Ava AI — Privacy Policy

Effective date: October 1, 2026

This Privacy Policy explains how Rao Industries, operating under the Ava AI brand (“Ava AI,” “Ava,” “we,” “us,” or “our”), collects, uses, stores, discloses, and otherwise processes information when you visit https://getava.in, create or use an Ava account, use the Ava AI software-as-a-service platform, deploy an Ava chatbot, or contact us.

Ava is primarily a business software service. This Privacy Policy is intended to describe our actual data practices for the current service and may be updated as the service, technology providers, or applicable law changes.

1. Interpretation and Definitions

The following terms have the meanings given below. Where a term has a specific meaning under applicable data-protection law, that legal meaning will apply to the extent required.

“Account” means an account created to access the Ava AI Service or any part of it.
“Ava,” “Ava AI,” “we,” “us,” or “our” means Rao Industries operating the Ava AI product and service.
“Business Customer” means a business, company, organization, or other legal entity that uses Ava AI and determines how it deploys and configures the Service.
“Customer Data”means information and content submitted to Ava by a Business Customer or processed by Ava on the Business Customer's instructions, including business knowledge, documents, website content, and customer conversation data.
“Personal Data” means information that relates to an identified or identifiable individual, or any equivalent category recognized under applicable law.
“Service” means the Ava AI software, website, chatbot, dashboard, related infrastructure, and associated functionality made available by Ava.
“Service Provider” means a third-party company or individual that processes information on behalf of Ava or provides infrastructure or services necessary to operate the Service.
“Visitor” means an individual who interacts with an Ava chatbot or other Ava-powered experience deployed by a Business Customer.
“Website” means https://getava.in and other Ava-controlled web properties through which the Service is provided.

2. Scope and Roles

Ava processes information in more than one context. When you create and use an Ava account, Ava processes information needed to provide the Service to you. When a Business Customer deploys an Ava chatbot on its own website, that Business Customer generally determines the purposes for which its website visitor information is collected and used, while Ava processes that information as necessary to provide the chatbot and related Service.

Accordingly, the Business Customer may have its own privacy notice and legal obligations for information collected from its visitors. Visitors should review the privacy notice of the website or business they are interacting with. Ava does not take ownership of a Business Customer's visitor data merely because Ava processes it.

3. Information We Collect

3.1 Account and identity information

When you create or administer an Ava account, we may collect:

  • Name.
  • Email address.
  • Password-related information, including a securely hashed password where password authentication is used.
  • Organization or workspace information.
  • Account status, authentication and security information.

3.2 Business information

A Business Customer may provide information such as:

  • Business name and description.
  • Business website and public business pages.
  • Business address and contact information.
  • Business hours.
  • Products and services.
  • FAQs and policies.
  • Documents, text, and other business knowledge submitted to the Service.

3.3 Website content and crawling

When a Business Customer asks Ava to learn from a website, Ava may retrieve and process publicly accessible website content for the purpose of configuring and providing the customer's AI assistant. The current website-learning flow is designed to work with publicly accessible content and does not use credentials or authenticated sessions to access private areas.

Crawled website content may be stored in the Business Customer's knowledge base, including source text and derived indexing information used to retrieve relevant information during AI conversations.

3.4 Visitor and conversation information

When a Visitor interacts with an Ava chatbot or supported customer channel, Ava may process information contained in the interaction. Depending on what the Visitor or Business Customer provides, this may include:

  • Conversation and message content.
  • Name, email address, or telephone number.
  • Lead information and customer inquiries.
  • Conversation identifiers and pseudonymous visitor identifiers.
  • Timestamps and service-related interaction information.
  • Channel identifiers, such as identifiers required to operate supported messaging channels.

3.5 Technical and security information

Ava may temporarily process network information such as an IP address for security and rate-limiting purposes. IP addresses used for short-lived rate limiting are not intended to be maintained as permanent account records. Ava does not intentionally store browser or device fingerprints for advertising or cross-site behavioral profiling.

3.6 Cookies

Ava uses functional first-party cookies and similar browser storage required to operate the Service, including authentication/session functionality and limited onboarding state. Ava does not currently use advertising cookies or third-party advertising tracking on the SaaS dashboard.

3.7 Operational analytics

Ava maintains first-party operational information such as conversation counts, lead-related metrics, AI token usage, estimated provider costs, response latency, and other service metrics needed to operate and improve the platform.

3.8 Payment information

Ava does not intentionally store raw payment-card credentials such as card numbers, CVV values, or card expiry information in its own database. Subscription payments are processed through Razorpay and may be subject to Razorpay's own privacy practices and terms.

4. How We Use Personal Data and Customer Data

Ava may use information for the following purposes:

  • Create, authenticate, maintain, and secure user accounts and workspaces.
  • Provide the Ava AI Service and its features.
  • Crawl and process customer-provided public websites.
  • Store, index, retrieve, and use business knowledge supplied by customers.
  • Generate AI responses and maintain customer conversations.
  • Support human review, support requests, troubleshooting, and debugging.
  • Prevent fraud, abuse, unauthorized access, and attacks on the Service.
  • Measure usage, enforce quotas, maintain billing state, and administer subscriptions.
  • Process payments through applicable payment providers.
  • Send transactional and service-related communications, such as account, verification, security, billing, and support messages.
  • Investigate incidents and maintain service reliability.
  • Improve the Service using operational analytics and customer feedback, without using Customer Data to train or fine-tune general AI models.
  • Comply with applicable laws, lawful requests, and contractual obligations.

5. AI Processing

Ava currently uses Groq as its AI inference provider. Information necessary to generate an AI response may be transmitted to and processed by Groq in accordance with Groq's applicable contractual terms and privacy documentation.

Ava does not authorize or use Customer Data to train or fine-tune general-purpose AI models. Groq's current Cloud Services agreement treats customer Inputs and Outputs as Customer Data and states that they are not permitted to be used for model training or fine-tuning unless the customer explicitly grants permission or instructs Groq to do so.

Ava may add additional AI or infrastructure providers in the future. If the provider change materially affects how Personal Data is processed, this Privacy Policy and/or Ava's public provider disclosures may be updated.

6. Customer Data Ownership and Limited Processing Rights

Business Customers retain ownership and other applicable rights in Customer Data they submit to Ava. Ava does not acquire ownership of Customer Data merely because the Service stores or processes it.

A Business Customer grants Ava only the limited rights reasonably necessary to host, store, process, transmit, index, secure, troubleshoot, and otherwise provide the Service.

7. Business Visitor Data

A Business Customer may use Ava to communicate with its own customers or website visitors. The Business Customer is generally responsible for determining the purposes of that processing, identifying the lawful basis or authorization required under applicable law, providing appropriate notices, and responding to requests from those individuals.

Ava processes visitor information only as necessary to provide the Service to the Business Customer and does not independently claim ownership over the Business Customer's visitor conversation data.

Because the business deploying the chatbot controls its own customer relationship, a Visitor who wants to understand how that business uses their information should also consult that business's own privacy notice.

8. Customer Data and AI Model Training

Ava does not use customer business information, uploaded knowledge, website content, or customer conversations to train or fine-tune general AI models.

Ava may use appropriate operational analytics and customer feedback to improve the SaaS product, service reliability, customer experience, and business operations. This does not grant Ava permission to use Customer Data to train general AI models.

9. Service Providers and Third-Party Processing

Ava relies on third-party service providers to operate the Service. Current providers include:

ProviderPurposeInformation potentially processed
GroqAI inferencePrompts, relevant conversation context, and generated model outputs required for inference.
VercelWeb/application hosting and deliveryService requests, application data transmitted through the hosted application, and operational information.
RenderReal-time WebSocket infrastructure & live chat relayReal-time visitor and operator chat messages, live room events, and connection synchronization data.
SupabaseDatabase and related infrastructureAccount, business, knowledge, conversation, configuration, and operational data stored by Ava.
Upstash / RedisCaching, rate limiting, and operational infrastructureShort-lived rate-limit and cache information and other operational state.
FirecrawlExternal website scraping & content extractionPublic website URLs and crawled text/structured document data instructed by customer for knowledge ingestion.
RazorpayPayments and subscription processingPayment and billing information submitted during checkout and related subscription identifiers.
ResendTransactional email deliveryEmail addresses and message content necessary to deliver transactional emails.
GoogleGoogle authenticationAuthentication and basic account information returned through Google sign-in where used.

Service providers may change as Ava develops. Each provider may process information according to its own applicable agreements, privacy documentation, and security controls.

10. Debugging and Support Access

Ava may access customer information when reasonably necessary to provide customer support, investigate technical problems, diagnose incidents, maintain reliability, or address security issues. Such access is limited to the purposes necessary for operating and supporting the Service.

Ava personnel and authorized service providers are not permitted to use customer information for unrelated purposes.

11. International Processing

Ava is initially operated from India and may be made available internationally. Because Ava relies on cloud, AI, email, payment, and other technology providers operating in multiple jurisdictions, Personal Data and Customer Data may be processed or stored outside India.

Where applicable, Ava will use reasonable contractual, technical, and organizational measures required by applicable law for international processing and service-provider arrangements.

12. Data Retention

12.1 Ava account and business-user data

Ava intends to retain a Business Customer's account, workspace, business information, and related SaaS data while the customer maintains an account or otherwise remains on the platform.

After an account becomes inactive and the customer has been away from the platform for one year, Ava intends to delete applicable data, unless the customer requests continued retention, applicable law requires longer retention, or retention is reasonably necessary for legal, security, accounting, fraud-prevention, or dispute-resolution purposes.

12.2 Customer-requested deletion

A customer may request deletion of its data by contacting support@getava.in. Where deletion is applicable, Ava will delete the relevant data from active production systems as soon as reasonably practicable and will make reasonable attempts to direct applicable service providers to delete the relevant information.

12.3 Backups

Deletion from active production systems does not necessarily mean immediate deletion from every backup. Encrypted backup copies may persist for a limited period under the ordinary backup lifecycle of the relevant infrastructure provider and may be overwritten or deleted as those systems expire or rotate.

12.4 Visitor conversation data

Visitor conversations created through an Ava chatbot are distinct from the Business Customer's own account records. Retention of these conversations can depend on the Business Customer's use and configuration of the Service, operational retention controls, customer-support requirements, deletion requests, and applicable law. The Business Customer remains responsible for defining and communicating its own retention practices to visitors where required.

13. Security of Personal Data

Security is important to Ava. We use technical and organizational measures designed to protect information from unauthorized access, alteration, disclosure, loss, or misuse. Depending on the system and data involved, these measures may include:

  • Encryption in transit.
  • Secure password hashing.
  • Server-side authorization and tenant isolation controls.
  • Encryption of certain connected-channel credentials.
  • Rate limiting and abuse prevention.
  • Signed visitor/session controls for deployed chat experiences.
  • Webhook signature verification where supported.
  • Security monitoring, logging, and controlled access to production systems.

No method of transmission or electronic storage can be guaranteed to be completely secure. Ava therefore does not promise absolute security, but we work to maintain safeguards appropriate to the nature of the Service.

14. Data Minimization and Prohibited Sensitive Information

Ava is designed primarily for business information and customer-support conversations. Customers should not intentionally submit or store the following through the standard Service:

  • Passwords or authentication credentials.
  • Payment-card information such as full card numbers or CVV values.
  • Government-issued identity documents or identity numbers.
  • Health or medical information.
  • Other highly sensitive personal information unless Ava has specifically introduced and documented a lawful, supported use case for it.

Ava is not responsible for loss or damage resulting from a customer's decision to submit such information contrary to the intended use of the Service, except to the extent applicable law provides otherwise.

15. Cookies and Browser Storage

Ava currently uses functional first-party cookies and limited browser storage for purposes such as authentication/session management and onboarding state. These technologies are necessary for core Service functionality.

Ava does not currently use third-party advertising cookies or cross-site advertising profiles in the SaaS dashboard. If non-essential tracking technologies are introduced in the future, the relevant disclosures will be updated.

16. Marketing Communications

Ava does not currently use Customer account information to send marketing emails as a standard practice. Ava may send transactional communications necessary to operate the Service, such as verification, password recovery, security, billing, service, and support messages.

17. Analytics and Product Improvement

Ava currently uses first-party operational analytics rather than a third-party advertising analytics stack on the SaaS dashboard. These metrics may include conversation counts, lead-related metrics, AI usage, response latency, and provider cost information.

Ava may use aggregated operational information and customer feedback to improve the SaaS product, service reliability, user experience, and business operations. Ava does not use Customer Data to train or fine-tune general AI models.

18. Payments and Billing Providers

Ava uses Razorpay for payment processing. Payment information entered into Razorpay checkout is handled by Razorpay according to its own policies and controls. Ava stores subscription identifiers and related billing state needed to administer the Service, but does not intentionally store raw card credentials.

19. Legal Disclosures and Government Requests

Ava may disclose Personal Data or Customer Data where required or permitted by applicable law, valid court order, governmental direction, lawful authority, or other legal process. Ava may also disclose information where reasonably necessary to prevent fraud, security incidents, illegal activity, or harm, or to protect the rights, property, or safety of Ava, its customers, users, or the public.

Where legally permitted and reasonably practical, Ava may notify the affected customer before or after a disclosure. Ava may also suspend or restrict a customer account, chatbot, content, or deployment when required by applicable law or lawful authority.

20. Business Transfers

If Ava is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, relevant information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality and data-protection measures.

21. Privacy Rights and Requests

Depending on applicable law and the context in which Ava processes your information, you may have rights relating to your Personal Data, including rights of access, correction, deletion, grievance handling, or other rights provided by applicable law.

Requests concerning privacy, account data, or deletion may be submitted to:

Phone: +91 9491831026

Where the information is controlled by a Business Customer, Ava may direct the request to that Business Customer or assist the customer as appropriate under the applicable legal and contractual arrangement.

22. Children's Privacy

Ava AI accounts and the SaaS Service are strictly intended for commercial and business use by individuals who are 18 years of age or older. Ava does not knowingly collect, process, track, or direct targeted services to children under 18 years of age (in compliance with Section 9 of the India Digital Personal Data Protection Act, 2023) or children under 13 years of age (in compliance with the US Children's Online Privacy Protection Act — COPPA).

Because Ava may be deployed on third-party business websites, Business Customers are strictly responsible for ensuring that their target audience complies with applicable age requirements and that chatbots deployed on services directed to minors are not configured without verifiable parental or guardian consent.

23. Links to Third-Party Websites

The Ava website or Service may contain links to third-party websites, platforms, or services. Ava does not control those third parties and is not responsible for their content, security, or privacy practices. We encourage you to review the privacy policy of any third-party service you access.

24. Changes to This Privacy Policy

Ava may update this Privacy Policy when our Service, data-processing practices, technology providers, or applicable legal requirements change. We will update the effective date when the policy is revised.

Where required or appropriate, material changes may also be communicated through the Service, website, email, or another reasonable method. For details on how we process data as a processor on your behalf, please review our Data Processing Addendum (DPA).

25. Contact Us & Grievance Redressal

For questions, privacy requests, data deletion, or statutory grievances about how Ava processes personal information, contact our designated officer:

Rao Industries (Ava AI)
Contact Grievance Officer: grievance@getava.in