Privacy policy
How Yandle collects, uses, and protects personal data when teams use our platform and customers interact through voice and connected channels.
Effective date
8 July 2026
1. Scope and roles
This Privacy Policy applies to website visitors, account holders, and authorized users of Yandle Services. For customer calling workflows, customer acts as Data Fiduciary/Controller and Yandle acts as Data Processor under applicable law unless otherwise agreed in writing.
2. Categories of personal data
- Account and billing data (name, email, phone, organization details, invoices, payment references)
- Operational data (settings, scripts, prompts, integration metadata, support conversations)
- Call data (caller identifiers, timestamps, recordings, transcripts, summaries, tags, outcomes)
- Security and device data (IP address, user-agent, logs, session events, fraud signals)
3. Purposes of processing
We process data to operate and secure the Services, route and analyze calls, provide support, detect abuse, fulfill contractual obligations, comply with law, and improve reliability using aggregated/de-identified telemetry where permitted by contract.
4. Lawful basis and customer obligations
We process account data based on contract and legitimate interest. Customers are responsible for obtaining required notices and consents (including call recording disclosures) and for honoring opt-out/withdrawal requests in applicable jurisdictions.
5. Sharing and disclosure
We may share data with vetted infrastructure, telephony, analytics, payment, and security providers under contractual protections. We may disclose data where required by law, legal process, or to protect rights, safety, and service integrity. We do not sell personal data.
6. International transfers and localization
Primary processing for applicable customer workloads is performed in India. If cross-border processing is required for resilience/support, we apply contractual and technical safeguards consistent with applicable law.
7. Retention and deletion
Data is retained for the active service term and legitimate business/legal purposes. After termination, customer export is available for up to 30 days unless otherwise agreed. Deletion schedules then apply, subject to legal hold, fraud prevention, and regulatory recordkeeping requirements.
8. Security controls
We apply layered controls including encryption in transit, access controls, tenant separation, monitoring, and incident response procedures. No method is absolutely secure, but we continuously assess and improve safeguards.
9. Data subject rights
Where applicable, data subjects may request access, correction, deletion, restriction, and grievance handling. If Yandle processes data as processor, requests may be routed through the relevant customer controller/fiduciary.
10. Cookies and tracking
We use essential cookies for authentication, security, and service continuity. Non-essential analytics may be used as disclosed in the Cookie Policy and may be controlled through browser settings where supported.
11. Children's data
The Services are not directed to children. We do not knowingly collect children's data for independent marketing use.
12. Incident and breach response
If we identify a personal data incident affecting customer data, we notify impacted customers without undue delay as required by law and contract, and cooperate with reasonable incident handling obligations.
13. Policy updates
We may update this policy from time to time. Material updates are published with revised effective date.
14. Contact
Privacy or grievance requests: privacy@yandle.io. Registered office: Bengaluru, Karnataka, India.
15. Governing law
This policy is governed by applicable laws of India unless otherwise required by mandatory local law.