HuskyVoiceAI is designed to support DPDP Act-aligned privacy and security obligations for Indian customers. Our platform is built with India-region hosting by default, encryption, access controls, audit logs, subprocessors transparency, data retention controls, breach response processes, and support for Data Principal rights. Because DPDP compliance also depends on how each customer configures its workflows, scripts, consent language, data fields, integrations, and retention settings, we work with customers to support compliant implementation rather than claiming a one-size-fits-all certification.
Compliance by Design
HuskyVoiceAI incorporates DPDP-aligned principles:
- Purpose Limitation: Data used only for configured business purpose
- Data Minimization: Workflows collect only necessary information
- Storage Limitation: Configurable retention policies
- Integrity & Confidentiality: Encryption, access controls, audit logs
- Transparency: Clear subprocessor and data flow documentation
- Data Principal Rights: Support for access, correction, erasure, consent withdrawal
Roles & Responsibilities
Data Fiduciary (Customer)
For most customer-configured voice AI workflows, the customer (clinic, hospital, employer, business, enterprise) acts as the Data Fiduciary because it determines the purpose and means of processing personal data.
Data Processor (HuskyVoiceAI)
HuskyVoiceAI typically acts as a Data Processor, processing personal data on behalf of the customer according to the customer's instructions and applicable agreement.
Data Fiduciary (HuskyVoiceAI)
In limited cases (website visitors, direct sales inquiries, billing, support, our own operations), HuskyVoiceAI may act as a Data Fiduciary for that specific data.
Notice & Consent
HuskyVoiceAI supports customer-configured notice and consent workflows for:
- Voice calls with notice & consent scripts
- WhatsApp, SMS, or email follow-ups
- Appointment booking confirmations
- Lead qualification & qualification
- Call recording & transcription consent
- Other configured workflows
Customers are responsible for defining the lawful purpose, notice language, and consent requirements for their use case. HuskyVoiceAI can help configure consent scripts, capture consent signals, and maintain consent-related logs where enabled.
Call Recordings & Transcripts
Depending on customer configuration, HuskyVoiceAI may process:
- Call recordings and transcripts
- Call metadata (caller ID, timestamp, duration)
- Caller details and appointment preferences
- Workflow outputs and conversation summaries
These are used only for the configured business purpose (appointment booking, follow-up, quality review, lead qualification, workflow automation). Customers can configure retention policies for recordings and transcripts, subject to legal, contractual, and operational requirements.
Healthcare & Patient Data
Although the DPDP Act does not separately define "sensitive personal data," HuskyVoiceAI treats health-related communication data as high-sensitivity personal data. For healthcare workflows, this may include:
- Patient name and phone number
- Appointment preference and booking status
- Call recording and transcript
- Follow-up status and communication history
- Information voluntarily shared by the caller
Customers should configure workflows to collect only information necessary for the specified purpose and avoid collecting clinical or diagnostic information unless required for the workflow.
Data Principal Rights
HuskyVoiceAI supports customers in responding to Data Principal requests, including:
- Right to access personal data
- Right to correction and updating
- Right to erasure (subject to legal retention)
- Right to restrict processing
- Right to withdraw consent
- Grievance handling and escalation
Where HuskyVoiceAI acts as a Data Processor, the customer is typically responsible for validating the request, verifying Data Principal identity, determining legal retention obligations, and communicating with the Data Principal. HuskyVoiceAI provides reasonable assistance to access, export, correct, restrict, or delete relevant customer data where technically available and contractually applicable.
Data Residency
HuskyVoiceAI provisions Indian customer accounts in India-region infrastructure by default:
• Cloud infrastructure hosted on AWS Mumbai (ap-south-1)
• Structured customer data in MongoDB infrastructure located in India
• Call recordings stored in India-region S3 buckets
International deployments are available only with explicit customer request and agreement. Data transfers outside India require Data Principal notification and consent as applicable under DPDP.
Subprocessors
HuskyVoiceAI uses the following subprocessors for customer data:
AWS (Cloud Infrastructure)
Hosting, storage, compute; located in India region
MongoDB (Data Storage)
Structured data storage in India
AI Inference Providers
Transient processing for transcription and response generation (may process data outside India depending on provider)
A complete subprocessor list is available in our Data Processing Agreement.
Security & Encryption
HuskyVoiceAI implements comprehensive security controls:
- Encryption in transit (TLS 1.3)
- Encryption at rest (AES-256)
- Role-based access control (RBAC)
- Audit logging and monitoring
- Regular security assessments
- Incident response procedures
Detailed security measures are documented in our Security Policy.
Retention & Deletion
HuskyVoiceAI supports configurable retention policies:
- Customers configure retention periods for recordings and transcripts
- Automatic deletion upon retention period expiration
- Manual data deletion on customer request
- Legal hold capabilities for litigation/regulatory requirements
- Secure data deletion procedures
Detailed retention timelines are available in our Data Retention Policy.
Breach Notification
In the event of a confirmed personal data breach, HuskyVoiceAI will:
- Notify the Data Fiduciary (customer) without unreasonable delay
- Provide details of the breach, affected data, and remedial actions
- Assist the customer in notification to Data Principals as required
- Cooperate with regulatory investigations and inquiries
- Maintain documentation of breach response
Customers remain responsible for assessing the need for breach notification to Data Principals and regulatory authorities under applicable DPDP requirements.
Grievance Mechanism
HuskyVoiceAI maintains a grievance redressal mechanism for Data Principals and customers:
Contact: privacy@huskeyvoiceai.com | Phone: +91-XXXXX-XXXXX
Grievances will be acknowledged within 5 business days and resolved within 30 days or as required by applicable law. For unresolved grievances, Data Principals may escalate to the Data Protection Board of India as per DPDP Act provisions.
Questions about DPDP?
Contact our Data Protection Officer for detailed compliance guidance and implementation support.
Email Privacy Team