Legal

Privacy Policy

This Privacy Policy explains how Bolcho AI, a product of Neobound, operator of the Bolcho voice- and chat-AI platform, collects, uses, discloses, retains, and safeguards your information. We are committed to processing personal data lawfully and transparently, in accordance with India's Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and rules made thereunder.

Last updated: 27 June 2026

1. Who we are

“Bolcho”, “we”, “us” or “our” refers to Bolcho AI, a product of Neobound, with its registered office at 804, Tower-19, Plot No. 9, Unitech Habitat, Sec Pi-2, Alpha Greater Noida, Gautam Buddha Nagar, Noida, Uttar Pradesh, India – 201310. You can reach us at info@bolchoai.in or info@neobound.ai.

Bolcho provides software that lets businesses (“Customers”) build and run AI voice and chat assistants that place and receive phone calls and answer chats. In relation to the data a Customer processes through Bolcho about their own callers, contacts, and end-users (“End-User Data”), the Customer is the Data Fiduciary/Controller and Bolcho acts as a Data Processor on the Customer’s instructions. For the account and usage data of the Customer themselves, Bolcho is the Data Fiduciary.

2. Information we collect

a) Information you provide

  • Account & profile — name, work email, password (stored only as a one-way hash), workspace and organisation details.
  • Assistant configuration — prompts, knowledge-base documents you upload, phone-number and routing settings.
  • Contacts & leads — any contact lists, phone numbers, or lead details you or your end-users submit through Bolcho.
  • Billing — company details and transaction records. Card/UPI details are collected and processed directly by our PCI-DSS-compliant payment processors (e.g. Razorpay/Stripe); we do not store full card numbers.
  • Support communications — messages you send us.

b) Information generated by using the service

  • Call data — phone numbers, call metadata (time, duration, direction, status), and, where enabled, call audio recordings and their transcripts.
  • Chat data — messages exchanged with chat assistants and widget sessions.
  • Analytics & derived data — summaries, sentiment, and quality signals generated from conversations to power dashboards and improve routing.

c) Information collected automatically

  • Technical data — IP address, approximate location (city/country derived from IP), browser/device type, and log data.
  • Cookies & local storage — used to keep you signed in and to remember preferences (see “Cookies” below).

3. How we use your information

  • To provide, operate, and secure the Bolcho platform and to route and process calls and chats.
  • To generate transcripts, summaries, analytics, and lead capture that you have configured.
  • To authenticate you, prevent fraud and abuse, and enforce our Terms.
  • To bill for usage, manage credits, and process payments.
  • To provide support and to send service, security, and administrative notices.
  • To maintain, debug, and improve the reliability and quality of the service.
  • To comply with legal obligations and respond to lawful requests.

We do not sell your personal data, and we do not use your or your end-users’ conversation content to train our own or third parties’ foundation models.

4. Legal bases for processing

We process personal data on the basis of your consent, the performance of a contractwith you, our legitimate uses/interests in operating and securing the service, and compliance with law. Where we act as a Data Processor for a Customer, we process End-User Data only on that Customer’s documented instructions.

5. AI processing & sub-processors

To deliver real-time voice and chat, conversation content (audio, text, and configured context) is transmitted to specialised third-party providers strictly to perform the requested processing — for example speech-to-text, large-language-model reasoning, text-to-speech, and telephony carriage. These sub-processors are contractually bound to use the data only to provide their service to us and not to train their models on it where such controls are available. Categories of sub-processors include:

  • Cloud & hosting — Microsoft Azure (compute, storage, networking).
  • Real-time media — LiveKit (media/SFU + SIP).
  • Telephony carriers — e.g. Plivo, for placing/receiving PSTN calls.
  • AI providers — LLM, speech-to-text, and text-to-speech vendors (e.g. OpenAI, Anthropic, Google, Deepgram, ElevenLabs, Cartesia, Sarvam, xAI, Azure Speech), used per your assistant’s configuration.
  • Payments — Razorpay/Stripe.

A current list of sub-processors is available on request at info@bolchoai.in.

6. Call recording & consent

Where call recording and transcription are enabled, Bolcho stores audio and text for the features you use. You are responsible for obtaining any legally required notice and consent from callers and recipients before recording, and for complying with applicable telecom regulations (including TRAI/DLT requirements and Do-Not-Disturb rules in India). Bolcho provides the tooling; the Customer determines the purpose and lawfulness of each call.

7. How we share information

  • With sub-processors — as described above, to run the service.
  • With the relevant Customer — End-User Data is made available to the Customer who owns the assistant.
  • For legal reasons — to comply with law, enforce our Terms, or protect the rights, safety, and security of users and the public.
  • Business transfers — in connection with a merger, acquisition, or asset sale, subject to this Policy.

8. International data transfers

Some sub-processors may process data outside India. Where this occurs, we take steps to ensure appropriate safeguards and that transfers are permitted under applicable law. We will honour any restrictions the Government of India notifies on cross-border transfers under the DPDP Act.

9. Data retention

We retain personal data for as long as your account is active or as needed to provide the service, and thereafter only as required to comply with legal obligations, resolve disputes, and enforce agreements. Customers can configure or request deletion of conversation data (recordings, transcripts, contacts) associated with their workspace; on account closure we delete or de-identify personal data within a reasonable period, save for records we are legally required to keep.

10. How we protect your data (Security)

We apply organisational and technical safeguards designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. These include:

  • Encryption in transit — all traffic to and between our services is encrypted using TLS (HTTPS/WSS). Certificates are issued and auto-renewed by our edge proxy; plaintext HTTP is redirected to HTTPS.
  • Encryption at rest — databases, object storage (recordings/uploads), and disks are hosted on Microsoft Azure and encrypted at rest.
  • Credential protection — account passwords are never stored in plaintext; they are salted and hashed with a strong, memory-hard one-way algorithm (Argon2). Sessions use short-lived signed access tokens with rotating refresh tokens.
  • Network isolation — data stores (PostgreSQL, Redis) run on a private virtual network, are password-protected, and are not exposed to the public internet. Service-to-service calls are authenticated with secret tokens.
  • Access control — access to production systems and data is restricted on a least-privilege, need-to-know basis; workspaces are logically isolated and scoped by role-based permissions.
  • Secrets management — API keys and credentials are stored outside source control and injected as environment secrets.
  • Payments — card data is handled by PCI-DSS-compliant processors; we do not store full card numbers.

No method of transmission or storage is 100% secure, so while we strive to protect your data using commercially acceptable means, we cannot guarantee absolute security. If we become aware of a personal-data breach that is likely to result in risk to you, we will notify you and the relevant authority as required by law.

11. Your rights

Subject to applicable law (including the DPDP Act), you may:

  • Access a summary of the personal data we process about you.
  • Request correction, completion, or updating of inaccurate or incomplete data.
  • Request erasure of your personal data, subject to legal retention needs.
  • Withdraw consent (this does not affect processing already carried out).
  • Nominate another individual to exercise your rights in the event of death or incapacity.
  • Raise a grievance with our Grievance Officer (below).

To exercise these rights, contact us at info@bolchoai.in. If you are an end-user of a Customer’s assistant, please direct your request to that Customer (the Data Fiduciary); we will assist them as their processor.

12. Cookies & local storage

We use strictly necessary cookies and browser local storage to keep you signed in and remember preferences. We do not use third-party advertising cookies. You can clear or block storage through your browser, though this may affect functionality.

13. Children

Bolcho is intended for business use and is not directed to children under 18. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this Policy

We may update this Policy from time to time. Material changes will be posted on this page with a revised “Last updated” date and, where appropriate, notified to you.

15. Contact & Grievance Officer

For any questions, requests, or grievances regarding this Policy or your personal data, contact our Grievance Officer:

Bolcho AI, a product of Neobound
804, Tower-19, Plot No. 9, Unitech Habitat, Sec Pi-2, Alpha Greater Noida, Gautam Buddha Nagar, Noida, Uttar Pradesh, India – 201310
Email: info@bolchoai.in  |  info@neobound.ai