Effective date: October 1, 2026
This Privacy Policy explains how Rao Industries, operating under the Ava AI brand (“Ava AI,” “Ava,” “we,” “us,” or “our”), collects, uses, stores, discloses, and otherwise processes information when you visit https://getava.in, create or use an Ava account, use the Ava AI software-as-a-service platform, deploy an Ava chatbot, or contact us.
Ava is primarily a business software service. This Privacy Policy is intended to describe our actual data practices for the current service and may be updated as the service, technology providers, or applicable law changes.
The following terms have the meanings given below. Where a term has a specific meaning under applicable data-protection law, that legal meaning will apply to the extent required.
Ava processes information in more than one context. When you create and use an Ava account, Ava processes information needed to provide the Service to you. When a Business Customer deploys an Ava chatbot on its own website, that Business Customer generally determines the purposes for which its website visitor information is collected and used, while Ava processes that information as necessary to provide the chatbot and related Service.
Accordingly, the Business Customer may have its own privacy notice and legal obligations for information collected from its visitors. Visitors should review the privacy notice of the website or business they are interacting with. Ava does not take ownership of a Business Customer's visitor data merely because Ava processes it.
When you create or administer an Ava account, we may collect:
A Business Customer may provide information such as:
When a Business Customer asks Ava to learn from a website, Ava may retrieve and process publicly accessible website content for the purpose of configuring and providing the customer's AI assistant. The current website-learning flow is designed to work with publicly accessible content and does not use credentials or authenticated sessions to access private areas.
Crawled website content may be stored in the Business Customer's knowledge base, including source text and derived indexing information used to retrieve relevant information during AI conversations.
When a Visitor interacts with an Ava chatbot or supported customer channel, Ava may process information contained in the interaction. Depending on what the Visitor or Business Customer provides, this may include:
Ava may temporarily process network information such as an IP address for security and rate-limiting purposes. IP addresses used for short-lived rate limiting are not intended to be maintained as permanent account records. Ava does not intentionally store browser or device fingerprints for advertising or cross-site behavioral profiling.
Ava uses functional first-party cookies and similar browser storage required to operate the Service, including authentication/session functionality and limited onboarding state. Ava does not currently use advertising cookies or third-party advertising tracking on the SaaS dashboard.
Ava maintains first-party operational information such as conversation counts, lead-related metrics, AI token usage, estimated provider costs, response latency, and other service metrics needed to operate and improve the platform.
Ava does not intentionally store raw payment-card credentials such as card numbers, CVV values, or card expiry information in its own database. Subscription payments are processed through Razorpay and may be subject to Razorpay's own privacy practices and terms.
Ava may use information for the following purposes:
Ava currently uses Groq as its AI inference provider. Information necessary to generate an AI response may be transmitted to and processed by Groq in accordance with Groq's applicable contractual terms and privacy documentation.
Ava does not authorize or use Customer Data to train or fine-tune general-purpose AI models. Groq's current Cloud Services agreement treats customer Inputs and Outputs as Customer Data and states that they are not permitted to be used for model training or fine-tuning unless the customer explicitly grants permission or instructs Groq to do so.
Ava may add additional AI or infrastructure providers in the future. If the provider change materially affects how Personal Data is processed, this Privacy Policy and/or Ava's public provider disclosures may be updated.
Business Customers retain ownership and other applicable rights in Customer Data they submit to Ava. Ava does not acquire ownership of Customer Data merely because the Service stores or processes it.
A Business Customer grants Ava only the limited rights reasonably necessary to host, store, process, transmit, index, secure, troubleshoot, and otherwise provide the Service.
A Business Customer may use Ava to communicate with its own customers or website visitors. The Business Customer is generally responsible for determining the purposes of that processing, identifying the lawful basis or authorization required under applicable law, providing appropriate notices, and responding to requests from those individuals.
Ava processes visitor information only as necessary to provide the Service to the Business Customer and does not independently claim ownership over the Business Customer's visitor conversation data.
Because the business deploying the chatbot controls its own customer relationship, a Visitor who wants to understand how that business uses their information should also consult that business's own privacy notice.
Ava does not use customer business information, uploaded knowledge, website content, or customer conversations to train or fine-tune general AI models.
Ava may use appropriate operational analytics and customer feedback to improve the SaaS product, service reliability, customer experience, and business operations. This does not grant Ava permission to use Customer Data to train general AI models.
Ava relies on third-party service providers to operate the Service. Current providers include:
| Provider | Purpose | Information potentially processed |
|---|---|---|
| Groq | AI inference | Prompts, relevant conversation context, and generated model outputs required for inference. |
| Vercel | Web/application hosting and delivery | Service requests, application data transmitted through the hosted application, and operational information. |
| Render | Real-time WebSocket infrastructure & live chat relay | Real-time visitor and operator chat messages, live room events, and connection synchronization data. |
| Supabase | Database and related infrastructure | Account, business, knowledge, conversation, configuration, and operational data stored by Ava. |
| Upstash / Redis | Caching, rate limiting, and operational infrastructure | Short-lived rate-limit and cache information and other operational state. |
| Firecrawl | External website scraping & content extraction | Public website URLs and crawled text/structured document data instructed by customer for knowledge ingestion. |
| Razorpay | Payments and subscription processing | Payment and billing information submitted during checkout and related subscription identifiers. |
| Resend | Transactional email delivery | Email addresses and message content necessary to deliver transactional emails. |
| Google authentication | Authentication and basic account information returned through Google sign-in where used. |
Service providers may change as Ava develops. Each provider may process information according to its own applicable agreements, privacy documentation, and security controls.
Ava may access customer information when reasonably necessary to provide customer support, investigate technical problems, diagnose incidents, maintain reliability, or address security issues. Such access is limited to the purposes necessary for operating and supporting the Service.
Ava personnel and authorized service providers are not permitted to use customer information for unrelated purposes.
Ava is initially operated from India and may be made available internationally. Because Ava relies on cloud, AI, email, payment, and other technology providers operating in multiple jurisdictions, Personal Data and Customer Data may be processed or stored outside India.
Where applicable, Ava will use reasonable contractual, technical, and organizational measures required by applicable law for international processing and service-provider arrangements.
Ava intends to retain a Business Customer's account, workspace, business information, and related SaaS data while the customer maintains an account or otherwise remains on the platform.
After an account becomes inactive and the customer has been away from the platform for one year, Ava intends to delete applicable data, unless the customer requests continued retention, applicable law requires longer retention, or retention is reasonably necessary for legal, security, accounting, fraud-prevention, or dispute-resolution purposes.
A customer may request deletion of its data by contacting support@getava.in. Where deletion is applicable, Ava will delete the relevant data from active production systems as soon as reasonably practicable and will make reasonable attempts to direct applicable service providers to delete the relevant information.
Deletion from active production systems does not necessarily mean immediate deletion from every backup. Encrypted backup copies may persist for a limited period under the ordinary backup lifecycle of the relevant infrastructure provider and may be overwritten or deleted as those systems expire or rotate.
Visitor conversations created through an Ava chatbot are distinct from the Business Customer's own account records. Retention of these conversations can depend on the Business Customer's use and configuration of the Service, operational retention controls, customer-support requirements, deletion requests, and applicable law. The Business Customer remains responsible for defining and communicating its own retention practices to visitors where required.
Security is important to Ava. We use technical and organizational measures designed to protect information from unauthorized access, alteration, disclosure, loss, or misuse. Depending on the system and data involved, these measures may include:
No method of transmission or electronic storage can be guaranteed to be completely secure. Ava therefore does not promise absolute security, but we work to maintain safeguards appropriate to the nature of the Service.
Ava is designed primarily for business information and customer-support conversations. Customers should not intentionally submit or store the following through the standard Service:
Ava is not responsible for loss or damage resulting from a customer's decision to submit such information contrary to the intended use of the Service, except to the extent applicable law provides otherwise.
Ava currently uses functional first-party cookies and limited browser storage for purposes such as authentication/session management and onboarding state. These technologies are necessary for core Service functionality.
Ava does not currently use third-party advertising cookies or cross-site advertising profiles in the SaaS dashboard. If non-essential tracking technologies are introduced in the future, the relevant disclosures will be updated.
Ava does not currently use Customer account information to send marketing emails as a standard practice. Ava may send transactional communications necessary to operate the Service, such as verification, password recovery, security, billing, service, and support messages.
Ava currently uses first-party operational analytics rather than a third-party advertising analytics stack on the SaaS dashboard. These metrics may include conversation counts, lead-related metrics, AI usage, response latency, and provider cost information.
Ava may use aggregated operational information and customer feedback to improve the SaaS product, service reliability, user experience, and business operations. Ava does not use Customer Data to train or fine-tune general AI models.
Ava uses Razorpay for payment processing. Payment information entered into Razorpay checkout is handled by Razorpay according to its own policies and controls. Ava stores subscription identifiers and related billing state needed to administer the Service, but does not intentionally store raw card credentials.
Ava may disclose Personal Data or Customer Data where required or permitted by applicable law, valid court order, governmental direction, lawful authority, or other legal process. Ava may also disclose information where reasonably necessary to prevent fraud, security incidents, illegal activity, or harm, or to protect the rights, property, or safety of Ava, its customers, users, or the public.
Where legally permitted and reasonably practical, Ava may notify the affected customer before or after a disclosure. Ava may also suspend or restrict a customer account, chatbot, content, or deployment when required by applicable law or lawful authority.
If Ava is involved in a merger, acquisition, financing, restructuring, sale of assets, or similar business transaction, relevant information may be transferred as part of that transaction, subject to applicable law and appropriate confidentiality and data-protection measures.
Depending on applicable law and the context in which Ava processes your information, you may have rights relating to your Personal Data, including rights of access, correction, deletion, grievance handling, or other rights provided by applicable law.
Requests concerning privacy, account data, or deletion may be submitted to:
Where the information is controlled by a Business Customer, Ava may direct the request to that Business Customer or assist the customer as appropriate under the applicable legal and contractual arrangement.
Ava AI accounts and the SaaS Service are strictly intended for commercial and business use by individuals who are 18 years of age or older. Ava does not knowingly collect, process, track, or direct targeted services to children under 18 years of age (in compliance with Section 9 of the India Digital Personal Data Protection Act, 2023) or children under 13 years of age (in compliance with the US Children's Online Privacy Protection Act — COPPA).
Because Ava may be deployed on third-party business websites, Business Customers are strictly responsible for ensuring that their target audience complies with applicable age requirements and that chatbots deployed on services directed to minors are not configured without verifiable parental or guardian consent.
The Ava website or Service may contain links to third-party websites, platforms, or services. Ava does not control those third parties and is not responsible for their content, security, or privacy practices. We encourage you to review the privacy policy of any third-party service you access.
Ava may update this Privacy Policy when our Service, data-processing practices, technology providers, or applicable legal requirements change. We will update the effective date when the policy is revised.
Where required or appropriate, material changes may also be communicated through the Service, website, email, or another reasonable method. For details on how we process data as a processor on your behalf, please review our Data Processing Addendum (DPA).
For questions, privacy requests, data deletion, or statutory grievances about how Ava processes personal information, contact our designated officer: