Legal
Privacy Policy
What personal information Insta AI 365 handles, how AI features and call transcription process it, who it is shared with, how long it is kept, and how to exercise your rights.
Last updated 18 September 2026 · KWIKFUTURE AI PRIVATE LIMITED · Private Limited Company · GSTIN 06AANCK2107N1ZC
1.Who we are
Insta AI 365 is operated by KWIKFUTURE AI PRIVATE LIMITED, a private limited company registered in India under GSTIN 06AANCK2107N1ZC. Our registered address is at the foot of this page.
For questions about this policy or about personal information we hold, contact privacy@instaai365.com.
2.Scope, and the three kinds of data on this page
This policy covers the website at https://instaai365.com and the Insta AI 365 CRM application. It is important to distinguish three different kinds of information, because our role and your rights differ for each.
- A. CRM data entered by our business customers
- Records about leads, contacts, companies and their staff, put into a workspace by the customer who operates it. That customer decides why and how this data is used. We process it on their instruction in order to run the service — we do not decide what it is used for. If you are a lead or customer of a business that uses Insta AI 365 and you want your details changed or removed, contact that business; they control the record. We will assist them, and if you contact us we will pass the request on where we can identify the workspace.
- B. Account information of our customers and their users
- The names, work email addresses, phone numbers and login details of the people who use Insta AI 365, and the organisation and billing details of the businesses that subscribe. We decide how this is used, and this policy governs it directly.
- C. Operational data we generate to run the service
- Security and audit logs, authentication records, error diagnostics and backups. Ours, and necessary to operate the service safely.
3.Information we collect
Account and identity information
Name, work email address, phone number where provided, a cryptographic hash of your password (never the password itself), your role and permissions, the organisation you belong to, notification preferences, and your login and session history.
Business and billing information
Organisation name, contact details, plan and subscription record, and the invoices and payment records we raise for your subscription, including tax identifiers where required.
When you buy a plan through our online checkout we collect your name, email address, mobile number (optional), company name, and the billing details you give us — legal business name, GSTIN, address and state. We use them to create your account and workspace, to raise tax invoices, and to meet our GST obligations. We also keep the plan, number of users and billing period you chose, and the payment and subscription references Razorpay returns.
CRM records you enter
Leads, contacts, companies, deals, tasks, follow-ups, notes, activity timelines, quotations, invoices, payment records, custom fields and tags. This is category A above: it is whatever you choose to put in.
Files and documents
Attachments uploaded against records. Uploads are size-limited and are virus-scanned before they are stored, and are served through short-lived signed links rather than public URLs.
Communication data
Messages and threads recorded against a record. If your workspace connects WhatsApp through the WhatsApp Cloud API, message content and metadata for those conversations are stored against the relevant record. This integration is available in the product but is enabled per workspace, and no data flows through it unless you connect it.
Call metadata, recordings and transcripts
Where click-to-call is enabled, we store the number dialled, who placed the call, timestamps, duration, the call’s lifecycle state, and the provider’s reference for it. Where recording is enabled, we also store the recording, its transcript, and any AI-generated summary or extracted detail. Transcripts include timed segments and speaker separation.
Lead capture from third parties
If you connect Meta Lead Ads, we receive the lead information the person submitted on the advertising platform’s form and create a record from it. If you use website lead forms, we receive what the visitor submitted.
Technical and log information
IP address, browser and device information, request paths and timestamps, and error diagnostics — recorded to operate the service, diagnose faults, and investigate abuse. Administrative and authentication actions are recorded in audit logs.
5.How we use information
- To provide the CRM — storing and returning your records, running searches and reports, executing automation rules you configure, generating quotations and invoices, and delivering the features on your plan.
- To authenticate and secure— verifying who is signing in, enforcing roles and permissions, separating one workspace’s data from another’s, scanning uploads, and detecting and investigating abuse.
- To provide AI features — see section 6.
- To support you — responding to your questions and diagnosing problems you report.
- To administer the commercial relationship — managing your subscription, raising invoices, and meeting tax obligations.
- To operate and improve the service — diagnosing faults and understanding failures from our own logs and error records.
- To communicate — service and security notices, and replies to you. We do not sell your details to anyone.
- To meet legal obligations — retaining financial records, and responding to lawful requests.
6.AI processing and Ira AI
AI features — including the Ira assistant, call summaries, and suggested next actions — work by sending the relevant content from your workspace to a third-party AI provider, which processes it and returns a result.
The AI provider currently used is OpenAI. Speech-to-text transcription of call recordings also currently uses OpenAI. This means that where these features are used, the text of records and the audio or text of calls leaves our servers and is processed by that provider.
To make the assistant able to answer from your own records, an indexed copy of workspace content is maintained for retrieval. AI conversation history is retained for a limited period — see section 9.
We do not use your data to train AI models, and we do not permit it to be used to train the provider’s general models. AI output can be inaccurate and should be reviewed by a person before it is relied on; see the AI clause in our Terms.
8.International transfers
Our application, database and file storage run on infrastructure we manage. Some of the providers named above process data outside India — in particular, content sent to OpenAI for AI features and transcription is processed on that provider’s infrastructure, which is located outside India. Where we transfer personal information across borders, we do so to deliver the features you have enabled, and under the terms offered by those providers.
9.Data retention
We keep information for as long as your organisation maintains an account, and afterwards only where there is a reason to. We would rather state the few periods the system genuinely enforces than publish a schedule we do not keep.
- CRM records, files, communications, calls
- Kept for the life of the workspace. They are yours to delete at any time from within the application; deleting a record removes it from the workspace.
- AI conversation history
- Retained for 90 days of inactivity, after which conversations are expired automatically. This period is enforced by the system.
- Backups
- Encrypted database backups run daily and rotate on a 14 daily and 8 weekly schedule. Data deleted from the live system is not restored into it and ages out with the backup.
- Financial records
- Invoices, tax records and payment evidence are kept for the period Indian law requires a registered business to keep them, and are used for no other purpose.
- Security and audit logs
- Retained to investigate incidents and to demonstrate that actions — including deletions — were carried out.
10.How we protect information
The measures below are in place today:
- Traffic to the service is encrypted in transit over HTTPS.
- Passwords are stored only as cryptographic hashes and are never recoverable.
- Sessions use
Secure,HttpOnlycookies with short-lived access sessions and separate refresh sessions. - Every query is scoped to a workspace, so one organisation’s records are not reachable from another’s, and roles and permissions restrict access within a workspace.
- Uploaded files are virus-scanned before storage and served only through short-lived signed links.
- Credentials for connected integrations are encrypted before being stored.
- Database backups are encrypted at rest with AES-256, run on an automated daily schedule, and are verified.
- Administrative and authentication actions are recorded in audit logs.
We do not currently hold an external security certification such as ISO 27001 or SOC 2, and this page should not be read as claiming one. No system is completely secure; you also play a part by protecting credentials and managing who has access. Report a suspected vulnerability to legal@instaai365.com. See also our security page.
11.Your rights and choices
On request, and subject to verifying who you are, we will: tell you what personal information we hold about you; correct information that is wrong; provide a copy of it; and delete it, subject to the retention exceptions in section 9.
If you are a lead or customer of a business that uses Insta AI 365 (category A), that business controls your record. Contact them directly. If you contact us instead, we will refer the request to them where we can identify the workspace, and assist them in acting on it — but we will not unilaterally alter their records.
Send requests to privacy@instaai365.com. We respond as promptly as we reasonably can.
12.Data export
The application includes export tools that let you take your CRM records out in a portable format. Export your data before closing a workspace, because deletion is not reversible. If you need an export we cannot produce from the interface, ask privacy@instaai365.com.
13.Account and data deletion
You can delete individual records from within the application at any time. Deleting an entire user account or an entire workspace is handled as a request to us rather than by a self-service button, so that we can verify the request before acting on something irreversible. The full process, what is removed, and what is retained, is set out on the Data Deletion page.
14.Children's privacy
Insta AI 365 is a business tool and is not directed at children. We do not knowingly collect personal information from anyone under 18 as a user of the service. If you believe a child has been given access, contact privacy@instaai365.com and we will remove the account.
15.Changes to this policy
We update this policy as the product and the law change. The “last updated” date at the top of the page shows when it last changed. Where a change materially affects how we handle personal information, we will take reasonable steps to notify workspace administrators.
16.Contact us
- Privacy: privacy@instaai365.com
- Legal: legal@instaai365.com
- Telephone: +91 85718 14899
Insta AI 365 is operated by KWIKFUTURE AI PRIVATE LIMITED
Basement, Office No 19,Neelkanth Complex,Camp Chowk,Hisar, Haryana – 125001,India