Privacy Policy

~15 min read
Last updated: September 21, 2026

This policy explains what personal data Cognitiev collects through our website and the Vaani platform, why we collect it, how long we keep it, who we share it with, and how you can delete it.

Privacy Topics

16 sections

Overview & Scope

This Privacy Policy is issued by Kritrima AI Technologies Private Limited, doing business as Cognitiev ("Cognitiev", "we", "us" or "our"). It applies to:

  • our marketing website at cognitiev.com and its sub-domains;
  • the Vaani agentic AI platform, including the web dashboard at voice.cognitiev.com, our API at api.cognitiev.com, the embeddable website voice widget, and our mobile and desktop clients (together, the "Platform");
  • AI voice and messaging agents that our customers deploy using the Platform to talk to their own customers, leads and callers.
In short: we collect only the data needed to run your AI agents, workflows and integrations. We do not sell personal data, we do not use customer or Google user data for advertising, and we do not use it to train general-purpose AI models.

By creating an account or using the Platform you agree to this policy and to our Terms of Service. If you do not agree, please do not use our services.

Our Role: Controller vs. Processor

Vaani is a business-to-business platform. Understanding who is responsible for which data helps you exercise your rights with the right party:

Cognitiev as data controller

For website visitors, prospects and the people who register and administer a Cognitiev account, we decide how and why personal data is processed.

Cognitiev as data processor

For contacts, leads, callers and message recipients that our customers upload or interact with through their AI agents, the customer is the controller. We process that data only on the customer's instructions.

If you received a call, message or email from an AI agent powered by Cognitiev and want to exercise your rights, please contact the business that contacted you. We will assist them, and you can also reach us directly (see ).

Information We Collect

1. Account information you provide

Name, company name, business address, email address, phone number, password (stored as a salted hash), billing details processed by our payment provider, and any information you send us when you contact support.

2. Customer content you create or upload

  • Agent configurations, prompts, knowledge-base documents and workflow definitions.
  • Contact and lead lists (names, phone numbers, email addresses, custom fields) that you import or sync from your CRM.
  • Campaign schedules, call scripts and message templates.

3. Communication data generated by your agents

  • Call metadata — caller and callee numbers, timestamps, duration, outcome and cost.
  • Call recordings — audio of calls, only when recording is enabled on the agent or phone number. You are responsible for obtaining any consent your jurisdiction requires from callers.
  • Transcripts and AI summaries — text produced by speech recognition and language models during and after conversations.
  • Messages — SMS, WhatsApp, Instagram, Facebook Messenger and email conversations routed through connected channels, including sender identifiers and timestamps.

4. Integration data

When you connect a third-party service (Google Calendar, Gmail, Meta, CRMs, telephony providers) we receive the access tokens and the specific data described in the sections below. Tokens are encrypted at rest.

5. Technical and usage data

IP address, browser and device type, pages visited, feature usage, API request logs and error diagnostics. On cognitiev.com we also use cookies and analytics as described under .

How We Use Information

We use personal data for the following purposes and legal bases:

PurposeLegal basis
Provide the Platform: run AI agents, place and receive calls, send messages, book appointments, execute workflowsContract
Transcribe, summarise and analyse conversations so you can review outcomes and qualityContract / customer instructions
Authenticate users, secure accounts, detect fraud, abuse and spam callingLegitimate interest / legal obligation
Billing, usage metering and invoicingContract / legal obligation
Customer support and service communicationsContract
Product analytics and improving reliability of our own serviceLegitimate interest
Marketing emails to prospects and account owners (you can opt out at any time)Consent / legitimate interest
Complying with telecom, tax and other laws and responding to lawful requestsLegal obligation
What we do not do: we do not sell personal data; we do not use customer content, call recordings, transcripts or data obtained from integrations to train or improve general-purpose AI or machine-learning models; and we do not use such data for advertising or to build profiles unrelated to the service you requested.

Google API Services & Google User Data

The Platform offers two optional integrations with Google that you, as an account administrator, can enable from Dashboard → Integrations in the Vaani app: Google Calendar (appointment booking) and Gmail (reply detection for email workflows). Google sign-in is not used to log in to Cognitiev; each integration asks for its own consent through Google's OAuth 2.0 consent screen. See our Google integration overview for a walkthrough.

Scopes we request and why

ScopeWhat it gives access toWhy we need it
openid, emailYour Google account ID and primary email address.Identify which Google account is connected, display it in your Integrations page, and prevent duplicate or mismatched connections. We do not request your Google profile name or photo.
calendar.calendarlist.readonlyThe list of calendars on your account (names and IDs only).Let you choose which calendar your AI agent should book appointments into.
calendar.events.freebusyBusy/free time blocks on the selected calendar.Check availability so the AI agent only offers open time slots to your callers and leads.
calendar.eventsCreate, update and delete events on the selected calendar.Book, reschedule and cancel appointments that were arranged through your AI agent or workflow. We only modify events that Cognitiev itself created.
gmail.readonlyRead-only access to messages and threads in the connected mailbox.Detect replies to emails your Cognitiev workflow sent, so the workflow can stop follow-ups or branch on the response. We look up specific threads and reply headers; we do not scan, index, mine or store the rest of your mailbox.

What Google user data we store

  • Your Google account ID and email address, to label the connection.
  • OAuth access and refresh tokens, encrypted at rest and used only by our servers. Tokens are never sent to your browser, to other customers, or to third parties.
  • The calendar you selected and the IDs of events that Cognitiev created, so we can update or cancel them later.
  • For Gmail: the thread and message IDs of emails your workflow sent, and — only when a matching reply arrives — the reply's sender, recipient, subject and body text (truncated) so the workflow can act on it. Other messages in your mailbox are not stored.

How we use, share and protect it

  • Google user data is used only to provide the calendar-booking and reply-detection features you enabled, and to display the resulting appointments and replies in your own dashboard.
  • We do not transfer Google user data to third parties except as necessary to provide these features (our cloud hosting provider), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
  • We do not use Google user data for advertising, credit-worthiness or lending decisions, or to train AI or machine-learning models.
  • Humans at Cognitiev do not read Google user data except with your explicit permission (for example, a support request), where required for security or legal compliance, or when the data has been aggregated and anonymised.
Limited Use disclosure: Cognitiev's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Revoking access and deleting Google data

  • Disconnect the integration at any time from Dashboard → Integrations. We revoke the token with Google and permanently delete the stored tokens, calendar selection and Gmail thread references immediately. Appointments already created remain on your Google Calendar unless you delete them there.
  • You can also remove Cognitiev's access from your Google Account at myaccount.google.com/permissions; our next request will fail and the connection will be marked as disconnected.
  • Deleting your Cognitiev account deletes all Google user data associated with it. You may also email [email protected] and we will confirm deletion within 30 days.

Other Third-Party Integrations

Besides Google, you may connect other services. In each case we receive only the data needed to operate the feature, and you can disconnect at any time from Dashboard → Integrations:

  • Meta (Facebook Pages, Instagram, WhatsApp Business) — page/asset identifiers, an encrypted access token, and the messages exchanged between your business and your customers, so they appear in your unified inbox. Our Meta-specific data-deletion instructions are at voice.cognitiev.com/data-deletion.
  • Telephony providers (Twilio, SIP trunks you bring) — phone numbers, credentials you supply (encrypted), and call signalling data.
  • CRMs and webhooks — API keys you supply (encrypted) and the contact and activity records you choose to sync.
  • Large-language-model providers — if you bring your own API key, it is encrypted and used only for your agents.

Third-party services are governed by their own privacy policies. We encourage you to review them.

How We Share Information

We share personal data only in the following circumstances:

Sub-processors

Vendors that process data on our behalf, under contract, and only to the extent needed to deliver the Platform:

CategoryProviders
Cloud hosting, database & AI modelsMicrosoft Azure (including Azure OpenAI and Azure Speech)
Recording & file storageCloudflare R2
Real-time voice mediaLiveKit
Speech recognition & synthesisDeepgram, Cartesia, Azure Speech
Large language modelsOpenAI / Azure OpenAI
Telephony carriersTwilio and regional SIP carriers selected by the customer
Transactional emailResend
Website analytics & support chatGoogle Analytics, Intercom (cognitiev.com only)

Speech and language-model providers receive audio and text solely to process the conversation in real time under terms that prohibit training on your data. Google user data is shared only with our cloud hosting provider.

Other disclosures

  • Your instructions — for example, when your workflow pushes a lead to your CRM or sends an email through your connected mailbox.
  • Legal requirements — to comply with law, regulation, legal process or enforceable governmental request, or to protect the rights, property or safety of Cognitiev, our users or the public.
  • Business transfers — in a merger, acquisition or asset sale, with notice to you before your data becomes subject to a different privacy policy.

We never sell personal data and never share it with advertisers or data brokers.

Data Retention

We keep personal data only as long as necessary for the purposes described above:

  • Account data — for the life of your account and up to 30 days after deletion, except records we must keep for tax or legal reasons (up to 7 years).
  • Call recordings, transcripts and messages — according to the retention policy you configure in Settings → Data Retention (default 90 days, with automatic deletion). You may also delete individual recordings or conversations at any time.
  • Contacts and leads — until you delete them or your account is deleted.
  • Integration tokens (including Google OAuth tokens) — until you disconnect the integration or delete your account, whichever comes first.
  • Gmail reply data — follows the retention policy of the workflow that received it and is deleted with the workflow run.
  • Server and security logs — up to 90 days.
  • Backups — encrypted backups roll off within 30 days of deletion from production systems.

Deleting Your Data

You are in control of your data. You can:

  • Disconnect an integration in Dashboard → Integrations — deletes the associated tokens and integration data immediately.
  • Delete recordings, transcripts, contacts or campaigns individually from the dashboard.
  • Delete your account from Settings or by emailing [email protected]. All personal data, customer content and integration data is permanently deleted from production within 30 days, and from backups within a further 30 days.

If you are an end-user who interacted with a Cognitiev-powered agent, contact the business that contacted you; you may also write to us and we will help route your request.

Security

We apply technical and organisational measures appropriate to the sensitivity of voice and communications data, including:

  • Encryption in transit (TLS 1.2+) for all web, API and media traffic, and encryption at rest for databases and file storage.
  • Additional application-level encryption for OAuth tokens, API keys and telephony credentials.
  • Per-tenant isolation so one customer can never access another customer's data; role-based access within your workspace.
  • Signed, single-use OAuth state parameters and PKCE for integration connections.
  • Audit logging of sensitive administrative actions, monitoring and alerting.
  • Least-privilege access for Cognitiev staff, restricted to what is needed for support and operations.

No system is perfectly secure. If you believe your account has been compromised, contact us immediately at [email protected]. We will notify affected customers and regulators of a personal-data breach as required by applicable law.

International Transfers

Cognitiev is headquartered in India and operates an office in the United States. Our infrastructure providers may process data in India, the United States, the European Union and other regions where they operate. Where personal data originating in the EU/EEA, UK or Switzerland is transferred elsewhere, we rely on Standard Contractual Clauses or equivalent safeguards and require our sub-processors to do the same.

Cookies, Log Files & Analytics

cognitiev.com uses cookies and similar technologies for essential site functionality, to remember preferences, and — through Google Analytics and Intercom — to understand how visitors use the site and to offer live chat support. These tools may set their own cookies and collect IP address, browser type, referring pages and time on page. You can disable cookies in your browser settings; the site will still work.

The Vaani dashboard uses only strictly necessary cookies and local storage for authentication and session state. We do not run advertising cookies or third-party ad networks on any Cognitiev property.

Our servers keep standard access logs (IP address, user agent, request path, timestamp, response code) for security monitoring and troubleshooting. These logs are retained for up to 90 days.

Your Privacy Rights (GDPR, CCPA, DPDP)

Depending on where you live, you may have some or all of the following rights over your personal data:

Right to Access

Request copies of your personal data

Right to Rectification

Correct inaccurate or incomplete information

Right to Erasure

Request deletion of your personal data

Right to Restrict Processing

Limit how we process your data

Right to Object

Object to our processing of your data

Right to Data Portability

Receive your data in a machine-readable format

EU/EEA & UK (GDPR)

You may also withdraw consent at any time and lodge a complaint with your local supervisory authority.

California (CCPA/CPRA)

You have the right to know what personal information we collect, use and disclose; to request deletion or correction; and to not be discriminated against for exercising these rights. We do not sell or "share" (for cross-context behavioural advertising) personal information, so no opt-out is required.

India (DPDP Act 2023)

You have the right to access a summary of your personal data, to correction and erasure, to nominate another person to exercise your rights, and to grievance redressal. Our Grievance Officer can be reached at [email protected].

To exercise any right, email [email protected] from the address on your account. We respond within 30 days and may ask for information to verify your identity.

Children's Information

Cognitiev is a business platform and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or the age of digital consent in your jurisdiction). If you believe a child has provided us personal data, contact us and we will delete it promptly.

Changes to This Policy

We may update this policy as our services or the law change. We will post the new version here with an updated "Last updated" date and, for material changes, notify account owners by email or an in-app notice at least 14 days before they take effect. Continued use of the services after that date constitutes acceptance of the updated policy.

Contact Us

Questions, requests or complaints about this policy or our handling of your data can be sent to our privacy team:

Registered office (India)
Kritrima AI Technologies Private Limited
Plot No. 307, Phase 4, Udyog Vihar, Sector 18
Gurugram, Haryana - 122015, India
USA Office
17274 Ventana Drive
Boca Raton, FL 33487, USA
We aim to acknowledge every privacy request within 5 business days and to resolve it within 30 days.
Ready when you are

Ship your first AI agent this week.

Adaptive Agentic AI & Automation · CRM · Omnichannel — one platform for revenue teams that refuse to lose a lead.

Kritrima AI Technologies Pvt. Ltd.

Cognitiev is a brand of
Kritrima AI Technologies Pvt. Ltd.

USA Office

17274 Ventana Drive
Boca Raton, FL 33487, USA

Headquarter

Plot No. 307, Phase 4
Udyog Vihar, Sector 18
Gurugram, Haryana - 122015, India

Product

Company

© 2026 Kritrima AI Technologies Pvt. Ltd. · Cognitiev is a brand of Kritrima AI Technologies Pvt. Ltd.

ISO 27001·SOC 2 aligned·GDPR·DPDP