Controlled-pilot legal draft · 2 August 2026

Privacy notice

This notice explains how AT Infotech's AT AI service handles personal data. It must be approved by the business owner and legal adviser before unrestricted public launch.

Who is responsible

For account, website and direct support data, AT Infotech operates AT AI and determines why that data is used. For data submitted by a client through its assistant, CRM or connected sources, the client generally determines the purpose and AT AI processes it under the client's instructions. Contract terms may allocate these roles differently.

Data we handle

Purposes and grounds

We use data to provide contracted services, authenticate users, secure and support the platform, deliver requested communications, enforce client-approved retention, meet legal duties and improve reliability. Where consent is required, it must be specific and may be withdrawn through the applicable client or support channel. We do not sell personal data.

AI processing and recipients

Approved content may be sent to a configured AI provider only after the client service and provider route are enabled. OpenAI is not enabled for the live pilot until credentials and approval are supplied. Infrastructure, identity and email providers may process limited data to deliver their services. Access is role-based and tenant-scoped.

Retention and deletion

Client conversation retention defaults to 30 days. A Platform Admin may set 30, 60, 90, 120, 150 or 180 days separately for each client. Audit, billing, security and backup records may follow separate documented periods required for integrity, recovery or law. An active legal hold suspends deletion. Governed tenant deletion requires a recent export, exact confirmation and MFA-approved scheduling.

Your choices and requests

Depending on the applicable law and your relationship with the client, you may ask for access, correction, completion, erasure, withdrawal of consent or grievance handling. Contact the client first for data collected through its assistant; otherwise email sureshkardam@gmail.com. We may verify identity before acting.

Children and sensitive use

The controlled pilot is for business users and is not directed to children. Clients must not intentionally configure child-facing or high-risk processing without written approval and appropriate consent controls. Voice recording remains disabled unless a separately reviewed consent policy is activated.

Security and incidents

Controls include encrypted transport, isolated tenant access, MFA for privileged actions, secret redaction, audit trails, backups and tested recovery procedures. No system is risk-free. Confirmed personal-data incidents are assessed and notified as required by applicable law and client agreements.

Indian data-protection framework

This draft was prepared with reference to the Digital Personal Data Protection Act, 2023, the Digital Personal Data Protection Rules, 2025, their phased commencement, and the Information Technology Act, 2000. This notice is not a certification of compliance.

Contact and changes

Privacy and grievance contact: sureshkardam@gmail.com. Material changes will be dated here and, where appropriate, communicated to active clients.