GRX10← Legal hub
GRX10

Privacy Policy

GRX10 Solutions Private Limited MKB Tower, 3rd Floor, 2nd Cross Road, Appareddy Palya Road, HAL 2nd Stage, Indiranagar, Bengaluru, Karnataka 560008, India

Effective date: 23 July 2026 · Last updated: 23 July 2026

Hosting note: publish at https://grx10.com/privacy-policy (replacing the current version). Marketplace and app-store reviews (Meta, Google, Pipedrive, HubSpot, Zoho) require a public, dated privacy policy at a stable URL.

1. Who we are

GRX10 Solutions Private Limited ("GRX10", "we", "us") provides AI-powered business software delivered as a suite of applications:

This policy explains what personal data we collect, how we use it, who we share it with, and the rights you have. It covers our website (grx10.com) and the applications listed above (the "Services").

Controller vs processor. For our own website visitors, prospects and account administrators, GRX10 is the data controller. For the customer records our business customers load into the Services (their leads, contacts, call recipients), GRX10 acts as a data processor on that customer's behalf — see our Data Processing Addendum and Subprocessor list.

2. Data we collect

You provide directly: name, email, phone number, company, role, billing details, and the content of messages you send us.

Created by using the Services: account and usage data, log data (IP address, browser, device, timestamps), and — for Voice AI — call metadata, recordings and transcripts where you have enabled them.

Customer-uploaded data (we process on our customers' behalf): the contact records, phone numbers, and conversation histories our business customers manage in Micro CRM, Nudge and Voice AI.

Automatically: cookies and similar technologies for authentication, preferences and analytics (see §8).

3. How we use data

We use personal data to: provide and operate the Services; authenticate users and secure accounts; process transactions and billing; respond to enquiries and provide support; send service and (with consent) marketing communications; monitor, debug and improve the Services; prevent fraud and abuse; and comply with legal obligations.

We do not sell your personal data, and we do not share it with third parties for their own marketing. (This replaces prior language permitting sharing of email addresses with other organisations.)

4. Legal bases (GDPR / DPDP)

We rely on: performance of a contract (to deliver the Services), legitimate interests (security, product improvement, B2B communications), consent (marketing, non-essential cookies, call recording where required), and legal obligation. Under India's Digital Personal Data Protection Act, we process personal data on the basis of consent or legitimate uses as defined by the Act.

5. Sharing and subprocessors

We share personal data only with: (a) subprocessors who host and power the Services under contract (see SUBPROCESSORS.md); (b) payment processors for billing; (c) authorities where legally required; and (d) a successor entity in a merger or acquisition. All subprocessors are bound by data-protection terms and may only process data on our instructions.

6. International transfers

We are based in India and use infrastructure in India and other regions. Where personal data is transferred across borders, we use appropriate safeguards (contractual data-protection terms with each subprocessor).

7. Retention

We keep personal data only as long as needed for the purposes above or as required by law. Account data is retained for the life of the account; on deletion it is removed or anonymised within 90 days, except where retention is legally required. Call recordings and transcripts follow the retention period configured by the customer. Customers may request export or deletion at any time (see §9).

8. Cookies

We use strictly necessary cookies (authentication, security), preference cookies, and analytics cookies. Non-essential cookies are set only with consent. You can control cookies through your browser settings.

9. Your rights

Depending on your jurisdiction (India DPDP, EU/UK GDPR, California CCPA/CPRA), you may have the right to access, correct, delete, port, or restrict processing of your personal data, to withdraw consent, and to object to certain processing. California residents have the right to opt out of "sharing"/"selling" — note we do neither.

To exercise any right, email privacy@grx10.com (or support@grx10.com). We respond within the timeframe required by applicable law. Where GRX10 processes data on behalf of a business customer, we will refer your request to that customer.

10. Security

We protect personal data with role-based access control, encryption in transit, audit logging, signed and reviewed code changes, dependency and secret scanning, and least-privilege access. No method of transmission or storage is perfectly secure; we work continuously to protect your data. Report vulnerabilities to security@grx10.com (see our security policy).

11. Children

The Services are for business use and are not directed to children under 18. We do not knowingly collect their data.

12. Grievance / Data Protection contact

Grievance Officer (India DPDP): GRX10 Solutions Private Limited, at the registered address above · privacy@grx10.com For EU/UK matters, the same contact serves as our data-protection point of contact.

13. Changes

We may update this policy. Material changes will be posted here with a new effective date; where required by law we will seek consent or provide notice. Continued use of the Services after an update constitutes acceptance.


This document is a drafting aid prepared for GRX10 and should be reviewed by qualified legal counsel before publication.