Privacy Policy
Datasirpi Pvt. Ltd. ("Datasirpi", "we", "us", or "our") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, use our services, or interact with us.
1. Scope
This Privacy Policy applies to all information collected by Datasirpi through our website (datasirpi.com), mobile applications, services, and any other digital platforms we operate. This policy covers:
- Personal information collected directly from users
- Information collected automatically through our digital platforms
- Information received from third-party sources
- Data processed in connection with our services
2. Information We Collect
2.1 Personal Information
We may collect the following types of personal information:
- Contact Information: Name, email address, phone number, mailing address
- Professional Information: Company name, job title, industry, business requirements
- Account Information: Username, password, preferences, and account settings
- Communication Data: Messages, feedback, and correspondence with us
2.2 Technical Information
We automatically collect certain technical information, including:
- IP address and location data
- Browser type and version
- Device information and operating system
- Website usage patterns and analytics
- Cookies and similar tracking technologies
3. How We Use Information
We use your information for the following purposes:
- Service Delivery: To provide, maintain, and improve our services
- Communication: To respond to inquiries and provide customer support
- Business Operations: To process transactions and manage accounts
- Marketing: To send relevant updates and promotional materials (with consent)
- Analytics: To understand usage patterns and improve user experience
- Legal Compliance: To comply with applicable laws and regulations
4. Messaging Services
This section describes how we handle information obtained from the messaging platforms our customers connect to EnvoySirpi, DataSirpi's conversational messaging platform. It applies in addition to, and takes precedence over, the general provisions above for that data.
4.1 WhatsApp
Messaging services (WhatsApp): For customers who connect a WhatsApp Business number, we process the messages and metadata on that number solely to send and receive messages on the customer's behalf. Connection credentials are encrypted at rest, inbound messages are verified before processing, and this data is never used for advertising or sold. A customer can disconnect a number at any time, which deletes its stored credentials immediately.
4.2 Microsoft Teams
Messaging services (Microsoft Teams): For customers who connect a Microsoft 365 organisation, we use the information obtained from Microsoft — Teams messages in the conversations the assistant takes part in, and directory details (such as a colleague's name and email) needed to reach them — only to send and receive those messages on the customer's behalf. Connection credentials are encrypted at rest, and this data is never used for advertising or sold. A customer can disconnect their organisation at any time, which deletes its stored credentials immediately.
4.3 Applies to every connected channel
- Isolation: Each customer's data is isolated from every other customer's.
- Encryption: Stored securely with encryption, in line with our ISO 27001 certification.
- No advertising, no sale: Data obtained from a connected messaging platform is never used for advertising and is never sold.
- Purpose limitation: It is used only to send and receive messages on the customer's behalf and to show them their connection's status.
- Disconnection: Disconnecting a channel deletes its stored credentials immediately.
- Recipient consent: Our customers may only message people who have given their business prior opt-in consent, and must honour opt-out requests promptly. This is required by section 4 of our Terms of Service.
5. Data Storage, Retention, and Deletion
5.1 Data Storage
Your data is stored on secure servers located in data centers that comply with industry standards. We use cloud infrastructure providers that maintain appropriate security certifications.
5.2 Data Retention
We retain your personal information for as long as necessary to:
- Fulfill the purposes outlined in this policy
- Comply with legal obligations
- Resolve disputes and enforce agreements
5.3 Data Deletion
You may request deletion of your personal information at any time. We will delete your data within 30 days of your request, unless retention is required by law.
6. Data Security
We implement comprehensive security measures to protect your information:
- Encryption: Data is encrypted in transit and at rest using industry-standard protocols
- Access Controls: Strict access controls and authentication mechanisms
- Regular Audits: Periodic security assessments and vulnerability testing
- Employee Training: Regular security awareness training for all staff
- ISO 27001 Certification: We maintain ISO 27001 certification for information security
7. Data Sharing and Disclosure
We may share your information in the following circumstances:
- Service Providers: With trusted third-party vendors who assist in our operations
- Business Partners: With partners when necessary to provide requested services
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with mergers, acquisitions, or asset sales
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
8. User Rights and Choices
You have the following rights regarding your personal information:
- Access: Request access to your personal information
- Correction: Request correction of inaccurate information
- Deletion: Request deletion of your personal information
- Portability: Request transfer of your data to another service
- Opt-out: Unsubscribe from marketing communications
- Restriction: Request restriction of processing in certain circumstances
To exercise these rights, please contact us using the information provided below.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. We ensure that such transfers comply with applicable data protection laws and implement appropriate safeguards to protect your information.
10. Children's Privacy
Our services are not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected such information, we will take steps to delete it promptly.
11. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website and updating the "Last Updated" date.
12. Contact Information
If you have any questions about this Privacy Policy or our data practices, please contact us:
Datasirpi Pvt. Ltd.
Email: hr@datasirpi.com
Website: www.datasirpi.com
