Legal

Privacy Policy

What we collect, why, and what you can do about it. We don’t sell personal data, we don’t store call recordings, and we encrypt the credentials you connect.

Updated · 5 October 202615 sections
01

Who we are

Atomicia is operated by Atomicia Build (“we”, “us”). This Privacy Policy explains what personal data we collect, why, who we share it with and the choices you have. It applies to our website and platform (the “Service”) and should be read with our Terms of Service.

We act in two roles:

  • For our customers’ account data (you, your team and your business), we decide how it is used and are the data controller / Data Fiduciary.
  • For the leads our customers upload and call, the customer is the controller / Data Fiduciary and we process that data on their behalf, as their processor. If you were called by a business using Atomicia, that business is responsible for the call; please contact it first. We will help it respond to your request, and you can also contact us.
02

Data we collect

From customers

  • Account data: name, email address and password (stored only as a secure one-way hash), or your Google profile name and email if you sign in with Google.
  • Business profile: company name, agent name, what you sell, ideal customer and team email.
  • Connected accounts: your Google Calendar authorisation and the calendar email it belongs to; your Plivo account ID, auth token and phone numbers. Access tokens and auth tokens are encrypted at rest.
  • Billing data: your plan, subscription status and payment references from Razorpay. We never receive or store full card numbers, CVVs or bank credentials.
  • Usage and audit data: leads imported, calls placed, call duration, AI usage, setup steps completed, compliance acceptance and security events.
  • Technical data: IP address, browser type and request logs, used for security, rate-limiting and debugging.
  • Product analytics: pages viewed, buttons clicked and setup steps reached on our website and dashboard, and session replays in which form inputs (and, in the dashboard, all on-screen text) are masked. We use these to understand where people get stuck and to improve the Service.
  • Communications: messages you send to support.

About leads (on our customers’ behalf)

  • Data the customer uploads: company name, website, contact name, phone number, email and notes on their needs.
  • Research: publicly available text from the lead’s company website, and an AI-generated summary of it.
  • Calls: call status, timing and duration, a written transcript, and what the person said about their needs, interest and availability. Call audio is processed in real time to run the conversation and is not stored by us as a recording.
  • Meetings booked and any do-not-contact requests, which we keep so the person is never called again by that customer.
03

How we use data

  • To provide the Service: research leads, place and run AI calls, transcribe and summarise them, check availability and book meetings.
  • To create and secure your account, verify your email, keep you signed in and prevent fraud and abuse.
  • To process payments, enforce plan limits and send service and billing emails.
  • To enforce compliance safeguards such as calling hours and do-not-contact lists, and to investigate misuse.
  • To provide support, fix problems and improve the reliability of the Service.
  • To comply with law and respond to lawful requests from authorities.
04

Legal basis

We process customer data to perform our contract with you, to meet legal obligations, for our legitimate interests in running a secure and reliable Service, and, where required, with your consent (for example, when you connect a Google or Plivo account). You can withdraw consent at any time by disconnecting the account or contacting us; this does not affect processing already carried out. Lead data is processed on the customer’s instructions and the customer is responsible for its lawful basis.

05

AI processing

Lead details, website text, call audio and transcripts are sent to the AI model providers that power research, speech recognition, voice and conversation, only to produce the result requested. We do not sell this data, and we do not use your data or your leads’ data to train our own AI models. AI output may be inaccurate; see our Terms.

06

Google user data

If you connect Google, we use it only to sign you in (name and email) and, for Google Calendar, to read your free/busy availability and to create, view and cancel meetings that the agent books for you, and to show the titles and times of upcoming events in your dashboard. We do not read event descriptions or attendees of your other events, or any other Google data such as email or files.

Atomicia’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or allow humans to read it except with your consent, for security or legal reasons, or to fix a problem you ask us about. You can revoke access at any time from your Google Account (Security → Third-party connections) or by contacting us.

07

Who we share data with

We do not sell or rent personal data. We share it only with service providers that help us run the Service, under contracts that limit their use of it:

  • Cloud hosting and database providers, which store the Service’s data.
  • Plivo (through your own account), which carries the phone calls.
  • Google, for sign-in and calendar booking when you connect it.
  • Razorpay, which processes subscription payments.
  • Our email provider, which sends verification and service emails.
  • PostHog, our product analytics provider, which receives the product analytics described above.
  • AI model providers for research, speech recognition, voice and conversation.

We may also disclose data if required by law, court order or a government authority; to protect the rights, safety or property of Atomicia Build, our customers or others; or as part of a merger, acquisition or sale of assets, in which case this Policy will continue to apply to the data transferred.

08

International transfers

Our database and some providers are located outside India, including in the United States. When data is transferred abroad we take steps to protect it as described in this Policy and as required by applicable law, and we will not transfer data to any country restricted by the Government of India.

09

Retention

  • Account, business profile and lead data are kept while your account is active. After you close your account, we delete or anonymise it within 30 days, except as below.
  • Do-not-contact entries are kept as long as needed to keep honouring them.
  • Billing and tax records are kept for as long as Indian law requires (generally up to 8 years).
  • Security logs and audit events are kept for up to 1 year, or longer if needed for an investigation or legal claim.
  • Data in backups is removed as the backups expire.
10

Security

We use encryption in transit (HTTPS/TLS), encryption at rest for connected-account tokens, hashed passwords, httpOnly session cookies, per-customer data isolation, signed webhooks, rate-limiting and access controls. No system is perfectly secure; if a breach affects your personal data, we will notify you and the relevant authorities as required by law. Keep your password and connected-account credentials secret.

11

Cookies

We use one essential cookie to keep you signed in, and browser storage to remember small preferences such as the plan you picked before signing up. We also use first-party analytics cookies and storage set by PostHog to understand how the site is used (see “Data we collect”). We do not use advertising cookies or sell this data. Payment pages provided by Razorpay may set their own cookies.

12

Your rights

Depending on where you live, including under India’s Digital Personal Data Protection Act, 2023 and the GDPR, you may have the right to:

  • Get a summary of, or access to, the personal data we hold about you.
  • Correct or update inaccurate or incomplete data.
  • Have your data erased, subject to legal retention requirements.
  • Withdraw consent you have given.
  • Object to or restrict certain processing, and receive your data in a portable format.
  • Nominate another person to exercise your rights if you die or become incapacitated.
  • Complain to us through our Grievance Officer, and then to the Data Protection Board of India or your local data-protection authority.

To exercise these rights, email support@atomiciabuild.com. We may need to verify your identity. If you were called by one of our customers, we will pass your request to that customer and help it respond; to stop being called, simply say so on the call or email us with your phone number.

13

Children

The Service is for businesses and is not directed at anyone under 18. We do not knowingly collect data about children, and customers must not upload it. If you believe we have, contact us and we will delete it.

14

Changes to this Policy

We may update this Policy from time to time. If a change is material, we will notify customers by email or in the Service before it takes effect. The “last updated” date at the top shows when it was last changed.

15

Grievance Officer and contact

In line with the Information Technology Act, 2000, its rules and the Digital Personal Data Protection Act, 2023, complaints and requests about personal data can be sent to the Grievance Officer, Atomicia Build, at support@atomiciabuild.com. We acknowledge complaints within 24 hours and aim to resolve them within 15 days.