Privacy Policy
The short version. Lumoscale provides AI voice agents that answer and place phone calls for businesses. If you call one of those businesses, you are talking to an AI, and the call may be recorded and transcribed if that business turned recording on. We do not sell personal data, we do not run advertising trackers, and businesses control how long their call data is kept. You can ask us or the business to access or delete your data at any time.
1. Who we are and our two roles
This policy is issued by Lumoscale (“Lumoscale”, “we”, “us”), a sole proprietorship owned by Vamsi and based in India. It covers our website, our customer dashboard, and our voice agent platform (together, the “Service”).
We act in two different roles, and the difference matters:
- Data Processor / Service Provider (for call data). Our customers are businesses (“Customers”). When a Customer uses Lumoscale to take or make calls, the Customer decides why and how the personal data of the people on those calls (“Callers”) is used. We process that data on the Customer’s instructions. The Customer is the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 (“DPDP Act”) and the “business” under US state privacy laws. For Caller requests, the Customer is usually your first point of contact.
- Data Fiduciary / Controller (for our own data). We decide how we handle data about our website visitors, prospects, and the people who hold Customer accounts on the dashboard (“Account Users”), and billing data.
2. What we collect
a) From Callers (on behalf of Customers)
- Phone number, and any name, email, address or other details you give during the call or that the Customer already holds (for example from a web form or CRM that triggers an outbound call).
- Your voice and the content of the conversation, as live audio, a written transcript, and, if the Customer has enabled recording, an audio recording.
- AI-generated outputs: a call summary, outcome (for example “appointment booked”), an estimate of caller sentiment, and any follow-up the Customer configured.
- Appointment and lead details (name, phone, requested time, notes) and whether you asked not to be contacted again.
- Call metadata: date, time, duration, direction (inbound or outbound), and call cost.
b) From Account Users and Customer representatives
- Name, work email, phone, business name, role and login credentials (passwords are stored only in hashed form).
- Workspace content you upload or configure: agent instructions, business hours, knowledge-base documents, contact lists, campaigns, DND lists, and connection details for calendars or other tools you link (stored encrypted).
- Billing and usage records: credit purchases, per-call usage charges, invoices, and tax details. We do not store full payment card numbers.
c) From website visitors
- Information you submit when you book a demo or contact us.
- Basic technical data such as IP address, browser and device type, and pages viewed, to keep the site secure and working.
- If you use a live web demo, the audio and transcript of that demo conversation.
What we do not intend to collect
Voice agents are not designed to collect payment card numbers, government ID numbers, passwords, or health or other sensitive records. We ask Customers not to have agents collect them (see our Terms). We do not create voiceprints or identify people by their voice.
3. Calls, AI and recordings
This section is the “Data & recording” notice referred to on our website.
- You are speaking with an AI. Customers are required to make clear that the caller is an automated AI voice agent. If you are ever unsure, ask the agent directly and it should tell you.
- Recording is a Customer setting. Recording is off unless the Customer turns it on. Where it is on, the Customer is responsible for telling you (for example in the greeting) and, where the law requires, obtaining your consent. If you do not want to be recorded, say so at the start of the call or hang up.
- Transcripts and summaries. Even where audio is not recorded, calls are processed in real time by AI models to produce the conversation, and a transcript and summary are usually kept so the Customer can review what happened.
- Stop contacting me. If you tell an agent to stop calling or to remove you, the platform can flag the number as Do Not Disturb and stop further automated calls to it, subject to the Customer having that feature enabled. You can also tell the Customer directly, or write to us.
- No use to train general AI models. We do not use Caller audio, recordings or transcripts to train general-purpose AI models, ours or anyone else’s, and we do not permit our AI providers to do so with your data under our agreements with them.
- Emergencies. Lumoscale agents are not a route to emergency services. In an emergency, call your local emergency number (112 in India, 911 in the US).
4. How we use information
| Purpose | Examples |
|---|---|
| Provide the Service for Customers | Answer and place calls, book appointments, transcribe, summarise, run campaigns and callbacks, show dashboards and reports. |
| Accounts, billing and support | Log-in, credits and invoices, responding to requests, service notices. |
| Security and fraud prevention | Access controls, rate limiting, detecting misuse such as spam or unlawful calling. |
| Improve and maintain the Service | Fixing bugs, measuring latency and reliability, using aggregated or de-identified metrics that do not identify any Caller. |
| Legal and compliance | Meeting tax, accounting and legal obligations, responding to lawful requests, enforcing our Terms. |
| Marketing to businesses | Telling prospects and Customers about Lumoscale. You can opt out at any time. |
Our basis is: consent (which you can withdraw), performance of a contract with a Customer, our legitimate uses under the DPDP Act such as compliance with law, and our legitimate business interests such as security. For Caller data, the Customer is responsible for having a valid basis.
5. Who we share information with
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We share only as needed:
- The Customer whose call it was, and that Customer’s authorised users and integrations (for example a calendar or CRM it connects).
- Service providers (sub-processors) that help us run the Service, under written confidentiality and data-protection terms: telephone carriers and network providers, real-time audio and media infrastructure, speech and language AI providers, cloud hosting, database and file storage, and monitoring and error-reporting tools. We can provide a current list on request.
- Authorities and advisers where required by law, court order or to protect rights and safety, and to professional advisers under confidentiality.
- A successor in a merger, acquisition or asset sale, who must honour this policy.
6. International transfers
We serve Customers and Callers in India and the United States. Data may be processed in India, the United States and other countries where our providers operate. Where required, we use contractual and technical safeguards so your data keeps equivalent protection, and we comply with any transfer restrictions notified under the DPDP Act.
7. How long we keep data
- Call records and lead/appointment data: by default 90 days, then deleted automatically.
- Call audio recordings: by default 30 days, then deleted automatically.
- Customers can set shorter or longer periods for their workspace, so a Customer’s own policy may differ. Customers can also delete data earlier.
- Billing and financial records are kept, stripped of call content, for as long as tax and accounting law requires, even after call data is deleted.
- Account data is kept while the account is active and for a limited period afterwards. Security logs are kept for at least the period the law requires.
- Copies in backups are overwritten in the ordinary course. We may keep data longer where needed for a legal claim or legal obligation.
8. Security
We use safeguards appropriate to the risk, including encryption in transit, encryption of stored credentials and integration secrets, strict separation between each Customer’s data, role-based access, private storage for recordings accessed through short-lived links, and rate limiting and monitoring. No system is perfectly secure. If a personal data breach affects you, we will notify the affected Customer without undue delay and, where we are the responsible party, notify you and the relevant authority as the law requires (including within 72 hours where the DPDP Rules apply).
9. Your rights and choices
India (DPDP Act)
You may ask to access a summary of your personal data and who it is shared with, correct or update it, erase it, withdraw consent, have your grievance addressed, and nominate someone to exercise these rights on your behalf if you die or become incapacitated.
United States
Depending on your state (including California, Colorado, Connecticut, Virginia, Texas and others), you may have the right to know what we hold, access and correct it, delete it, receive a portable copy, opt out of sale, sharing or targeted advertising (we do none of these), and not be discriminated against for using your rights. Nothing here limits rights you have under your own state’s law.
How to exercise them
- If your data came from a call with a business, ask that business first, or write to us and we will pass the request to them or act on their instruction.
- For our own data, email contact@lumoscale.com. We may need to verify your identity. We aim to respond within 30 days (45 days for US state requests, extendable as the law allows). You may use an authorised agent, and you may appeal a refusal by replying to our decision.
- To stop marketing emails, use the unsubscribe link or write to us.
If you are unhappy with our response you may complain to the Data Protection Board of India or your state attorney general.
California notice at collection
In the past 12 months we collected identifiers (name, phone, email, IP address), commercial information (usage and credits), audio and electronic recordings (call audio and voice), internet activity (site and dashboard use), and inferences (call sentiment and outcome), for the purposes in section 4. We did not sell or share personal information, and we do not use or disclose sensitive personal information to infer characteristics about consumers.
10. Cookies and similar technologies
We use only what is needed to run the Service: a secure session to keep Account Users signed in and browser storage to remember preferences such as theme. We do not use advertising cookies. Our website loads fonts from a third-party font service and offers demo booking through a third-party scheduling page, which may receive your IP address and their own cookies under their own policies. We honour browser “Global Privacy Control” signals.
11. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect children’s data. Customers must not use agents to target children or process children’s data without the verifiable parental consent the law requires. If you believe a child’s data has reached us, contact us and we will delete it.
12. Changes to this policy
We will post updates here with a new date, and notify Account Users by email or in the dashboard for material changes. Continued use after the effective date means you accept the update; where the law requires fresh consent, we will ask for it.
13. Contact and grievance officer
Lumoscale (sole proprietorship of Vamsi), India
Privacy requests:
Grievance Officer (India): Vamsi (proprietor), vamsi@lumoscale.com. We acknowledge grievances within 7 days and aim to resolve them within 30 days.
Lumoscale