1. Executive Overview & Company Entity

Welcome to Akashic Soft Private Limited (hereinafter referred to as "ASPL", "Company", "We", "Us", or "Our"). We are an enterprise software company incorporated under the laws of India, providing cloud-native SaaS platforms for Customer Relationship Management (CRM), Customer Support Ticketing, Live Chat, Marketing Automation, Omnichannel Communication, and Cloud Telephony.

At ASPL, we understand that data privacy and security are paramount to our business customers ("Customers") and their end-users ("End-Users"). This Privacy Policy outlines our commitment to transparency, ethical data stewardship, legal compliance, and enterprise-grade data protection across all web applications, mobile applications, APIs, and associated cloud services owned and operated by ASPL.

Core Principle: ASPL acts as a Data Processor/Service Provider for customer business data and a Data Controller for account administrative data. We process data strictly to deliver contracted SaaS services and never sell, lease, or monetize customer data or integration data.

2. Product Ecosystem Scope

This Privacy Policy governs all products, services, platforms, and features offered under the Assign Ecosystem by Akashic Soft Private Limited, including but not limited to:

  • AssignSales (CRM): Cloud CRM platform for pipeline management, lead capture, sales automation, and deal tracking.
  • AssignTeams (Helpdesk): Omni-channel customer support desk, ticketing system, and knowledge-base management.
  • AssignChat (Helpdesk Live Chat & Messaging): Real-time live chat widget, website messaging, and social messaging aggregation.
  • AssignHours (Marketing Automation): Multi-channel marketing automation, lead nurturing, campaign tracking, and analytics.
  • AssignVoice (Cloud Telephony & Dialer): Cloud telephony integration, call recording, outbound dialer, and IVR workflows.

By accessing or using any product in the Assign Ecosystem, registering an account, or interacting with our websites, you acknowledge that you have read and understood this Privacy Policy.

3. Information We Collect

We collect information through three primary channels:

A. Information Provided Directly by You (Account Administration)

  • Account Details: Full name, professional email address, phone number, company name, domain, job title, and password credentials.
  • Billing Information: Business address, tax registration details (GSTIN/VAT), credit card or bank details (processed securely via PCI-DSS compliant payment gateways).
  • Support Communications: Inquiries, feedback, ticket submissions, and correspondence sent to our support teams.

B. Customer Data Processed on Behalf of Customers (Service Data)

When businesses utilize our Assign products, they upload or transmit customer content into our platform, including:

  • Contact records, lead demographics, custom contact attributes, deal histories, and notes in AssignSales CRM.
  • Support tickets, customer messages, agent resolution logs, and attachment files in AssignTeams Helpdesk.
  • Live chat transcripts, visitor session metadata, and web interaction logs in AssignChat.
  • Subscriber lists, email/SMS message templates, and campaign engagement metrics in AssignHours.
  • Call logs, phone numbers, caller IDs, call recordings, and telephony metadata in AssignVoice.

C. Automatically Collected Technical Data

  • Device & Browser Info: IP address, operating system, browser type, language preferences, device identifiers.
  • Usage Analytics: Page views, feature usage frequency, response latencies, error logs, and session durations.

4. Meta Platform & Third-Party API Integrations

To enable seamless omnichannel customer communication, the Assign Product Ecosystem integrates with third-party platforms including Meta Platforms, Inc. (Facebook, Instagram, WhatsApp), Google Workspace, and cloud telephony carriers.

Meta Developer & WhatsApp Business API Compliance Notice

ASPL integrates with Meta APIs (Facebook Lead Ads, WhatsApp Business Platform API, Facebook Page Messenger API, Instagram Graph API, and Facebook Login) to aggregate incoming business leads and customer messaging directly into AssignSales CRM, AssignTeams, and AssignChat.

  • Data Accessed via Meta APIs: Lead Form submissions (name, email, phone, custom questions), WhatsApp messages/media/phone numbers, Messenger chat transcripts, Page IDs, and User IDs.
  • Strict Data Usage Boundary: Meta API data is accessed exclusively to display, manage, automate, and respond to incoming conversations or leads inside the customer's Assign account.
  • Non-Monetization Commitment: ASPL strictly complies with Meta Developer Data Use Policy (Sections 4.b and 4.d). We never sell, transfer, disclose, or use Meta user data for cross-app tracking, targeted advertising, data broker profiling, or marketing purposes.

Google API Integrations

If you connect Google Workspace (e.g., Gmail, Google Calendar) to AssignSales or AssignTeams, our access and use of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements.

5. How We Use Your Information

ASPL processes collected data solely for legitimate, contracted operational purposes:

Data Category Primary Purpose Legal Basis / Standard
Account & Billing Data Provisioning accounts, billing, sending transactional notifications, platform security. Contractual Performance & Legal Obligation
Customer Content (CRM/Helpdesk Data) Storing, routing, displaying, and executing customer-configured workflows. Performance of Service Agreement (Data Processor)
Meta & Third-Party API Data Syncing lead forms, enabling multi-channel chat, sending WhatsApp responses. User Authorization & Explicit Integration Request
Technical & Log Data System performance monitoring, fault diagnostics, DDoS prevention, security auditing. Legitimate Interest (Security & Availability)

6. Data Security & Infrastructure Safeguards

ASPL implements multi-layered enterprise security controls aligned with ISO/IEC 27001 standards and SOC 2 security principles:

  • Encryption in Transit: All data transmitted between clients, web applications, and servers is encrypted using modern TLS 1.3 / HTTPS encryption.
  • Encryption at Rest: Customer database records, file attachments, and backups are encrypted using AES-256 bit encryption algorithms.
  • Tenant Data Isolation: Logical separation is enforced across all customer data layers inside our cloud database infrastructure to prevent cross-tenant data access.
  • Access Control: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) govern administrative access to production infrastructure.
  • Vulnerability Management: Regular vulnerability scanning, code audits, and third-party penetration testing are conducted continuously.

7. Data Retention & Deletion Schedules

We retain personal and business data only for as long as necessary to fulfill the purposes for which it was collected or to satisfy legal, accounting, and regulatory obligations.

  • Active Accounts: Customer Data is retained for the duration of the active subscription agreement.
  • Account Cancellation / Expiration: Upon account termination, Customer Data enters a 30-day grace period during which the customer may request a full data export. Following 30 days, all customer content and connected API tokens are permanently purged from active databases.
  • Backup Lifecycle: Encrypted system database backups are automatically overwritten and purged on a 60-day rolling lifecycle.

8. User Rights & Meta Data Deletion Mechanism

Pursuant to global privacy laws (DPDP Act 2023, GDPR, CCPA) and Meta Platform Guidelines, users and end-users have explicit rights regarding their personal data.

Your Privacy Rights

  • Right to Access & Portability: Request a copy of all personal data held by ASPL in a structured, machine-readable format.
  • Right to Rectification: Update or correct inaccurate personal details.
  • Right to Erasure (Right to be Forgotten): Request permanent deletion of personal records.
  • Right to Revoke Authorization: Disconnect Meta, Google, or telephony integrations at any time via platform settings.

Meta User Data Deletion Request & Callback Instructions

If you interact with an ASPL-powered Assign product via Facebook, Instagram, or WhatsApp and wish to delete your data or revoke app permissions:

  1. Via Facebook/Meta Account: Navigate to your Facebook Profile > Settings & Privacy > Settings > Apps and Websites > Find Assign Sales / Akashic Soft > Click Remove and select Request Data Deletion.
  2. Via Direct Request to ASPL: Email your data deletion request directly to our Data Protection Officer at support@akashicsoft.com with the subject line "Meta Data Deletion Request" along with your phone number/Facebook User ID.

Processing Timeline: Data deletion requests are acknowledged within 48 hours and completed within 14 business days. A confirmation receipt with a tracking code is issued upon completion.

9. Third-Party Sub-processors

ASPL engages trusted third-party infrastructure and technology providers to assist in delivering SaaS services. All sub-processors undergo rigorous security evaluation and are legally bound by Data Processing Agreements (DPAs):

Sub-processor Service Provided Location
Amazon Web Services (AWS) / Google Cloud Cloud Infrastructure, Hosting, Managed Relational Databases India / US
Meta Platforms, Inc. WhatsApp Business API, Facebook Lead Ads, Messenger API USA / Global
Twilio / Telecom Partners SMS Gateway & Voice Telephony Carrier Services Global / India
Razorpay / Stripe PCI-DSS Compliant Payment Processing India / USA

10. Cookie & Tracking Technologies Policy

Our web applications use cookies and similar session tracking mechanisms to enhance user experience, preserve active logins, and collect aggregate analytics:

  • Essential Cookies: Required for account authentication, security validation, and session state maintenance.
  • Functional Cookies: Remember user settings, layout preferences, and language selections.
  • Analytics Cookies: Help us measure site traffic, page popularities, and feature usage patterns to improve platform utility.

You can control or disable cookies via your browser preferences. However, disabling essential cookies may impact account accessibility and functionality.

11. Regulatory Framework Compliance

ASPL operates in compliance with premier international and national data protection standards:

  • Digital Personal Data Protection (DPDP) Act 2023 (India): Strict adherence to notice, explicit consent, purpose limitation, and data principal rights.
  • Information Technology Act, 2000 (India): Compliance with Section 43A and Information Technology (Reasonable Security Practices and Procedures) Rules.
  • General Data Protection Regulation (GDPR - EU/UK): Full support for Data Subject Rights, Standard Contractual Clauses (SCCs), and Data Processing Addendums.
  • California Consumer Privacy Act (CCPA/CPRA): Transparency regarding data categories and explicit guarantee of non-sale of personal data.

12. Grievance Officer & Contact Information

In accordance with the Information Technology Act 2000 and Digital Personal Data Protection Act 2023, the details of our designated Grievance Officer / Data Protection Officer (DPO) are provided below:

Data Protection & Grievance Officer

Company Entity: Akashic Soft Private Limited (ASPL)

Attention: Privacy & Legal Grievance Cell

Email: support@akashicsoft.com

Official Website: https://akashicsoft.com

Country: India

We aim to respond to all formal privacy complaints, access requests, or deletion notices within 48 hours of receipt.