Legal

Privacy Policy

How we protect your business information throughout our engagements, comply with GDPR, and ensure absolute customer data privacy.

Last updated: July 3, 2026

1. Who we are & DPO contacts

Deciding Labs is an AI automation agency specializing in designing custom conversational voice assistants and web chat widgets. We prioritize your privacy and data security.

For any data protection inquiries, to exercise your legal rights, or to reach our **Data Protection Officer (DPO)**, please contact us directly at hello@rahulparathy.com.

2. GDPR Role definition (Processor vs Controller)

Under the EU General Data Protection Regulation (GDPR) and other international data privacy acts:

  • Data Processor: Deciding Labs operates strictly as a Data Processor when we build, test, and temporarily run AI voice/chat configurations containing your customers' conversations.
  • Data Controller: The Client (you) acts as the Data Controller. You retain ultimate responsibility for getting consent from your users, defining transcript retention policies, and securing your customer phone lists.

3. Information we collect & legal basis

Under Article 6 of the GDPR, we collect and process information based on the following legal foundations:

  • Performance of a Contract: To build your AI agents, we collect your business contact details, billing credentials, API credentials, and calendar tokens.
  • Explicit Consent: To tune prompts and scripts, we temporarily process sample customer conversations, logs, or databases with your explicit authorization.
  • Legitimate Interests: To resolve technical bugs, manage billing invoices, and prevent fraud.

4. Data storage, retention & complete deletion

We execute a strict handover practice to ensure you retain absolute control over your customer logs:

  • Active Sandbox Purge: Once your voice receptionist or chat widget is approved and launched in your own telephony accounts, Stripe, or web container, we delete all credentials, sandbox API keys, and sandbox customer databases from our system.
  • Retention limits: We retain only transactional invoices, signed Statement of Work agreements, and support email histories for tax and dispute purposes as required by law.
  • No model training: Your custom business configurations and customer transcripts are never used to train global AI models or share templates with other clients.

5. Technical security measures

We enforce hardware-level disk encryption, secure multi-factor authentication (MFA) across all repository accounts, isolated staging nodes, and manage project passwords in encrypted password vaults.

6. International data transfers (US & Third-Party APIs)

Because our AI systems integrate with specialized API providers (such as OpenAI, Google Gemini, and others), processing voice files and text transcripts may involve transferring data to servers in the United States.

To ensure EU compliance, we support implementing standard contractual clauses (SCCs) and configuring webhook storage nodes so that transcripts are sent directly to EU-based secure databases.

7. GDPR Data Subject Rights

If you are located in the European Union or United Kingdom, you hold the following rights:

  • Right to Access: Ask for details of what information we hold.
  • Right to Rectification: Request correction of inaccurate information.
  • Right to Erasure (Forgotten): Request deletion of your development records.
  • Right to Restriction: Temporarily suspend processing of your credentials.
  • Right to Data Portability: Obtain your custom wrapper code in a standard format.

To invoke these rights, email us at hello@rahulparathy.com. We will process your requests within 30 days free of charge.

8. Cookies & tracking policy

Our website implements a strictly functional zero-tracking policy. We employ only essential cookies necessary for rendering the layout and saving theme selections (light/dark mode). We do not run third-party advertising pixels, remarketing trackers, or behavioural profiling scripts.

9. Governing law

This Privacy Policy is governed by the laws of Sri Lanka, incorporating the Personal Data Protection Act No. 9 of 2022, and structured to align with GDPR standards for European integrations.