Legal

Privacy Policy

Plain-language notes on what we collect, why, and the rights you have under the Digital Personal Data Protection Act, 2023. Last updated 5 September 2026.

1. Who we are

Agent27 (“Agent27”, “we”, “us”) provides a customer relationship management service for sales teams. This policy explains what personal data we handle, why, and what rights you have.

For data you enter about your own leads and customers, your company is the Data Fiduciary and Agent27 acts as a Data Processor on its instructions. For your account details, billing and product usage, Agent27 is the Data Fiduciary. You can reach our Grievance Officer at privacy@agent27.app.

2. What we collect

Account data: name, work email, phone number, role, workspace name and the password hash held by our authentication provider.

Customer data you upload: lead names, phone numbers, emails, company, deal values, notes, tags, tasks and the messages exchanged with them over WhatsApp, calls and email.

Communication data: WhatsApp message content and delivery status, call recordings and transcripts when your workspace enables them, and email metadata.

Billing data: plan, invoices, GSTIN if you provide one, and payment status. Card, UPI and bank details are entered directly into Razorpay and never touch our servers.

Usage and device data: pages visited, features used, browser type, approximate location from IP, and error reports. We use this to keep the product working and to improve it.

3. Why we use it

  • To run the service: store your pipeline, route inbound leads, send the messages you or your automations ask us to send, and place calls you initiate.
  • To generate AI assistance: draft replies, summarise calls, build pre-call briefs and score urgency. Only the data needed for that task is sent to the AI provider, and it is not used to train their models under our agreements.
  • To bill you and prevent fraud.
  • To send product notices such as invites, security alerts and billing receipts.
  • To understand how the product is used, in aggregate, so we can improve it.

5. Your rights under the DPDP Act, 2023

If you are a Data Principal whose data we hold, you can:

  • Access a summary of the personal data we process about you and who we have shared it with.
  • Correct or update data that is inaccurate or incomplete.
  • Erase your data once it is no longer needed for the purpose it was collected for, subject to legal retention duties.
  • Withdraw consent at any time; withdrawal does not affect processing that already took place.
  • Nominate another person to exercise these rights on your behalf if you are unable to.
  • Raise a grievance with our Grievance Officer. We respond within 30 days. If you are not satisfied you may approach the Data Protection Board of India.

If your data was entered into Agent27 by a business that uses our service, we will forward your request to that business and help them fulfil it.

6. How long we keep data

  • Workspace and customer data: for as long as your workspace is active. Deleted leads are soft-deleted for 30 days so mistakes can be reversed, then permanently removed.
  • Call recordings and transcripts: 12 months by default, configurable per workspace down to 7 days.
  • Closed workspaces: all data is deleted 30 days after closure, except invoices and audit records we must keep for 8 years under Indian tax and company law.
  • Backups: encrypted backups are retained for 30 days and then overwritten.
  • Product analytics and error logs: 90 days.

7. How we protect it

  • All data is encrypted in transit (TLS 1.2 or higher) and at rest.
  • Integration credentials (WhatsApp, telephony, email) are stored only as AES-256-GCM ciphertext and decrypted inside the request that needs them.
  • Every table is protected by row-level security so one workspace can never read another’s rows.
  • Sensitive actions such as exports, member removals and billing changes are written to an append-only audit log.
  • Primary storage is in Mumbai, India. Some AI and email providers process data outside India; each is bound by a contract that limits use to providing the service to us.

8. Sub-processors

We use the following providers to deliver the service. We will update this list and notify workspace owners by email at least 15 days before adding a new sub-processor.

ProviderPurposeRegion
SupabaseDatabase, authentication and file storageMumbai (ap-south-1)
VercelApplication hosting and edge networkMumbai (bom1) with global edge caching
Meta PlatformsWhatsApp Business Cloud API and Lead Ads deliveryGlobal
AnthropicAI drafting, summaries and call briefsUnited States
OpenAICall transcriptionUnited States
ExotelTelephony, call recording and caller IDIndia
RazorpaySubscription billing and wallet paymentsIndia
ResendTransactional email (invites, alerts)United States and European Union

9. Cookies and analytics

We use strictly necessary cookies to keep you signed in and, if enabled, a first-party analytics cookie (PostHog) to understand product usage. We do not use advertising cookies and we do not sell personal data. You can block analytics cookies in your browser without affecting the service.

10. Children

Agent27 is a business tool and is not directed at anyone under 18. We do not knowingly collect personal data of children. If you believe a child’s data has been entered into the service, write to us and we will remove it.

11. Changes to this policy

We will post any changes on this page and, for material changes, email workspace owners at least 15 days before they take effect. The date at the top tells you when the policy was last revised.

12. Contact

Grievance Officer, Agent27. Email privacy@agent27.app or write via our contact page. We acknowledge every request within 72 hours.

See also our Terms of Service.