Legal

Privacy Policy

Last updated: August 11, 2026  ·  Effective: August 11, 2026

Privacy Policy Terms of Service Acceptable Use Sub-processors Cookies Refunds & Cancellation

This Privacy Policy explains how Vizionsys Technologies Private Limited (“we”, “us”, or “our”), operating as imatic.ai, collects, uses, stores, shares, and protects information when you use the imatic.ai website, the imatic.ai Voice AI Orchestration Platform, the imatic scheduling & calendar product, and the imatic survey product (collectively, the “Services”). It includes a dedicated section describing how we handle Google user data obtained through the Google Calendar API.

We never train on your data

Your calls, transcripts, survey responses and calendar content are never used to train or fine-tune any AI model. Our sub-processors are contractually barred from it too.

We don’t sell your data

We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.

You control retention

You decide whether calls are recorded and for how long recordings and transcripts are kept.

Data residency

We support hosting in India and the USA, plus private-cloud and on-premise deployment for regulated workloads.

Contents

  1. Who we are & our role
  2. Information we collect
  3. AI & model training
  4. Voice, calls & data residency
  5. Google user data & Calendar API
  6. Limited Use disclosure
  7. How we use information
  8. Legal bases for processing
  9. How we share information
  10. Sub-processors
  11. Data retention
  12. Security
  13. Breach notification
  14. International transfers
  15. Your rights
  16. India: DPDP Act, 2023
  17. Automated decision-making
  18. Revoking access & deletion
  19. Cookies
  20. Do Not Track
  21. Children
  22. Changes
  23. Contact & Grievance Officer

1. Who we are & our role

The Services are operated by Vizionsys Technologies Private Limited, a company incorporated in India, with its registered office in Bengaluru, Karnataka, India. You can reach us at hello@imatic.ai or +91 99675 80291.

Our role depends on whose data is involved:

2. Information we collect

The table below lists every category we collect, why, the legal basis we rely on, who it is shared with, and how long we keep it. Retention is summarised again in section 11.

CategoryWhat it includesWhy we process it Legal basisShared withRetention
Account Name, email, phone, organisation, role, hashed password, authentication identifiers (including Google Sign-In). Create and secure your account; identify you; provide the Services. Contract Hosting and email providers Life of account + 90 days
Voice & call data Call audio, recordings, transcripts, call metadata (numbers, timestamps, duration, outcome), and information shared during the conversation. Operate the conversation, deliver the call, and generate the analytics you asked for. Contract; your instructions as controller Telephony, speech and language-model providers you enable You configure it; see §11
Booking & calendar Meetings, availability, attendee details, event titles, times, notes. Compute availability, create and sync bookings. Contract Google Calendar (where you connect it) Life of account + 90 days
Survey responses Answers submitted to forms you publish, and any identifiers you choose to collect. Deliver the survey and report results to you. Your instructions as controller Hosting provider Until you delete them
Google user data Basic profile plus the calendar data described in section 5. Provide the scheduling features you request. Consent Not shared — see §6 While connected; deleted within 30 days
Enquiry & attribution Contact or demo-request form details, plus the campaign or referral source (UTM parameters, referrer, landing page). Respond to your enquiry and understand which campaigns work. Legitimate interests Not shared 24 months
Billing Billing contact, GST number, plan, invoices, payment status. Card details go directly to our payment processor and are never stored by us. Take payment, issue invoices, meet tax and accounting obligations. Contract; legal obligation Razorpay; auditors 8 years (Companies Act, 2013)
Usage & device Log data, IP address, browser and device type, pages viewed, diagnostics. For sign-ins and other security events, the approximate location (country, region, city) we derive from the IP address. Operate, secure and debug the Services; prevent abuse; let you and your administrators spot sign-ins from unfamiliar places. Legitimate interests Hosting provider; IP-geolocation provider (§10) 12 months
Website analytics On the imatic.ai marketing website only, and only if you accept: pages viewed, referring page, browser, device type and language, an identifier stored in a first-party cookie, and the approximate location Google derives from your IP address. Count visits and understand which pages are useful, so we can improve the site. Never used for advertising or to build audiences. Consent Google (Google Analytics) Cookies expire after 2 years; reports per the property’s retention setting
Communications Support requests and correspondence. Answer you and improve support quality. Contract; legitimate interests Email provider 24 months

We collect this information in three ways: when you give it to us directly; automatically as you use the Services (cookies and similar technologies — see section 19); and, where you authorise it, from third parties such as Google when you connect an account.

Sensitive personal data. We do not ask for special-category data (health, biometrics, religious or political views, and similar). Because voice conversations are open-ended, such information may occasionally be spoken during a call. Do not configure the Services to solicit it unless you have a lawful basis to do so, and use the redaction controls described in section 4.

3. AI & model training

We do not train AI models on your data

We do not use Your Data — including call audio, recordings, transcripts, survey responses, calendar content, documents, or any other customer content — to train, fine-tune, or otherwise improve any artificial-intelligence or machine-learning model, whether ours or a third party’s.

Our sub-processors are engaged under terms that contractually prohibit them from using data we send them to train or improve their own models. Data is sent to them only to produce the immediate output your configuration requires — transcribing an utterance, synthesising speech, or generating a reply — and for no other purpose.

We do not create voice clones of any individual, and we do not use recordings to build voice models. Where you choose a synthetic voice, it comes from your speech provider’s existing catalogue.

We do use aggregated, de-identified operational metrics — such as call volumes, latency percentiles, error rates and feature usage counts — to monitor reliability and plan capacity. These metrics contain no personal information and cannot be re-linked to any individual, organisation, or conversation.

4. Voice, calls, recordings & data residency

imatic.ai is a voice AI platform, so call handling is central to how we process data on your behalf. For these flows you are the controller of your end-customers’ data and we act as your processor.

5. Google user data & the Google Calendar API

When you choose to connect a Google Account, imatic.ai uses Google OAuth 2.0 to request access to specific data through Google APIs. We request only the scopes necessary to provide the scheduling features you ask for, and you can review and revoke this access at any time.

Google OAuth scopeWhat it allowsWhy we use it
openid, userinfo.email, userinfo.profile Read your basic profile: name, email address, and profile picture. To create and identify your account and show which Google Account is connected.
calendar.events View, create, edit, and delete events on calendars you authorize. To create bookings on your calendar, check conflicts, and keep events in sync when a meeting is booked, rescheduled, or cancelled through imatic.ai.
calendar.readonly / calendar.freebusy Read your calendar busy/free times and event details. To compute your real-time availability so invitees are only offered slots when you are free.

What we access: only the calendars and events you connect and authorize. What we store: we store the minimum data needed to operate scheduling — for example, event identifiers, start/end times, busy/free status, and the events that imatic.ai itself creates on your behalf. We store OAuth tokens in encrypted form so we can perform these actions while your connection is active. We do not store the full contents of unrelated calendar events beyond what is required to detect conflicts and display your schedule.

How Google data is used: Google user data is used solely to provide and improve the user-facing scheduling features you request. We do not use Google user data for advertising, we do not sell it, we do not use it to train any AI or machine-learning model, and we do not allow humans to read it except (a) with your explicit consent, (b) where necessary for security or to comply with applicable law, or (c) in aggregated/anonymized form for internal operations such as debugging.

6. Limited Use disclosure

Compliance with the Google API Services User Data Policy

imatic.ai’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically: we only use Google user data to provide or improve user-facing features that are prominent in our application; we do not transfer or sell this data for serving advertisements, for purposes unrelated to those features, to data brokers, or to determine creditworthiness; and we do not allow humans to read this data unless we have your affirmative consent for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or our use is limited to internal operations with data aggregated and anonymized.

7. How we use information

We do not use your information for advertising, and we do not sell or rent it.

8. Legal bases for processing

Where the EU or UK GDPR applies, we rely on the following bases. The table in section 2 shows which applies to each category.

9. How we share information

We do not sell your personal information. We share it only as follows:

Google user data is never shared with third parties except as strictly necessary to provide the features described in section 5, and always consistent with the Limited Use requirements in section 6.

10. Sub-processors

We publish a current list of sub-processors, the purpose each one serves, and the region it operates in, at imatic.ai/subprocessors.html. Which providers apply to your account depends on the telephony, speech and language-model options you enable — not every provider on the list touches every customer’s data.

Every sub-processor is engaged under written terms requiring confidentiality, appropriate security measures, processing limited to our instructions, and a prohibition on training their models with your data. We remain responsible to you for their performance.

11. Data retention

We keep personal information only as long as we need it for the purpose it was collected, or as long as the law requires. Our standard periods:

Account & profile
Life of the account, then deleted within 90 days of closure.
Call recordings & transcripts
You set the retention period. Where you set none, our default is 90 days. Deletion requests are actioned within 30 days.
Call metadata
Retained for the life of the account so your historical reporting stays intact, unless you delete it sooner.
Booking & calendar data
Life of the account, then deleted within 90 days.
Google tokens & synced calendar data
Only while your Google connection is active. Deleted from active systems within 30 days of disconnection or account deletion.
Survey responses
Until you delete them or close your account.
Billing, invoices & tax records
8 years, as required by the Companies Act, 2013 and applicable tax law.
Server & security logs
12 months. This includes sign-in audit records and the IP address and approximate location attached to them.
Website analytics
Only if you accepted analytics cookies. The cookies expire two years after your last visit, or immediately if you withdraw consent; the reports in Google Analytics are kept for the retention period set on the property, and Google’s maximum for user-level data is 14 months.
Support correspondence
24 months.
Marketing contact data
Until you unsubscribe, then removed within 30 days.
Backups
Encrypted backups roll off within 35 days. Deleted records may persist in a backup until that cycle completes, after which they are gone.

We may retain data longer where it is needed to resolve a dispute, enforce our agreements, or comply with a legal hold. Enterprise customers may agree different periods by contract, which take precedence over the defaults above.

12. Security

We apply administrative, technical, and physical safeguards proportionate to the risk, including:

No method of transmission or storage is completely secure. We do not claim any third-party security certification, and you should not infer one from this Policy; we describe the controls we actually operate so you can assess them on their merits. If you have a security concern or believe you have found a vulnerability, write to hello@imatic.ai.

13. Breach notification

If we become aware of a personal data breach, we will investigate promptly, take reasonable steps to contain it, and notify affected customers and the relevant supervisory authorities within the timeframes the applicable law requires — including notification to the Data Protection Board of India under the DPDP Act, 2023, and, where the GDPR applies, notification to the lead supervisory authority without undue delay and, where feasible, within 72 hours. Where we act as your processor, we will notify you without undue delay so that you can meet your own obligations.

14. International data transfers

We are based in India and use cloud infrastructure that may process data in India, the USA, and other regions depending on the residency option and providers you select. Where personal data moves across borders, we rely on appropriate safeguards under applicable law — including the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) for transfers out of the EEA or UK, together with contractual security and confidentiality commitments from the receiving party. You can ask us for details of the safeguards that apply to your account.

15. Your rights

Depending on where you are, you may have some or all of the following rights. To exercise any of them, write to hello@imatic.ai. We respond within 30 days and do not charge for reasonable requests.

If your data reached us through one of our customers — for example because you were called by an agent they operate, or answered their survey — they are the controller. Send your request to them; we will assist them in answering it, and we will refer you to them if you contact us directly.

16. India: Digital Personal Data Protection Act, 2023

Where we act as a Data Fiduciary under the DPDP Act, 2023, we process personal data for the lawful purposes described in this Policy, on the basis of your consent or a legitimate use permitted by the Act. As a Data Principal you have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to a readily available means of grievance redressal.

You may give, manage, review and withdraw consent at any time, and withdrawal must be as easy as giving it. Where you register with a Consent Manager under the Act, you may route consent through it. Notices about consent are available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.

Our Grievance Officer’s details are in section 23.

17. Automated decision-making

Our voice agents generate replies automatically, and our survey and routing features can branch based on the answers given. These are operational automations, not evaluations of a person.

We do not make decisions producing legal effects, or similarly significant effects, about any individual on a solely automated basis, and we do not use the Services to profile individuals for credit, employment, insurance, or law-enforcement purposes. If you configure the Services to feed such a decision, you are responsible for the human review and disclosures the law requires.

18. Revoking access & requesting deletion

You are always in control of your data. You can:

19. Cookies

In the product we use strictly necessary cookies and equivalent storage to keep you signed in, remember your preferences, and secure your session. These do not require consent, because without them you could not use the service you asked for.

On the marketing website we also use Google Analytics to count visits and see which pages are useful. This is the only non-essential category we operate, and it is off until you accept it: no analytics cookie is written and nothing is requested from Google until you choose to accept. We set no advertising cookies, and the tag is configured with Google Signals and ad-personalisation switched off. You can change or withdraw your choice at any time using the Cookie preferences link in the website footer; withdrawing also deletes the analytics cookies from your browser. The full inventory, including cookie names and lifetimes, is in our Cookie Policy.

20. Do Not Track

There is no industry consensus on how to interpret browser “Do Not Track” signals, and we do not currently respond to them. We do not track you across third-party websites, and we do not permit third-party advertising trackers on our sites, so there is no cross-site profile of you to opt out of. Our website analytics runs only with your consent, is limited to our own site, and is configured without Google’s advertising and ad-personalisation features — and you can refuse or withdraw it at any time, as described in section 19.

21. Children

The Services are not directed to children. You must be at least 18 to create an account, which matches the requirement in our Terms of Service and reflects the treatment of children under India’s DPDP Act, 2023. We do not knowingly collect personal data from children, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us data, contact us and we will delete it promptly.

22. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and notify account holders by email or in-product notice before the change takes effect. Your continued use of the Services after that date constitutes acceptance of the revised Policy. Previous versions are available on request.

23. Contact & Grievance Officer

For any question about this Policy, or to exercise a right under section 15:

Entity
Vizionsys Technologies Private Limited
Address
Bengaluru, Karnataka, India
Email
hello@imatic.ai
Phone
+91 99675 80291
Grievance Officer
Contactable at hello@imatic.ai with the subject line “Grievance”, or by phone on +91 99675 80291. We acknowledge grievances within 72 hours and aim to resolve them within 30 days.