Legal

Privacy Policy

Last updated: 13 September 2026

This Privacy Policy explains how [LEGAL ENTITY NAME] ("we", "us") handles personal data in connection with SCRMAI ("the Service"). It covers both visitors to this website and users of the product.

1. Our two roles

This distinction matters for understanding the rest of this policy:

  • We are the controller for data about our own customers — the institute staff who sign up, their contact details, billing information and how they use the product.
  • We are a processor for the data institutes put into the product about their students, parents and staff. The institute decides what to collect and why; we process it on their instructions to run the Service.

If you are a parent or student and want to know what data an institute holds about you, contact that institute directly — they control it. We will support them in responding.

2. Data we collect as controller

  • Account data: name, work email, phone number, institute name, role.
  • Billing data: subscription plan, transaction records and GST details. Card and UPI details are handled by Razorpay; we do not store them.
  • Usage data: log data, device and browser information, feature usage and error reports, used to operate, secure and improve the Service.
  • Communications: messages you send us by email or through forms on this website.

3. Data processed on behalf of institutes

Depending on how an institute configures the Service, this may include enquiry and lead records, student and parent names and contact details, attendance records, exam scores, fee and payment records, message history, and AI call transcripts. Some of this concerns minors, which is why we ask institutes to confirm they have a lawful basis and any required parental consent.

4. How we use data

  • To provide, maintain and secure the Service;
  • To process subscription payments and issue invoices;
  • To provide support and respond to your enquiries;
  • To monitor errors, prevent abuse and rate limit public forms;
  • To send service and account notices, and — where you have not opted out — occasional product updates;
  • To meet legal and tax obligations.

5. AI processing

AI features process institute data to generate lead scores, drop-risk assessments, suggested replies, drafted messages, progress reports and voice-call interactions. This processing happens to produce outputs for that institute's own account. Where sub-processors are involved in AI or voice processing, they are listed in section 7 and are bound by contractual confidentiality and security obligations.

6. Legal bases

Where applicable law requires a legal basis, we rely on: performance of a contract (providing the Service), legitimate interests (security, service improvement, fraud prevention), consent (marketing emails, non-essential cookies), and legal obligation (tax and accounting records).

7. Sharing and sub-processors

We do not sell personal data. We share it with service providers who help us run the Service, under contract and only for that purpose:

  • Razorpay — payment processing for subscriptions and institute fee collection
  • Meta — WhatsApp Cloud API messaging and Lead Ads
  • Twilio — SMS delivery
  • Vapi — AI voice agent calling
  • Google — Calendar synchronisation
  • [HOSTING PROVIDER] — application hosting and data storage
  • [ERROR MONITORING PROVIDER] — error monitoring

We may also disclose data where required by law, or to protect our rights, users or the security of the Service.

8. Retention

Institute data is retained for as long as the account is active. After cancellation or account deletion, data is deleted within [RETENTION PERIOD], except where we must retain records to meet legal, tax or accounting obligations. Export your data before deleting your account — deletion is not reversible.

9. Security

We use TOTP two-factor authentication, role-based access controls, an audit log of sensitive actions, security headers, rate limiting on public forms, encryption in transit, and error monitoring. No system is perfectly secure, but these are real controls rather than aspirations, and they are available on every plan.

10. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data, object to certain processing, or request a copy in portable form. Product data can be exported as CSV or PDF at any time without contacting us, and account deletion is self-service. For anything else, email hello@scrmai.in.

11. Cookies

This marketing website uses only what is necessary to serve pages. If we add analytics or advertising cookies in future, we will update this policy and request consent where required before setting them.

12. International transfers

Some sub-processors listed above may process data outside India. Where that happens we rely on appropriate safeguards as required by applicable law.

13. Children

The Service is sold to institutes, not to students. Institutes may record data about minors, and are responsible for obtaining any consent required from parents or guardians. We do not knowingly market to children.

14. Changes

We will post updates here with a revised date, and notify account holders of material changes by email.

15. Contact

Privacy questions or requests: hello@scrmai.in, or write to [LEGAL ENTITY NAME], [REGISTERED ADDRESS], India.


Other policies: Terms of Service · Refund Policy