Privacy Policy
How we collect, use and protect personal data.
This page is provided by Smart Gravity Shield ("we", "us"). You can contact us through the contact form on our website.
1. What this policy covers
This policy explains how we handle personal data in two situations: (a) when you visit this website or send us a demo request, where we decide why and how your data is used (we are the "controller" under the GDPR, and the "data fiduciary" under India's Digital Personal Data Protection Act, 2023); and (b) when a customer uses the Smart Gravity Shield service, where we process data on the customer's instructions (we are a "processor" or "data processor"). Section 3 covers the second case.
2. Data we collect on this website
| Data | Why we use it | Legal basis | Kept for |
|---|---|---|---|
| Demo request form: name, work email, company. Optional: company type, softswitch, monthly minutes range, message. | To reply to your request and arrange a demo. | Your consent (GDPR Art. 6(1)(a); DPDP Act s.6). You can withdraw it at any time. | Up to 12 months after our last contact with you, unless you become a customer or ask us to delete it sooner. |
| Server logs: IP address, browser type, pages requested, time. | To keep the site secure and working. | Legitimate interests (GDPR Art. 6(1)(f)): security and reliability. | For a limited period set by our hosting provider. |
| Anti-spam record: a salted, one-way hash of your IP address and a timestamp. | To limit repeated form submissions. | Legitimate interests: preventing abuse. | Deleted automatically within 1 hour. The hash is not added to our email. |
| Your cookie choice (stored only in your browser). | To remember your privacy choice. | Strictly necessary. | Until you clear your browser storage or change the choice. |
We do not ask for more than we need. The form does not collect phone numbers, addresses or any special category data. We do not use automated decision-making or profiling on website visitors, and we do not sell personal data.
3. Data processed inside the Smart Gravity Shield service
When a customer connects a softswitch, the service receives call detail records (CDR). These can include calling and called numbers, timestamps, call duration, account and route identifiers and result codes. The customer decides what is sent and is the controller of that data; we process it only to provide the service under our agreement and a data processing agreement (available on request).
- No call recording. The service does not record calls or analyse call audio or content.
- Agent Identity Lock (optional). It uses WebAuthn / Passkeys. Fingerprint or face data stays on the user's own device and is never sent to or stored by us. We store only the credential identifier and public key needed to verify a sign-in, linked to the user account.
- Customer responsibilities. Customers are responsible for having a lawful basis and giving any required notices to their own end users and agents.
4. Cookies and similar technologies
This site sets no analytics or advertising cookies and loads no third-party scripts, fonts or embeds. See the Cookies Policy for the full list and how to change your choice.
5. Who we share data with
We share personal data only with service providers that help us run the site and respond to you, under contract: our web hosting, infrastructure and email delivery providers. We may disclose data to professional advisers, and to authorities where the law requires it. We do not share personal data with advertisers or data brokers.
6. International transfers
Our hosting providers' data centres may be located outside your country. If your data is transferred outside the country or region where you are located, we rely on appropriate safeguards where the law requires them, such as standard contractual clauses or an adequacy decision.
7. How long we keep data
We keep data only as long as needed for the purposes in section 2, and then delete or anonymise it. Retention of service data is set in the customer agreement and configurable by the customer.
8. Your rights
Depending on where you live, you may have the right to access your data, correct it, delete it, restrict or object to its use, receive a copy in a portable format, and withdraw consent at any time (withdrawal does not affect earlier lawful use). Under the DPDP Act you may also nominate another person to exercise your rights and use our grievance process below. To exercise a right, send us a request through the contact form on this website. We aim to respond within 30 days. You can also complain to your data protection authority, or in India to the Data Protection Board of India after using our grievance process.
9. Grievance contact
Privacy and grievance requests can be sent through the contact form on this website. Please start your message with "Privacy request" so we can route it correctly.
10. Children
This website and service are for businesses and are not directed at anyone under 18. We do not knowingly collect data from children.
11. Security
We use measures appropriate to the risk, including encryption in transit, access controls and logging. No system is completely secure, and we cannot guarantee absolute security.
12. Changes
We may update this policy and will change the date below when we do. Last updated: 5 October 2026.