Skip to content
Saudaflow

AI voice agent — in development. See how it works →

Get a demo
Pricing
Sign inDownload the Android app

Saudaflow is sold through a short call — we set up your workspace, your projects and your team with you. No card, no self-serve signup.

Legal

Privacy policy

SaudaFlow is built and operated by AB Corp in Mumbai, India. This policy explains what personal data we handle, in which capacity, why, for how long, and the rights you hold under India's Digital Personal Data Protection Act 2023.

Effective 5 August 2026 · AB Corp, Mumbai, India · support@saudaflow.in

1. Two roles, two datasets

We process personal data in two distinct capacities, and your rights route differently depending on which dataset your data sits in:

  • As a Data Fiduciary — for data about our own customers and site visitors: account names, work emails, phone numbers, company details, GSTIN, billing records, support conversations, and technical logs. We decide the purposes here, and this policy governs directly.
  • As a Data Processor — for the CRM data our customers (agencies, builders, and their firms — each a “tenant”) store in SaudaFlow: leads, buyers, enquiries, site visits, documents, call logs. The tenant is the Data Fiduciary for that data; we process it only on the tenant’s instructions under our Data Processing Agreement. If your data was captured by a SaudaFlow tenant, that tenant is your first point of contact for rights requests, and we assist them in honouring you.

2. What we collect, and why

As a Fiduciary we collect only what the relationship needs:

  • Account and billing data — name, work email, mobile number, firm name, GSTIN and billing address: to create your workspace, issue GST-correct invoices and meet our obligations under Indian tax law.
  • Support and communication data — messages you send us, and records of the help we provide: to resolve your issues and improve the product.
  • Technical data — IP addresses, device and browser metadata, request logs: to secure the service, prevent abuse, and diagnose faults.

Lawful basis: your consent when your workspace is created, and the legitimate uses recognised by Section 7 of the DPDP Act (including voluntary provision for a specified purpose, and compliance with law). We do not sell personal data, and we do not use tenant CRM data for advertising — ours or anyone else’s.

3. Where your data lives

Tenant CRM data is stored and processed on infrastructure in the Mumbai region — compute on Mumbai-hosted servers, cold storage in a Mumbai object-storage bucket. Tenant CRM data does not leave India except where a tenant explicitly enables an integration that sends specific data elsewhere (for example, WhatsApp messaging via Meta), in which case the transfer happens on the tenant’s instruction and is described at the point of enabling it.

4. How we protect it

  • Encryption at rest for tenant records, with tenant-derived key material, and TLS 1.2+ in transit.
  • Per-tenant isolation enforced with Postgres row-level security: one tenant can never read another tenant’s rows.
  • Audited staff access. SaudaFlow staff have no standing access to tenant data. Where access is required — a support request you raise, a legal obligation, or an incident — every such access is recorded in an append-only audit log that is visible to the tenant. We do not claim our staff are cryptographically incapable of access; we commit to the stronger operational claim we can prove: every access is logged, attributable, and disclosed to you.
  • Encrypted backups on a fixed schedule, stored in the Mumbai region.
  • Reasonable security practices and procedures as required by Section 43A of the Information Technology Act 2000 and the DPDP Act’s security-safeguard obligations.

5. Who we share with

  • Infrastructure sub-processors in the Mumbai region (hosting and object storage) — listed in the DPA.
  • Razorpay, for subscription payments. Card and bank credentials go to Razorpay directly; we never store them.
  • Integration providers a tenant chooses to connect (WhatsApp Business via Meta, Google Workspace, property portals). Data flows to them only when, and only as far as, the tenant instructs.
  • Government authorities, where Indian law requires disclosure and the demand is valid. We disclose the minimum required and, where the law permits, we notify the affected tenant.

6. How long we keep it

We retain personal data no longer than the purpose requires, subject to the retention floors Indian law imposes. We deliberately do not promise immediate deletion, because the law does not permit it in every case:

  • Account and tenant data: for the life of the subscription, then deleted after the post-termination export window described in the Terms.
  • Personal data and associated traffic logs subject to the DPDP Rules: retained for at least one year where Rule 8(3) requires it, then erased.
  • Invoices and billing records: retained for the periods prescribed by GST law and the Companies Act (typically 8 years).
  • Audit logs of data access: retained so the access trail outlives the access — this is a safeguard for you, not a marketing dataset.
  • Erasure requests are honoured within the rights SLA in Section 7, minus only the records a statute obliges us to keep, which we then hold solely for that purpose.

7. Your rights as a Data Principal

The DPDP Act 2023 gives you the rights to access, correction, erasure, nomination, and grievance redressal. Exercise them at app.saudaflow.in/privacy/my-data if you hold a SaudaFlow account, or through the Grievance Officer below. Where a SaudaFlow tenant is the Fiduciary for your data, we route your request to them and assist their response.

We acknowledge every request promptly and fulfil verified requests within 90 days of receipt, in line with the timelines contemplated by the DPDP Rules. Most requests complete much faster. See Your DPDP rights for the full mechanics.

8. Grievance Officer

Grievance Officer, AB Corp — Mumbai, Maharashtra, India. Email: support@saudaflow.in (subject line “Grievance”). If you are dissatisfied with our response, you may complain to the Data Protection Board of India.

9. Children

SaudaFlow is a business tool and is not directed at persons under 18. We do not knowingly process children’s personal data as a Fiduciary, and tenants agree not to upload it.

10. Breach notification

In the event of a personal data breach we notify the Data Protection Board of India and affected Data Principals in the form and timeline the DPDP Act and its Rules prescribe, and we notify affected tenants without undue delay so they can meet their own obligations.

11. Changes to this policy

We will post changes here with a new effective date. For material changes we notify account holders by email before the change takes effect.

Draft — under legal review. Questions or corrections: support@saudaflow.in. See also Privacy · Terms · Acceptable use · DPA · Your DPDP rights.

Privacy policy under the DPDP Act 2023 · Saudaflow