Back to home
Legal

PRIVACY POLICY

Effective: 1 September 2026Last updated: 17 August 2026Read our Terms of Service

The short version

Your data stays yours

You own your business data and your customers' data. We hold it to run your automations, and we delete it when you ask.

We never train models on it

Your conversations are never used to train third-party AI models. They are sent to our AI providers only to generate a reply inside your own automation.

We sell nothing

We do not sell, rent, or trade personal data. We share it only with the named sub-processors that make the service work.

Ask and we act

Access, correction, export, deletion, or withdrawal of consent - write to our Grievance Officer and we respond within 30 days.

This summary is for readability only. The full terms below are what legally apply.

Lumoscale is a UDYAM-registered MSME building AI automation systems that talk to your customers on your behalf. That means we handle conversations, contact details, and business records that matter - and we treat that responsibility seriously.

This Policy sets out exactly what we collect, why, who else touches it, how long we keep it, and what you can demand of us. No hidden clauses, no data sales, no model training on your conversations.

01Who We Are

Lumoscale ("Lumoscale", "we", "us", or "our") is a UDYAM-registered Micro, Small and Medium Enterprise (MSME) operating under the Micro, Small and Medium Enterprises Development Act, 2006, based in Bengaluru, Karnataka, India.

We design, build, and operate done-for-you AI automation systems - AI voice agents and call handling, messaging and DM automation, and back-office workflow automation - for businesses across industries and geographies.

  • Entity type: UDYAM-registered MSME (registration number available on request)
  • Principal place of business: Bengaluru, Karnataka, India
  • Contact: contact@lumoscale.com

This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and the rights you can exercise over it. It applies to www.lumoscale.com and to every automation, dashboard, and support channel we operate for our clients.

02Our Role: Data Fiduciary vs. Data Processor

Depending on whose data is involved, Lumoscale acts in one of two distinct capacities. This distinction determines who is accountable for what.

  • As a Data Fiduciary (Controller): for data you give us directly as our client - your business details, account and billing information, and your correspondence with our team. We decide the purposes and means of processing this data, and this Policy governs it.
  • As a Data Processor: for data belonging to your customers, leads, and contacts that our automations handle on your behalf - call recordings and transcripts, chat and DM threads, appointment details, and enquiry information. We process this data solely on your documented instructions and only to deliver the service you have engaged us for.

Where we act as a Processor, you remain the Data Fiduciary. You are responsible for having a lawful basis and valid notice or consent for the data you route through our systems, and your end-customers should refer to your privacy policy. Our handling of that data is governed by the service agreement or Data Processing Addendum between us.

03Information We Collect

We collect only what is necessary to build, run, and support your automations.

  • Business and account information: company name, industry, website, contact name, email address, phone number, billing details, and the goals and requirements you share during onboarding.
  • Communication data: the calls, messages, chats, and DMs your automations handle, including transcripts, audio recordings (where enabled), message content, and metadata such as timestamps, duration, and outcome.
  • Integration and technical data: API keys, OAuth tokens, CRM and calendar credentials, webhook endpoints, and configuration settings you provide so we can connect your systems. Credentials are stored encrypted and used only to operate the integrations you authorised.
  • End-user data: information your customers share with your automations - names, phone numbers, email addresses, appointment details, enquiry content, and any other field your workflow is configured to capture.
  • Website and usage data: IP address, browser and device type, pages viewed, referring source, and interactions with our forms, audit tool, and demo agent. We use privacy-respecting analytics and essential cookies; we do not run third-party advertising trackers.
  • Support data: tickets, emails, and call notes exchanged with our team.

We do not intentionally collect special or sensitive categories of personal data (such as health, financial account, biometric, or government-ID information) unless your automation is expressly configured to capture it, in which case you must ensure you have the legal right to do so and must tell us in advance so we can apply appropriate safeguards.

04How We Use Your Information

We use the information described above to:

  • Build, configure, deploy, and maintain your custom AI automations
  • Answer calls, reply to messages, and qualify leads on your behalf
  • Schedule appointments and sync bookings with your calendar and CRM
  • Provide analytics, transcripts, and performance reporting in your dashboard
  • Monitor, debug, and optimise automation performance
  • Provide technical support and respond to your requests
  • Process payments, issue invoices, and maintain statutory financial records
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal, tax, and regulatory obligations applicable to us in India
  • Send service and account communications; marketing emails are sent only where you have opted in, and every one carries an unsubscribe link

We do not use your data, or your end-customers' data, to train third-party AI models. Content sent to our AI providers is used solely to generate a response within your automation in that moment. We do not sell, rent, or trade personal data to anyone, for any purpose.

06AI-Powered and Automated Interactions

Transparency about AI is central to how we build. Where an automation communicates directly with your customers:

  • It discloses that the person is interacting with an AI assistant, consistent with WhatsApp Business API, Instagram, and other platform policies.
  • Automated decisions such as lead qualification, prioritisation, and routing are based strictly on the criteria and business rules you supply.
  • Any automated outcome can be reviewed, escalated to, or overridden by a human on request. Your customers can ask to speak to a person at any point in a conversation.
  • AI systems can make mistakes. Outputs are not professional advice, and you should apply human review wherever an interaction carries material consequences.
  • You remain responsible for ensuring your scripts, prompts, and business rules comply with the laws of your jurisdiction and industry - including consent, calling-hours, and do-not-call requirements.

07Call and Message Recording

  • Call recording is off by default. We enable it only where you specifically request it.
  • When recording is enabled, callers are informed at the start of the call that the call is being recorded, and the automation honours a request to stop or to speak with a human.
  • Transcripts and recordings are available in your dashboard on read-only access and are used for service delivery, quality assurance, and troubleshooting.
  • Message and DM conversations are retained for delivery, continuity of context, and optimisation.
  • You are responsible for meeting any additional recording-consent requirements that apply in the jurisdictions you call into, including two-party consent regimes.

08Third-Party Services and Sub-Processors

To deliver the service we rely on a small set of trusted providers who process data on our instructions as sub-processors. We share only the minimum data each one needs.

  • Twilio: voice telephony for clients in the US, UAE, and other international markets
  • Viboz: voice telephony for clients in India
  • WhatsApp Business API (Meta): official messaging channel
  • Instagram API (Meta): official messaging channel
  • OpenAI: AI language processing for automation responses
  • PayPal: payment processing; card details are handled by PayPal and never stored by us
  • Cloud hosting and workflow infrastructure: for application hosting, databases, and automation orchestration
  • Your own tools: CRMs (HubSpot, Salesforce, Zoho, and similar) and calendars (Google Calendar, Calendly, and similar) that you connect

Each provider operates under its own privacy policy and security programme, and we require contractual commitments to confidentiality and appropriate safeguards. We may update this list as our stack evolves; material changes are notified under Section 14. A current list of sub-processors is available on request.

09Data Storage, Security, and Location

  • Data is stored in secured cloud infrastructure with encryption in transit (TLS) and encryption at rest for credentials and stored records.
  • Access is restricted to you and to the specific Lumoscale personnel who need it to operate your automations, under role-based access control and confidentiality obligations.
  • All communication channels run on official, sanctioned APIs - never on unofficial or scraped integrations.
  • We apply the principle of least privilege to integration credentials and revoke access promptly when it is no longer needed.
  • Your data may be stored or processed outside India by the sub-processors listed above. Where it is, we rely on the safeguards those providers offer and transfer only what the service requires, in line with applicable cross-border transfer rules.

No system is perfectly secure. We maintain reasonable, industry-standard safeguards appropriate to our size and the sensitivity of the data, and we continue to strengthen them as we grow. If a personal data breach affects you, we will notify you and the relevant authority without undue delay, in accordance with the Digital Personal Data Protection Act, 2023 and CERT-In directions.

10Data Retention

We keep personal data only as long as it serves a purpose:

  • Active accounts: data is retained for as long as your service is active, so your automations keep working with the right context.
  • After termination: we delete or irreversibly anonymise your operational data within 90 days of termination, or sooner on written request.
  • On request: you can ask us to delete specific records at any time and we will act on it within 30 days, unless retention is legally required.
  • Statutory records: invoices, tax records, and contractual documents are retained for the period Indian law requires, regardless of deletion requests.
  • Backups: deleted data may persist in encrypted backups for a short rolling window before being overwritten.

11Your Rights and Choices

Under the Digital Personal Data Protection Act, 2023 and other applicable data protection laws, you have the right to:

  • Access the personal data we hold about you, and a summary of how it is processed
  • Request correction of inaccurate, incomplete, or outdated information
  • Request erasure of your data where it is no longer needed for its purpose
  • Export your conversation history, transcripts, and analytics
  • Withdraw consent at any time, as easily as it was given
  • Opt out of specific features, integrations, or marketing communications
  • Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity
  • Raise a grievance with our Grievance Officer, and escalate to the Data Protection Board of India if unsatisfied
  • Cancel your service month-to-month, with no long-term lock-in

To exercise any right, email contact@lumoscale.com. We verify identity before acting and respond within 30 days. If you are an end-customer of one of our clients, please direct your request to that business - we will forward it to them and assist them in responding.

12Data Ownership

  • You retain full ownership of your business data, your customer data, and the content of conversations your automations handle.
  • Lumoscale holds a limited right to access and process that data purely to operate, support, and optimise the automations we build for you.
  • You may export your data at any time during the engagement and on exit.
  • Lumoscale retains ownership of its own platform, tooling, prompt frameworks, architecture, and reusable components, as set out in our Terms of Service.

13Industry Compliance

Our automations are built to handle communication, qualification, and booking in a compliant manner across the industries we serve.

  • Automations treat all leads equally and do not discriminate on the basis of protected characteristics.
  • Qualification is driven only by the criteria and business rules you provide.
  • You remain responsible for compliance with the regulations specific to your business - for example fair housing rules in real estate, healthcare privacy rules, financial services regulation, and telemarketing or do-not-call regimes.
  • Lumoscale does not generate independent medical, legal, financial, or other professional advice. Automated responses reflect the information, availability, and rules you supply.
  • You must hold and maintain any professional licences or registrations required in your industry and jurisdiction.

14Children's Privacy

Our services are built for businesses and are not directed at individuals under 18. We do not knowingly collect personal data from children. If you believe a child's data has reached us through one of our systems, contact us and we will delete it promptly. Where your automation may interact with minors, you are responsible for obtaining verifiable parental consent as required by law.

15Changes to This Policy

We may update this Privacy Policy as our services, providers, or legal obligations change. The "Last updated" date at the top always reflects the current version. For material changes we will give you reasonable advance notice by email or through your dashboard before they take effect. Continued use of our services after the effective date means you accept the updated Policy.

16Contact Us and Grievance Officer

For questions about this Policy, to exercise your rights, or to raise a grievance under the Digital Personal Data Protection Act, 2023, contact our Grievance Officer:

If your grievance is not resolved to your satisfaction, you may escalate it to the Data Protection Board of India.