Privacy Policy
Akashic Soft Private Limited (ASPL) & The Assign Product Ecosystem
1. Executive Overview & Company Entity
Welcome to Akashic Soft Private Limited (hereinafter referred to as "ASPL", "Company", "We", "Us", or "Our"). We are an enterprise software company incorporated under the laws of India, providing cloud-native SaaS platforms for Customer Relationship Management (CRM), Customer Support Ticketing, Live Chat, Marketing Automation, Omnichannel Communication, and Cloud Telephony.
At ASPL, we understand that data privacy and security are paramount to our business customers ("Customers") and their end-users ("End-Users"). This Privacy Policy outlines our commitment to transparency, ethical data stewardship, legal compliance, and enterprise-grade data protection across all web applications, mobile applications, APIs, and associated cloud services owned and operated by ASPL.
2. Product Ecosystem Scope
This Privacy Policy governs all products, services, platforms, and features offered under the Assign Ecosystem by Akashic Soft Private Limited, including but not limited to:
- AssignSales (CRM): Cloud CRM platform for pipeline management, lead capture, sales automation, and deal tracking.
- AssignTeams (Helpdesk): Omni-channel customer support desk, ticketing system, and knowledge-base management.
- AssignChat (Helpdesk Live Chat & Messaging): Real-time live chat widget, website messaging, and social messaging aggregation.
- AssignHours (Marketing Automation): Multi-channel marketing automation, lead nurturing, campaign tracking, and analytics.
- AssignVoice (Cloud Telephony & Dialer): Cloud telephony integration, call recording, outbound dialer, and IVR workflows.
By accessing or using any product in the Assign Ecosystem, registering an account, or interacting with our websites, you acknowledge that you have read and understood this Privacy Policy.
3. Information We Collect
We collect information through three primary channels:
A. Information Provided Directly by You (Account Administration)
- Account Details: Full name, professional email address, phone number, company name, domain, job title, and password credentials.
- Billing Information: Business address, tax registration details (GSTIN/VAT), credit card or bank details (processed securely via PCI-DSS compliant payment gateways).
- Support Communications: Inquiries, feedback, ticket submissions, and correspondence sent to our support teams.
B. Customer Data Processed on Behalf of Customers (Service Data)
When businesses utilize our Assign products, they upload or transmit customer content into our platform, including:
- Contact records, lead demographics, custom contact attributes, deal histories, and notes in AssignSales CRM.
- Support tickets, customer messages, agent resolution logs, and attachment files in AssignTeams Helpdesk.
- Live chat transcripts, visitor session metadata, and web interaction logs in AssignChat.
- Subscriber lists, email/SMS message templates, and campaign engagement metrics in AssignHours.
- Call logs, phone numbers, caller IDs, call recordings, and telephony metadata in AssignVoice.
C. Automatically Collected Technical Data
- Device & Browser Info: IP address, operating system, browser type, language preferences, device identifiers.
- Usage Analytics: Page views, feature usage frequency, response latencies, error logs, and session durations.
4. Meta Platform & Third-Party API Integrations
To enable seamless omnichannel customer communication, the Assign Product Ecosystem integrates with third-party platforms including Meta Platforms, Inc. (Facebook, Instagram, WhatsApp), Google Workspace, and cloud telephony carriers.
Google API Integrations
If you connect Google Workspace (e.g., Gmail, Google Calendar) to AssignSales or AssignTeams, our access and use of information received from Google APIs adheres strictly to the Google API Services User Data Policy, including the Limited Use requirements.
5. How We Use Your Information
ASPL processes collected data solely for legitimate, contracted operational purposes:
| Data Category | Primary Purpose | Legal Basis / Standard |
|---|---|---|
| Account & Billing Data | Provisioning accounts, billing, sending transactional notifications, platform security. | Contractual Performance & Legal Obligation |
| Customer Content (CRM/Helpdesk Data) | Storing, routing, displaying, and executing customer-configured workflows. | Performance of Service Agreement (Data Processor) |
| Meta & Third-Party API Data | Syncing lead forms, enabling multi-channel chat, sending WhatsApp responses. | User Authorization & Explicit Integration Request |
| Technical & Log Data | System performance monitoring, fault diagnostics, DDoS prevention, security auditing. | Legitimate Interest (Security & Availability) |
6. Data Security & Infrastructure Safeguards
ASPL implements multi-layered enterprise security controls aligned with ISO/IEC 27001 standards and SOC 2 security principles:
- Encryption in Transit: All data transmitted between clients, web applications, and servers is encrypted using modern TLS 1.3 / HTTPS encryption.
- Encryption at Rest: Customer database records, file attachments, and backups are encrypted using AES-256 bit encryption algorithms.
- Tenant Data Isolation: Logical separation is enforced across all customer data layers inside our cloud database infrastructure to prevent cross-tenant data access.
- Access Control: Strict Role-Based Access Control (RBAC) and Multi-Factor Authentication (MFA) govern administrative access to production infrastructure.
- Vulnerability Management: Regular vulnerability scanning, code audits, and third-party penetration testing are conducted continuously.
7. Data Retention & Deletion Schedules
We retain personal and business data only for as long as necessary to fulfill the purposes for which it was collected or to satisfy legal, accounting, and regulatory obligations.
- Active Accounts: Customer Data is retained for the duration of the active subscription agreement.
- Account Cancellation / Expiration: Upon account termination, Customer Data enters a 30-day grace period during which the customer may request a full data export. Following 30 days, all customer content and connected API tokens are permanently purged from active databases.
- Backup Lifecycle: Encrypted system database backups are automatically overwritten and purged on a 60-day rolling lifecycle.
8. User Rights & Meta Data Deletion Mechanism
Pursuant to global privacy laws (DPDP Act 2023, GDPR, CCPA) and Meta Platform Guidelines, users and end-users have explicit rights regarding their personal data.
Your Privacy Rights
- Right to Access & Portability: Request a copy of all personal data held by ASPL in a structured, machine-readable format.
- Right to Rectification: Update or correct inaccurate personal details.
- Right to Erasure (Right to be Forgotten): Request permanent deletion of personal records.
- Right to Revoke Authorization: Disconnect Meta, Google, or telephony integrations at any time via platform settings.
Meta User Data Deletion Request & Callback Instructions
If you interact with an ASPL-powered Assign product via Facebook, Instagram, or WhatsApp and wish to delete your data or revoke app permissions:
- Via Facebook/Meta Account: Navigate to your Facebook Profile > Settings & Privacy > Settings > Apps and Websites > Find Assign Sales / Akashic Soft > Click Remove and select Request Data Deletion.
- Via Direct Request to ASPL: Email your data deletion request directly to our Data Protection Officer at support@akashicsoft.com with the subject line
"Meta Data Deletion Request"along with your phone number/Facebook User ID.
Processing Timeline: Data deletion requests are acknowledged within 48 hours and completed within 14 business days. A confirmation receipt with a tracking code is issued upon completion.
9. Third-Party Sub-processors
ASPL engages trusted third-party infrastructure and technology providers to assist in delivering SaaS services. All sub-processors undergo rigorous security evaluation and are legally bound by Data Processing Agreements (DPAs):
| Sub-processor | Service Provided | Location |
|---|---|---|
| Amazon Web Services (AWS) / Google Cloud | Cloud Infrastructure, Hosting, Managed Relational Databases | India / US |
| Meta Platforms, Inc. | WhatsApp Business API, Facebook Lead Ads, Messenger API | USA / Global |
| Twilio / Telecom Partners | SMS Gateway & Voice Telephony Carrier Services | Global / India |
| Razorpay / Stripe | PCI-DSS Compliant Payment Processing | India / USA |
11. Regulatory Framework Compliance
ASPL operates in compliance with premier international and national data protection standards:
- Digital Personal Data Protection (DPDP) Act 2023 (India): Strict adherence to notice, explicit consent, purpose limitation, and data principal rights.
- Information Technology Act, 2000 (India): Compliance with Section 43A and Information Technology (Reasonable Security Practices and Procedures) Rules.
- General Data Protection Regulation (GDPR - EU/UK): Full support for Data Subject Rights, Standard Contractual Clauses (SCCs), and Data Processing Addendums.
- California Consumer Privacy Act (CCPA/CPRA): Transparency regarding data categories and explicit guarantee of non-sale of personal data.
12. Grievance Officer & Contact Information
In accordance with the Information Technology Act 2000 and Digital Personal Data Protection Act 2023, the details of our designated Grievance Officer / Data Protection Officer (DPO) are provided below:
Data Protection & Grievance Officer
Company Entity: Akashic Soft Private Limited (ASPL)
Attention: Privacy & Legal Grievance Cell
Email: support@akashicsoft.com
Official Website: https://akashicsoft.com
Country: India
We aim to respond to all formal privacy complaints, access requests, or deletion notices within 48 hours of receipt.