Legal

Privacy Policy

Last updated: August 2026

Draft — pending legal review. This page was generated to describe, as accurately as we could, how LIRA Voice actually collects and uses data today. It is not final legal advice and has not yet been reviewed by a lawyer qualified in your jurisdiction. Please don't treat it as a binding legal document until that review is complete.

This policy explains what personal data LIRA Voice Technologies Pvt. Ltd. ("LIRA Voice", "we", "us") collects through the Lira Voice Agent platform, why, and what rights you have over it — under the EU General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act 2023 (DPDP), and the California Consumer Privacy Act / CPRA, where each applies.

Who this applies to

Two different groups of people have data processed by this platform, and this policy covers both:

  • Account holders — people who sign up for a LIRA Voice account to build and manage AI voice/chat agents.
  • Callers and message senders — the end customers of our account holders' businesses, who talk to a LIRA Voice AI agent over a phone call, web chat, or WhatsApp. Their conversation data is processed on behalf of, and under the direction of, the account holder's business (we act as a data processor for this data, not the controller).

What we collect

From account holders: name, email address, phone number (optional), a securely hashed password (we never store your actual password), company name, and account activity (agents created, tokens used, billing history).

From callers and message senders: phone number or contact identifier, the content of the conversation (voice transcript, chat messages, or WhatsApp messages), and any details volunteered during the conversation itself (for example, a name, city, or educational background, if the specific agent is configured to ask for it). Voice calls are transcribed; audio may be temporarily processed to generate that transcript.

Automatically: basic technical data needed to operate the site (IP-adjacent request metadata, browser type). If you consent to analytics cookies via our cookie banner, Google Analytics collects anonymized usage statistics — see our Cookie Policy for detail.

Why we process this data

  • To provide the service — operating your account, running your AI agents, routing calls/messages, generating billing records. (Legal basis: performance of a contract with you.)
  • To improve the product and keep it secure — debugging, fraud/abuse prevention, service reliability. (Legal basis: legitimate interest.)
  • Analytics — only after you actively consent via the cookie banner. (Legal basis: consent, withdrawable at any time.)

Who we share data with

We use third-party service providers to actually deliver the product — each only receives the data it needs to perform its specific function, under its own terms of service:

  • Telephony providers (e.g. Exotel, Twilio, Plivo, Vonage, Tata SmartFlo) — to place and receive phone calls.
  • Messaging providers (e.g. MSG91) — to send and receive WhatsApp messages and SMS/OTP codes.
  • AI model providers — to generate agent responses. This may include self-hosted models we operate ourselves, and Anthropic's Claude API as a fallback when our own infrastructure is unavailable.
  • Email delivery — for account verification, password resets, and transactional notifications.
  • Google Analytics — only if you've consented to analytics cookies.
  • Cloud hosting infrastructure — to run the application and store data.

Some of these providers may process data outside your country, including outside the EU/EEA or India. Where that happens, we rely on the safeguards those providers themselves offer (such as standard contractual clauses) — we have not yet completed a full data-transfer-impact assessment for every sub-processor, and are flagging that honestly rather than claiming otherwise.

We do not sell personal data, and do not share it for third-party advertising.

How long we keep it

We currently retain account and conversation data for as long as your account is active, so agents can reference conversation history and you can review past activity. We do not yet have an automated data-retention schedule that purges old records on a fixed timeline — this is a known gap we intend to close. You can request deletion at any time; see "Your rights" below.

Your rights

Depending on where you're located, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your data ("right to erasure" / "right to be forgotten")
  • Export your data in a portable format
  • Object to or restrict certain processing
  • Withdraw consent for anything based on consent (e.g. analytics cookies), at any time
  • Opt out of sale/sharing of personal information (California residents — though as noted above, we don't sell data)

If you have an account, you can download your account data or request deletion directly from Settings → Privacy. If you're a caller or message sender who spoke with one of our customers' AI agents and want to exercise these rights, contact that business directly, or email us at hello@aiveda.io and we'll route your request appropriately.

Security

Passwords are hashed with bcrypt and never stored in plain text. Access to the platform is gated behind authenticated sessions. We use industry-standard encryption for data in transit. As with any software company, no system is perfectly secure, and we're continuing to invest in this over time — see our note on security-audit readiness for where we currently stand.

Children's privacy

This platform is intended for business use and is not directed at children. We do not knowingly collect personal data from children.

Changes to this policy

We'll update the "Last updated" date above when this policy changes, and post material changes on this page.

Contact us

Questions about this policy or your data: hello@aiveda.io