Global Privacy Policy

Last Updated: August 17, 2026

Important Notice: This Privacy Policy applies globally, including to residents of India, the European Economic Area (EEA), the United Kingdom (UK), and the United States (including California). It complies with the Indian Digital Personal Data Protection Act 2023 (DPDP Act), the EU & UK General Data Protection Regulation (GDPR), and the California Consumer Privacy Act (CCPA).

1. Introduction & Data Controller

Welcome to Tenzor ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This Privacy Policy informs you about how we collect, process, and protect your personal data when you visit our website (tenzorai.in) or use our AI chatbot, voice agent, and business automation services (the "Services").

For the purposes of applicable data protection laws, Tenzor (located in Ahmedabad, Gujarat, India) is the Data Controller (or "Data Fiduciary" under Indian law) of your personal data.

2. The Data We Collect About You

We may collect, use, store, and transfer different kinds of personal data about you, which we have grouped together as follows:

  • Identity & Contact Data: First name, last name, email address, telephone number, and professional details provided via our contact forms or Calendly bookings.
  • Technical Data: Internet Protocol (IP) address, browser type and version, time zone setting, location, browser plug-in types and versions, operating system, and platform.
  • Interaction & Communications Data: Chat transcripts, voice recordings (if interacting with our AI Voice Agents), customer service communications, and feedback.
  • Usage Data: Information about how you use our website, products, and services (collected via cookies and analytics).

3. AI Processing & Third-Party APIs

Our core services involve Artificial Intelligence. When you interact with our chatbots or voice agents, your text and voice inputs are processed in real-time to generate responses.

  • LLM Providers: We utilize enterprise-grade APIs from OpenAI, Anthropic (Claude), Google (Gemini), and Groq. Data transmitted to these APIs is strictly for generating responses. We do not permit these providers to use your personal data to train their foundational models.
  • Voice Services: For AI Voice Agents, audio streams are processed by Vapi and ElevenLabs. Voice data is processed ephemerally for transcription and synthesis.

4. Lawful Basis for Processing (UK/EU GDPR & DPDP Act)

We will only process your personal data when the law allows us to. Our lawful bases include:

  • Consent: Where you have provided verifiable consent (e.g., accepting non-essential cookies, consenting to voice processing, or subscribing to marketing).
  • Performance of a Contract: Where processing is necessary to deliver our Services, provide a consultation, or fulfill a contract with you.
  • Legitimate Interests: Where necessary for our legitimate business interests (e.g., improving our AI models, securing our website, preventing fraud), provided your fundamental rights do not override these interests.
  • Legal Obligation: Where necessary to comply with a legal or regulatory obligation.

5. Disclosures of Your Personal Data

We do not sell your personal data. We may share your personal data with trusted third-party processors ("Data Processors") strictly for the purposes set out in this policy:

  • Infrastructure & Hosting: Vercel (Frontend Hosting) and Railway (Backend Hosting).
  • Communication & Scheduling: Calendly (booking meetings), Formspree/Resend (email routing).
  • Analytics: Website analytics providers.
  • Professional Advisers: Lawyers, bankers, auditors, and insurers who provide consultancy, banking, legal, insurance, and accounting services.

6. International Data Transfers

Tenzor is based in India. By using our Services, your data will be processed in India and may be transferred to servers located in the United States or the European Union (where our cloud providers and AI partners operate).

For EEA/UK Users: When we transfer your personal data out of the EEA or UK, we ensure a similar degree of protection is afforded to it by utilizing safeguards such as the European Commission's Standard Contractual Clauses (SCCs) or ensuring the destination country has an adequacy decision.

7. Data Security & Retention

We have implemented appropriate technical and organizational measures designed to secure your personal data from accidental loss and from unauthorized access, use, alteration, and disclosure (including encryption in transit and at rest).

We will only retain your personal data for as long as reasonably necessary to fulfill the purposes we collected it for, including for the purposes of satisfying any legal, regulatory, tax, accounting, or reporting requirements.

8. Your Data Protection Rights

Depending on your jurisdiction (including the EU, UK, and India), you have the right to:

  • Request Access: Receive a copy of the personal data we hold about you.
  • Request Correction: Have any incomplete or inaccurate data corrected.
  • Request Erasure ("Right to be Forgotten"): Ask us to delete personal data where there is no good reason for us continuing to process it.
  • Object to Processing: Object to processing where we rely on a legitimate interest or process for direct marketing.
  • Request Restriction: Ask us to suspend the processing of your personal data.
  • Data Portability: Request the transfer of your data to you or a third party in a machine-readable format.
  • Withdraw Consent: Withdraw consent at any time where we rely on consent to process your personal data.

To exercise these rights, please contact our Grievance Officer.

9. Children's Privacy

Our Services are not directed to individuals under the age of 18 (or the age of majority in your jurisdiction). We do not knowingly collect personal data from children. Under the Indian DPDP Act, processing of children's data requires verifiable parental consent. Under COPPA (US), we do not collect data from children under 13. Under GDPR (EU/UK), we do not process data of children under 16 without parental consent. If we become aware that we have collected personal data from a child without appropriate consent, we will take steps to delete that information promptly. If you believe your child has provided us with personal data, please contact our Grievance Officer immediately.

10. Additional Rights for US Residents (CCPA/CPRA)

If you are a resident of California or other US states with applicable privacy laws, this section applies to you.

  • Notice at Collection: We collect identifiers, commercial information, and internet activity as described in Section 2.
  • No Sale or Sharing of Personal Information: We do not "sell" or "share" (for cross-context behavioral advertising) your personal information as defined by the CCPA. We do not use third-party advertising trackers.
  • Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

11. Grievance Officer & Contact Details

In compliance with the Indian Digital Personal Data Protection Act (DPDP), 2023, and the Information Technology Rules, 2011, we have appointed a Grievance Officer to address your concerns regarding data privacy.

Grievance Officer / Data Protection Officer

Name: Pankit Shah

Email: tenzorai2004@gmail.com

Location: Ahmedabad, Gujarat, India

EEA/UK Residents: If you are located in the EEA or UK, you also have the right to lodge a complaint with your local supervisory authority (e.g., the Information Commissioner's Office in the UK) if you believe our processing of your personal data violates applicable law. We would, however, appreciate the chance to deal with your concerns before you approach the authority.