Privacy Policy
This Privacy Policy ("Policy") sets forth the legal framework, principles, and practices governing the collection, utilization, processing, transmission, storage, and protection of personal data and telecommunications metadata by PropelRoot AI ("Company", "we", "us", or "our"). This Policy applies to all users, account holders, enterprise clients, and end-consumer communication recipients accessing or utilizing our primary marketing website (propelroot.pro), client application portal (app.propelroot.tech), regional services (in.propelroot.pro), conversational voice artificial intelligence telephony engines, application programming interfaces ("APIs"), SMS/MMS mobile messaging gateways, and multi-channel customer relationship management integrations (collectively, the "Platform" or "Service").
MANDATORY MOBILE MESSAGING & SMS PRIVACY COVENANT (THE CAMPAIGN REGISTRY & CTIA COMPLIANCE):
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties or affiliates.
PropelRoot AI covenants and warrants that mobile phone numbers, short message service (SMS) opt-in consent records, and mobile subscriber data provided to or processed by the Platform shall remain strictly confidential. Mobile subscriber information will under no circumstances be sold, leased, rented, bartered, monetized, assigned, or disclosed to third parties, affiliate marketers, data brokers, or commercial advertising syndicates for promotional, commercial marketing, or cross-context behavioral advertising purposes.
1. Legal Capacity and Scope of Processing (Controller vs. Processor)
To ensure full adherence to applicable data protection jurisprudence—including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA", Cal. Civ. Code § 1798.100 et seq.), the General Data Protection Regulation ("GDPR", Regulation (EU) 2016/679), the Telephone Consumer Protection Act ("TCPA", 47 U.S.C. § 227), and regulatory frameworks established by the Federal Communications Commission ("FCC") and the Telecom Regulatory Authority of India ("TRAI")—PropelRoot AI operates in two distinct legal capacities:
- PropelRoot AI as a Data Controller: We act as an independent Data Controller with respect to Personal Information directly submitted by corporate subscribers, account administrators, registered dashboard users, and website visitors (such as account credentials, billing contact data, authentication tokens, and administrative audit trails).
- PropelRoot AI as a Data Processor / Service Provider: With respect to third-party contact lists, customer telephone numbers, call audio recordings, transcription text, and recipient metadata uploaded or routed by our enterprise clients through our voice AI and messaging pipelines, PropelRoot AI functions strictly as a Data Processor and Service Provider. We process such information solely upon the documented lawful instructions of our enterprise clients and pursuant to binding contractual agreements.
2. Categories of Personal Information Collected
We collect and process personal data across distinct operational categories necessary for the delivery and security of our telecommunications and voice intelligence services:
A. Corporate Account and Billing Identifiers
- Administrative Profile Data: Full legal name, corporate title, corporate entity name, business email address, authorized primary telephone number, and physical business domicile address.
- Authentication and Access Credentials: WorkOS-authenticated identity records, single sign-on (SSO) identifiers, hashed passwords, encrypted session cookies, and API secret keys.
- Commercial Transaction Records: Wallet recharge amounts, ledger balances, transaction reference IDs, and payment gateway receipts. All payment transactions are executed via PCI-DSS Level 1 certified payment gateways (such as Razorpay). PropelRoot AI does not store or process unencrypted credit card primary account numbers (PAN) or security verification codes.
B. Telephony Detail Records, Speech Data, and Messaging Metadata
- Mobile Telephone Numbers & Opt-In Proof: Mobile numbers collected via web-based intake forms, customer service requests, or inbound phone calls, accompanied by cryptographic timestamps, originating IP addresses, and records of affirmative consumer consent.
- Call Detail Records (CDRs): Originating telephone numbers, terminating destination numbers, call routing carrier hops, connection timestamps, call completion disposition codes (answered, busy, voicemail, no-answer), and duration metrics required for network billing and routing optimization.
- Voice Audio Recordings and Synthetic Transcriptions: Digital audio files capturing voice interactions between conversational AI agents and call recipients, together with real-time neural speech-to-text (STT) transcripts generated for emergency contractor triage, CRM synchronization, and quality verification.
- Messaging Transit Data: SMS/MMS message payloads, transmission timestamps, network carrier delivery receipts (DLRs), error failure codes, and messaging campaign identifiers.
C. Technical, Device, and Telemetry Data
- Log Information: Internet Protocol (IP) addresses, browser user agent strings, operating system identifiers, geographic location derived from IP, HTTP referrers, and system performance audit logs.
- Cryptographic Session Tokens: Tamper-proof HTTP-only cryptographic session cookies utilized strictly for user state verification and defense against Cross-Site Request Forgery (CSRF). We do not deploy third-party commercial advertising tracking beacons.
3. Lawful Basis and Purpose of Processing
PropelRoot AI processes Personal Information exclusively in furtherance of the following legitimate business, operational, and telecommunications purposes:
- Performance of Contractual Obligations: Executing real-time automated voice telephone calls, conducting sub-second conversational speech synthesis, transmitting requested SMS/MMS alerts, and routing customer leads to designated field contractors.
- Emergency Contractor Triage: Facilitating rapid speed-to-lead qualification, capturing home-service incident details, and synchronizing dispatch appointments directly with contractor field management software (e.g., ServiceTitan, Jobber).
- Telecommunications & Regulatory Compliance: Validating prior express consent records under the TCPA, verifying DLT commercial registrations in accordance with TRAI regulations, scrubbing numbers against applicable national Do-Not-Call (DNC) registries, and satisfying mandatory A2P 10DLC carrier vetting requirements overseen by The Campaign Registry (TCR).
- Platform Security and Fraud Mitigation: Preventing unauthorized robocalling, defending against caller ID spoofing, identifying telephony denial-of-service attempts, and safeguarding multi-tenant data isolation.
4. Non-Sharing of Mobile Data & Commercial Segregation (TCR Policy)
PropelRoot AI strictly enforces technical and organizational barriers to ensure that mobile phone numbers and text messaging consent are never commercialized, sold, or shared:
- Absolute Non-Sharing Covenant: No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties or affiliates.
- Exclusion from Corporate Transfers and Asset Sales: Text messaging originator opt-in data, affirmative consumer consent records, and mobile subscriber phone numbers will not be sold, rented, leased, licensed, assigned, or transferred to any third party or affiliate under any circumstances, including in connection with any corporate merger, acquisition, debt financing, asset sale, bankruptcy, or reorganization.
- Prohibition on Cross-Tenant Data Aggregation: Mobile phone numbers, opt-in timestamps, and messaging records collected through the Service are strictly segregated within private tenant workspaces. Mobile data is never merged into cross-tenant consumer profiles, rented to third-party telemarketers, or sold to external lead generation syndicates.
- Scope of Messaging Services: Text messaging dispatched by PropelRoot AI under the program name PropelRoot AI SMS Alerts & Communications is utilized exclusively for customer-authorized transactional notifications, emergency contractor dispatch triage, appointment booking confirmations and reminders, two-factor authentication (2FA) verification, and conversational customer care.
- Service-Bound Technical Routing: Mobile numbers and message payloads are transmitted solely to authorized telecommunications carriers, Campaign Service Providers (CSPs), Direct Connect Aggregators (DCAs), and Tier-1 wireless network operators (including AT&T, Verizon Wireless, T-Mobile, and regional carriers) strictly to the technical extent necessary to route, transmit, and deliver communications over the Public Switched Telephone Network (PSTN).
- Carrier Rates, Frequency & Non-Liability:
- Message Frequency: Message frequency varies based on customer interaction, scheduled appointments, and emergency dispatch alerts.
- Rate Disclosure: Message and data rates may apply in accordance with your mobile carrier wireless service plan.
- Carrier Disclaimer: Mobile network carriers (including AT&T, T-Mobile, Verizon Wireless, Sprint, Boost Mobile, Cricket, MetroPCS, and regional operators) are not liable for delayed or undelivered messages.
- Universal Opt-Out: You may opt out of text communications at any time by replying STOP, END, CANCEL, UNSUBSCRIBE, or QUIT to any message received.
- Support Assistance: You may request customer assistance at any time by replying HELP to any message or emailing [email protected].
5. Downstream Technical Sub-Processors & Infrastructure Providers
To maintain sub-second latency and carrier-grade voice intelligence, PropelRoot AI partners with select infrastructure and communications providers. Each sub-processor is bound by written Data Processing Agreements (DPAs) imposing confidentiality obligations and data protection standards no less restrictive than those set forth herein:
- Telecommunications Carriers & Messaging Gateways: Certified Tier-1 telecommunications carriers, Direct Connect Aggregators (DCAs), Campaign Service Providers (CSPs), and licensed SIP trunking operators for PSTN connectivity, telephony call termination, and A2P 10DLC short-message packet delivery.
- Speech Recognition & AI Intelligence: Deepgram, AssemblyAI, Sarvam AI, and OpenAI for neural streaming speech recognition, language synthesis, and conversational reasoning under zero-data-retention API agreements where applicable.
- Cloud Hosting & Database Architecture: Google Cloud Platform (GCP) and Supabase PostgreSQL with encrypted connection pooling, physically hosted in secure enterprise data centers in Northern Virginia, USA (us-east-1) and Mumbai, India (ap-south-1).
- Payment & Financial Clearing: Razorpay for PCI-DSS Level 1 compliant credit card, debit card, and international settlement clearing.
6. Cryptographic Security Standards & Architecture
PropelRoot AI implements state-of-the-art technical, physical, and administrative security measures designed to protect personal data against accidental loss, unauthorized disclosure, or illicit access:
- In-Transit Encryption: All communications between user browsers, API clients, and our server infrastructure are enforced using modern Transport Layer Security (TLS 1.3 / TLS 1.2) with strong cipher suites. Unencrypted HTTP traffic is strictly disallowed.
- At-Rest Encryption: All database volumes, backups, voice recordings, and transcript logs are encrypted at rest utilizing Advanced Encryption Standard (AES-256).
- Multi-Tenant Isolation: Customer accounts and campaign databases are partitioned utilizing strict multi-tenant workspace isolation. Enterprise customer datasets are logically segregated to prevent cross-tenant data leakage.
- Access Governance: Administrative access to production clusters and database instances requires multi-factor authentication (MFA), hardware security keys, and audited role-based access control (RBAC).
7. Data Retention Schedules and Deletion Governance
We retain personal information only for the period necessary to fulfill the operational purposes described in this Policy, satisfy telecommunications carrier audit windows, or comply with statutory accounting requirements:
- Account Profile Data: Retained for the duration of the active enterprise subscription plus ninety (90) days following account termination for audit reconciliation.
- Telephony & Call Detail Records (CDRs): Retained for a rolling period of twelve (12) months to facilitate carrier billing reconciliation, dispute resolution, and regulatory compliance review.
- Audio Recordings & Transcripts: Maintained in accordance with the data retention parameters selected by the enterprise client within the dashboard. Clients may manually purge or automate the deletion of audio recordings and transcripts at any time.
- Right to Erasure Requests: Consumers and account holders may formally request the permanent deletion of their personal information by contacting our privacy office at [email protected]. Validated requests are processed within thirty (30) days.
8. Consumer Privacy Rights and Statutory Opt-Out Procedures
Depending on your jurisdiction of residence, you possess specific legal rights regarding your personal information:
- SMS Opt-Out (Revocation of Consent): You maintain the absolute right to revoke text messaging consent at any time. To unsubscribe from SMS messages sent by or on behalf of PropelRoot AI, reply STOP, CANCEL, UNSUBSCRIBE, QUIT, or END to any message received. You will receive a single confirmation message confirming your unsubscription, after which no further SMS communications will be transmitted to your number unless you re-enroll.
- SMS Support Assistance: If you require assistance regarding text messages, reply HELP to any message or contact our customer support desk at [email protected].
- Rights Under CCPA / CPRA (California Residents): California residents have the right to request: (i) disclosure of categories and specific pieces of Personal Information collected; (ii) deletion of Personal Information; (iii) correction of inaccurate Personal Information; and (iv) freedom from discriminatory treatment for exercising statutory privacy rights. We do not sell or share personal information for cross-context behavioral advertising.
- Rights Under GDPR (European Economic Area): Data subjects possess the right to access, rectify, restrict processing of, or port their personal data, or lodge a formal complaint with a competent supervisory authority.
9. Protection of Minors (COPPA Compliance)
The Platform is exclusively designed for commercial enterprise business applications and is not directed to individuals under the age of eighteen (18). We do not knowingly collect, process, or maintain personal data from individuals under the age of thirteen (13) in accordance with the Children's Online Privacy Protection Act (COPPA). If we discover that an individual under thirteen (13) has provided us with personal data, we will immediately delete such information from our records.
10. Modifications and Amendments
PropelRoot AI reserves the right to amend or update this Privacy Policy at any time to reflect statutory changes, carrier compliance mandates, or technological developments. In the event of material modifications, we will publish the amended Policy on this page, update the "Effective Date" at the top of this document, and provide prominent notice via email or within the client dashboard prior to the effective date of such modifications.
11. Corporate Directory & Designated Privacy Officer
For questions, formal legal notices, regulatory inquiries, or requests to exercise statutory privacy rights, please direct all correspondence to our designated privacy office:
Corporate Brand / Entity: PropelRoot AI
Legal Operating Entity: PropelRoot (Guru Praneeth Kumar)
Registered Physical Address: 18-1-337 67 Arundathi Colony Uppugu, Hyderabad, Telangana 500053, India
Designated Privacy Email: [email protected]
Customer Billing & Inquiries: [email protected]
Online Compliance Directory: https://propelroot.tech/contact
Official Web Domain: https://propelroot.tech