Skip to main content
hiveCell
Privacy Terms Disclaimer
Back to site

Legal

Privacy Policy

hiveCell Technologies Pvt. Ltd. · Last updated 8 September 2026

On this page

  1. Who we are
  2. Two kinds of people, two roles
  3. What we collect
  4. How we use it
  5. Lawful basis and consent
  6. Who we share it with
  7. Where data is stored and international transfers
  8. How long we keep it
  9. How we protect it
  10. Your rights
  11. Cookies and analytics
  12. Children
  13. Changes to this Policy
  14. Grievance Officer and contact

1. Who we are

This Privacy Policy explains how hiveCell Technologies Pvt. Ltd. (“hiveCell”, “we”, “us”) collects, uses, shares and protects personal data when you visit hivecell.ai (the “Website”), contact us, or use the hiveCell omnichannel AI customer-service platform (the “Service”).

hiveCell Technologies Pvt. Ltd. is a company incorporated in India with its registered office at [Registered office address], [City] (CIN [CIN]). For the purposes of the Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the Information Technology Act, 2000 and rules thereunder, we act as a Data Fiduciary for data about Website visitors, prospective customers and our business customers’ staff, and as a Data Processor when we process end-customer data on behalf of a business customer.

2. Two kinds of people, two roles

Website visitors, prospects and business-customer users. If you browse the Website, book a meeting, email us, or administer a hiveCell account for your employer, we decide why and how your data is processed and this Policy applies to you directly.

End customers of our business customers. If you are a consumer who has messaged, emailed or called a business that uses hiveCell, that business is the Data Fiduciary. It decides what the AI agent may do, what it may remember and for how long. We process your data only on that business’s documented instructions, under a written agreement. Requests about that data should go to the business you contacted; we will help them respond.

3. What we collect

From Website visitors and prospects:

  • Contact details you give us when you book a meeting or write to us — name, work email, company, role, phone number, and anything you choose to tell us about your support operation.
  • Technical data — IP address, browser and device type, pages viewed, referring page, approximate location derived from IP, collected through server logs and any analytics tool we enable (see Cookies below).
  • Meeting scheduling data handled by our scheduling provider when you pick a time.

From business-customer users (your staff administering the Service):

  • Account data — name, work email, role, authentication details, and activity logs within the Service (configuration changes, approvals, reviews).
  • Support and billing correspondence.

On behalf of business customers (end-customer data we process as a Data Processor):

  • Conversation content across the channels the business connects — email, WhatsApp, voice (including call recordings and transcripts), web chat and Instagram.
  • Facts the AI agent extracts to a customer’s memory profile (for example city, order history, preferred channel, language, verification status) — the categories are chosen and controlled by the business.
  • Records drawn from the business’s systems the agent is permitted to read or act on (orders, deliveries, subscriptions, appointments, account details).
  • Verification signals such as one-time codes or known-value checks used before sensitive actions.
  • Historical conversations (typically the last 30 days) used, with the business’s permission, to configure the agent before go-live.

4. How we use it

As Data Fiduciary, we use your data to respond to enquiries, run the meeting you booked, operate and secure the Website, send information you asked for, administer accounts, invoice, comply with law, and improve the Website. We send marketing emails only where you have agreed or where permitted by law, and every such email contains an unsubscribe link.

As Data Processor, we use end-customer data solely to provide the Service to the business customer: to understand and answer conversations, to take the actions the business has authorised, to keep the customer’s memory profile so they need not repeat themselves, to hand off to a human with context, to log every action for audit, and to evaluate new agent versions against past cases before release. We do not use one business’s end-customer data to train models for other customers, and we do not sell personal data.

5. Lawful basis and consent

Under the DPDP Act we process personal data either with your consent or for certain legitimate uses permitted by the Act, such as where you voluntarily provide data for a specified purpose, to comply with law, or to respond to a request you make. Where we rely on consent you may withdraw it at any time; withdrawing consent does not affect processing already carried out. Businesses using the Service are responsible for giving their end customers the notices and obtaining any consents the law requires for the channels and actions they enable.

6. Who we share it with

We share personal data only with parties who help us provide the Website and the Service, under contracts that restrict their use of the data:

  • Cloud hosting and storage providers.
  • Large-language-model and speech providers that process conversation content to generate responses and transcripts, configured not to retain or train on that content where such settings are available.
  • Telephony, messaging and email delivery providers (for example the WhatsApp Business Platform, voice carriers and SMS gateways) needed to send and receive on the channels a business connects.
  • Scheduling, CRM, analytics, support and payment tools we use to run our own business.
  • Professional advisers, auditors and insurers.
  • Regulators, courts and law enforcement where the law requires, or to protect our rights, our customers or the public.
  • A successor entity in a merger, acquisition or asset sale, subject to this Policy.

A current list of sub-processors used for the Service is available to business customers on request and is set out in the data processing terms of their agreement with us.

7. Where data is stored and international transfers

Personal data is stored on cloud infrastructure in India by default. Business customers may choose other supported hosting regions in their agreement. Some providers we rely on process data outside India; where they do, we use contractual safeguards and comply with any restrictions on transfer notified by the Central Government under the DPDP Act.

8. How long we keep it

  • Prospect and enquiry data: up to 24 months after our last contact, unless you become a customer or ask us to delete it sooner.
  • Account and billing data: for the life of the customer relationship and thereafter as required by tax, company and accounting law (generally 8 years in India).
  • End-customer conversation data and memory profiles: for the retention period configured by the business customer, after which they are deleted or irreversibly anonymised. On termination of a customer agreement we delete or return end-customer data within 90 days unless the law requires otherwise.
  • Server and security logs: typically 12 months.

9. How we protect it

We use encryption in transit and at rest, role-based access controls, permission-scoping of every action the AI agent may take, step-up verification before sensitive actions, masking of personal identifiers in logs and transcripts, audit logging, regular access reviews and vendor due diligence. No system is perfectly secure; if we become aware of a personal data breach affecting you, we will notify you and the Data Protection Board of India as the DPDP Act requires.

10. Your rights

Subject to the DPDP Act and other applicable law you have the right to:

  • access a summary of the personal data we hold about you and how it has been processed and shared;
  • have inaccurate or incomplete data corrected, completed or updated;
  • have your data erased where it is no longer necessary for the purpose it was collected, or where you withdraw consent;
  • withdraw consent you have given, as easily as you gave it;
  • nominate a person to exercise these rights on your behalf in the event of death or incapacity;
  • raise a grievance with us and, if unresolved, complain to the Data Protection Board of India.

To exercise these rights, email privacy@hivecell.ai. We will verify your identity and respond within the time the law allows. If your request concerns a conversation you had with a business that uses hiveCell, we will forward it to that business and assist them.

11. Cookies and analytics

The Website uses strictly necessary cookies to function. We may also use privacy-respecting analytics to understand how the Website is used; where such analytics set cookies or similar identifiers that require consent, we ask for it before setting them. You can block or delete cookies in your browser settings; the Website will still work. Third-party embeds (for example the meeting scheduler) may set their own cookies subject to their own policies.

12. Children

The Website and Service are intended for businesses and their adult representatives. We do not knowingly collect personal data from children under 18 for our own purposes. Businesses that serve children through the Service are responsible for obtaining verifiable parental consent as the DPDP Act requires.

13. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date at the top shows the current version. For material changes affecting business customers, we will give notice through the Service or by email.

14. Grievance Officer and contact

Grievance Officer: [Name], hiveCell Technologies Pvt. Ltd., [Registered office address], [City]. Email: privacy@hivecell.ai. We aim to acknowledge grievances within 48 hours and resolve them within the period prescribed by law.

General enquiries: hello@hivecell.ai.

© 2026 hiveCell Technologies Pvt. Ltd. · hivecell.ai Privacy · Terms · Disclaimer