Privacy Policy
Last updated: March 1, 2026 | DPDP Act 2023 (Digital Personal Data Protection Act) Compliant
1. Data Controller Information
SwanDigitals ("SwanDigitals", "we", "us", or "our") is the data controller responsible for your personal data. We are committed to protecting your privacy in accordance with applicable data protection laws including the Digital Personal Data Protection Act (DPDP), 2023.
Data Controller: SwanDigitals
Address: B31 Flat, Aaykar Society, Kothrud, Pune, Maharashtra 411038, India
Contact Number: +91 7770070762
Email: Support Team
Leadership: Swati Gaikwad & Kiran Shelke
2. Data We Collect
We collect the following categories of personal data:
2.1 Data You Provide Directly
- Account Data: Name, email address, company name, job title, phone number
- Billing Data: Payment information (processed by Razorpay, a PCI DSS Level 1 compliant processor)
- Content Data: Chatbot configurations, conversation flows, training data you create
- Communication Data: Support requests, feedback, correspondence with us
2.2 Data Collected Automatically
- Usage Data: Features accessed, API calls, session duration, interaction patterns
- Technical Data: IP address, browser type, operating system, device identifiers
- Cookies: Session cookies, analytics cookies (see our Cookie Policy)
2.3 End-User Conversation Data
When your customers interact with chatbots you create using our platform, we process conversation data as a Data Processor on your behalf, hosted on our India-based cloud infrastructure.
2.4 Third-Party Authentication & Google OAuth
When you choose to log in or register for the SwanDigitals platform using Google Authentication (OAuth), we request and access certain information from your Google account. This access is strictly limited to what is absolutely necessary for account authentication and provisioning.
- What we access: Your email address and basic profile information (name and profile picture).
- How we use it: This restricted data is used exclusively to verify your identity, securely create or link your SwanDigitals account, and pre-fill your basic profile details within our dashboard.
- What we DO NOT do: We do not access your Google Drive, Gmail, Calendar, Contacts, or any other sensitive scopes. We do not sell your Google data, nor do we use it for advertising purposes. Your Google data is subject to the same strict enterprise data protection and sovereignty standards as all other Customer Data described in this policy.
You can revoke SwanDigitals's access to your Google account at any time via your Google Account Security settings.
3. Legal Basis for Processing (DPDP Act 2023)
| Purpose | Legal Basis |
|---|---|
| Providing the Service | Contract performance |
| Processing payments | Contract performance |
| Customer support | Legitimate interest |
| Service improvements | Legitimate interest |
| Marketing communications | Consent |
| Legal compliance | Legal obligation |
4. Your Rights Under DPDP Act 2023
As a data principal under Indian law, you have the following rights:
Right of Access
Request a copy of your personal data
Right to Correction
Correct inaccurate personal data
Right to Erasure
Request deletion of your data
Right to Grievance Redressal
Contact us to resolve data concerns
Right to Data Portability
Receive your data in machine-readable format
Right to Nominate
Nominate a person to exercise rights on your behalf
Right to Withdraw Consent
Withdraw consent at any time
Right to Lodge Complaint
File complaint with supervisory authority
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
5. Data Transfers
For cloud deployments, your data may be processed within India or in countries with adequate data protection standards. We ensure adequate protection through appropriate contractual safeguards.
- India Data Residency: All data stored in Indian data centers by default
- Third-party processors: Subject to equivalent data protection obligations
India-Hosted by Default: All customer data is processed and stored on cloud infrastructure within India.
6. Data Security
We implement appropriate technical and organizational measures:
- Encryption: Data encrypted at rest and in transit
- Access Controls: Restricted internal access to customer data
- Auditing: Internal logging and periodic security reviews
- Incident Response: Breach notification as required under DPDP Act 2023
7. Data Retention
- Account Data: Retained while account is active + 30 days after deletion
- Billing Data: Retained for 7 years (legal tax requirements)
- Conversation Logs: Configurable retention (default: 90 days)
- Usage Analytics: Anonymized after 24 months
8. Sub-Processors
We use the following sub-processors:
| Sub-Processor | Purpose | Location |
|---|---|---|
| AWS (Amazon) | Cloud infrastructure | India (Mumbai) |
| Razorpay | Payment processing | India |
| Google Analytics | Website analytics | India |
9. Contact Information
Supervisory Authority
Ministry of Electronics and Information Technology (MEITY), Government of India
