This Privacy Policy (“Policy”) applies to the agentic artificial intelligence software platform for agent-based assistance, workflow automation, knowledge retrieval, analytics, reporting, and data processing, together with its associated applications, dashboards, modules, interfaces, APIs, integrations, and related services (collectively, the “Software” or “Platform”) operated by DAHOTRE CORPTECH PRIVATE LIMITED (“Company”, “we”, “our”, or “us”).
This Policy forms an integral part of the applicable Terms of Use, subscription documents, and other binding contractual terms governing access to and use of the Software. By accessing or using the Software, the relevant User and Subscriber acknowledge that they have read and understood this Policy and agree to be bound by it, to the extent applicable.
01Introduction and Applicability
1.1This Policy applies to: (i) individual users of the Software (“Users”); (ii) organisations subscribing to the Software (“Subscribers”); and (iii) authorised personnel, employees, consultants, and representatives of Subscribers.
1.2This Policy governs the processing of data uploaded, transmitted, integrated, received, stored, viewed, downloaded, or otherwise processed through the Software.
1.3In the event of inconsistency between this Policy and the Terms of Use or governing contract, the Terms of Use or governing contract shall prevail to the extent of such inconsistency.
1.4This Policy is product-specific and has been drafted for an agentic artificial intelligence platform used in a business and enterprise context.
02Nature of the Software
2.1The Software is a technology platform intended to facilitate: (i) configuration and operation of AI agents; (ii) conversational assistance and task execution; (iii) processing of organisational data, documents, and connector information; (iv) analytics, dashboards, and reporting; and (v) allied workflow, memory, skills, library, connectors, automations, goals, approvals, and audit trail functions.
2.2The Company provides the Software solely as a technology-enabled platform and does not, merely by providing the Software: (i) provide professional advice of any kind, including without limitation legal, tax, accounting, audit, medical, HR, engineering, safety, or regulatory advice; (ii) certify correctness of outputs, records, agent-generated responses, actions, or reports; or (iii) assume the Subscriber’s statutory, contractual, or regulatory compliance obligations.
2.3The Software functions based on data made available by the Subscriber or User, whether by upload, manual entry, integration, synchronisation, or other authorised means.
2.4The Company does not independently originate or validate business, operational, organisational, connector, or other Subscriber data processed through the Software, except for system-generated logs, usage records, and technical metadata required for operation, security, and support.
03Definitions
3.1“Applicable Law” means all applicable laws, rules, regulations, notifications, directions, and binding legal requirements, including, where relevant, the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000.
3.2“Personal Data” shall have the meaning assigned under Applicable Law.
3.3“Subscriber Data” means all data, information, files, records, and datasets submitted, uploaded, transmitted, or otherwise made available by or on behalf of the Subscriber through the Software.
3.4“Processing” means any operation performed on data, including collection, storage, use, analysis, retrieval, transmission, disclosure, deletion, anonymisation, or destruction.
3.5“Model Provider” means a third-party large language model, foundation model, or inference service whose account, credentials, and subscription the Subscriber supplies and controls.
3.6“BYOK” or “bring-your-own-key” means the default arrangement under which model inference is performed on the Subscriber’s own Model Provider account using the Subscriber’s own keys and configuration, and not on a Company-operated model account.
04Categories of Data Processed
4.1The Company may process the following categories of data:
(A) Business / Transactional Data
(i) organisational records, documents, and knowledge base materials; (ii) prompts, instructions, chat content, and agent interactions; (iii) files, library materials, and uploaded content; (iv) connector and integration data; (v) vendor, supplier, customer, and counterparty details; (vi) agent configurations, skills, memory, automations, goals, and related settings; (vii) workflow outputs, approvals, exceptions, and audit trails.
(B) User and Account Data
(i) names, usernames, and login IDs; (ii) email addresses and phone numbers; (iii) user roles, permissions, and account administration details; (iv) authentication-related information.
(C) Technical Data
(i) IP addresses; (ii) device, browser, and system information; (iii) access timestamps, session logs, and usage analytics; (iv) diagnostic, performance, and security logs.
(D) Support and Communication Data
(i) support requests; (ii) implementation and onboarding communications; (iii) issue reports and service correspondence.
(E) Model Inference Data (BYOK)
(i) prompts, instructions, retrieved context, documents, connector extracts, tool inputs and outputs, and related content transmitted to a Model Provider at the Subscriber’s direction; (ii) Model Provider account identifiers, configuration, and credentials stored to operate BYOK.
4.2The nature and extent of data processed will depend on the modules used, integrations enabled, user permissions configured, and the Subscriber’s chosen deployment of the Software.
4.3The Company does not independently verify the legality, completeness, authority, or correctness of Subscriber Data unless expressly agreed in writing under a separate service arrangement.
4.4The Company processes Model Inference Data on the Software in order to route it as directed by the Subscriber. Once transmitted to a Model Provider, that data is processed by the Model Provider under the Model Provider’s own privacy policy and subscription terms. Those terms are not incorporated into this Policy and do not form part of the Company’s Privacy Policy.
05Personal Data and Business Data
5.1A substantial portion of the data processed through the Software may relate to business entities, commercial operations, organisational records, and operational information and may therefore not constitute Personal Data.
5.2The Software may process data relating to listed companies and other business entities. The fact that such information relates to a commercial organisation does not, by itself, make it Personal Data.
5.3To the extent any Personal Data is processed through the Software, such processing shall be subject to Applicable Law.
5.4The Subscriber is responsible for determining the legal character of the data it uploads or causes to be uploaded, including whether such data constitutes Personal Data, confidential information, regulated information, or non-personal business data.
5.5The Company shall not be responsible for incorrect classification, tagging, or treatment of data by the Subscriber or User.
06Sources and Purposes of Processing
6.1Data processed through the Software may originate from: (i) direct uploads or manual entries by the Subscriber or User; (ii) imports from ERP, email, calendar, messaging, accounting, or other enterprise systems; (iii) third-party integrations or APIs enabled by the Subscriber; (iv) onboarding, implementation, and support interactions; (v) system-generated logs and metadata; and (vi) Model Providers under the Subscriber’s BYOK account.
6.2The Company processes data only for purposes connected with provision and administration of the Software, including: (i) operating the Software and enabling access; (ii) performing agent-based assistance, automation, analytics, reporting, and retrieval functions; (iii) enabling integrations, imports, synchronisation, exports, and configurable outputs; (iv) maintaining security, audit trails, system integrity, and abuse prevention; (v) troubleshooting, diagnostics, support, and account management; (vi) improving platform stability, usability, and performance; (vii) complying with Applicable Law and enforcing contractual rights; and (viii) transmitting content to Model Providers at the Subscriber’s direction under BYOK.
6.3The Company does not sell Personal Data as part of the ordinary business model of the Software.
6.4The Company does not operate its own models and does not use Subscriber Data to train or fine-tune any model. Training, retention, or “improvement” by a Model Provider is controlled solely by the Subscriber on that Model Provider’s account (including any improvement or training toggle). The Company does not operate that toggle. The Software’s security settings include a control under which the Subscriber may permit the Company to access and review Subscriber Data — including chat content, logs, traces, and related diagnostic material — for the purpose of investigating and fixing issues. The Company may use anonymised, aggregated, statistical, or non-identifiable information for internal analytics, security analysis, and platform stability.
6.5The outputs generated by the Software — including drafts, reports, recommendations, comparisons, agent-generated responses, automations, actions, and any final deliverable — depend on the accuracy, completeness, and configuration of the data supplied by the Subscriber or User and on the Model Provider selected by the Subscriber. The Company does not guarantee that any such output is accurate, complete, current, or fit for any particular purpose. The Subscriber and each User must independently review every output and every final deliverable for accuracy, completeness, and suitability before relying on it for any operational, commercial, professional, legal, financial, HR, technical, safety, or regulatory purpose.
07Role of the Company
7.1In relation to Subscriber Data, the Company acts primarily as a technology service provider and, where applicable, as a processor or service provider on behalf of the Subscriber, unless otherwise required by Applicable Law or expressly agreed otherwise in writing.
7.2The Subscriber shall be solely responsible for: (i) determining the purpose of processing; (ii) deciding what data is uploaded or integrated; (iii) ensuring lawful collection, disclosure, and processing of such data; (iv) obtaining all required notices, permissions, approvals, and consents; (v) configuring user access and permissions; (vi) determining retention requirements applicable to its business; and (vii) independently validating every output and every final deliverable for accuracy, completeness, and suitability before reliance for any operational, commercial, professional, legal, financial, or other purpose.
7.3The Company shall not be responsible for verifying: (i) the legality or authority for upload of Subscriber Data; (ii) whether required consents or notices have been obtained; (iii) whether the data is accurate, current, complete, or lawful; or (iv) whether the Subscriber’s use of the Software complies with its internal policies, contracts, or statutory duties.
7.4Nothing in this Policy shall be construed to mean that the Company assumes the role of professional advisor — including without limitation tax advisor, legal counsel, auditor, compliance manager, or other regulated adviser — for the Subscriber.
08Model Providers and Bring-Your-Own-Key
8.1The default and exclusive model-inference path for the Software is BYOK. The Subscriber supplies, owns, and controls its Model Provider account, API keys, credentials, and configuration. The Company does not provide a Company-managed model account as the ordinary path for inference.
8.2Content may be transmitted to a Model Provider at the Subscriber’s direction, including prompts, instructions, retrieved context, documents, connector extracts, tool inputs and outputs, and related inference data. Such processing is performed by the Model Provider on the Subscriber’s account.
8.3The privacy policy, subscription agreement, data-processing terms, training or improvement settings, retention, security practices, and place of processing of the Model Provider apply to that path. Those terms are the Model Provider’s terms. They are not incorporated into this Policy and do not form part of the Company’s Privacy Policy.
8.4The Company does not control the Model Provider’s infrastructure, availability, content filters, training or improvement features, or location of processing, including any ban, suspension, restriction, or disallowance of BYOK or of the Subscriber’s account or credentials. A Model Provider may process data outside India. The Subscriber is responsible for selecting the Model Provider, for the location of that processing, and for configuring that account, including turning off any improvement, training, or similar feature on the Model Provider’s account.
8.5Allocation of risk arising from a Model Provider — including outage, unavailability, error, hallucination, unauthorised access, confidentiality incident, ban, suspension, restriction, or disallowance of BYOK or of the Subscriber’s account, or other loss caused by the Model Provider — is not set out in this Policy. Those matters are governed by the Subscriber’s agreement with the Model Provider and, as between the Company and the Subscriber, by the Terms of Use and governing contract. This Policy does not make the Company responsible for any loss or damage arising from a Model Provider.
8.6The Software depends on a valid, permitted Subscriber BYOK account. If a Model Provider bans, suspends, restricts, or otherwise disallows BYOK, the Subscriber’s account, API keys, or the use of those credentials with the Software, inference on that path may fail or cease. The Company will not substitute a Company-managed model account. Such ban, suspension, restriction, or disallowance is a matter between the Subscriber and the Model Provider. This Policy does not make the Company responsible for any loss or damage arising from it, including inability to use model-dependent functions of the Software.
09Subscriber and User Obligations
9.1The Subscriber and each User represent, warrant, and undertake that: (i) all data uploaded or processed through the Software is lawful and properly authorised; (ii) they have the necessary right or lawful basis to provide such data for processing; (iii) all required notices, permissions, and consents have been obtained, where applicable; (iv) use of the Software does not violate Applicable Law, confidentiality obligations, or third-party rights; and (v) all outputs, agent-generated responses, and final deliverables will be independently reviewed for accuracy, completeness, and suitability before being relied upon or acted upon.
9.2The Subscriber shall be responsible for maintaining confidentiality of credentials, controlling user access, and promptly notifying the Company of suspected unauthorised access or compromise.
9.3The Company shall have no responsibility or liability for: (i) unlawful or unauthorised data uploaded by the Subscriber or User; (ii) absence of required consent, notice, or authority; (iii) inaccurate, incomplete, stale, duplicate, or misleading data; (iv) misuse or incorrect configuration of the Software by the Subscriber or User; or (v) claims, proceedings, or liabilities arising from Subscriber data handling practices or reliance on Software outputs without independent review.
10No Professional Advice; Human Review Required
10.1The Software is a facilitative technology tool and does not constitute professional advice of any kind, including legal, tax, accounting, audit, medical, HR, engineering, safety, or regulatory advice, and does not constitute statutory validation or certification.
10.2The Software does not replace independent professional review, internal controls, or due diligence by the Subscriber’s qualified advisors or internal teams.
10.3Any report, dashboard, summary, agent-generated response, recommendation, automation result, action, or other output or deliverable generated by the Software is operational and informational in nature. The Subscriber and each User must independently review it for accuracy, completeness, and suitability before it is relied upon, issued, filed, published, or acted upon, including for any operational, commercial, professional, compliance, financial, or high-impact purpose.
11Data Storage, Cloud Infrastructure, and Security
11.1Data processed through the Software may be stored, hosted, backed up, transmitted, or otherwise processed using third-party cloud, hosting, database, security, monitoring, and infrastructure providers.
11.2The Software application and Subscriber Data retained by the Company for provision of the Software are hosted in India.
11.3The Company may use commercially reasonable care in selecting such providers, but does not own or control the underlying infrastructure of such third parties.
11.4The Subscriber acknowledges that operation of cloud-based software services ordinarily involves reliance on third-party infrastructure and networks.
11.5The Company implements reasonable technical and organisational measures designed to protect data from unauthorised access, misuse, alteration, loss, or disclosure. Such measures may include access controls, role-based permissions, authentication safeguards, encryption where applicable, logging, monitoring, backups, and incident response processes.
11.6No digital system or transmission method is completely secure. Security also depends materially on the Subscriber’s internal controls, access management, device hygiene, network security, and third-party integrations.
11.7The Company shall not be liable for downtime, outages, corruption, delay, loss, breaches, or unauthorised access arising from: (i) third-party cloud or infrastructure providers; (ii) compromised credentials; (iii) weak passwords or inadequate access controls by the Subscriber; (iv) insecure Subscriber devices or networks; (v) third-party integrations, APIs, or external systems; or (vi) circumstances beyond the reasonable control of the Company.
11.8Transmission of data to a Model Provider under BYOK is not Company hosting. That data may be processed outside India on the Subscriber’s Model Provider account, under that Model Provider’s own privacy policy and subscription terms, which are not part of this Policy.
12Logs, Audit Trails, and Monitoring
12.1The Software may maintain access logs, activity histories, audit trails, usage records, and system logs for security, accountability, traceability, troubleshooting, dispute resolution, and service improvement.
12.2Such logs may include login timestamps, actions performed, records accessed, imports, exports, reports generated, agent runs, prompts, approvals, configuration changes, and other system activities.
12.3The Company may use such records internally for security review, incident investigation, support handling, and enforcement of contractual rights.
13Data Retention and Deletion
13.1Data shall be retained for such period as may be: (i) necessary during the subscription or service relationship; (ii) operationally required for functioning, support, backup, audit, or security purposes; (iii) required under Applicable Law; or (iv) necessary for enforcement of legal rights or resolution of disputes.
13.2Upon expiry or termination of the applicable relationship: (i) access to the Software may be suspended or revoked; (ii) the Subscriber may lose access to stored data after the applicable transition period, if any; and (iii) data may be deleted, anonymised, archived, or rendered inaccessible in accordance with the Company’s retention protocols, contractual commitments, or Applicable Law.
13.3The Company shall have no obligation to retain data indefinitely after termination unless expressly agreed in writing or required by Applicable Law.
13.4Backup copies, residual logs, and archival records may continue to exist for a limited period due to technical, operational, legal, or recovery requirements.
14Data Sharing and Disclosure
14.1The Company may disclose or make data available, strictly on a need-to-know basis, to: (i) cloud, hosting, storage, monitoring, and infrastructure providers; (ii) implementation, support, security, and technical service providers; (iii) professional advisors, auditors, or consultants engaged under confidentiality obligations; (iv) affiliates involved in lawful service delivery or support, where applicable; (v) governmental, judicial, quasi-judicial, regulatory, tax, or law enforcement authorities where required by Applicable Law or lawful process; and (vi) a successor entity in connection with merger, acquisition, restructuring, financing, or transfer of business or assets, subject to continuity of obligations where commercially and legally feasible.
14.2The Company does not disclose Subscriber Data to third parties for unrelated sale or marketing as part of the ordinary operation of the Software.
14.3Where the Subscriber enables third-party integrations, exports, connectors, Model Providers, or APIs, data may be transmitted to or from such systems at the Subscriber’s direction. Processing by a Model Provider is governed by that Model Provider’s privacy policy and subscription terms, which are not part of this Policy. The Company does not control, and this Policy does not govern, the privacy, legality, or security practices of such third parties.
15Cross-Border Data Transfer
15.1The Software application and Subscriber Data held by the Company are stored and processed in India.
15.2Data transmitted to a Model Provider under BYOK may be stored, transferred, or processed outside India, as determined by the Subscriber’s Model Provider account and configuration. Such processing is at the Subscriber’s direction and is subject to the Model Provider’s terms, not this Policy.
15.3To the extent legally required, the Subscriber shall remain responsible for obtaining any necessary permissions, notices, or consents for BYOK transfers to a Model Provider, unless otherwise expressly agreed in writing.
16User Rights and Requests
16.1To the extent mandated by Applicable Law and subject to the nature of the Company’s role, a User may seek rights such as access, correction, updating, deletion, or withdrawal of consent in relation to Personal Data.
16.2Where the relevant data is controlled by the Subscriber, or where the Company acts only on the Subscriber’s behalf, the Company may require such request to be routed through or validated by the Subscriber.
16.3The Company may refuse, limit, or defer a request where: (i) it is not legally required to comply; (ii) compliance is not technically feasible; (iii) the Company is not the correct responding party; (iv) the request affects rights of others; or (v) retention is required for law, security, audit, or dispute-related purposes.
17Confidentiality, Third-Party Services, and Incidents
17.1The Company recognises that data processed through the Software may include confidential, commercially sensitive, strategic, financial, or compliance-related information and shall use reasonable measures to maintain confidentiality in accordance with its internal practices and contractual commitments.
17.2The Software may interoperate with third-party applications, APIs, ERP systems, email and messaging systems, Model Providers, authentication services, and other external tools. The Company does not control the privacy or security practices of such third parties. Processing by a Model Provider under BYOK is governed by that Model Provider’s own privacy policy and subscription terms, which are not part of this Policy. Allocation of risk for Model Providers is set out in the Terms of Use and governing contract, and in the Subscriber’s agreement with the Model Provider.
17.3The Company may maintain internal processes for responding to suspected security incidents affecting the Software and may take such steps as it considers appropriate, including containment, investigation, mitigation, remediation, and legally required notification.
17.4The Company does not guarantee that every attempted attack, anomaly, suspicious event, or unsuccessful threat will result in notice to the Subscriber.
18User Age
18.1The Software is an enterprise and business-focused platform and is not intended for use by minors.
18.2The Subscriber shall not knowingly use the Software in a manner that violates Applicable Law relating to children’s data.
19Changes to this Policy
19.1The Company may update or modify this Policy from time to time due to changes in law, the Software, infrastructure, service model, or risk management requirements.
19.2The updated Policy may be posted on the Platform, website, or otherwise communicated through appropriate means.
19.3Continued use of the Software after such update becomes effective shall constitute acceptance of the revised Policy, to the extent permitted by Applicable Law and the governing contract.
20Limitation of Liability
20.1To the maximum extent permitted by Applicable Law, the Company shall not be liable for: (i) data uploaded, shared, entered, or integrated by the Subscriber or User; (ii) unlawful, unauthorised, or improper processing initiated by the Subscriber or User; (iii) absence of required notices, permissions, approvals, or consents; (iv) inaccurate, incomplete, outdated, duplicated, manipulated, or misleading data; (v) any decision, filing, action, or omission taken on the basis of Software-generated outputs without independent review; (vi) losses caused by third-party infrastructure, APIs, connectivity failures, or cloud provider incidents; (vii) breaches caused by compromised credentials, Subscriber systems, User practices, or third-party environments; (viii) indirect, incidental, special, punitive, or consequential losses; or (ix) regulatory action, tax demands, penalties, interest, proceedings, or claims arising from Subscriber conduct, Subscriber data, Subscriber compliance failures, or Subscriber reliance on Software outputs.
20.2The Subscriber expressly acknowledges that the Software is a facilitative tool and that final responsibility for all decisions — including operational, commercial, professional, legal, financial, HR, technical, safety, and regulatory decisions — remains with the Subscriber. The Subscriber and each User must independently review every output and every final deliverable for accuracy, completeness, and suitability before reliance.
20.3This Clause shall be read together with, and shall be subject to, the limitation of liability, disclaimers, exclusions, and risk allocation set out in the Terms of Use and governing contract, which shall prevail where applicable.
20.4This Policy does not allocate liability for Model Providers or for inference performed under BYOK. That allocation is set out in the Terms of Use and governing contract, and in the Subscriber’s agreement with the Model Provider. The Company is not responsible under this Policy for any loss or damage arising from a Model Provider, including outage, unavailability, error, confidentiality incident, ban, suspension, restriction, or disallowance of BYOK or of the Subscriber’s account, or other vendor-caused loss.
21Governing Law, Jurisdiction, and Contact
21.1This Policy shall be governed by and construed in accordance with the laws of India.
21.2Subject to any agreed dispute resolution mechanism in the Terms of Use or governing contract, the courts at Pune, Maharashtra shall have exclusive jurisdiction over disputes arising out of or in connection with this Policy.
22Contact
For questions, requests, notices, or grievances relating to this Policy, Users and Subscribers may contact:
DAHOTRE CORPTECH PRIVATE LIMITED
Address: Floor 7, Kotibhaskar Business Court, Karve Rd, opposite Karishma Society, Kothrud Industrial Area, Kothrud, Pune, Maharashtra 411038
Email: varun.d@heyxia.io
Phone: +91 9699984943
Attention: Grievance Officer / Compliance Contact