SvaraCall — Privacy Policy
Sarwagyna Private Limited
Effective Date: 12 September 2026
Version 1.0
1. Who We Are and What This Covers
Sarwagyna Private Limited (CIN U62013AP2026PTC124652), registered office at D No. 7-7-24/2, Block 10, VIP RD 2nd Line, Ongole, Prakasam District – 523001, Andhra Pradesh, India, operates the SvaraCall platform.
This Policy explains how we handle personal data in connection with:
- our websites, www.sarwagyna.com and svaracall.sarwagyna.com;
- the SvaraCall platform, dashboard, and APIs;
- calls placed and received through the platform; and
- our sales, support, and marketing activity.
This Policy is an electronic record under the Information Technology Act, 2000. It should be read with our Terms of Service and Data Processing Addendum.
2. The Two Roles We Play — Read This First
This is the most important section of this Policy. Which of your rights apply, and who you exercise them against, depends on which role we are in.
2.1 We are the Data Fiduciary (controller)
For data about our own customers, prospects, and website visitors — the people who sign up for SvaraCall, evaluate it, or browse our site — we decide why and how the data is processed. We are the Data Fiduciary under the DPDP Act. Sections 3 to 11 of this Policy describe that processing.
2.2 We are a Data Processor
For data about people who are called by, or who call, an AI Agent operated by one of our customers — contact lists, call audio, transcripts, extracted fields, and call outcomes — our customer decides why and how that data is processed. Our customer is the Data Fiduciary. We process it only on their documented instructions.
If you received a call from an AI agent and want to know why, exercise your rights, or object, contact the business that called you. Their identity is disclosed at the start of the call. We will refer any request we receive directly to the relevant customer, and will support them in responding. Section 12 explains this in more detail.
3. Personal Data We Collect as Data Fiduciary
3.1 Data you give us
| Category | Examples |
|---|---|
| Identity and contact | Name, business email, phone number, job title, company name |
| Business verification (KYC) | Entity registration number, registered address, GSTIN, authorised signatory identity evidence, DLT registration details |
| Account | Username, hashed password, role, workspace settings, API key metadata |
| Billing | Billing address, GSTIN, invoice history, transaction references. Card and bank credentials are collected and stored by our payment gateway, not by us. |
| Support and sales | Correspondence, ticket contents, demo call notes, feedback, survey responses |
3.2 Data we collect automatically
IP address and approximate city-level location derived from it; browser type and version; device and operating system; language and time zone; pages visited, features used, and session duration; referring URL; API request logs; error and diagnostic data; cookie identifiers.
We do not collect precise GPS location.
3.3 Data we receive from others
From payment gateways: transaction status and settlement confirmation. From telephony providers: carrier, routing, delivery status, and error records associated with your account. From business data providers and public sources: company and role information used for sales outreach.
4. Why We Process It, and On What Legal Basis
| Purpose | Legal basis under the DPDP Act |
|---|---|
| Creating and operating your account; delivering the Services | Certain legitimate use (you voluntarily provided data for this purpose) / performance of contract |
| Billing, invoicing, tax and statutory records | Compliance with legal obligation |
| KYC and fraud prevention | Legal obligation and certain legitimate use |
| Security monitoring, incident detection, abuse prevention | Certain legitimate use |
| Support and service communications | Performance of contract |
| Product analytics and improvement | Consent, or certain legitimate use where aggregated |
| Marketing communications to non-customers | Consent |
| Responding to lawful requests from authorities | Legal obligation |
You may withdraw consent at any time where consent is the basis. Withdrawal does not affect processing already carried out, and may limit your ability to use parts of the Services.
5. Cookies and Tracking
We use:
- Strictly necessary cookies — session management, authentication, security. These cannot be disabled.
- Preference cookies — remembering your settings.
- Analytics cookies — understanding feature usage. Set only with your consent.
- Marketing cookies — measuring campaign effectiveness on our public website. Set only with your consent.
You can manage non-essential cookies through the consent banner on our website or through your browser. Blocking strictly necessary cookies will break the dashboard.
We honour Global Privacy Control signals on our public website where technically supported.
6. Who We Share Data With
We do not sell personal data. We do not share it for cross-context behavioural advertising.
We share personal data with:
Subprocessors — hosting, telephony, speech recognition, speech synthesis, language model inference, payments, email delivery, error monitoring, and analytics providers. Each is bound by contract to process only on our instructions and to maintain appropriate security. Our current list is available on request from privacy@svaracall.com and is incorporated into this Policy.
Professional advisers — auditors, lawyers, accountants, bound by professional confidentiality.
Authorities — where required by law, court order, or a valid request from a regulator or law enforcement agency, including under the Telecommunications Act, 2023 and the Information Technology Act, 2000.
Acquirers — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality and to the acquirer honouring this Policy. We will notify you where required.
7. Where Data Goes
We host the SvaraCall platform and its databases with cloud infrastructure providers. Some of our Subprocessors process data outside India, including large language model inference and parts of our hosting and monitoring stack.
Where we transfer personal data outside India, we rely on contractual safeguards with the recipient and transfer only what is necessary to deliver the Services. We will not transfer personal data to any territory restricted by the Central Government under Section 16 of the DPDP Act.
Our current data residency position, by component, is set out in the Subprocessor List, which is available on request. If you require in-country processing for all components, contact us before you sign — we cannot guarantee it on the standard platform.
8. How Long We Keep It
| Data | Retention |
|---|---|
| Account and profile data | For the life of the account, then 90 days |
| Billing records, invoices, tax records | 8 years from the end of the relevant financial year (Companies Act, 2013 and GST law) |
| KYC and verification records | 5 years from account closure, or longer where a regulator requires |
| Platform and API logs | 90 days |
| Security and audit logs | 12 months |
| Support correspondence | 24 months from closure |
| Marketing contact data | Until you unsubscribe, then suppression-list only |
| Call recordings, transcripts, campaign data | Set by the customer, subject to platform defaults and maximums — see Section 12 |
Backups are retained on their ordinary rotation and overwritten in the normal cycle. Data may be retained beyond these periods where necessary for a legal claim, regulatory requirement, or litigation hold.
9. Security
We apply administrative, technical, and physical safeguards proportionate to the risk, including:
- encryption of data in transit using TLS;
- encryption at rest for databases and stored credentials;
- role-based access control and least-privilege access to production;
- secrets management for API keys and authentication tokens, with encryption at rest;
- HMAC verification on inbound webhooks;
- audit logging of administrative actions;
- separation of environments;
- vulnerability patching on a defined cadence.
We are not currently ISO 27001 certified or SOC 2 attested. We do not claim certifications we do not hold. Our security roadmap, including target dates for independent assessment, is available on request under NDA.
No system is completely secure. We cannot guarantee that personal data will never be accessed, altered, or disclosed in breach of our safeguards.
Breach notification. Where a personal data breach occurs, we will notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act and rules, and will notify CERT-In within the timelines set out in its directions. Where we act as Processor, we will notify the relevant customer without undue delay so they can meet their own obligations.
10. Your Rights
Where we are the Data Fiduciary, you may:
- access a summary of the personal data we process about you and the identities of those we have shared it with;
- correct inaccurate or incomplete data, and complete or update it;
- erase personal data where it is no longer needed for the purpose it was collected for and no law requires us to keep it;
- withdraw consent where consent is the basis for processing;
- nominate another individual to exercise your rights in the event of death or incapacity;
- complain to us and, if unsatisfied, to the Data Protection Board of India.
To exercise a right, email privacy@svaracall.com from the address on your account, or contact the Grievance Officer in Section 14. We will verify your identity before acting. We aim to respond within thirty (30) days and will tell you if we need longer.
Your duties as a Data Principal. Under the DPDP Act you must not impersonate another person when providing data, must not suppress material information, and must not file false or frivolous complaints. Penalties apply.
11. Children
The Services are business-to-business and not directed at children. We do not knowingly collect personal data of anyone under 18 as a customer or account holder. If you believe a child has provided us data, write to privacy@svaracall.com and we will delete it.
Where you use the Services to contact minors — for example in education or paediatric healthcare use cases — you are responsible for obtaining verifiable parental consent and for complying with the restrictions the DPDP Act places on processing children's data, including the prohibition on tracking, behavioural monitoring, and targeted advertising directed at children. You must inform us in writing before running any such campaign.
12. Call Data — Our Role as Processor
12.1 What is processed
When a customer runs an AI Agent through SvaraCall, the following is processed: the phone number and any contact fields uploaded; the audio of the call; the speech-to-text transcript; the language model's reasoning inputs and responses; the synthesised audio returned; call metadata (start time, duration, direction, disposition, carrier response codes); and any structured fields extracted from the conversation and pushed to the customer's CRM.
12.2 Who decides what
The customer decides whether to record, what to record, how long to retain it, whether to redact, who in their organisation can access it, and whether to push data onward to their CRM or other systems. We make those controls available. We do not make those decisions.
12.3 What we do with it
We process it to deliver the call, to produce the transcript and analytics the customer has configured, to bill for usage, to investigate faults and abuse, and to comply with law. We do not use identifiable call audio or transcripts to train general-purpose AI models.
12.4 If you were called
Contact the business that called you. If you cannot identify it, write to privacy@svaracall.com with the number that called you, the number that was called, and the approximate date and time. We will identify the customer and forward your request to them, and will tell you we have done so. We will act on the request directly only where the customer instructs us to, or where the law requires us to.
13. Changes
We may update this Policy. The current version and its effective date are always posted here. For material changes affecting customers we will give notice by email at least thirty (30) days in advance. Check this page before sharing personal data with us.
14. Contact, Grievances, and Escalation
Data Protection / Privacy queries
Email: privacy@svaracall.com
Grievance Officer (IT Act, 2000 and IT Rules, 2021)
Name: Sarwan Thondamalla
Designation: CEO
Email: grievance@svaracall.com
Phone: +91 6305036991
Address: D No. 7-7-24/2, Block 10, VIP RD 2nd Line, Ongole, Prakasam – 523001, Andhra Pradesh, India
Complaints acknowledged within 48 hours; resolved within 15 days.
Escalation. If you are not satisfied with our response, you may complain to the Data Protection Board of India under the Digital Personal Data Protection Act, 2023.
Sarwagyna Private Limited | CIN U62013AP2026PTC124652 | GSTIN 37ABTCS0879E1ZR
www.sarwagyna.com | svaracall.sarwagyna.com | contact@svaracall.com | +91 6305036991