In plain language
A quick orientation. The numbered sections below are the binding text.
- Zoft.AI Private Limited (Chennai, India) runs this website and the Zoft platform. We are the controller for your account and for anything you send us directly, and a processor for the data your agents handle on behalf of your business.
- The marketing site sets no advertising or analytics cookies. Product analytics run in cookieless mode on an EU-hosted instance, and the only browser storage we use is your light/dark theme choice.
- Inside the platform we store what your agents need to run: call recordings and transcripts, chat messages, workflow run records, and the credentials for the tools you connect. Credentials are encrypted before they are written to disk.
- We never train or fine-tune AI models on your data, and we contract with model providers on terms that prohibit them from doing so.
- Production data is hosted on Amazon Web Services in the United States. Transfers out of the EEA, UK and India are covered by the safeguards in Section 8.
- You can access, correct, export or delete your data, or object to how we use it, by writing to privacy@zoft.ai. We respond within 30 days.
1. Who we are and what this policy covers
This Privacy Policy is issued by Zoft.AI Private Limited, a company incorporated under the Companies Act, 2013 with its registered office in Chennai, Tamil Nadu, India ("Zoft", "we", "us"). It explains how we handle personal data when you:
- visit our website at www.zoft.ai (the "Site"), including when you join the waitlist or contact sales;
- create an account and use the Zoft platform at app.flow.zoft.ai and its API at api.flow.zoft.ai (the "Platform"), including Copilot, Spaces, Desk, workflows, multi-agent crews, voice agents, chat agents and browser agents;
- interact with a voice agent, chat agent, or automated workflow that one of our customers has built and deployed with Zoft (an "End-User");
- communicate with us by email, in a sales conversation, or at an event.
It does not cover websites, applications or services operated by third parties, including the systems a customer connects to Zoft (for example their CRM, help desk, calendar or telephony provider). Those are governed by their own policies.
Our two roles
- Zoft as controller
- For data about Site visitors, prospects, account holders and the people who administer a workspace, we decide why and how personal data is processed. Sections 3–5 describe this in full.
- Zoft as processor (service provider)
- For data that flows through agents and workflows our customers build — callers, chat users, customers' customers, records pulled from connected systems — we act only on the customer's documented instructions. The customer is the controller. Our obligations to them are set out in the Data Processing Addendum. If you are an End-User, the business you dealt with is your first point of contact; we will help them respond to you.
2. Definitions
- Personal data
- Any information relating to an identified or identifiable natural person. It has the same meaning as "personal data" under the Digital Personal Data Protection Act, 2023 (India) and the GDPR, and "personal information" under the CCPA.
- Customer
- The business or individual that holds a Zoft account and agrees to our Terms of Service.
- Customer Content
- Everything a Customer uploads, connects, generates or receives through the Platform: prompts, knowledge documents, agent configurations, connected-app credentials, call recordings and transcripts, chat messages, tool inputs and outputs, and workflow run records.
- End-User
- A person who interacts with an agent or workflow that a Customer runs on Zoft, or whose data a Customer's workflow processes.
- Sub-processor
- A third party we engage to process Customer Content on our behalf. The current list is published at /legal/subprocessors.
3. Personal data we collect
3.1 Data you give us on the Site
| Where | Fields | Why we ask |
|---|---|---|
| Waitlist | Full name, work email, company, role, and an optional tick box for product updates | To place you on the private-beta waitlist and tell you when access opens |
| Contact sales | Full name, work email, company, role, phone (optional), company size, area of interest, how you heard about us, your message, and a required consent tick box | To answer your enquiry and scope a fit |
| Zoft chat widget | The messages you type into the chat bubble on the Site, which is itself a Zoft chat agent | To answer questions about the product in real time |
Form submissions are delivered into our own Zoft workspace through a workflow webhook and onward to the CRM and inbox our team uses. Each submission also records the page you sent it from and your browser's user-agent string so we can spot spam. Your IP address is used transiently to rate-limit the form and is not stored with your submission.
3.2 Data collected automatically on the Site
- Product analytics. We use PostHog in cookieless mode: no cookie or persistent identifier is set, and events are keyed to an anonymous, per-session value that is not linked across visits. Events include page views, section visibility, scroll depth, CTA clicks and form outcomes (success or failure, never the field values). Requests are proxied through our own domain and stored on PostHog's EU (Frankfurt) instance.
- Server logs. Our hosting provider keeps standard request logs (IP address, user agent, URL, timestamp, response code) for security and debugging. These are retained for no longer than 30 days.
- Browser storage.
localStorageholds your light/dark theme preference.sessionStoragebriefly holds the email address you type into the inline waitlist field so it can be pre-filled on the next page; it is cleared when you close the tab. Neither is sent to us.
3.3 Account and workspace data on the Platform
- Identity: name, work email, hashed password or, if you sign in with Google, the identifier and email Google returns, two-factor authentication secrets, profile picture if you add one.
- Workspace: organisation name, team members and their roles and permissions, invitations, audit-log entries recording who changed what and when.
- Billing (when paid plans are enabled): plan, invoices, billing address, GSTIN or other tax identifiers, and payment status. Card and bank details are handled by Razorpay and never touch our servers.
- Support and communications: emails, tickets, meeting notes, and feedback you send us.
- Usage telemetry: which features are used, application error logs scrubbed of Customer Content, performance metrics, and the minutes, messages and tokens consumed for metering.
3.4 Customer Content processed on your instructions
| Product | What it typically contains |
|---|---|
| Copilot & workflows | Your plain-language briefs, the agents, tools and workflows generated from them, and every run record: inputs, outputs, tool calls, retries, approvals and errors. |
| Voice agents | Caller and callee phone numbers, call metadata, audio recordings (if you enable recording), real-time and post-call transcripts, extracted fields, and any actions taken (bookings, tickets, transfers). |
| Chat agents | Conversation transcripts on your website, in-app, or the messaging channels you connect, sender identifiers on those channels, uploaded files, and hand-off notes to your team. |
| Browser agents | The URLs visited, page content read, form fields filled, screenshots and session recordings captured while completing a task, and the credentials you supply for sites the agent signs into. |
| Spaces & Desk | Task boards, human-in-the-loop approval queues, comments, and the records synced from systems you connect. |
| Connected apps & knowledge | OAuth tokens and API keys for the tools you connect (for example Slack, Gmail, Google Calendar, Calendly, Stripe, your own Twilio or model-provider account), documents you upload for retrieval, and the data your agents read from or write to those tools. |
4. How and why we use personal data
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the Platform | Account, workspace, Customer Content | Performance of a contract (Terms of Service); processor instructions for Customer Content |
| Respond to enquiries and waitlist requests | Site form data | Consent; legitimate interest in responding to people who contact us |
| Send product updates | Email, name | Consent (opt-in tick box), withdrawable at any time via the unsubscribe link |
| Secure the service | Logs, telemetry, audit log, IP for rate limiting | Legitimate interest in preventing abuse, fraud and outages; legal obligation |
| Improve the product | Aggregated usage telemetry, anonymised analytics | Legitimate interest. Never uses Customer Content or trains models (see 4.2) |
| Bill and collect | Billing data, metering | Contract; legal obligation (tax, accounting) |
| Comply with law | Whatever is required | Legal obligation; establishment or defence of legal claims |
4.2 AI models and your data
- We do not use Customer Content or End-User data to train, fine-tune, or otherwise improve any machine-learning model, whether ours or a third party's.
- Prompts and completions are sent to the model providers you select (currently OpenAI, Anthropic and Google) under API terms that prohibit training on your data.
- Live-call voice processing (Ultravox), text-to-speech (ElevenLabs, Cartesia, Fish Audio, Sarvam AI) and telephony (Twilio) providers receive audio only as needed to run the call. They act as our sub-processors under written contracts.
- Human review by Zoft staff of Customer Content happens only when you ask us for support, when required to investigate abuse or a security incident, or when the law requires it. Access is logged.
4.3 Automated decision-making
Zoft agents can make or recommend decisions (route a call, approve a refund, book a slot). The Customer configures those decisions and remains responsible for them, including any human-review or explanation rights End-Users have under applicable law. The Platform provides permissions, human-approval gates and run records so Customers can meet those obligations. Zoft does not itself make automated decisions with legal or similarly significant effects about Site visitors or account holders.
7. How long we keep data
We keep personal data only as long as needed for the purpose it was collected, then delete or irreversibly anonymise it. Defaults are below; Customers on the Platform can shorten retention of Customer Content in their workspace settings or by instruction to us.
| Data | Retention |
|---|---|
| Waitlist and contact-sales submissions | 24 months from last contact, or until you ask us to delete them |
| Product-update subscription | Until you unsubscribe |
| Site analytics events | 12 months, anonymous throughout |
| Hosting request logs | 30 days |
| Account and workspace data | Life of the account, then deleted within 30 days of closure |
| Customer Content (recordings, transcripts, run records, connected-app data) | Life of the subscription or as configured by the Customer, then deleted within 30 days of termination. Customers may export first (Terms §12). |
| Connected-app credentials | Deleted immediately when you disconnect the app or close the account |
| Audit log | Life of the workspace plus 12 months, to support investigations |
| Billing records and invoices | 8 years, as required by Indian tax and company law |
| Encrypted backups | Rolling; a deleted record leaves all backups within 35 days |
8. Where data is stored and international transfers
Our production infrastructure runs on Amazon Web Services in the United States (us-east-1). Site analytics are stored in the European Union. Our team is based in India and accesses production systems from there under role-based access controls.
- From India. Transfers are made in accordance with the Digital Personal Data Protection Act, 2023, which permits transfer to any country not restricted by the Central Government.
- From the EEA, UK and Switzerland. We rely on the European Commission's Standard Contractual Clauses (Module 2 and Module 3, as applicable), the UK International Data Transfer Addendum and the Swiss FDPIC amendments, supplemented by encryption in transit and at rest and the assessments described in our DPA. Copies are available on request.
- From other jurisdictions. We apply the same contractual safeguards and comply with any local transfer requirements that apply to us.
Enterprise Customers who require a specific hosting region can contact sales to discuss availability.
9. How we protect data
- Encryption. TLS 1.2+ for all traffic. Databases, object storage and backups are encrypted at rest. Connected-app credentials and API keys are additionally encrypted at the application layer before they are written, with keys held separately from the data.
- Access control. Role-based access control and per-workspace isolation in the Platform; least-privilege, two-factor-protected access for Zoft staff; production access is logged and reviewed.
- Agent guardrails. Permissions on every tool, human-approval gates, run records and evaluations so that Customers can see and constrain what an agent may do before it goes live.
- Operational security. Isolated execution environments for workflows and browser agents, dependency and secret scanning, monitoring and alerting, and tested backup and restore.
- Vulnerability disclosure. Report security issues to security@zoft.ai. We acknowledge within two business days and will not pursue good-faith researchers who respect user privacy and give us reasonable time to fix.
No system is perfectly secure. If a personal-data breach occurs we will notify affected Customers without undue delay and in any case within 48 hours of confirming it, with enough detail for them to meet their own notification duties, and we will notify the Data Protection Board of India and any other regulator as the law requires.
10. Your rights and how to exercise them
Depending on where you live you have some or all of the rights below. We honour them for everyone, regardless of location, wherever it is practical to do so.
- Access a copy of the personal data we hold about you and a summary of how it is processed.
- Correct inaccurate or incomplete data.
- Delete your data, subject to legal retention duties.
- Port your data in a structured, machine-readable format.
- Withdraw consent at any time where consent is the legal basis, without affecting processing already carried out.
- Object to or restrict processing based on legitimate interests.
- Nominate another person to exercise your rights if you die or become incapacitated (DPDP s.14).
- Not be discriminated against for exercising any of these rights.
10.1 India (DPDP Act, 2023)
Zoft.AI Private Limited is a Data Fiduciary for Site and account data. Consent requests are presented in clear, plain language and can be withdrawn as easily as they were given. Our Grievance Officer can be reached at privacy@zoft.ai; we respond to grievances within 30 days. If you are not satisfied you may approach the Data Protection Board of India.
10.2 European Economic Area, United Kingdom and Switzerland
You have the rights in Articles 15–22 GDPR (and UK GDPR equivalents). We respond within one month, extendable by two months for complex requests. You may lodge a complaint with your local supervisory authority; a list is at edpb.europa.eu. We have not appointed an EU or UK representative under Article 27 because we do not currently offer the Platform to EU/UK consumers on a large scale; if that changes we will update this section.
10.3 California and other US states
California residents have the rights to know, delete, correct and opt out of sale or sharing under the CCPA/CPRA, and residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon and other states with comprehensive privacy laws have comparable rights. We do not sell or share personal information as those terms are defined, and we do not use sensitive personal information other than to provide the service. We do not knowingly collect data from consumers under 16. In the preceding 12 months we have collected the categories listed in Section 3 for the purposes in Section 4 and disclosed them to the service providers in Section 5. You may use an authorised agent; we will verify the request.
10.4 If you are an End-User of a Zoft customer
Direct your request to the business you interacted with; they control your data and decide how to respond. If you contact us instead, we will pass your request to them within five business days and assist them. Where you cannot identify the business, write to privacy@zoft.ai with the phone number, channel and approximate time of the interaction and we will help.
10.5 How to make a request
Email privacy@zoft.ai from the address associated with your account or submission, or use the privacy controls in your Platform account settings. We may ask for information to verify your identity; we will not ask for more than we need. Requests are free unless they are manifestly unfounded or excessive. We respond within 30 days.
11. Recording, telephony and messaging obligations
Voice and chat agents are subject to laws that apply to the Customer deploying them, not only to Zoft. If you deploy agents you are responsible for:
- disclosing at the start of a call or chat that the End-User is speaking with an automated system, where the law requires it (for example California's bot-disclosure law, the EU AI Act's transparency duty, and TRAI regulations in India);
- obtaining any consent required to record a call, including two-party consent in jurisdictions that require it, and configuring the agent to announce recording;
- complying with telemarketing and anti-spam rules such as the TCPA and the National Do Not Call Registry in the United States, the TRAI Do Not Disturb registry and TCCCPR 2018 in India, PECR in the UK, and the messaging policies of any channel you connect;
- honouring an End-User's request to speak to a human, which the Platform supports through built-in hand-off.
The Platform lets you configure disclosures, recording announcements, consent capture and hand-off rules. Zoft does not initiate calls or messages except on a Customer's instruction.
12. Children
The Site and Platform are for businesses and are not directed to children. We do not knowingly collect personal data from anyone under 18 (or the age of majority where they live). Customers must not deploy agents that knowingly target children without the verifiable parental consent that DPDP s.9, COPPA or equivalent laws require. If you believe a child has provided us with personal data, contact us and we will delete it.
13. Changes to this policy
We will update this policy when our practices change or the law requires it. The effective date and version at the top will change, and the previous version is available on request. For material changes that reduce your rights we will give account holders at least 30 days' notice by email or in-product notice before they take effect. Continuing to use the Site or Platform after the effective date means the updated policy applies.
14. Contact us
- Data controller / Data Fiduciary
- Zoft.AI Private Limited, Chennai, Tamil Nadu, India
- Grievance Officer and privacy requests
- privacy@zoft.ai
- Security reports
- security@zoft.ai
- Legal notices
- legal@zoft.ai
This policy should be read with our Terms of Service, Data Processing Addendum and Sub-processor list.