Privacy Policy
This Privacy Policy explains how Vizionsys Technologies Private Limited (“we”, “us”, or “our”), operating as imatic.ai, collects, uses, stores, shares, and protects information when you use the imatic.ai website, the imatic.ai Voice AI Orchestration Platform, the imatic scheduling & calendar product, and the imatic survey product (collectively, the “Services”). It includes a dedicated section describing how we handle Google user data obtained through the Google Calendar API.
We never train on your data
Your calls, transcripts, survey responses and calendar content are never used to train or fine-tune any AI model. Our sub-processors are contractually barred from it too.
We don’t sell your data
We do not sell or rent personal information, and we do not share it for cross-context behavioural advertising.
You control retention
You decide whether calls are recorded and for how long recordings and transcripts are kept.
Data residency
We support hosting in India and the USA, plus private-cloud and on-premise deployment for regulated workloads.
Contents
- Who we are & our role
- Information we collect
- AI & model training
- Voice, calls & data residency
- Google user data & Calendar API
- Limited Use disclosure
- How we use information
- Legal bases for processing
- How we share information
- Sub-processors
- Data retention
- Security
- Breach notification
- International transfers
- Your rights
- India: DPDP Act, 2023
- Automated decision-making
- Revoking access & deletion
- Cookies
- Do Not Track
- Children
- Changes
- Contact & Grievance Officer
1. Who we are & our role
The Services are operated by Vizionsys Technologies Private Limited, a company incorporated in India, with its registered office in Bengaluru, Karnataka, India. You can reach us at hello@imatic.ai or +91 99675 80291.
Our role depends on whose data is involved:
- We are the controller (in India, the Data Fiduciary) for data about our own customers and website visitors — your account, billing, support and usage data. This Policy governs that processing.
- We are the processor (in India, a Data Processor) for data about your end-customers that flows through the Services — for example the person your voice agent calls, or someone who answers your survey or books a meeting with you. You are the controller of that data; we process it only on your documented instructions, and your agreement with us governs it.
2. Information we collect
The table below lists every category we collect, why, the legal basis we rely on, who it is shared with, and how long we keep it. Retention is summarised again in section 11.
| Category | What it includes | Why we process it | Legal basis | Shared with | Retention |
|---|---|---|---|---|---|
| Account | Name, email, phone, organisation, role, hashed password, authentication identifiers (including Google Sign-In). | Create and secure your account; identify you; provide the Services. | Contract | Hosting and email providers | Life of account + 90 days |
| Voice & call data | Call audio, recordings, transcripts, call metadata (numbers, timestamps, duration, outcome), and information shared during the conversation. | Operate the conversation, deliver the call, and generate the analytics you asked for. | Contract; your instructions as controller | Telephony, speech and language-model providers you enable | You configure it; see §11 |
| Booking & calendar | Meetings, availability, attendee details, event titles, times, notes. | Compute availability, create and sync bookings. | Contract | Google Calendar (where you connect it) | Life of account + 90 days |
| Survey responses | Answers submitted to forms you publish, and any identifiers you choose to collect. | Deliver the survey and report results to you. | Your instructions as controller | Hosting provider | Until you delete them |
| Google user data | Basic profile plus the calendar data described in section 5. | Provide the scheduling features you request. | Consent | Not shared — see §6 | While connected; deleted within 30 days |
| Enquiry & attribution | Contact or demo-request form details, plus the campaign or referral source (UTM parameters, referrer, landing page). | Respond to your enquiry and understand which campaigns work. | Legitimate interests | Not shared | 24 months |
| Billing | Billing contact, GST number, plan, invoices, payment status. Card details go directly to our payment processor and are never stored by us. | Take payment, issue invoices, meet tax and accounting obligations. | Contract; legal obligation | Razorpay; auditors | 8 years (Companies Act, 2013) |
| Usage & device | Log data, IP address, browser and device type, pages viewed, diagnostics. For sign-ins and other security events, the approximate location (country, region, city) we derive from the IP address. | Operate, secure and debug the Services; prevent abuse; let you and your administrators spot sign-ins from unfamiliar places. | Legitimate interests | Hosting provider; IP-geolocation provider (§10) | 12 months |
| Website analytics | On the imatic.ai marketing website only, and only if you accept: pages viewed, referring page, browser, device type and language, an identifier stored in a first-party cookie, and the approximate location Google derives from your IP address. | Count visits and understand which pages are useful, so we can improve the site. Never used for advertising or to build audiences. | Consent | Google (Google Analytics) | Cookies expire after 2 years; reports per the property’s retention setting |
| Communications | Support requests and correspondence. | Answer you and improve support quality. | Contract; legitimate interests | Email provider | 24 months |
We collect this information in three ways: when you give it to us directly; automatically as you use the Services (cookies and similar technologies — see section 19); and, where you authorise it, from third parties such as Google when you connect an account.
Sensitive personal data. We do not ask for special-category data (health, biometrics, religious or political views, and similar). Because voice conversations are open-ended, such information may occasionally be spoken during a call. Do not configure the Services to solicit it unless you have a lawful basis to do so, and use the redaction controls described in section 4.
3. AI & model training
We do not train AI models on your data
We do not use Your Data — including call audio, recordings, transcripts, survey responses, calendar content, documents, or any other customer content — to train, fine-tune, or otherwise improve any artificial-intelligence or machine-learning model, whether ours or a third party’s.
Our sub-processors are engaged under terms that contractually prohibit them from using data we send them to train or improve their own models. Data is sent to them only to produce the immediate output your configuration requires — transcribing an utterance, synthesising speech, or generating a reply — and for no other purpose.
We do not create voice clones of any individual, and we do not use recordings to build voice models. Where you choose a synthetic voice, it comes from your speech provider’s existing catalogue.
We do use aggregated, de-identified operational metrics — such as call volumes, latency percentiles, error rates and feature usage counts — to monitor reliability and plan capacity. These metrics contain no personal information and cannot be re-linked to any individual, organisation, or conversation.
4. Voice, calls, recordings & data residency
imatic.ai is a voice AI platform, so call handling is central to how we process data on your behalf. For these flows you are the controller of your end-customers’ data and we act as your processor.
- Recordings & transcripts are processed to run the conversation and generate the analytics you have enabled. You configure whether calls are recorded at all, and for how long recordings and transcripts are retained.
- Automatic PII redaction can mask sensitive fields — such as card or identity numbers — in transcripts and logs.
- Data residency — we support hosting in India and the USA, plus private-cloud and on-premise deployment for regulated workloads.
- Sub-processors — to deliver a call we route audio and text through the telephony, speech (STT/TTS) and language-model providers you enable. The full list is published at imatic.ai/subprocessors.html.
- Consent & lawful calling — you are responsible for obtaining the consents required to place calls and record conversations, and for honouring do-not-call registers. See our Acceptable Use Policy, which covers TRAI DND and DLT obligations in India and equivalent rules elsewhere.
- Disclosure to call participants — where the law requires that a person be told they are speaking with an automated system or that a call is recorded, you must configure your agent to say so.
5. Google user data & the Google Calendar API
When you choose to connect a Google Account, imatic.ai uses Google OAuth 2.0 to request access to specific data through Google APIs. We request only the scopes necessary to provide the scheduling features you ask for, and you can review and revoke this access at any time.
| Google OAuth scope | What it allows | Why we use it |
|---|---|---|
openid, userinfo.email, userinfo.profile |
Read your basic profile: name, email address, and profile picture. | To create and identify your account and show which Google Account is connected. |
calendar.events |
View, create, edit, and delete events on calendars you authorize. | To create bookings on your calendar, check conflicts, and keep events in sync when a meeting is booked, rescheduled, or cancelled through imatic.ai. |
calendar.readonly / calendar.freebusy |
Read your calendar busy/free times and event details. | To compute your real-time availability so invitees are only offered slots when you are free. |
What we access: only the calendars and events you connect and authorize. What we store: we store the minimum data needed to operate scheduling — for example, event identifiers, start/end times, busy/free status, and the events that imatic.ai itself creates on your behalf. We store OAuth tokens in encrypted form so we can perform these actions while your connection is active. We do not store the full contents of unrelated calendar events beyond what is required to detect conflicts and display your schedule.
How Google data is used: Google user data is used solely to provide and improve the user-facing scheduling features you request. We do not use Google user data for advertising, we do not sell it, we do not use it to train any AI or machine-learning model, and we do not allow humans to read it except (a) with your explicit consent, (b) where necessary for security or to comply with applicable law, or (c) in aggregated/anonymized form for internal operations such as debugging.
6. Limited Use disclosure
Compliance with the Google API Services User Data Policy
imatic.ai’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we only use Google user data to provide or improve user-facing features that are prominent in our application; we do not transfer or sell this data for serving advertisements, for purposes unrelated to those features, to data brokers, or to determine creditworthiness; and we do not allow humans to read this data unless we have your affirmative consent for specific messages, it is necessary for security purposes (such as investigating abuse), to comply with applicable law, or our use is limited to internal operations with data aggregated and anonymized.
7. How we use information
- Provide, operate, and maintain the Services and the features you request.
- Authenticate you and secure your account.
- Place and receive calls, run conversations, and produce the analytics you enable.
- Calculate availability, create and manage bookings, and synchronize events with your calendar.
- Deliver surveys and report results back to you.
- Send transactional communications (e.g., booking confirmations, reminders, account notices).
- Take payment, issue invoices, and meet tax and accounting obligations.
- Provide customer support and respond to your requests.
- Detect, prevent, and address fraud, abuse, security incidents, and technical issues.
- Comply with legal obligations and enforce our Terms of Service.
We do not use your information for advertising, and we do not sell or rent it.
8. Legal bases for processing
Where the EU or UK GDPR applies, we rely on the following bases. The table in section 2 shows which applies to each category.
- Performance of a contract — to deliver the Services you have signed up for and to bill you for them.
- Legitimate interests — to secure the Services, prevent fraud and abuse, debug problems, and understand which campaigns bring people to us. We balance these against your rights and you may object at any time (section 14).
- Consent — for optional integrations such as connecting a Google Account, for website analytics and any other non-essential cookies, and for marketing email. You may withdraw consent at any time, and withdrawing is as easy as giving it.
- Legal obligation — to retain accounting records and to respond to lawful requests from authorities.
9. How we share information
We do not sell your personal information. We share it only as follows:
- Sub-processors — hosting, telephony, speech, language-model, payment, email, IP-geolocation and website-analytics providers who process data on our behalf under contractual confidentiality, security, and no-training obligations. The list, and what each one receives, is at imatic.ai/subprocessors.html.
- At your direction — for example sharing booking details with the invitees or hosts of a meeting you schedule, or delivering data to an integration you connect.
- Legal & safety — when required by law, regulation, or legal process, or to protect the rights, property, or safety of users, the public, or imatic.ai. Where we are legally permitted to do so, we will tell you before disclosing your data.
- Professional advisors — auditors, accountants and lawyers, under a duty of confidentiality.
- Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this Policy. We will notify you before your data becomes subject to a different privacy policy.
Google user data is never shared with third parties except as strictly necessary to provide the features described in section 5, and always consistent with the Limited Use requirements in section 6.
10. Sub-processors
We publish a current list of sub-processors, the purpose each one serves, and the region it operates in, at imatic.ai/subprocessors.html. Which providers apply to your account depends on the telephony, speech and language-model options you enable — not every provider on the list touches every customer’s data.
Every sub-processor is engaged under written terms requiring confidentiality, appropriate security measures, processing limited to our instructions, and a prohibition on training their models with your data. We remain responsible to you for their performance.
11. Data retention
We keep personal information only as long as we need it for the purpose it was collected, or as long as the law requires. Our standard periods:
- Account & profile
- Life of the account, then deleted within 90 days of closure.
- Call recordings & transcripts
- You set the retention period. Where you set none, our default is 90 days. Deletion requests are actioned within 30 days.
- Call metadata
- Retained for the life of the account so your historical reporting stays intact, unless you delete it sooner.
- Booking & calendar data
- Life of the account, then deleted within 90 days.
- Google tokens & synced calendar data
- Only while your Google connection is active. Deleted from active systems within 30 days of disconnection or account deletion.
- Survey responses
- Until you delete them or close your account.
- Billing, invoices & tax records
- 8 years, as required by the Companies Act, 2013 and applicable tax law.
- Server & security logs
- 12 months. This includes sign-in audit records and the IP address and approximate location attached to them.
- Website analytics
- Only if you accepted analytics cookies. The cookies expire two years after your last visit, or immediately if you withdraw consent; the reports in Google Analytics are kept for the retention period set on the property, and Google’s maximum for user-level data is 14 months.
- Support correspondence
- 24 months.
- Marketing contact data
- Until you unsubscribe, then removed within 30 days.
- Backups
- Encrypted backups roll off within 35 days. Deleted records may persist in a backup until that cycle completes, after which they are gone.
We may retain data longer where it is needed to resolve a dispute, enforce our agreements, or comply with a legal hold. Enterprise customers may agree different periods by contract, which take precedence over the defaults above.
12. Security
We apply administrative, technical, and physical safeguards proportionate to the risk, including:
- Encryption in transit (TLS 1.2+) and encryption at rest for stored data.
- Encryption of stored OAuth tokens and API credentials.
- Role-based access control, least-privilege provisioning, and tenant isolation so one customer’s data is not reachable from another’s account.
- Audit logging of administrative and privileged actions, and of sign-in activity — including successful and failed attempts, the IP address used, and the approximate location we resolve from it through the IP-geolocation provider listed on our Sub-processors page — so that unfamiliar access can be spotted. Passwords, one-time codes and reset links are never written to these records.
- Optional automatic PII redaction in transcripts and logs.
- Regular patching, dependency scanning, and access reviews.
No method of transmission or storage is completely secure. We do not claim any third-party security certification, and you should not infer one from this Policy; we describe the controls we actually operate so you can assess them on their merits. If you have a security concern or believe you have found a vulnerability, write to hello@imatic.ai.
13. Breach notification
If we become aware of a personal data breach, we will investigate promptly, take reasonable steps to contain it, and notify affected customers and the relevant supervisory authorities within the timeframes the applicable law requires — including notification to the Data Protection Board of India under the DPDP Act, 2023, and, where the GDPR applies, notification to the lead supervisory authority without undue delay and, where feasible, within 72 hours. Where we act as your processor, we will notify you without undue delay so that you can meet your own obligations.
14. International data transfers
We are based in India and use cloud infrastructure that may process data in India, the USA, and other regions depending on the residency option and providers you select. Where personal data moves across borders, we rely on appropriate safeguards under applicable law — including the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant) for transfers out of the EEA or UK, together with contractual security and confidentiality commitments from the receiving party. You can ask us for details of the safeguards that apply to your account.
15. Your rights
Depending on where you are, you may have some or all of the following rights. To exercise any of them, write to hello@imatic.ai. We respond within 30 days and do not charge for reasonable requests.
- Access — obtain a copy of the personal data we hold about you.
- Rectification — correct data that is inaccurate or incomplete.
- Erasure — ask us to delete your data, subject to legal retention obligations. Deleting data may make some or all of the Services unusable.
- Portability — receive data you provided in a structured, machine-readable format, and have it sent to another provider where technically feasible.
- Restriction — limit how we use your data while a dispute about its accuracy or our basis for processing is resolved.
- Objection — object to processing based on legitimate interests, and to direct marketing at any time and without qualification.
- Withdraw consent — where processing relies on consent. Withdrawal does not affect the lawfulness of processing carried out beforehand.
- Complain — lodge a complaint with your local data protection authority. In India this is the Data Protection Board; in the EU/UK it is your national supervisory authority. We would appreciate the chance to resolve it first.
If your data reached us through one of our customers — for example because you were called by an agent they operate, or answered their survey — they are the controller. Send your request to them; we will assist them in answering it, and we will refer you to them if you contact us directly.
16. India: Digital Personal Data Protection Act, 2023
Where we act as a Data Fiduciary under the DPDP Act, 2023, we process personal data for the lawful purposes described in this Policy, on the basis of your consent or a legitimate use permitted by the Act. As a Data Principal you have the right to access a summary of your personal data and our processing, to correction and erasure, to nominate another person to exercise your rights in the event of death or incapacity, and to a readily available means of grievance redressal.
You may give, manage, review and withdraw consent at any time, and withdrawal must be as easy as giving it. Where you register with a Consent Manager under the Act, you may route consent through it. Notices about consent are available in English and, on request, in any language listed in the Eighth Schedule to the Constitution of India.
Our Grievance Officer’s details are in section 23.
17. Automated decision-making
Our voice agents generate replies automatically, and our survey and routing features can branch based on the answers given. These are operational automations, not evaluations of a person.
We do not make decisions producing legal effects, or similarly significant effects, about any individual on a solely automated basis, and we do not use the Services to profile individuals for credit, employment, insurance, or law-enforcement purposes. If you configure the Services to feed such a decision, you are responsible for the human review and disclosures the law requires.
18. Revoking access & requesting deletion
You are always in control of your data. You can:
- Disconnect Google inside imatic.ai — open Settings → Integrations and remove the Google connection. This revokes our access and removes stored Google tokens.
- Revoke access from your Google Account — visit myaccount.google.com/permissions and remove imatic.ai. Google will immediately stop our access.
- Delete individual records — recordings, transcripts, survey responses and bookings can be deleted from within the product.
- Delete your account & data — email hello@imatic.ai and we will delete your account and the personal data we hold, subject to legal retention requirements, within 30 days.
19. Cookies
In the product we use strictly necessary cookies and equivalent storage to keep you signed in, remember your preferences, and secure your session. These do not require consent, because without them you could not use the service you asked for.
On the marketing website we also use Google Analytics to count visits and see which pages are useful. This is the only non-essential category we operate, and it is off until you accept it: no analytics cookie is written and nothing is requested from Google until you choose to accept. We set no advertising cookies, and the tag is configured with Google Signals and ad-personalisation switched off. You can change or withdraw your choice at any time using the Cookie preferences link in the website footer; withdrawing also deletes the analytics cookies from your browser. The full inventory, including cookie names and lifetimes, is in our Cookie Policy.
20. Do Not Track
There is no industry consensus on how to interpret browser “Do Not Track” signals, and we do not currently respond to them. We do not track you across third-party websites, and we do not permit third-party advertising trackers on our sites, so there is no cross-site profile of you to opt out of. Our website analytics runs only with your consent, is limited to our own site, and is configured without Google’s advertising and ad-personalisation features — and you can refuse or withdraw it at any time, as described in section 19.
21. Children
The Services are not directed to children. You must be at least 18 to create an account, which matches the requirement in our Terms of Service and reflects the treatment of children under India’s DPDP Act, 2023. We do not knowingly collect personal data from children, and we do not undertake tracking, behavioural monitoring, or targeted advertising directed at children. If you believe a child has provided us data, contact us and we will delete it promptly.
22. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date above and notify account holders by email or in-product notice before the change takes effect. Your continued use of the Services after that date constitutes acceptance of the revised Policy. Previous versions are available on request.
23. Contact & Grievance Officer
For any question about this Policy, or to exercise a right under section 15:
- Entity
- Vizionsys Technologies Private Limited
- Address
- Bengaluru, Karnataka, India
- hello@imatic.ai
- Phone
- +91 99675 80291
- Grievance Officer
- Contactable at hello@imatic.ai with the subject line “Grievance”, or by phone on +91 99675 80291. We acknowledge grievances within 72 hours and aim to resolve them within 30 days.