- 1Protect your privacy by agreeing to Girikon AI's Privacy Policy to use their services.
- 2Rely on Girikon AI's enterprise-grade security, evidenced by SOC 2 Type II, ISO 27001:2022, and ISO/IEC 42001 certifications.
- 3Understand that Girikon AI collects personal identifiers, account data, usage logs, device information, and location data.
- 4Benefit from Girikon AI using your data for service operation, improvement, personalization, and customer support.
- 5Be assured that Girikon AI does not sell your data and shares it only with trusted service providers and sub-processors under strict contractual agreements, including DPAs with AI partners like OpenAI and Google.
Overview
Girikon AI Inc. ("Girikon AI," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at girikon.ai, use our AI-powered products (GirikUnified, GirikVOICE, GirikCTI, GirikSMS, GirikQA, GirikHire, GirikIQ, GirikForms), or interact with us in any other way.
By accessing or using our services, you agree to the terms of this Privacy Policy. If you do not agree, please discontinue use of our services.
Enterprise-Grade Security & Compliance: Girikon AI is SOC 2 Type II certified, ISO 27001:2022 certified for information security management, and ISO/IEC 42001 certified for AI management systems. Our security and privacy practices are independently audited to ensure your data is handled with the highest standards of protection and governance.
Certifications & Technology Partnerships
Girikon AI maintains the highest standards of security, quality, and governance through multiple independent certifications and strategic technology partnerships:
Enterprise Technology Partnerships: Girikon AI is a certified Salesforce Consulting Partner, Oracle Gold Partner, Microsoft Gold Application Development Partner, and Adobe Technology Partner. These partnerships validate our expertise in secure, compliant platform integrations and our commitment to customer success.
Information We Collect
We collect information in several ways depending on how you interact with us:
Information you provide directly includes name, email address, phone number, company name, job title, billing information, and any messages you send us through forms or support channels.
Information collected automatically includes IP addresses, browser type, operating system, referring URLs, pages visited, session duration, and Salesforce platform integration metadata when you use our products.
How We Use Your Information
We use the information we collect to operate, improve, and personalise our services. Specifically, we use your data to:
- Provide and manage services — deliver, operate, and maintain GirikUnified, GirikVOICE, GirikCTI, GirikSMS, GirikQA, GirikHire, GirikIQ, GirikForms, and related Salesforce AppExchange products.
- Process transactions — handle billing, payments, and enterprise licensing agreements.
- Customer support — respond to enquiries, troubleshoot issues, and provide technical assistance within our 2-hour average response commitment.
- Product improvement — analyse usage patterns to improve AI agent performance, reduce handle time, and increase query resolution rates.
- Communications — send product updates, security alerts, promotional materials (where consented), and policy change notifications.
- Security & compliance — detect fraud, enforce terms of service, and meet legal obligations including SOC 2 audit requirements.
- Analytics — measure and understand service performance, user engagement, and business metrics.
Sharing & Disclosure
We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We may share your information only in the following circumstances:
- Service providers — trusted vendors who assist us in operating our platform (hosting, analytics, payment processing, email delivery). They are contractually bound to protect your data.
We share your data with the following third-party sub-processors to deliver AI-powered features. All sub-processors are contractually required to protect your data and have Data Processing Agreements (DPAs) in place.
| Sub-Processor | Service / API | Data Transferred | Purpose | Safeguards |
|---|---|---|---|---|
| OpenAI | GPT APIs | Call transcripts, meeting notes | Transcription, Q&A, summarisation | DPA; Data never used for training |
| Google (Gemini) | Gemini API | Call content, meeting transcripts | AI summarisation, sentiment analysis | DPA; Data never used for training |
| Salesforce | Salesforce Platform | All CRM records, activities, metadata | Core platform hosting & integration | Salesforce DPA; Standard Contractual Clauses |
| Meta (WhatsApp) | WhatsApp Business API | Phone numbers, message content | SMS & WhatsApp messaging delivery | Meta Business DPA |
| Meta (WhatsApp Calling) | WhatsApp Cloud API / SIP | Phone numbers, call metadata, call logs | Voice calling, transcription, automated tasks | Meta Business DPA; End-to-end encrypted by WhatsApp |
| Twilio | CTI, Voice, SMS APIs | Phone numbers, call metadata, SMS content, call recordings | CTI integration, voice calling, SMS delivery, IVR, call recording | Twilio DPA; Standard Contractual Clauses |
| Telnyx | CTI, Voice, SMS APIs | Phone numbers, call metadata, voice content, SMS content | CTI integration, voice calling, SMS delivery, call routing | Telnyx DPA; Standard Contractual Clauses |
| TATA Communications | SMS Gateway | Phone numbers, SMS text content | SMS delivery (India TRAI compliant) | TATA DPA; TRAI regulations |
| Smartflo (TATA Communications) | Contact Center Platform | Call logs, agent data, customer interactions, call recordings | Contact center management, call queuing, IVR, analytics | TATA DPA; TRAI regulations |
| ServiceNow | ITSM, Workflow Platform | Service requests, incident data, user activity, configuration items | IT service management, workflow automation, incident tracking | ServiceNow DPA; Standard Contractual Clauses |
| HubSpot | CRM, Marketing Automation | Contact data, interaction history, email content, engagement metrics | CRM management, marketing automation, customer engagement tracking | HubSpot DPA; Standard Contractual Clauses |
| Microsoft Azure | Cloud Infrastructure | As required for service operation | Infrastructure, hosting, compute | Microsoft DPA; Standard Contractual Clauses |
- Salesforce ecosystem — because our products run natively on Salesforce, certain data interactions occur within the Salesforce platform under its own Privacy Policy.
- Business transfers — in the event of a merger, acquisition, or sale of assets, your data may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
- Legal requirements — when required by law, court order, or to protect the rights, property, or safety of Girikon AI, its users, or the public.
- With your consent — for any other purpose with your explicit prior consent.
We never sell your data. Girikon AI products are built on an enterprise-grade trust model — your data is yours.
Cookies & Tracking Technologies
We use cookies and similar tracking technologies to enhance your experience, understand how our site is used, and deliver relevant content.
- Essential cookies — required for core site functionality, authentication, and security.
- Analytics cookies — help us understand visitor behaviour and page performance (e.g., Google Analytics).
- Preference cookies — remember your settings and personalisation choices.
- Marketing cookies — used to deliver relevant advertisements. You can opt out at any time.
You can control cookie settings through your browser preferences or our cookie consent banner. Note that disabling certain cookies may affect site functionality.
Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes outlined in this policy, comply with legal obligations, resolve disputes, and enforce our agreements.
- Account data — retained for the duration of your account and up to 3 years after termination for legal compliance.
- Usage & log data — retained for up to 12 months in identifiable form, then anonymised for analytical purposes.
- Communication records — support tickets and emails retained for 2 years.
- Financial records — retained for 7 years as required by applicable tax and accounting regulations.
When your data is no longer needed, we securely delete or anonymise it in accordance with our data disposal procedures.
Your Rights
Depending on your location, you may have the following rights regarding your personal data under applicable laws including GDPR, CCPA, and other regional privacy regulations:
- Right to access — request a copy of the personal information we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure — request deletion of your personal data ("right to be forgotten"), subject to legal obligations.
- Right to restriction — request that we limit how we process your data in certain circumstances.
- Right to portability — receive your data in a structured, machine-readable format.
- Right to object — object to processing based on our legitimate interests or for direct marketing.
- Right to withdraw consent — where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, contact us at privacy@girikon.com. We will respond within 30 days or as required by applicable law.
If you reside in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under GDPR and applicable data protection laws:
- Right to lodge a complaint — You have the right to lodge a complaint with your local Data Protection Authority (DPA) if you believe we have violated your rights. Notable authorities include:
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
- Right to Know — Request what categories and specific pieces of personal information we have collected.
- Right to Delete — Request deletion of personal information collected from you, subject to certain exceptions.
- Right to Correct — Request correction of inaccurate personal information we maintain about you.
- Right to Opt-Out — Opt out of the sale or sharing of your personal information for cross-context behavioural advertising.
- Right to Limit Use — Limit our use of sensitive personal information to purposes necessary to provide requested services.
- Right to Non-Discrimination — We will not discriminate against you for exercising your CCPA/CPRA rights.
- Annual Limit — You may submit up to 2 requests per 12-month period at no charge.
To exercise California consumer rights, contact us at privacy@girikon.com with "CCPA Request" in the subject line.
If you are a resident of India, you have the following rights under the Digital Personal Data Protection (DPDP) Act, 2023:
- Right to access your data — Request a copy of your personal data held by Girikon AI.
- Right to correction — Request correction of inaccurate or incomplete personal data.
- Right to erasure — Request deletion of your personal data where we no longer have a lawful basis to process it.
- Right to grievance redressal — Lodge a grievance with our Grievance Officer if you believe your rights have been violated. We will respond within 30 days.
Contact our Data Principal at privacy@girikon.com for any DPDP Act requests or grievances.
Security
We implement industry-standard technical, administrative, and physical security measures to protect your personal information against unauthorised access, disclosure, alteration, or destruction. Our commitment to data protection is demonstrated through multiple independent certifications and partnerships with leading technology providers.
- Encryption — data is encrypted in transit using TLS 1.2+ and at rest using AES-256 encryption standards.
- Access controls — strict role-based access controls (RBAC) and principle of least privilege limit internal access to personal data.
- SOC 2 Type II Certified — our security and confidentiality controls are independently audited annually by third-party auditors.
- ISO 27001:2022 Certified — our information security management system (ISMS) is certified and regularly audited for continuous compliance.
- ISO/IEC 42001 Certified — our AI management system demonstrates responsible AI development and governance practices.
- ISO 9001:2015 Certified — our quality management system ensures consistent service delivery and continuous improvement.
- ISO 14001:2015 Certified — our environmental management system reflects our commitment to sustainable operations.
- Incident response — we have a documented breach notification process and will notify affected users within 72 hours of becoming aware of a significant breach, in compliance with applicable data protection regulations.
Technology Partnerships: Girikon AI is a certified Salesforce Consulting Partner, Oracle Gold Partner, Microsoft Gold Application Development Partner, and Adobe Technology Partner. These partnerships ensure we maintain the highest standards of integration, security, and compliance across enterprise platforms. We are also Great Place To Work certified, reflecting our commitment to an inclusive and secure workplace culture.
No method of transmission over the Internet is 100% secure. While we strive to protect your data through multiple layers of security and third-party validation, we cannot guarantee absolute security.
Data Processing Addendum (DPA)
For enterprise and B2B customers who require a formal Data Processing Addendum (DPA), Girikon AI offers a standard DPA template that governs the processing of personal data as a data processor (or joint controller) under GDPR Article 28 and similar international regulations.
- Who needs a DPA? — B2B customers, especially those subject to GDPR, CCPA, DPDP Act, or other data protection laws, should execute a DPA to establish compliant data processing terms.
- What's included? — Our standard DPA covers data subject rights, sub-processor authorisation, data security obligations, breach notification, international transfers (Standard Contractual Clauses), and audit rights.
- How to request? — Contact us at privacy@girikon.com with the subject line "DPA Request" and include your organisation name, contact details, and jurisdiction. We will provide our standard DPA within 10 business days.
- International transfers — For transfers outside your region (e.g., EU to US), our DPA references EU Standard Contractual Clauses (SCCs) as the legal mechanism to ensure adequate data protection safeguards.
Security Evidence: Our SOC 2 Type II certification and ISO 27001:2022 accreditation provide independent verification of our security controls and data protection practices. These certifications are referenced in our DPA as supporting evidence of our ability to safeguard customer data.
Third-Party Links
Our website and products may contain links to third-party websites, including Salesforce AppExchange, partner sites, and external documentation. These third-party sites have their own privacy policies, and we have no responsibility or liability for their content or practices.
We encourage you to review the privacy policies of any third-party sites you visit.
Children's Privacy
Our services are designed for business and enterprise use and are not directed to children under the age of 16. We do not knowingly collect personal information from children.
If you believe we have inadvertently collected data from a child under 16, please contact us immediately at privacy@girikon.com and we will take prompt steps to delete such data.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
When we make material changes, we will notify you by updating the "Last Updated" date at the top of this page, sending an email to registered users, or displaying a prominent notice on our website. We encourage you to review this policy periodically.
Your continued use of our services after the effective date of any changes constitutes your acceptance of the revised policy.
AI Calling & CTI (GirikVOICE / GirikCTI)
Our AI Calling CTI processes communication and operational data to facilitate the following services:
Integrated AI tools provide Real-Time Note Taking and Automated Task Creation, automatically capturing key information during calls and creating follow-up actions inside Salesforce — without requiring manual input from agents.
- Live Call Monitoring — supervisors may silently listen to active calls for quality assurance purposes.
- Barge & Whisper — supervisors can whisper guidance to agents or barge into calls to assist customers directly.
- Call Broadcasting — mass voice broadcasts may be sent to lists of contacts for operational or campaign purposes.
Consent Responsibility: All data is processed securely and integrated with your Salesforce environment. Users and administrators are solely responsible for obtaining all necessary participant consents required by applicable law for any monitored, recorded, or broadcasted interactions.
US All-Party Consent States: Recording laws vary by jurisdiction. In the following US states, recording a conversation requires the consent of ALL parties, not just one: California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, Oregon, Washington. Recording without consent of all parties in these states may violate state wiretapping and eavesdropping laws. Administrators must verify compliance with state law before enabling recording features.
Google Meet & Calendar Permissions
This application is operated by Girikon AI and is designed to help users view and sync meeting information through Google Calendar integrations.
- Basic Account Details (auth/userinfo.email, auth/userinfo.profile) — Your name and primary Google email address used for authentication.
- Calendar Availability (auth/calendar.freebusy) — Free/busy status used exclusively to detect scheduling conflicts.
- Calendar and Event Data (auth/calendar.readonly, auth/calendar.calendars.readonly, auth/calendar.events.owned.readonly) — Read-only access to view calendar titles, time zones, properties, and owned event details.
- How We Use Your Data: This data is used solely to provide and improve user-facing features of our application: displaying calendar schedules, verifying event metadata, and checking availability. Because this application requests strictly read-only permissions, we do not create, modify, delete, or update any of your calendar events, nor do we manage Google Meet configuration links.
- Data Sharing and Transfers: We do not sell, rent, or share your Google data with third parties for advertising or unrelated purposes. We only transfer Google data to others if that transfer is necessary to provide or improve user-facing features of the application, to comply with applicable laws, or as part of a merger, acquisition, or sale of assets. All data transfers comply with applicable data protection laws.
- For users in the EEA/UK/Switzerland: Your personal data will be transferred outside these regions only when appropriate safeguards are in place, such as standard contractual clauses (SCCs), and in compliance with GDPR/UK GDPR requirements. You may request details of these safeguards by contacting us.
- Data Retention and Deletion: We store calendar and meeting data only as long as needed to provide the service. Upon account deletion or user request, calendar event data is permanently removed from our servers. You can revoke access and request data deletion at any time through your Google Account settings or by contacting us directly.
- Our use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements. We access only the minimum permissions necessary to provide the requested read-only functionality.
Data Access and Processing: Your data is accessed and processed solely to provide or improve user-facing features. We do not use your Google data for personalized advertising, ad targeting, or any unrelated commercial purposes. All processing is conducted in accordance with this policy and applicable data protection laws.
Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements. We access only the minimum permissions necessary to provide the requested functionality.
Microsoft API Permissions
When you connect Girikon AI to your Microsoft 365 account, we request the following OAuth permissions to provide calendar and scheduling functionality. All permissions are scoped to the minimum required for operation.
- Read Your Calendar — View your calendar events and availability to check scheduling conflicts and retrieve meeting details.
- Manage Your Calendar — Create, update, and delete calendar events on your behalf to schedule and manage meetings.
- Stay Signed In — Keep you connected in the background so the app can sync your calendar without asking you to sign in repeatedly.
- Sign In & Read Your Profile — Identify who you are and access your basic profile (name and email) to personalise the experience.
- Read Organisation Calendars — Access calendars across your organisation for admin-level scheduling and team-wide availability checks.
- Read All User Profiles — Look up colleague details from your organisation's directory to resolve attendees and contacts.
AI Call & Recording
Our AI Call & Recording capability captures, transcribes, and analyses voice interactions to improve service delivery and agent performance. The following data may be collected and processed during AI-enabled calls:
- Audio recordings — full or partial call recordings stored securely and encrypted at rest with AES-256.
- Real-time transcripts — live speech-to-text conversion used to generate notes and trigger automations in Salesforce.
- Sentiment analysis — AI-derived signals (tone, sentiment, intent) extracted from call audio to assist supervisors and QA teams.
- Automated task data — structured output (follow-up tasks, case updates, field changes) written back to Salesforce records based on call content.
- Agent performance data — talk time, silence ratio, script adherence, and other analytics used for coaching and compliance review.
Recording Consent: Call recording and AI analysis may be subject to wiretapping, telemarketing, and data protection laws in your jurisdiction. Administrators and users are responsible for disclosing recording activity to all call participants and obtaining legally required consents before enabling recording features.
US All-Party Consent States: Recording laws vary by jurisdiction. In the following US states, recording a conversation requires the consent of ALL parties, not just one: California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, Oregon, Washington. Recording without consent of all parties in these states may violate state wiretapping and eavesdropping laws. Administrators must verify compliance with state law before enabling recording features.
Recordings and transcripts are retained per your configured data retention policy and can be deleted on request. Access is restricted to authorised personnel only.
SMS, WhatsApp & Messaging Services
GirikSMS integrates with the TATA Communications SMS gateway for enterprise-grade SMS delivery. The following data is processed through this integration:
- Recipient phone numbers — sourced from Salesforce records and used solely for message delivery.
- Message content — SMS body text, including personalisation tokens resolved at send time.
- Delivery receipts — sent, delivered, and failed status codes returned by the TATA gateway and written back to Salesforce.
- Sender ID / DLT registration — approved sender headers required under TRAI DLT regulations for India-bound traffic.
All SMS traffic sent via TATA Communications is subject to TRAI regulatory requirements. Administrators are responsible for registering templates and obtaining recipient consent per applicable telemarketing regulations.
GirikSMS supports WhatsApp Business messaging via the official WhatsApp Business API (Meta). Data processed includes:
- WhatsApp-enabled phone numbers — used to initiate or receive business-initiated messages (BIMs) and user-initiated conversations.
- Message content — text, media attachments (images, documents, audio), and interactive message payloads (buttons, lists).
- Template messages — pre-approved message templates required for proactive outreach outside the 24-hour messaging window.
- Conversation metadata — session timestamps, read receipts, and conversation window status.
Use of WhatsApp Business API is subject to Meta's WhatsApp Business Policy. Administrators must ensure all contacts have opted in to receive WhatsApp messages from your business before sending.
GirikVOICE extends into WhatsApp Business Calling, enabling voice calls initiated directly through the WhatsApp platform. The following data is processed:
- Call audio — encrypted end-to-end by WhatsApp; Girikon AI processes metadata only (duration, timestamps, call outcome).
- Call logs — call records written to Salesforce activity history for CRM tracking and reporting.
- AI note-taking — where enabled, real-time transcription and automated task creation are applied to WhatsApp calls in the same manner as PSTN calls.
WhatsApp Business Calling is available only to approved WhatsApp Business API partners. Organisations must comply with Meta's calling policies and applicable telecommunication regulations in their operating region. User consent for call recording and AI analysis must be obtained prior to enabling these features.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your data, please reach out to us: