PrivacyTermsData deletion
Login
Trust centre

Privacy Policy

How RevPilot AI handles business, lead, messaging and call data when providing its revenue operations service.

Effective 27 September 2026Last updated 27 September 2026
Our roleProcessor for client CRM data
Primary storageMumbai, India
Data salesNever
AI trainingNever with client data

1. Who operates RevPilot AI

RevPilot AI is operated by Inflex Media (“Inflex Media”, “RevPilot AI”, “we”, “us” or “our”). This policy applies to the RevPilot AI website, CRM workspace, integrations and related support services.

Privacy questions and requests may be sent to harsh@bluinfotech.com.

2. Our role: processor for client data

A business using RevPilot AI decides why its leads and customers are contacted, which information is collected, how long that information is needed and which communication channels are used. For that client CRM data, the client business is the data controller (called a “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023), and Inflex Media acts as its data processor.

We process that information only to provide, secure and support RevPilot AI, under the client’s instructions and our agreement with the client. For limited information that Inflex Media collects for its own account administration, security, fraud prevention and legal compliance, Inflex Media may act as the Data Fiduciary.

The definitions and responsibilities in this policy are intended to align with the Digital Personal Data Protection Act, 2023 and applicable rules.

3. Information we process

Depending on the features selected by a client, RevPilot AI may process:

  • Lead and contact information: names, business names, phone numbers, email addresses, locations, lead sources, campaign attribution and consent or opt-out records.
  • WhatsApp information: inbound and outbound message content, message identifiers, template details, attachments, delivery/read status and conversation timestamps.
  • Call information: caller and recipient numbers, call direction, time, duration, outcome, recordings and transcripts where call recording and transcription are enabled lawfully.
  • CRM activity: pipeline stages, lead value, expected close date, assignments, tasks, notes, meetings, outcomes, qualification signals, AI-generated drafts and audit history.
  • Workspace information: authorised user names, business email addresses, roles, authentication records and security events.
  • Technical information: IP address, request time, browser and device information, diagnostic logs and integration event identifiers needed to operate and secure the service.

4. Where the information comes from

Information may be entered by an authorised user, imported by the client, submitted through a client website or lead form, or received through integrations selected by the client, including Meta lead forms, WhatsApp providers and calling providers. We do not independently purchase lead lists.

5. Why we process information

We process information to capture and deduplicate leads; assign work; display a unified customer timeline; send or receive authorised communications; record consent and opt-outs; schedule follow-ups; create call summaries and transcripts; calculate explainable lead-priority signals; generate human-reviewable drafts; report operational performance; prevent abuse; maintain audit records; and provide support.

No sale and no model training.

We do not sell, rent or trade client data. We do not use client CRM records, WhatsApp content, calls, transcripts or notes to train our own or third-party general-purpose AI models.

6. AI-assisted features

When a client enables an AI feature, limited relevant content may be sent to the configured AI service to create a draft, summary, transcription-derived signal or recommendation. RevPilot AI is designed to keep outbound AI communications subject to client configuration, consent controls and human-review rules. AI output may be incomplete or inaccurate and should be reviewed before it is used for a consequential decision.

7. Service providers and disclosures

We disclose information only as needed to operate the service, follow a client’s instructions, protect the service or comply with law. Relevant providers may include our Mumbai hosting provider, Meta and a client-selected WhatsApp Business Solution Provider, a client-selected telephony provider, and an AI or transcription provider when that feature is enabled.

Each external communication provider processes information under its own terms and privacy practices. We may also disclose information when legally required, to investigate security incidents, or as part of a corporate transaction subject to appropriate confidentiality protections.

8. Data location and security

RevPilot AI’s primary application database and application backups are hosted in Mumbai, India. Data sent through Meta, WhatsApp, telephony, email, AI or transcription integrations may also be processed on infrastructure operated by those providers in locations permitted by the client’s agreement with them.

We use HTTPS encryption in transit, encrypted secrets, tenant-level database isolation, role-based access, signed webhooks, audit trails, restricted administrative access, rate limits and backups. No system is perfectly secure, but we maintain technical and organisational safeguards proportionate to the data handled.

9. Retention and account closure

  • Active accounts: CRM records, messages, call records, recordings, transcripts and activity history are retained for the duration of the client account or until the client instructs us to delete them, subject to legal requirements.
  • Account closure: access is disabled at closure. Client content in the live production system is deleted or irreversibly de-identified within 30 calendar days after the closure request is verified and any agreed export is completed.
  • Backups: deleted client content may remain in encrypted, access-restricted backups for up to 14 additional days before those backups expire through scheduled rotation. Backups are used only for disaster recovery and are not restored to resume ordinary processing of deleted data.
  • Required retention: a limited record may be retained longer where necessary to establish, exercise or defend legal claims, meet tax or legal obligations, investigate abuse or preserve security evidence. We restrict such information and delete or de-identify it when the reason ends.

10. Your privacy choices

If you are a lead or customer of a business that uses RevPilot AI, that business is normally responsible for responding to your access, correction, erasure, consent-withdrawal and grievance requests. You may contact the business directly or email us; we will identify the relevant client and assist it with the request.

For exact deletion instructions and timeframes, visit our Data Deletion page. We honour recorded WhatsApp opt-outs and provide clients with controls to prevent further messaging.

11. Children

RevPilot AI is a business service and is not directed to children. Clients must not intentionally submit children’s personal data unless they have a lawful basis and have met all applicable parental-consent and notice requirements.

12. Changes and contact

We may update this policy when our services or legal obligations change. Material changes will be identified by the “Last updated” date. Questions, complaints and privacy requests may be sent to harsh@bluinfotech.com.

Revenue operations infrastructure operated by Inflex Media.

harsh@bluinfotech.com