Privacy Policy
Effective Date April 09, 2026
1. Introduction
Mivikron Solutions Private Limited ("we," "our," or "us") operates Basalix. This Privacy Policy describes how we collect, process, use, and share personal information when you access our website, platform, and APIs. We comply with the Information Technology Act, 2000, the Digital Personal Data Protection (DPDP) Act, 2023, and adhere to global standards such as the GDPR.
2. Information We Collect
2.1 Information You Provide Directly: When you register, we collect your name, email address, organization name, payment information, and account credentials. (If you register via Google OAuth, we receive your name, email, and profile picture).
2.2 Customer Data (Knowledge Base): Documents, text, and data you upload to the Basalix platform to train your AI agents.
2.3 Automatically Collected Information: We automatically collect log data, device information, IP addresses, browser types, and usage statistics (e.g., chat logs, API request volumes) using cookies and similar tracking technologies.
2.4 End-User Data: If you deploy our chat widget on your website, we may process information from your end-users (e.g., chat queries, session IDs). You are the Data Fiduciary/Controller for your end-users, and we act solely as the Data Processor.
3. How We Use Your Information
We use the collected information to:
• Provide, operate, and maintain the Basalix platform and AI infrastructure.
• Process payments and prevent fraudulent transactions.
• Provide customer support and technical troubleshooting.
• Analyze platform usage to improve our retrieval algorithms and user experience.
• Communicate with you regarding updates, security alerts, and administrative messages.
4. AI Processing and Third-Party Subprocessors
• Strict Data Isolation: Your Customer Data is isolated using multi-tenant architecture.
• No Foundational Training: We do not use your personal information or Customer Data to train foundational AI models.
• Subprocessors: We share data only with the service providers below, each bound by a data processing agreement (and, where health information is involved, a Business Associate Agreement). Our LLM providers are used through API tiers that do not retain your data for model training.
– Amazon Web Services (United States): cloud hosting, database, file storage, backups and encryption keys.
– OpenAI and Anthropic (United States): generation of AI responses from your conversation and the knowledge you provide.
– Retell AI (United States): voice call transport, speech-to-text and text-to-speech for the phone channel, including call recordings where enabled.
– Twilio (United States): telephone numbers, SMS and WhatsApp follow-up messages.
– Dodo Payments: subscription billing. Card details are entered on their pages and never reach our servers.
– Bright Data: retrieval of publicly available web pages that you add to your knowledge base.
– Only when you connect them from your dashboard: Google (Calendar, Sheets), Microsoft (Outlook Calendar) and Clio (lead and matter records). Data is sent to these providers solely to perform the integration you enabled, and stops when you disconnect it.
– Our transactional email provider, for account and appointment emails.
• We will update this list before adding a new subprocessor. Enterprise customers may request notice by email.
5. Data Sharing and Disclosure
We do not sell your personal information. We may disclose information:
• To comply with valid legal processes, subpoenas, or government requests.
• To enforce our Terms of Service or protect the rights, property, or safety of Mivikron Solutions Private Limited, our users, or the public.
• In connection with a merger, acquisition, or sale of company assets.
6. Data Security and Retention
We employ industry-standard organizational and technical measures (including HTTPS/TLS encryption and encrypted vector databases) to protect your data. We retain personal information only for as long as necessary to fulfil the purposes outlined in this Policy, or as required by law. Upon account deletion, Customer Data is securely purged from our active databases.
7. International Data Transfers
Mivikron Solutions Private Limited is based in India. Customer Data is stored and processed in the United States (Amazon Web Services, US East region); our subprocessors listed above operate primarily in the United States. By using the Services, you consent to the transfer of your data to servers located outside your country of residence, subject to appropriate data transfer safeguards (including standard contractual clauses where required).
8. Your Privacy Rights
Depending on your jurisdiction (e.g., EU, California, or India), you may have the right to:
• Access and obtain a copy of your personal data.
• Request correction of inaccurate or incomplete data.
• Request deletion of your personal data ("Right to be Forgotten").
• Withdraw consent to processing (where applicable).