01 Introduction & Scope
Diradz Solutions ("Diradz", "we", "our", or "us"), headquartered in Bengaluru, Karnataka, India, is an AI-first product engineering organization developing enterprise Vertical Operating Systems (including PRO 360 CRM, SITE 360, EDU 360, and MED 360) and conducting Deep-Tech R&D.
This Privacy Policy explains our practices regarding the collection, processing, storage, and transfer of personal and telemetry data when you visit our website (diradzsolutions.com), interact with our presales voice agents, or utilize our enterprise platforms as a customer or authorized end-user.
Role as Data Controller vs. Data Processor
When you browse our public website or submit an inquiry, Diradz operates as the Data Fiduciary (Data Controller). When an enterprise developer or enterprise client deploys our PRO 360 CRM or 360 Suite to manage their customer records and lead pipelines, the enterprise client acts as the Data Controller, and Diradz acts strictly as the Data Processor operating under rigorous sub-processing contracts.
02 Information We Collect
We collect data under three primary classifications depending on how you interact with our ecosystem:
A. Information You Voluntarily Provide
- Contact & Inquiry Data: Full name, professional email address, phone number, company name, designation, and project specifications submitted through our demo forms, investor decks, or job applications.
- Presales & Interactive AI Conversations: Audio voice streams, conversational transcripts, property preferences, configuration requests, and budget parameters provided during interactive presales triage calls.
- Career Application Data: Resumes, employment history, portfolio links, and technical assessments submitted via our recruitment portal.
B. Automatically Collected Technical & Telemetry Data
- Device & Network Identifiers: IP address, browser type and version, operating system, preferred language, referrer URLs, and network latency telemetry.
- Usage Analytics: Pages viewed, time spent per section, scroll depth, and interaction metrics with our platform demos.
C. On-Site Operations Data (Diradz Pro 360 Suite)
- Gate Check-In & OTP Logs: Visitor mobile numbers, one-time password (OTP) verification timestamps, sourcing channel partner identifiers, and assigned sales executive IDs.
| Data Category | Source | Purpose | Retention Period |
|---|---|---|---|
| Contact Inquiries | Web Forms | Product demonstrations, sales discovery, and contractual proposals | 3 years from last activity or until consent revocation |
| AI Presales Voice Logs | Voice Agent / Telephony | Lead triage, sentiment analysis, and human executive handover | 90 days rolling (transcripts retained as CRM lead note) |
| Visitor OTP Records | GRE Tablet App | Physical site visit verification, broker attribution, and RERA audit trails | 7 years (statutory real estate audit compliance) |
| Security & Web Logs | Server Infrastructure | DDoS protection, incident analysis, and rate-limiting | 30 days rolling |
03 Legal Bases for Processing
We process personal data in strict accordance with the Digital Personal Data Protection (DPDP) Act 2023 (India), General Data Protection Regulation (GDPR) (EU/UK), and relevant regional statutes based on the following grounds:
- Consent (Section 6, DPDP Act / Art. 6(1)(a) GDPR): When you explicitly submit a contact form, request an investor deck, or opt into communication updates.
- Contractual Necessity (Art. 6(1)(b) GDPR): To provision access to our 360 Suite platforms, process billing schedules, and maintain active SLA performance.
- Legitimate Interests (Art. 6(1)(f) GDPR): To secure our web infrastructure, prevent duplicate lead cannibalization, audit system security, and continuously improve platform performance.
- Legal & Regulatory Compliance: To comply with RERA regulations, financial reporting, and statutory requests from law enforcement authorities.
04 Enterprise CRM & Multi-Tenant Data Isolation
In our flagship PRO 360 CRM and enterprise suites, customer lead data and property inventory matrices are protected by rigorous architectural boundaries:
- Zero Cross-Tenant Pollution: Each enterprise customer’s database schema and customer registries are logically and cryptographically partitioned. Customer records belonging to Developer A are never accessible, indexable, or visible to Developer B.
- Customer Data Ownership: All end-consumer lead records, booking receipts, and payment schedules uploaded into Pro 360 remain the sole, uncompromised intellectual property of the licensed enterprise client. Diradz does not monetize, sell, or rent CRM records.
- Two-Tier Fuzzy Deduplication: Phone number normalization and fuzzy string matching execute strictly within the customer’s private tenant perimeter to prevent duplicate lead spend without exposing data across boundaries.
05 AI Presales, Voice Processing & Model Ethics
Diradz integrates conversational voice intelligence (including Sarvam AI and specialized LLM workflows) to triage inquiries and facilitate scheduled property walkthroughs. We adhere to these non-negotiable principles:
No Model Training on Private Customer Records
Diradz Solutions does not use proprietary enterprise CRM data, customer voice audio, or client negotiation transcripts to train public foundational AI models. All inferencing operates over zero-retention enterprise API endpoints.
- Transparent Voice Handover: Callers are informed of automated AI assistance, and conversations are immediately routed to human sales executives whenever requested.
- Audio Ephemerality: Raw voice audio streams are processed in real-time memory buffers; only synthesized structured JSON notes (e.g. configuration, timeline, budget tier) are committed to the client's CRM timeline.
06 Third-Party Sub-Processors & Disclosures
We do not sell personal information. We share data only with verified sub-processors under rigorous Data Processing Addendums (DPAs):
- Cloud & Compute Infrastructure: Amazon Web Services (AWS Asia Pacific - Mumbai Region) and verified tier-4 sovereign data centers.
- Telephony & Messaging Carriers: Enterprise CPaaS carriers (e.g., WhatsApp Business API, Twilio, Exotel) for OTP verification and automated visit pin dispatches.
- Mobility & Ride Dispatch APIs: Integrated mobility partners utilized exclusively when a prospect consents to scheduled cab dispatch for a physical site walkthrough.
- Legal & Regulatory Disclosures: If required by court order, subpoena, or applicable Indian or international law.
07 Data Sovereignty & International Transfers
For our Indian enterprise clients, all primary databases, CRM records, and audit ledgers reside on sovereign servers located within the territory of India in accordance with DPDP localization mandates.
For European and global customers utilizing our SME Data Clean Rooms or cloud modules, data is transferred under standard contractual clauses (SCCs) or processed within zero-knowledge hardware enclaves (Intel SGX / AMD SEV) ensuring mathematical isolation without plaintext exposure.
08 Security, Cryptography & Retention
Diradz enforces defense-in-depth security standards across all layers of the technology stack:
- Encryption at Rest: All database stores, backups, and file objects are encrypted using AES-256 with managed KMS key rotation.
- Encryption in Transit: Mandatory TLS 1.3 encryption across all public and internal microservice communication channels.
- Post-Quantum Readiness: Our deep-tech R&D lab is actively testing NIST FIPS 203/204 lattice-based cryptographic handshakes (CRYSTALS-Kyber) to future-proof customer ledgers against quantum compute decryption vectors.
- Role-Based Access Control (RBAC): Strict principle of least privilege, multi-factor authentication (MFA), and automated audit logs for all administrative actions.
09 Your Statutory Rights as a Data Principal
Under the DPDP Act 2023, GDPR, and global data privacy frameworks, you have the following enforceable rights:
- Right to Access & Summary: Request a full copy of the personal data we hold concerning you and a summary of processing activities.
- Right to Correction & Rectification: Update inaccurate or incomplete personal records.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data where retention is no longer necessary or consent is withdrawn.
- Right to Restrict or Object to Processing: Limit how we process specific categories of data.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable JSON or CSV format.
- Right to Grievance Redressal: File a complaint with our Data Protection Officer or the Data Protection Board of India.
To exercise any of these rights, please email dpo@diradzsolutions.com. We verify requester identities and respond within 30 calendar days.
10 Cookies & Local Storage Policy
Our website uses minimal, privacy-preserving cookies and local storage tokens:
- Essential Preferences: We use
localStorage.getItem('diradz_theme')strictly to persist your preferred Dark or Light theme across page visits. This does not track your browsing history or identify your persona. - Session Identifiers: Ephemeral session tokens to prevent Cross-Site Request Forgery (CSRF) on contact and demo submission forms.
- Analytics Telemetry: Aggregated, anonymized performance metrics. We do not use intrusive cross-site ad retargeting pixels without explicit prior consent.
11 Grievance Redressal & Data Protection Officer
In compliance with the Digital Personal Data Protection Act 2023 and the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, Diradz Solutions has appointed a designated Grievance Officer and Data Protection Officer (DPO):
Office of the Data Protection Officer
Name: Legal & Compliance Team
Entity: Diradz Solutions
Address: Bengaluru, Karnataka, India
Email: dpo@diradzsolutions.com
Support Hotline: +91 91005 36320
Grievance Response SLA: Initial acknowledgment within 24 hours; complete resolution within 15 working days.
If your grievance is not resolved satisfactorily, you retain the statutory right to escalate the matter to the Data Protection Board of India or your regional supervisory authority.