How we handle personal data, and which of two roles we are in.
Almost every privacy question about us is answered by one distinction. If you are on this website, we decide what happens with your data. If our AI called you about your loan or your policy, the company you hold that with decides, and we act only on their instruction.
This page is written to be substantively correct under the DPDP Act, 2023, but it has not been reviewed by a lawyer and every dotted item is an unresolved fact. It must not go public in this state.
- Two different roles, and which one applies to you
- What we collect when you use this website
- When our AI calls you for a company you deal with
- Why we process website data, and on what basis
- Call recordings and transcripts
- How long we keep it
- Who else touches your data
- Where your data is stored
- Your rights under the DPDP Act
- Cookies and analytics
- Security
- Children
- Changes to this notice
Two different roles, and which one applies to you
This notice covers two very different situations, and almost every question about our handling of personal data is answered by working out which one you are in.
You browse oriserve.com, request a call, book a demo or apply for a job. Here Unlax Consumer Solutions Private Limited, operating as Oriserve (CIN U74999MH2015PTC264880) decides why and how your data is used, so we are the Data Fiduciary and this notice governs.
Your bank, insurer, lender or telecom operator instructed us to contact you. They decide who is called and why, so they are the Data Fiduciary and we are their Data Processor. Your rights are exercised with that company, and section 03 explains how.
We use the terms Data Fiduciary, Data Processor and Data Principal as they are defined in India's Digital Personal Data Protection Act, 2023.
What we collect when you use this website
We keep this deliberately short, because we collect little.
- What you give us. Your name, work email, phone number, company and role when you request a call, book a demo, or write to us. Your CV and application details if you apply for a role.
- What your browser sends. IP address, device and browser type, pages viewed, referring source and approximate location derived from IP, through our analytics.
- The demo call itself. If you ask our AI to call you, that call is recorded and transcribed so we can show you what happened on it and improve the product. Demo-call audio may be recorded, with notice and consent given at the start of the call, and is retained only as long as needed for follow-up and then deleted.
We do not buy personal data to market to you, and we do not sell yours. If a message from us appears unsolicited, it came from publicly available business contact information, and every message carries a route to stop.
When our AI calls you for a company you deal with
If you received a call from an AI agent about a loan, a policy, a bill or an account, we ran that call as a service provider to the company you hold that relationship with. We did not choose to call you and we do not decide what happens with the outcome.
Your rights are exercised with that company, not with us. Ask them for their privacy notice and their grievance officer. If you tell us instead, we will pass your request to them promptly and confirm that we have done so, but they are the party that must act on it.
What we do on their instruction is bounded: we process only the data they provide or the call generates, only for the purpose in their contract, under the controls set out in our data processing terms. We do not use their customers' data to build products for anyone else.
Why we process website data, and on what basis
| What | Why | Basis under the DPDP Act |
|---|---|---|
| Your contact details | To call you back, run the demo you asked for, and follow up on that conversation | Your consent, given when you submit the request |
| Demo call recording | To show you what the AI did, and to improve accuracy and safety | Your consent, with notice at the point of the call |
| Analytics | To understand which pages help buyers and which do not | Consent, and consent-gated: no non-essential analytics runs until you accept via the cookie banner |
| Job applications | To assess you for the role and keep a record of the decision | Your consent |
| Business correspondence | To hold and evidence a commercial relationship | Legitimate use for the purpose the data was volunteered for |
You can withdraw consent at any time. Where consent was the only basis, we stop and delete, except where we must keep a record to evidence the withdrawal itself.
Call recordings and transcripts
Recording is central to what we sell, so we are explicit about it. Every conversation our platform runs is recorded, transcribed and scored. That is the point: it is what lets a client audit the whole book rather than a five per cent sample.
- For calls run for a client, the recording belongs to that client's programme and is held under their contract and instructions.
- For a demo call you requested from this site, the recording exists so we can show you the transcript and improve the product.
- Recordings are encrypted at rest and in transit, and access is limited to the people who need it for the programme they work on.
How long we keep it
Retention periods: website enquiry data is kept for 12 months; demo-call recordings are kept only as long as needed for follow-up and then deleted; analytics data is kept for 1 month; job applications are kept for 1 month; and client programme data is kept per the client contract.
The principle we hold to, whatever the periods say: we keep website enquiry data only while a commercial conversation is genuinely live or legally required, and we delete rather than archive by default.
Who else touches your data
We use a small number of sub-processors to run the business and deliver the service, including for hosting, telephony and speech services. They act on our instructions, under contract, and none of them may use your data for their own purposes.
The specifics are covered in each client's MSA or DPA, and a current list of our sub-processors is available on request. We notify you of changes to that list.
We do not disclose personal data to anyone else except where the law requires it, and where that happens we will tell you unless we are prohibited from doing so.
Where your data is stored
Data is held in India. Client conversation data is stored in-region, encrypted, access-controlled and kept logically separated per client so it is never mixed across accounts.
No client data is stored or processed outside India.
Your rights under the DPDP Act
- Access. A summary of the personal data we hold about you and what we do with it.
- Correction and completion. Have inaccurate or incomplete data corrected.
- Erasure. Have data deleted where we no longer need it and no law requires us to keep it.
- Withdrawal of consent. At any time, as easily as you gave it.
- Grievance redressal. Raise a complaint with our grievance officer and get a response.
- Nomination. Nominate someone to exercise these rights if you are unable to.
Write to our grievance officer, Maaz Ansari (maaz@oriserve.com), at our correspondence office, 4th Floor, C-15, Sector-3, Noida, Gautam Buddha Nagar, Uttar Pradesh 201301. Our registered office is 15 F, Bapurao Jagtap Marg, Jacob Circle, Mumbai, Maharashtra 400011. We will acknowledge a data-rights request within 7 days and respond substantively within 30 days. If we cannot resolve your complaint, you may escalate to the Data Protection Board of India.
Cookies and analytics
Analytics on this site is consent-gated: no non-essential analytics or cookies run until you accept them via the cookie banner, and you can decline or change your choice at any time.
Our position, whatever the final mechanism: analytics that tells us which pages help a buyer is worth having, and nothing on this site needs to follow you around the internet to achieve it.
Security
We hold ISO 27001:2022 certification for our information security management system, with SOC 2 and ISO 42001 on the roadmap. Data is encrypted in transit and at rest, access is role-based and logged, and changes to production are controlled and reviewable.
The trust centre carries the detail security teams usually ask for. Our ISO 27001:2022 certificate is IC-IS-2505161, issued by INTERCERT and valid to 2028.
Children
This website and our services are built for business use and are not directed at children. We do not knowingly collect personal data of children through this site. Where our platform calls a customer of a client, the client is responsible for who is on their calling list.
Changes to this notice
When we change this notice we will update the version and date at the top. If a change materially affects how we use data you have already given us, we will tell you directly rather than relying on you to re-read the page.