LEGAL · PRIVACY
Privacy Policy
How AnalyticsM collects, uses, and protects personal data across Quallix Audit and Quallix Assist.
Last updated ·
Introduction
AnalyticsM is a brand of Aashiva Analytics Private Limited, a company incorporated in India with its registered office at E-42, 9th Floor, Tower - C, Logix Cyber Park, Noida 201301, UP, India. We build Quallix Audit, a conversation auditing engine, and Quallix Assist, an agentic customer care system.
This policy explains what personal data we handle when you visit our website, speak to our team, or use our products, and what choices you have. It applies to our own processing. Where we process conversation data on behalf of a business customer, that customer decides the purpose and we act on their documented instructions under a separate data processing agreement.
This page is maintained by AnalyticsM and is written to answer common privacy questions in plain language. It is not a certification and does not replace the contract you sign with us.
Data we collect
We keep collection narrow and tie it to a purpose. Broadly, we handle three categories of data.
- Contact and business data you give us — name, work email, company, role, country, and anything you write in a demo request or support message.
- Product and account data — user accounts, roles and permissions, configuration such as audit scorecards and workflow rules, and audit logs of actions taken inside the product.
- Conversation data processed for a customer — call audio, transcripts, chat and email threads, metadata such as timestamps, queue, agent and disposition, and the scores, summaries and flags Quallix derives from them.
- Website and diagnostic data — pages viewed, referrer, approximate region, browser and device type, and error traces used to keep the service running.
How we use data
We use contact and business data to reply to enquiries, run demos, provide the service, invoice, and send service notices. We use product and diagnostic data to operate, secure, debug and improve the platform.
Conversation data is processed to deliver the functions the customer has configured: transcription, translation, quality scoring, compliance checks, coaching signals, and — for Quallix Assist — generating and executing agentic responses. We do not sell personal data, and we do not use customer conversation data to train general-purpose models for other customers. Model tuning on customer data happens only where that customer has instructed it in writing, and stays scoped to their tenant.
Legal bases
Where the EU or UK GDPR applies, we rely on: performance of a contract, for providing the service and managing accounts; legitimate interests, for security, service improvement, and business-to-business outreach that is proportionate and can be objected to; consent, where we ask for it, such as marketing subscriptions; and legal obligation, for tax, accounting and lawful requests.
Where India's Digital Personal Data Protection Act, 2023 applies, we rely on consent or on legitimate uses as defined by that Act. See our DPDP notice for detail on notice, consent and grievance redressal.
Call recordings and transcripts handling
Conversation data is the most sensitive material we touch, so it is handled under specific rules.
- Our customer is responsible for lawful recording and for giving the required notice or consent to the people on the call. We provide configuration to support disclosure prompts and consent capture.
- Audio and transcripts are encrypted in transit and at rest and are segregated by tenant.
- Redaction can be applied to card numbers, government identifiers, bank details and other configurable patterns before transcripts are stored or shown.
- Access is role-based and logged. Our engineers do not access customer conversation content except for a support request, a documented incident, or where the contract permits it, and access is time-bound.
- Derived artefacts — scores, summaries, risk flags — inherit the retention and deletion rules of the source conversation.
Sub-processors
We use a short list of vetted vendors for hosting, telephony, speech processing, model inference and email delivery. Each is bound by a written agreement with confidentiality and security terms no weaker than our own.
The current list, with the purpose and processing region of each vendor, is published on our sub-processors page. Customers on an active agreement can subscribe to advance notice of changes.
Data retention
Retention periods are set by the customer in their contract and configuration. Default behaviour is to retain conversation audio and transcripts for the contracted window, then delete them on a rolling schedule.
Enquiry and marketing contact data is kept for up to 24 months from the last interaction unless you ask us to remove it sooner. Billing and tax records are kept for the period Indian law requires. Backups age out on their own cycle, normally within 35 days of deletion from primary storage.
Security
We operate least-privilege access, single sign-on and multi-factor authentication for internal systems, encrypted storage and transport, tenant isolation, centralised logging, and periodic access reviews. Changes to production follow peer review and are recorded.
No system is risk-free. If a security incident affects your data, we will notify the affected customer without undue delay, describe what we know, and share the remediation steps we are taking. Report a suspected vulnerability to privacy@analyticsm.com and we will acknowledge it.
Your rights
Depending on where you are, you may have the right to access your personal data, correct it, delete it, restrict or object to processing, withdraw consent, receive a portable copy, and complain to a supervisory authority.
If your data reached us through one of our business customers — for example, you were on a recorded call with their contact centre — that customer is the controller or data fiduciary. Send your request to them, or write to us and we will route it to them and support their response.
To exercise a right directly with us, email privacy@analyticsm.com. We verify identity before acting and respond within the timelines the applicable law sets.
International transfers
We serve customers in India, the Gulf and beyond, and can host data in a specific region where the contract requires it. Support and engineering staff work across four time zones, so limited remote access from other countries may occur under the safeguards described above.
Where personal data moves out of its region of origin, we rely on the transfer mechanism appropriate to that jurisdiction, such as standard contractual clauses, and on contractual controls with our sub-processors.
Contact
Aashiva Analytics Private Limited, E-42, 9th Floor, Tower - C, Logix Cyber Park, Noida 201301, UP, India.
Privacy and data protection: privacy@analyticsm.com. Commercial and contractual questions: sales@analyticsm.com. We update this policy as the product and the law change, and the date above always reflects the current version.
OTHER LEGAL DOCUMENTS