We take your privacy seriously. This policy explains what data we collect, why we collect it, and how we protect it — in plain language.
Last updated: 1 May 2026 · Effective: 1 May 2026
Sreegen Technologies Pvt. Ltd. ("Sreegen", "we", "us", or "our") operates the Sreegen Digital Workforce OS accessible at app.sreegen.com and the marketing website at www.sreegen.com (collectively, the "Services"). The platform enables customers to configure digital workers, workflows, tools, approvals, communications, and related operating records.
This Privacy Policy describes how we collect, use, store, and disclose personal data of:
This policy is designed to comply with the Digital Personal Data Protection Act, 2023 (DPDP Act) of India, and applicable rules issued thereunder. Sreegen acts as a Data Fiduciary with respect to Platform User account data, and as a Data Processor on behalf of Platform Users with respect to the business-contact, workflow, communication, and related data they submit to the Services.
When you register or use the platform, we collect: your name, work email address, phone number, company name, billing address, and payment method information (processed by our payment provider — we do not store raw card numbers).
Platform Users may configure departments, teams, digital workers, workflows, permissions, integrations, and work items, and may submit contact or business records. Depending on the configured use case, this may include names, phone numbers, email addresses, custom fields, workflow state, tool activity, approval records, evidence events, communication metadata, AI-generated summaries, and — where enabled by the Platform User — audio recordings or message content.
We automatically collect: IP address, browser type, operating system, pages visited, features used, and session duration. This is used for product analytics, debugging, and security monitoring.
If you contact our support team, we retain the content of those communications to resolve your issue and improve our services.
We do not knowingly collect sensitive personal data as defined under the DPDP Act (e.g., financial data beyond payment processing, health data, biometric data, caste, or religious beliefs) unless explicitly required for a specific enterprise use case and consented to in writing.
We use personal data only for the purposes described below, which constitute the lawful bases under the DPDP Act:
| Purpose | Lawful Basis |
|---|---|
| Delivering the platform and processing customer-configured digital work and communications | Contract performance |
| Billing and payment processing | Contract performance |
| Product analytics and feature improvement | Legitimate interests |
| Security monitoring and fraud prevention | Legitimate interests / legal obligation |
| Sending transactional emails (invoices, alerts) | Contract performance |
| Sending product updates and marketing emails | Consent (opt-in at signup; opt-out anytime) |
| Compliance with court orders or legal process | Legal obligation |
We do not sell personal data to any third party. We do not use personal data for automated profiling that produces legal or similarly significant effects without human review.
As a Data Principal under the Digital Personal Data Protection Act, 2023, you have the following rights with respect to your personal data held by Sreegen:
To exercise any of these rights, email us at privacy@sreegen.com with the subject "DPDP Rights Request". We will respond within 72 hours of receipt and resolve within the timeframe prescribed by law.
We retain personal data only as long as necessary for the purposes described in this policy:
You may request earlier deletion subject to our legal obligations. See Section 4 for how to submit a request.
We implement industry-standard technical and organisational measures to protect personal data, including:
In the event of a data breach that is likely to result in high risk to individuals, we will notify affected parties and the relevant authority within the timelines prescribed by the DPDP Act.
The Sreegen platform is intended for business use by individuals aged 18 and above. We do not knowingly collect personal data from children under 18. If we become aware that data of a person under 18 has been collected without verifiable parental consent, we will delete it promptly. If you believe we have inadvertently collected such data, please contact privacy@sreegen.com.
Primary production infrastructure is hosted on AWS in the eu-west-2 (London) region. For AI inference, telephony, messaging, billing, support, or integrations, limited data may be processed by partner services outside that AWS region depending on the enabled feature and provider architecture. Such transfers are governed by contractual safeguards that require appropriate protection standards.
We comply with the cross-border transfer provisions of the DPDP Act and applicable government notifications. We will update this section as the Government of India issues further guidance on permitted jurisdictions.
In accordance with the DPDP Act, 2023, we have appointed a Grievance Officer to address complaints and inquiries:
Name: Vikrant Thete
Designation: Founder & Chief Privacy Officer
Email: privacy@sreegen.com
Address: Sreegen Technologies Pvt. Ltd., Mumbai, Maharashtra, India
Response time: Acknowledgement within 72 hours; resolution within 30 days
If you are not satisfied with our response, you may escalate to the Data Protection Board of India once it is constituted under the DPDP Act.
We may update this Privacy Policy from time to time. When we make material changes, we will notify Platform Users by email and post a prominent notice in the application dashboard at least 14 days before the changes take effect. Continued use of the Services after that date constitutes acceptance of the revised policy.
The version history of this policy is maintained internally. If you would like a copy of a previous version, contact privacy@sreegen.com.
Questions about this policy? privacy@sreegen.com · Also see our Terms of Service and Data Deletion instructions