Sivient Technologies Private Limited
Privacy Policy
Effective date: 18 May 2026
Sivient Technologies Private Limited ("Sivient", "Company", "we", "us", or "our"), based in Bengaluru, India, is committed to protecting your privacy and the security of your personal data.
This Privacy Policy explains how we collect, use, store, share, and protect your personal data when you use our AI-powered email, calendar, and meeting management assistant (the "Platform"). It applies to all users located in the United States, Europe, and India.
Under global data protection frameworks:
- We act as a Data Fiduciaryunder India's Digital Personal Data Protection (DPDP) Act, 2023.
- We act as a Data Controllerunder the European Union's General Data Protection Regulation (GDPR) (Regulation EU 2016/679).
Where we process personal data on behalf of a Customer's organisation under a Team Plan, we act as a Data Processor/Processor and the organisation acts as the Data Controller/Fiduciary.
1. Information We Collect
We collect and process personal data to deliver, optimise, and secure the Platform. We categorise this data as follows.
1.1 Account Registration Information
When you create an account, we collect your first and last name, business email address, company name, billing address, telephone number, and payment credentials. All payment card data is tokenised and stored securely by our PCI-DSS compliant payment gateways; we do not store raw card numbers.
1.2 Connected Workspace and API Data
By linking your email and calendar clients using secure OAuth 2.0 authorisation, you grant us permission to programmatically access:
- Google Workspace (Gmail and Google Calendar): email body text, subject lines, header metadata, sender and recipient addresses, and calendar entries.
- Microsoft 365 (Outlook): email text, calendar appointments, video call links, and task logs.
- Third-party integrations: connection tokens and structured data from other tools you authorise us to connect with, including Slack, Teams, Notion, Granola, Zoom, HubSpot, and Salesforce.
1.3 Virtual Meeting Audio, Video, and Transcript Data
When you authorise our Notetaker Bot to join online meetings, we process:
- Audio and video recordings of the video conferences.
- Text transcripts automatically generated from the meeting audio.
- Meeting metadata, including participant names and emails, meeting titles, durations, and timestamps.
1.4 Technical and Device Data
To ensure system performance, prevent security incidents, and maintain reliability, we automatically collect technical logs, including IP addresses, device identifiers, browser types, operating systems, and platform interaction metrics.
2. Purposes and Legal Bases of Processing
We process personal data in compliance with the legal bases defined by the GDPR and the consent mandates of the Indian DPDP Act.
| Data category | Processing purpose | Legal basis (GDPR) | Legal basis (DPDP Act) |
|---|
| Account info | Managing subscription plans, processing payments, and verifying identity. | Contractual necessity. | Explicit consent. |
| Email and calendar | Automated labelling, drafting email replies, and scheduling calendar invites. | Contractual necessity. | Explicit consent. |
| Meeting records | Automated transcription, action-item creation, and meeting summaries. | Explicit consent. | Explicit consent. |
| Integration tokens | Enabling cross-platform synchronisation with Slack, HubSpot, Salesforce, and other authorised tools. | Contractual necessity. | Explicit consent. |
| Technical data | Troubleshooting bugs, auditing APIs, and monitoring against cyber threats. | Legitimate interest. | Legitimate use. |
3. Third-Party API Compliance and Restrictions
3.1 Google API Limited Use Disclosure
Sivient's use and transfer of information received from Google APIs to any other application adheres to the Google API Services User Data Policy, including its Limited Use requirements:
- No model training. We do not use Gmail data or any Google API data to train, retrain, or improve generalised, non-personalised machine learning or AI models.
- No advertising. We do not use or transfer Google API data for serving advertisements, including retargeting, personalised, or interest-based ads.
- Limited transfer. We do not transfer Google API data to external parties unless necessary to deliver or improve prominent, user-facing features within the active application interface, with your explicit consent, for security purposes, or to comply with applicable law.
- No human review. No human employee, contractor, or reviewer accesses your raw Google user data, unless we have secured your explicit, documented consent to access specific messages to resolve a documented technical support request, the access is required for security or legal compliance, or the data has been aggregated and anonymised.
3.2 Microsoft API Privacy Standards
Our integration with Microsoft Outlook and the Microsoft Graph API complies with Microsoft's developer security requirements. To protect email immutability, we do not modify, alter, or delete any received, non-draft email message (including its body text and recipient list). All generated responses are written as new, independent draft messages in your drafts folder.
4. Privacy Boundaries for Team Workspaces
Under Team plans, the Platform implements strict technical controls to prevent internal data exposure and unauthorised administrative access:
- Admins have zero inbox visibility. Organisation administrators manage billing, configure licences, and view aggregate usage metrics. Admins cannot access, read, search, or review your private email messages, generated drafts, private meeting summaries, or inbox folders.
- Meeting privacy by default. Meeting summaries, transcripts, and recordings are private by default and visible only to the individual who scheduled or authorised the Notetaker Bot. Other team members and administrators cannot browse or play your meeting recordings unless you explicitly share a link.
5. Data Security and Retention
6.1 Security Controls
We implement appropriate technical, physical, and organisational security measures to protect your data, including:
- Encryption of personal data, email bodies, and meeting transcripts at rest using AES-256.
- Transmission of all data over secure, modern protocols using HTTPS and TLS.
- Storage of all OAuth access tokens and database records using strict row-level tenant isolation.
- Regular external security reviews and penetration testing.
6.2 Data Retention
We retain personal data only as long as necessary to fulfil the purposes outlined in this policy or to comply with statutory legal requirements:
- Active subscriptions. Data is retained during the term of your subscription.
- Meeting files. Meeting audio/video recordings and text transcripts are stored for thirty (30) days by default, after which they are permanently deleted from our active servers unless you adjust your account configuration.
- Account deletion. If you cancel your subscription or request account deletion, all personal data is permanently deleted from primary production databases within thirty (30) days. System backups are overwritten and purged within ninety (90) days.
6. Your Data Privacy Rights
Depending on your jurisdiction, you have the following enforceable rights regarding your personal data.
7.1 Rights under the GDPR (European Union users)
- Access and portability. Request a copy of all personal data we process, delivered in a structured, machine-readable format.
- Erasure (right to be forgotten). Request the permanent deletion of your personal data.
- Rectification. Request corrections to inaccurate or incomplete personal data.
- Objection and restriction. Request that we stop processing your data, or restrict processing, under certain conditions.
- Withdraw consent. Withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal.
7.2 Rights under the DPDP Act, 2023 (Indian users)
- Access summary. Request a summary of the personal data we hold, the processing activities performed, and the identity of other parties with whom data has been shared.
- Correction and erasure. Request correction of inaccurate data, completion of incomplete data, or erasure of data no longer necessary.
- Grievance redressal. Resolve any data privacy concern through our Grievance Officer before escalating to the Data Protection Board of India.
- Nomination. Nominate another individual to exercise your data privacy rights in the event of death or incapacity.
To exercise any of these rights, email us at admin@sivient.com. You may also revoke our access at any time through your email or integration provider's account settings.
7. Updates to This Policy
We may update this Privacy Policy periodically to reflect changes in our AI architecture, security practices, or legal developments. We will notify you of material changes by:
- Posting the updated policy on our website with a revised effective date.
- Displaying a prominent in-app notification when you access the Platform.
- Sending a direct email notification to the address registered with your account.
For any questions about this Privacy Policy, or about how we handle your data, contact us at admin@sivient.com.