Privacy Policy
This Privacy Policy explains how Clevotics, an AI automation company operating from India, collects, uses, stores, shares, and protects personal data across its website, AI agents, and software products, in line with India's Digital Personal Data Protection Act (DPDPA) 2023. By using our services you accept the practices described here.
DPDPA 2023
Compliance baseline
India's data protection act
72 hrs
Breach notification
To authorities, as required
Zero
Data sold or rented
No third-party data sales
100%
Remote workforce
Access-controlled, no shared office
Overview
Clevotics ("we", "our", "us") builds AI automation, AI agents, and custom software for businesses. Delivering that work means handling personal data belonging to you, to your team, and sometimes to your customers. We treat that data as something we hold on your behalf, not as an asset of our own.
This policy covers our website, our client engagements, and the products we operate, including our AI agents and the automation systems described on our AI automation services page. Where a signed agreement or data processing addendum gives you stronger terms, that agreement wins.
If you disagree with anything in this policy, please stop using our services and contact us so we can resolve it.
At a glance
- We never sell, rent, or trade your personal data.
- We collect only the data needed to deliver the service you asked for.
- You can access, correct, export, or delete your data at any time.
- Client data is not used to train shared or general-purpose AI models.
What we collect
We collect three categories of data, and only the parts of each that a service actually requires.
Personal and business information
Details you give us directly when you contact us, sign up, or buy a service.
- Name, email address, phone number, and contact details
- Company name, job title, and professional details
- Payment and billing information for our services
Technical and usage data
Information collected automatically when you use our website, apps, or AI systems.
- IP address, device identifiers, and browser details
- Pages viewed, features used, and interaction patterns
- Diagnostic logs and error reports
Data processed for AI services
Operational data you route through our AI agents and automation workflows.
- Business documents and records you submit for processing
- Customer interactions handled by chat, voice, or email agents
- Workflow and integration data from your connected systems
We also use cookies and similar technologies to keep the site working, measure traffic, and improve our services. You can manage cookie preferences in your browser settings.
How we use your data
- Providing, operating, and improving our AI automation and software development services
- Configuring and tuning AI models inside your own deployment, scoped to your agreement
- Communicating with you about services, updates, and support
- Processing payments and managing customer accounts
- Running data protection impact assessments and algorithmic audits
- Complying with legal obligations and preventing fraud or abuse
- Marketing our services, where you have consented to receive it
Legal basis for processing
- Consent
- Where you have explicitly agreed to the processing.
- Contract performance
- To deliver the services in our agreement with you.
- Legitimate interests
- For security, service improvement, and business operations.
- Legal obligations
- To comply with applicable laws and regulations.
AI-specific protections
AI agents act on data instead of just storing it, so they need controls that a standard privacy policy does not cover.
Algorithmic transparency
We run regular audits of our AI systems for fairness, bias, and privacy exposure, and we can explain what data an agent reads and what actions it is permitted to take.
Data minimization by design
Agents receive the narrowest data scope that still lets them do the job. Privacy-enhancing techniques such as redaction, pseudonymisation, and scoped retrieval are applied where they fit the workload.
Human review of automated decisions
Where an automated decision significantly affects a person, we document the logic involved and provide a route to human review and appeal.
How we secure data
- Encryption in transit and at rest for personal and client data
- Role-based access control, least privilege, and multi-factor authentication on company accounts
- Regular security reviews and vulnerability assessments
- Cloud infrastructure with industry-standard certifications
- Mandatory data protection and confidentiality training for every team member
- Documented incident response and breach notification procedures
If something goes wrong
On becoming aware of a personal data breach we intimate the Data Protection Board of India without delay, and file the detailed report required under Rule 7 of the DPDP Rules, 2025 within 72 hours. Affected individuals are notified directly.
Our notice explains in plain language what happened, what data was involved, what you can do to protect yourself, and what we have done to contain it.
Remote work and device policy
Where our people work, and what they work on, changes the shape of the risk. We would rather state it plainly than leave it out.
Fully remote, full time
Clevotics operates as a fully remote, full-time team. We do not run a shared office network, so access to client systems and personal data happens through company accounts protected by multi-factor authentication and role-based access control, not through a trusted office perimeter. Access is scoped to the specific engagement a person works on, logged, and revoked the day their role changes or their employment ends.
Personal devices during probation
New team members serve a six-month probation period. During those six months they work on their own personal devices, and Clevotics does not issue company hardware. Company-provisioned assets are issued after probation is successfully completed, at which point work moves onto managed equipment.
A personal device used during probation must meet the control baseline listed alongside this section before it is granted any access. Client data stays inside company-controlled systems and is not copied into personal storage, personal email, or personal cloud accounts. If a client engagement requires managed hardware from day one, we staff it with post-probation team members instead.
Control baseline for personal devices
- Full-disk encryption and an enforced screen lock
- Supported operating system with security updates applied
- Access to client systems only through company accounts protected by multi-factor authentication
- Client data accessed through company-controlled systems, not stored in local personal files
- Signed confidentiality and acceptable-use agreements before any access is granted
- All access revoked on the same day a team member leaves or changes role
Asset timeline
Probation
Personal device, baseline controls, scoped access
Confirmed
Company-issued asset, managed and inventoried
Legal accountability for client information
Confidentiality is not only a promise in our contract. Under Indian law, failing to protect client information, or disclosing it without authorisation, is a statutory contravention with consequences for Clevotics as a company and for the individual responsible.
Digital Personal Data Protection Act, 2023
read with the DPDP Rules, 2025
Failing to take reasonable security safeguards to prevent a personal data breach attracts a penalty of up to ₹250 crore, and failing to report a breach attracts up to ₹200 crore. The Data Protection Board of India imposes these penalties, and they apply per contravention and cumulatively. The DPDP Rules were notified on 13 November 2025, the Board and its penalty powers are already operative, and the full set of data fiduciary obligations becomes enforceable from 13 May 2027.
Information Technology Act, 2000
Section 72A
Disclosing personal information obtained under a lawful contract, without consent and with intent to cause or knowledge of likely wrongful loss or wrongful gain, is punishable with imprisonment of up to three years, a fine of up to ₹5 lakh, or both. This provision attaches to the individual who made the disclosure, not only to the company that employs them.
Bharatiya Nyaya Sanhita, 2023
Sections 316 and 318
Client data, credentials, and systems entrusted to a team member are property held in trust. Misappropriating or converting them to another use is criminal breach of trust under Section 316, and where deception is used to obtain them it is cheating under Section 318.
Indian Contract Act, 1872
Sections 73 and 74
This is the provision under which damages are actually recovered. A party that breaches a confidentiality, non-disclosure, or service agreement is liable to compensate the other party for loss or damage caused by the breach, and for the sum stipulated in the agreement where the agreement names one.
What this means for our team
Every person at Clevotics signs a confidentiality and acceptable-use agreement before receiving any access to client systems, and that agreement names the statutory consequences above. Liability under Section 72A of the IT Act and under the Bharatiya Nyaya Sanhita is personal. It stays with the individual who caused the disclosure and cannot be absorbed by the company on their behalf.
A confirmed breach of client confidentiality by a team member results in immediate revocation of all access, termination of engagement, recovery of the loss caused under the signed agreement, and a report to law enforcement where an offence has been committed. This applies equally during the six-month probation period described above, when work is done on personal devices.
If we cause you loss
Penalties under the DPDP Act are paid to the government, not to the person whose data was exposed, and Section 43A of the IT Act, which previously allowed an individual to claim compensation, was omitted by Section 44(2) of the DPDP Act. Compensation for your loss is therefore a contractual matter, not a statutory one.
Where a failure by Clevotics or a member of our team causes demonstrable loss to a client or a data principal, we accept responsibility for making it good under the liability terms of the signed agreement covering that engagement, in addition to any penalty the Data Protection Board imposes on us. We also cooperate fully with any Board inquiry and give affected clients what they need to meet their own reporting obligations.
This section summarises the position under Indian law as at August 3, 2026 and is not legal advice. The terms of your signed agreement with Clevotics govern the commercial relationship, including liability.
Your rights
Under the DPDPA 2023 and other applicable privacy laws, you hold the following rights over your personal data.
Access
Ask what personal data we hold about you and why.
Correction
Have inaccurate or incomplete data corrected.
Erasure
Request deletion, subject to our legal retention duties.
Portability
Receive your data in a structured, machine-readable format.
Restriction
Limit how we process your data in certain circumstances.
Objection
Object to processing based on legitimate interests.
Withdraw consent
Withdraw consent you previously gave, at any time.
Grievance redressal
Raise a complaint with our contact point under the DPDPA 2023.
To exercise any of these rights, email us with enough detail to identify your records. We may ask you to verify your identity first.
Email support@clevotics.comRetention, transfers, and other terms
Data retention
We keep personal data only as long as needed for the purposes in this policy, to meet legal obligations, resolve disputes, and enforce our agreements. Data processed for a specific project is anonymised or deleted once the project closes and the retention period in your agreement expires.
International data transfers
We primarily process data in India. Where a transfer outside India is necessary, we apply safeguards such as standard contractual clauses or another legally recognised mechanism so the data keeps equivalent protection.
Children's privacy
Our services are not directed to anyone under 18, and we do not knowingly collect personal data from children. If we learn that we have, we delete it promptly.
Third-party services
Our website and products link to and integrate with third-party services. This policy does not cover those services, so review their privacy policies before using them.
Breach notification
If a breach creates a risk to your privacy rights, we notify the relevant authorities within 72 hours as required by law and inform affected individuals without undue delay, describing what happened and what we did about it.
Updates and governing law
We update this policy as our practices, services, or legal duties change, and we announce significant changes by email or a prominent notice on our website. This policy is governed by the laws of India, including the DPDPA 2023, and disputes fall under the jurisdiction of the courts of Bengaluru, Karnataka.
Frequently asked questions
Does Clevotics sell or rent personal data?
Clevotics does not sell, rent, or trade personal data to anyone. Data is shared only with vetted service providers who help deliver the service, where you have given explicit consent, or where the law requires disclosure.
Which privacy law does Clevotics follow?
Clevotics follows India's Digital Personal Data Protection Act (DPDPA) 2023 as its compliance baseline, alongside other privacy laws that apply to a specific client engagement. Clients with GDPR or sector-specific obligations can request a data processing agreement covering those requirements.
Does Clevotics use client data to train AI models?
Client data is used to configure and tune AI systems inside that client's own deployment only. Clevotics does not use client or customer data to train shared or general-purpose AI models without separate written consent, and project data is anonymised or deleted once the engagement ends.
How does a fully remote team keep client data secure?
Clevotics runs as a fully remote, full-time team, so there is no shared office network and every team member reaches client systems through company accounts protected by multi-factor authentication and role-based access control. Access is scoped to the specific engagement a person works on and revoked the day their role changes or ends.
Do Clevotics team members use personal devices?
During the first six months of employment, which is the probation period, Clevotics team members work on their own personal devices, and company-issued equipment is provisioned after probation is completed. Personal devices used in that period must meet a baseline of disk encryption, screen lock, current security updates, and company-account access with multi-factor authentication, and client data is accessed through company-controlled systems rather than stored in local personal files.
What are the legal consequences if client information is leaked?
Failing to protect personal data is a contravention of India's Digital Personal Data Protection Act 2023, carrying a penalty of up to ₹250 crore for inadequate security safeguards and up to ₹200 crore for failing to report a breach, imposed by the Data Protection Board of India. Disclosing information obtained under a lawful contract is separately punishable under Section 72A of the Information Technology Act 2000 with up to three years imprisonment, a fine of up to ₹5 lakh, or both, and that liability attaches to the individual who made the disclosure. Compensation for loss actually suffered is recovered under Sections 73 and 74 of the Indian Contract Act 1872 through the signed agreement, because the DPDP Act directs penalties to the government rather than to the affected person.
How do I request access to or deletion of my data?
Email support@clevotics.com with the request and enough detail to identify the records involved. Clevotics acknowledges data rights requests and responds within the timelines set by the DPDPA 2023, and may ask for proof of identity before releasing or deleting personal data.
Questions about your data?
Reach our privacy contact for data access requests, deletion requests, data processing agreements, or anything else in this policy.