Azuren Privacy Policy
Effective Date: August 9, 2026 · Governed by Indian Law (IT Act 2000, SPDI Rules 2011)
1. Overview & Scope
This Privacy Policy ("Policy") governs the collection, storage, processing, transfer, and disclosure of personal data by Azuren (a technology platform operated by its founders) ("Azuren", "we", "us", "our") through the platform accessible at https://www.azuren.ai and related mobile or web applications (collectively, the "Service").
This Policy applies to all visitors, registered users, business account holders, and any natural person who interacts with Azuren ("User", "you", "your"). By accessing or using the Service, you signify that you have read, understood, and agree to be bound by this Policy. If you do not agree, you must immediately discontinue use.
This Policy is compliant with applicable Indian law including the Information Technology Act, 2000 ("IT Act"), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011 ("SPDI Rules"), and the Consumer Protection Act, 2019.
2. Definitions
- "Personal Data" means any information that, alone or in combination with other data, identifies or can reasonably identify a natural person, including name, email address, phone number, IP address, and device identifiers.
- "Sensitive Personal Data or Information (SPDI)" as defined under Rule 3 of the SPDI Rules includes passwords, financial information, health data, biometric data, and sexual orientation. Azuren does not intentionally collect SPDI beyond payment-related data processed exclusively by Razorpay.
- "Processing" means any operation on Personal Data including collection, recording, storage, adaptation, retrieval, use, disclosure, erasure, or destruction.
- "Data Fiduciary" means Azuren, which determines the purpose and means of processing.
- "Data Principal" means the natural person to whom Personal Data relates — i.e., you.
- "Third-Party Services" means Clerk (authentication), Supabase (database), Razorpay (payments), Meta/WhatsApp Business API (messaging), Vercel (hosting), and any analytics services.
- "Business Account" means an account registered by a legal entity, sole proprietor, or individual to manage WhatsApp AI automation for their customers.
3. Data We Collect
3.1 Account & Identity Data (via Clerk)
- Full name, email address, and profile photo (sourced from OAuth providers you use to sign up — Google, etc.).
- Encrypted session tokens and authentication metadata maintained by Clerk, Inc. Azuren does not store raw passwords at any point.
- Account creation timestamp, last login time, and device/browser fingerprint for security purposes.
3.2 Business Configuration Data
- Business name, description, service catalog, pricing lists, FAQs, and any documents you upload to the knowledge base.
- WhatsApp Business phone numbers and WABA IDs linked to your account via Meta Business API OAuth.
- AI autonomy level settings, policy configurations, and automation workflow rules you define.
- Booking calendars, availability slots, and appointment data you configure.
3.3 WhatsApp Conversation Data (End-Customer Data)
When your end-customers message your WhatsApp number, Azuren receives and processes those messages on your behalf to execute your configured automations. This includes:
- Inbound and outbound WhatsApp messages, including text, media references, and interactive reply content.
- End-customer WhatsApp phone numbers (used solely to route replies; not used for any Azuren marketing).
- Conversation session metadata: timestamps, message delivery status, and escalation flags.
- Lead data captured during conversations: names, intent signals, and qualification scores derived by the AI.
- YOU, as the Business Account holder, are the Data Fiduciary for your end-customers' data. Azuren acts as a Data Processor on your behalf. You are solely responsible for maintaining a lawful basis to process your end-customers' data and for providing them with appropriate notice.
3.4 Payment Data (via Razorpay)
- Azuren uses Razorpay exclusively to process subscription payments. Razorpay collects and stores all payment card/UPI/bank details directly. Azuren only receives a payment confirmation token, subscription status, and invoice metadata.
- We do not store, transmit, or have access to raw card numbers, CVV codes, UPI PINs, or net banking credentials.
- Razorpay's privacy policy governs all payment data: https://razorpay.com/privacy/
3.5 Usage & Technical Data
- IP address, browser type, operating system, referring URL, pages visited, and session duration — collected via Vercel Analytics and server logs.
- API call logs, error logs, and performance telemetry — retained for debugging and platform stability.
- Cookies and similar tracking technologies (see Section 7).
4. Legal Basis for Processing
We process your Personal Data on the following legal grounds:
- Contractual Necessity: To create and manage your account, provide the Service, process payments, and enforce this Policy and our Terms of Service.
- Legitimate Interests: To detect fraud, ensure platform security, prevent abuse, improve the Service, and send essential service communications.
- Consent: Where you have explicitly provided consent (e.g., optional marketing communications). You may withdraw consent at any time without affecting lawfulness of prior processing.
- Legal Obligation: To comply with applicable laws, court orders, and regulatory requirements.
5. How We Use Your Data
- Provide, operate, and improve the Azuren platform and all features therein.
- Authenticate your identity and maintain the security of your account.
- Execute your AI automation workflows via the WhatsApp Business API.
- Generate AI responses using large language models (LLMs). No personally identifiable conversation data is used to train third-party AI models without explicit consent.
- Process subscription payments, issue invoices, and manage billing.
- Send transactional emails (account creation, password reset, billing confirmations, and policy updates).
- Detect, investigate, and prevent fraudulent transactions, abuse, and violations of our Terms of Service.
- Comply with legal obligations, respond to lawful government requests, and enforce our agreements.
- Analyse aggregate, anonymised usage patterns to improve product features and user experience.
- We NEVER sell, rent, or trade your Personal Data to any third party for their own marketing or commercial purposes.
6. Data Sharing & Disclosure
6.1 Authorised Sub-Processors
We share data with the following categories of sub-processors who act under strict contractual obligations:
- Clerk, Inc. (USA) — Identity & authentication management.
- Supabase, Inc. (USA/EU) — Encrypted database and file storage.
- Razorpay Software Pvt. Ltd. (India) — Payment processing.
- Meta Platforms, Inc. (USA) — WhatsApp Business API messaging.
- Vercel, Inc. (USA) — Web hosting, edge functions, and analytics.
- OpenAI / Anthropic / Google (AI providers) — LLM inference. Prompts contain conversation context only; no persistent user profiles are sent to AI providers.
6.2 Legal Disclosures
- We may disclose Personal Data if required by law, court order, subpoena, or a lawful government request under applicable Indian or international law.
- We will, where legally permissible, notify affected users of such requests before disclosure.
6.3 Business Transfers
In the event of a merger, acquisition, asset sale, or insolvency proceeding, Personal Data may be transferred to a successor entity. We will provide notice on the website and, where required, seek fresh consent before any such transfer.
6.4 Aggregated & Anonymised Data
We may share aggregated or de-identified data that cannot reasonably be used to identify any individual. Such data is not considered Personal Data.
8. Data Retention
- Account & Profile Data: Retained for the duration of your active account plus 90 days after account deletion, after which it is permanently purged from production systems.
- WhatsApp Conversation Logs: Retained for 12 months from the date of conversation. You may request earlier deletion (see Section 9).
- Payment Records & Invoices: Retained for 7 years in accordance with Indian accounting and tax law (Companies Act, GST Act).
- Security & Audit Logs: Retained for 6 months for fraud investigation and legal compliance.
- Backups: Encrypted database backups containing personal data are retained for 30 days before secure destruction.
- After the applicable retention period, data is either permanently deleted or irreversibly anonymised.
9. Your Rights
Subject to applicable law, you have the following rights regarding your Personal Data:
- Right to Access: Request a copy of all Personal Data we hold about you.
- Right to Correction: Request correction of inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): Request deletion of your Personal Data, subject to legal retention obligations. Verified requests are executed within 30 days.
- Right to Data Portability: Request your Personal Data in a machine-readable format (JSON/CSV) for transfer to another service.
- Right to Withdraw Consent: Withdraw any consent you previously granted. Withdrawal does not affect prior lawful processing.
- Right to Restrict Processing: Request that we limit how we use your data while a dispute or correction request is pending.
- Right to Object: Object to processing based on legitimate interests.
- Right to Lodge a Complaint: File a complaint with the relevant data protection authority or our Grievance Officer (see Section 12).
- To exercise any right, email us at support@azuren.ai with subject line 'Data Rights Request' and proof of identity. We respond within 30 days.
10. Data Security
- All data in transit is encrypted using TLS 1.2 or higher. All data at rest in Supabase is encrypted using AES-256.
- Authentication tokens are managed by Clerk and are never stored in plaintext.
- WhatsApp OAuth tokens are stored encrypted in our database with additional application-layer encryption.
- Access to production systems is restricted to authorised personnel under strict role-based access control (RBAC) with audit logging.
- We conduct periodic security reviews and vulnerability assessments.
- In the event of a data breach affecting your Personal Data, we will notify you and applicable authorities as required by law within 72 hours of becoming aware.
- Despite our safeguards, no system is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
11. Meta / WhatsApp Data Deletion Instructions
Azuren connects to your WhatsApp Business Account via Meta's OAuth flow. To revoke Azuren's access and request deletion of associated data:
- Go to your Facebook Account Settings → Business Integrations (https://www.facebook.com/settings?tab=business_tools).
- Find "Azuren" in the list of connected apps.
- Click "Remove". Upon removal, Meta's systems send a deauthorisation webhook to Azuren.
- Azuren's systems will, within 24 hours, permanently delete all stored OAuth tokens, WhatsApp session data, automation configurations, and conversation logs tied to your WhatsApp Business Account.
- You will receive a deletion confirmation email at your registered address.
- Alternatively, email grievance@azuren.ai with subject 'Meta Data Deletion Request' for manual processing within 30 days.
12. Grievance Officer
In accordance with the Information Technology Act, 2000 and the SPDI Rules, 2011, the details of the Grievance Officer are:
- Name: Grievance Officer, Azuren
- Email: grievance@azuren.ai
- Phone: +91-9050997755
- Address: Azuren Platform Support — [Registered Address, India]
- We will acknowledge your complaint within 24 hours and resolve it within 30 days of receipt.
13. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect Personal Data from minors. If you believe we have inadvertently collected data from a person under 18, contact us immediately at support@azuren.ai and we will delete it within 72 hours.
14. Cross-Border Data Transfers
Your Personal Data may be transferred to and stored on servers located outside India (e.g., servers operated by Clerk, Supabase, and Vercel in the United States or EU). We ensure such transfers are protected by equivalent safeguards — including contractual clauses equivalent to Standard Contractual Clauses — consistent with applicable Indian law.
15. Changes to This Policy
We may update this Policy periodically. When we make material changes, we will: (a) update the 'Last Updated' date at the top; (b) post a prominent notice on the Service; and (c) where required by law, send email notification to registered users. Continued use of the Service after the effective date of any change constitutes acceptance of the updated Policy.
16. Contact Us
- General: support@azuren.ai
- Phone: +91-9050997755
- Grievance / Legal: grievance@azuren.ai
- Website: https://www.azuren.ai