The paperwork, in plain sight.
Everything that governs your use of GRX10 products and services, on one page: our privacy policy, terms of service, data processing addendum and grievance redressal process.
Privacy Policy.
We collect only what we need to run your account and your campaigns. Conversations your customers have with our AI agents belong to you. We process them on your instructions, keep recordings 90 days by default, and delete on request. Write to admin@grx10.com to exercise any right; we respond within 30 days.
Who we are in this relationship
Under India's Digital Personal Data Protection Act, 2023 (DPDP Act), GRX10 Solutions Private Limited acts as a Data Fiduciary for the data you give us directly (your account, billing and contact information) and as a Data Processor for the data of your customers that flows through our products — calls, messages and CRM records processed on your documented instructions.
Data we collect
- Account data — name, email, mobile number, and the identity or business verification documents required for your plan tier.
- Usage data — call metadata, transcripts, and audio recordings made with consent.
- Billing data — tax registration details and the last four digits of payment instruments.
- Technical data — IP address, device fingerprint, and webhook signing keys.
How we use it
To operate the service, route and record calls you configure, generate transcripts and reports, bill you accurately, prevent fraud and abuse, and meet legal obligations. We do not sell personal data, and we do not use your customers' conversations to train models for anyone else.
Your rights
You may request access, correction, or erasure of your personal data, and withdraw consent where processing rests on it. Send requests to admin@grx10.com. We respond within 30 days.
Retention
- Call recordings — 90 days by default, configurable down to a 7-day minimum.
- Transcripts — 2 years.
- Billing records — 7 years, as statute requires.
- Account data — life of the account plus 1 year.
Grievances
Unresolved privacy concerns follow the grievance redressal process in the Grievance Redressal section below.
Terms of Service.
Use the products lawfully, verify your identity for the tier you are on, and pay for what you use. We can suspend accounts that break calling rules or the law. Liability is capped at your trailing twelve months of platform fees; disputes are settled in the courts of Bengaluru, India.
1. Acceptance of terms
The service is operated by GRX10 Solutions Private Limited. By creating an account or using any GRX10 product, you accept these terms together with the Privacy Policy and, where applicable, the Data Processing Addendum.
2. Account & eligibility
You must be 18 or older. Verification scales with your plan: entry tiers verify by mobile OTP and may call only verified destinations; higher tiers require identity KYC; enterprise accounts require business registration documents. Accounts that cannot be verified may be limited or closed.
3. Acceptable use
- No calls or messages that violate telecom regulations or do-not-disturb registries in the destination market.
- No impersonation of government bodies, law enforcement, regulators or emergency services.
- No fraud, phishing, harassment or extortion.
- No calls to numbers GRX10 has blocklisted, and no circumvention of rate limits or KYC.
4. Billing
Platform usage is billed monthly in arrears at the rates on your plan. Carrier charges are passed through at cost. Applicable taxes are additional. Unused prepaid credits are refundable pro-rata within 30 days; carrier pass-through charges are non-refundable.
5. Suspension
We may suspend an account when KYC cannot be verified, blocklisted destinations are dialled, complaint thresholds are crossed, a regulator or law-enforcement direction requires it, or billing is in default for more than 15 days. Where the law allows, we notify you before or at the time of suspension.
6. Liability cap
Our total liability under these terms is capped at the platform fees you paid in the trailing twelve months, excluding carrier pass-through. Neither party is liable for indirect, consequential or punitive damages.
7. Governing law
These terms are governed by the laws of India. The courts of Bengaluru, Karnataka have exclusive jurisdiction.
Data Processing Addendum.
You are the Data Fiduciary for your customers' data; we process it only on your documented instructions. Everything is encrypted, sub-processors are disclosed, you can audit us annually, and we notify you of any breach affecting your data within 72 hours.
1. Roles
The customer is the Data Fiduciary; GRX10 is the Data Processor and processes personal data only on the customer's documented instructions.
2. Nature of processing
Data subjects are the customer's end-users — the people our agents call, or who call in. Data types processed: phone numbers, names, audio recordings, transcripts and call metadata.
3. Sub-processors
- Primary cloud provider (Mumbai region) — hosting and storage.
- Secondary India compute provider — GPU inference.
- Licensed carrier partners — voice termination.
- Cloud AI provider — audio model inference.
The current sub-processor list is available on request from admin@grx10.com. We give notice before adding or replacing a sub-processor.
4. Security measures
AES-256 encryption at rest, TLS 1.3 in transit, per-tenant encryption keys, PII tokenisation in logs, least-privilege access with MFA, and an annual penetration test. Details on the Security page.
5. Breach notification
GRX10 notifies the customer of any personal data breach affecting their data within 72 hours of confirming it, with the facts, the data involved, containment status and next steps.
6. Audit rights
Customers may audit our compliance with this addendum once per year, on 30 days' notice, under NDA. Enterprise agreements may provide for more frequent audits.
7. Termination
On termination, we delete or return personal data within 30 days, subject to statutory retention obligations.
Grievance Redressal.
One named person answers for complaints, not a ticket queue. We acknowledge every grievance within 24 hours and resolve it within 15 days.
What you can raise
Complaints about calls or messages made through GRX10 products, privacy and data concerns, content takedown requests, or anything you believe violates our terms or applicable law — including India's IT Rules, 2021 and the DPDP Act, 2023.
Response timeline
- Acknowledgement within 24 hours.
- Resolution within 15 days.
- Urgent takedown categories are actioned within 24 hours as the IT Rules require.
If you are not satisfied
You may appeal to the Grievance Appellate Committee constituted under the IT Rules, 2021, or approach the Data Protection Board of India for DPDP matters.
Include your account email, the number or campaign involved, and dates.