Privacy Policy
This Privacy Policy explains how [Legal Entity Name Pvt. Ltd.] ("Widgenix", "we", "us") collects, uses, discloses, and protects personal data through our website, dashboard, and embedded AI chat and voice widgets.
This is a template drafted to match Widgenix's actual data flows. It is not a substitute for review by a qualified lawyer, particularly one familiar with Indian, EU/UK, and US privacy law, before you publish it as binding.
1. Scope & our role
Widgenix operates in two distinct roles, and this policy is written to reflect both:
- As a data controller — for our own website visitors, marketing leads, and the admin accounts of businesses that sign up for Widgenix (billing contacts, team members, usage data).
- As a data processor— for the end-users ("widget visitors") who interact with a chat or voice widget embedded by one of our business customers on their own website. In that relationship, our customer is the controller and instructs us on how their visitors' data may be used. Our processing obligations to customers are set out in our Data Processing Agreement (DPA), which takes precedence over this notice for that data.
2. Information we collect
Account & admin data
- Name, email address, phone number, and password (stored hashed, never in plain text)
- Company name, billing address, and payment details (processed by Stripe — we do not store full card numbers)
- Team member roles and permissions, if you invite collaborators
- Usage and billing metrics: message volume, voice usage, and associated costs
- Authentication cookies / session tokens used to keep you signed in
- Support communications you send us
Knowledge base content
Documents, URLs, FAQs, and other content you upload to train your AI agent. This content is used solely to power your agent's responses and is not used to train shared or general-purpose models unless we have your explicit, separate consent to do so.
3. Widget visitor data
When a visitor interacts with a chat or voice widget embedded by one of our business customers, we process the following on that customer's behalf:
- A session identifier stored in the visitor's browser (
localStorage) to maintain conversation continuity - Chat message content and conversation history, stored in our database
- Optional lead information the visitor submits: name, email, phone number, and message
- For the voice widget: speech is converted to text in the browser where possible; resulting text is sent to our backend, and spoken responses are generated via our text-to-speech provider
- The embedding website's origin (
parentOrigin), used for security validation - IP address, used transiently for rate-limiting and abuse prevention — we do not retain IP addresses beyond what is operationally necessary
- If configured by our customer, data may be forwarded to their own systems via webhooks (e.g., CRM sync, lead notification)
If you are a visitor to a website using a Widgenix-powered widget and have questions about how your data is handled, the website you visited (our customer) is the right first point of contact, since they control what the widget is configured to do. You can also reach us directly using the details in Section 15.
4. How we use information
- To provide, operate, and maintain the Widgenix platform and embedded widgets
- To train and power AI agent responses using the knowledge base a customer provides
- To process payments and manage subscriptions
- To monitor usage against plan quotas and calculate billing
- To detect, prevent, and investigate fraud, abuse, or security incidents
- To respond to support requests and account inquiries
- To send service-related communications (billing, security notices, product updates)
- With separate consent, to send marketing communications, which you may opt out of at any time
5. Legal bases (GDPR)
Where GDPR applies, we rely on the following legal bases:
| Processing activity | Legal basis |
|---|---|
| Providing the core service to admin account holders | Performance of a contract |
| Processing widget visitor data | Performance of our contract with the business customer (as processor) |
| Billing and fraud prevention | Legitimate interests / legal obligation |
| Marketing communications | Consent (withdrawable at any time) |
| Security monitoring and abuse prevention | Legitimate interests |
6. Cookies & similar technology
We use essential cookies (authentication, security) and, where enabled, optional analytics cookies. Full details, including how to manage your preferences, are in our Cookie Policy.
7. Who we share data with
We do not sell personal data. We share data with the following categories of service providers, strictly to operate Widgenix:
| Provider | Purpose | Location |
|---|---|---|
| OpenRouter | LLM inference for chat and RAG-based responses | United States |
| ElevenLabs | Text-to-speech voice synthesis for the voice widget | United States |
| Stripe | Payment processing and subscription billing | United States / Ireland (Stripe Payments Europe) |
| [Hosting provider, e.g. Vercel / AWS / Render] | Application hosting and infrastructure | [Region(s) — disclose if data residency matters to your customers] |
| [Database provider, e.g. Supabase / Neon / RDS] | Storage of chat logs, leads, and account data | [Region(s)] |
We may also disclose information if required by law, to enforce our Terms of Service, or to protect the rights, property, or safety of Widgenix, our customers, or others.
8. International transfers
Widgenix and several of our sub-processors operate outside India, including in the United States. Where we transfer personal data internationally, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) with our processors, and we take steps to ensure recipients provide an adequate level of protection consistent with GDPR, India's DPDP Act, 2023, and other applicable transfer rules.
9. Data retention
- Account data is retained for as long as your account is active, plus a reasonable period afterward for legal, tax, and dispute-resolution purposes
- Chat and voice logs are retained according to your plan's configured retention setting, or until you delete them via the dashboard
- Billing records are retained as required by applicable tax and accounting law
- We do not currently auto-delete chat logs by default — if you need shorter retention, configure it in your dashboard settings or contact us
10. Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data
- Object to or restrict certain processing
- Receive a portable copy of your data
- Withdraw consent at any time, where processing is based on consent
- Opt out of the sale or sharing of personal data (we do not currently sell data)
- Lodge a complaint with your local data protection authority
To exercise any of these rights, contact us at privacy@widgenix.ai. We will respond within the timeframe required by applicable law.
11. India-specific disclosures
As an Indian company, we also comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021.
- We process personal data only for lawful purposes disclosed in this policy, or with your consent
- You may withdraw consent at any time, with effect going forward, by contacting our Grievance Officer below
- You may nominate another individual to exercise your rights on your behalf in the event of death or incapacity, per the DPDP Act
Grievance Officer: [Grievance Officer Full Name]
Email: grievance@widgenix.ai
Phone: [+91-XXXXXXXXXX]
Address: [Same as registered office, or designated address]
We acknowledge grievances within 24 hours and aim to resolve them within 15 days, as required under the IT Rules, 2021.
12. Children's privacy
Widgenix is not directed at children under 13 (or the relevant age of digital consent in your jurisdiction), and we do not knowingly collect personal data from children. If you operate a website directed at children and wish to embed a Widgenix widget, contact us first — additional safeguards and consent mechanisms (e.g., under COPPA) will apply, and standard deployment is not appropriate without them.
13. Security
We use industry-standard measures to protect personal data, including encryption in transit (TLS) and at rest, access controls, and regular review of our infrastructure. No system is completely secure, and we encourage you to use strong, unique passwords and enable any available account security features.
Note on compliance certifications: Any claims about specific certifications (such as SOC 2 or ISO 27001) on our marketing pages are only accurate once we have completed the relevant audit. Do not publish such claims until they are true — see the launch checklist in the project README.
14. Changes to this policy
We may update this policy from time to time. If changes are material, we will notify registered users by email or an in-product notice before the changes take effect. The "Last updated" date at the top of this page always reflects the current version.
15. Contact us
[Legal Entity Name Pvt. Ltd.]
[Registered office address, City, State, PIN, India]
Privacy inquiries: privacy@widgenix.ai
General support: support@widgenix.ai
