Privacy Policy
Last updated: 27 August 2026
1. Who we are
This Privacy Policy explains how Zyfer Digital Systems Private Limited (CIN: U62011TN2026PTC195598), a company incorporated under the Companies Act, 2013 with the Government of India, Ministry of Corporate Affairs ("Zyfer", "we", "us", "our"), the operator of the Zyfer AI Employee platform available at portal.zyfer.ai (the "Service"), collects, uses, discloses, and protects information when you or your organisation ("Customer", "you") use the Service.
Registered office: G1, #4/608, V.O.C. Street, Desk # 223, Kottivakkam, Tiruvanmiyur, Chennai City Corporation, Chennai- 600041, Tamil Nadu. For privacy questions, contact our Grievance Officer / Data Protection contact at privacy@zyfer.ai (or Ganesh S. @ G1, #4/608, V.O.C. Street, Desk # 223, Kottivakkam, Tiruvanmiyur, Chennai City Corporation, Chennai- 600041, Tamil Nadu, as required under the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 of India).
2. Information we collect
2.1 Information you provide to us
- Account & organisation data: name, work email, password (hashed), organisation name, industry, phone number, GSTIN, and other business details provided during sign-up or onboarding.
- Verification documents: KYC and compliance documents you upload (e.g. certificate of incorporation, GST certificate, authorised signatory KYC), stored in encrypted cloud storage.
- AI Employee configuration: the names, roles, voice/persona settings, working hours, system-prompt descriptions, welcome messages, and reference/RAG documents you configure for your AI Employees.
- Calendar connections: the name, email, and calendar-provider authorisation (Google or Microsoft, via OAuth) of anyone who connects a calendar so an AI Employee can schedule on their behalf — for example, an HR Executive's interview panellists, or the calendar of a customer-facing employee booking demos, site visits, or other meetings. See Section 3 for our complete, dedicated statement on this calendar data specifically.
- Billing information: plan selection, billing address, and payment details processed by our payment processors (Razorpay / Dodo Payments) — we do not store full card numbers ourselves.
- Support communications: anything you send us via email or in-app support.
2.2 Information collected automatically
- Call data: when your AI Employees make or receive calls, we process call metadata (timestamps, duration, direction, outcome) and, via our voice-AI subprocessor, call recordings and transcripts, in order to provide the Service, calculate usage/billing, and let you review activity.
- Usage & log data: IP address, browser/device information, pages visited, and actions taken in the portal, for security, debugging, and product analytics.
- Cookies: we use essential cookies (e.g. session/authentication tokens) required for the Service to function. We do not use third-party advertising cookies.
3. Our use of Google and Microsoft calendar data
This section describes, completely and exclusively, how we handle information we receive through the Google Calendar and Microsoft Graph calendar APIs, authorised by whoever connects a calendar for an AI Employee to schedule against. Nothing elsewhere in this policy expands this use, and the same restrictions apply equally regardless of which provider the calendar is connected through.
- We use this calendar data solely to identify the connected calendar and to check availability and create or update events for the scheduling task relevant to that AI Employee's role — for example, an interview (HR Executive), a demo or site visit (outbound sales roles), or another customer meeting. We do not use it for anything else.
- We do not use this calendar data for advertising or marketing of any kind, and we do not use it to train or improve any artificial intelligence or machine learning model, foundational or otherwise.
- We do not combine this calendar data with other information about you for any purpose beyond providing the relevant scheduling feature.
- This calendar data is not read by Zyfer personnel in the ordinary course. Access is limited to the automated processing necessary to provide the feature, or as required to investigate abuse, comply with law, or with your explicit consent.
- We do not sell or transfer this calendar data to any third party, except: (a) to n8n, our workflow-automation subprocessor, strictly to perform the scheduling operation on our behalf; (b) where required by law; or (c) as part of a merger, acquisition, or asset sale, subject to the acquiring party continuing to honour this policy.
- Whoever connected a calendar can revoke that access at any time — the customer can revoke it from the Configure page, and the calendar owner can revoke it directly in their Google or Microsoft account settings — either of which stops all further access immediately.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of information received from Microsoft Graph likewise adheres to the Microsoft APIs Terms of Use.
4. How we use your information
Outside of the calendar data described in Section 3 (governed exclusively by that section), we use the information described in Section 2 to:
- Provide, operate, and maintain the Service, including provisioning and operating your AI Employees.
- Process payments, manage subscriptions, and send billing communications.
- Verify your organisation's identity and compliance documents where required.
- Monitor, secure, and improve the Service, including fraud and abuse prevention.
- Communicate with you about your account, including service notices, security alerts, and (with consent, where required) product updates.
- Comply with legal obligations, including tax, accounting, and regulatory requirements applicable in India.
5. Who we share information with
We do not sell your personal information. Calendar data (Section 3) is shared only as described there. For everything else, we share information with the following categories of subprocessors, solely to operate the Service:
- Voice-AI subprocessor — conversational voice-AI processing for your AI Employees (calls, transcripts, voice synthesis). Does not receive Google or Microsoft calendar data.
- Google Cloud Platform — hosting, databases, and storage for the Service (data residency in the Mumbai / asia-south1 region where applicable).
- n8n (workflow automation) — orchestration of AI Employee provisioning, and (per Section 3) performing the scheduling operation using Google or Microsoft calendar data on our behalf.
- Razorpay / Dodo Payments — payment processing for subscriptions and invoices. Does not receive Google or Microsoft calendar data.
- Email delivery providers — transactional email (account, billing, and scheduling notifications). Does not receive Google or Microsoft calendar data.
We may also disclose information where required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Zyfer, our customers, or others.
6. Data retention
We retain account and organisation data for as long as your account is active, and for a reasonable period thereafter to comply with legal, tax, and accounting obligations. Call recordings and transcripts are retained for the period necessary to provide the Service and resolve disputes, after which they are deleted or anonymised. You may request deletion of your data as described in Section 8, subject to statutory retention requirements (e.g. financial records under Indian law).
7. Data security
We use industry-standard safeguards, including encryption in transit (TLS) and at rest for sensitive data such as KYC documents and calendar tokens, role-based access controls, and audit logging. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Your rights
Subject to applicable law (including the Digital Personal Data Protection Act, 2023), you may have the right to:
- Access, correct, or update your personal information (available directly in your account Profile);
- Request deletion of your account and associated data;
- Withdraw consent for optional processing (e.g. revoke a connected calendar at any time from the Configure page);
- Lodge a grievance with our Grievance Officer (Section 1) or the appropriate data protection authority.
To exercise these rights, contact privacy@zyfer.ai.
9. International data transfers
Our infrastructure is primarily hosted in India (Google Cloud, asia-south1). Some subprocessors (e.g. our voice-AI processor) may process data in other jurisdictions. Where this occurs, we require subprocessors to maintain appropriate safeguards.
10. Children's privacy
The Service is intended for business use by adults. We do not knowingly collect personal information from individuals under 18.
11. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or via an in-app notice. Continued use of the Service after changes take effect constitutes acceptance of the revised policy.
12. Contact us
Questions about this Privacy Policy? Email privacy@zyfer.ai or write to G1, #4/608, V.O.C. Street, Desk # 223, Kottivakkam, Tiruvanmiyur, Chennai City Corporation, Chennai- 600041, Tamil Nadu.
See also our Terms of Service.
