Privacy Policy

    How XyRo.ai collects, uses, and protects your information

    Effective Date: April 25, 2025
    XyRo AI Pvt. Ltd. | https://xyro.ai | [email protected]

    1. Introduction

    XyRo AI Pvt. Ltd. ("XyRo", "we", "our", or "us") is committed to protecting the privacy of all individuals who use our AI-powered lead generation and sales automation platform ("Service") available at https://xyro.ai.

    This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service. It applies to all Users, including Organisation Admins, Members, and individual account holders. Please read this Policy carefully.

    This Policy must be read in conjunction with our Terms and Conditions, which govern your use of the Service.

    2. Data Controller

    The data controller responsible for your personal data is:

    XyRo AI Pvt. Ltd.

    Registered in India

    Contact: [email protected]

    Website: https://xyro.ai

    If you are located in the European Union, XyRo AI Pvt. Ltd. acts as the data controller in respect of your personal data under Regulation (EU) 2016/679 ("GDPR").

    3. Information We Collect

    3.1 Account and Organisation Information

    • Name, email address, and password when you register.
    • Organisation name, billing address, and contact information.
    • Payment details (processed by our payment processor; we do not store full card numbers).
    • Job title and role information.

    3.2 Integration Data: Google (Gmail)

    When you connect your Google account to XyRo, we request the following OAuth 2.0 permission scopes. Each scope is used exclusively for the stated purpose:

    • Scope: https://www.googleapis.com/auth/gmail.readonly
      Purpose: To read incoming emails in your Gmail inbox so that XyRo can detect replies to outreach campaigns, update lead statuses in Cortex (our CRM module), and trigger follow-up automations based on reply content.
    • Scope: https://www.googleapis.com/auth/gmail.send
      Purpose: To send emails on your behalf as part of configured sales sequences and automated outreach campaigns. Emails are composed based on templates and personalisation data you define within the Platform.
    • Scope: https://www.googleapis.com/auth/gmail.modify
      Purpose: To apply labels and mark emails as read within your Gmail account, enabling XyRo to organise your inbox and reflect campaign reply states accurately within the Platform.

    XyRo's use of information received from Google APIs strictly adheres to the Google API Services User Data Policy, available at https://developers.google.com/terms/api-services-user-data-policy, including the Limited Use requirements. Specifically:

    • Google user data is used only to provide or improve the user-facing features of the Service.
    • Google user data is not used to develop, train, or improve generalised AI or machine learning models.
    • Google user data is not shared with third parties except as necessary to provide the Service, and only with your direction or consent.
    • We do not allow humans to read your Gmail data unless you have given explicit permission, it is necessary for security purposes, or we are required to do so by law.

    3.3 Integration Data: Microsoft (Outlook / Microsoft 365)

    When you connect your Microsoft account, we request the following Microsoft Graph API permissions:

    • Mail.Read: To read emails in your Outlook inbox to detect replies and update lead statuses.
    • Mail.Send: To send emails from your Outlook account as part of your configured sales automations.
    • Mail.ReadWrite: To apply categories or mark emails as read within your Outlook inbox.

    Microsoft account data is used solely for the purpose of executing your configured automations and is subject to the same Limited Use restrictions described for Google data above.

    3.4 Twilio Voice and Call Recordings

    • Phone numbers dialled and call metadata (duration, timestamp, outcome).
    • Call recordings, where call recording is enabled by your Organisation Admin.

    Call recordings are stored securely and are accessible only to Organisation Admins for quality review purposes. You and your Organisation are responsible for obtaining all legally required consents from call participants in your jurisdiction.

    3.5 Lead and Prospect Data

    The Service allows you to import, discover, and manage data about your business prospects and leads, including names, job titles, company names, email addresses, phone numbers, and publicly available professional information. This data is controlled by you (or your Organisation) and processed by XyRo solely on your behalf.

    3.6 Usage and Technical Data

    • IP address, browser type, device information, and operating system.
    • Log data, including pages visited, features used, and timestamps.
    • Cookies and similar tracking technologies (see Section 11).

    4. How We Use Your Information

    We use the information we collect for the following purposes:

    • To provide, operate, and maintain the Service.
    • To authenticate your account and manage your Organisation.
    • To execute email and phone outreach automations you have configured.
    • To process payments and manage your Subscription.
    • To send you transactional notifications (e.g., billing receipts, password resets).
    • To provide customer support.
    • To monitor and improve the security and performance of the Platform.
    • To comply with legal obligations.

    We do not use your Content, email data, or call recordings to train or improve AI or machine learning models. All AI processing is performed in service of your explicitly configured workflows only.

    5. Data Sharing and Disclosure

    We do not sell your personal data. We may share your information in the following limited circumstances:

    5.1 Service Providers

    We engage trusted third-party service providers to support the operation of the Platform, including cloud infrastructure, payment processing, email delivery, and telephony. These providers process data only on our instructions and are bound by data processing agreements.

    Key sub-processors include:

    • Amazon Web Services / Railway: Cloud hosting and infrastructure.
    • Twilio Inc.: Voice call and SMS services.
    • OpenAI: AI-powered automation features (data is sent only as required to execute your workflows; OpenAI does not train on API inputs by default).
    • Payment processors (e.g., Stripe or Razorpay): Billing and subscription management.

    5.2 Legal Requirements

    We may disclose your information if required to do so by law, regulation, court order, or governmental authority, or if we believe disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud.

    5.3 Business Transfers

    In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.

    6. Data Retention

    We retain your personal data for as long as necessary to provide the Service and fulfil the purposes described in this Policy. Specifically:

    • Organisation data (including all Member data, leads, recordings, and email history) is permanently deleted within 30 days of Organisation deletion or account cancellation.
    • When an individual Member account is deleted from an Organisation (by an Admin or the Member themselves), that Member's personal credentials are removed; however, activity and content data associated with that Member's work may be retained by the Organisation Admin for operational and audit purposes.
    • Billing and transaction records are retained for 7 years in accordance with Indian accounting and tax laws.
    • Call recordings are retained for the duration of the Organisation's active Subscription, unless deleted earlier by an Organisation Admin.

    7. Your Rights

    7.1 All Users

    Regardless of your location, you have the right to:

    • Access the personal data we hold about you.
    • Request correction of inaccurate data.
    • Delete your account and associated personal data.
    • Disconnect third-party Integrations (Google, Microsoft) at any time via your account settings or directly through your Google/Microsoft account.

    7.2 European Union Users (GDPR)

    If you are located in the EU or EEA, you have additional rights under the GDPR:

    • Right to Restriction of Processing: You may request that we limit how we process your data in certain circumstances.
    • Right to Data Portability: You may request a copy of your data in a structured, machine-readable format.
    • Right to Object: You may object to processing based on legitimate interests.
    • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection supervisory authority.

    The legal bases on which we process your personal data are: (a) performance of a contract (providing the Service); (b) compliance with a legal obligation; (c) our legitimate interests (security, fraud prevention, service improvement); and (d) your consent (for optional Integrations and cookies).

    XyRo transfers personal data outside the EU/EEA only where appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission.

    7.3 California Users (CCPA / CPRA)

    If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

    • Right to Know: The right to know what personal information we collect, use, disclose, and sell.
    • Right to Delete: The right to request deletion of your personal information, subject to certain exceptions.
    • Right to Opt-Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioural advertising.
    • Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA rights.
    • Right to Correct: The right to request correction of inaccurate personal information.
    • Right to Limit Use of Sensitive Personal Information: Where applicable.

    To exercise any of these rights, contact us at [email protected]. We will respond within 45 days, extendable by a further 45 days where necessary.

    8. Security

    We implement industry-standard technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These include:

    • Encryption of data in transit using TLS/HTTPS.
    • Encryption of sensitive data at rest.
    • Access controls and authentication requirements for all staff with data access.
    • Regular security assessments and monitoring.

    No method of transmission over the internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee absolute security.

    9. Children's Privacy

    The Service is not directed to individuals under the age of 18. We do not knowingly collect personal data from minors. If you believe we have collected data from a minor, please contact us immediately at [email protected] and we will take steps to delete such data.

    10. Third-Party Links

    The Platform may contain links to third-party websites or services. This Privacy Policy does not apply to those third-party sites, and we are not responsible for their privacy practices. We encourage you to review the privacy policies of any third-party sites you visit.

    11. Cookies and Tracking

    We use cookies and similar technologies to:

    • Maintain your session and authentication state.
    • Understand how the Platform is used and improve its performance.
    • Store your preferences and settings.

    You can control cookies through your browser settings. Disabling cookies may affect certain features of the Platform. We do not use cookies for cross-site advertising or tracking.

    12. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a prominent notice on the Platform at least 15 days before the change takes effect. Your continued use of the Service after such changes constitutes your acceptance of the updated Policy.

    13. Revoking Google / Microsoft Permissions

    You may revoke XyRo's access to your Google account at any time by visiting https://myaccount.google.com/permissions and removing XyRo.ai. You may revoke Microsoft access at https://account.microsoft.com/privacy. Upon revocation, XyRo will no longer be able to access your email account, and Integration-dependent features will cease to function until you reconnect.

    14. Contact Us

    For questions, complaints, or to exercise your data rights, please contact our Privacy team at:

    XyRo AI Pvt. Ltd.

    Email: [email protected]

    Website: https://xyro.ai

    We aim to respond to all privacy inquiries within 30 days.