Privacy notice
Last updated
Placeholder — this is a draft written from the product specification, not legal advice, and it has not been reviewed by a lawyer. Every value in square brackets must be supplied by a human, and the whole document reviewed, before launch.
Nishchit stores a customer’s phone number, the order it called about, the call recording and the transcript. All of it belongs to the merchant whose order it was, is filtered by that merchant’s organisation in the database itself, and is readable inside their team only according to role.
Who this notice is from
Nishchit is operated by [registered company name], registered in [jurisdiction] at [registered address]. Questions about this notice go to [privacy contact address].
Nishchit is a business-to-business platform. Its direct customer is a merchant; the people it telephones are that merchant’s customers. For the call data described below the merchant is the controller and Nishchit is the processor acting on their instructions.
What Nishchit collects about a merchant
To create and run an account Nishchit stores a phone number, the organisation and workspace a user belongs to, their role, and the times they signed in. Sign-in is a phone number and a one-time code; there is no password, so no password is stored.
- Phone number, in E.164 form, used to sign in and to identify the account
- Organisation, workspace and role, which decide what a user can read
- Session records, so a session can be revoked
- Audit entries for administrative actions and access to customer records
What Nishchit collects about a merchant’s customers
When a merchant asks Nishchit to confirm an order, Nishchit receives the order and the customer’s phone number from the merchant’s own store or API, places a call, and records what happened.
- The customer’s phone number, supplied by the merchant
- The order: items, quantities, the amount payable and the delivery address
- A recording of the call
- A transcript of the call, and the intent detected in each turn
- The structured outcome: confirmed, cancelled, modified, callback, escalated or unresolved
Why each of those is kept
The order and the phone number are needed to place the call at all. The recording and transcript exist so a merchant can check what was agreed — which is the entire value of confirming by phone rather than by guesswork, and the only defence against a disputed delivery.
How long it is kept
[Retention period for call recordings] and [retention period for transcripts and order data]. These periods are not settled yet and must be filled in before this notice is published.
A merchant can delete an order and its associated call data from their own workspace at any time.
Who can read it
Only people in the merchant’s own organisation, and only according to their role. Isolation is enforced in the database query rather than in the interface, and a test suite attempts cross-organisation reads on every resource and expects them to fail.
Platform staff access is a separate permission and is written to the audit log. [Describe the circumstances in which platform staff access customer data.]
Automated calling and a customer’s choices
A customer who asks not to be called again should not be called again, and a merchant is responsible for honouring that. The agent records such a request as an outcome so it is visible on the order.
The agent does not claim to be a human being if asked.
Rights
A customer wanting a copy of what was recorded about them, or its deletion, should ask the merchant they ordered from — they are the controller of that data. Nishchit will act on a merchant’s instruction to export or delete it. [Describe the statutory rights that apply in the jurisdiction and the response deadline.]
Changes to this notice
Material changes will be published on this page with a new date at the top. [State whether merchants are notified directly, and how far in advance.]