Effective date: 28 September 2026
This policy explains how Comcent Technologies Private Limited (“Comcent”, “we”, “us”) handles personal data on this website, comcent.io, and in Comcent Cloud, our hosted voice infrastructure service at app.comcent.io.
Comcent Technologies Private Limited
Aasare, 2-187/B16, Fourth Floor, (301) Prathvi Palace
Behind Maari Gudi, Brahmavara, Karnataka, India - 576213
Email: contact@comcent.io
The open-source edition of Comcent runs on your own servers. We do not receive any data from it, and this policy does not apply to it.
If you were on a call with an organisation that uses Comcent Cloud, please contact that organisation about your data. Its own privacy policy applies. If you contact us, we will pass your request on to it.
Account data. When you or your organisation sign up: your name, email address, phone number, password (stored only as a secure hash), organisation name, and your role. If you sign in with Google or another identity provider, we receive your name and email address from it.
Billing data. The billing name and address, tax details if you give them, your top-ups, plan, charges and invoices. We do not collect or store card numbers or bank details: PayPal and Razorpay handle those. We receive payment metadata from them, such as the payment ID, amount, currency, status and the payer’s name and email.
Call data (processed for our customers). Call recordings, transcripts, AI summaries, sentiment and labels, call logs (numbers, times, durations, agents), voicemail, contact details, and voice bot conversations.
Usage data. How you use the app and website: pages and features used, device and browser, IP address, approximate location from the IP address, and logs we keep for security and troubleshooting.
Marketing and attribution data. The campaign that brought you to us, such as UTM tags and ad click IDs (for example gclid), and which ads or pages you saw before signing up. See section 6.
What you send us. Messages to support, feedback, and anything else you choose to share.
| Purpose | Lawful basis |
|---|---|
| Create and run your account, provide the service, process call data for your organisation | Performing our contract with you or your organisation |
| Take payments, issue invoices, keep accounting records | Contract, and legal obligation (tax and company law) |
| Security, fraud and abuse prevention (including coupon abuse and toll fraud) | Legitimate uses under the DPDP Act; legitimate interests under GDPR |
| Service emails (sign-up, security, low balance, renewals, invoices) | Contract |
| Support and responding to your requests | Contract, or legitimate interests |
| Analytics cookies on the website and in the app | Your consent |
| Advertising tags and measuring our ads | Your consent |
| Marketing emails | Your consent, which you can withdraw at any time |
| Complying with the law and responding to lawful requests | Legal obligation |
Under the DPDP Act, we process your data with your consent or for the “legitimate uses” the Act allows, such as when you give us your data voluntarily to use a service or to meet a legal obligation. Where we rely on consent, you can withdraw it at any time; this does not affect what we did before.
We do not sell your personal data.
We use the following subprocessors to run Comcent Cloud. Each gets only the data it needs for its task:
| Subprocessor | What it does | Where |
|---|---|---|
| DigitalOcean | Hosting of the app, database and call servers | United States |
| Amazon Web Services (S3) | Storage of call recordings and encrypted backups | United States |
| OpenAI | Transcript analysis, summaries, sentiment and the voice bot | United States |
| Deepgram | Speech-to-text and text-to-speech | United States |
| Resend | Sending email | United States |
| PayPal | Payments outside India | Global |
| Razorpay | Payments in India | India |
| Zoho Books | Invoicing and accounting | India |
| Sentry | Error reports from our servers, which may include account identifiers | United States |
| Your phone carrier | Carrying your calls, such as Twilio or your SIP trunk provider, under your own agreement with the carrier | Depends on the carrier |
| We also use the analytics and advertising providers in section 6. |
We may also share data:
On comcent.io we use Google Analytics, Google Ads, Reddit and Microsoft advertising tags, and PostHog. In the app, PostHog records the pages you view and the features you use, and may record your session (password fields are never recorded).
When you sign up or first top up, we may send that event and its value, with a hashed (scrambled) copy of your email address, to Google Ads and Reddit to measure how well our ads work. We store the campaign details (UTM tags and click IDs) that brought you to us on your account, so we know which ads and posts bring customers.
Your choice. Analytics and advertising cookies and tags stay off until you accept them, through the cookie banner. Google tags run in Google’s Consent Mode: until you accept, they do not set cookies for analytics or ads. You can accept or reject analytics and advertising separately, and change your choice at any time from the Cookie settings link at the bottom of every page. Cookies we use:
comcent_consent, kept for one year). These are always on.We are based in India, and most of our subprocessors are in the United States. Your data may therefore be processed outside your country. We choose providers with strong security and contract terms that protect personal data.
For data from the EU, UK or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (and the UK addendum) in our providers’ data processing agreements, or on another transfer mechanism the law recognises.
We protect personal data with measures such as encryption in transit (TLS), encrypted backups, access controls that limit who can reach production systems, and logging. No system is perfectly secure, but we work to keep your data safe and fix problems quickly.
If a breach affects your personal data, we will tell you and the relevant authorities as the law requires, including the Data Protection Board of India under the DPDP Act and, where GDPR applies, the supervisory authority. For call data we process for an organisation, we will tell that organisation without undue delay so it can meet its own obligations.
Under the DPDP Act (India) you can:
Under the GDPR (EU and UK) you can:
How to use your rights. Email contact@comcent.io from the address on your account, or tell us how we can confirm who you are. We will reply within 30 days. For call data, we will pass your request to the organisation that controls it and help it respond.
If you have a question or complaint about your personal data, contact:
Grievance Officer, Comcent Technologies Private Limited
Aasare, 2-187/B16, Fourth Floor, (301) Prathvi Palace
Behind Maari Gudi, Brahmavara, Karnataka, India - 576213
Email: contact@comcent.io
We will acknowledge your complaint and aim to resolve it within 30 days. If you are in India and not satisfied with our answer, you may complain to the Data Protection Board of India.
Comcent Cloud is a business service and is not meant for anyone under 18. We do not knowingly collect personal data from children. If you think a child has given us personal data, contact us and we will delete it.
Organisations that use Comcent Cloud are responsible for their Callers’ and Members’ personal data: telling them how it is used (for example, that calls are recorded), having a lawful basis, and answering their requests. Our Terms of Use set out these responsibilities.
We may update this policy. When we make a change that matters, we will tell you by email or in the app before it takes effect. The effective date at the top shows which version applies.