Privacy Policy
Last updated: 26 July 2026
This Privacy Policy explains how Prakryt Technology Services ("Prakryt", "we", "us") collects, uses, discloses, and protects personal data in connection with prakryt.com and the Sevā AI Agent, Sevā CRM, and Sevā CMS services (together, the "Services"). We've written it with reference to India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), which uses the terms Data Fiduciary (roughly, the party deciding why and how data is processed) and Data Principal (the individual the data is about) — we use those terms below alongside their more familiar equivalents.
1. Who This Policy Applies To
This policy covers personal data belonging to three different groups, and we act differently for each:
- Website visitors — anyone browsing prakryt.com, reading our docs, or filling in a contact form. Here, Prakryt is the Data Fiduciary.
- Customers — the businesses (and their staff) who sign up for Sevā AI Agent, Sevā CRM, or Sevā CMS. Here too, Prakryt is the Data Fiduciary for account and billing data.
- End Users — the customers of our Customers, who chat with a Sevā-powered agent, raise a ticket, or read a page built with Sevā CMS. For this data, our Customer is the Data Fiduciary and Prakryt processes it only on that Customer's instructions. If you're an End User and have a question about how your data is used, please contact the business you interacted with directly — they control that relationship, not us.
2. Personal Data We Collect
Account & billing data
Name, work email, business name, phone number, and billing details you provide when you sign up or upgrade a plan.
Conversation & ticket data
Messages exchanged between an End User and a Sevā AI Agent or Sevā CRM inbox, on whichever channel they used — website widget, WhatsApp, Instagram, or Messenger — along with metadata like timestamps and channel.
Content you upload
FAQs, product catalogs, documents, and other knowledge-base material you give an agent, plus any content drafted or published through Sevā CMS.
Usage & device data
Log data, IP address, browser and device information, and pages visited, collected automatically when you use our website or product dashboards.
3. How AI Processing Works
When a Sevā AI Agent responds to a message, the relevant conversation content and knowledge-base context are sent to our AI inference provider, Groq, Inc., which runs the underlying language model and returns a generated reply. Prakryt itself does not use a Customer's conversation or knowledge-base content to train any model, and we don't sell conversation data to third parties for advertising. Groq processes this content under its own Customer Data Processing Addendum, which governs Groq as a data processor and does not include a blanket commitment that submitted content is never used to improve Groq's own models — we're working with Groq to confirm a stronger commitment, and will update this section if that changes. Where a Customer connects Sevā AI Agent to a different third-party model provider directly, that provider's own data-handling terms apply instead.
Separately from generating a reply, we log conversation traces — the full prompt and completion for each exchange — to Langfuse, an AI observability provider, so we can debug and improve how the AI Agent performs. This is a distinct purpose from reply generation: it's about monitoring and improving our own system, not answering the message itself. Langfuse deletes this data no later than one month after an account is closed, subject to the same kind of legal and fraud-prevention exceptions described in Section 8. As with Groq, Langfuse's terms don't include an explicit commitment that logged content is never used to train their own products, and we're following up with them on this directly.
4. How We Use Personal Data
- To provide, maintain, and secure the Services, including generating AI responses and routing tickets;
- To bill Customers and manage subscriptions;
- To provide customer support and respond to enquiries;
- To send service updates, security notices, and — where you've agreed — product news you can opt out of at any time;
- To detect abuse, enforce our Terms of Use, and meet legal obligations;
- To monitor and improve the quality of AI Agent responses, using conversation traces logged to our observability provider, Langfuse;
- To improve the Services in aggregate or de-identified form.
5. Our Legal Basis Under the DPDP Act
We process personal data on the basis of your consent (for example, when you sign up or opt in to marketing), for the performance of our contract with you, and — for a narrow set of "certain legitimate uses" recognised under the DPDP Act, such as fraud prevention and network security — without separate consent, as the Act permits. Where consent is our basis, you can withdraw it at any time without affecting processing that already took place.
6. Sharing & Sub-Processors
We share personal data only where necessary to run the Services:
- Infrastructure & hosting — Amazon Web Services, which hosts our production environment and, via Amazon S3, stores media and other files uploaded to Sevā CMS;
- Database — MongoDB Atlas, which stores account, ticket, and text content data for Sevā CRM and Sevā CMS in its Mumbai region;
- AI inference — Groq, Inc., which runs the language model behind Sevā AI Agent and processes conversation content to generate replies; see Groq's own sub-processor list for who they in turn rely on;
- AI observability — Langfuse, which receives a full copy of each conversation's prompts and completions so we can monitor and debug AI Agent quality;
- Payments — our payment gateway processes billing details on our behalf; we don't store full card numbers ourselves;
- Channel platforms — Meta (WhatsApp Business, Instagram, Messenger), to deliver and receive messages on the channels a Customer connects;
- Legal & safety — where required to comply with a law, court order, or to protect the rights and safety of Prakryt, our Customers, or others.
We do not sell personal data.
7. Where Data Is Stored
Account data, billing records, and — for every product — the underlying stored data are hosted in India by default: business and transactional data and text content live in MongoDB Atlas's Mumbai region, media and uploaded files live in Amazon S3, and supporting infrastructure runs on AWS ap-south-1 (Mumbai).
- Sevā CRM — ticket, inbox, and contact data is stored in MongoDB Atlas (Mumbai region); there is no AI-inference step, so no cross-border transfer is involved in the core product.
- Sevā CMS — page metadata and text content is stored in MongoDB Atlas (Mumbai region); media and other uploaded files are stored separately in Amazon S3. Neither is involved in a cross-border transfer, aside from any AI-drafting feature you use (see below).
- Sevā AI Agent — conversation history is stored in MongoDB Atlas (Mumbai region), but generating and reviewing each reply involves two extra steps outside that default: the message content is sent to Groq for inference, and a copy of the exchange is separately logged to Langfuse for quality monitoring. Both providers' processing operations are based outside India, so that portion of the data flow leaves India for a reply to be generated and reviewed. The same applies when Sevā CMS's AI drafting feature is used, since it calls the same inference provider.
These transfers are covered by each provider's standard contractual protections. Enterprise Customers with a dedicated deployment can discuss alternate inference and observability arrangements as part of their agreement. Where any data is transferred outside India, we put contractual safeguards in place consistent with the DPDP Act.
8. Retention
We retain account and conversation data for as long as your subscription is active, plus a limited period afterward to handle billing disputes, legal claims, and reactivation. You can request earlier deletion as described in Section 10. Backups are rotated on a schedule and are not retained indefinitely.
9. Security
We encrypt data in transit and at rest, restrict internal access on a need-to-know basis, and monitor our infrastructure for unusual activity. No method of transmission or storage is completely secure, and we can't guarantee absolute security — but we treat a security incident affecting your data as a priority and will notify affected Customers without undue delay if one occurs.
10. Your Rights as a Data Principal
Subject to applicable law, you can ask us to:
- Confirm what personal data we hold about you and provide a copy of it;
- Correct or update inaccurate or incomplete data;
- Erase personal data we no longer need to keep;
- Withdraw consent you previously gave;
- Nominate another individual to exercise these rights on your behalf in the event of your death or incapacity;
- Register a grievance about how we've handled your data, and escalate it to the Data Protection Board of India if it isn't resolved to your satisfaction.
To exercise any of these, email support@prakryt.com. If you're an End User of one of our Customers, please raise the request with that business directly — we process that data on their instructions and will support them in responding to you.
11. Children's Privacy
The Services are built for business use and are not directed at children. We don't knowingly collect personal data from anyone under 18. If you believe a child has provided us data, contact us and we'll delete it.
12. Cookies
Our website and product dashboards use cookies and similar technologies. Details of what we use them for and how to control them are in our Cookie Notice.
13. Changes to This Policy
We'll post any changes to this policy here and update the "Last updated" date above. For material changes, we'll also notify registered Customers by email or in-product notice.
14. Grievance Officer & Contact
In accordance with the DPDP Act, Prakryt has appointed a Grievance Officer to address questions and complaints about this policy.
Grievance Officer
Prakryt Technology Services
Bengaluru, Karnataka, India
Email: support@prakryt.com
For general privacy questions, email support@prakryt.com or contact us.