1. Introduction
This Data Processing & Privacy Compliance Policy outlines how Parakeeet.ai (“we,” “our,” “us”) collects, processes, stores, and protects personal data, including call recordings, to comply with GDPR, CCPA, and TCPA regulations.
We act as both a Data Controller (for our own customers) and a Data Processor (when processing data on behalf of our clients). This policy applies to all international customer calls, SMS communications, AI-driven
interactions, and data captured via our DFY/DYI AI voice assistant services.
2. Scope & Applicability
This policy applies to:
- All clients and end-users of Parakeeet.ai worldwide.
- Any personal data collected via phone calls, SMS, WhatsApp, or web forms.
- All data stored in connected CRMs, calendars, and integrated third-party apps.
- Data processed on behalf of our clients’ businesses, including real estate, healthcare, retail, and professional services.
3. Legal Frameworks
3.1 GDPR (General Data Protection Regulation – EU/EEA)
We process data lawfully under Article 6 of GDPR, including:
- Consent: Where users opt in to calls, SMS, or marketing.
- Contractual necessity: To provide services requested by the client.
- Legitimate interest: When contacting leads who have engaged with a client’s services, in compliance with soft opt-in rules.
3.2 CCPA (California Consumer Privacy Act)
For California residents, we ensure:
- Right to know what data we collect.
- Right to request deletion.
- Right to opt out of sale or sharing of personal information.
- Equal service and price regardless of privacy choices.
3.3 TCPA (Telephone Consumer Protection Act – USA)
For U.S. contacts:
- Calls are made only to numbers provided by the client or obtained with prior express consent.
- Opt-out instructions are provided in every SMS.
- No calls/SMS are made before 8:00 AM or after 9:00 PM local time of the recipient.
- Automated dialing compliance is ensured where applicable.
4. Data We Process
We may process the following categories of personal data:
- Contact Information: Name, phone number, email, company name.
- Communication Records: Call logs, call recordings, SMS transcripts.
- Transactional Data: Appointment bookings, form submissions, sales data.
- CRM-Linked Data: Tags, lead stage, and engagement history.
- Technical Data: IP address, device ID, browser type.
5. How We Process Data
- Collection: Data is collected via web forms, inbound/outbound calls, SMS, and client CRM integrations.
- Storage: Data is stored securely on encrypted servers with access controls.
- Use: To qualify leads, book appointments, send reminders, and deliver marketing (only with consent).
- Retention: Data is retained for the period agreed with the client or as required by law (max 24 months unless otherwise contracted).
- Anonymization: When data is no longer needed, it is anonymized or permanently deleted.
6. Data Processing on Behalf of Clients (Processor Role)
When acting as a Data Processor:
- We process data only on documented instructions from the client (Data Controller).
- We do not sell, share, or use the data for our own purposes.
- We assist clients in responding to data subject requests (DSRs).
- We ensure sub-processors (e.g., cloud hosting, CRM tools) meet equivalent compliance standards.
7. International Data Transfers
Where personal data is transferred outside the EU/EEA or California:
- We use Standard Contractual Clauses (SCCs) for GDPR compliance.
- Data is stored with providers who meet GDPR, CCPA, and ISO 27001 security standards.
8. Data Subject Rights
Under GDPR/CCPA, individuals have the right to:
- Request access to their personal data.
- Request correction of inaccurate data.
- Request deletion (“Right to be Forgotten”).
- Object to processing for direct marketing.
- Receive data in a portable format
To exercise these rights, email info@parakeeet.ai.
9. Call Recording & Consent Compliance
- We inform all call participants if the call is being recorded.
- We comply with one-party consent and two-party consent laws depending on the recipient’s state/country.
- We log proof of consent for all automated communications.
10. Security Measures
- End-to-end encryption for all stored and transmitted data.
- Role-based access control (RBAC) for staff.
- Regular security audits and penetration testing.
- Incident response plan for data breaches, including 72-hour GDPR breach notification.
11. Client Responsibilities
Clients using Parakeeet.ai are responsible for:
- Providing legally obtained contact lists.
- Ensuring their lead collection methods comply with applicable laws.
- Informing Parakeeet.ai of any withdrawal of consent from their contacts.
12. Changes to This Policy
We may update this policy from time to time. The latest version will always be posted at: https://parakeeet.ai/data-processing-privacy-compliance
13. Contact Us
📧 Email: info@parakeeet.ai
🏢 Address: Parakeeet.ai, 602-603, Crystal Plaza, New Link Road, Chakala, Andheri (East), Mumbai - 400099, India