Privacy Policy
Last updated: 29 July 2026
VaaniLabs ("VaaniLabs", "we", "us") builds AI voice agents that make and take phone and web calls for collections, customer support, and assisted commerce on behalf of Indian businesses. This Privacy Policy explains what personal data we handle, why, how we protect it, and the rights available to individuals under India's Digital Personal Data Protection Act, 2023 (DPDP Act). It applies to vaanilabs.tech, the VaaniLabs console, and our voice-agent services.
1. Our role: processor, not fiduciary
For most of the personal data flowing through our platform, VaaniLabs acts as a data processor operating strictly on the documented instructions of our business customers (the lenders, NBFCs, D2C brands, and enterprises who use the platform). Those customers are the data fiduciary (controller) who decide why and how the data of their borrowers and callers is used.
If you are an end-consumer (for example, a borrower or caller who spoke with one of our agents) and you want to access, correct, or erase your data, please contact the business you dealt with — they are the fiduciary. VaaniLabs will support that business in fulfilling your request. VaaniLabs is a data fiduciary in its own right only for the limited data of our business customers' own account users (console logins, billing contacts) described in this policy.
2. Data we collect and process
- Contact and lead data: names, phone numbers, email addresses, and account references of the people our customers ask us to call, uploaded or synced by the customer.
- Call audio recordings: separate caller and agent audio tracks, where recording is enabled by the customer.
- Transcripts and call outcomes: speech-to-text transcripts, detected intents, dispositions, and resolution status.
- Connected-source data: where a customer connects a source (their CRM, spreadsheet, or database), data read from that source during a call to personalise the conversation (e.g. outstanding amount, order status).
- Compliance metadata: consent flags, DND status, calling-window and frequency-cap checks, and pre-call disclosure records.
- Console account data: the login and profile details of our business customers' users, plus billing and usage information.
- Technical logs: minimal server logs needed to run and secure the service.
3. Why we process it and legal basis
We process this data to deliver the calling service our customers instruct us to run: placing and receiving calls, transcribing and summarising them, personalising conversations from connected sources, enforcing compliance checks, billing usage, and securing the platform. Under the DPDP Act, the lawful basis rests with the data fiduciary (our customer), who is responsible for obtaining valid consent or relying on another legitimate use before instructing us to contact an individual. We process only as needed to provide the service and do not sell personal data or use it for our own advertising.
4. Compliance-native calling
The platform is built to the DPDP Act and the RBI Digital Lending Directions, 2025. Every outbound call carries a pre-call agent-identity disclosure. A compliance gate blocks any dial that fails calling-hours, consent, frequency-cap, or DND checks. Each such decision is hashed and KMS-signed into an append-only audit chain so that the compliance record cannot be silently altered after the fact.
5. How we secure your data
- Encryption at rest: stored credentials and secrets are protected with AES-256-GCM field-level encryption, and the master key is held outside the database — so a database dump on its own cannot decrypt them.
- Encryption in transit: traffic is protected with TLS.
- Tenant isolation: data is separated per workspace using row-level security in our Postgres (Supabase) storage.
- Sensitive-field redaction: fields such as passwords, card numbers, CVV, Aadhaar, and tokens are redacted before any data reaches the AI model or the transcript.
- Retention controls: recordings and transcripts are retained per the customer's configured retention settings.
6. Sub-processors
We rely on a small set of infrastructure and model providers to run the service, including a real-time telephony and media transport layer (LiveKit and telephony carriers), a managed Postgres database and object storage provider (Supabase), and speech and language model providers used for transcription and conversation. Each sub-processor is engaged to process data only for the purposes above and under appropriate contractual safeguards.
7. Cross-border processing
Our goal is India-region processing, and we architect toward keeping data within India. We will be honest that this is not yet absolute: some voice and language models we depend on (for example, Gemini Live) may process call data outside India under a cross-border data-transfer agreement. We do not claim 100% India-only processing today. Customers with strict data-residency needs can discuss India-resident model configurations with us.
8. Retention
Recordings, transcripts, and related records are retained for the period each customer configures for their workspace, after which they are deleted or anonymised. Account, billing, and audit records are retained as long as needed to provide the service and to meet legal, tax, and regulatory obligations.
9. Your rights under the DPDP Act
Data principals have the right to access a summary of their personal data and its processing, to correction and completion, to erasure, to nominate another person to exercise rights, and to grievance redressal. Because we usually act as a processor, the fastest route for end-consumers is to contact the business that called you. VaaniLabs will assist that business, and where we are the fiduciary you can contact us directly at legal@starvoxlabs.io.
10. Grievance officer
If you have a concern about how your data has been handled, you can reach our grievance officer / Data Protection Officer at legal@starvoxlabs.io. We aim to acknowledge and address grievances within the timelines set out under the DPDP Act.
11. Cookies
The VaaniLabs console uses a single signed session cookie to keep you logged in. It is strictly functional. We do not use advertising cookies, cross- site trackers, or third-party analytics profiling on the console.
12. Children
VaaniLabs is a business-to-business service and is not directed at, or intended for, anyone under 18. We do not knowingly build agents to target children, and our customers are responsible for not directing calls at minors.
13. Changes to this policy
We may update this Privacy Policy as the product and the law evolve. We will revise the "Last updated" date above and, for material changes, notify our business customers through the console or by email.
Questions? Contact legal@starvoxlabs.io
