New
📢 1600 Series Enterprise Numbers Now Available click here → 📢 VNO Licensed Cloud Telephony Platform click here →
📢 1600 Series Enterprise Numbers Now Available click here → 📢 VNO Licensed Cloud Telephony Platform click here →
/*whatsapp chatbot*/

iKonTel Support

Online
Hi 👋 Thanks for reaching out! We're glad to connect with you. How can we help today?
×

Please provide your contact details to continue

Please enter your full name
Please enter a valid email address
Please enter a valid phone number
🔒 Your information is secure and will only be used to provide better customer support.

Setting up your chat...

Privacy Policy

Ikontel Solutions Private Limited

Last updated: 08.09.2026 | Effective from: 08.09.2026

1. Introduction

Ikontel Solutions Private Limited ("Ikontel", "we", "us", "our") provides cloud telephony, AI voice bot, messaging and business communication services to organisations in India. This Privacy Policy explains how we collect, use, disclose, store and protect personal data in the course of operating our website at [WEBSITE URL] (the "Site") and providing our products and services (together, the "Services").

We are committed to handling personal data in accordance with the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 ("DPDP"), the Information Technology Act, 2000 and rules made under it, applicable regulations and directions of the Telecom Regulatory Authority of India ("TRAI") and the Department of Telecommunications ("DoT"), and the terms of our agreements with our business customers.

Please read this Policy together with our Terms of Service and, where applicable, the Data Processing Addendum executed with your organisation.

2. Who we are

Legal entity Ikontel Solutions Private Limited
CIN U61900KA2014PTC072933
Registered office #72,73 & 74,ABMGP Building, Margosa Road,17th Cross,Malleshwaram, Bengaluru, 560055,Karnataka, India
General contact 8867858986
Privacy contact 7411800015
Grievance Officer See Section 15

3. Two different roles — please read this section first

How this Policy applies to you depends on your relationship with us. We handle personal data in two distinct capacities, and the difference matters for what rights you have and who you should approach.

As a Data Fiduciary. When we decide why and how personal data is processed, we act as a Data Fiduciary under DPDP. This applies to data about our business customers and their staff, prospective customers, website visitors, job applicants, vendors and our own personnel. Sections 4, 6, 8, 9, 11, 12, 13, 14 and 15 of this Policy describe that processing, and you may exercise your Data Principal rights directly with us.

As a Data Processor. When our business customers — banks, NBFCs, insurers, hospitals, enterprises and other organisations (each a "Customer") — use our Services to communicate with their own customers, borrowers, policyholders, patients or contacts (each an "End User"), the Customer decides what data is processed and for what purpose. The Customer is the Data Fiduciary; we are a Data Processor acting on their documented instructions under a written contract.

In that role, we do not decide what to collect, do not use End User data for our own purposes, and do not sell or share it for marketing. If you are an End User who received a call or message from a business using our platform and you want to access, correct or erase your data, or withdraw consent, please contact that business directly — they hold the relationship and the underlying records. If you approach us, we will make reasonable efforts to identify the relevant Customer and route your request to them, but we cannot act on their data without their instruction.

Section 5 describes the categories of End User data we process as a Processor, so that you understand what passes through our systems.

4. Personal data we collect as a Data Fiduciary

  • Account and contact data. Name, business email address, mobile and landline numbers, designation, department, employer name, business address, and the credentials associated with your account on our platform.
  • Commercial and billing data. Purchase orders, invoices, GSTIN, PAN of the entity, bank remittance references, service plan and usage-based billing records. Card details, where card payment is offered, are collected and processed by our payment gateway partner and are not stored on our systems.
  • KYC and onboarding data. Where telecom licensing conditions, TRAI regulations, DLT registration requirements or Meta's WhatsApp Business Platform policies require it, we collect entity registration documents, authorised signatory details, and the declarations and consent artefacts needed to provision numbers, sender IDs, templates or WhatsApp Business Accounts.
  • Support and correspondence data. Records of tickets you raise, emails and calls with our support and sales teams, and the contents of enquiry and demo request forms.
  • Website and technical data. IP address, approximate location derived from IP, device and browser type, operating system, referring URL, pages viewed, time spent, and similar analytics data collected through cookies and comparable technologies. See Section 12.
  • Recruitment data. Where you apply for a role with us, the contents of your application, CV, and interview records.

5. End User data we process as a Data Processor

The following categories pass through our platform on behalf of Customers. The precise fields are determined by each Customer's configuration and their contract with us.

  • Contact and identifier data. Telephone numbers, and where the Customer supplies them, names, account or loan or policy numbers, customer IDs, and language preference.
  • Communication content. The content of SMS, WhatsApp and other messages sent or received; message templates; delivery and read receipts; and inbound replies.
  • Call data. Call detail records including calling and called numbers, date, time, duration, direction, disposition and routing information; DTMF keypad input; and, where the Customer has enabled it, call recordings.
  • Voice bot interaction data. Audio captured during a voice bot conversation, text transcripts produced by automatic speech recognition, the responses generated by the bot, conversation state, and outcome or disposition codes. Section 6 describes this in more detail.
  • Data supplied for campaigns. Contact lists, variable fields used to personalise a message or call, and consent or Do Not Disturb ("DND") status indicators provided by the Customer.

Customers are responsible for having a lawful basis to share this data with us, for issuing the notice and obtaining the consent that DPDP requires, for honouring DND and TRAI's commercial communication rules, and for instructing us not to send data we do not need. We contractually require this. We do not verify the lawfulness of each individual record and we do not enrich, resell or repurpose End User data.

6. Voice bots, call recording and AI processing

Because our Services include AI-powered voice bots, some processing deserves specific explanation.

  • Recording and disclosure. Calls placed or received through our platform may be recorded where the Customer has enabled recording. Customers are responsible for disclosing recording to the End User at the start of the call and for obtaining any consent required by law.
  • Automated conversation. In a voice bot call, the End User is speaking to an automated system, not a human agent. Speech is converted to text by automatic speech recognition, interpreted by a language model, and answered with synthesised speech. Where a Customer has configured it, a call may be transferred to a human agent.
  • Model processing. Language models used for understanding and response generation may be operated by us on infrastructure we control, or accessed from third-party model providers under contract. Where a third-party provider is used, we contract for the provider not to train models on Customer or End User data. The providers engaged for a given Service are disclosed to the Customer under their agreement.
  • Voice data. Reference voice recordings used to generate synthetic speech are recorded from consenting voice artists engaged by us or supplied by the Customer. We do not use End User voice recordings to create synthetic voices, and we do not perform voice biometric identification or authentication unless a Customer has expressly contracted for it and confirmed it has the necessary consents.
  • Quality and improvement. Where our agreement with a Customer permits, a limited sample of interactions may be reviewed by authorised personnel, or used in de-identified or aggregated form, to diagnose faults and improve recognition and response accuracy for that Customer. Where it does not, we do not.

7. WhatsApp Business Platform

Where we act as a technology provider on Meta's WhatsApp Business Platform, we transmit and receive messages between our Customers and their End Users through Meta's infrastructure. In this capacity:

  • Message content and phone numbers are processed by Meta in accordance with Meta's own terms and privacy policies, over which we have no control.
  • We use WhatsApp data only to provide the messaging service to the Customer whose WhatsApp Business Account it relates to.
  • We do not use WhatsApp message content for advertising, do not share it with other Customers, and do not use it to build profiles.
  • Customers must comply with the WhatsApp Business Messaging Policy and Commerce Policy, including opt-in requirements before sending business-initiated messages.

8. How we use personal data

As a Data Fiduciary, we use personal data to:

  • create, provision and administer accounts and provide the Services;
  • authenticate users and secure access to the platform;
  • raise invoices, collect payment and maintain financial records;
  • respond to enquiries, provide technical support and communicate service notices, outages and changes;
  • monitor performance, capacity and reliability, and diagnose faults;
  • detect, investigate and prevent fraud, abuse, spam, toll fraud, SIP-level attacks and other threats to our network and our Customers;
  • meet obligations under telecom licensing conditions, TRAI regulations, tax law, and lawful requests from courts, regulators and law enforcement;
  • establish, exercise or defend legal claims and obtain professional advice or insurance;
  • with your consent where required, send you information about our products and services; and
  • assess job applications.

As a Data Processor, we use End User data solely to deliver the Services the Customer has instructed us to deliver, and for the limited security, fault-diagnosis and legal-compliance purposes described above.

We do not sell personal data.

9. Legal basis

Under DPDP we process personal data on the basis of the consent of the Data Principal, or for certain legitimate uses that the Act permits without separate consent — including where you have voluntarily provided data for a specified purpose, and for compliance with law or an order of a court.

Where processing rests on consent, the notice we or our Customer provide identifies the personal data, the purpose, how to withdraw consent, how to exercise your rights, and how to complain to the Data Protection Board of India. You may withdraw consent at any time; withdrawal does not affect processing carried out before withdrawal, and may prevent us from continuing to provide part or all of the Service.

10. Disclosure and sub-processors

We disclose personal data only as set out below.

  • To the Customer. As a Processor, we make data available to the Customer on whose behalf we process it, and to users the Customer has authorised on its account.
  • To telecom operators and platform providers. Delivering a call or message necessarily involves passing the numbers and, for messaging, the content to telecom service providers, aggregators, DLT registries and platform providers such as Meta. This is inherent to the Service.
  • To sub-processors. We engage carefully selected vendors for cloud hosting, infrastructure, AI model inference, analytics, ticketing, communications and similar functions. Sub-processors are bound by written agreements restricting them to processing on our instructions, imposing confidentiality and security obligations, and prohibiting any independent use of the data. A current list of sub-processors is available to Customers on request at info@ikontel.com.
  • To professional advisers and insurers. Where reasonably necessary for legal advice, audit, insurance or the defence of claims.
  • For legal and regulatory reasons. Where we believe in good faith that disclosure is required by law or a lawful order, or is necessary to enforce our agreements, protect the security or integrity of our network, or protect against imminent harm to any person.
  • On a business transfer. In connection with a merger, acquisition, financing or sale of assets, subject to the recipient being bound to terms no less protective than this Policy. We will notify affected Customers of any such transfer.

11. Retention

We retain personal data only for as long as it is needed for the purpose for which it was collected, or for as long as law requires.

As a Processor, retention periods for End User data — including call recordings and transcripts — are set by the Customer in their agreement with us. On expiry of the retention period, or on termination of the agreement and the Customer's instruction, we delete or return the data, subject to any copies we are required by law to retain and to routine backup cycles from which data is purged on schedule.

As a Fiduciary, we retain account, billing and statutory records for the periods required under the Companies Act, 2013, tax law and telecom licensing conditions, and other data for no longer than is necessary for the purpose.

Indicative periods: [INSERT — e.g. call detail records: X months; call recordings: X months unless the Customer specifies otherwise; support tickets: X years; invoices and statutory books: 8 years].

12. Cookies and analytics

Our Site uses cookies and similar technologies that are strictly necessary for the Site to function, and, with your consent, cookies for analytics and performance measurement. You can configure your browser to refuse cookies or to alert you when they are set; parts of the Site may not work correctly if you do. Third-party analytics providers we use are listed in our Cookie Policy.

13. Security

We maintain administrative, technical and physical safeguards appropriate to the nature of the data we handle, including:

  • encryption of data in transit using TLS, and encryption at rest for stored recordings and databases;
  • role-based access control, with access to production systems and to Customer data limited to personnel who need it for their role;
  • network segmentation, firewalling, and monitoring and blocking of anomalous SIP and application traffic;
  • logging of administrative and data access activity;
  • secure development practices, patching and periodic vulnerability assessment;
  • background verification and confidentiality undertakings for personnel with access to Customer data; and
  • documented incident response procedures.

No system is completely secure, and we cannot guarantee absolute security. If we become aware of a personal data breach, we will notify the affected Data Principals and the Data Protection Board of India in the manner and within the timelines prescribed under the DPDP Rules, and will notify affected Customers without undue delay so that they can meet their own obligations.

14. Storage location and transfers

Personal data processed through our Services is primarily stored and processed on infrastructure located in India. Some sub-processors may process limited data outside India; where that is the case, we do so subject to contractual safeguards and to the restrictions applicable under Section 16 of the DPDP Act and any country restrictions notified by the Central Government, and subject to any localisation requirement in a Customer's own regulatory framework — including, for regulated financial entities, applicable Reserve Bank of India directions.

15. Your rights and how to exercise them

Subject to DPDP and to the qualifications in Section 3, you have the right to:

  • obtain a summary of the personal data we process about you and the processing activities;
  • obtain the identities of other Data Fiduciaries and Processors with whom your data has been shared, and a description of what was shared;
  • have inaccurate or incomplete data corrected, completed or updated;
  • have your personal data erased where it is no longer needed for the purpose and retention is not required by law;
  • nominate another individual to exercise your rights in the event of your death or incapacity;
  • withdraw consent where processing is based on consent; and
  • have your grievance addressed by us.

To exercise a right, write to the Grievance Officer below with enough detail for us to identify you and your request. We may ask for information to verify your identity. We will respond within the period prescribed under the DPDP Rules.

Grievance Officer

If you are not satisfied with our response, you may complain to the Data Protection Board of India.

16. Children

Our Services are directed at businesses and are not intended for individuals under the age of 18. We do not knowingly collect personal data of children through our Site or our own accounts. Where a Customer's use of the Services involves processing the personal data of a child, the Customer is responsible for obtaining verifiable consent of a parent or lawful guardian as required under DPDP, and for not carrying out tracking, behavioural monitoring or targeted advertising directed at children. If you believe a child's personal data has been provided to us, contact the Grievance Officer and we will act to delete it.

17. Third-party sites

Our Site may link to third-party websites and services. We do not control them and are not responsible for their content or privacy practices. Review their policies before providing personal data to them.

18. Changes to this Policy

We may update this Policy from time to time. The revised version will be posted on this page with an updated effective date. Where changes are significant, we will take reasonable steps to notify Customers by email or through the platform. Your continued use of the Services after the effective date constitutes acceptance of the revised Policy. Data collected before a change remains subject to the Policy in force at the time of collection.

19. Contact

Questions about this Policy or our privacy practices:

```