AI voice agents that answer, decide and act — on every call.

Privacy Policy

Effective from 12/09/2026. Thank you for using Kwinova. We build voice automation for businesses, which means that some of the data passing through our platform is not ours and not even our customers’ — it belongs to the people who pick up the phone. We take that seriously, and this policy sets out plainly what we collect, what we merely handle on someone else’s behalf, and what you can ask us to do about it. By using our website, platform or services, you agree to what is described here.

Who we are

Kwinova is Kwinova Communicaiton Solutions, a voice automation company based in Vellore, Tamil Nadu, India. We provide SIP connectivity, IVR and call-flow software, AI voice agents, a private knowledge base and related services to business customers. We can be reached at info@kwinova.com or on +91 416 290 6233. Our postal address is 153, Karunai Nagar, Sevoor, Katpadi Taluk, Vellore, Tamil Naud – 632106.

The two roles we play

This is the part worth reading carefully, because almost everything else follows from it. Where we decide — we are the data fiduciary. When you browse kwinova.com, fill in an enquiry form, sign up for an account, or email our support team, we decide why that data is held and for how long. You can bring any request about it straight to us. Where our customer decides — we are a processor. When a business uses Kwinova to answer its phone lines, the calls, recordings, transcripts and documents involved belong to that business. It chooses what to record, what to retain and for how long; we act on its instructions and nothing else. We do not use that data for our own purposes. If you called a company and reached an automated agent, and you want your recording deleted or a copy of what was captured, the company you called is who can grant that. We will help them do it, and if you contact us we will point you to them — but we cannot act over their head on their data.

What we collect about you directly

Depending on how you deal with us, we may hold:

  • Name
  • Email address
  • Phone number
  • Company name and your role
  • Billing details and GSTIN, where you are a paying customer
  • Subscription, credit balance and invoice history
  • Account login details, stored as a salted hash — never as readable text
  • IP address, browser and device information
  • Pages visited on our website
  • Your correspondence with our sales and support teams

We use it to answer enquiries, provide and bill for the service, support you, keep the platform secure, improve what we build, and meet our legal and accounting obligations. We do not deliberately collect sensitive personal data about you, and we ask you not to send it to us in an enquiry form.

Data that passes through the platform

When a business runs its calls on Kwinova, the following may be processed on its behalf. It remains that business’s data throughout.

Call audio and recordings. Recording is a setting the customer controls. Where it is on, the audio is stored inside that customer’s own storage area and released according to the retention period they set — [default recording retention] unless they change it. Transcripts. Speech recognition produces text from call audio. Transcripts are held under the same tenant boundary and the same retention rules as the audio. What the caller said and what the agent did. The intent detected, the knowledge articles matched, the values captured in a form, the systems called during the conversation and the outcome recorded at the end. Telephony metadata. Calling and called numbers, time, duration, direction, routing decisions, disposition and quality measurements. This is generated for every call whether or not recording is enabled, and some of it we are required to keep. Knowledge base content. Documents, pages and other material a customer uploads so the agent can answer from them, along with the numerical representations — embeddings — used to search that material. Each customer’s data sits in a separate database schema rather than being separated by a filter in a query, and outbound calls use trunks belonging to that customer’s own realm. The separation is structural, not procedural.

Call recording, and who is responsible for consent

The customer running the line is responsible for telling callers that the call is being recorded, and for obtaining consent where the law requires it. They control the greeting, the recording setting and the retention period. We provide the controls and the means to announce recording; we cannot know what a given customer has told its callers, and we do not make that decision for them. If you are a Kwinova customer: announce recording at the start of the call, in the language the caller is being served in, and keep the announcement in the flow even when you edit it later.

AI processing

Conversations are processed by speech recognition, language models and speech synthesis to produce the agent’s replies.

  • Some of this runs on our own infrastructure, and some through third-party model providers — currently [list of AI model providers].
  • Document embeddings for the knowledge base are computed on our own infrastructure, so uploaded material is not sent to an external embedding service.
  • We do not use customer call data, transcripts or uploaded documents to train models, ours or anyone else’s.
  • Where a third-party provider is involved, only the content needed for that turn of the conversation is sent, under contract terms that prohibit using it for training.

Automated decision-making

We will not pretend otherwise: a voice agent decides things automatically. During a call it may decide what a caller wants, which answer to give, whether to hand the call to a person, and what to record as the outcome. That is what the product does. Those decisions are made inside a flow the customer configures, and the customer chooses where a human takes over. We do not run automated profiling or scoring that produces legal or similarly significant effects on a caller — no creditworthiness assessment, no eligibility decision, no automated denial of a service. A caller can ask to be transferred to a person, and the flow should honour it.

Contact forms

Our contact form collects your name, email address, phone number, company and message. We use it to reply to you and for follow-up about your enquiry. Submissions are emailed to us rather than stored in the website database, and we keep basic anti-abuse signals — a timestamp and a short-lived record of the submitting network — long enough to block spam. We do not sell or rent your contact details. Ever.

Cookies

Our website uses cookies and similar technologies for session and login handling, security, remembering your preferences, and measuring how the site performs. You can block or delete cookies in your browser. Parts of the site may then stop working — staying logged in, in particular.

Analytics

We may use analytics tools to understand how the website is used: pages viewed, time on page, device and browser type, and approximate region. This is aggregated and is not used to identify you individually.

Who we share data with

We share only what a job requires, and only with providers engaged to do that job:

  • Hosting and cloud infrastructure
  • Telecom carriers and SIP interconnect partners, for call delivery
  • Payment gateways, for subscription and credit payments
  • Email delivery services
  • AI model providers, as described above
  • Analytics, monitoring and security services

Payments are handled by the gateway. We do not store complete card numbers on our servers. We do not sell personal data, and we do not share it with advertisers. We may disclose data where the law, a court order or a lawful government request requires it — and where we are permitted to tell the affected customer, we will.

How long we keep data

  • Call recordings and transcripts — for the period the customer sets, then deleted automatically. 45 days by default.
  • Call metadata — kept for billing, fraud prevention and the record-keeping periods our telecom obligations require.
  • Knowledge base content — until the customer deletes it or closes the account.
  • Account, billing and invoice records — 365, as accounting and tax law requires.
  • Enquiries and support correspondence — as long as needed to deal with the matter and any follow-up.
  • Website analytics — in aggregated form, for trend analysis.

When an account closes, customer data is deleted or irreversibly anonymised on the schedule in the customer’s contract, except where we are legally required to keep it.

Your rights

Subject to the law that applies to you, you may ask us to:

  • Confirm what personal data we hold about you, and give you a copy
  • Correct anything inaccurate or incomplete
  • Delete personal data we no longer have a reason to keep
  • Restrict how we process it in defined circumstances
  • Provide it in a portable form
  • Withdraw a consent you previously gave
  • Nominate someone to exercise these rights if you cannot

Write to info@kwinova.com. We may need to verify who you are before we act, which protects you as much as us. We will respond within the time the applicable law allows. If your data reached us through a business that uses Kwinova, that business decides. Ask them. We will support their response.

Grievance Officer

If you are unhappy with how we have handled your data or your request, you may escalate to our Grievance Officer: Siva M Email: msivamoorthy@gmail.com Address: 53, Vaibav Nagar Phase III, Katpadi, Vellore. We will acknowledge and respond within the period Indian law requires. If you remain dissatisfied, you may complain to the relevant data protection authority.

Where your data goes

Our infrastructure is operated in Vellore, Chennai & Mumbai. Some providers — model providers in particular — may process data outside India. Where that happens, we use providers offering appropriate safeguards and contract terms covering security, confidentiality and restrictions on use. Customers with a requirement that data stays within a particular jurisdiction should raise it before onboarding, so the deployment can be arranged accordingly.

How we protect data

  • TLS on call signalling and SRTP on call media, per leg
  • HTTPS across the website and the customer portal
  • A separate database schema per customer, so isolation is structural
  • Embeddings computed on our own infrastructure
  • Role-based access, with administrative access limited to staff who need it
  • Logging, monitoring and regular patching
  • Credentials stored only as salted hashes

No system can be guaranteed secure, and we will not claim ours is. What we can say is what we do, which is the list above.

If there is a breach

If we suspect or confirm a breach of personal data, we will contain it and secure the affected systems, investigate what happened and what was exposed, notify affected customers without undue delay and in any case within [breach notification window], notify the authorities where the law requires, and fix what let it happen.

Third-party services

Our website and platform may link to or embed third-party services, including payment pages and integrations a customer chooses to connect. Those services handle data under their own policies, which are worth reading. We are not responsible for what they do with data you give them directly.

Children

Kwinova is sold to businesses and is not directed at children. We do not knowingly collect personal data from children through our website. A caller reaching a customer’s phone line could be a minor. We do not treat call data differently on that basis, because we do not know who is calling — and a customer whose service is aimed at children should take that into account in its own privacy notice and its recording announcement.

Changes to this policy

We may update this policy as our services, obligations or infrastructure change. The current version is always on this page, effective when posted unless we say otherwise. If a change materially affects how we handle customer data, we will tell our customers directly rather than relying on them noticing.

Contact

Questions about this policy or about your data: Kwinova, 153, Karunai Nagar, Sevoor, Katpadi, Vellore – 632106, info@kwinova.com · +91 416 290 6233

Governing law

This policy is governed by the laws of India. Any dispute arising under it is subject to the jurisdiction of the courts at Vellore, Tamil Nadu, India.