ConnectailAI receptionist
HelpTermsSign in
Privacy Policy

How Connectail handles business and customer data

Effective September 5, 2026 · Version 2026-09-05

Plain-language summary

Connectail uses account, business, conversation, operational, support, and technical data to provide and secure the service. A business controls the customer data it submits to its workspace; Connectail processes that data to deliver the requested functions. We do not sell personal data or use customer conversations for cross-context behavioural advertising.

1. Scope and who we are

This Privacy Policy applies when you visit Connectail, create or use a workspace, contact support, upload business knowledge, connect a communication channel, or interact with a Connectail-powered chat or booking experience. Connectail is provided by Codesvera Infotech Private Limited, located at Amstor building,technopark, Trivandrum, Kerala, India.

It does not replace the privacy notice of a business using Connectail. Third-party websites, messaging providers, payment services, and integrations have their own privacy practices.

2. Our privacy roles

For information used to manage Connectail accounts, subscriptions, security, direct support, legal compliance, and our own website, Codesvera Infotech Private Limited determines the relevant purposes and means of processing.

For customer conversations, bookings, leads, staff data, and business records processed through a subscriber’s workspace, the subscriber generally determines the purpose and instructions. Connectail processes that data to provide the service. The subscriber must give its customers and personnel an appropriate privacy notice and establish the lawful authority required for its processing.

3. Personal data we collect

Account and identity data: name, business email, phone number, username, password hash, role, organization membership, authentication events, and legal-policy acceptance evidence.

Business and workforce data: business names, descriptions, contact details, addresses, branches, staff names and roles, services, prices, offers, working hours, availability, booking rules, policies, FAQs, documents, and approved knowledge.

Customer interaction data: names, contact details, channel identifiers, message content, conversation state and summaries, enquiry details, appointments, changes and cancellations, leads, customer requests, support handoffs, internal assignments, and delivery status.

Channel and integration data: selected Meta, WhatsApp, Facebook, Instagram, and website assets; encrypted access credentials; external account identifiers; connection status; webhook events; permission and delivery diagnostics.

Billing data: plan, trial and subscription status, invoice information, amounts, tax-related details, payment-provider references, mandate status, success or failure events, and limited payment metadata. Connectail does not store full payment-card numbers or card security codes.

Support data: ticket subjects, descriptions, replies, status, priority, attached files, attachment security-scan results, and related audit events.

Technical and usage data: IP address, browser and device information, session and security cookies, timestamps, request and diagnostic identifiers, logs, feature usage, errors, and performance information.

4. Where data comes from

We receive data directly from account holders and website visitors; from businesses and their authorized staff; from customers who message or book with those businesses; automatically from devices and our systems; and from connected providers such as Meta channels, Razorpay, email providers, and hosting or security services.

5. Why we process data

We process data to create and secure accounts; verify acceptance and authority; provide workspaces; compile approved business knowledge; understand and respond to enquiries; route conversations; support human handoff; find availability; create and manage bookings, leads, and requests; operate channel connections; send permitted messages and alerts; process subscriptions and invoices; prevent fraud and abuse; scan attachments; troubleshoot failures; answer support tickets; maintain audit records; comply with law; and establish, exercise, or defend legal claims.

Where processing relies on consent, the request will identify the purpose and data involved. Consent may be withdrawn through the available account controls or by contacting the responsible business or Connectail, as appropriate. Withdrawal does not affect earlier lawful processing and may make a requested feature unavailable. We may also process data for other uses authorized by applicable law.

6. AI processing and automated assistance

Connectail may send relevant customer messages, approved Business Data, conversation context, and structured response instructions to configured AI providers to interpret an enquiry or draft wording. Database records and validated business facts remain the authoritative source for operational answers and actions. Deterministic safeguards and response validation are used, and uncertain conversations may be handed to a person.

AI can make mistakes. Businesses must not rely on Connectail as the sole decision-maker for medical, legal, financial, emergency, employment, credit, insurance, or similarly significant decisions. We do not use a business’s customer conversations to build advertising profiles for unrelated businesses.

7. When data is shared

Data is disclosed only as reasonably necessary to:

  • authorized users of the relevant business workspace;
  • hosting, database, storage, security, malware-scanning, monitoring, email, and customer-support providers;
  • AI providers configured to process prompts and responses;
  • Meta, WhatsApp, Facebook, Instagram, and other channels selected by the business;
  • Razorpay and financial institutions involved in subscription payments;
  • professional advisers, auditors, insurers, and corporate transaction counterparties subject to suitable duties;
  • courts, regulators, law enforcement, or other parties where legally required or reasonably necessary to protect rights, safety, systems, and users.

We do not sell personal data. We do not disclose customer conversation content for third parties’ independent advertising.

8. International processing

Providers may process data in India or other countries where they or their infrastructure operate. We use contractual, organizational, and technical safeguards appropriate to the processing and comply with applicable restrictions on international transfers. A connected channel may independently route data according to that provider’s infrastructure and terms.

9. Cookies, analytics, and advertising measurement

We use strictly necessary cookies and similar storage for authenticated sessions, security, CSRF protection, preferences, device notification settings, and application functionality. Blocking necessary cookies may prevent login or integrations from working.

We use Google Analytics to understand page visits and engagement across Connectail. We also use Meta Pixel on public marketing, sign-in, and signup pages to measure visits and the effectiveness of advertising. These providers may receive limited technical and usage information such as an IP address, browser or device information, referrer, and page path under their own terms. Connectail excludes URL query strings from Google Analytics and does not intentionally send verification tokens, customer-message content, payment-card details, or private workspace content to these tools. Meta Pixel is not loaded in customer chats, booking pages, billing pages, administration areas, or authenticated workspaces.

Connected-provider login windows or SDKs may set their own cookies. Where applicable law requires a consent or opt-out choice for non-essential analytics or advertising measurement, we will provide and respect that choice. Browser, device, Google, and Meta controls may also limit measurement, although those controls are operated by their respective providers.

10. Retention and deletion

We retain data only while reasonably necessary for the specified service, account administration, security, backups, dispute resolution, payment and tax records, legal claims, and applicable law. Retention depends on the record: active workspace data generally remains while the subscription or customer relationship continues; security and audit records are retained for a proportionate period; payment and tax records may be retained for statutory periods; and backup copies are removed through scheduled rotation.

When deletion is requested or an account ends, we delete or anonymize data that is no longer required, subject to lawful retention, fraud prevention, unresolved tickets, billing disputes, backups, and legal holds. Businesses should export records they must retain before closing their account.

11. Security

Safeguards include authenticated access, role and tenant separation, encrypted transport, secure cookies in production, encryption of sensitive integration credentials, private attachment delivery, malware-scan support, request verification, database transaction controls, logging, backups, and restricted administrative access. No internet service is completely secure.

If you suspect unauthorized access, do not include credentials in a ticket. Secure the affected provider account and contact privacy@connectail.com. We will assess and notify affected parties and authorities where required.

12. Your rights and choices

Subject to applicable law and verification, you may request information about processing, access, correction, completion, updating, erasure, withdrawal of consent, and grievance resolution. You may nominate another individual where applicable. We may retain or withhold information where law permits or requires, including to protect another person’s rights, security, confidential information, or legal claims.

Workspace users can update some account and business data inside the product. A customer of a business should normally contact that business first because the business controls the relevant conversation or appointment. We will assist the business as required. For data controlled directly by Connectail, contact the grievance channel below.

13. Children and regulated data

Connectail accounts are for adults acting for businesses. The Services are not directed to children. Businesses must not knowingly use Connectail to process a child’s personal data unless they have completed all legally required age verification, parental consent, notices, safety measures, and sector-specific requirements. Businesses must configure human review and additional safeguards before handling health, financial, biometric, government-identity, or other regulated or highly sensitive information.

14. Duties of businesses using Connectail

Businesses must collect only necessary data; keep data accurate; configure access appropriately; respond to customer rights and grievances; disclose their use of AI and communication providers where required; obtain messaging and marketing permissions; avoid uploading unnecessary secrets; and notify Connectail promptly of incidents or unlawful instructions. Connectail may refuse or restrict processing that creates material legal or security risk.

15. Changes to this Policy

We may update this Policy to reflect changes in law, providers, security, or the Services. We will post the new version and effective date and provide additional notice for material changes where required. A change will not retroactively reduce rights that cannot lawfully be reduced.

16. Grievance and privacy contact

Grievance contact: Abhilash Anil. Send privacy and data-rights requests to privacy@connectail.com. General legal enquiries may be sent to support@connectail.com, or by post to Amstor building,technopark, Trivandrum, Kerala, India.

Describe the account or business involved and the right you wish to exercise. Do not send passwords, full payment-card data, or unnecessary identity documents. We may request proportionate information to verify identity and authority before acting.