Privacy Policy
Last updated: 20 July 2026
This Privacy Policy explains how Replova Labs Private Limited ("Replova Labs", "we", "us", "our"), operating the OutreachAI platform (accessible via the Replov PaaS), collects, uses, stores, and protects your personal and business data in compliance with the Digital Personal Data Protection Act, 2023 (DPDP Act) and other applicable Indian laws.
1. Information We Collect
1.1 Account Information
When you create an account via Replov, we receive your name, email address, and authentication credentials (OAuth tokens from Google or GitHub). We do not store passwords directly — authentication is handled by Replov's identity service.
1.2 Workspace & Business Data
You provide your company name, description, products/services, and target audience to configure outreach campaigns. This data is stored in your workspace and used solely to personalize your AI-generated outreach content.
1.3 Lead Data
Lead information is sourced from publicly available business directories (Google Places API) or uploaded by you via CSV/Excel files. This may include business names, phone numbers, email addresses, websites, and addresses. For bulk calling, you provide contact phone numbers and optional metadata (name, company).
1.4 Communication Data
When you use OutreachAI to send emails, SMS, WhatsApp messages, or make voice calls, we store:
- Message content, templates, and scripts you create
- Delivery status and engagement metrics (opens, replies, call duration)
- Call recordings and transcripts (for AI voice calls via Bolna AI)
- Extracted data and summaries from AI voice conversations
1.5 Usage & Billing Data
We track feature usage (searches, emails sent, calls made, SMS count) for billing purposes. Transaction records are maintained for your Replov wallet charges.
1.6 Technical Data
Standard server logs including IP addresses, browser type, access timestamps, and API request metadata.
2. How We Use Your Data
- Service delivery: Running outreach campaigns, making AI voice calls, sending emails/SMS/WhatsApp
- AI personalization: Using your company profile to generate tailored outreach scripts and messages
- Billing: Tracking usage against plan quotas and deducting from your Replov wallet
- Analytics: Providing campaign performance dashboards and call analytics
- Service improvement: Debugging errors, monitoring system health, and improving features
- Legal compliance: Responding to lawful requests from authorities, maintaining audit trails
3. Third-Party Data Sharing
We share data with third-party service providers strictly for service delivery:
| Provider | Purpose | Data Shared |
|---|---|---|
| Bolna AI | AI voice calls & batch calling | Phone numbers, call scripts, voice config |
| Plivo | Telephony infrastructure | Phone numbers, call routing |
| Google (Places API) | Lead discovery | Search queries, location data |
| ZeptoMail / User SMTP | Email delivery | Recipient emails, message content |
| MSG91 | SMS delivery | Phone numbers, message content |
| Meta (WhatsApp Cloud API) | WhatsApp messaging | Phone numbers, message content |
| Anthropic (Claude) | AI segmentation & classification | Lead data for scoring, reply classification |
| Supabase | Database hosting | All application data (encrypted at rest) |
We do not sell, rent, or trade your personal data to any third party for marketing purposes.
4. Data Storage & Security
- All data is stored in encrypted databases (AES-256 at rest) hosted on Supabase infrastructure
- API keys and sensitive credentials are encrypted using application-level encryption before storage
- All data transmissions use TLS 1.2+ encryption
- Row-Level Security (RLS) policies ensure workspace-level data isolation
- Access to production systems is restricted to authorized personnel only
5. Data Retention
- Account data: Retained while your account is active, deleted within 90 days of account closure
- Lead data: Retained while your workspace is active; you can delete individual leads or campaigns at any time
- Call recordings: Stored for 90 days unless you delete them sooner
- Billing records: Retained for 7 years as required by Indian tax and accounting regulations
- Server logs: Retained for 30 days
6. Your Rights Under DPDP Act 2023
As a Data Principal under the DPDP Act, you have the right to:
- Access: Request a summary of your personal data and how it is processed
- Correction: Request correction of inaccurate or incomplete personal data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Grievance redressal: File a complaint with our Data Protection Officer
- Nominate: Nominate another person to exercise your rights in case of death or incapacity
7. Children's Data
OutreachAI is a B2B platform intended for business use. We do not knowingly collect personal data from individuals under 18 years of age. If you believe a minor's data has been submitted, contact us immediately.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be notified via email or an in-app notification at least 15 days before they take effect.
9. Contact Us
For privacy-related queries, data access requests, or to exercise your DPDP rights:
- Data Protection Officer: Replova Labs Private Limited
- Email: privacy@replov.com
- Address: Replova Labs Private Limited, India