Privacy Policy
This Privacy Policy explains how Namuste Technologies Pvt. Ltd. collects, uses, safeguards, and processes your personal data and business communication records across our AI Voice, WhatsApp, and Web platform, including secure payment gateway transactions.
1. Identification of Data Fiduciary & Scope
This Privacy Policy is issued by Namuste Technologies Pvt. Ltd.(“Namuste”, “Company”, “we”, “us”, or “our”), a company incorporated under the laws of India, having its registered office at:
Namuste Technologies Pvt. Ltd.
CIN: U62013WB2026PTC286896 | GST Number: 19AALCN3032B1ZR
Registered Office: 245 B/1, Raipur Road, Kolkata 700047, West Bengal, India
General Enquiries: connect@namuste.com | Billing & Payments: payments@namuste.com
This policy applies to all visitors, registered subscribers, enterprise clients, and end-users who access our website (https://namuste.com), subscribe to our software services, utilize our AI Voice, WhatsApp, or Web Assistants, or interact with our billing and checkout systems.
2. Information We Collect
We collect information directly provided by you, automatically gathered through your device, and generated in the course of conversational assistant operations:
- Account & Contact Information: Name, business name, business email address, corporate telephone number, billing address, and account login credentials.
- Billing & Payment Information: When you purchase subscriptions, setup packages, or add-on conversational tokens, our payment gateway partners collect billing names, billing addresses, tax IDs (e.g., GSTIN), and payment card/account tokens. We do not store your full credit/debit card numbers, CVVs, or online banking passwords on our servers.
- Conversational Data & Transcripts: Audio recordings (where call recording is activated by the client), synthesized speech logs, WhatsApp chat histories, SMS alerts, and web concierge chat sessions processed on behalf of our enterprise clients.
- Technical & Telemetry Data: IP addresses, browser types, operating systems, referring URLs, access timestamps, latency logs, and interaction heatmaps via Google Tag Manager and security cookies.
3. Payment Processing & Payment Gateway Disclosures
We utilize authorized, RBI-registered and PCI-DSS Level 1 compliant third-party payment gateways (such as Stripe, Razorpay, or bank-authorized payment aggregators) to securely process online transactions, recurring subscription charges, and usage invoices.
- All payment card transactions are encrypted using Transport Layer Security (TLS 1.3) directly transmitted to the payment gateway.
- Our systems only receive anonymized transaction identifiers, payment authorization tokens, payment status (success/failure), card brand, and the last 4 digits of the payment method for accounting and invoice reconciliation.
- Automatic recurring billing for monthly or annual SaaS subscriptions is executed strictly in accordance with regulatory mandates, customer mandate approvals, and multi-factor authentication requirements.
4. Purpose of Processing & Legal Grounds
We process your personal information and corporate data under the following legal bases:
- Performance of Contract: Provisioning and maintaining your AI voice and chat assistants, executing automated appointment scheduling, routing customer enquiries, and billing your account.
- Legitimate Interests: Preventing fraud, safeguarding infrastructure integrity, diagnosing runtime latency, and monitoring system availability.
- Explicit Consent: Sending marketing newsletters or running opt-in telephony pilot evaluations.
- Statutory Compliance: Maintaining tax invoices under GST laws, assisting verified regulatory inquiries, and preserving financial audit records.
5. Enterprise Multi-Tenancy & PII Masking
Our architecture enforces air-gapped logical separation between tenants. We adhere to the following privacy commitments:
Customer proprietary documents, internal knowledge graphs, and caller transcripts are never utilized to train generic foundation models for third parties.
Acoustic and text redact filters automatically mask sensitive data such as government identity numbers, payment card numbers, and health markers from diagnostic logs.
6. Subprocessors & Third-Party Service Providers
We share data solely with verified subprocessors under strict confidentiality and data-processing agreements:
- Payment Processors: RBI-compliant payment gateways (Stripe, Razorpay) for transaction settlement.
- Cloud Infrastructure: Cloud hosting providers (such as AWS, Microsoft Azure, Google Cloud) with Indian data residency capabilities.
- Telecommunication & SIP Gateways: Licensed telecom providers (e.g. Twilio, Exotel, Tata Tele Business Services) to originate and terminate voice calls and SMS.
- Analytics & Tag Management: Google Tag Manager for aggregate visitor analytics and web performance monitoring.
7. Data Retention & Customer Deletion Rights
We retain conversational records and customer data only as long as necessary to fulfill the service agreements or comply with statutory requirements:
- Call audio and transcripts are stored according to client-configured retention windows (defaulting to 90 days, or customized by enterprise agreements).
- Financial and tax transaction records are retained for a minimum of 7 years in accordance with Indian taxation and corporate statutory requirements.
- Clients may submit a written request to erase, export, or anonymize their business data at any time by emailing connect@namuste.com.
8. Cookies & Google Tag Manager
Our website utilizes necessary cookies to authenticate sessions, maintain security, and optimize page rendering speed. We also use Google Tag Manager (GTM-M6D769MW) to measure aggregate website traffic and visitor interactions. You can adjust your browser settings to reject non-essential cookies at any time without impacting your core browsing experience.
9. Grievance Redressal & Contact Officer
In accordance with the Information Technology Act, 2000, and the Digital Personal Data Protection Act, 2023, the details of the designated Grievance Officer are set forth below:
