Effective Date: September 5, 2026 • Version 3.4

Privacy Policy

This Privacy Policy ("Policy") sets forth the legal framework, principles, and practices governing the collection, utilization, processing, transmission, storage, and protection of personal data and telecommunications metadata by PropelRoot AI ("Company", "we", "us", or "our"). This Policy applies to all users, account holders, enterprise clients, and end-consumer communication recipients accessing or utilizing our primary marketing website (propelroot.pro), client application portal (app.propelroot.tech), regional services (in.propelroot.pro), conversational voice artificial intelligence telephony engines, application programming interfaces ("APIs"), SMS/MMS mobile messaging gateways, and multi-channel customer relationship management integrations (collectively, the "Platform" or "Service").

MANDATORY MOBILE MESSAGING & SMS PRIVACY COVENANT (THE CAMPAIGN REGISTRY & CTIA COMPLIANCE):

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the above categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties or affiliates.

PropelRoot AI covenants and warrants that mobile phone numbers, short message service (SMS) opt-in consent records, and mobile subscriber data provided to or processed by the Platform shall remain strictly confidential. Mobile subscriber information will under no circumstances be sold, leased, rented, bartered, monetized, assigned, or disclosed to third parties, affiliate marketers, data brokers, or commercial advertising syndicates for promotional, commercial marketing, or cross-context behavioral advertising purposes.

1. Legal Capacity and Scope of Processing (Controller vs. Processor)

To ensure full adherence to applicable data protection jurisprudence—including the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act of 2020 (collectively, "CCPA/CPRA", Cal. Civ. Code § 1798.100 et seq.), the General Data Protection Regulation ("GDPR", Regulation (EU) 2016/679), the Telephone Consumer Protection Act ("TCPA", 47 U.S.C. § 227), and regulatory frameworks established by the Federal Communications Commission ("FCC") and the Telecom Regulatory Authority of India ("TRAI")—PropelRoot AI operates in two distinct legal capacities:

2. Categories of Personal Information Collected

We collect and process personal data across distinct operational categories necessary for the delivery and security of our telecommunications and voice intelligence services:

A. Corporate Account and Billing Identifiers

B. Telephony Detail Records, Speech Data, and Messaging Metadata

C. Technical, Device, and Telemetry Data

3. Lawful Basis and Purpose of Processing

PropelRoot AI processes Personal Information exclusively in furtherance of the following legitimate business, operational, and telecommunications purposes:

4. Non-Sharing of Mobile Data & Commercial Segregation (TCR Policy)

PropelRoot AI strictly enforces technical and organizational barriers to ensure that mobile phone numbers and text messaging consent are never commercialized, sold, or shared:

5. Downstream Technical Sub-Processors & Infrastructure Providers

To maintain sub-second latency and carrier-grade voice intelligence, PropelRoot AI partners with select infrastructure and communications providers. Each sub-processor is bound by written Data Processing Agreements (DPAs) imposing confidentiality obligations and data protection standards no less restrictive than those set forth herein:

6. Cryptographic Security Standards & Architecture

PropelRoot AI implements state-of-the-art technical, physical, and administrative security measures designed to protect personal data against accidental loss, unauthorized disclosure, or illicit access:

7. Data Retention Schedules and Deletion Governance

We retain personal information only for the period necessary to fulfill the operational purposes described in this Policy, satisfy telecommunications carrier audit windows, or comply with statutory accounting requirements:

8. Consumer Privacy Rights and Statutory Opt-Out Procedures

Depending on your jurisdiction of residence, you possess specific legal rights regarding your personal information:

9. Protection of Minors (COPPA Compliance)

The Platform is exclusively designed for commercial enterprise business applications and is not directed to individuals under the age of eighteen (18). We do not knowingly collect, process, or maintain personal data from individuals under the age of thirteen (13) in accordance with the Children's Online Privacy Protection Act (COPPA). If we discover that an individual under thirteen (13) has provided us with personal data, we will immediately delete such information from our records.

10. Modifications and Amendments

PropelRoot AI reserves the right to amend or update this Privacy Policy at any time to reflect statutory changes, carrier compliance mandates, or technological developments. In the event of material modifications, we will publish the amended Policy on this page, update the "Effective Date" at the top of this document, and provide prominent notice via email or within the client dashboard prior to the effective date of such modifications.

11. Corporate Directory & Designated Privacy Officer

For questions, formal legal notices, regulatory inquiries, or requests to exercise statutory privacy rights, please direct all correspondence to our designated privacy office:

Corporate Brand / Entity: PropelRoot AI

Legal Operating Entity: PropelRoot (Guru Praneeth Kumar)

Registered Physical Address: 18-1-337 67 Arundathi Colony Uppugu, Hyderabad, Telangana 500053, India

Designated Privacy Email: [email protected]

Customer Billing & Inquiries: [email protected]

Online Compliance Directory: https://propelroot.tech/contact

Official Web Domain: https://propelroot.tech