How we process data on your instruction, not ours.
You decide who gets called and why. We execute, and we prove it. This is the plain-language version of the data processing terms we sign, written so your risk team can assess us before the first meeting rather than after the third. Section 07 answers the model-training question directly.
Every clause here must be reconciled with the DPA we actually sign, and the tenancy and model-training statements must be verified against the architecture by engineering. Each dotted item is unresolved.
- Why this page exists
- Who is who
- What we process, and for how long a purpose
- Processing only on your instructions
- Security measures
- Tenancy, and never mixing your book with anyone else
- Whether your data trains our models
- Sub-processors
- Audit and information rights
- If something goes wrong
- Helping you answer your customers
- Return and deletion at the end
- Precedence, and getting the signed version
Why this page exists
Enterprise buyers in BFSI and telecom ask for our data processing position before they will take a second meeting, and they should not have to ask twice or wait for a PDF.
This page is a plain-language summary of the data processing terms we sign. It is not itself the agreement. The signed Data Processing Agreement, executed with your master services agreement, is the binding document, and where the two differ the signed version governs.
Who is who
You decide whose data enters the programme, why they are contacted and what outcome is pursued. You hold the relationship with the data principal and their consent.
We process on your documented instructions, for the purposes in your contract, and for nothing else. We do not decide who is called or why.
Terms follow the Digital Personal Data Protection Act, 2023. Where you also carry obligations under sectoral regulation, whether RBI, IRDAI, TRAI or PCI-DSS, our controls are designed to sit inside them rather than beside them.
What we process, and for how long a purpose
| Element | Position |
|---|---|
| Nature of processing | Placing and receiving voice calls and messages, transcription, reasoning over your systems of record, updating dispositions, and recording, scoring and reporting on every interaction. |
| Purpose | Solely the programme in your statement of work, for example collections, renewals, retention, qualification or support. |
| Categories of data principal | Your customers, prospects or policyholders, as identified by you, and your own agents who work the handoff. |
| Categories of data | Identifiers and contact details, account, loan or policy attributes needed for the conversation, the call audio, its transcript and the disposition. Financial data only where the programme requires it. |
| Duration | The term of your agreement, plus any retention you instruct in writing. |
Processing only on your instructions
We act on documented instructions. If an instruction appears to breach the law, we will say so and pause rather than proceed quietly. We do not process your data for our own purposes, and we do not enrich it against outside sources unless you tell us to.
Personnel are bound by confidentiality, access is role-based and least-privilege, and access to a programme is limited to the people working on it.
Security measures
- ISO 27001:2022 certified information security management, with SOC 2 and ISO 42001 on the roadmap. Certificate IC-IS-2505161, issued by INTERCERT and valid to 2028.
- Encryption in transit and at rest for call audio, transcripts and account data.
- Access control that is role-based, logged and reviewed, with production change control.
- Data residency in India, with logical separation per client.
- Full-coverage audit trail: every interaction recorded, transcribed and scored, which is a control as much as a product feature.
Tenancy, and never mixing your book with anyone else
Your data is held logically separated and is never pooled with another client's. No conversation, transcript or account attribute from your programme is visible in, or used to inform, another client's programme.
Each client runs on a separate instance, with full separation rather than shared schemas.
Whether your data trains our models
This is the question that decides deals, so it should be the clearest paragraph on the page.
Client data is not used to train models, and nothing is shared or interchanged between clients' models.
What we always do, whatever the instruction, is keep the benefit of your data inside your programme: tuning that improves your calls improves your calls.
Sub-processors
To deliver the service we engage sub-processors, and by accepting these terms you give a general authorisation for us to do so. They span categories such as cloud hosting and data residency, telephony and carrier connectivity, and speech services, meaning speech-to-text and text-to-speech. Each is engaged under contract, with data-protection obligations no weaker than ours to you.
A current list of our sub-processors is available on request.
We give advance notice of any new sub-processor, and at least 30 days' notice, before it starts work on your data, and a reasonable opportunity to object on reasonable data-protection grounds. If we cannot resolve your objection, you may terminate the affected service.
Audit and information rights
You may verify our compliance, and we would rather you did it efficiently than exhaustively. In order of preference for both of us: our certifications and reports, then a completed security questionnaire, then a walkthrough with our security owner, then an on-site or remote audit on reasonable notice.
Audits are once per quarter at most, on reasonable notice, and you bear the cost unless there is a material finding.
If something goes wrong
On becoming aware of a personal data breach affecting your data, we will notify you without undue delay and within 48 hours of confirming the breach, with what we know, what we are doing, and what you need in order to meet your own reporting obligations.
We will not sit on partial information waiting for a complete picture. You need to start your own clock, and under sectoral rules that clock can be short.
Helping you answer your customers
Where a data principal exercises a right against you and it touches data we hold, we assist: locating the data, correcting it, deleting it, or producing what you need to answer. If they come to us directly, we route them to you and confirm we have done so, because the request is yours to answer.
Return and deletion at the end
On termination or expiry, at your written election we return your data in an agreed format or delete it, including from backups on the ordinary backup cycle, and we certify the deletion.
Return and deletion timelines are agreed per engagement in the contract.
Precedence, and getting the signed version
This page summarises. Your signed DPA governs, and in a conflict between the two, your DPA wins. In a conflict between the DPA and the master services agreement on a data matter, the DPA wins.
To receive the signed DPA, a completed security questionnaire, or a walkthrough with our security owner, use the security route on the contact page. Governing law is India, with the courts at Delhi having exclusive jurisdiction. The processor entity is Unlax Consumer Solutions Private Limited, operating as Oriserve (CIN U74999MH2015PTC264880), whose registered office is at 15 F, Bapurao Jagtap Marg, Jacob Circle, Mumbai, Maharashtra 400011, with its correspondence office at 4th Floor, C-15, Sector-3, Noida, Gautam Buddha Nagar, Uttar Pradesh 201301.