Privacy Policy

Effective Date September 02, 2026

1. Introduction

Mivikron Solutions Private Limited ("we," "our," or "us") operates Basalix AI. This Privacy Policy describes how we collect, process, use, and share personal information when you access our website, platform, and APIs. We comply with the Information Technology Act, 2000, the Digital Personal Data Protection (DPDP) Act, 2023, and adhere to global standards such as the GDPR.

2. Information We Collect

2.1 Information You Provide Directly: When you register, we collect your name, email address, organization name, payment information, and account credentials. (If you register via Google OAuth, we receive your name, email, and profile picture).

2.2 Customer Data (Knowledge Base): Documents, text, and data you upload to the Basalix AI platform to train your AI agents.

2.3 Automatically Collected Information: We automatically collect log data, device information, IP addresses, browser types, and usage statistics (e.g., chat logs, API request volumes) using cookies and similar tracking technologies.

2.4 End-User Data: If you deploy our chat widget on your website, we may process information from your end-users (e.g., chat queries, session IDs). You are the Data Fiduciary/Controller for your end-users, and we act solely as the Data Processor.

3. Google API Data Disclosure & Limited Use Policy

The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Furthermore, if you connect your Google Calendar account to Basalix AI via Google OAuth, the collection, use, and transfer of data received from Google APIs will strictly adhere to the Google API Services User Data Policy, including its Limited Use requirements.

3.1 Scopes Requested: We request access to calendar.readonly and calendar.events.

3.2 Specific Use Case: We access your Google Calendar data solely to read existing availability (to prevent booking conflicts) and to create, update, or delete calendar events initiated by your interaction with our booking AI application.

3.3 Strict Prohibitions on Google Data:

  • We do not use Google user data to train foundational artificial intelligence or machine learning models.
  • We do not use Google user data for advertising, marketing, profiling, or tracking across other services.
  • We do not sell, rent, or trade any data obtained from Google APIs to third parties.
  • We do not transfer or share Google user data with third parties unless it is strictly necessary to provide or improve the core user-facing calendar booking features, comply with applicable law, or as part of a merger/acquisition.

4. How We Use Your Information

For general information collected outside of Google APIs, we use it to:

  • Provide, operate, and maintain the Basalix AI platform and AI infrastructure.
  • Process payments and prevent fraudulent transactions.
  • Provide customer support and technical troubleshooting.
  • Analyze platform usage to improve our retrieval algorithms and user experience.
  • Communicate with you regarding updates, security alerts, and administrative messages.

5. AI Processing and Third-Party Subprocessors

  • Strict Data Isolation: Your Customer Data is isolated using multi-tenant architecture.
  • No Foundational Training: We do not use your personal information or Customer Data to train foundational AI models.
  • Subprocessors: We share data with trusted third-party service providers, such as cloud hosting providers, payment gateways, and enterprise LLM providers like Google Gemini or OpenAI. Our LLM providers are contractually bound by “Zero Data Retention” API agreements and do not retain your data for model training.

6. Data Sharing and Disclosure

We do not sell your personal information. We may disclose information:

  • To comply with valid legal processes, subpoenas, or government requests.
  • To enforce our Terms of Service or protect the rights, property, or safety of Mivikron Solutions Private Limited, our users, or the public.
  • In connection with a merger, acquisition, or sale of company assets.

7. Data Security and Retention

We employ industry-standard organizational and technical measures, including HTTPS/TLS encryption and encrypted vector databases, to protect your data. We retain personal information only for as long as necessary to fulfil the purposes outlined in this Policy or as required by law. Upon account deletion, Customer Data is securely purged from our active databases.

8. International Data Transfers

While Mivikron Solutions Private Limited is based in India, our cloud infrastructure and subprocessors may be located globally. By using the Services, you consent to the transfer of your data to servers located outside your country of residence, subject to appropriate data transfer safeguards.

9. Your Privacy Rights

Depending on your jurisdiction (e.g., EU, California, or India), you may have the right to access, correct, or delete your personal data. You may contact us at any time to withdraw consent to processing.