This Privacy Policy explains how Kulp Labs Private Limited ("Kulp Labs", "Frontel", "we", "us") collects, uses, discloses, and protects personal data in connection with the Frontel AI sales platform and the website at frontel.in (the "Service"). It is written to align with the Digital Personal Data Protection Act, 2023 (the "DPDP Act"), the Information Technology Act, 2000, and the rules made under them.
1. Roles: who is responsible for what
Frontel is a multi-tenant platform. The role we play depends on whose personal data is being processed:
- For account holders (the owners and staff who sign up to use Frontel): we are the Data Fiduciary. This Policy tells you what we do with your personal data and how to exercise your rights.
- For end-customers (the leads, patients, clients, or customers a business reaches or who contact a Frontel-operated number, WhatsApp line, inbox, or chat widget): the business operating that channel (the "Tenant") is the Data Fiduciary. Frontel acts as a Data Processor processing that personal data on the Tenant's instructions. If you are an end-customer and want to exercise rights against the underlying business, please contact that business directly; we will assist them in responding.
2. The personal data we process
2.1 From account holders (Tenant Owners and Staff)
- Identity and contact: name, email address, mobile number, the business you represent, your role within it.
- Authentication signals: Google account identifier (when you sign in with Google), one-time-passcode hashes, IP address at the time the OTP was issued, last-login timestamps.
- Integration authorisation: OAuth tokens and account identifiers for services you connect (such as Google Calendar, or an email mailbox), plus webhook metadata for two-way sync. Tokens and secrets are encrypted at the application layer before being written to our database.
- Billing: plan, wallet balance and credit ledger, invoices, and payment metadata. Card and bank details are handled by our payment processor; we do not store full card numbers.
- Configuration: business name, address, hours, services, prices, team names, AI voice and language settings, custom greetings, knowledge-base content, FAQs, and other settings you enter.
2.2 From end-customers, on the Tenant's behalf
- Contact and channel metadata: phone number, WhatsApp number, email address, web-chat session, message direction, timestamps, and the IDs of the underlying telephony or messaging sessions.
- Call audio: a recording of the conversation with the AI agent, where voice is used.
- Transcripts and messages: turn-by-turn transcripts of calls and the content of WhatsApp, email, and chat conversations handled by the Service.
- Lead / customer record: name, phone number, email (where volunteered), and the reason for the enquiry, along with tags, stage, and notes.
- Booking records: appointment time, duration, assigned person or service, and the source conversation.
- Summaries: a short AI-generated description of what the customer asked for and what was done.
Some of this data may be sensitive depending on the business (for example, health-related details where a clinic uses the Service). The AI agent records only what the customer volunteers, but Tenants must ensure their customers are notified that conversations are AI-handled and may be recorded.
2.3 From visitors to our website and product
- Usage logs: IP address, user-agent, requested URL, referrer, response status, timestamp. We use these to operate and secure the Service.
- Cookies and similar technologies: see section 6 below, including the analytics and advertising tools we use on our marketing website.
3. Why we process this data (purposes and lawful bases)
We process personal data for the following purposes:
- To deliver the Service: making and receiving calls, sending and receiving WhatsApp, email, and chat messages, generating responses, transcribing audio, summarising conversations, booking and rescheduling appointments, syncing with connected calendars, sending notifications, and presenting all of this in a dashboard.
- To authenticate users and protect accounts: verifying email OTPs, validating Google sign-in, rate-limiting login attempts, detecting unauthorised access.
- To bill, account, and report: processing payments, maintaining the credit ledger, invoicing, tax compliance, fraud and abuse monitoring, statutory record-keeping.
- To support customers: responding to queries, troubleshooting issues, training our staff using the minimum necessary access.
- To market the Service: measuring website traffic and campaign performance, and showing relevant ads to people who have visited our site (see section 6).
- To improve the Service: aggregated and de-identified analysis of usage, latency, and error patterns. We do not use identifiable Customer Data to train general-purpose foundation models.
- To comply with law: responding to lawful requests from authorities, defending legal claims, enforcing our Terms.
Under the DPDP Act, our processing of account-holder personal data is based principally on the performance of the contract with you (our Terms and your subscription) and on legitimate uses such as compliance with law. For website analytics and advertising, we rely on your consent where required. For end-customer personal data processed on a Tenant's behalf, the lawful basis (typically the customer's consent or a legitimate use under section 7 of the DPDP Act) is the Tenant's to establish; we process such data on the Tenant's instructions.
4. How we share personal data
We do not sell personal data. We share it only as follows:
- With sub-processors: vetted third parties that help us run the Service, listed in section 5 below. They are contractually bound to process personal data only on our instructions and with appropriate safeguards.
- With your Tenant: if you are an end-customer, the business whose channel you contacted is the Data Fiduciary and can see the recording, transcript, summary, and customer record.
- For legal reasons: where disclosure is required by law, court order, or other lawful demand, or where necessary to establish, exercise, or defend legal claims, or to protect the vital interests of a person.
- In a corporate transaction: in connection with a merger, acquisition, financing, or sale of all or part of our business, subject to standard confidentiality protections and on terms consistent with this Policy.
5. Sub-processors
We currently rely on the following categories of sub-processors:
- Cloud infrastructure and storage — Amazon Web Services (Mumbai region) for application hosting, the database, and object storage of recordings.
- Telephony & WhatsApp — Plivo and equivalent carriers for inbound/outbound calling and number provisioning, and the WhatsApp Business Platform for messaging.
- Real-time voice infrastructure — LiveKit, for carrying the audio session between the carrier and the AI agent.
- AI models — Google (Gemini family), OpenRouter-routed large language models, and Sarvam AI for speech-to-text and text-to-speech. Content is processed in transit and is not used to train providers' general-purpose foundation models on our API tiers.
- Integrations — Composio and Google Calendar, when you explicitly connect an account, using only the scopes needed.
- Email — a transactional email provider (Brevo) and any mailbox you connect, for OTPs, invites, notifications, and outbound mail.
- Payments — Razorpay, for subscription and top-up payments. Card and bank details are handled by the processor under PCI-DSS.
- Analytics & advertising — Google Analytics (Google LLC), PostHog (product analytics, hosted in the EU), and Meta Platforms, Inc. (the Meta/Facebook Pixel and Meta Ads), used on our marketing website and product as described in section 6.
We will keep the list above current. Material changes — for example, adding a sub-processor that handles personal data in a new category — will be communicated to Tenants through the dashboard or by email.
6. Cookies, analytics and advertising
On our product, we use strictly necessary cookies and local storage to keep you signed in, remember your selected business, and remember UI preferences. These cannot be switched off through our site.
On our marketing website (frontel.in) we also use:
- Analytics cookies — Google Analytics and PostHog, to understand how visitors find and use our site and product (pages viewed, sessions, features used, approximate location, device and referrer) so we can improve them. PostHog data is hosted in the European Union. This data is used for product and statistical analysis.
- Advertising and measurement cookies — the Meta (Facebook) Pixel and Meta Ads, and similar tools, to measure the performance of our ad campaigns, build audiences, and show relevant ads to people who have visited our site (including remarketing on Facebook and Instagram).
These third parties may set their own cookies and act as independent controllers of the data they collect; their use is governed by their own privacy policies. You can control or refuse cookies through your browser settings, opt out of Google Analytics using Google's browser add-on, and manage ad personalisation through your Google and Meta account settings. Where required by law, we will ask for your consent before setting non-essential cookies.
7. Where personal data is stored
Customer Data is hosted in the Asia Pacific (Mumbai) region. Limited operational metadata may transit through systems located outside India when conversations are routed via international AI inference endpoints, or when sub-processors deliver email, messaging, payment, analytics, or webhook traffic. Where such cross-border transfers occur, they are made in accordance with the DPDP Act and applicable government notifications.
8. How long we keep personal data
We retain personal data for as long as needed to provide the Service and to meet legal, accounting, and reporting obligations. As a baseline:
- Call audio recordings: 90 days from the call, after which they are deleted from object storage.
- Transcripts, messages and summaries: 24 months from the conversation.
- Lead / customer records, appointments: for as long as the Tenant's subscription is active, plus 30 days after termination, after which we delete or anonymise them unless a longer period is required by law.
- Account, invoicing, and tax records: up to 8 years, in line with Indian tax and corporate-records requirements.
- Authentication logs: up to 12 months, longer where needed to investigate a security incident.
A Tenant Owner can request earlier deletion of any customer record from the dashboard or by writing to us; deletion is propagated to the recording and transcript stores within a reasonable time.
9. Your rights
Under the DPDP Act, account-holder Data Principals have the following rights with respect to personal data we hold as Data Fiduciary:
- Access — to obtain a summary of the personal data we process about you and the identities of recipients with whom it has been shared.
- Correction and erasure — to correct inaccurate or misleading data, complete incomplete data, update outdated data, and request erasure of personal data that is no longer necessary.
- Grievance redressal — to raise grievances about our handling of personal data with our Grievance Officer (see section 13).
- Nominate — to nominate another individual to exercise these rights in the event of your death or incapacity.
- Withdraw consent — where we rely on consent, to withdraw it at any time, without affecting the lawfulness of processing prior to withdrawal. Withdrawing consent for essential processing may mean we are no longer able to provide parts of the Service.
To exercise these rights, write to us using the contact details in section 13. We may need to verify your identity before responding. End-customers should direct rights requests to the business whose channel they contacted; we will assist that business in fulfilling them.
10. Security
We use reasonable technical and organisational measures to protect personal data, including:
- encryption in transit (TLS) and encryption at rest;
- application-layer encryption of high-value secrets (OAuth refresh tokens, connected-mailbox and integration credentials);
- hashed storage of one-time passcodes and invite tokens;
- tenant-scoped database access and row-level isolation;
- least-privilege access for our staff, with audit logging;
- rate-limiting and abuse protections on authentication endpoints.
No system is perfectly secure. If you believe an account has been compromised, write to us immediately at hello@frontel.in. We will notify affected Data Principals and the Data Protection Board of India of any personal-data breach as required by law.
11. Children
The Service is for businesses and is not intended for use by individuals under 18. The Service may, however, be used by a business to schedule appointments for, or correspond about, minors, where a parent or guardian interacts with the AI agent on a child's behalf. In such cases, the Tenant is the Data Fiduciary and is responsible for obtaining any consent required under section 9 of the DPDP Act.
12. Changes to this Policy
We may update this Policy from time to time. Material changes will be notified through the dashboard or by email to account Owners at least 14 days before they take effect. The "Effective date" at the top of this page tells you when the current version was published.
13. Contact and Grievance Officer
For any privacy question, request to exercise your rights, or complaint, contact our Grievance Officer:
Ashish Kulkarni
Kulp Labs Private Limited
Runwal Gardens, Kalyan-Shil Road
Dombivli 421204, Maharashtra, India
Email: ashish@kulp.ai
Phone: +91 88791 85675
We will acknowledge grievances within a reasonable time and respond within the periods required by the DPDP Act and the Information Technology Rules. If you are not satisfied with our response, you may approach the Data Protection Board of India.
