Privacy Policy
This policy explains what personal data Cognitiev collects through our website and the Vaani platform, why we collect it, how long we keep it, who we share it with, and how you can delete it.
Privacy Topics
16 sections
Overview & Scope
This Privacy Policy is issued by Kritrima AI Technologies Private Limited, doing business as Cognitiev ("Cognitiev", "we", "us" or "our"). It applies to:
- our marketing website at cognitiev.com and its sub-domains;
- the Vaani agentic AI platform, including the web dashboard at voice.cognitiev.com, our API at api.cognitiev.com, the embeddable website voice widget, and our mobile and desktop clients (together, the "Platform");
- AI voice and messaging agents that our customers deploy using the Platform to talk to their own customers, leads and callers.
By creating an account or using the Platform you agree to this policy and to our Terms of Service. If you do not agree, please do not use our services.
Our Role: Controller vs. Processor
Vaani is a business-to-business platform. Understanding who is responsible for which data helps you exercise your rights with the right party:
Cognitiev as data controller
For website visitors, prospects and the people who register and administer a Cognitiev account, we decide how and why personal data is processed.
Cognitiev as data processor
For contacts, leads, callers and message recipients that our customers upload or interact with through their AI agents, the customer is the controller. We process that data only on the customer's instructions.
If you received a call, message or email from an AI agent powered by Cognitiev and want to exercise your rights, please contact the business that contacted you. We will assist them, and you can also reach us directly (see ).
Information We Collect
1. Account information you provide
Name, company name, business address, email address, phone number, password (stored as a salted hash), billing details processed by our payment provider, and any information you send us when you contact support.
2. Customer content you create or upload
- Agent configurations, prompts, knowledge-base documents and workflow definitions.
- Contact and lead lists (names, phone numbers, email addresses, custom fields) that you import or sync from your CRM.
- Campaign schedules, call scripts and message templates.
3. Communication data generated by your agents
- Call metadata — caller and callee numbers, timestamps, duration, outcome and cost.
- Call recordings — audio of calls, only when recording is enabled on the agent or phone number. You are responsible for obtaining any consent your jurisdiction requires from callers.
- Transcripts and AI summaries — text produced by speech recognition and language models during and after conversations.
- Messages — SMS, WhatsApp, Instagram, Facebook Messenger and email conversations routed through connected channels, including sender identifiers and timestamps.
4. Integration data
When you connect a third-party service (Google Calendar, Gmail, Meta, CRMs, telephony providers) we receive the access tokens and the specific data described in the sections below. Tokens are encrypted at rest.
5. Technical and usage data
IP address, browser and device type, pages visited, feature usage, API request logs and error diagnostics. On cognitiev.com we also use cookies and analytics as described under .
How We Use Information
We use personal data for the following purposes and legal bases:
| Purpose | Legal basis |
|---|---|
| Provide the Platform: run AI agents, place and receive calls, send messages, book appointments, execute workflows | Contract |
| Transcribe, summarise and analyse conversations so you can review outcomes and quality | Contract / customer instructions |
| Authenticate users, secure accounts, detect fraud, abuse and spam calling | Legitimate interest / legal obligation |
| Billing, usage metering and invoicing | Contract / legal obligation |
| Customer support and service communications | Contract |
| Product analytics and improving reliability of our own service | Legitimate interest |
| Marketing emails to prospects and account owners (you can opt out at any time) | Consent / legitimate interest |
| Complying with telecom, tax and other laws and responding to lawful requests | Legal obligation |
Google API Services & Google User Data
The Platform offers two optional integrations with Google that you, as an account administrator, can enable from Dashboard → Integrations in the Vaani app: Google Calendar (appointment booking) and Gmail (reply detection for email workflows). Google sign-in is not used to log in to Cognitiev; each integration asks for its own consent through Google's OAuth 2.0 consent screen. See our Google integration overview for a walkthrough.
Scopes we request and why
| Scope | What it gives access to | Why we need it |
|---|---|---|
| openid, email | Your Google account ID and primary email address. | Identify which Google account is connected, display it in your Integrations page, and prevent duplicate or mismatched connections. We do not request your Google profile name or photo. |
| calendar.calendarlist.readonly | The list of calendars on your account (names and IDs only). | Let you choose which calendar your AI agent should book appointments into. |
| calendar.events.freebusy | Busy/free time blocks on the selected calendar. | Check availability so the AI agent only offers open time slots to your callers and leads. |
| calendar.events | Create, update and delete events on the selected calendar. | Book, reschedule and cancel appointments that were arranged through your AI agent or workflow. We only modify events that Cognitiev itself created. |
| gmail.readonly | Read-only access to messages and threads in the connected mailbox. | Detect replies to emails your Cognitiev workflow sent, so the workflow can stop follow-ups or branch on the response. We look up specific threads and reply headers; we do not scan, index, mine or store the rest of your mailbox. |
What Google user data we store
- Your Google account ID and email address, to label the connection.
- OAuth access and refresh tokens, encrypted at rest and used only by our servers. Tokens are never sent to your browser, to other customers, or to third parties.
- The calendar you selected and the IDs of events that Cognitiev created, so we can update or cancel them later.
- For Gmail: the thread and message IDs of emails your workflow sent, and — only when a matching reply arrives — the reply's sender, recipient, subject and body text (truncated) so the workflow can act on it. Other messages in your mailbox are not stored.
How we use, share and protect it
- Google user data is used only to provide the calendar-booking and reply-detection features you enabled, and to display the resulting appointments and replies in your own dashboard.
- We do not transfer Google user data to third parties except as necessary to provide these features (our cloud hosting provider), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not use Google user data for advertising, credit-worthiness or lending decisions, or to train AI or machine-learning models.
- Humans at Cognitiev do not read Google user data except with your explicit permission (for example, a support request), where required for security or legal compliance, or when the data has been aggregated and anonymised.
Revoking access and deleting Google data
- Disconnect the integration at any time from Dashboard → Integrations. We revoke the token with Google and permanently delete the stored tokens, calendar selection and Gmail thread references immediately. Appointments already created remain on your Google Calendar unless you delete them there.
- You can also remove Cognitiev's access from your Google Account at myaccount.google.com/permissions; our next request will fail and the connection will be marked as disconnected.
- Deleting your Cognitiev account deletes all Google user data associated with it. You may also email [email protected] and we will confirm deletion within 30 days.
Other Third-Party Integrations
Besides Google, you may connect other services. In each case we receive only the data needed to operate the feature, and you can disconnect at any time from Dashboard → Integrations:
- Meta (Facebook Pages, Instagram, WhatsApp Business) — page/asset identifiers, an encrypted access token, and the messages exchanged between your business and your customers, so they appear in your unified inbox. Our Meta-specific data-deletion instructions are at voice.cognitiev.com/data-deletion.
- Telephony providers (Twilio, SIP trunks you bring) — phone numbers, credentials you supply (encrypted), and call signalling data.
- CRMs and webhooks — API keys you supply (encrypted) and the contact and activity records you choose to sync.
- Large-language-model providers — if you bring your own API key, it is encrypted and used only for your agents.
Third-party services are governed by their own privacy policies. We encourage you to review them.
How We Share Information
We share personal data only in the following circumstances:
Sub-processors
Vendors that process data on our behalf, under contract, and only to the extent needed to deliver the Platform:
| Category | Providers |
|---|---|
| Cloud hosting, database & AI models | Microsoft Azure (including Azure OpenAI and Azure Speech) |
| Recording & file storage | Cloudflare R2 |
| Real-time voice media | LiveKit |
| Speech recognition & synthesis | Deepgram, Cartesia, Azure Speech |
| Large language models | OpenAI / Azure OpenAI |
| Telephony carriers | Twilio and regional SIP carriers selected by the customer |
| Transactional email | Resend |
| Website analytics & support chat | Google Analytics, Intercom (cognitiev.com only) |
Speech and language-model providers receive audio and text solely to process the conversation in real time under terms that prohibit training on your data. Google user data is shared only with our cloud hosting provider.
Other disclosures
- Your instructions — for example, when your workflow pushes a lead to your CRM or sends an email through your connected mailbox.
- Legal requirements — to comply with law, regulation, legal process or enforceable governmental request, or to protect the rights, property or safety of Cognitiev, our users or the public.
- Business transfers — in a merger, acquisition or asset sale, with notice to you before your data becomes subject to a different privacy policy.
We never sell personal data and never share it with advertisers or data brokers.
Data Retention
We keep personal data only as long as necessary for the purposes described above:
- Account data — for the life of your account and up to 30 days after deletion, except records we must keep for tax or legal reasons (up to 7 years).
- Call recordings, transcripts and messages — according to the retention policy you configure in Settings → Data Retention (default 90 days, with automatic deletion). You may also delete individual recordings or conversations at any time.
- Contacts and leads — until you delete them or your account is deleted.
- Integration tokens (including Google OAuth tokens) — until you disconnect the integration or delete your account, whichever comes first.
- Gmail reply data — follows the retention policy of the workflow that received it and is deleted with the workflow run.
- Server and security logs — up to 90 days.
- Backups — encrypted backups roll off within 30 days of deletion from production systems.
Deleting Your Data
You are in control of your data. You can:
- Disconnect an integration in Dashboard → Integrations — deletes the associated tokens and integration data immediately.
- Delete recordings, transcripts, contacts or campaigns individually from the dashboard.
- Delete your account from Settings or by emailing [email protected]. All personal data, customer content and integration data is permanently deleted from production within 30 days, and from backups within a further 30 days.
If you are an end-user who interacted with a Cognitiev-powered agent, contact the business that contacted you; you may also write to us and we will help route your request.
Security
We apply technical and organisational measures appropriate to the sensitivity of voice and communications data, including:
- Encryption in transit (TLS 1.2+) for all web, API and media traffic, and encryption at rest for databases and file storage.
- Additional application-level encryption for OAuth tokens, API keys and telephony credentials.
- Per-tenant isolation so one customer can never access another customer's data; role-based access within your workspace.
- Signed, single-use OAuth state parameters and PKCE for integration connections.
- Audit logging of sensitive administrative actions, monitoring and alerting.
- Least-privilege access for Cognitiev staff, restricted to what is needed for support and operations.
No system is perfectly secure. If you believe your account has been compromised, contact us immediately at [email protected]. We will notify affected customers and regulators of a personal-data breach as required by applicable law.
International Transfers
Cognitiev is headquartered in India and operates an office in the United States. Our infrastructure providers may process data in India, the United States, the European Union and other regions where they operate. Where personal data originating in the EU/EEA, UK or Switzerland is transferred elsewhere, we rely on Standard Contractual Clauses or equivalent safeguards and require our sub-processors to do the same.
Cookies, Log Files & Analytics
cognitiev.com uses cookies and similar technologies for essential site functionality, to remember preferences, and — through Google Analytics and Intercom — to understand how visitors use the site and to offer live chat support. These tools may set their own cookies and collect IP address, browser type, referring pages and time on page. You can disable cookies in your browser settings; the site will still work.
The Vaani dashboard uses only strictly necessary cookies and local storage for authentication and session state. We do not run advertising cookies or third-party ad networks on any Cognitiev property.
Our servers keep standard access logs (IP address, user agent, request path, timestamp, response code) for security monitoring and troubleshooting. These logs are retained for up to 90 days.
Your Privacy Rights (GDPR, CCPA, DPDP)
Depending on where you live, you may have some or all of the following rights over your personal data:
Right to Access
Request copies of your personal data
Right to Rectification
Correct inaccurate or incomplete information
Right to Erasure
Request deletion of your personal data
Right to Restrict Processing
Limit how we process your data
Right to Object
Object to our processing of your data
Right to Data Portability
Receive your data in a machine-readable format
EU/EEA & UK (GDPR)
You may also withdraw consent at any time and lodge a complaint with your local supervisory authority.
California (CCPA/CPRA)
You have the right to know what personal information we collect, use and disclose; to request deletion or correction; and to not be discriminated against for exercising these rights. We do not sell or "share" (for cross-context behavioural advertising) personal information, so no opt-out is required.
India (DPDP Act 2023)
You have the right to access a summary of your personal data, to correction and erasure, to nominate another person to exercise your rights, and to grievance redressal. Our Grievance Officer can be reached at [email protected].
To exercise any right, email [email protected] from the address on your account. We respond within 30 days and may ask for information to verify your identity.
Children's Information
Cognitiev is a business platform and is not directed to children. We do not knowingly collect personal data from anyone under 16 (or the age of digital consent in your jurisdiction). If you believe a child has provided us personal data, contact us and we will delete it promptly.
Changes to This Policy
We may update this policy as our services or the law change. We will post the new version here with an updated "Last updated" date and, for material changes, notify account owners by email or an in-app notice at least 14 days before they take effect. Continued use of the services after that date constitutes acceptance of the updated policy.
Contact Us
Questions, requests or complaints about this policy or our handling of your data can be sent to our privacy team: