Legal & Compliance

Privacy Policy

Version 2.0.0 · Effective and last updated: August 22, 2026 · India

Regulatory status: This notice is designed for India’s current IT/privacy framework and to prepare for the Digital Personal Data Protection Act, 2023 and the Digital Personal Data Protection Rules, 2025 as their provisions commence in phases. It is not a government certification or a blanket claim of GDPR compliance.

1. Who is responsible for your data

WebVoix AI is the service and trade name used for the platform at webvoix.com. For platform accounts, billing, support and service analytics, WebVoix AI determines why and how personal data is processed and acts as the data fiduciary/controller as applicable. The service is operated from Nagpur, Maharashtra, India. Privacy questions may be sent to support@webvoix.com.

The operator must publish its full legal name, complete principal postal address, named privacy/grievance contact and telephone/customer-care contact before accepting paid public orders. Those details are not verifiably present in the current repository and should not be invented.

2. Scope and roles for published websites

This Policy covers WebVoix AI’s own website, dashboard, account, billing, generation, editing, publishing, domain, analytics and support features. A WebVoix customer controls the content of a website they create and may collect data from that site’s visitors. For that visitor data, the customer is normally responsible for its own privacy notice and lawful processing, while WebVoix AI may process the data on the customer’s instructions as a processor/service provider. Customers must not use WebVoix AI to collect data unlawfully.

3. Personal data we process

  • Account and identity: name, email, organisation/company, optional phone/profile details, user ID, login provider, account status and authentication/session metadata.
  • Projects and AI creation: prompts, chat instructions, project names, website configuration, generated code/content, editing history and uploaded images or other assets.
  • Publishing and domains: published-site IDs, publishing status, subdomain/custom-domain records, DNS/SSL status, project ownership and operational events.
  • Billing and affiliate records: plan, credits, amount, currency, invoice/tax details if provided, Dodo Payments checkout/payment/subscription/refund identifiers, payment status, cancellation and refund records. WebVoix AI should not receive or store raw card numbers, CVVs or online-banking passwords.
  • Support, grievance and privacy requests: registered email, category, subject, message, evidence you choose to provide, case status and resolution.
  • Technical, security and usage data: IP address, timestamps, browser/device and request metadata, authentication/security events, pages/features used, errors, rate-limit events and cookie/analytics identifiers when enabled.
  • Published-site responses: a visitor’s name, email, phone and message if the customer enables a response/contact feature. The customer decides how it uses those responses.

4. Where data comes from

We receive data directly from you, automatically from your browser/device and service use, from a login provider you choose, from published-site visitors, and from processors such as Dodo Payments when they confirm a transaction. We may also receive lawful abuse reports or government/legal requests.

5. Why we process data

  • create and secure accounts, authenticate sessions and prevent unauthorised access;
  • generate, edit, save, publish and support the websites you request;
  • manage plans, credits, subscriptions, cancellations, refunds, referrals, payouts, invoices and accounting;
  • respond to support, consumer grievances, privacy-rights requests and abuse/takedown reports;
  • protect users and systems, enforce the Terms, investigate fraud and meet cyber-incident duties;
  • measure reliability and improve product performance; and
  • comply with tax, accounting, court, regulator and other legal obligations.

Processing is based on your free, specific and informed consent where consent is required; on data you voluntarily provide for the service you request; and on legal obligations or other grounds permitted by applicable law. Withdrawing consent does not invalidate earlier lawful processing and may make a requested feature unavailable if the data is necessary for it.

6. AI processing

Prompts, configuration and selected project content are sent to the configured Google Cloud/Gemini service to produce output. Provider use, location and retention depend on the contracted product and account configuration and must be verified operationally. WebVoix AI does not promise that every prompt is ephemeral or excluded from all provider improvement unless the applicable provider terms and configuration confirm that. Do not submit unnecessary personal or confidential data in prompts.

7. Cookies, analytics and advertising technology

The site may use essential storage for authentication, security and preferences and may use Google Tag Manager/Analytics or Meta technologies when configured. Non-essential analytics or advertising technologies should be activated only after the required notice/choice is provided. Browser or device controls may also limit cookies. Rejecting non-essential tracking should not prevent core account functions.

8. Recipients and processors

Personal data is shared only as reasonably necessary with authorised personnel and vendors supporting the service, including:

  • Supabase: authentication, database and storage;
  • Google Cloud/Gemini: AI generation and compute;
  • Render and Vercel: backend infrastructure, publishing and edge delivery where configured;
  • Dodo Payments: payments, subscriptions and refunds;
  • Google/Meta analytics or advertising services: only when configured and lawfully enabled; and
  • professional advisers, courts, regulators or authorities: where legally required or necessary to establish, exercise or defend legal claims.

WebVoix AI does not sell personal data for money. Vendor contracts, processing locations, security reviews and deletion terms must be maintained in the internal vendor register.

9. International processing

Cloud and edge providers may process data outside India. Transfers are subject to applicable Indian restrictions and appropriate contractual/technical safeguards. Certain security logs may need to be maintained within India under CERT-In directions. Provider region and transfer settings must be verified rather than assumed.

10. Retention and deletion

  • Account, projects and published content: while the account/project is active and for a limited deletion/recovery period, unless you delete earlier or law requires longer retention.
  • Payment, invoice, refund and payout records: for the tax, accounting, payment-dispute and legal period applicable to the operator.
  • Policy and consent evidence: while needed to show which notice/terms applied and to resolve legal claims.
  • Support, grievance and rights cases: until completed and for a proportionate evidence/limitation period.
  • Security logs: at least the rolling period required by CERT-In where applicable (currently 180 days in India); prepare for the longer retention required by DPDP Rule 6 when that provision commences, unless another law requires otherwise.
  • Backups: removed on the normal secure rotation cycle after source deletion, subject to legal hold and incident preservation.

We erase or anonymise data when its purpose and required retention end. Account deletion is not an assurance of instantaneous removal from every backup or legally required record.

11. Security safeguards

Safeguards include TLS in transit, restricted service credentials, database row-level security, least-privilege access, rate limits, payment/webhook signature verification, monitoring, backups and dependency/incident management. No system is risk-free. Administrators must use MFA, rotate secrets, keep privileged credentials only on the server, review access controls after schema changes and test recovery.

12. Your choices and rights

Subject to the law and its commencement, you may request a summary of your personal data and processing, correction/completion/update, erasure, withdrawal of consent, grievance redressal and nomination of another individual. You may also unsubscribe from marketing without stopping essential service messages.

Send a request from your registered email to support@webvoix.com with the request type and enough information to identify the account. We may verify identity and ask for clarification. We publish a privacy-grievance response period of no more than 90 days; a shorter consumer-law deadline applies where relevant. If an applicable request is denied or limited, we will explain the lawful reason where permitted.

13. Children

WebVoix AI accounts are intended only for adults aged 18 or older. We do not knowingly offer accounts to children. If we learn that a child’s data was processed without the legally required verifiable parental consent, we will restrict the account and take appropriate deletion or preservation steps. Report a concern to support@webvoix.com.

14. Personal-data and cyber incidents

We maintain an incident process for containment, investigation, recovery and required notifications. Listed cyber incidents may need to be reported to CERT-In within six hours of notice. When the applicable DPDP breach rule commences, affected individuals and the Data Protection Board will be informed in the form and timeframe the rule requires. Notices will describe the incident, likely effects, mitigation and contact route without disclosing information that would worsen security.

15. Changes to this Policy

The version and effective date appear at the top. Material changes will be notified through the account or registered email before taking effect where reasonably practicable. New consent will be requested when required. Historic policy versions and acceptance evidence are retained in the compliance register.

16. Privacy and grievance contact

Contact: Legal & Compliance Desk

Role: Privacy Contact / Grievance Redressal

Service: WebVoix AI

Email: support@webvoix.com

Location: Nagpur, Maharashtra, India

Consumer grievances: acknowledge within 48 hours and target resolution within one month. Privacy grievances: no later than the published 90-day period, unless a shorter law applies.

The operator must replace the generic desk with a real named officer/contact and publish the complete postal address and telephone/customer-care contact before paid public launch.

17. Additional regional rights

If another privacy law applies to a particular user or processing activity (for example because WebVoix specifically offers services in that jurisdiction), additional rights and transfer safeguards may apply. This Policy does not claim that every regional law, including the EU/UK GDPR, applies to every WebVoix user.