their side is governed by their policies.
- Payments, analytics and support tooling
- Our payment processor, product-analytics tooling and support desk.
9. Google and Microsoft calendar data
Access is requested through OAuth and needs your explicit consent. We ask for the narrowest scopes that make the feature work — reading the calendars you select, and creating or updating the events you ask us to schedule — plus your email address and basic profile so we can attach the connection to your account.
We use this data only to deliver the features you initiated. We do not use it for advertising, we do not build profiles from it, and we do not sell it. We do not share it except as needed to provide the feature, comply with law, or enforce our agreements.
Tokens are stored encrypted, limited to the scopes you approved, and kept only while the connection is live. You can revoke access at any time — for Google at myaccount.google.com/permissions, for Microsoft in your account’s app permissions — or by disconnecting inside Convarza AI.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
10. Deletion and retention
- Data you delete in the product moves to Trash for 30 days, where you can restore it.
- After 30 days it is permanently deleted and cannot be recovered.
- If you empty the Trash yourself, deletion is immediate and irreversible across our systems.
- We keep no separate copies of permanently deleted content.
- Call recordings and transcripts follow the same rules as any other content you delete.
- On termination, we delete or return workspace data in line with the Terms of Service.
- Account and billing records are kept for up to seven years for tax, accounting and legal-defence purposes, then deleted or anonymised.
Please be careful. Permanent deletion is permanent.
11. Where data is processed
We process data in India and in other countries where our service providers operate. If your organisation has a data-residency requirement, raise it with us before you subscribe rather than after, so we can tell you whether we can meet it.
12. Security
- Encryption in transit and at rest.
- Role-based access control, mirroring the agent, manager and admin roles in the product.
- Secrets, tokens and carrier credentials stored encrypted and masked in the interface.
- Access to production limited to staff who need it, and logged.
- Monitoring, backups and a documented incident-response process.
No system is perfectly secure, and we do not claim otherwise.
13. Your rights
Depending on where you live, you may have the right to access your personal data, correct it, delete it, restrict or object to processing, withdraw consent, or receive it in a portable form. You also have the right to complain to your data protection authority.
Write to privacy@convarza.com. We may require verification before fulfilling your request. We do not treat anyone worse for exercising these rights.
If your request concerns data held inside a customer’s workspace, we will pass it to that customer, who is the controller and the only party who can act on it.
14. Children
Convarza AI is a business product. It is not directed at anyone under 18 and we do not knowingly collect their data. If you believe a minor’s data has reached us, tell us and we will remove it.
15. Changes
We may update this policy. Where a change is material we will tell you by email or in the product before it takes effect. The date at the top of this page always reflects the current version.
16. Contact
Profunnel Technologies Private Limited
268, Tower Blossom, Gaur Saundaryam, Techzone IV, Greater Noida West,
Gautam Budh Nagar, Uttar Pradesh 201318, India
Privacy: privacy@convarza.com
Sales: sales@convarza.com
Support: support@convarza.com